Repository navigation
Releases: Ninozzz95/talos
Release list
TALOS Desktop desktop-v0.1.22
TALOS Desktop 0.1.22
Windows 10 1809 or later, x64, or Windows 11 x64. Node does not need to be installed.
Build and smoke test run on a Windows Server 2025 runner; the minimum Windows 10 compatibility still needs a test on that system.
What changed
A beta: installs of 0.1.21 do not receive it automatically. TALOS now speaks English and Italian across the interface,
asks before reading or listing anything outside the project, and lets you queue a message that goes in right after the
current step.
Added
- Every screen, dialog and fragment of the interface speaks both English and Italian, including the server's messages
people read (Doctor, providers, web-search sources, GitHub, files, the approval card's sentence before a secret).
A language gate keeps it so: no hard-coded text, no Italian sentence in the code, a pseudo-language check on every
section, the open session and the main dialogs. - The short description under each command follows the interface language.
- The model can list its sub-agents and stop one (with the ones it started); a sub-agent's result is never stuck behind
a Stop, and the parent picks it up. - A message queued while tools run goes in right after their results, in the same turn.
Changed
- Reading or listing outside the project folder asks first; credentials always ask. With Full access only credentials ask.
- The kernel writes to the model in English.
Fixed
- Opening the Terminal of a session whose folder no longer exists no longer brings the server down; the terminal says why.
- A sub-agent's suspicious result delivered in the middle of a turn still makes the next change ask for confirmation.
Known
- A part of the server's texts is still being translated (lane K4b); a few kernel sentences for people (the WSL root
consent, the local engine notice, provider notices in the chat) are still Italian only.
Install
Open TALOS-Setup-0.1.22.exe: NSIS installer for the current user, no administrator prompt.
Alternatively extract TALOS-0.1.22-win.zip in full and open TALOS.exe, keeping resources and the DLLs next to the executable.
The v0.1 is not code-signed: SmartScreen may show "Windows protected your PC" and an unknown publisher.
After checking the SHA256 and the provenance, choose "More info", check the name TALOS-Setup-0.1.22.exe, then "Run anyway" if you intend to proceed.
If your device management blocks that option, ask your administrator. Do not turn SmartScreen or Defender off.
The GitHub attestation certifies where the build came from; it is not an Authenticode signature and does not remove the SmartScreen warning.
What is inside
An Electron 44.3.0 shell with the Node runtime included, the TALOS backend, the built frontend, the kernel, the context engine, native addons, and llama.cpp b10517 CPU/Vulkan builds with their licences.
Vulkan needs a compatible driver; the CPU engine is included as the alternative.
Node.js 24.18.0 and ripgrep 15.0.0 for Linux, with their licences: when WSL is installed and a session runs its commands in Linux, the file tools run there too, with these binaries. Nothing is installed inside the WSL distribution.
No GGUF model and no credential is bundled, and there is no telemetry.
Automatic updates
The app checks for a new desktop release when it starts and every 4 hours, downloads it in the background and installs it when you close the app, or at once with Riavvia ora. latest.yml is signed with an Ed25519 key (latest.yml.sig): the app verifies the signature with the public key it carries before downloading anything, and checks the downloaded installer against the signed SHA-512 before installing it. Automatic updates can be turned off in Settings, under Account, Doctor e backup.
Remote providers and model downloads need the network and their own configuration; this installer does not certify that they work.
Check the SHA256
Compare both values with SHA256SUMS.txt and with the ones published here:
5f50a51e5fd3aacf8e072e68bda22dcdf57d44f772875eecad170b32a821e840 TALOS-Setup-0.1.22.exe
5086026ce4d8d70d597933a0e773a420a4754d58a3331c9bf0e96f0a89275472 TALOS-0.1.22-win.zip
fa8a4869df423485e87d1b93a9f6af1cb32f54e1e11f202d2ffe81d27ef08100 latest.yml
9cf976676f71737bce2c850e022dbd41da04fec6b52d48351e9270337223050e latest.yml.sig
Get-FileHash -Algorithm SHA256 .\TALOS-Setup-0.1.22.exe
Get-FileHash -Algorithm SHA256 .\TALOS-0.1.22-win.zip
Get-Content .\SHA256SUMS.txtCheck the GitHub provenance
With the GitHub CLI installed, verify every file you downloaded against the repository that produced this release:
gh attestation verify .\TALOS-Setup-0.1.22.exe --repo Ninozzz95/talos
gh attestation verify .\TALOS-0.1.22-win.zip --repo Ninozzz95/talosThe provenance ties the artifacts to the workflow and to the commit of tag desktop-v0.1.22.
The desktop job runs the gates before packaging, then verifies silent install, start of the installed EXE, health with cookie, reload, close and uninstall with no processes left behind.
v0.1.40
What changed
Signing in to OpenRouter no longer fights itself.
Providers
- "Sign in with OpenRouter" now spends the authorization code exactly once. Coming back from the browser, the app
could exchange the same code a second time, which OpenRouter refuses ("Invalid code or code_verifier"): the sign-in
showed an error even when it had worked, or failed when the second exchange won the race. Measured on the OnePlus Pad 3
with a made-up code: two exchanges before, one after. A finished, failed or abandoned sign-in now leaves nothing behind
to be exchanged again, and the diagnostics report says whether a failed exchange came from the live sign-in or from
resuming one after the app was recreated. - If OpenRouter rejects the saved key ("User not found."), the error card is unchanged: it tells you to renew the key in
Settings. Signing in again, or pasting a new key, replaces it.
Install
This APK does not come from the Play Store, so Android treats it as
an app from an unknown source and will ask you to confirm. That is
expected.
arm64-v8a only, Android 8.0 or later.
Check you got the right file
sha256sum TALOS-0.1.40.apk
# b1ecf9ee1103dbbf7c57ae6162850ecc4f77456ec546adfbc8da283317212833And that it really came from this source, built here:
gh attestation verify TALOS-0.1.40.apk --repo Ninozzz95/talosWhat it was tested on
Two devices: a OnePlus 13 and a OnePlus Pad 3. Two devices are a
small sample, and Android ROMs diverge a good deal on
accessibility, background execution and lock screen behaviour.
