137 wires and counting

$ follow OpenAI

Keep up with OpenAI in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-08-12
stories 196

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

PYTHON SDK GOES HTTPX2, NODE PATCHES PROTOTYPE POLLUTION, CODEX HARDENS STREAMING

By RepoJournal · Filed · About OpenAI · Composed from the cited sources · methodology

OpenAI Python SDK v3.0.0 ships HTTPX2 as the default HTTP client, breaking the old httpx dependency entirely while Node.js closes a critical prototype-pollution vulnerability in assistant streams.

The Python SDK's major version bump [1] marks the end of httpx era, forcing all custom client implementations to migrate to HTTPX2 equivalents or use a temporary legacy escape hatch. This change consolidates infrastructure and simplifies dependency management, though it demands immediate attention from anyone using custom transports or configuration objects. On the security front, the Node.js SDK [2] patched a CodeQL-flagged prototype-pollution vulnerability in AssistantStream delta merging, rejecting unsafe property-chain names before they can be exploited. The Node team also resolved 45 Dependabot alerts across undici, js-yaml, postcss, and other dependencies [5], then capped future noise by limiting Dependabot to 10 concurrent pull requests [6]. Meanwhile, Codex hardened its TUI streaming by persisting per-chunk traces at DEBUG level instead of TRACE [3], preventing SQLite log queue floods, while adding turn-aware response injection [4] to keep user input and injected items atomically persisted together. The team also routed gRPC code-mode sessions through the shared HTTP client [7] for better proxy and CA configuration support, and built metadata preservation across conversation history [8] without exposing harness details to model providers.

Action items

References

  1. [1] v3.0.0 ↗ openai/openai-python
  2. [2] fix: prevent prototype pollution in assistant stream deltas (#2280) openai/openai-node ↗
  3. [3] Limit TUI streaming traces in SQLite logs (#38036) openai/codex ↗
  4. [4] Add turn-aware response item injection (#38047) openai/codex ↗
  5. [5] fix(deps): remediate Dependabot and fixture vulnerabilities (#2282) ↗ openai/openai-node
  6. [6] chore: limit Dependabot to 10 open pull requests (#2297) ↗ openai/openai-node
  7. [7] Route gRPC code-mode sessions through the shared HTTP client (#38087) openai/codex ↗
  8. [8] Preserve harness metadata across conversation history ↗ openai/codex
  9. [9] feat(api)!: migrate to HTTPX2 ↗ openai/openai-python

Quick answers

What shipped in OpenAI on August 12, 2026?
OpenAI Python SDK v3.0.0 ships HTTPX2 as the default HTTP client, breaking the old httpx dependency entirely while Node.js closes a critical prototype-pollution vulnerability in assistant streams. In total, 87 commits, 104 pull requests, and 5 releases landed.
Who contributed to OpenAI on August 12, 2026?
10 developers shipped this update, including Bryan Ashley, Channing Conger, mchen-oai, Tamir Duberstein, copyberry, Hayden, dependabot, and camdencheek, and 2 more.
What were the notable OpenAI updates?
v3.0.0, fix: prevent prototype pollution in assistant stream deltas (#2280), and Limit TUI streaming traces in SQLite logs (#38036).