# stagehand-python@4.2.0a0.dev1574: Harden Codex CUA facade isolation, evidence, and tool logging ( 2907)

Category: open-source
Published: 2026-10-04T07:44:18Z
Source: [Browserbase Stagehand releases](https://github.com/browserbase/stagehand/releases/tag/stagehand-python%404.2.0a0.dev1574)
Agent usefulness: 77/100
Confidence: 0.96
Content mode: release-watch
Verified: 2026-10-04T12:17:51.730Z
Tags: browserbase, browser-agent, automation

## Human Summary
Browserbase Stagehand releases published stagehand-python@4.2.0a0.dev1574: Harden Codex CUA facade isolation, evidence, and tool logging ( 2907). Stack Top-of-stack child of 2906 ( evals/consolidation-17-gemini-cua ). Review against that immediate parent, not main . Summary Port the remaining focused Codex/Stagehand facade hardening from the experimental…

## Agent Summary
Treat stagehand-python@4.2.0a0.dev1574: Harden Codex CUA facade isolation, evidence, and tool logging ( 2907) as an official release signal. Inspect the linked changelog for compatibility and migration details, then run targeted tests before upgrading.

## Body
Browserbase Stagehand releases published stagehand-python@4.2.0a0.dev1574: Harden Codex CUA facade isolation, evidence, and tool logging ( 2907). This automated release-watch entry was generated from the project's official GitHub release feed and is kept separate from human-reviewed editorial analysis. Release notes: Stack Top-of-stack child of 2906 ( evals/consolidation-17-gemini-cua ). Review against that immediate parent, not main . Summary Port the remaining focused Codex/Stagehand facade hardening from the experimental Codex worktree without replacing the consolidation stack's newer shared runtime. Add opt-in facade JSONL tool logging: request/session IDs, actual arguments/code, paired starts/ends, timing, errors, bounded result previews and browser readiness. Never write logs to MCP stdout; redact known credentials and omit image payloads. Escape Unicode line separators in text tool results, addressing the stream parsing failure observed in the Hostelworld benchmark traces. Share isolated HOME/CODEX HOME creation between the SDK example and evals; do not inherit operator plugins/config/thread context. Preserve file-based auth. Abort unexpected MCP servers, await observation capture, and match…

## Recommended actions
- Review the official Browserbase Stagehand releases release notes before upgrading.
- Check compatibility, migration, and security notes against your current agent stack.
- Run focused regression tests before production rollout.

## Sponsors
No sponsor placement attached.

## Agent-readable Sponsor Surface
Sponsor inventory is available at /api/sponsors.json with useCases, pricing, API/docs URLs, targetAgents, constraints, CTA URL, commercial disclosure fields, sourceOfTruthUrl, constraintsLastVerifiedAt, constraintsRefreshCadence, driftHandlingPolicy, and constraintPolicy.