Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
595bd10
fix(release): restore reviewed Chinese guides and preserve Windows br…
Oct 7, 2026
d796509
fix(weixin): retain retired account receipts and enforce chat thread …
Oct 7, 2026
e09cf47
docs(weixin): explain explicit account retirement and thread ownership
Oct 7, 2026
a0191fe
fix(release): audit every npm lock and ship the 19-plugin first-party…
Oct 7, 2026
00b84da
fix(engine): never block local turns on an unavailable Codewhale acco…
Oct 7, 2026
8fb9e13
fix(account): keep a DeepSeek or keyed local route when signing in
Oct 7, 2026
b2ab4a5
fix(tui): keep the account-profile fallback notice in the transcript
Oct 7, 2026
abd2190
docs(changelog): record the Weixin, Windows bridge and Chinese guide …
Oct 7, 2026
b50ba33
fix(weixin,runtime): address PR #6880 review findings
Oct 7, 2026
4a3001d
fix(release): close OAuth logging and bound retired account receipts
Oct 7, 2026
a8e3d03
docs(account): lead sign-in with central provider key management
Oct 7, 2026
a12bce9
fix(weixin): preserve unbound account context until explicit replacement
Oct 7, 2026
5950450
fix(release): keep resume path checks async and account docs translated
Oct 7, 2026
a270db7
feat(avatars): compose reviewed Native packs into GPUI and TUI catalogs
Oct 7, 2026
1156ef8
style(avatars): keep shared pack helpers and tests lint clean
Oct 7, 2026
06dbce9
style(release): format avatar routes and vendored module declarations
Oct 7, 2026
a88b3ab
fix(release): qualify portable avatar package and polling CI
Oct 7, 2026
de77d9f
fix(release): sync qualified Windows observation and portable avatar …
Oct 7, 2026
642d7f3
ci(windows): qualify actual Terminal clipboard input before release
Oct 7, 2026
8e46dad
docs(plugins): describe reviewed DSH compositions and portable limits
Oct 7, 2026
5261328
fix(release): run DSH preview off the live TUI runtime and repair thr…
Oct 7, 2026
d623b21
fix(release): keep emoji in Windows Terminal pastes and make reviewed…
Oct 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .config/nextest.toml
Original file line number Diff line number Diff line change
Expand Up @@ -79,7 +79,7 @@ test-group = 'fleet-manager-lifecycle'
[[profile.default.overrides]]
# DSH preparation also launches the isolated host against the shared hermetic
# home. Keep its ACL grants/retirement in this existing serial lane.
filter = 'package(codewhale-tui) & kind(lib) & (test(/^extension_host::/) | test(/^core::engine::.*extension/) | test(/^plugins::install::dsh::/) | test(/^plugins::tests::dsh_/) | test(/^runtime_api::tests::dsh_package_preview_then_exact_install_over_http$/) | test(/^commands::groups::plugins::tests::dsh_import_reviews_without_installing_then_installs_the_exact_bundle$/))'
filter = 'package(codewhale-tui) & kind(lib) & (test(/^extension_host::/) | test(/^core::engine::.*extension/) | test(/^plugins::install::dsh::/) | test(/^plugins::tests::dsh_/) | test(/^runtime_api::tests::dsh_package_preview_then_exact_install_over_http$/) | test(/^commands::contract::tests::plugin_adapter_dsh_preview_runs_from_live_runtime$/) | test(/^commands::groups::plugins::tests::dsh_import_reviews_without_installing_then_installs_the_exact_bundle$/))'
test-group = 'extension-host'

[[profile.default.overrides]]
Expand Down
24 changes: 21 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -429,6 +429,11 @@ jobs:
# `tsc` ever running in CI. `npm test` compiles first (tsc -p ./), so
# this is the type-check gate for the extension too.
run: npm test
# @vscode/vsce 4 is a build-only packager that requires Node >=22. The
# extension itself still compiles and tests on Node 20 above.
- uses: actions/setup-node@v7
with:
node-version: 22
- name: Package VS Code extension
run: npm run package

