Releases: Pepewitch/wisp
Release list
Wisp 0.6.7
Wisp 0.6.7
Wisp 0.6.7 gives Wisp its own look and a smoother feel. A small flame spirit
with two eyes replaces the glass icosahedron as the mark, and the interface
moves with one quick, calm motion throughout.
- A new mark. The Desktop app icon, the phone's home-screen icon, the
browser favicon and the mark in the top bar are the spirit now. - Tooltips that unfold. Hovering or keyboard-focusing a control shows
Wisp's own tooltip, instead of the browser's. - A composer that grows with your message. The message box grows line by
line as you type, instead of scrolling inside a fixed box.
What changed since 0.6.6
The spirit, Wisp's new mark
- The spirit replaces the glass icosahedron (#359): a small flame with two
eyes and no mouth. It is the Desktop app icon, the phone's home-screen and
touch icons, the browser favicon and the mark in the app's top bar. Small
sizes use a flat drawing of the same silhouette, so it stays legible at
16 px.
Motion
- Tooltips (#358). Every control that names itself on hover now shows
Wisp's own tooltip. The first one waits a moment, so a pointer crossing a
toolbar shows nothing, and the next one along a row opens at once.
Focusing a control from the keyboard shows it too; a field you are typing
in never gets one. Touch screens keep their usual long-press. - Menus, popovers and dialogs (#358) open from the control that opened
them and settle into place, then close a little faster than they opened. - The composer (#358) grows with your message, up to its usual limit, and
glides to each new height. Before, a long message scrolled inside a fixed
box three lines tall (two on a phone). - Reduced motion turns all of it off: with the system setting on,
everything appears and disappears at once, as before.
Fixes
- A connection tab carries one mark (#364): its connection's health, the
same on a selected tab and an inactive one. Before, an inactive tab could
also show the dot of its busiest task, so two dots sat side by side and
their colours collided: the amber of delayed live updates beside the amber
of a task waiting for input. Delayed or dropped live updates are now a
hollow grey ring. Which task needs you still shows in the connection
switcher's menu, and desktop notifications are unchanged. - DOMPurify 3.4.16 (#363). The sanitizer that cleans mermaid diagrams
moves past a low advisory
(GHSA-p98j-92pf-mc4p)
affecting 3.4.13 to 3.4.15.
Also
- The project README and the social preview are rewritten (#360, #361), with
a short film of what Wisp does.
Install or upgrade
Apple Silicon macOS (12.3 configured minimum):
brew install Pepewitch/tap/wisp Pepewitch/tap/wisp-desktop
open -a WispThe Cask installs the separate daemon Formula as a dependency. Name both:
Homebrew trusts only the fully qualified names you install from a non-official
tap, so the Cask alone refuses to load that Formula. Existing updater-capable
Desktop builds can use Updates → Check now, then Update Desktop and
relaunch. Update Local daemon separately. The legacy alpha
channel URL remains compatible and advertises the regular 0.6.7 version.
For Homebrew recovery or older builds without an updater:
brew update
brew upgrade Pepewitch/tap/wisp
brew upgrade --cask --greedy Pepewitch/tap/wisp-desktop
brew services restart wisp
open -a WispLinux (Ubuntu 24.04 LTS, x86_64, glibc):
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/Pepewitch/wisp/v0.6.7/scripts/install.sh | shBack up task state and the original Git repositories before upgrading.
Follow backup and restore; copying .wisp
alone does not preserve linked worktrees or unpublished Git objects.
This release adds no database migration.
Scope and known limits
This release is for a trusted single OS user. Worktrees separate checkouts;
they do not sandbox agents or their credentials. There is no multi-user
permission boundary. Closing Desktop leaves daemons and agents running.
Intel macOS and non-Apple-Silicon Desktop builds are unsupported.
Desktop publication requires Developer ID signing, notarization, a stapled
ticket, and a verified updater signature. The public macOS daemon application
also requires Developer ID signing, notarization, and a stapled ticket.
Automated release gates verify immutable downloads and promote the Formula,
Cask, daemon channel, and Desktop channel together. At source
preparation, the 0.6.7 artifact gates are pending; the qualification ledger
records the final outcome separately from these immutable release notes.