What's Changed
- Desktop 0.1.21 by @Ninozzz95 in #47
- release(mobile): v0.1.40 — OpenRouter sign-in spends the code once by @Ninozzz95 in #48
Full Changelog: v0.1.39...v0.1.40
v0.1.39
What changed
Long conversations keep going on the phone's own model, the Qualcomm NPU ships, and chats can be
selected, archived and restored in bulk.
On-device models
- The Qualcomm NPU ships in the app, built with Qualcomm's official SDK. It turns on only after you accept
Qualcomm's software terms in the app, once, when you pick a local model; they stay available in Models. On
the OnePlus Pad 3 the first word arrives in about 1.0 s on the NPU instead of about 9.5 s on the GPU. - llama.cpp b11312, with Q4_K_M models running on the NPU.
- GPU programs are prepared for each installed model before you first use it, instead of compiling
for about 80 seconds on the first message after every update. - A model is fingerprinted once when it arrives, instead of being re-read on every open (24–29 s
each time before). - On-device models find the tools they need by search instead of reading a 65-line index.
- The context the phone can give a model is now measured correctly while the model is open: the
memory already holding the open conversation is counted back, so long chats are no longer refused
as they grow (before: "needs 6312 tokens, the device can give 3584"). The model's head size is read
from the file as declared (256 for Spark-X2.5-4B instead of 160), measured on the device at about
147,000 bytes of cache per token.
Chats
- Conversations are summarized automatically when they fill the context, right after a reply; a
message you send meanwhile waits. A line in the chat says "Conversation summarized · X → Y tokens"
with Undo, and "Compact now" in the chat menu asks first. The numbers are real tokens: the phone's
model counts them itself, and hosted models use the provider's count. A summary is kept only if the
next request gets at least 30% lighter. Measured on the Pad with Spark-X2.5-4B on a coding task:
8,427 → 4,264 tokens after seven turns, and the conversation went on. - Chats can be selected from a button next to the count, then archived, restored or deleted together.
The selection bar stays at the top while you scroll, and Undo brings archived chats back. - The TALOS logo fills three quarters of the assistant's circle.
- When a reply says an action is done ("Saved the note ✅") but no tool ran, TALOS asks the model once to
really do it, and if it still does nothing it says so under the reply: "No tool ran: nothing was done."
Seen with Spark-X2.5-4B saving a note.
Codice
- The Codice summarizes long sessions the same way, keeps the full history, and can undo.
- The Codice stays inside its folder: it can no longer write into TALOS's own files or outside the
session folder without asking. - Every failure is explained in words with one next action; interactive visuals are back.
- The session list no longer shows raw keys such as HARNESS.GROUPS.LAST7 as group titles; a finished run says
"Finished" instead of "Stopped"; the approval card says "approved" or "denied" instead of staying "waiting";
the strip counts "tokens" instead of calling the sum of every step "context".
Permissions and safety
- Tool permissions are answered at once, and the Stop button is never covered.
- The non-commercial "hey jarvis" wake-word model is no longer shipped.
Install
This APK does not come from the Play Store, so Android treats it as
an app from an unknown source and will ask you to confirm. That is
expected.
arm64-v8a only, Android 8.0 or later.
Check you got the right file
sha256sum TALOS-0.1.39.apk
# e9b5f9c18e69fc7c822e335ad01e07835765c8fe47f5fd98a9026b64d5dbcd8eAnd that it really came from this source, built here:
gh attestation verify TALOS-0.1.39.apk --repo Ninozzz95/talosWhat it was tested on
Two devices: a OnePlus 13 and a OnePlus Pad 3. Two devices are a
small sample, and Android ROMs diverge a good deal on
accessibility, background execution and lock screen behaviour.
What's Changed
- docs(readme): TALOS CLI, published on npm as talos-code 0.1.0 by @Ninozzz95 in #43
- TALOS Desktop 0.1.19: urgent fixes and pre-tag installer gate by @Ninozzz95 in #44
- Desktop 0.1.20 by @Ninozzz95 in #45
- release(mobile): v0.1.39 by @Ninozzz95 in #46
Full Changelog: v0.1.38...v0.1.39
TALOS Desktop desktop-v0.1.21
TALOS Desktop 0.1.21
Windows 10 1809 or later, x64, or Windows 11 x64. Node does not need to be installed.
Build and smoke test run on a Windows Server 2025 runner; the minimum Windows 10 compatibility still needs a test on that system.
What changed
TALOS now updates itself: it looks for a new version in the background, checks our signature, and installs it when you
close the app. The agent's commands get read-only tabs of their own in the Terminal, MCP servers can ask you for details
or to open a page, and the model can read Word, Excel, PowerPoint and PDF files.
Added
- Automatic updates. Thirty seconds after start and then every four hours, the app looks for a newer desktop
release, downloads it in the background and installs it when you close the app, or right away with Riavvia ora.
Every update manifest is signed with our Ed25519 key, and the app checks the signature before downloading anything.
A band under the title bar says when an update is ready; a card at the top of Account, Doctor e backup holds the
switch, on by default. If a session is working, Riavvia ora asks before restarting. Preview builds are not updated. - The agent's commands in the Terminal. Each turn of the agent gets a read-only tab, agente · giro N, with its
commands one under the other: the command, its output and how it ended. The tab appears without taking the one you
are using; its dot is green when every command succeeded and red when one failed; it can be closed but not renamed,
and it is rebuilt when you reopen the session. The commands you type with!stay in the chat and in Processi. - MCP servers can ask you. When a server needs details (a form with text, numbers, yes/no and choices) or wants
you to open a page (a sign-in, a payment), the chat shows a card that names the server. The page opens only when you
click, and what you type in the form goes to the server without staying on screen. - Office and PDF files can be read. The model gets the text of docx, xlsx, pptx and pdf files, with Hermes' limits,
instead of being told that they are binary. - A Stop for each command. In Processi every running command has its own Stop. The model is told that you
stopped it and not to run it again unless you ask, and the chat says Annullato, not that it failed. A command
waiting for your consent says so and has no Stop; a command you typed is marked tu. - On a first start with no provider ready, the Home shows Imposta un provider, which opens the Provider tab of the
model lab. Ollama and LM Studio with a saved address count as ready.