Expand Down Expand Up @@ -994,6 +999,19 @@ jobs:
run: cargo build -p codewhale-cli --bin codewhale --all-features --locked
env:
RUSTC_WRAPPER: ${{ matrix.os != 'windows-latest' && env.RUSTC_WRAPPER || '' }}
- name: Windows Terminal clipboard acceptance
if: needs.changes.outputs.heavy == 'true' && matrix.os == 'windows-latest'
timeout-minutes: 5
shell: pwsh
run: node scripts/release/windows-terminal-clipboard.mjs target/debug/codewhale.exe "${{ runner.temp }}/windows-clipboard"
- name: Retain Windows Terminal clipboard evidence
if: ${{ !cancelled() && matrix.os == 'windows-latest' && needs.changes.outputs.heavy == 'true' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: windows-clipboard-${{ github.sha }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/windows-clipboard/
if-no-files-found: error
retention-days: 7
- name: Run tests
# Same test binaries as `cargo test`, run by cargo-nextest: one
# process per test, all runner cores busy, slow tests named instead
Expand Down Expand Up @@ -1281,9 +1299,9 @@ jobs:
# leg was a ~28-minute hosted-Mac build on every main push while hosted
# macOS is capped at 5 concurrent jobs; it stays in the manual
# workflow_dispatch (full CI) matrix and in the release pipeline.
# A cold Windows build can take 29 minutes before the smoke even starts.
# Leave room for installation; bound the smoke itself independently below.
timeout-minutes: 45
# A cold Windows compile can take 42 minutes; leave room for cache save
# after the separately bounded five-minute install/entrypoint smoke test.
timeout-minutes: 60
runs-on: ${{ needs.changes.outputs.heavy == 'true' && matrix.os || 'ubuntu-latest' }}
strategy:
matrix:
Expand Down
13 changes: 13 additions & 0 deletions .github/workflows/release-artifacts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -270,6 +270,19 @@ jobs:
bin_dir="target/${{ matrix.target }}/dist"
"${bin_dir}/${{ matrix.cli_binary }}" --version
"${bin_dir}/${{ matrix.shim_binary }}" --version
- name: Windows Terminal clipboard acceptance
if: matrix.platform == 'windows-x64'
timeout-minutes: 5
shell: pwsh
run: node scripts/release/windows-terminal-clipboard.mjs "target/${{ matrix.target }}/dist/codewhale.exe" "${{ runner.temp }}/windows-clipboard"
- name: Retain Windows Terminal clipboard evidence
if: ${{ !cancelled() && matrix.platform == 'windows-x64' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: release-windows-clipboard-${{ github.sha }}
path: ${{ runner.temp }}/windows-clipboard/
if-no-files-found: error
retention-days: ${{ inputs.retention_days }}
- name: Stage binaries
shell: bash
run: |
Expand Down
67 changes: 67 additions & 0 deletions .github/workflows/security-audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,11 @@ on:
- '**/Cargo.toml'
- '**/Cargo.lock'
- '**/audit.toml'
- '**/package.json'
- '**/package-lock.json'
- 'web/scripts/patch-braces.mjs'
- 'web/scripts/audit-dependencies.mjs'
- 'web/scripts/dependency-security.test.mjs'
push:
branches: [main, master]
schedule:
Expand All @@ -23,10 +28,72 @@ jobs:
name: cargo-audit
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: read
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- name: Install cargo-audit
run: cargo install cargo-audit
- name: Run cargo audit
run: cargo audit

