OctoLink GEO

OpenHands SDK 1.49.5 Isolates Each Coding Conversation in Its Own Runtime

Author Editor

The 23 September 2026 OpenHands SDK adds per-conversation Docker runtimes, secret profiles, and safer ACP isolation.

Harness Engineering OpenHands ACP Docker

Direct answer

OpenHands Software Agent SDK v1.49.5, published 23 September 2026, gives each conversation its own Docker runtime and tightens how ACP isolation and MCP plugins are loaded.

OpenHands shipped Software Agent SDK v1.49.5 on 23 September 2026. A status check dated the next day treats that build as the stable line, and the interesting part is not a new model. It is the harness around the conversation.

From v1.46 through v1.49.5 the SDK adds conversation-scoped Docker runtimes, profile-scoped secrets, Agent Plugins that load MCP with path containment, and an AgentSandboxWorkspace. v1.49.0 makes the Docker runtime optional per conversation and drops a deprecated desktop URL endpoint. A self-hosted agent server can isolate one job without changing the public conversation API.

What v1.49.5 specifically tightens

The 1.49.5 notes cover idle Docker runtime eviction, forwarding of an ACP data-directory flag, persisted MCP wire compatibility, and tolerance for an orphaned observation. Long-running fleets drop stale runtimes, and a conversation started on an older build is safer to resume. v1.49.2 had already treated package paths and plugin-supplied MCP config as a trust boundary. v1.49.4 made local secret lookup resolve in process and fixed ACP profile reset.

ACP isolation only counts if the client actually forwards it. The same write-up says v1.49.5 fixes the TypeScript client allow-list so acp_isolate_data_dir reaches the server instead of being dropped. Teams that rely on a separate data directory should check the client path they deploy, not only the server changelog.

For harness work, this release is a boundary release: one conversation, one runtime, secrets and plugins scoped to that runtime.

Source: AI Stack Current, 24 September 2026.

FAQ

What shipped in the 1.49 line?
Per-conversation Docker runtimes, profile-scoped secrets, Agent Plugins MCP loading with path containment, and idle runtime eviction in v1.49.5.
Why does the runtime boundary matter?
A self-hosted agent server can isolate one conversation without changing the public conversation API, and MCP filesystem references become an explicit trust boundary.