Spark R29 is now live!
R29 consolidated accepted work across Spark CLI, Telegram Bot, Builder, Spawner, Researcher, Character, Voice, Personality, Memory, Domain Chips, and the installer surface from community PRs.
The biggest changes:
Spark CLI is safer.
R29 added stronger approval gates for risky commands, module-name sanitization, SQL allowlists, Unicode prompt-injection normalization, atomic SSH known_hosts writes, npm install-command restrictions, and better secret/path redaction.
Telegram is more reliable.
Accepted fixes improved group command parsing, API-key/stderr redaction, SQLite WAL shutdown, conversation memory races, temp-file cleanup, socket cleanup, preview URL SSRF checks, and slash-command handling.
Builder is harder to break or abuse.
R29 added provider SSRF validation, OAuth transaction safety, minimal child-process environments to avoid secret leakage, SDK module allowlists, JSON guards, and safer runtime path behavior.
Spawner got mission stability work.
R29 added lifecycle dedupe, retry tolerance, timeout settlement, reconnect jitter, scheduler in-flight dedupe, workspace containment, event cleanup, and constant-time comparison hardening.
Researcher got safer execution paths.
Accepted work covered path traversal prevention, SSRF/IP validation, stale lock recovery, subprocess timeouts, corrupt JSON guards, and public summary redaction.
Character, Voice, Personality, and Memory got durability and privacy fixes.
That includes .env exfil detection, voice SSRF protection, NaN/Inf rejection, atomic personality writes, path traversal guards, corrupt YAML warnings, log growth bounds, and safer profile loading.
The release also included smaller but important system fixes across Spark-Agent-Site, Domain Chip Labs, Domain Chip Memory, and Startup Bench.
R29’s theme: fewer leaks, fewer crashes, safer local authority, and a more reliable agent path from install → Telegram → Builder → mission → memory/persona/voice.
Spark Compete leaderboards are updated as well. Still there are more community PRs to ship in the next installers, so the current leaderboard is not final.
See you in the next updates!
Make sure to update your Spark agents 🫡