npm-audit:
name: npm-audit (${{ matrix.name }})
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
strategy:
fail-fast: false
matrix:
# Every committed package-lock.json, including build-only tooling.
include:
- { name: root, directory: . }
- { name: web, directory: web }
- { name: telemetry-ingest, directory: telemetry-ingest }
- { name: extension-host, directory: crates/tui/extension-host }
- { name: embedded-computer-use, directory: crates/tui/plugins/computer-use }
- { name: vscode, directory: extensions/vscode }
- { name: feishu-bridge, directory: integrations/feishu-bridge }
- { name: telegram-bridge, directory: integrations/telegram-bridge }
- { name: wecom-bridge, directory: integrations/wecom-bridge }
- { name: pet, directory: pet }
defaults:
run:
working-directory: ${{ matrix.directory }}
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: '22'
# Audit the complete committed lock, including build dependencies, and
# keep the raw report. Runtime compatibility remains owned by surface CI.
- name: Audit locked dependencies
if: matrix.name != 'web'
run: |
set +e
npm audit --json > "${{ runner.temp }}/npm-audit.json"
status=$?
set -e
node -e '
const r = require(process.argv[1]);
if (r.error || !r.metadata?.vulnerabilities) throw new Error("Incomplete dependency audit");
console.log(JSON.stringify(r.metadata.vulnerabilities));
' "${{ runner.temp }}/npm-audit.json"
exit "$status"
# The website also verifies its installed, reviewed build dependency
# mitigation (docs/DEPENDENCY_SECURITY.md); the raw report keeps every
# upstream finding.
- name: Install and verify website build dependency mitigation
if: matrix.name == 'web'
run: npm ci --no-audit
- name: Audit website with verified build dependency mitigation
if: matrix.name == 'web'
run: npm run audit:dependencies -- --report "${{ runner.temp }}/npm-audit.json"
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
if: always()
with:
name: npm-audit-${{ matrix.name }}
path: ${{ runner.temp }}/npm-audit.json
if-no-files-found: error
46 changes: 43 additions & 3 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,20 +7,60 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [0.10.1] - 2026-10-01
## [0.10.1] - 2026-10-07

### Contributor integration and reliability

- OAuth retry diagnostics omit provider-controlled error fields; account replacement stops before retired Weixin receipts exceed their storage limit, preserving uncertain work for local review.
- Resuming a session through a symlink to the same workspace no longer shows a false workspace-change warning.
- Runtime clients can read one tool call's actual workspace changes and reviewed skill details (thanks @gaord, #6817 and #6869). In-flight snapshot pairs remain pending; missing objects and corrupt repository metadata are distinguished.
- Search accepts valid preferred locales, and image dimensions describe the same bytes sent to the model (thanks @asto18089, #6860 and #6858). Automation deletion keeps its definition until cleanup succeeds, and compaction preserves its original summary anchor (#6864 and #6857).
- Config/status/permission commands share portable contracts while the host retains mutation authority; queue workers acknowledge a scheduled retry for temporary first-claim contention and fail honestly on corruption (thanks @aboimpinto, #6832).
- Indefinite questions, approvals and elevation waits survive the TUI watchdog. Answers get time to resume the current turn; settled requests disappear by identity. Thanks @7jrxt42BxFZo4iAnN4CX for #6872.
- Configured approval expiry belongs to the held Engine request; hiding or covering its card cannot restart the deadline, and a late queued answer cannot approve an expired call.
- Tool discovery keeps the highest-ranked matches when a result batch exceeds the existing cache bounds, preserving search order and the 16 KiB limit (adapted from @AdityaVG13's #6393).
- Model-switch receipts now translate their session-only saving note in every complete locale pack; the three save commands remain directly usable (thanks @Lstarsky0, #6875).
- Weixin bridge threads belong to the account and chat that created them:
resuming or listing another chat's thread is refused. An explicit `/new` after
an account replacement keeps the old account's private receipt and never
replays its prompts automatically. Replies never reuse another bot account's
Weixin context token, and `/threads` lists this chat's own older threads even
when other chats have newer ones.
- Windows messaging bridges retry a briefly locked record replacement
(EPERM/EACCES/EBUSY) with bounded delays and never delete the previous record
first.
- The website and README installation guides are generated from one shared
source, and the critical Simplified Chinese guides were re-reviewed against
current English.
- A Codewhale sign-in that expired, or an account service that is unreachable,
no longer blocks turns on your own provider key. The turn uses your local
settings and Codewhale says once how to restore account preferences.
- `codewhale login` keeps a DeepSeek route you chose, or one with a local key,
instead of switching it to the managed Codewhale provider.
- The bundled `computer-use` plugin is 0.12.1, reconciled with canonical source
`a656f67455fc5639f28304fbf61075db3925058a` while retaining Core's embedding
manifest and version contract.
`724f9c422db1a51880dc81154dae70816c475ed8` while retaining Core's embedding
manifest and version contract. Its image renderer lock now carries Sharp 0.35.5.
- The bundled first-party catalog pins marketplace revision
`6512f1dfaa91ee287e9f81ebabaf4909e8a371a3` and lists all 19 reviewed plugins,
up from 6. Every catalog plugin still installs disabled and untrusted until
you review it.
- Every committed npm lockfile is audited in CI, including build tooling. The
VS Code extension packages with `@vscode/vsce` 4 on Node 22 while it still
compiles and tests on its Node 20 runtime. The website keeps one reviewed,
hash-verified depth guard for an unpatched `braces` advisory
(GHSA-vfj7-8cjw-p6xm); its raw audit findings are retained, not hidden.
- Pasting through Windows Terminal (Ctrl+Shift+V) no longer drops emoji and
other characters outside the Basic Multilingual Plane. Release binaries and source builds carry
a small patch to crossterm 0.29.0 in `patches/` (the change proposed upstream
as crossterm-rs/crossterm#1073); a real Windows Terminal paste of 24 Unicode
lines is now a release gate.
- Experimental extension host: reviewed Native plugins can register avatar
packs with `ctx.avatars.registerPack` (`/pet avatar [key]`, `/pet action|view
<name>`). `/plugin import dsh <package-dir>` reviews a DeepSeek Harness
bundle and now lists the Native host code it contains; `approve <dir>
<content-hash>` installs it disabled and untrusted. Trusted host plugins stay
trusted across a restart, enabling a second host plugin activates it without
`/plugin reload`, and the review no longer crashes the TUI.

