Skip to content

Raven 0.2.1 (2026-09-24)

Choose a tag to compare

@github-actions github-actions released this 24 Sep 14:25
e176941

Raven 0.2.1 is a patch release: no command, flag or config key is removed or renamed and no configured default changes, but three behaviour changes are worth reading before you upgrade. The web first-run wizard now asks only for a model and, optionally, a search tool; its agents and data-sync steps are held back until they are ready, so a first run no longer offers to connect local agents, and until the step returns an import runs from raven import on the CLI (#784). exec on this computer now refuses a typed ssh to a machine the connection registry knows and names the two paths meant for it, while scp and rsync are untouched and an unreadable registry refuses nothing (#552). And a permissions.tools deny rule now stops the program it names however the command runs it, so bash -c, env, sudo, xargs, find -exec, a $(...) substitution or a redirection no longer walk past it (#783). The rest of the release is the agent connector (what a refused connect says, and where it is drawn), a round of web page fixes, and a -P guard that keeps a source checkout off the engine's sys.path.

Highlights

Connecting coding agents

  • A failed connect or test is now said under the agent rather than instead of it. Every card keeps one fixed shape with a slot that always speaks -- a grey word for the row's state, a single-line strip naming what failed and a short reason read off the remedy, amber while a write is in flight -- and the sheet keeps its 520x500 box, with the why and the how as a note at the top of the body: a title per remedy kind, the fix, the command on its own line, and the agent's own sentence folded under it. The card no longer carries the raw English sentence a server returned (#754, #785).

  • A refused Qwen Code connect names the fix and the command. A provider status the agent reports is classified (401/unset credential, 404 for a model it will not serve, 402 for credit, 429 for a rate limit, an unreachable provider, a launch that quit, a binary too old for --acp), and the sheet shows the fix as two numbered steps: run qwen, then type /auth there. /auth, not /model -- /model only picks among the models already registered in ~/.qwen/settings.json, and qwen 0.24.4's own OpenRouter preset registers two free models that OpenRouter has since withdrawn (#779, #786).

  • A Qwen Code started on a Node.js that is too old says so. Qwen Code runs on whichever node comes first on its launch PATH, and on 18.x it dies at import with a SyntaxError that names no version. Raven now resolves the interpreter from the agent's shebang, reads the floor from the agent's own package.json (>=22.0.0), and names both versions, with nvm install 22 && nvm alias default 22 or brew upgrade node only where the installer shows in the path (#786).

  • A refused Kimi Code connect says why instead of always asking for a sign-in. Kimi Code reports a session it cannot start as a bare Authentication required, so Raven asks it once more the way a reader in a terminal would (kimi -p, in the launch's own environment, capped at 20 s), checks a config it cannot parse with kimi doctor config, and reads a signed-in account's own plan limits (a spent usage window as 403, a model above the tier as 401, an unverifiable membership as 402) before the status (#781).

  • A missing npx is answered with Node.js, not with the agent's own npm installer, and a connect gives a first download time to finish: the start gets the row's readyTimeoutMs (120000 ms on the npx presets) with the answer keeping its 60 s cap, and an npx fetch that failed is named by npm's own error-code line rather than reported as an agent that did not answer (#754).

  • "Check again" finds an agent installed after the gateway started. The login-shell environment is captured once per process, so an installer's new PATH line was invisible until a restart; the sheet's re-check now asks subagents.list for a fresh capture (refresh_login_env, default false, so no other listing pays for a login-shell run), and the connect that follows launches on the PATH the probe found (#768).

  • A row that has just connected stops wearing a stale warning. The writes a server answers by running the agent now ask for the probe on their follow-up read instead of carrying the previous verdict over it, the card's dot and the sheet's status line read one ranked verdict, and a write refused while a later one landed repaints from a fresh listing instead of from the rows it started with (#773, #769). The TUI's /subagents overlay gets the same fix for its ! glyph (#774).

  • An API key already stored for an agent can be replaced from the sheet. An openai row whose stored key the endpoint rejects used to offer Connect, be refused with "change the key and press Retry", and have no field to change it in; the field is now drawn at every stage but live and stale, a typed key turns the press into Connect, and saving a key on a row that is off is followed by the switch that proves it (#788).

The web page

  • The first-run wizard draws its step before the data lands. The model step used to hold a "Loading..." line for 6.4 s on a warm install while the whole settings payload arrived; it now draws its real (empty) cards at 148 ms and fills in behind them (#771).

  • Task-board DAG edges no longer hide under the boxes they pass. Layout moves to @dagrejs/dagre for in-layer ordering and edge routing: an edge that skips a layer bends through the gap, edges meeting one face of a box get their own ports, and a root that feeds only a deep node stays on the first layer (#761).

  • Running tasks get a stop button in the floating tasks list, so a stuck sub-agent can be stopped without opening its read-only context view. It reuses the existing calls -- subagent.cancel_instance for a spawn, subagent.interrupt for a task graph (#764).

  • The file bar gains a download button for every kind, so a file read on a remote serve can be saved to the reader's own machine; a file this session delivered is saved from its delivery, anything else from the route the viewer already reads it through (#770). In the same bar the rendered/source pair is now offered only on md, svg, html, csv and json, where the two positions actually differ -- a PDF no longer fetches its whole body to draw it as numbered lines -- and the new-tab, download and folder buttons form one group (#778).