Changed
- The floor for commands that cannot be undone is Hermes' in full, and looks behind wrappers. Deleting the root,
formatting a disk, shutting down and the like are refused at every permission level, now also behindsudo -u,
timeout,nice,env,evaland similar wrappers, while the same words inside quotes no longer trigger it. The
refusal says what the floor is and what it is not. - Scrive nel progetto keeps writes inside the session folder, measured on the real path: absolute paths,
../and
junctions included. The path is measured again right before the write. - Network paths (
\\server\share) are never contacted without a yes. Reading, listing and writing ask first, with one
card per file; a session folder on a share asks once per session. - A delegated sub-agent gets its parent's permissions by default, and never more: under a read-only parent it starts
read-only. - The delegation graph uses the Workflow graph's controls and movements, and its minimap shows only when the graph does
not fit. - The default interface size is back to Predefinita, and the TALOS mark fills the orb.
Fixed
- A command now ends when it exits, even if a program it started in the background keeps its output open; before, the
reply waited and Stop did not end it. - Editing a file that is not UTF-8 no longer damages it: a Windows-1252 file lost its accented letters for good while
the reply said the rest was untouched. The edit is now refused and names the first byte that is not UTF-8, and file
tools report sizes in bytes. - In the Linux home, Consenti in questa cartella covers the whole folder, and a file changed by someone else while
its approval card was open is not overwritten. - On a worktree created by Git for Windows, Linux git's «not a git repository» is explained, with its cause and the fix
(git worktree repair --relative-paths). - A long delegation no longer fills the memory: its timeline is capped and each round costs the same as the first.
- The loading indicator of a long conversation shows from the click.
- In the chat, the outcome of a consent card (Approvato, Negato) and of an MCP card is again a small pill in its
colour, and the reason on a consent card is small and muted. The retained-output reader keeps its size and speaks
plainly; the command card no longer shows the line about retained output that is meant for the model; and the right
side of a command row shows the command instead of repeating its description. - Reopening a session no longer says «da un’altra finestra» for an answer given in this window, and no longer shows an
invented duration for a command you typed.
Known limits
- Automatic updates start with this version: from 0.1.20, install 0.1.21 by hand once.
- The outcome lines of commands are in Italian even when the interface is in English.
- The limits listed for 0.1.20 still apply, except the one about a background program keeping a command's output open,
which is fixed.
Install
Open TALOS-Setup-0.1.21.exe: NSIS installer for the current user, no administrator prompt.
Alternatively extract TALOS-0.1.21-win.zip in full and open TALOS.exe, keeping resources and the DLLs next to the executable.
The v0.1 is not code-signed: SmartScreen may show "Windows protected your PC" and an unknown publisher.
After checking the SHA256 and the provenance, choose "More info", check the name TALOS-Setup-0.1.21.exe, then "Run anyway" if you intend to proceed.
If your device management blocks that option, ask your administrator. Do not turn SmartScreen or Defender off.
The GitHub attestation certifies where the build came from; it is not an Authenticode signature and does not remove the SmartScreen warning.
What is inside
An Electron 44.3.0 shell with the Node runtime included, the TALOS backend, the built frontend, the kernel, the context engine, native addons, and llama.cpp b10517 CPU/Vulkan builds with their licences.
Vulkan needs a compatible driver; the CPU engine is included as the alternative.
Node.js 24.18.0 and ripgrep 15.0.0 for Linux, with their licences: when WSL is installed and a session runs its commands in Linux, the file tools run there too, with these binaries. Nothing is installed inside the WSL distribution.
No GGUF model and no credential is bundled, and there is no telemetry.
Automatic updates
The app checks for a new desktop release when it starts and every 4 hours, downloads it in the background and installs it when you close the app, or at once with Riavvia ora. latest.yml is signed with an Ed25519 key (latest.yml.sig): the app verifies the signature with the public key it carries before downloading anything, and checks the downloaded installer against the signed SHA-512 before installing it. Automatic updates can be turned off in Settings, under Account, Doctor e backup.
Remote providers and model downloads need the network and their own configuration; this installer does not certify that they work.
Check the SHA256
Compare both values with SHA256SUMS.txt and with the ones published here:
6f084e35ae94fa049fe654219319b05d515ec8247323a01a402667ea1c39da71 TALOS-Setup-0.1.21.exe
9e3e694183fea1d67b1b3e6ef11fc41d4a68b34a60ccc956cb088fb357fc7e81 TALOS-0.1.21-win.zip
3998e463c7d267f201ec983c2bbfa4acc8fe332aced50ebfbb11c4f038f871a6 latest.yml
0818c983ee955f72c48dc8ee0dcaeaeb342d82cd74ab80b9d09560ce79bc40e0 latest.yml.sig
Get-FileHash -Algorithm SHA256 .\TALOS-Setup-0.1.21.exe
Get-FileHash -Algorithm SHA256 .\TALOS-0.1.21-win.zip
Get-Content .\SHA256SUMS.txtCheck the GitHub provenance
With the GitHub CLI installed, verify every file you downloaded against the repository that produced this release:
gh attestation verify .\TALOS-Setup-0.1.21.exe --repo Ninozzz95/talos
gh attestation verify .\TALOS-0.1.21-win.zip --repo Ninozzz95/talosThe provenance ties the artifacts to the workflow and to the commit of tag desktop-v0.1.21.
The desktop job runs the gates before packaging, then verifies silent install, start of the installed EXE, health with cookie, reload, close and uninstall with no processes left behind.
TALOS Desktop desktop-v0.1.20
TALOS Desktop 0.1.20
Windows 10 1809 or later, x64, or Windows 11 x64. Node does not need to be installed.
Build and smoke test run on a Windows Server 2025 runner; the minimum Windows 10 compatibility still needs a test on that system.