Specific to this release:
- An existing Desktop install can keep showing the old icon in the Dock or
Finder until macOS refreshes its icon cache, for example after a restart. - Tooltips need a device with a pointer that can hover. On a phone or tablet
Wisp shows none, keyboard focus included, and leaves long-press to the system.
The Autopilot-tab, background-process, wisp audit and GitHub-use limits
listed for
0.6.6,
the updater-signing, Linux update manifest, error-boundary and older-daemon
composer limits listed for
0.6.5,
the task-brief limits listed for
0.6.4,
the shell-tab, plan-limit, and Desktop first-launch limits listed for
0.6.3,
and the auto-merge, auto-fix, review judge and draft limits listed for
0.6.2,
still apply.
Native dependency advisories still include upstream maintenance notices and a
locked Linux-only glib warning. Full clean-machine provider journeys, a
human-observed Desktop upgrade across this version, broad OS coverage, and
cross-machine restore remain incomplete. Task export excludes repositories and
provider sessions; it is not a complete backup or an import format. Permanent
deletion is logical, not forensic erasure. This release is not a security
certification.
Release assets
The release contains these ten immutable assets:
wisp-v0.6.7-linux-x86_64release-manifest.jsonSHA256SUMSwisp-v0.6.7-darwin-arm64.tar.gzrelease-manifest-darwin-arm64.jsonSHA256SUMS-darwin-arm64wisp-desktop-v0.6.7-darwin-arm64.tar.gzwisp-desktop-v0.6.7-darwin-arm64.tar.gz.sigrelease-manifest-desktop-darwin-arm64.jsonSHA256SUMS-desktop-darwin-arm64
Wisp 0.6.6
Wisp 0.6.6
Wisp 0.6.6 brings autopilot together in one tab and keeps it within GitHub's
limits. It also lets a Claude task leave a dev server running without holding
its turn open, and records who took each task action.
- An Autopilot tab. The task panel's first tab holds the brief, the
Auto-merge and Auto-fix switches with their live status, and the autopilot
history. - Lighter on GitHub. Wisp keeps its GitHub API use to a quarter of the
hourly limit and, when GitHub rate-limits it, says when it will resume. - Background processes don't hold a turn open. A Claude task that starts
a dev server finishes its turn and reads
Done · 1 background process running.
What changed since 0.6.5
Autopilot
- The Brief tab becomes an Autopilot tab (#354). The task panel's first
tab, still open by default, is now Autopilot.- The brief comes first, then the Auto-merge and Auto-fix
switches. While a switch is on, it shows the live status: the PR, the
reason and how long it has stood. The action that status asks for sits
under it: Resume, Continue now, or Send now / Skip. - History lists the latest autopilot events, and All history opens
a full log for each PR.#PRand commit links open on GitHub, and
View message scrolls to the message an auto-fix round sent. - When a long brief pushes the switches out of view, their status stays
docked at the bottom of the pane. - The task
…menu keeps the switches as shortcuts.
- The brief comes first, then the Auto-merge and Auto-fix
- Wisp keeps to a quarter of GitHub's hourly limit (#347). Autopilot and
the sidebar's PR status share that limit with every other tool you run
throughgh, so Wisp now keeps its own use to a quarter of it.- While it waits on a reviewer or an approval, it checks less often, and it
slows down when GitHub reports little left. - When GitHub rate-limits the account, the PR status reads
Paused: GitHub rate limit, resumes 14:05instead of
"GitHub unavailable", and a merge refused for the rate limit no longer
counts as a failed merge. wisp doctorgains agithub budgetcheck.
- While it waits on a reviewer or an approval, it checks less often, and it
Also new
- A background process no longer keeps a Claude turn running (#349).
When a Claude task starts a background process, such as a dev server, and
then answers, the turn finishes and the task reads
Done · 1 background process running. Hovering the state names the
process.- The process keeps running. The next message goes to the same process as
a new turn, and Stop ends it. - When the background work wakes the agent later, that becomes a
follow-up turn of its own, with no webhook and no "finished" banner. - A normal archive refuses while the process runs; force-archive stops it.
- A daemon restart stops a harness a finished turn left running, so the
next message resumes the session in a single process.
- The process keeps running. The next message goes to the same process as
wisp audit <task>shows who took each action (#345). Each task action
now records where it came from: the web app, Desktop, the CLI, an agent
inside a task, autopilot, or a workflow.- A changelog (#344).