Codewhale v0.10.1 focuses on reliability and first-run behavior. Turns that
stall now say so, approvals keep what you approved, plugin suggestions are
Expand Down
2 changes: 0 additions & 2 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

6 changes: 6 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -136,3 +136,9 @@ codegen-units = 1
# them as 2 columns, causing cell-offset rendering glitches. (#4479)
[patch.crates-io]
unicode-width = { path = "patches/unicode-width-0.2.2" }
# Windows Terminal paste dropped every non-BMP character (emoji): upstream pairs a
# surrogate half with its own key-up record. See patches/crossterm-0.29.0 parse.rs.
# Same change as crossterm-rs/crossterm#1073 (open); drop this once a release carries it.
# Also drops one redundant pair of parentheses and allows upstream warnings, because a
# path crate is built under our `-D warnings`.
crossterm = { path = "patches/crossterm-0.29.0" }
8 changes: 7 additions & 1 deletion README.ar.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
<!-- source: README.md sha256:604da19bff2c -->
<!-- source: README.md sha256:004b3d422063 -->
<div align="center">

<picture>
Expand Down Expand Up @@ -57,6 +57,12 @@ cargo install codewhale-cli --locked # build from crates.io

## البدء السريع

**مفاتيح API لمزوّديك، في مكان واحد.** [أنشئ حساب Codewhale](https://app.codewhale.net/register)
أو شغّل `codewhale login` لتسجيل الدخول. احفظ مفاتيح API وحدّثها في حسابك،
ثم استخدمها عبر مسار النماذج في Codewhale على الأجهزة التي سجّلت الدخول عليها.
[إعداد مفاتيح الحساب](docs/CONFIGURATION.md#account-provider-keys).
تسجيل الدخول لا يرفع المفاتيح المحلية الموجودة؛ ويمكنك مواصلة الاستخدام المحلي دون حساب.

1. **افتح مشروعك.** شغّل `codewhale` في المجلد الذي تريد العمل عليه.
2. **اربط نموذجًا.** شغّل `/provider` (أو اضغط `F3`) لإضافة مفتاح مستضاف أو اختيار
بيئة تشغيل محلية. إذا كان Ollama يعمل بالفعل مع نموذج محادثة، ينتقل Codewhale إليه
Expand Down
8 changes: 7 additions & 1 deletion README.ca.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
<!-- source: README.md sha256:604da19bff2c -->
<!-- source: README.md sha256:004b3d422063 -->
<div align="center">

<picture>
Expand Down Expand Up @@ -58,6 +58,12 @@ instal·lacions a la mateixa màquina acaben disputant-se el `PATH`.

## Inici ràpid

**Les claus API dels teus proveïdors, en un sol lloc.** [Crea un compte de Codewhale](https://app.codewhale.net/register)
o executa `codewhale login` per iniciar la sessió. Desa i actualitza les claus API al teu compte
i fes-les servir a través de la ruta de models de Codewhale als dispositius on hagis iniciat la sessió.
[Configura les claus del compte](docs/CONFIGURATION.md#account-provider-keys).
Iniciar la sessió no puja les claus locals existents; pots continuar fent-ne un ús local sense compte.