What changed
Commands and file tools now work in the same place: with WSL installed, a session's shell and its reads, writes and
searches run in the same Linux, using a Node.js and a ripgrep for Linux that ship inside the installer. Long files,
large projects, long web pages and command output are also easier for the model to read in full.
Added
- One place for commands and files. With WSL installed and commands set to Automatico or Linux (WSL2), the
model's file tools — read, write, edit, list and search — run in the same Linux as its commands, through Node.js
24.18.0 and ripgrep 15.0.0 for Linux bundled in the installer (hashes pinned and checked again when the package is
built). Nothing is installed in your distribution. The model works with Linux paths; permissions, receipts and the
Review show the Windows path of the same file. Windows keeps everything on Windows, as before. - The Linux user is stated. The permissions sheet says which Linux user runs the commands and what holds on the
Windows drives: there is no isolation, and/mnt/cis your Windows disk. A switch, on by default, uses a normal
user when the distribution has one, and shows the command to create one when it has none. When a command would run
as root and nobody would otherwise be asked, TALOS asks once per session. - Searches that keep going. In a very large project a search is no longer stopped at 20 seconds and handed to a
slower fallback: the reply shows what was found so far, the search keeps running in the session (at most two at a
time, ten minutes each), and the model picks it up again by reference. Results come in pages. Folders inside WSL
get 60 seconds, and when the system runs out of threads ripgrep is retried on one thread. - Long web pages are kept whole. When a page is too long for the model, the full text is saved with the session
and the note at the top of the page says exactly how to read the part in the middle. The saved pages are deleted
with the session. - Files are read by lines. The model reads up to 2,000 lines or 100 KB at a time and continues where it stopped;
a single line too long to show is continued from the byte where it was cut. Binary files can be read as hex, and an
empty file says that it is empty. - Command output that lasts. The output of the model's commands is kept per session: it can be read back after a
restart or a crash, viewed in its own panel, downloaded in full and deleted. Output that a Windows program writes in
an OEM code page (cp850 in Italy, for example) can be read in that code page instead of being reported as binary,
and the preview says when it is not faithful UTF-8. - Provider retries you can see. When a provider fails, the chat shows the automatic retry with a countdown and a
Stop, and the wait the provider asks for is honoured, in seconds or milliseconds. - Long conversations open already scrolled to the end, behind a loading indicator, instead of being built in view and
stopping above the last answer. - A sub-agent's result in the chat is rendered as Markdown, with Mostra tutto when it is long.
Changed
- The model must have read a file in full before it replaces it, and the file must not have changed since; otherwise
the write is refused, with the two ways out (read it first, or edit only the part that changes). A replacement says
that it replaced a file. - A read-only session, and every workflow step, can still show an artifact but no longer copies it into the
Library. - The dialog that configures a provider has a single Salva: it saves the key you pasted and the changed address or
timeout, closes, and confirms. Errors stay inside the dialog. - Riprendi il lavoro on the Home lists your conversations, not the helper sessions of a delegation.
- Choice cards (permissions, web search source, model files) align their content to the top, so the titles in a row
line up. - When the context does not fit, a long first turn can be compacted inside the turn; your request stays word for word
above the summary. - The model is told how long a workflow run has been idle, not only how long it ran up to its last event.
Fixed
- In the desktop app, Accedi con OpenRouter did nothing: the window only let github.com addresses reach the system
browser. It now opens OpenRouter's sign-in page in the system browser, and only that page, only when the sign-in comes
back to this app or shows its code on screen. - A command that reaches its time limit now stops together with everything it started. On Windows the program under
the shell kept running, and the reply waited for it to end by itself. - Stopping a command that has already exited no longer targets its process id, which Windows may have given to
another program in the meantime. - In the installed app, a test run in a folder with no test suite reported success, because it started a second copy
of TALOS. It now exits 127 and says that no test suite is configured. - A Linux symbolic link on a Windows drive, which Windows cannot follow, is explained — where it points and what to
do — instead of being reported as a permission error or a missing file. - A local provider that answers 401 or 403 when no key was sent no longer reports a rejected key.
- An error whose outcome is uncertain says so, without claiming that the request was not sent. After a crash, an
interrupted request is not sent again at startup, and what had already arrived is recovered. - OpenRouter's 402 answers are told apart: a budget that is only temporarily committed is waited for; a key limit or
exhausted credit is reported, never worked around with another key or provider. - A tool that changes files no longer reports success when its reply is missing, false or invalid.
- A read inside a long line that hits an invalid byte says which byte it is and how to inspect it.
- Searches name the paths ripgrep could not read instead of reporting a generic error, and searches by file name are
complete. - Artifacts and Library cards keep pointing to the exact item they were made from.
- On Windows, a path that starts with a single slash, which can mean two different places, is refused instead of
guessed.
Known limits
- Running file tools in Linux needs WSL 2 and a project folder reachable from Linux. Under heavy load the WSL service
can stop answering for about 30 seconds; TALOS retries once before its Linux process is ready and records the
retry. - A forked conversation reads its parent's saved web pages only after asking.
- If the app is killed, a search still running in the background ends on its own.
- On Windows, a command that leaves a program running in the background with its output still open (for example
start /bin cmd) keeps the reply waiting, and Stop does not end it; in Linux (WSL) the reply arrives only at the
time limit, and what the command printed may be lost. Use a separate terminal for servers that must keep running. - The model has no tool to stop one of its own commands: Stop and the time limit do.
- TALOS records when an answer was cut by the output limit, but the desktop app does not show it yet.
Install
Open TALOS-Setup-0.1.20.exe: NSIS installer for the current user, no administrator prompt.
Alternatively extract TALOS-0.1.20-win.zip in full and open TALOS.exe, keeping resources and the DLLs next to the executable.
The v0.1 is not code-signed: SmartScreen may show "Windows protected your PC" and an unknown publisher.
After checking the SHA256 and the provenance, choose "More info", check the name TALOS-Setup-0.1.20.exe, then "Run anyway" if you intend to proceed.
