Changelog
Every new feature, improvement, and fix in Sim, the open-source AI workspace, with release notes straight from GitHub.
Features
- feat(library): GitHub MCP Server for AI Agents: Builders, Security, and Setup
- feat(library): Best Slack MCP Agent Builders: 7 Options Compared
- feat(library): How to Use the GitHub MCP Server With AI Agents: Builders, Security, and Setup
Bug Fixes
- fix(db): compare tables by schema-qualified name in the migration audit
- fix(deps): patch sharp librsvg CVE and MCP SDK OAuth issuer binding
- fix(db): refuse migrations whose ownership statements only pass outside production
- fix(build): keep zod's default error messages in production builds
Other Changes
- docs(library): update govern-ai-agents-multiple-teams-enterprise-workspace
- docs(library): update best-conversational-ai-platforms-crm-helpdesk
- docs(library): update what-is-human-in-the-loop-in-ai-agents
- ci: bump the actions group across 4 directories with 19 updates
- docs(library): update open-source-ai-agent-platforms
Features
- feat(buffer): complete stable API tool coverage
- feat(api): expose credential sharing and SSO administration
- feat(models): add current frontier models
- feat(integrations): add Ramp and Microsoft Intune
- feat(permission-groups): add agent default
- feat(providers): add Nebius Token Factory
- feat(desktop): import local files from the background executor
- feat(desktop): keep the machine awake for background chats and yield the page to the user
- feat(desktop): show background desktop chats and keep the chat view display-only for them
- feat(desktop): run a chat's desktop tools in the background executor
- feat(mothership): let the worker choose models when the model picker is off
- feat(desktop): bind turns to a desktop and enforce its deadlines from the row
- feat(sso): allow self-hosted DNS verification bypass
- feat(plane): add core integration with self-hosted support
- feat(library): 25 Multi-Step AI Agent Examples Beyond Chatbots
- feat(desktop): device registry, inbox and leased claims for a background executor
- feat(library): Best Conversational AI Platforms With CRM and Helpdesk Integrations
- feat(library): Best AI Coding Agents for Refactoring and Debugging: 5 Tools Compared
- feat(mothership): keep each chat's reasoning effort, default to medium, restore Low
- feat(projects): add project identity and lifecycle foundation
- feat(workflows): stop a manual v2 run after a block, and
workflows run --stop-after - feat(library): How do you build an AI bot for Discord without code?
Improvements
- improvement(desktop): ship the background executor without a flag, close its QA gaps
- improvement(files): add sharing to file resource view
- perf(pii): batch spaCy NER passes in redact_batch
- improvement(ci): check out same-repo pull requests through a git mirror
- improvement(mothership): relabel the Sol pick GPT-6.1 Sol and retire the none effort
- refactor(mothership): a saved Stop handoff's id wins on restore
- refactor(mothership): keep a queued send's reused id in one field
- refactor(mothership): one hold field and one retry field on a queued send
- improvement(desktop): Electron E2E for desktop tool lifetimes against a live local Sim
- refactor(mothership): one re-queue policy and one send payload, and keep a Stop-failed send waiting for the user
- refactor(desktop): one forward-only state per recorded tmux run, and one check for a delivered result
- improvement(outbox): load handler modules only for the event types a run will process
- improvement(cron): only start outbox and file-search passes when work is due, via a shared scheduled-pass helper
- improvement(triggers): move TRIGGER_TYPES to a dependency-free module
- perf(cli): load a manual run's draft once and keep embedded CLI results lean
- improvement(trigger): downsize connector sync and document processing machines
- improvement(tables): read row counts and versions through an append-only change log
- perf(sandbox): grant the run_code session lease in the reconnect instead of extra E2B round trips
Bug Fixes
- fix(code-placeholders): reject arithmetic comparisons and heredoc operands
