Raven 0.1.12 (2026-08-18)
A patch release that makes cron reminders fire where they were created, puts skill hub installs behind a safety policy gate, and lifts the stale 64k context window off upgraded installs, plus fixes to first run, provider auth errors, and the one-line installer. Interactive chat is raven tui now: bare raven agent no longer opens a REPL.
Highlights
- Breaking: bare
raven agentno longer hosts a REPL. It prints a pointer toraven tuiand exits 2, whileraven agent -m "..."keeps working for scripted one-shot turns. Theclicron channel retires with it, and jobs stored withchannel="cli"migrate totuiat load (#329) - Breaking:
--wait-skill-extractand--flush-skill-bufferare gone. Both promised a boundary-detection workflow that has been a no-op since extraction moved to the memory backend, so a script still passing them now fails on an unknown option (#334) - Cron reminders fire at their origin: a job is claimed and delivered only by the runner that owns its creation-time channel binding, ending the case where a reminder created in the CLI never fired while a headless gateway was running (#326)
- A recurring reminder nobody engages with disables itself once it crosses a per-job fire limit (default 12), and
cron list/cron getsurface the live counter (#333) - Reminders that lapsed while the TUI was closed are shown at startup as one "missed N reminders" block, instead of a warning log the user never sees (#332)
- Skill hub installs go through a single policy gate: safety scores are actually checked, every install is recorded to disk, and
skillForge.blocklistrefuses a named skill everywhere (#327) skillForge.autoInstallpicks the consent mode (auto/prompt/off, defaultauto), andskill listgains an Installed column plus a[blocked]marker (#328)- An install upgraded from 0.1.10 or earlier is no longer capped at a 64k context window by the
contextWindowTokens: 65536those builds wrote into config.json. The stale pin is dropped once at config load, with a one-line notice, and a value you set yourself is never second-guessed (#341) - Model output is no longer capped at 8192 tokens by a shadowed default, and a truncated response is reported as truncation instead of nudging the model into resending the same oversized call (#308)
- Provider authentication failures print classified guidance and exit non-zero, instead of dumping a raw exception as if it were the agent's reply and exiting 0 (#330)
- First run is one command again: the installers send a fresh machine to bare
raven, a zero-provider install no longer names a vendor you never chose, and the model the wizard recommends is priced again instead of reporting an unknown cost (#342) - Choosing to run on the host rather than the sandbox now warns that injected commands would execute with full host privileges, and asks for an explicit confirmation that defaults to No (#321)
channels enablestops exiting 0 on missing credentials, and enabling a channel whoseallow_fromresolves to*(anyone who can message it can command the agent on this host) now requires an acknowledgement (#323)- Sessions are auto-titled from the first user message (capped at 40 characters), and
sessions createpersists immediately so create / list / delete round-trips work (#324) - EverOS memory ownership is a recorded decision instead of a per-call guess: onboarding asks once whether Raven runs the server, a root you run yourself is left alone, and a memory failure no longer stalls the session for up to a minute (#310, #343)
raven statuslists only configured providers and folds the rest into one line, every turn ends with a usage summary, andraven doctorreports the config as valid / invalid / missing and exits 1 on a broken one (#331, #322)- The identity block carries the gateway-resolved routed model id, so the agent stops answering "which model are you" from pretraining memory (#325)
- The tracing dashboard no longer reuses a viewer whose UI files were deleted, which served an unstyled page that never connected (#316)
- Running the one-line installer from inside a clone no longer silently installs that working tree as an editable checkout instead of the released wheel; an editable install is now an explicit
RAVEN_LOCAL_SRCopt-in (#294) - When the unauthenticated GitHub API quota is spent,
raven upgradeand the installers fall back to the release page to resolve the latest version, and the launch-time update check no longer spends an API request at all (#299) - Skill retrieval fusion is retuned: the RRF damping constant is configurable (
rrf_k) and the source weights are rebalanced (#290)
Install
New install on Linux, macOS, or WSL2:
curl -fsSL https://raven.evermind.ai/install.sh | bashNew install on native Windows, in PowerShell:
irm https://raven.evermind.ai/install.ps1 | iexWindows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:
irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iexOpen a new terminal, then run:
ravenThat sets you up on first run and then opens the TUI. raven onboard stays
the explicit way to reconfigure later.
Upgrade
Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved:
raven upgraderaven upgrade installs the latest stable release, so it does not pick up a
pre-release; rerun the installer above for that. Editable source checkouts are
never overwritten -- pull the checkout and rerun its development setup. On
native Windows the upgrade finishes in an external helper; wait for its
completion message before running Raven again.
Release Status
- Version:
0.1.12 - Tag:
v0.1.12 - Stability: public preview patch
- Assets: wheel and source distribution attached to this release
Notes
- Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
- PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.