# Buzz Desktop v0.5.17: authorization fix, CPU burn fix, h2 security bump

> Buzz Desktop ships a small batch of fixes: remote agent mention authorization is now bounded, a CPU burn issue in mounted views is eliminated, presence retry timers are properly bound, and the h2 dependency is bumped for RUSTSEC-2026-0258.

| | |
|---|---|
| **Tool** | Buzz |
| **Version** | desktop-v0.5.17 |
| **Kind** | release |
| **Published** | 2026-08-18 |
| **Observed** | 2026-08-22 |
| **Significance** | 2/5 |
| **Breaking** | no |
| **Categories** | fix, security |

## What changed


- **Authorization**: remote agent mention authorization now properly bounded
- **Presence**: retry timers bound correctly
- **Performance**: mounted-view CPU burn eliminated — compositor-safe shimmer, observer append fast path, poll-tick disk reads
- **CI**: file-size policy made a first-class gate
- **Security**: h2 dependency bumped for RUSTSEC-2026-0258


## Sources

- [github_release](https://github.com/block/buzz/releases/tag/desktop-v0.5.17) — retrieved 2026-08-22


## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/buzz/desktop-v0-5-17
Entity: https://changelogs.info/buzz
Event ID: `evt_2026-08-18_buzz_desktop-v0-5-17`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