If your device management blocks that option, ask your administrator. Do not turn SmartScreen or Defender off.
The GitHub attestation certifies where the build came from; it is not an Authenticode signature and does not remove the SmartScreen warning.
What is inside
An Electron 44.3.0 shell with the Node runtime included, the TALOS backend, the built frontend, the kernel, the context engine, native addons, and llama.cpp b10517 CPU/Vulkan builds with their licences.
Vulkan needs a compatible driver; the CPU engine is included as the alternative.
Node.js 24.18.0 and ripgrep 15.0.0 for Linux, with their licences: when WSL is installed and a session runs its commands in Linux, the file tools run there too, with these binaries. Nothing is installed inside the WSL distribution.
No GGUF model and no credential is bundled. The shell adds no automatic updates and no telemetry.
Remote providers and model downloads need the network and their own configuration; this installer does not certify that they work.
Check the SHA256
Compare both values with SHA256SUMS.txt and with the ones published here:
534ea7c3ccb2ba6301ac2ad47df7cb0f839342ab885919ae800415f57de6e1cb TALOS-Setup-0.1.20.exe
4c72454abea4957d3f4dc19b4c9d690780054444fbde997cb54fcf8932c4102c TALOS-0.1.20-win.zip
Get-FileHash -Algorithm SHA256 .\TALOS-Setup-0.1.20.exe
Get-FileHash -Algorithm SHA256 .\TALOS-0.1.20-win.zip
Get-Content .\SHA256SUMS.txtCheck the GitHub provenance
With the GitHub CLI installed, verify every file you downloaded against the repository that produced this release:
gh attestation verify .\TALOS-Setup-0.1.20.exe --repo Ninozzz95/talos
gh attestation verify .\TALOS-0.1.20-win.zip --repo Ninozzz95/talosThe provenance ties the artifacts to the workflow and to the commit of tag desktop-v0.1.20.
The desktop job runs the gates before packaging, then verifies silent install, start of the installed EXE, health with cookie, reload, close and uninstall with no processes left behind.
TALOS CLI 0.4.0
npm i -g talos-code@0.4.0, or talos update to see it.
Sub-agents now work in the background while you keep talking to TALOS, and TALOS runs on the same kernel as the
TALOS desktop app.
Added
- Background sub-agents. A delegated agent no longer holds the main agent's turn: the main agent answers at once,
the agent works on, and when it ends TALOS answers its result in a new turn. The result is shown as an agent row
("◆ Agent finished · ", three lines of its summary, the rest with the transcript's expand), never as your
message. /agents(also/subagents, and Alt+A): the agents of this session with what each one is doing (its last three
steps).xor Ctrl+X stops the selected one;/agents stop <n|id|all>and/agents show <n|id>name them.- The status line says "2 agents working" while only agents work, and "· 2 agents in background" while TALOS works too.
- Leaving with agents at work asks first.
/exitoffers: wait for them and exit by itself once TALOS has answered
their results, stop them and exit, or stay. The first Ctrl+C says how many agents an exit stops. talos -pwaits for its agents and the turn that answers them, and prints both answers. Ctrl+C, the timeout or a
failed turn stop the agents still working.agentsin the configuration (user or project-user file):maxConcurrent(1–32, default 10),maxDepth(1–4,
default 2),model(provider:model) andreasoningEffortfor the agents. A repository's.talos-clicannot set
them: they are ignored with a notice, likereasoningEffort.- When an agent's work woke TALOS, the desktop notification says which agent finished; the terminal's progress
indicator stays on while agents work.
Changed
- TALOS uses the kernel of the TALOS desktop app (one kernel for both): long outputs are cut in the middle with the
total kept, retries follow the provider's own wait, read rows show the file's real line count, Linux symbolic links
on a Windows drive are explained instead of reported as a denied permission, and a WSL command declares its user. - Answers wrapped in a
```markdownfence are drawn as Markdown, and---is a rule. - A search row says "2+ results" when the scan was not complete (a file that could not be read, a Linux link, a time or
size limit), instead of a count that read as final.
Fixed
- Git submodules and nested repositories no longer block the tools; their files are covered by
/undo, their Git
history is not, and that is said. - A local provider without a key (for example Ollama) that answers HTTP 401 or 403 is no longer reported as a refused
key: TALOS says to check the endpoint or the server's permissions. - A key benched after repeated provider errors (no provider for the model, a timeout, the network) now says to wait or
choose another model with/model, instead of "add another key", which would not help. - In a read-only session an artifact is no longer copied into the Library.
talos -p: Ctrl+C with TALOS idle ends at once.
Known limits
- Ollama with a real model was not tested for this release (owner decision); the provider is covered by fake-provider
tests only. - The physical mouse selection of 0.3.3 is still untested on a real terminal by the owner.
- macOS and Linux were not run; the private CI is blocked by Actions billing.
Verification
- Typecheck and build pass. Unit: 2,084 tests, 2,080 pass, 4 skipped, 0 fail. Acceptance on the built CLI in a real
pseudo-terminal: 297 of 297, including the new s39 (background agents:/agents, stop,/exitwait,talos -p).
Standalone package check: pass. - Tarball (2.4 MB, 508 files) installed with
npm install -gfrom an outside folder into an isolated prefix and
profile in 13 s:talos --versionprints 0.4.0, andtalos doctor --jsonpasses every check (configuration, data
and cache paths, git, keyring, kernel, project, MCP, hooks), asking only to choose a provider.
TALOS CLI 0.3.3
npm i -g talos-code@0.3.3, or talos update to see it.
Reliability fixes: select and copy the conversation with the terminal's own mouse selection again, see how long
quick turns took, understand a paused compaction, and ask any subcommand for JSON.
Changed
- Mouse tracking is now off by default, so dragging selects conversation text and right-click or Ctrl+C copies it,
as in any terminal program. Wheel scrolling is still available: turn it on in/configfor the current project
(it applies from the next launch) or setui.mouse: true. With it on, hold Shift while dragging to select.
