Repository navigation
Releases: NMHx2005/crossweave
Release list
v0.6.0
Headline
0.6.0 makes the loop with an AI agent safer and faster without choosing or configuring the agent for you: a checkpoint around every
agent turn you can look at and restore, comments on a diff that land in the session's shell, an opt-in automatic test run when a
turn ends, and flags on sensitive files before you land. Everything still ends in text typed into your own shell, and nothing presses
Enter for you.
New
- Session checkpoints. When a recognised agent starts and ends a turn, crossweave records the worktree as a hidden git commit
(refs/crossweave/checkpoints/<session>/<n>, from a private index; no branch, HEAD or real index moves).cw checkpoint list|take|diff|restoreand a Checkpoints… dialog in the session menu show what each turn changed. Restore is a dry run by default,
saves a return point and refuses before touching anything it would destroy. The newest 50 are kept. - Diff comments. Comment on a line of the Changes pane or the Checkpoints dialog; the notes are pasted into the session's shell as one
bracketed paste, never with Enter. Comments are matched back to their lines after a reload; the ones that no longer match are listed. - Auto-check (Settings → Checks, off by default). When an agent ends a turn that changed files, the trusted
converge.testCommandruns in that worktree, one automatic run at a time. A failing run offers Send test failure to shell
(secrets redacted, control characters removed, no Enter). - Sensitive-file flags. Files of a diff named like a secret, an automation file (CI, hooks, containers, the repository config), a
migration or a dependency manifest carry a labelled badge, with a summary line, in Changes, Checkpoints and Compare. Land asks first
for secret-like and automation files, in the same dialog as the failing-tests question. Judged by name only: it can miss and it can over-flag. - AI debug loop (from
mainsince 2026-10-01):cw hooks install|remove,cw debug, a Debug pane, a Responses view after a composer
send,cw browser errors, status that covers split panes, a live drag preview. - A calmer Settings page. No news banner; every section has a one-line lead, a titled first card and its longer explanation folded under
Details, and the column no longer shifts when a scrollbar appears. Notifications is grouped, Checks explains how it works, and the auto-run
row keeps its safety words (runs code the agent just wrote, outside its sandbox, for every project, off by default) in view. - A desktop alert when a check fails while the window is not in front:
<session>: tests failedwith the exit code and time, never the
output. One per failing run; switch When tests fail under Settings → Notifications, on by default. - Session panel overview: a count chip on rows with two or more panes lists them so you can focus one.
- Hardening round 2: a
✗ setupchip, a history filter capped at 500 rows, morecw debugfailure shapes and token shapes, opt-in
converge.requireCheck(withcw land --skip-check),cw checkwith the session's lease environment, Compare showing whether the pair
would conflict, a cancellable Refine, a corner notice when a newer release exists.
Fixed
- A shell's
cwcommands inside a session reach the daemon that owns the session. - "Send test failure to shell" cleans the output before redacting it: a key split by a zero-width character, a bidi override or an escape sequence
used to escape the redaction and be put back together afterwards; BEL, backspace and DEL are removed too. - The rail re-reads when a pane closes; the pane inset no longer disturbs the terminal fit; a stopped session's tick can be unticked.
Upgrading
- Schema v18 (
cw checkverdicts survive a restart). An oldercwrefuses a v18 database; update the CLI and the app together. - The new methods (
checkpoint.*, the automatic check) need a daemon of this version. Restarting a project's daemon ends its running
sessions, so pick a quiet moment. - Checkpoint refs are visible to
git log --alland to tools that list every ref; they are orphan commits, not branches. - Auto-check is a trust decision. It makes an agent's finished turn start a run of a command you already trusted with
cw config trust, for every project where you trusted one. Leave it off if you do not want that. - The failed-check alert comes from the window, so only projects the window has open raise it; it never shows test output.
- Limits and ideas not built:
docs/superpowers/specs/2026-10-10-{session-checkpoints,diff-comments,auto-check,sensitive-files}-known-limitations.mdand2026-10-11-settings-polish-check-alert-known-limitations.md.
v0.5.0
Headline
0.5.0 gives the cockpit a Settings page in the manner of Cursor's and a Dashboard that shows what your projects and sessions
cost in disk and memory — and proposes, never performs, what you could stop or delete to lighten the machine.
New
- Settings are re-laid out: grouped icon navigation, one centred column, rounded cards of rows (name and description left, control
right), real toggle switches, and a dismissible banner. Search and deep links use the same words as the page. - Dashboard (Settings → Dashboard): per project the sessions by state, the disk their worktrees hold, the daemon's memory and the
app's own; two charts (each with a table view); a sortable session list. - Suggestions to free space: clean up ended sessions, delete a long-idle empty session, land-or-delete a long-idle one that still
holds unlanded work, stop an idle shell. Every action asks first and names exactly what would be lost; a clean-up never includes
sessionsgcwould keep. - The rail's filter box reads Search and has an icon.