CHANGELOG.mdlists every published release with
its summary and a link to its notes. - Wisp's own default models (#350). A new task with no model chosen and
noharnessDefaultsentry now starts on Wisp's default for its harness:
claude-opus-5-5for claude and droid,gpt-6.1-solfor codex, and
grok-4.7-highfor cursor. opencode keeps its own.- Wisp uses its default only when the installed CLI offers that model, so
an older CLI keeps its own default. - A model set in
harnessDefaultsstill wins, andwisp modelssays
which default applies. - The harness facts Wisp checks each CLI against are re-pinned to the
current CLI releases.
- Wisp uses its default only when the installed CLI offers that model, so
- Auto-fix waits for a reviewer bot to finish (#353). Some reviewer bots
edit their summary comment when their check starts, before the new review
is in. Auto-fix now holds a round while that bot's own check is still
running on the PR's head, for up to 20 minutes, then sends its findings
with everything else in one round. Stale rounds no longer use up the PR's
five.
Fixes
- Live input, queue order and setup scripts (#341).
- One failed write to a running turn no longer breaks every later write,
so a steer or a retried answer still gets through. - Queued messages are delivered in the order they were sent, even if the
system clock moves. - A setup script's leftover processes are stopped at its timeout. A normal
archive refuses while they run, and force-archive stops them.
- One failed write to a running turn no longer breaks every later write,
Performance
- 27% less JavaScript on first load (#343). The browser app loads the
terminal, the code highlighter and the gallery only when they are needed.
Switching back to a browser tab no longer resyncs a healthy connection,
and reconnects after a daemon restart back off instead of arriving all at
once.
Internals
- The daemon and the web app share their API types, task create and archive
move into domain operations, routes get one daemon context, and the daemon
tests are typechecked and hermetic (#342, #346, #348, #351, #352). The
release notes count migrations kept in their own files (#340), a
development-only dependency is pinned past new advisories (#356), and the
0.6.5 publication is recorded (#339).
Install or upgrade
Apple Silicon macOS (12.3 configured minimum):
brew install Pepewitch/tap/wisp Pepewitch/tap/wisp-desktop
open -a WispThe Cask installs the separate daemon Formula as a dependency. Name both:
Homebrew trusts only the fully qualified names you install from a non-official
tap, so the Cask alone refuses to load that Formula. Existing updater-capable
Desktop builds can use Updates → Check now, then Update Desktop and
relaunch. Update Local daemon separately. The legacy alpha
channel URL remains compatible and advertises the regular 0.6.6 version.
For Homebrew recovery or older builds without an updater:
brew update
brew upgrade Pepewitch/tap/wisp
brew upgrade --cask --greedy Pepewitch/tap/wisp-desktop
brew services restart wisp
open -a WispLinux (Ubuntu 24.04 LTS, x86_64, glibc):
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/Pepewitch/wisp/v0.6.6/scripts/install.sh | shBack up task state and the original Git repositories before upgrading.
Follow backup and restore; copying .wisp
alone does not preserve linked worktrees or unpublished Git objects.
This release adds database migrations 20 and 21, so a 0.6.5 daemon cannot reopen a profile that 0.6.6 has opened.
Scope and known limits
This release is for a trusted single OS user. Worktrees separate checkouts;
they do not sandbox agents or their credentials. There is no multi-user
permission boundary. Closing Desktop leaves daemons and agents running.
Intel macOS and non-Apple-Silicon Desktop builds are unsupported.
Desktop publication requires Developer ID signing, notarization, a stapled
ticket, and a verified updater signature. The public macOS daemon application
also requires Developer ID signing, notarization, and a stapled ticket.
Automated release gates verify immutable downloads and promote the Formula,
Cask, daemon channel, and Desktop channel together. At source
preparation, the 0.6.6 artifact gates are pending; the qualification ledger
records the final outcome separately from these immutable release notes.
Specific to this release:
- A daemon restart or upgrade now stops a background process, such as a dev
server, that a Claude task left running after its turn finished. - The client
wisp auditnames for an action is what that client reports
about itself. It is not authentication. - The autopilot history shows a PR's status only for the task's current PR.
- Wisp counts its own GitHub use in memory, so a daemon restart starts that
count again. - Against an older daemon, the tab keeps the name Brief and shows only
the brief, or has no History section.
