Home › Changelog › 2026-09-27
Last updated: 2026-09-27
Changelog — September 27, 2026
A maintenance window: no new flagship models, plenty of controls. Claude Code gives admins exact model allow and deny lists and a way to audit old prompting patterns. Kilo Code's localhost previews now render real web pages. Hermes tags 0.21.5 without itemised notes, again. The most useful item for people running agents is small: Claude Code finally applies Bash permission rules with a mid-pattern :* the same way from every settings source.
2026-09-25
Claude Code
2.1.282 → 2.1.283 — model allow/deny lists, prompt audit
Admins can pin exactly which models run. 2.1.283 adds a deniedModels managed setting that blocks specific models even when availableModels allows them, and availableModelsMatch: "exact", so a newly released model stays blocked until it's listed. Organisations that approve models one at a time no longer get new ones by default. The same release adds /doctor prompt-audit, which checks your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models.
2.1.282 fixes a permission inconsistency worth knowing about. Bash rules with a mid-pattern :* were skipped when they came from settings files but honoured from --allowedTools; they now work from every source, with a startup warning explaining how they match. Managed permissions, autoMode, worktree and attribution blocks are no longer ignored wholesale when one nested value is invalid. Also new: a maxProseWidth setting for wide terminals, and a fix for sessions failing on every turn with a redacted_thinking error.
Releases →
Affects: /claude-cowork/faq/claude-code-undocumented-configuration/, /claude-cowork/faq/effort-levels/
2026-09-25
Anthropic
Claude apps · API — plugin submissions, refusal billing, cache diagnostics GA
Anyone can now submit plugins to the Claude directory (2026-09-25) through a new developer portal with review tracking and usage analytics. That's the same plugin format that syncs into Claude Code; see skills & plugins. On the API: billing resumes for refusals that arrive before any output in the bio, frontier_llm and reasoning_extraction categories (2026-09-24), and cache diagnostics is out of beta, with no beta header needed (2026-09-23).
API release notes →
Affects: /claude-cowork/, /claude-cowork/skills-guide/
2026-09-25
Kilo Code
v7.7.12 → v7.8.1 — a real browser in localhost previews
v7.8.0 streams a high-resolution browser into Agent Manager's localhost previews, so previews can load public HTTPS pages and CDN resources instead of breaking on them, with clear prompts when a browser isn't installed. It also adds Azure Entra ID sign-in by resource name or endpoint URL, a stop button for session cleanup, and reclaims disk space after cleanup. It adopts OpenCode v1.18.21–v1.18.26, including Cloudflare AI Gateway routing and Anthropic model-id fixes. v7.8.1 publishes CycloneDX software bills of materials. Note that v7.7.12 and v7.8.0 were tagged as pre-releases; v7.8.1 is the stable one.
Releases →
Affects: /kilocode/, /kilocode/setup/
2026-09-24
Hermes
v0.21.5 — 460 PRs, notes deferred to v0.22.0
A stable roll-up of ~460 merged PRs and 1,610 commits since v0.21.4, tagged so Docker images (nousresearch/hermes-agent:v2026.9.24) and Hermes Cloud pick it up. Curated notes are deferred to v0.22.0, which Nous says will document everything since v0.21.0. That's the fourth window in a row where the code ships ahead of the explanation. If you're on 0.21.0 or 0.21.1, update anyway: 0.21.2 fixed a state.db bug that could report healthy databases as corrupt (details). Our Hermes guides were rebuilt against 0.21.5 this week.
Releases →
Affects: /hermes/, /hermes/setup/, /hermes/troubleshooting/
2026-09-24
IronClaw
1.4.1-rc.2 — release candidate: Google OAuth activation fix
A second release candidate over 1.4.0 with one fix. Gmail and Google Calendar could complete sign-in and then fail activation, revoking the new credential, when the operator had entered the Google OAuth client in the web UI rather than in environment variables. Every retry re-consented and failed again. Readiness is now resolved per activation from the same credential chain the auth engine uses. 1.4.0 remains the current stable release.
Releases →
Affects: /ironclaw/, /ironclaw/setup/
TypeSafe's Jev Router is now on OpenRouter as typesafe/jev-router. It uses Jev to score each request and choose a model and reasoning effort, balancing quality, speed and cost. OpenRouter lists its price as variable, so check what it routes to before relying on it for cost control. OpenAI fixed an image-encoding bug in GPT-6 Sol and Luna that hurt visual tasks (2026-09-25). GPT-6 prices are unchanged: Astra $10/$50, Sol $2/$10, Luna $0.10/$0.50.
Cost calculator →
Affects: /jev/, /tools/cost-calculator/
Corrections made on this site this week
Re-checking our guides against each vendor's own documentation found many that described things that don't exist. We rebuilt them: Hermes (all 15 pages), NemoClaw (7), IronClaw (7), Kilo Code (6) and Claude Cowork (19, which had been written as though Cowork were a separate team-workspace product). We also fixed about 20 OpenClaw commands. Every platform page is now checked against its official sources before publishing (how this works). We also added a Meta Muse section.
Not counted as news
OpenClaw pushed a signed v2026.8.33 tag on 2026-09-26 with no release notes and no docs page; with nothing official to report, we're not guessing at its contents. NemoClaw has no new version since 0.0.129. Its commits this window are fixes: verifying the Telegram runtime credential, repairing Podman onboarding, DNS repair and keeping strict Landlock in v1 exports. Hermes also pushed daily +canary builds and rc tags, which we now filter out.
See all releases
Browse the full changelog index for the complete history across all platforms, or the daily one-liner for the most recent state of each agent.