  • A spawn's task row opens the task pane however soon it is clicked. A click landing before the tasks store had filed the run used to open the agents panel's instance window instead; the opener now reads that one row with tasks.list and retries while the record is still being written, falling back to the tasks list (#772).

  • Settings pages get real empty states that tell "nothing here" apart from "service down": usage, archive, plugins, skills, providers, schedules, channels and memory share one shape (a mark, a title, one line, at most one control), a failed memory read takes the whole frame with a retry, and only rows with a panel to expand look clickable. The memory pager no longer slides under the pointer on a page turn (#775). Reopening the dialog no longer swallows the first click either: a reload that answers the same values leaves the page mounted instead of rebuilding every control about 670 ms in (#782).

Runtime, tools and providers

  • The machine registry has one reader and one writer, and the coding agent can add a machine. A sub-agent reads the owner's registry in RAVEN_HOME rather than the empty state directory beside its rendered config, a host started with --config keeps the list beside that config, and ops_connection_add is a trunk tool served on tools.connectionAdd (off by default; on in raven-code and raven-oncall). It probes a machine the way the owner's own terminal would resolve it (ssh -G, each candidate key offered on its own) and writes nothing until the machine answers; raven ops connection add calls the same functions (#690).

  • A user exec deny rule stops its program however the command runs it. Deny rules are asked first, about every command the string can be seen to run: shell wrappers and runners, $(...) and backtick substitutions read off the raw text, a keyword in front of a command, env -S, find -exec, a redirection, and the program compared by its bare name so a path prefix or a Windows .exe suffix does not hide it. Allow and ask rules are unchanged, and a heredoc body no shell reads is dropped first (#783).

  • DeepSeek's shown API base is now https://api.deepseek.com, not https://api.deepseek.com/beta, so saving a working key stops answering Couldn't verify (http_404), saved anyway; /beta is DeepSeek's FIM endpoint and serves no models route. A config that already stored /beta keeps it -- clear or reset the API Base field by hand. In the same pane a refusal is drawn at the foot of the column that scrolls and scrolled into view, instead of a screen below the control that refused (#763).

  • read_skill returns a local skill's body the way context injection renders it: headed with the skill's directory, with links to its bundled references/, scripts/, assets/ and examples/ rewritten to absolute paths. Models were otherwise searching the disk for a skill's own reference files and reading another checkout's copy (#762).

  • Image generation through OpenRouter no longer fails with HTTP 404 on a stored model such as openrouter/openai/gpt-image-2.5-sunburst: the routing prefix is stripped on the wire while the stored configuration is left alone, and OpenRouter is detected by the API hostname exactly (#766).

Install and startup

  • raven web no longer runs a source checkout's code. It starts its supervisor and engine as python -m raven, which puts the working directory first on sys.path, so started from inside a checkout the installed Raven came up on that checkout -- running its config migrations against the real ~/.raven/config.json, crash-looping the supervisor on a dependency the wheel lacks, and serving <repo>/ui-web/dist. All three launches now pass -P, and both installers move to the home directory before starting the page (install.sh with a cd, install.ps1 with Push-Location $HOME and a Pop-Location, because under irm | iex the script runs in the caller's own shell). Editable installs still resolve through their .pth entry (#776).

Install

New install on Linux, macOS, or WSL2:

curl -fsSL https://raven.evermind.ai/install.sh | bash

New install on native Windows, in PowerShell:

irm https://raven.evermind.ai/install.ps1 | iex

Windows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:

irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iex

The installer puts uv, Node.js 22, Raven and its plugins in place, downloads the
browser runtime, installs or offers LibreOffice, and then finishes by opening
Raven in your browser. First-run setup happens on that page. The installer holds
the terminal while the page is up; press Ctrl-C to stop it, then start Raven
again with:

raven web

That keeps Raven running in the background and opens the page; raven web --stop
stops it. Prefer the terminal? raven runs the same first-run setup and opens
the TUI, and raven onboard stays the explicit way to reconfigure later. Set
RAVEN_MINIMAL=1 to skip the browser and LibreOffice downloads, or
RAVEN_NO_LAUNCH=1 to have the installer return without opening the page.

Upgrade

Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved. Stop the page first, then upgrade:

raven web --stop
raven upgrade

On Linux and macOS raven upgrade runs the install in the foreground and
returns when it is done. On native Windows it hands the install to a separate
helper and returns at once; wait for the helper's completion message. Then
start Raven again:

raven web

raven upgrade installs the latest stable release together with the plugin
wheels it ships. It never picks up a pre-release unless this install has joined
the beta channel (a ~/.raven/beta.json that only the beta installer writes).
raven upgrade --check reports whether a newer release exists without
installing it. Editable source checkouts are never overwritten: raven upgrade
reports the checkout path and how far it is ahead of or behind origin/main,
and the remedy is git pull && ./install.sh in the checkout. Rerunning the
one-line installer also upgrades, and ends on the running page.

Release Status

  • Version: 0.2.1
  • Tag: v0.2.1
  • Stability: public preview patch
  • Assets: the raven wheel and source distribution, the three plugin wheels
    (everos_memory, design_engine, ppt_engine), the locked constraints file
    raven-constraints.txt, and the plugin list raven-plugins.txt

Notes

  • Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
  • PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.