The updater-signing, Linux update manifest, error-boundary and older-daemon
composer limits listed for
0.6.5,
the task-brief limits listed for
0.6.4,
the shell-tab, plan-limit, and Desktop first-launch limits listed for
0.6.3,
and the auto-merge, auto-fix, review judge and draft limits listed for
0.6.2,
still apply.
Native dependency advisories still include upstream maintenance notices and a
locked Linux-only glib warning. Full clean-machine provider journeys, a
human-observed Desktop upgrade across this version, broad OS coverage, and
cross-machine restore remain incomplete. Task export excludes repositories and
provider sessions; it is not a complete backup or an import format. Permanent
deletion is logical, not forensic erasure. This release is not a security
certification.
Release assets
The release contains these ten immutable assets:
wisp-v0.6.6-linux-x86_64release-manifest.jsonSHA256SUMSwisp-v0.6.6-darwin-arm64.tar.gzrelease-manifest-darwin-arm64.jsonSHA256SUMS-darwin-arm64wisp-desktop-v0.6.6-darwin-arm64.tar.gzwisp-desktop-v0.6.6-darwin-arm64.tar.gz.sigrelease-manifest-desktop-darwin-arm64.jsonSHA256SUMS-desktop-darwin-arm64
Wisp 0.6.5
Wisp 0.6.5
Wisp 0.6.5 is a reliability and security release. It fixes several ways the
daemon could freeze, crash, or lose work, closes gaps that agent output or
unauthenticated input could use, and makes finished tasks and search cheaper.
- The daemon stays up. Idle shells, a malformed harness line, or a client
disconnecting no longer freeze or crash it, and it stops gracefully when
asked to. - Updates ask first. Updating while tasks are running asks before it
interrupts them, in the app and inwisp update. - Steering says what it will do. While a turn runs, the composer says
whether a send steers the turn, starts the next one, or stops the turn.
What changed since 0.6.4
Reliability
- Idle terminal shells no longer freeze the daemon (#319). Shell tabs
read and write without holding the daemon's file worker threads, so idle
shells can no longer block everything else. - One malformed harness line no longer crashes the daemon (#317). Route
errors and background-loop failures are now logged instead of lost. - Turns keep their whole result (#316). Long final reports are no longer
cut at 16 KiB, a daemon restart no longer loses a turn's session, and every
turn now settles instead of staying open. - No second harness after a timezone or locale change (#318). Wisp no
longer mistakes a live harness for a dead one when the timezone or locale
changes, so it no longer starts a second copy. - Resumed Claude turns keep their background agents (#313). A resumed
turn no longer kills the agent's background agents after 10 minutes. - Data-safety fixes (#325).
- Archive refuses, and deletes nothing, when git cannot read a worktree's
status, so it never removes uncommitted work. - Removing a project no longer undoes changes made at the same time.
- An out-of-range config value falls back to its default, with a warning.
- Purge removes every related row.
- The instance ID is written atomically.
- Archive refuses, and deletes nothing, when git cannot read a worktree's
- Graceful stop and safer updates (#330). The daemon stops gracefully on
SIGTERM. Updating while tasks are running asks first: a dialog in the app,
a y/N prompt inwisp update, andwisp update --yesfor scripts. - Bun 1.4.2 (#329). The runtime moves to Bun 1.4.2, which fixes an
intermittent crash when a client disconnects. The Linux binary is smaller
and starts faster.
Security
- Desktop hardening (#321). The Local connection's token is never sent
through an HTTP proxy, external links open in your browser, the app asks
for narrower permissions, relayed responses are hardened, and Desktop
recovers from a corrupt connections file. - Agent-written diagrams and HTML are contained (#328). They can no
longer fetch remote content, navigate the window, or overwrite the page
around them. A diagram that would load remote content shows as source. - Daemon input and probes (#327). Unauthenticated input is size-bounded,
the claude usage probe runs from a private directory, prompts that start
with-are passed safely to cursor and opencode, every response sets
X-Content-Type-Options: nosniff, and large JSON responses are gzipped. - Tokens and webhooks (#335). Repeated wrong tokens are throttled,
webhook URLs are redacted in logs, and webhooks no longer follow redirects. - Safe
--helpand terminal output (#314).--helpnever runs a
command, and agent-written text can no longer drive your terminal with
escape sequences. - Autopilot merge gate (#331).
