Skip to content

Raven 0.2.4 (2026-10-03)

Latest

Choose a tag to compare

@github-actions github-actions released this 03 Oct 16:36
3632e60

Raven 0.2.4 is a patch release. Raven can now read and change its own configuration from the conversation: a new raven_config tool reads any setting without asking, asks before every write, and never takes a key through the chat (#833). Four things behave differently once you upgrade. The approval sheet on the page no longer answers to 1, 2 and 3: Esc denies, Cmd+Enter (Ctrl+Enter) allows once, and Shift+Cmd+Enter gives the broader grant (#817). Channels have left the Settings dialog: the rail row that was Agent Connector is now Connectors, with Agents and Channels as its two tabs (#830). Every turn the gateway runs (the page, chat apps, cron) now takes the per-turn workspace checkpoint, a shadow git repository at .raven/shadow.git in the workspace, which is what lets a file an exec command wrote open as a diff; runtime.checkpoint.policy: "never" turns it off (#829, #849). And the main agent answers in plainer, shorter prose, using headers, bullet menus and emoji only when you ask for them (#853). No command, flag or config key is removed or renamed.

Highlights

Raven configures itself

  • The raven_config tool has seven actions: describe (every setting with its value, or a search), get, set (one path, or several under one confirmation), unset, add (connect preset agents, several at once), test and restart (reload or restart once pending changes are gathered). Its catalog covers 14 sections and about 93 settings, each saying when a change takes effect: next turn, at once, on reload, on restart, or on the memory server. Writes go through the same methods the Settings page uses, so both are checked the same way. Setting session.model switches only the current conversation (#833).

  • Every write asks first, on a config card that shows what changes, the value before and after, and when it takes effect. Full access, your own allow rule or the smart-mode reviewer can let a change through, but only in a turn someone is at, and the reviewer never approves a sensitive setting (approval mode, sandbox, deny patterns, MCP servers, provider endpoints, who may instruct Raven on a channel, lent keys and the like). Cron and other unattended turns cannot change the configuration (#833).

  • A key never goes through a tool call. The agent names the setting and a credential card on the page takes the key, which the host writes; the model only learns whether it was saved or skipped. A key passed to the tool directly is not written, and the agent is told to ask you to rotate it. In the terminal or a chat app, where no card can be shown, you are told where to enter it. Tool output is scrubbed of the keys Raven holds. The credential card answers to the same keys as the approval sheet: Esc skips, Cmd+Enter saves (#833, #849).

  • Raven can connect preset agents, test them and work out why one does not answer. On the Agents page, a refused connect or a failed test offers "Hand it to Raven", which opens a new conversation naming the agent and the reason, without sending it. An ACP agent can be started with one of Raven's provider keys (lendKeys; Pi only for now), and the connect card says which key it lends (#833, #849).

  • An EverOS memory LLM left unset now follows the main model, and the memory server restarts when the main model changes (#833).

The page

  • Connectors: one rail row with Agents and Channels tabs, and it returns to the tab you were last on. The channel page is laid out like the agent hub: All / Connected / Not connected filters over a grid of cards with three states. A connection problem (switched on, but the adapter is not running) is red, sorted first, and says what to do. A card only opens its sheet; connecting happens there, and the list's switches and search are gone. Each tab has a one-line description under it (#830, #849).

  • Approvals: Esc denies, Cmd+Enter allows once, and Shift+Cmd+Enter grants the saved rule, or this conversation when there is no rule. Ctrl works in place of Cmd. Each button shows its key, digits no longer answer, and Deny keeps the focus, so a bare Enter never grants. The broader button now just says "Always allow" and names the rule it saves on its own line. The question sheet keeps number keys for options and gains Cmd+Enter for Next / Submit (#817).

  • The file viewer shows ten Office formats (ppt, pptx, doc, docx, xls, xlsx, odp, odt, ods, rtf) as pictures of their pages, converted with LibreOffice, where only pptx was before, and delivery tiles get a first-page thumbnail. A file with an unknown or no extension (Makefile, .gitignore) is judged by its first 8 KB and shown as text when it is text. A broken image says whether the file is gone, too large, refused or could not be drawn. A file with no preview gets a centred card with one open-in-app button (#817).

  • A previewed image is drawn at its own size, and one bigger than the window scrolls both ways instead of running off the screen (#854).

  • A delivered file that the agent rewrites shows its new content instead of the browser's cached copy (#838).

Diffs

  • A file an exec command created, rewrote or removed opens as a diff in the desk's diff tab, with +/- counts, instead of as the bare file. The command measures what it wrote against the workspace checkpoint. Files the checkpoint excludes (.env, *.log, your .gitignore) never carry their text, and text files over 256 KB get no counts (#829, #849).

  • The diff tab no longer lists files with no diff to show (images, Office files, archives, PDFs), and its badge counts only the rows it draws. A task's file chip opens such a file directly (#847).