- fix(desktop): poll desktop activity only for users with a desktop, keep XDG zsh configs integrated
- fix(audit): harden data drains and expand security event coverage
- fix(executor): preserve stop-after across pause and resume
- fix(billing): converge Stripe subscription syncs and stop webhook echoes overwriting unsynced changes
- fix(docs): publish full LLM text as a static asset
- fix(docs): prerender complete LLM documentation
- fix(tables): stop the fold sweep from starting a page query past its budget
- fix(mothership): cancel desktop tools a signed-out turn starts late, guard the shown-once license key
- fix(sandbox): keep reused E2B workbench leases within the runtime cap
- fix(settings): protect generated keys and identity transitions
- fix(mothership): use a spinner while workflow resources load
- fix(mothership): close a pre-aborted SSE stream, keep the new-chat effort across a failed first send
- fix(desktop): stop a run the model never got the result of
- fix(outbox): log unloaded handler modules as a failure, not a completed run
- fix(desktop): linear path trim, prompt Stop between keystrokes, clear a closed session's input marker
- fix(ci): count both sides of a rename in the desktop live gate, keep canary reports
- fix(desktop): keep a chat-view import alive while it works, by the lease its session renews
- fix(mothership): a pure resend verdict, and Send-now drops a message the server already has
- fix(mothership): send a late queue write to the chat a new-chat queue moved to
- fix(desktop): leave a stopped native file tool's outcome to Stop
- fix(mothership): keep a failed direct send ahead of follow-ups queued during its POST
- fix(mothership): decide once whether a queued send may already be on the server
- fix(desktop): frame each tmux format record so a newline in a field cannot forge a pane
- fix(desktop): stop the agent's tmux runs a previous process left going
- fix(mothership): retry a send that failed while the browser stayed online
- fix(mothership): claim under the chat lock in the Stop-versus-recovery settlement test
- fix(ci): tidy stop-session.sh scans, listings and arguments
- fix(settings): prevent false unsaved prompts and preserve drafts
- fix(mothership): keep any queued send the server may already hold from being edited
- fix(desktop): run an agent command on tmux that cannot tag its pane, untracked
- fix(ci): match E2E app tags literally, make them unique per run, and never stop the caller
- fix(mothership): keep a withdrawn first message held at the queue head as written
- fix(events): authorize the events queued before a stream opens once
- fix(desktop): read tmux format output with a separator no tmux version escapes
- fix(mothership): run same-workflow workflow tools in order instead of failing as busy
- fix(webhooks): skip duplicate webhook deliveries already in progress instead of polling
- fix(ci): stop the detached telemetry flush too, re-signal stragglers on a monotonic clock, and report HTTP E2E failures by route
- fix(mothership): keep a chatless surface's queue across remounts and contain hung chat hook tests
- fix(events): start every SSE response once its subscriptions are live
- fix(chat): resolve a new chat's history entry to the chat route on Back, and say when an effort save fails
- fix(analytics): protect production Google measurement
- fix(mothership): close the remaining ways a chat send is lost, resent hot, or polled after unmount
- fix(e2e): compile every timed route first in the HTTP suites and stop sessions completely
- fix(mothership): prune composer contexts during render so fast typing cannot trip the update-depth limit
- fix(plane): validate webhook fields by registration mode
- fix(ci): stop each HTTP end-to-end app fully and start the next from an empty dev cache
- fix(plane): correct tile styling and capped connector syncs
- fix(mothership): keep a message the server never admitted instead of dropping it
- fix(mothership): re-attach at once when the user returns to a recovered stream
- fix(mothership): re-read the transcript until the server has saved a finished turn
- fix(desktop): inbox persistence order, desktop-only overdue sweep, and ungated pickup windows
