integration_changed · 2026-09-14

UFO Fixed security issues.: What's Changed Pin GitHub Actions to full-length commit SHAs by Dan Fiedler (@danfiedler-msft) in #343 fix MSRC1

The official Fixed security issues. release documents a concrete integrations change. This update explains what changed from v3.0.8, who should reassess the product, and what to verify next.

What changed
The official Fixed security issues. release documents a concrete integrations change. This update explains what changed from v3.0.8, who should reassess the product, and what to verify next.
Who is affected
Evaluators, administrators, and workflow owners using UFO where integrations requirements affect adoption or deployment.
What to do now
Review the official Fixed security issues. notes, test the affected integrations workflow, and update the adoption decision if the result changes product fit.
What changed

The material change

Previously: {{agentName}} v3.0.8 documents this product change: What's Changed Security fix: Implement per-command argument policies for enhanced co… by rhmsd (@rhmsd) in #334 fix: [MSRC] [123355] - UFO system - ufo/client/mcp/http_servers/linux… by rhmsd (@rhmsd) in #336 fix: [MSRC]

Now: UFO Fixed security issues. documents this product change: What's Changed Pin GitHub Actions to full-length commit SHAs by Dan Fiedler (@danfiedler-msft) in #343 fix MSRC139482: UFO - ufo/client/mcp/http_servers/linux_mcp_server.py… by rhmsd (@rhmsd) in #349 fix MSRC138616: UFO

This update covers the Fixed security issues. release notes and does not infer behavior beyond the official release description.

Why it matters

What users should reconsider

The move from v3.0.8 to Fixed security issues. introduces a documented change that may alter operational compatibility.

The release has a versioned first-party source, so teams can verify the exact scope instead of relying on a generic monitoring excerpt.

Practical next step

Verify the affected workflow

  1. Review the official Fixed security issues. notes, test the affected integrations workflow, and update the adoption decision if the result changes product fit.
  2. Open the official source and verify the current product state.
  3. Review the current Agent Profile and affected Decision before acting.

Source-Backed does not mean execution-verified and does not establish comparative rank.

Previous state

What was recorded before

{{agentName}} v3.0.8 documents this product change: What's Changed Security fix: Implement per-command argument policies for enhanced co… by rhmsd (@rhmsd) in #334 fix: [MSRC] [123355] - UFO system - ufo/client/mcp/http_servers/linux… by rhmsd (@rhmsd) in #336 fix: [MSRC]

Current Agent state

What is known now

UFO Fixed security issues. documents this product change: What's Changed Pin GitHub Actions to full-length commit SHAs by Dan Fiedler (@danfiedler-msft) in #343 fix MSRC139482: UFO - ufo/client/mcp/http_servers/linux_mcp_server.py… by rhmsd (@rhmsd) in #349 fix MSRC138616: UFO This update covers the Fixed security issues. release notes and does not infer behavior beyond the official release description.

Accepted Change accepted:89fef6f427b4513f8907a7f663adf515 · Agent Fact fact:89fef6f427b4513f8907a7f663adf515 · Last verified 2026-09-14
Official evidence

UFO official releases

Published by Microsoft. Evidence state remains Source-Backed; this is not execution verification.

Open official source →