Skip to content

Release notes — week of 4 August 2026

These notes cover everything that shipped across all antcrew repos this week. Audience: technical evaluators, buyers, and users already running the platform.


What's new this week

Conversational discovery + brownfield write-back

The platform now includes a Discovery workflow: start a conversation with your codebase, ask it questions, and receive a structured analysis (dependencies, risks, entry points). When you're ready to act on what you found, the write-back feature opens a PR directly in your GitHub repository from within the dashboard.

Requires: GitHub App configured on your workspace (Settings → GitHub).

GitHub App integration (write-back for engine runs)

Engine runs can now automatically open a GitHub PR when they produce code changes. The platform creates the branch, commits the diff, and opens the PR with a structured summary that includes which capabilities ran, what changed, and why.

Activity tab on run pages

Each run detail page now has an Activity tab alongside Events and Trace. It shows a human-readable timeline of what happened: which agents ran, in what order, how long each took, and whether they succeeded. No raw JSON required.

New agent roles: Conflict, Retro, Cost, Security, Discovery

Five new agent roles available in pipelines:

  • ConflictAgent — detects and surfaces contradictions in requirements or design
  • RetroAgent — generates structured retrospectives from run history
  • CostAgent — estimates LLM and infrastructure cost for a proposed pipeline
  • SecurityAgent — scans code or config for security issues, outputs SARIF-compatible findings
  • DiscoveryAgent — maps codebase structure for brownfield context

Context budget management (engine SDK)

BaseLLM now accepts context_compressor and context_budget_tokens. When a context string exceeds the budget, it is automatically compressed (Python-aware AST compression for source files, line-based compression for text) before being sent to the LLM. Reduces token spend on large-context runs without changing model outputs for well-structured code.

Proxy per-request observability

keybridge now emits a structured log line for every forwarded request:

proxy.request provider=anthropic path=v1/messages status=200 duration_ms=847 request_id=req_01abc
  • duration_ms measures from request dispatch to first response byte (time to first token)
  • request_id is extracted from the upstream provider's response headers — use it when filing support tickets with Anthropic, OpenAI, or Groq
  • 5xx errors log at ERROR level; 4xx at WARNING; success at INFO
  • No request or response body content is ever logged

Security patch (platform v0.6.10+)

Five vulnerabilities were identified and patched this week. All affect platform self-hosted deployments; the managed service was updated automatically.

Area What changed
Admin session expiry Expired session cookies were accepted indefinitely on all /admin routes. Fixed: server-side expiry check added.
Engine filesystem sandbox source_dir and output_dir parameters on /engine/run accepted any absolute server path. Fixed: rejected in non-dev environments unless ENGINE_FS_ROOT is configured.
TOTP secret at rest MFA TOTP secrets were stored in plaintext in the database. Fixed: Fernet-encrypted at rest using TOTP_ENCRYPTION_KEY.
Email verification hashing Verification codes fell back to unkeyed SHA-256 when SECRET_KEY was absent. Fixed: startup raises an error if SECRET_KEY is missing.

Action required for self-hosters: add TOTP_ENCRYPTION_KEY to your environment before restarting. Generate one with:

python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"

Existing TOTP secrets in the database (plaintext) are read transparently until users next re-enroll MFA — no forced re-enrollment required.


What else shipped this week

Redis-backed rate limiter (multi-worker safe)

The in-process rate limiter has been replaced with a Redis sliding-window implementation using a Lua atomic script. This resolves the known limitation where running multiple uvicorn workers multiplied the effective rate limit per process.

  • Fails open (passes traffic) on Redis unavailability — a Redis outage never blocks requests
  • In-process fallback retained for local development when REDIS_URL is not set
  • Startup check: if ANTCREW_WORKERS > 1 and REDIS_URL is not set, the platform raises an error in production and logs a warning in other environments

Self-hosters running multiple workers must set REDIS_URL. The reference docker-compose.prod.yml and docker-compose.uat.yml now include a redis:7-alpine service and wire REDIS_URL automatically.

GDPR Art. 17 right-to-erasure (admin API)

Platform admins can now erase a user's personal data via POST /admin/users/{id}/erase. The endpoint anonymises the user's email, display name, TOTP secret, and password hash; replaces run.request content across all their workspaces with a datestamped placeholder; deletes discovery session turns; revokes all API keys; and clears all browser sessions. Billing records are retained for legal obligation. The operation is idempotent.

HITL workflow improvements

  • Bulk approve — select multiple pending reviews with checkboxes and approve all in one click. Processes in batches of 5 to avoid thundering herd on the database.
  • Deep-link from run list — a run with a pending review shows an amber "Review" chip that navigates directly to the review queue.
  • Re-run from list — hover any run row to reveal a re-run button that pre-fills the New Run modal with the same team and request.

Capability analytics endpoint

GET /admin/analytics/capabilities aggregates engine capability usage from the event table. Returns per-capability: dispatch count, completion count, success rate, average duration, and total cost. No new instrumentation required — data comes from existing agent.start / agent.end events. Accepts ?days=N (default 30, max 365).

Token usage columns

run.tokens_in and run.tokens_out now accumulate per-run input/output token counts from agent.end events (migration 055). Workspace-level token analytics are now a single SUM query instead of requiring JSON extraction over the full event table.

Uptime status page

The platform SLA document now references status.antcrew.org for live uptime history, active incidents, and scheduled maintenance. P1 incidents will receive an initial status update within 30 minutes of detection.


Under the hood

Engine event payloads enriched — agent.end events now carry duration_ms, tokens_in, tokens_out, succeeded, and errors fields. This unlocks SQL analytics over execution history without any schema migration. See Event payload schema for the full reference and example queries.

MFA join-request tokens hashed — join tokens are now stored as SHA-256 hashes rather than plaintext. Existing tokens are invalidated on upgrade; new ones are issued automatically.

Billing multiplier isolated from run completion — a bug in campaign/multiplier logic could leave runs stuck at status="running" if eligibility evaluation threw. The billing block is now isolated in its own try/except; failures log at ERROR and fall back to raw provider cost without blocking run completion.

Discovery API path corrected — the quick-start documentation listed /discovery/ and /discovery/{id}/answer; the correct paths are /discovery/sessions and /discovery/sessions/{id}/answer. Both the docs and the API reference are now consistent.


Upgrading

pip install --upgrade antcrew antcrew-engine

For platform self-hosters:

  1. Add TOTP_ENCRYPTION_KEY to your environment (see Security patch above).
  2. Add a Redis service and set REDIS_URL if you run --workers > 1. See the updated docker-compose.prod.yml in the platform repo for a reference configuration.
  3. Pull the latest image and restart. Alembic runs migration 055 (token columns) automatically on startup.

For proxy self-hosters: docker pull ghcr.io/iagop03/keybridge:latest && docker compose up -d


Next release notes: week of 11 August 2026.