1. **Obre el teu projecte.** Executa `codewhale` a la carpeta on vols treballar.
2. **Connecta un model.** Executa `/provider` (o prem `F3`) per afegir una clau
allotjada o triar un entorn local. Si Ollama ja s’està executant amb un model
Expand Down
8 changes: 7 additions & 1 deletion README.de.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
<!-- source: README.md sha256:604da19bff2c -->
<!-- source: README.md sha256:004b3d422063 -->
<div align="center">

<picture>
Expand Down Expand Up @@ -58,6 +58,12 @@ auf einem Rechner streiten sich am Ende um den `PATH`.

## Schnellstart

**Die API-Schlüssel deiner Anbieter an einem Ort verwalten.** [Erstelle ein Codewhale-Konto](https://app.codewhale.net/register)
oder führe `codewhale login` aus, um dich anzumelden. Speichere und aktualisiere deine API-Schlüssel im Konto
und nutze sie über die Codewhale-Modellroute auf deinen angemeldeten Geräten.
[Kontoschlüssel einrichten](docs/CONFIGURATION.md#account-provider-keys).
Beim Anmelden werden vorhandene lokale Schlüssel nicht hochgeladen; die lokale Nutzung ist weiterhin ohne Konto möglich.

1. **Öffne dein Projekt.** Starte `codewhale` in dem Ordner, an dem du arbeiten willst.
2. **Verbinde ein Modell.** Starte `/provider` (oder drücke `F3`), um einen gehosteten Schlüssel
hinzuzufügen oder eine lokale Runtime zu wählen. Läuft Ollama bereits mit einem Chat-Modell,
Expand Down
8 changes: 7 additions & 1 deletion README.es-419.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
<!-- source: README.md sha256:604da19bff2c -->
<!-- source: README.md sha256:004b3d422063 -->
<div align="center">

<picture>
Expand Down Expand Up @@ -58,6 +58,12 @@ en la misma máquina terminan disputándose el `PATH`.

## Inicio rápido

**Las claves API de tus proveedores, en un solo lugar.** [Crea una cuenta de Codewhale](https://app.codewhale.net/register)
o ejecuta `codewhale login` para iniciar sesión. Guarda y actualiza tus claves API en tu cuenta
y úsalas a través de la ruta de modelos de Codewhale en los dispositivos donde hayas iniciado sesión.
[Configura las claves de tu cuenta](docs/CONFIGURATION.md#account-provider-keys).
Iniciar sesión no sube las claves locales existentes; puedes seguir usando Codewhale localmente sin una cuenta.

1. **Abre tu proyecto.** Ejecuta `codewhale` en la carpeta en la que quieres trabajar.
2. **Conecta un modelo.** Ejecuta `/provider` (o presiona `F3`) para agregar una
clave alojada o elegir un entorno local. Si Ollama ya se está ejecutando con
Expand Down
8 changes: 7 additions & 1 deletion README.fr.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
<!-- source: README.md sha256:604da19bff2c -->
<!-- source: README.md sha256:004b3d422063 -->
<div align="center">

<picture>
Expand Down Expand Up @@ -58,6 +58,12 @@ sur une même machine finissent par se disputer le `PATH`.

## Démarrage rapide

**Les clés API de vos fournisseurs, au même endroit.** [Créez un compte Codewhale](https://app.codewhale.net/register)
ou lancez `codewhale login` pour vous connecter. Enregistrez et mettez à jour vos clés API dans votre compte,
puis utilisez-les via le routage des modèles Codewhale sur vos appareils connectés à ce compte.
[Configurer les clés du compte](docs/CONFIGURATION.md#account-provider-keys).
La connexion ne transfère pas les clés locales existantes ; l’utilisation locale reste possible sans compte.

1. **Ouvrez votre projet.** Lancez `codewhale` dans le dossier sur lequel vous voulez travailler.
2. **Connectez un modèle.** Lancez `/provider` (ou appuyez sur `F3`) pour ajouter une clé
hébergée ou choisir un runtime local. Si Ollama est déjà en cours d’exécution avec un modèle
Expand Down
Loading
Loading