{
  "generated_at": "2026-09-16T19:08:00+00:00",
  "guides": [
    {
      "title": "How to review an automation change before it reaches production",
      "url": "https://automation.briefpulse.com/guides/review-an-automation-change"
    }
  ],
  "publication": "automation",
  "stories": [
    {
      "format": "brief",
      "headline": "A live app's exposed API key becomes a cost event while you sleep",
      "published_at": "2026-09-16T19:01:32+00:00",
      "standfirst": "A first-person account of shipping a vibe-coded app describes a common failure: someone finds exposed keys in a new app and spends them on an expensive model. The evidence here is the setup only — it stops before the avoidance guidance it promises.",
      "url": "https://automation.briefpulse.com/stories/automation-live-app-exposed-api-key"
    },
    {
      "format": "brief",
      "headline": "Shopify Customer Address APIs Add countryCode, Deprecate territoryCode",
      "published_at": "2026-09-16T09:23:10+00:00",
      "standfirst": "Shopify's Customer Account API version 2026-10 now supports countryCode for customer addresses, deprecating the existing territoryCode field while keeping it fully supported.",
      "url": "https://automation.briefpulse.com/stories/automation-shopify-customer-address-apis-add"
    },
    {
      "format": "brief",
      "headline": "Shopify Functions can now read metafields on delivery options",
      "published_at": "2026-09-16T09:22:45+00:00",
      "standfirst": "Shopify Functions can now read metafields attached to delivery options in the cart on API version 2026-10.",
      "url": "https://automation.briefpulse.com/stories/automation-shopify-functions-can-now-read"
    },
    {
      "format": "brief",
      "headline": "Payments Apps API now documents family_name as optional for B2B orders",
      "published_at": "2026-09-16T09:11:27+00:00",
      "standfirst": "Shopify's B2B checkout treats the buyer's surname as optional, so payment session requests for B2B orders can omit family_name in shipping_address and billing_address. The Payments Apps API request reference now documents this as optional to match existing behavior.",
      "url": "https://automation.briefpulse.com/stories/automation-payments-apps-api-now-documents"
    },
    {
      "format": "brief",
      "headline": "Shopify Catalog API adds media type filtering and returns video, 3D model assets",
      "published_at": "2026-09-16T09:09:10+00:00",
      "standfirst": "The Catalog API now returns video and 3D model media on products and supports filtering search results by media type. The new filter is optional and existing queries keep returning the same products.",
      "url": "https://automation.briefpulse.com/stories/automation-shopify-catalog-api-adds-media"
    },
    {
      "format": "brief",
      "headline": "GitLab Path Traversal Vulnerability Allows Unauthenticated File Reads",
      "published_at": "2026-09-16T04:08:05+00:00",
      "standfirst": "GitLab Community Edition and Enterprise Edition contain a path traversal vulnerability that allows an unauthenticated user to read arbitrary files, according to the National Vulnerability Database.",
      "url": "https://automation.briefpulse.com/stories/automation-gitlab-path-traversal-vulnerability-allows"
    },
    {
      "format": "brief",
      "headline": "Gemini 3.8 Live models expose speech-to-speech via WebSocket endpoint",
      "published_at": "2026-09-16T00:12:14+00:00",
      "standfirst": "Google released two new speech-to-speech models, Gemini 3.8 Live and 3.8 Live Extended Thinking, and a developer built a browser UI to try them. The useful integration detail is a WebSocket endpoint for bidirectional audio.",
      "url": "https://automation.briefpulse.com/stories/automation-gemini-live-models-expose-speech-to-speech"
    },
    {
      "format": "brief",
      "headline": "Amazon Bedrock prompt caching targets repeated context costs",
      "published_at": "2026-09-15T17:04:15+00:00",
      "standfirst": "A post describes prompt caching in Amazon Bedrock and says it can cut input token costs by up to 90% when the same context is repeatedly sent to foundation models.",
      "url": "https://automation.briefpulse.com/stories/automation-amazon-bedrock-prompt-caching-targets"
    },
    {
      "format": "brief",
      "headline": "Claude Code v2.1.267 adds a provider-wide effort cap and a fresh-prompt switch",
      "published_at": "2026-09-15T16:37:45+00:00",