Fixed
- The active project's frame in the rail no longer changes the rows' size and position when you switch session or project.
- The "No open tabs" box no longer touches the pane's edges.
- The daemon measures worktree disk off its event loop (
DiskTracker), so a bignode_modulesno longer stalls it.
Upgrading
- The Dashboard needs a daemon of this version. A project still running an older daemon shows "restart its daemon to see its
numbers"; restarting ends that project's running sessions, so pick a quiet moment. - Disk figures are lower bounds (
≥) when a measurement hits its time limit. See
docs/superpowers/specs/2026-09-30-settings-dashboard-known-limitations.md.
v0.4.0
Headline
0.4.0 is the release where the cockpit and the shell talk to each other, and where running several agents at once gets easier
to supervise: a session can say it is done, its work can be tested before you land it, two attempts can be compared, one prompt can
go to several sessions, and a whole working setup starts in one click.
It also removes things on purpose (see "Removed"). If you are coming from 0.3.0, read that section first.
New
From a shell into the cockpit
cw notify "tests written" [--kind done|ask]— an agent's hook (or you) tells the cockpit a session is done or needs an
answer. A ✓ (or an amber row) appears, the words go in the tooltip and the desktop notification, and the next keystroke in the
session clears it. Exact where the screen-reading status is a guess. Example: a Claude CodeStophook running
cw notify "Claude finished".cw check [session]— runs the project's trustedconverge.testCommandin that session's worktree; the row shows✓ testsor
✗ tests(dim once the work has moved on). Same trust gate asland(cw config trust); nothing untrusted ever runs.
Landing a session whose last tests failed now asks first.cw pane list|split|select|zoom|layout|move|sync|close|open— arrange the running cockpit's panes from a shell. Layout-only
commands just happen; closing, synchronizing and opening a page or file ask you.cw browser list|console|network|dom|shot|navigate|click|type|eval— an agent reads and drives a Browser pane, behind a per-pane
Agent: Off / Read / Control switch (off by default). Control outside localhost, andevalanywhere, ask you for that one
command. Text read from a page is marked untrusted. See the known-limitations note before you turn it on for a logged-in page.- A command bridge underneath: the daemon carries a request to the cockpit and its answer back; closed namespaces, and every decision
is taken in the cockpit, never in the daemon.
In the window
- Prompt composer (⌘⇧P, the pen button): write one prompt, optionally Refine it with a program you name (Settings → Prompt;
only a proposal comes back), and send it to one or several sessions. The preview shows exactly what goes where; Enter is pressed only
if you tick it; a multi-line prompt is never typed into a plain shell. - Compare with another… (session menu): two sessions' changes side by side, the files both touched marked, and a Land button per side.
- Session presets (Settings → Presets, then ⌘T): a launcher, an own worktree or not, extra terminals that each run a command, and a
Browser pane on the session's port — in one click. - Session history (⌘⇧H,
cw session history): what you landed or deleted, kept after the session row is gone. - tmux-style panes:
Ctrl-Athen a key, synchronize panes, a vi-style copy mode, move a pane to another tab, layout presets,
next/previous tab. Optional terminal persistence (off by default) reopens extra terminals after a daemon restart. - An app icon of its own (a small weave in the agents' colours) instead of Electron's default.
- A quieter status: nothing for a shell with nothing running, a turning ring while an agent works, a ✓ when one finished and you have
not looked, amber when it asks. A failed setup hook shows on its row.
Fixed
- The rail could miss a session created at the same moment as another, because an older, slower refresh could overwrite a newer one.
- A plain shell showed a spinner every time you typed (the echo of your own keystrokes counted as work).
- A session in the project folder could trigger a false "holds 36 GB" disk warning.
- Dropping a file on a terminal, the context menu at the screen edge, and several concurrency flakes in the port tests.
- A landed session's leases are released after its teardown, not before; a daemon that does not know a method is told apart from other
RPC errors; a broken worktree can no longer freeze the overlap picture for everyone.
Removed
- In-app voice input. Dictation is better served system-wide (Handy, Superwhisper, macOS Dictation) and works in every app. The last
version with it is tagv0.5-voice-input; the composer's Refine keeps the idea for text. - Earlier (2026-09-27): the collision guard, tiers / Safe Mode, agent adapters and launch flags, the MCP server and the OS sandbox
(tagv0.3-radar), and the browser remote controlcw gateway(tagv0.4-remote-web). 0.3.0's notes describe a sandbox that no
longer exists.