- fix(mothership): end desktop tools at sign-out and settle held reports as final
- fix(copilot): store tool file outputs from workspace chats under the Copilot user
- fix(mothership): keep local file tools running when the chat view changes
- fix(mothership): keep a new chat's effort pick changed while its first send is pending
- fix(sandbox): judge session lease coverage from the request's own clock reading
- fix(mothership): fail unclaimed desktop calls fast and stop dropping them silently
- fix(mothership): default chat effort back to high
- fix(projects): revoke banned users' keys first and create imported workflows atomically
- fix(executor): unwrap boxed primitives by internal slot when checking JSON serializability
- fix(mcp): treat different URL credentials as a new destination
- fix(mothership): roll back a failed effort save by pick, not by value
- fix(mothership): refuse desktop claims for unapproved or stopped calls
- fix(seo): make content pagination indexable
- fix(projects): restore workspace deletion and tighten Project lifecycle
- fix(executor): fail a stop-after run whose routing skips the stop block
- fix(credentials): keep the field-less GitHub App installation out of v2 provider discovery
- fix(code-placeholders): reject shell arithmetic placeholders
- fix(mcp): restrict MCP server destination changes to admins
- fix(logs): keep a block log's file size from changing after the block completes
- fix(executor): drop the full JSON clone of execution state at run completion
- fix(chat): label simple effort options with the effort they send
Other Changes
- ci: duration-balanced integration shards, warm desktop-live, CI on every PR
- ci: faster, cheaper, consistently named CI
- test(desktop): pin the journal snapshot before recovery, keep start going when the journal cannot load, and run tmux in the canary E2E
- test(desktop): stop the agent's terminal commands in the real app, with real shells and real tmux
- test(mothership): stop the online case of the accepted-resend test passing without its history check
- chore(nextjs): upgrade to 16.4.0
- chore(trigger): fix queues that never serialized and schedule missing self-hosted crons
- chore(table): remove unused table-update background task
- docs(library): update 6-best-ai-observability-tools-for-production-agents-in-2026
- test(desktop): keep the SQL and TypeScript desktop-call classifiers in agreement
- docs(library): update best-ai-agents-for-lead-enrichment-2026
- docs(library): update sim-vs-dedicated-chatbot-builders
- docs(library): update top-ai-assistants-2026
- docs(library): update ai-agent-examples-by-department-and-industry
- docs(library): update open-source-ai-agent-platforms
- docs(library): update best-multi-agent-frameworks-2026
- test(mcp): exercise the real destination check in lifecycle tests
- docs(workflows): describe what still runs when a stop-after target is ruled out
- docs(library): update sim-open-source-zapier-alternative
- docs(library): update ai-agents-in-procurement
- docs(library): update mcp-security
- docs(library): update aeo-vs-geo-what-answer-engine-and-generative-engine-optimization-actually-mean
- docs(library): update ai-agent-observability
- docs(library): update best-ai-agents-for-customer-support-automation
- docs(library): update dify-alternatives
- docs(library): update langgraph-alternatives
- chore(terms): update terms of service
- docs(library): update agentic-ai-coding-tools-what-they-are-and-how-the-top-options-compare
helm-chart-1.11.7
A Helm chart for Sim - the open-source AI workspace where teams build, deploy, and manage AI agents
Bug Fixes
- fix(mothership): preserve workflow identity in background confirmations
- fix(files): retain known lineage through binary exports and extraction
- fix(code-placeholders): make python bare-placeholder classification and tagged-template edits linear
- fix(execution): make code placeholder and reference scans linear
Features
- feat(library): Slack AI Agent Security: Permissions, Data, and Audit Guide
- feat(library): Best HubSpot Alternatives for AI Marketing Automation in 2026
- feat(library): How do you build an AI voice agent with Twilio and Sim?