      "standfirst": "A point release adds a maxEffortLevel setting that caps effort across providers, plus a flag to stop reusing a conversation's recorded system prompt. It also bundles a batch of reliability fixes.",
      "url": "https://automation.briefpulse.com/stories/automation-claude-code-267-adds-provider-wide"
    },
    {
      "format": "brief",
      "headline": "Claude Code v2.1.271 adds per-command allowed domains for sandboxed Bash, PowerShell, and Monitor",
      "published_at": "2026-09-15T16:37:01+00:00",
      "standfirst": "The release notes for Claude Code v2.1.271 include a change that lets each command in auto mode with sandboxing have its own allowed_domains, with other hosts refused. The notes are brief on configuration details.",
      "url": "https://automation.briefpulse.com/stories/automation-claude-code-271-adds-per-command"
    },
    {
      "format": "brief",
      "headline": "Home Assistant 2026.8 release adds new integrations and UI setup options",
      "published_at": "2026-09-14T05:57:51+00:00",
      "standfirst": "Home Assistant 2026.8 has been released, with a stated focus on making the platform more approachable. The release notes list integration changes and UI improvements, but the evidence provides only headings, not the specifics of how workflows change.",
      "url": "https://automation.briefpulse.com/stories/automation-home-assistant-2026-release-adds"
    },
    {
      "format": "brief",
      "headline": "Home Assistant 2026.7 makes purpose-specific triggers and conditions the default for automations",
      "published_at": "2026-09-14T05:47:10+00:00",
      "standfirst": "Home Assistant 2026.7 graduates purpose-specific triggers and conditions from Labs to the default for all users. Integrations can now teach the automation engine their own triggers and conditions.",
      "url": "https://automation.briefpulse.com/stories/automation-home-assistant-2026-makes-purpose-specific"
    },
    {
      "format": "brief",
      "headline": "Home Assistant 2026.9 modernizes Modbus with shared connections and UI device picker",
      "published_at": "2026-09-14T05:25:59+00:00",
      "standfirst": "Home Assistant 2026.9 introduces Modbus integrations that share a single connection and let users pick their device in the UI, removing the need to hand-write register maps in YAML.",
      "url": "https://automation.briefpulse.com/stories/automation-home-assistant-2026-modernizes-modbus"
    },
    {
      "format": "brief",
      "headline": "Harness choice shows no resolved average task advantage in paired agentic coding tests",
      "published_at": "2026-09-14T05:20:21+00:00",
      "standfirst": "A preprint reports paired same-model contrasts on a private contamination-controlled suite of 256 repository and post-cutoff contest tasks. It finds no resolved average harness advantage, with cost and completion caveats.",
      "url": "https://automation.briefpulse.com/stories/automation-harness-choice-shows-resolved-average"
    },
    {
      "format": "brief",
      "headline": "Occamy-1.0 aims at the low-cost knee of the co-work cost-performance curve",
      "published_at": "2026-09-14T05:19:15+00:00",
      "standfirst": "A 35B co-work model, trained from a post-trained Qwen3.6-35B-A3B checkpoint, is presented as cost-efficient for long-horizon agent workflows. The paper reports it as competitive with larger frontier systems on several tasks, and releases the weights plus a subset of training data.",
      "url": "https://automation.briefpulse.com/stories/automation-occamy-1-aims-low-cost-knee-co-work"
    },
    {
      "format": "article",
      "headline": "MCP Changes Integration from Fixed Endpoints to Dynamic Tool Discovery",
      "published_at": "2026-09-12T08:27:07+00:00",
      "standfirst": "n8n has published a guide comparing the Model Context Protocol (MCP) with traditional APIs, explaining when to use each and how to combine them in workflows.",
      "url": "https://automation.briefpulse.com/stories/automation-mcp-changes-integration-fixed-endpoints"
    },
    {
      "format": "brief",
      "headline": "Scheduler decouples turn readiness from release to cut agentic workflow tail latency",
      "published_at": "2026-09-12T07:48:45+00:00",
      "standfirst": "A tail-risk-aware turn release scheduler for agentic LLM workflows matches eager release under light load and cuts P95 workflow flow time under contention by up to 3.50×, according to an arXiv preprint.",
      "url": "https://automation.briefpulse.com/stories/automation-scheduler-decouples-turn-readiness-release"
    }
  ]
}
