Release notes — week of 4 August 2026¶
These notes cover everything that shipped across all antcrew repos this week. Audience: technical evaluators, buyers, and users already running the platform.
What's new this week¶
Conversational discovery + brownfield write-back¶
The platform now includes a Discovery workflow: start a conversation with your codebase, ask it questions, and receive a structured analysis (dependencies, risks, entry points). When you're ready to act on what you found, the write-back feature opens a PR directly in your GitHub repository from within the dashboard.
Requires: GitHub App configured on your workspace (Settings → GitHub).
GitHub App integration (write-back for engine runs)¶
Engine runs can now automatically open a GitHub PR when they produce code changes. The platform creates the branch, commits the diff, and opens the PR with a structured summary that includes which capabilities ran, what changed, and why.
Activity tab on run pages¶
Each run detail page now has an Activity tab alongside Events and Trace. It shows a human-readable timeline of what happened: which agents ran, in what order, how long each took, and whether they succeeded. No raw JSON required.
New agent roles: Conflict, Retro, Cost, Security, Discovery¶
Five new agent roles available in pipelines:
- ConflictAgent — detects and surfaces contradictions in requirements or design
- RetroAgent — generates structured retrospectives from run history
- CostAgent — estimates LLM and infrastructure cost for a proposed pipeline
- SecurityAgent — scans code or config for security issues, outputs SARIF-compatible findings
- DiscoveryAgent — maps codebase structure for brownfield context
Context budget management (engine SDK)¶
BaseLLM now accepts context_compressor and context_budget_tokens. When a context
string exceeds the budget, it is automatically compressed (Python-aware AST compression
for source files, line-based compression for text) before being sent to the LLM. Reduces
token spend on large-context runs without changing model outputs for well-structured code.
Proxy per-request observability¶
keybridge now emits a structured log line for every forwarded request:
duration_msmeasures from request dispatch to first response byte (time to first token)request_idis extracted from the upstream provider's response headers — use it when filing support tickets with Anthropic, OpenAI, or Groq- 5xx errors log at ERROR level; 4xx at WARNING; success at INFO
- No request or response body content is ever logged
Security patch (platform v0.6.10+)¶
Five vulnerabilities were identified and patched this week. All affect platform self-hosted deployments; the managed service was updated automatically.
| Area | What changed |
|---|---|
| Admin session expiry | Expired session cookies were accepted indefinitely on all /admin routes. Fixed: server-side expiry check added. |
| Engine filesystem sandbox | source_dir and output_dir parameters on /engine/run accepted any absolute server path. Fixed: rejected in non-dev environments unless ENGINE_FS_ROOT is configured. |
| TOTP secret at rest | MFA TOTP secrets were stored in plaintext in the database. Fixed: Fernet-encrypted at rest using TOTP_ENCRYPTION_KEY. |
| Email verification hashing | Verification codes fell back to unkeyed SHA-256 when SECRET_KEY was absent. Fixed: startup raises an error if SECRET_KEY is missing. |
Action required for self-hosters: add TOTP_ENCRYPTION_KEY to your environment
before restarting. Generate one with:
Existing TOTP secrets in the database (plaintext) are read transparently until users next re-enroll MFA — no forced re-enrollment required.
What else shipped this week¶
Redis-backed rate limiter (multi-worker safe)¶
The in-process rate limiter has been replaced with a Redis sliding-window implementation using a Lua atomic script. This resolves the known limitation where running multiple uvicorn workers multiplied the effective rate limit per process.
- Fails open (passes traffic) on Redis unavailability — a Redis outage never blocks requests
- In-process fallback retained for local development when
REDIS_URLis not set - Startup check: if
ANTCREW_WORKERS > 1andREDIS_URLis not set, the platform raises an error in production and logs a warning in other environments
Self-hosters running multiple workers must set REDIS_URL. The reference
docker-compose.prod.yml and docker-compose.uat.yml now include a redis:7-alpine
service and wire REDIS_URL automatically.
GDPR Art. 17 right-to-erasure (admin API)¶
Platform admins can now erase a user's personal data via POST /admin/users/{id}/erase.
The endpoint anonymises the user's email, display name, TOTP secret, and password hash;
replaces run.request content across all their workspaces with a datestamped placeholder;
deletes discovery session turns; revokes all API keys; and clears all browser sessions.
Billing records are retained for legal obligation. The operation is idempotent.
HITL workflow improvements¶
- Bulk approve — select multiple pending reviews with checkboxes and approve all in one click. Processes in batches of 5 to avoid thundering herd on the database.
- Deep-link from run list — a run with a pending review shows an amber "Review" chip that navigates directly to the review queue.
- Re-run from list — hover any run row to reveal a re-run button that pre-fills the New Run modal with the same team and request.
Capability analytics endpoint¶
GET /admin/analytics/capabilities aggregates engine capability usage from the event
table. Returns per-capability: dispatch count, completion count, success rate, average
duration, and total cost. No new instrumentation required — data comes from existing
agent.start / agent.end events. Accepts ?days=N (default 30, max 365).
Token usage columns¶
run.tokens_in and run.tokens_out now accumulate per-run input/output token counts
from agent.end events (migration 055). Workspace-level token analytics are now a
single SUM query instead of requiring JSON extraction over the full event table.
Uptime status page¶
The platform SLA document now references status.antcrew.org for live uptime history, active incidents, and scheduled maintenance. P1 incidents will receive an initial status update within 30 minutes of detection.
Under the hood¶
Engine event payloads enriched — agent.end events now carry duration_ms,
tokens_in, tokens_out, succeeded, and errors fields. This unlocks SQL analytics
over execution history without any schema migration. See Event payload schema
for the full reference and example queries.
MFA join-request tokens hashed — join tokens are now stored as SHA-256 hashes rather than plaintext. Existing tokens are invalidated on upgrade; new ones are issued automatically.
Billing multiplier isolated from run completion — a bug in campaign/multiplier logic
could leave runs stuck at status="running" if eligibility evaluation threw. The billing
block is now isolated in its own try/except; failures log at ERROR and fall back to raw
provider cost without blocking run completion.
Discovery API path corrected — the quick-start documentation listed /discovery/ and
/discovery/{id}/answer; the correct paths are /discovery/sessions and
/discovery/sessions/{id}/answer. Both the docs and the API reference are now consistent.
Upgrading¶
For platform self-hosters:
- Add
TOTP_ENCRYPTION_KEYto your environment (see Security patch above). - Add a Redis service and set
REDIS_URLif you run--workers > 1. See the updateddocker-compose.prod.ymlin the platform repo for a reference configuration. - Pull the latest image and restart. Alembic runs migration 055 (token columns) automatically on startup.
For proxy self-hosters: docker pull ghcr.io/iagop03/keybridge:latest && docker compose up -d
Next release notes: week of 11 August 2026.