Improvements
- improvement(knip): check entry exports of private packages and delete their dead barrels
- improvement(tools): stop exporting tool types used only in their own file
- improvement(tools): delete unreferenced tool response types and the dead generic resource data path
- improvement(guidance): make every ratchet shrink-only, scope rules to their files, fix stale guidance
Bug Fixes
- fix(tools): reject dot path segments in tool request URLs
- fix(webhooks): check existing path owners before claiming on deploy
- fix(code-placeholders): skip heredoc bodies when scanning shell quote context
- fix(tools): check usage limits before running hosted-key tools via the API
- fix(docs): cap search query length and time out the embedding call
Features
- feat(forks): compare last synced source deployments
- feat(youcom): add You.com integration
- feat(search): browse Lucid folders and Notion pages
- feat(library): How to Use a Postgres MCP Server With AI Agents: Security, Deployment, and Evaluation
- feat(powerbi): add Power BI actions
Bug Fixes
- fix(docs): document You.com tools and expand shared output spreads
- fix(credentials): make Claude Platform API keys available in the provider catalog
- fix(audits): apply browser-runtime rules to @sim/utils; align settings checklist with the standalone description rule
- fix(files): read offset 0 as the first line instead of rejecting it
- fix(landing): return 404 for unknown library, blog, integration, model, and author slugs
- fix(mothership): make chat fork complete, consistent and safe to retry
- fix(sdk): default both SDKs to the www.sim.ai host
- fix(integrations): list tools for integrations without an operation dropdown
- fix(knowledge): scope list counts to selected knowledge bases
- fix(audits): close guardrail detector gaps and correct guidance from release review
- fix(powerbi): clear the explicit-any and unused-export ratchets on staging
- fix(mothership): leave desktop tool calls to the desktop app in other clients
Other Changes
- chore(pi): upgrade agent to 1.0.0
- docs(library): update ai-agent-examples-by-department-and-industry
typescript-sdk-v0.2.1
python-sdk-v0.2.1
v0.9.11
Improvements
- improvement(audits): enforce console, helper, render-path, persist, and deployment-flag rules
Bug Fixes
- fix(deps): bump mammoth to 1.12.3
- fix(logging): name the driver cause and redact bound params in logged errors
- fix(files): resolve chat uploads whose names are not in VFS form
- fix(search): reuse managed MCP sessions within operations
Other Changes
- docs(agents): accurate guidance, guardrail map, and check:guidance-refs
Features
- feat(workflows): compare deployment versions across UI and API
- feat(files): render diff fences and theme mermaid diagrams
- feat(dashboards): embed live dashboard panels in markdown
- feat(chat): cycle available composer modes with Shift+Tab
Improvements
- improvement(audits): ratchet unused exports, explicit any, and file names
- improvement(lint): strip comment noise and add check:comment-hygiene
- improvement(cron): run stale execution and file version cleanup off the request path
Bug Fixes
- fix(db): pin the primary-key plan in the search retirement read-bound test
- fix(cli): report authentication accurately and preserve file text
- fix(files): align workbench reads with provenance policy
- fix(accounts): report managed OAuth failures accurately
- fix(slack): honor implicit Search approval during authorization
- fix(mothership): bound stream recovery with a per-run restart budget
- fix(slack): verify Search permissions before changing active grants
- fix(search): correct onboarding and live citations
- fix(dashboards): keep DST fall-back range endpoints and resolve threshold axis from first series
- fix(ci): isolate HTTP end-to-end suites and stop the SCIM readiness flake
- fix(library): ignore sentence punctuation after bare internal URLs in check:library-content
- fix(mothership): stop duplicating chat resource tabs in workspace chats
- fix(sandbox): preserve workbench availability for unrecorded API responses
- fix(chat): preserve per-chat resource panel widths
- fix(wiza): surface Wiza's nested error messages
- fix(accounts): scope organization OAuth outbound requests
- fix(library): scope Sim license claims to the Apache 2.0 core and the Sim Enterprise License
- fix(seo): escape backslashes in llms-full.txt comparison table cells
Other Changes
- chore(lint): delete unused variables and parameters; enforce both rules repo-wide
- chore(cleanup): apply codebase-design deep-module pass across the monorepo
- chore(search): add paced projection replacement and data retirement
- chore(search): remove legacy indexed enterprise search
- chore(content): add check:library-content audit for content posts
- docs(library): restore content dropped by automated refreshes