Upgrading
- The database schema goes from v14 to v17 the first time a project's daemon starts on 0.4.0 (terminals, the setup hook's exit code,
session history). Migrations only add. - Restart each project's daemon after installing the app, or
cw notify,cw check,cw pane,cw browserand the history will be
answered by the old one ("Unknown method"). Restarting ends that project's running sessions. - A settings file that still has a
voiceblock loads fine and drops it on the next save. - The app is signed with a development certificate and not notarized (that needs an Apple Developer account): on first launch macOS may ask for Open Anyway.
Known limits
Every feature has a *-known-limitations.md next to its spec, and the one-line versions are in
docs/superpowers/specs/2026-08-14-known-limitations-digest.md. The ones worth knowing before you rely on them: a verdict from
cw check is remembered in memory only and tests the session's worktree, not the merge; page text, screenshots and eval results from
cw browser are not redacted; the command bridge's caller is unauthenticated by design (a same-user process can register first);
agent detection is a guess from the process tree, so an unrecognised agent is treated as a plain shell by the composer.
v0.3.0
Headline
Two things land in this release: an OS-level sandbox around every session, and the
crossweave Cockpit — the desktop client the core was designed for from day one.
New — OS-level session sandbox (macOS)
Safe Mode's tiers intercept what an agent reports about its tool calls, so a write made
through a shell, a script, or a subprocess slipped past all of them. Each session now runs
inside an OS boundary (macOS seatbelt) where that write is not merely unblocked — it is
impossible:
- a session can write inside its own worktree, its private temp dir, its caches and its
own agent state, and nowhere else — not your main checkout, not another session's
worktree, not$HOME, not.git/configor git hooks; git commitstill works, because the profile opens exactly the object/ref/log
shapes a commit writes in the shared.gita linked worktree commits through;- network is off unless the workspace opts in.
// crossweave.config.json
{ "sandbox": { "enabled": true, "network": false } }enabled defaults to true. On a platform with no provider (Linux, Windows) or on a
--no-worktree session sharing your checkout, the session runs unconfined and the
daemon log says so — the absence is never silent.
Linux (bubblewrap) is specified but not built; see
docs/superpowers/specs/2026-09-18-os-sandbox-design.md.
New — crossweave Cockpit (Electron, macOS arm64)
A thin desktop client over the same daemon: real xterm panes, an attention rail
(working / needs-you / blocked / landability), and evidence-gated land from the UI. It is
built from source (cd apps/cockpit && bun run dist:mac); attaching the installer to
releases is the next step. The CLI TUI (cw tui) remains the cross-platform dashboard.
New — cw session start, and honest tier labels
cw session start <session>— start an agent without attaching.session newis
create-only again (it used to spawn an agent, which failed wherever the binary was not
onPATH).- Every tier prints what it actually covers —
T2 · Edit|Write,T3 · nothing—
instead of a bare tier that reads as protection. Bash is watched after the fact and is
advisory only: a block stays reserved for a write the daemon actually evaluated. - A stopped session is no longer a green "ready" — the badge now reflects whether an
agent is actually running. cursor-print(T3) drivescursor-agent --print --output-format stream-json.
--agent cursor(T1/ACP) now fails fast with a clear message: current
cursor-agentbuilds dropped ACP, so it used to hang silently.
Fixed — land and lease reliability
- Land is evidence-gated: trials are recorded against the base commit they ran
against, and are re-run when the base moves, socw land allstops with "nothing to
land" rather than landing on stale evidence.--forceoverrides deliberately. - A squash merge whose commits produce no staged diff is a successful no-op, not a false
LAND_MERGE_FAILED. PORTcan no longer be overridden byports.named, and the whole port block is probed
before it is leased.cw session rm/kill --rm-worktreedispose leased cache directories and copied
databases before deleting their records.cw session listshows the port/cache/db lease summary.- The ACP adapter times out a handshake that never resolves instead of showing a
runningsession that is silent and dead.
Upgrading
The sandbox is on by default. If a workflow legitimately needs to write outside the
session's worktree (a shared build cache, a global tool config), either set
sandbox.enabled: false for that repo or opt the network in with sandbox.network: true
— the daemon log names the session and the reason whenever no boundary is applied.
Installers and checksums are attached below. install.sh picks the right binary for your
platform.
v0.2.1
v0.2.0
fix(release): macos-13 runner was retired in Dec 2025, use macos-15-i…
v0.1.0
chore: bump version to 0.1.0 — first real release