The latest releases changed how agents handle tools, data, sessions, approvals, and handoffs. We traced each change to the official source. Start with five recent changes before your next build.
One task moves through memory, tools, approval, artifacts, and handoff. The blue route marks every place the work can wait, change, or pass to someone else. AI-assisted editorial illustration.
In this editionA live index of what you can read today.
656
sourced records
301
systems and frameworks
157
terms and concepts
2
records held for more proof
The week in the field
Which five changes should you check before your next build?
These releases changed runtime context, data handling, approvals, sessions, or handoffs. Each note starts with the official release. Find the change closest to your work, then read the source before you ship. That is the quickest way to see whether it changes your limits, tests, or review plan.
01
Framework release
A good trace shows the route, every checkpoint, and the place a person stopped the work. AI-assisted editorial illustration.
CrewAI separates coding-agent runtime context
CrewAI 1.15.14 separates runtime context from its coding agent and adds a project identifier. The release note is terse, so broader architectural implications remain outside this update.
A file boundary has to hold from the first check to the place where the session writes. AI-assisted editorial illustration.
Pydantic AI carries compaction across adapters
Pydantic AI 2.27.0 round-trips compaction parts through Vercel AI and AG-UI adapters, adds Snowflake Cortex support, and honors binary-content exclusion across OpenTelemetry serialization sinks.
The valid path continues. The rejected action waits where someone can inspect it. AI-assisted editorial illustration.
Strands adds tool filters and risk classification
Strands Agents TypeScript 1.12.0 adds MCP tool filtering and name prefixes, offers disabled-by-default repetitive swarm-handoff detection, and adds an LLM-based tool-risk classifier. Classifier output is a review signal, not proof of safety.
A skill can be picked and reused like a tool. Someone still has to own its permissions and release. AI-assisted editorial illustration.
OpenAI tightens guardrail and sandbox boundaries
Agents SDK Python 0.19.4 preserves completed guardrail results, defers non-stream session saves until output guardrails finish, uses payload-free SDK invalid-argument errors when tool-data logging is disabled, and enforces sandbox token-output budgets. These are named boundary fixes, not a whole-system security guarantee.
The tool call crosses a confirmation gate before it can touch the artifact. AI-assisted editorial illustration.
Microsoft expands persistent agent hosting
Agent Framework Python 1.13.0 adds reusable session stores, bounded archive-backed MCP skill discovery, and opt-out process-wide feature telemetry on reviewed first-party User-Agent request paths. Operators still need to review which archives are trusted.
Start with the question in front of you. Need a definition? Open the glossary. Choosing a framework? Compare systems. Checking who built what? Use the ecosystem. Looking for a rule? Read the standards. One clear question is enough to begin.
They give you the agent, its workflow, its limits, its tool protocol, and the evaluation that helps you judge the result. Read them in order and the rest of the field becomes easier to follow. Together, they give you a working frame for every system, standard, and release note that follows.
Start with any term, system, organization, or standard. The map shows the records sitting closest to it, then lets you open each source for yourself. Use those connections to choose what to read next. A line suggests a path; it does not prove that the two things belong together.