Replies, agents and scheduling

  • The main agent leads with the answer, answers a simple question in plain prose with no headers, bullet list or closing recap, and keeps errors, failing output and warnings in full. A format you ask for still wins. Agents the host launches are unaffected. The workspace SOUL.md and AGENTS.md templates are trimmed to match, but only new workspaces get them; an existing workspace keeps its own copies (#853).

  • All five bundled agents (raven-code, raven-design, raven-oncall, raven-ppt, raven-research) can inherit a host model signed in with OAuth, OpenAI Codex included (#841).

  • A plugin connected during a turn can be used in that same turn, instead of reporting "connected" and then being unavailable until your next message (#816).

  • A cron reminder that already replied is no longer sent a second time by the heartbeat (#843).

  • WhatsApp switched on but never paired stops after three unscanned QR rounds instead of printing a fresh code every 20 seconds indefinitely. The channel then reads as stopped, and trying again restarts pairing (#832).

Providers and MCP

  • Signing in to OpenAI Codex (ChatGPT subscription) from the page works end to end: a second "Authorize in browser" click keeps the same code, the model pickers see the provider without a reload, usage is reported, and the token file is readable by its owner only (#818).

  • Testing a provider sends the extra headers its endpoint is configured with, so a relay that needs a tenant header is no longer reported as invalid_key (#831).

  • Updating a model's metadata under an equivalent id (hosted-vllm/team-model for team-model) keeps its existing label, description and tags (#835).

  • An MCP server that pages its tools/list answer now gets all its tools registered, not just the first page (#825).

Sandbox, browser and safety

  • Sub-agents of raven playbook runs now respect tools.sandbox and tools.restrict_to_workspace; before, they ran on the host unconfined. A playbook that relied on that will now see the configured limits (#827).

  • A boxlite sandbox with tools.sandbox.allow_net set to false or to a domain list starts again; with boxlite 0.9.5 it failed with a TypeError (#813).

  • When boxlite is missing, the advice is a command for the environment Raven runs in, uv pip install --python <Raven's python> boxlite==0.9.5, instead of pip install 'raven[sandbox]', which installs an unrelated package (#822).

  • A browser permission prompt names the site the call will actually act on, and the grant is keyed to it, so an approval for one site can no longer be reused for an action that landed on another page (#839).

  • When Chromium cannot start because a system library is missing, the browser tools name the library and the command to install it (<python> -m playwright install-deps chromium, which needs root), instead of reporting a busy profile or a missing browser (#848).

  • raven doctor warns when permissions.mode is full and when tools.sandbox.backend is none (commands run on this machine with no isolation). Neither warning changes the exit code, and --json reports both values. The agent is also told to install packages into the project's virtual environment, or a temporary one, rather than the global one (#837).

Docs

Install

New install on Linux, macOS, or WSL2:

curl -fsSL https://raven.evermind.ai/install.sh | bash

New install on native Windows, in PowerShell:

irm https://raven.evermind.ai/install.ps1 | iex

Windows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:

irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iex

The installer puts uv, Node.js 22, Raven and its plugins in place, downloads the
browser runtime, installs or offers LibreOffice, and then finishes by opening
Raven in your browser. First-run setup happens on that page. The installer holds
the terminal while the page is up; press Ctrl-C to stop it, then start Raven
again with:

raven web

That keeps Raven running in the background and opens the page; raven web --stop
stops it. Bare raven does the same, and opens the TUI only where no browser
can be opened. Prefer the terminal? raven tui runs the same first-run setup and
opens the TUI, and raven onboard stays the explicit way to reconfigure later. Set
RAVEN_MINIMAL=1 to skip the browser and LibreOffice downloads, or
RAVEN_NO_LAUNCH=1 to have the installer return without opening the page.

Upgrade

Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved. On a raven web install whose page is served by 0.2.3, the update
row at the bottom of the sidebar does this for you, and the page reloads itself,
still signed in, once 0.2.4 is up. A page served by 0.2.2 or earlier refuses it;
from the command line, stop the page first, then upgrade:

raven web --stop
raven upgrade

On Linux and macOS raven upgrade runs the install in the foreground and
returns when it is done. On native Windows it hands the install to a separate
helper and returns at once; wait for the helper's completion message. Then
start Raven again:

raven web

raven upgrade installs the latest stable release together with the plugin
wheels it ships. It never picks up a pre-release unless this install has joined
the beta channel (a ~/.raven/beta.json that only the beta installer writes).
raven upgrade --check reports whether a newer release exists without
installing it. Editable source checkouts are never overwritten: raven upgrade
reports the checkout path and how far it is ahead of or behind origin/main,
and the remedy is git pull && ./install.sh in the checkout. Rerunning the
one-line installer also upgrades, and ends on the running page.

Release Status

  • Version: 0.2.4
  • Tag: v0.2.4
  • Stability: public preview patch
  • Assets: the raven wheel and source distribution, the three plugin wheels
    (everos_memory, design_engine, ppt_engine), the locked constraints file
    raven-constraints.txt, and the plugin list raven-plugins.txt

Notes

  • Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
  • PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.