Skip to content
CortexDocs
Defender · Releases and compatibility

Cortex Defender releases

Check the latest production version, endpoint operating systems, AI harness and provider compatibility, validation evidence, and historical release notes.

Review compatibility
  • Production version0.5.24 · September 4, 2026
  • Endpoint platformsManaged desktop and headless Linux
  • Version evidenceHarness and provider observations
Current release and supported platforms
Production0.5.24September 4, 2026
macOS12 or laterApple silicon
Windows10 or 11x64
LinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Release metadata comes from the current Defender release catalog. The compatibility table below distinguishes support from observed validation.

Release 0.5.24

Change log and improvements

What release 0.5.24 changes for an installed fleet, grouped by area. Each entry describes a customer-visible improvement in the current production release.

Performance

Lower endpoint overhead and faster activity visibility in Cortex Atlas.

  • Lower idle resource useThe local relay releases idle capture workers, which reduces background CPU and memory on managed desktops during long sessions.
  • Faster session indexingActivity indexing runs incrementally, so a long session becomes searchable in Cortex Atlas without waiting for the session to close.
  • Quicker time to first activitySign-in and harness discovery run together at startup, which shortens the gap between launch and the first captured event.

Security

Stricter update verification and a narrower local trust boundary.

  • Signed update verificationUpdater artifacts are checked against signed manifests before installation on macOS, Windows, and Linux.
  • Scoped local relay accessThe local relay accepts connections from the signed-in desktop session only, and rejects requests from other local accounts.
  • Wider secret redactionRedaction covers additional provider token formats and runs on the endpoint, before any event leaves the device.

Release 0.5.24

Current compatibility

Reviewed September 4, 2026

Match the endpoint platform to the AI harness and upstream provider. Version labels distinguish exact observations from supported paths without a public pin.

Compatibility process

Continuous harness validation

  • Every client releaseTested across the supported operating systems.
  • Multiple harness versionsIncludes the latest stable release of each AI harness.
  • Continuously refreshedAutomated updates to the harness test set and compatibility checks keep observations current. New observations are published on this page.

How to read validation

VerifiedExact version observed in product validation.
Version unpinnedSupported path with no public version pin.
Operating system and versionHarness and providerHarness versionCapture pathValidation
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Claude Code logoAnthropic logoClaude CodeAnthropic
2.1.201 observed2.1.83+ is required for work-context events.
Local relayVerified
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Codex CLI logoOpenAI logoCodex CLIOpenAI
0.142.4 observedExact client version recorded during validation.
Local relayVerified
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Gemini CLI logoGoogle logoGemini CLIGoogle
0.46.0 observedVersioned request fixtures cover the current CLI protocol.
Local relayVerified
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Grok CLI logoxAI logoGrok CLIxAI
0.2.105 observedCurrent response protocol is covered from 0.2.82.
Local relayVerified
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Cursor logoConfigured provider logoCursorConfigured provider
4.0.0 observedDesktop attribution is versioned; CLI remains current-stable.
CLI relay and IDE historyVerified
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
OpenCode logoConfigured provider logoOpenCodeConfigured provider
1.17.4 observedA scrubbed real-session fixture pins this version.
Local relayVerified
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
OpenClaw logoConfigured provider logoOpenClawConfigured provider
Current stableSupported path with no public version pin.
Headless local relayVersion unpinned
macOS logomacOS12 or laterApple silicon
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Pi logoConfigured provider logoPiConfigured provider
Current stableSupported path with no public version pin.
Partial local relayVersion unpinned
Claude Code logoAnthropic logoClaude CodeAnthropic
Verified
Operating system and version
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Harness version
2.1.201 observed2.1.83+ is required for work-context events.
Capture path
Local relay
Codex CLI logoOpenAI logoCodex CLIOpenAI
Verified
Operating system and version
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Harness version
0.142.4 observedExact client version recorded during validation.
Capture path
Local relay
Gemini CLI logoGoogle logoGemini CLIGoogle
Verified
Operating system and version
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Harness version
0.46.0 observedVersioned request fixtures cover the current CLI protocol.
Capture path
Local relay
Grok CLI logoxAI logoGrok CLIxAI
Verified
Operating system and version
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Harness version
0.2.105 observedCurrent response protocol is covered from 0.2.82.
Capture path
Local relay
Cursor logoConfigured provider logoCursorConfigured provider
Verified
Operating system and version
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Harness version
4.0.0 observedDesktop attribution is versioned; CLI remains current-stable.
Capture path
CLI relay and IDE history
OpenCode logoConfigured provider logoOpenCodeConfigured provider
Verified
Operating system and version
macOS logomacOS12 or laterApple silicon
Windows logoWindows10 or 11x64
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Harness version
1.17.4 observedA scrubbed real-session fixture pins this version.
Capture path
Local relay
OpenClaw logoConfigured provider logoOpenClawConfigured provider
Version unpinned
Operating system and version
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Harness version
Current stableSupported path with no public version pin.
Capture path
Headless local relay
Pi logoConfigured provider logoPiConfigured provider
Version unpinned
Operating system and version
macOS logomacOS12 or laterApple silicon
Linux logoLinuxDebian 13+, Fedora, or Amazon Linux 2023x64 or ARM64
Harness version
Current stableSupported path with no public version pin.
Capture path
Partial local relay

No published release blockers

Release 0.5.24 has no published customer blocker. Amber rows remain supported paths without an exact public version pin.

Outside published support

macOS before 12, Windows before 10, and Linux distributions not listed in the matrix are outside the published operating-system scope.

Historical archive

Previous releases

0.5.19macOS releaseWindows releaseLinux releaseProduction

Selected changes

  • Added a packaged headless Linux service and CLI configuration commands.
  • Improved first-party Claude Code routing defaults.
  • Prevented imported Cursor history from replaying after a new commit.
  • Corrected provider-mix calculations and Linux dependency validation.
0.5.16macOS releaseWindows releaseProduction

Selected changes

  • Improved Cursor CLI capture and repair behavior on Windows and Unix.
  • Recovered Claude Desktop Cowork prompts and paired logical turns.
  • Added opt-in native Grok image capture and Firefox and Arc attribution.
0.5.15macOS releaseWindows releaseProduction

Selected changes

  • Improved Cursor activity projection and capture-search performance.
  • Added Gemini runtime-event health reporting and repair behavior.
  • Improved managed configuration resilience during service outages.
0.5.9macOS releaseWindows releaseProduction

Selected changes

  • Published the earlier production baseline for managed desktop deployment.
  • Established signed cross-platform updater artifacts for macOS and Windows.

Support policy

Version and rollout practice

Check your version

Open Settings → About & Updates in Cortex Defender.

Follow compatibility updates

We test multiple harness versions on every client release, including current stable versions.

Report exact context

Include Defender, operating system, harness, and provider versions when requesting support.

Was this helpful?