A savedui.mouse: truekeeps working as before. - A turn that ends in under a second now shows its duration ("done 0.4s"). A resumed conversation no longer shows
the time it took to replay a turn as if it were the turn's own duration. - The room kept for the answer (sent to the model as
max_tokens) is now the smaller of the model's stated maximum and
32,000 tokens, never more than a quarter of the window, instead of the model's whole stated maximum. Conversations get
more room before compaction. Your ownmodels.<provider:model>.maxOutputTokensis kept as set; set it for answers
longer than 32,000 tokens.
Fixed
- Models whose provider states a maximum output close to the whole window (for example 943,717 of 1,048,576 tokens)
no longer stop before the first request with "context window is too small". If your own setting still leaves no
room, TALOS uses its simple mode instead of refusing, and the error, where it can still appear, names the reserve.
/contextshows the reserve and where it comes from. - When compaction is paused after a refused summary,
/contextshows the error code, the number of attempts, the
full date and time (UTC) of the next automatic try, and that/compacttries now and may call a billed model at a
cost that is not estimated. The notice in the conversation shows the full date instead of only the hour, and the
pause survives a restart until its deadline. --jsonafter a subcommand (for exampletalos config list --json,talos checkpoint list --json) selects JSON
output, like--jsonbefore it. Anything after--is still passed through as written.
Known limits
- Tested on Windows 11 x64 with Node.js 24.18 or later in the 24 line; macOS/Linux and the native installer are not
certified by these checks. - Native mouse selection was checked with automated terminal tests and by hand in Windows Terminal (drag to select,
right-click and Ctrl+C to copy, Ctrl+C without a selection still offers to exit); other terminals were not checked
by hand. - Compaction against a real Ollama server was not run; the compaction path was checked with an Ollama-shaped local
test server. - Unchanged from 0.3.2: the read tool describes binary files instead of passing images/audio; MCP non-text results and
image budgets across long conversations need further work; long pastes can appear expanded in queued messages and
resumed conversations. - A local provider that answers 401/403 without a key can still suggest replacing a key; the fix is not in this
release. - An answer cut off because it reached the reserve is not yet announced as cut off.
Verification
- CLI unit suite: 2,018 tests, 2,014 pass, 4 skip, zero failures. Complete terminal acceptance: 292/292 on an
otherwise idle machine (two earlier runs under heavy parallel load each had one timing failure in the test harness,
not reproduced alone; they are tracked as open). - Installed package from the release tarball: standalone install from an empty prefix, fast-turn duration, compaction
cooldown after restart, mouse off by default and on by opt-in,--jsonafter a subcommand, no outbound traffic and
no writes into the package. - The bundled kernel is the same as in 0.3.2 (kernel files copied from the same kernel commit).
- These are Windows filesystem/terminal checks with local scripted providers, not live cloud-model evaluations.
TALOS Desktop desktop-v0.1.19
TALOS Desktop 0.1.19
Windows 10 1809 or later, x64, or Windows 11 x64. Node does not need to be installed.
Build and smoke test run on a Windows Server 2025 runner; the minimum Windows 10 compatibility still needs a test on that system.
What changed
This release candidate addresses workflow results, chat attachments and settings lost after a
restart. It also adds visible history and output controls to the workflow Board.
Added
- Non-image files chosen, pasted or dropped into chat are copied into the session workspace before
they are attached. The UI waits for the upload receipt and passes the real relative path to the
agent. Each file is limited to 25 MiB; collisions receive a distinct name. - Workflow history can be searched and filtered by state. The Board opens a run by its exact ID,
pages through its results and offers the complete text or an explicit download for binary output.
Fixed
- A dependent workflow step can read a completed direct predecessor's result without gaining
workflow control. Multiple results require an explicit selection; binary results are not decoded
as text, and links are not downloaded implicitly. - Results from delegated child sessions remain queued durably and wake an idle parent once with the
pending results. Stopped or unsettled parents keep the results for explicit recovery. - A request to enter Plan mode takes effect only after the turn and settings write succeed. The
banner and next turn follow the persisted mode, including after a restart. - A workflow start receipt opens the run it created, even when another run of the same version
exists; ambiguous starts do not claim an unrelated run. - System settings, including sidebar widths and chat/interface text sizes, persist across normal
restarts. New profiles start with a large interface, default chat text and compact lists. The
last recorded origin from a 0.1.18 installation is reused on upgrade without deleting older
browser data. - Chat file uploads use a bounded stream and a verified workspace root. The upload helper does not
inherit server credentials, and Playwright reports no longer serialize the test server's full
environment.
Known limits
- Settings stored in origins older than the last recorded 0.1.18 origin, or in an origin without a
reliable launch record, remain intact but are not imported automatically. - A real Space Bunny Alpha run verified file reading, the exact answer and chat/model replay after
reload. The other model-driven workflow, delegation and upload-to-reading scenarios have
deterministic contract and browser coverage but have not all been certified with a live model.
Install
Open TALOS-Setup-0.1.19.exe: NSIS installer for the current user, no administrator prompt.
Alternatively extract TALOS-0.1.19-win.zip in full and open TALOS.exe, keeping resources and the DLLs next to the executable.
The v0.1 is not code-signed: SmartScreen may show "Windows protected your PC" and an unknown publisher.
After checking the SHA256 and the provenance, choose "More info", check the name TALOS-Setup-0.1.19.exe, then "Run anyway" if you intend to proceed.
If your device management blocks that option, ask your administrator. Do not turn SmartScreen or Defender off.
The GitHub attestation certifies where the build came from; it is not an Authenticode signature and does not remove the SmartScreen warning.
What is inside
An Electron 44.3.0 shell with the Node runtime included, the TALOS backend, the built frontend, the kernel, the context engine, native addons, and llama.cpp b10517 CPU/Vulkan builds with their licences.
Vulkan needs a compatible driver; the CPU engine is included as the alternative.
No GGUF model and no credential is bundled. The shell adds no automatic updates and no telemetry.
Remote providers and model downloads need the network and their own configuration; this installer does not certify that they work.
Check the SHA256
Compare both values with SHA256SUMS.txt and with the ones published here:
a4bdd8ddd460804753ca24d928c77268adf0859dec3869daafa0e86800bda0af TALOS-Setup-0.1.19.exe
94f45faab3e25f34a80c7bc9621092ac6d43b809b3332f1bd7df5a9a92f2015e TALOS-0.1.19-win.zip
Get-FileHash -Algorithm SHA256 .\TALOS-Setup-0.1.19.exe
Get-FileHash -Algorithm SHA256 .\TALOS-0.1.19-win.zip
Get-Content .\SHA256SUMS.txtCheck the GitHub provenance
With the GitHub CLI installed, verify every file you downloaded against the repository that produced this release:
gh attestation verify .\TALOS-Setup-0.1.19.exe --repo Ninozzz95/talos
gh attestation verify .\TALOS-0.1.19-win.zip --repo Ninozzz95/talosThe provenance ties the artifacts to the workflow and to the commit of tag desktop-v0.1.19.
The desktop job runs the gates before packaging, then verifies silent install, start of the installed EXE, health with cookie, reload, close and uninstall with no processes left behind.
TALOS Desktop desktop-v0.1.18
TALOS Desktop 0.1.18
Windows 10 1809 or later, x64, or Windows 11 x64. Node does not need to be installed.
Build and smoke test run on a Windows Server 2025 runner; the minimum Windows 10 compatibility still needs a test on that system.
What changed
Same product as desktop-v0.1.16 and desktop-v0.1.17, which never published: both release jobs
stopped at the install smoke, and a published tag is never rewritten, so this attempt gets a new
number. The fixes for those stops are the first four under Fixed.
The biggest release so far: the model can plan, ask and run workflows with you, the app reads your
files and your git repository, and the window and the installer become TALOS's own.
Added
- Workflows. The model can propose a workflow — steps grouped in phases — as a short draft that
the server compiles and checks. It appears as a card in the chat: you approve it (or change its
limits, which makes a new version to approve), start it, and follow it in a diagram at the centre
of the chat. Steps run as read-only sessions, several at once, and a failed step is retried
according to why it failed. A run can be paused, resumed, cancelled, and its failed steps retried;
after a restart, a run picks up where it was. The Agents column follows the same run. - Plan mode. The mode selector offers Normale and Piano. In Piano the model presents a
plan on a single card that updates in place, and you choose: proceed asking before edits, proceed
accepting edits, proceed in a clean conversation, or keep planning with your feedback. A pending
plan survives a restart. Sub-agents started before the switch keep working. - Questions from the model. The model can stop and ask: up to four questions at a time, each
with two to four options and room for your own answer. Questions come one at a time, a question
survives a restart, and the sidebar shows which conversations are waiting for you. A time limit
for unanswered questions is optional, in Settings. - File reader. Files open in the right column, full screen, or from the Library: text, code,
Markdown, CSV, images, PDF, Word, Excel and PowerPoint, and HTML pages (their scripts run, the
network stays blocked, and the source is one click away). The type is told from the name and
from the bytes. - The GitHub tab. Your changes grouped as git sees them, with the diff of each file in the
column; stage, unstage or discard a whole file or a single hunk; commit what is staged; amend or
undo the last commit; create, switch, rename and delete branches; stash and restore; a history
graph with what is incoming and outgoing, where a commit opens its own changes. Fetch, pull and
push from the tab header — a push is never forced and always says where it goes. Pull requests
through the GitHub CLI: see, draft, create and check them. A commit message can be generated
with the session's model, or the commit handed to the agent. A folder that is not a repository
offers Initialize Repository, as in VS Code: local only, no GitHub account needed. - Sections the model can use. Your memories reach every new chat, and the model can list and
search them by words; it can also search and read your notes, tasks and research, browse the
Board, and find and read your past conversations, with a link that opens them. - A compact activity segment in the chat: what the model did in a turn, summarised in one row,
with a live phrase while it works, the failure pinned when there is one, and filters. - Context you can see. A warning before the context fills up, a live bar while a summary is
written, and a "X → Y tokens" row with Undo. The Context Manager button always opens its window;
compacting asks first. - The window has its own title bar: the window buttons follow the theme, and the "⋯" button
opens the app menu. - An assisted installer, in Italian: a welcome page, the AGPL licence with a plain summary of
what it allows, install for the current user without administrator rights, and "Avvia TALOS" at
the end. Uninstalling also removes TALOS's temporary files. - A deep research shows a progress bar with its phase and real counts.
- An automation remembers the model it was created with, and says so.
- Forge is the default theme, and the theme studio lists it first.
Changed
- The Workflow mode is retired: delegation and questions are tools of Normale. A session saved
in Workflow mode opens with a banner that says so. - Library and research files live in TALOS's own data folder, no longer inside your project folder.
- Providers and keys are managed only in the Model lab.
- Notifications sit at the bottom beside the composer, and climb over it only when the sides are
full. - The conversation is saved as small deltas with checkpoints instead of being rewritten: long
sessions open and save faster, and a file cut short by a crash is repaired on the next start.
Performance
- Reads the model asks for in the same answer run together, and they start while the answer is
still streaming. - Searches use ripgrep, and the git state is read from files when a session starts.
- A long workflow history replays in linear time instead of quadratic.
Fixed
-
The installed app's local server now starts. Packaging dropped
src/scratch.mjs: a rule meant
to keep scratch folders out of the package also matched that file's name, so the installed server
failed five times in a row with "module not found" and gave up. It was invisible to the tests,
which run the app from source; launching the packagedTALOS.exebefore this release found it.
The rule now applies only to folders, and a new test requires every production source file to be
in the package. -
The install smoke recognises the app's uninstall entry. The installer registers it as
"TALOS 0.1.18" (product name and version); the smoke looked for exactly "TALOS", found nothing,
and its registry checks had been passing without looking at anything. -
The install smoke looks for the app where the new installer puts it. The assisted installer
installs toPrograms\TALOS, named after the product; the one-click installer used the package
name,Programs\talos-desktop(electron-builder 26.16.1,NsisTarget.js:179). The installer
had worked, and the smoke looked in the old folder and reported "installed EXE missing". It now
also reads the folder the installer declares in the registry, and if the two differ it says
where the app went. An update from an earlier version keeps its folder, because the installer
reads the previous location first. -
A test of delegation from a local model no longer races with itself. The parent does not wait
for its child, so the parent's next request — which repeats the delegated task inside its own
tool call — could reach the engine first. The test took that echo for the child and stopped the
child before it spoke, about one run in five. It now waits for the child's own request. -
An answer cut off mid-stream continues instead of ending the turn; an empty answer
is no longer mistaken for an interrupted one, and a failed turn keeps the work it did. -
A reasoning level costlier than the one you chose is never sent.
-
Reading a file stops at 1 MiB and says so, and a binary file's bytes never end up in the
conversation. -
While following a streaming answer, the view never jumps up; a conversation that fits the screen
no longer scrolls. -
The orb stops on Stop and on any error.
-
Sessions can be created on disks without hard links (exFAT, FAT32, ReFS).
-
A missing or failing local engine, a full context and a model too big for memory are each said
for what they are, instead of looking like a provider refusal. -
Automatic compaction pauses after a refused summary, says for how long, and shortens the kept
tail under pressure instead of giving up. -
Tooltips no longer reopen after a click; chip labels in the composer are no longer cut; select
arrows use the icon.
Verification
- The release gates, in the order the release workflow runs them, on this commit:
- server: 4,643 of 4,653, 10 skipped, no failures;
- kernel: 615 passed, 1 skipped;
- frontend unit: 1,698;
- desktop pure: 105;
- the real Electron shell: 3;
- the installer builds (156.6 MB).
- The packaged app, launched before tagging with the release smoke's own launcher and a separate
data folder:- the page is ready in 1.6 s and health answers 200 with the cookie;
- it closes in 1.2 s;
- 648 MiB at rest.
This is the step that found the missing module.
- The install and uninstall part of the smoke runs in the release job only. The machine that built
this release has an earlier TALOS installed, and the smoke refuses to touch it by design. - Known intermittent, not seen in this run: a test server can hit an internal libuv assertion while
it exits after a clean shutdown (about one run in ten under full load). kernel:controllastill reports the declared divergence from the mobile kernel source (11,711
lines against 6,260), as indesktop-v0.1.15.
Install
Open TALOS-Setup-0.1.18.exe: NSIS installer for the current user, no administrator prompt.
Alternatively extract TALOS-0.1.18-win.zip in full and open TALOS.exe, keeping resources and the DLLs next to the executable.
The v0.1 is not code-signed: SmartScreen may show "Windows protected your PC" and an unknown publisher.
After checking the SHA256 and the provenance, choose "More info", check the name TALOS-Setup-0.1.18.exe, then "Run anyway" if you intend to proceed.
If your device management blocks that option, ask your administrator. Do not turn SmartScreen or Defender off.
The GitHub attestation certifies where the build came from; it is not an Authenticode signature and does not remove the SmartScreen warning.
What is inside
An Electron 44.3.0 shell with the Node runtime included, the TALOS backend, the built frontend, ...
TALOS CLI 0.3.2
npm i -g talos-code@0.3.2, or talos update to see it.
Display settings in the terminal, clearer permission changes, and safer file reads, with conversation recovery
and workspace checkpoints preserved.
Added
/configchanges response width, notifications, mouse-wheel scrolling and exit output. Settings are private to you
in the current project. Response width updates immediately; the other settings apply on the next launch.- Focus-aware completion, failure and approval notifications, with fixed messages that contain no prompts, filenames
or model answers. Supported terminals also receive running/error progress indicators.
Changed
- Entering Full access requires an explicit confirmation. Changing permission mode also updates the current session,
so the next turn follows the mode shown on screen. - Turns without mutations avoid preparing a workspace checkpoint when no extensions are present. The checkpoint still
precedes writes and delegated work; projects with extensions retain the earlier preparation for compatibility.
Fixed
- File reads check a bounded binary sample before decoding. Text reads stop at 1 MiB, even without line breaks or when
a file grows during the read, and disclose incomplete reads at the beginning of the result. Binary sizes come from
the original file. Edit and checkpoint operations retain their full reads. - A completed turn settles its saved conversation before follow-up operations such as compaction and resume use it.
- Fragmented UTF-8 input preserves accents, CJK and emoji. Mouse-report filtering no longer alters matching sequences
inside bracketed paste or leaks incomplete report prefixes into the composer. - Command completion opens when fast typing arrives in one input chunk, preserving the whole prefix. Bracketed paste
retains its separate text behavior. - Builds refresh the bundled kernel, preventing a package from silently using a stale copy.
Known limits
- Tested on Windows 11 x64 with Node.js 24.18 or later in the 24 line. macOS/Linux and the native installer are not
certified by these checks. - Native desktop notification delivery still needs physical checks; automated checks intercept delivery. Other
terminal applications have not been verified on their target platforms. - The read tool returns a description for binary files, not their image/audio content. MCP non-text results and image
budgets across long conversations still need further work. - Long pastes can still appear expanded in queued messages and resumed conversations. Mouse interaction is wheel-only.
- Compaction retry cooldowns and extension startup costs still need broader stress testing.
Verification
- CLI unit suite: 1,998 tests, 1,994 pass, 4 skip, zero failures; complete terminal acceptance 292/292.
Kernel suite: 603 pass, 1 skip; 12 bounded-read tests and five additional edge-case checks pass. - The installed 0.3.2 candidate passes the bounded-read tests and real terminal flows through reading, command completion,
restart and resume. Upgrade from published 0.3.1, real write, checkpoint undo, rollback and redo pass. - Four independent mutations of the read limit, sample, byte count and tool dispatch are detected by the tests.
- The command-input regression and the test fixture's distinction between terminal controls and frames each detect
an isolated reintroduction of the defect. - These are Windows filesystem/terminal checks with local scripted providers, not live cloud-model evaluations.
The broader backend suite retains three pre-existing documentation/test-inventory failures.