- A PR with more than 100 reviews is held, not merged.
- Text a bot relays from someone else can no longer instruct the agent or
let a merge through. - A PR from a fork can no longer hide the task's own PR.
- Each merge record carries the merged commit SHA and its evidence, and the
newwisp pr <task> historylists a task's auto-merge and auto-fix
history.
- Release pipeline (#322, #323). Release jobs run without caches and
with signing secrets scoped to the steps that use them, the installer and
updater accept only https, and undici is pinned past a denial-of-service
advisory.
Performance
- Finished tasks open without streaming their transcript (#332). Opening
one sent up to 25 MB to the pane; it now sends under 100 bytes.
/api/statusno longer runs git for every task on every event. - Search no longer stalls the daemon (#336). Search runs off the request
thread, the daemon boots faster, and retention cleanup does less work. - Lighter background work (#309, #311). The daemon-served app loads
Mermaid only when a diagram needs it, and automatic harness limit probes
are throttled. - CI now enforces performance budgets (#337).
Visibility
wisp doctorreports more (#335): crash loops, failing or dead
webhooks, the last self-update,ghauthentication, every project, and
background-loop health. Daemon log lines now have timestamps.
App
- One bad render no longer blanks the app (#333). A rendering error
degrades only the pane it happened in. - Brief tab (#320). The task brief moves from the band above the
conversation into a Brief tab, first in the task panel and open by
default, with an on/off switch. The conversation gets its full height back. - Steering says what a send will do (#326). While a turn runs, the note
above the composer says whether a send steers the turn, starts the next
turn, or stops the turn and then sends. A toggle beside the send button
holds one message for the next turn, and a queued message has a
send now action. - iOS home-screen app (#312). Touch headers stay clear of iOS's top blur.
Docs and hygiene
- Documentation fixes for attachments, versioning, config, and the security
boundary (#315). - CI, test, and dependency upkeep (#310, #324, #334), and the 0.6.4
publication record (#308).
Install or upgrade
Apple Silicon macOS (12.3 configured minimum):
brew install Pepewitch/tap/wisp Pepewitch/tap/wisp-desktop
open -a WispThe Cask installs the separate daemon Formula as a dependency. Name both:
Homebrew trusts only the fully qualified names you install from a non-official
tap, so the Cask alone refuses to load that Formula. Existing updater-capable
Desktop builds can use Updates → Check now, then Update Desktop and
relaunch. Update Local daemon separately. The legacy alpha
channel URL remains compatible and advertises the regular 0.6.5 version.
For Homebrew recovery or older builds without an updater:
brew update
brew upgrade Pepewitch/tap/wisp
brew upgrade --cask --greedy Pepewitch/tap/wisp-desktop
brew services restart wisp
open -a WispLinux (Ubuntu 24.04 LTS, x86_64, glibc):
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/Pepewitch/wisp/v0.6.5/scripts/install.sh | shBack up task state and the original Git repositories before upgrading.
Follow backup and restore; copying .wisp
alone does not preserve linked worktrees or unpublished Git objects.
This release adds database migrations 16–19, so a 0.6.4 daemon cannot reopen a profile that 0.6.5 has opened.
Scope and known limits
This release is for a trusted single OS user. Worktrees separate checkouts;
they do not sandbox agents or their credentials. There is no multi-user
permission boundary. Closing Desktop leaves daemons and agents running.
Intel macOS and non-Apple-Silicon Desktop builds are unsupported.
Desktop publication requires Developer ID signing, notarization, a stapled
ticket, and a verified updater signature. The public macOS daemon application
also requires Developer ID signing, notarization, and a stapled ticket.
Automated release gates verify immutable downloads and promote the Formula,
Cask, daemon channel, and Desktop channel together. At source
preparation, the 0.6.5 artifact gates are pending; the qualification ledger
records the final outcome separately from these immutable release notes.
Specific to this release:
- Updater signing now runs without the build step's environment. That narrows
the signing key's exposure; it does not fully isolate the key. - The Linux update manifest is still verified by a hash published in the
same release, so it is only as trustworthy as that release. - The app's error boundaries catch rendering errors only. An error thrown in
asynchronous code is not caught by them. - Against an older daemon, the composer keeps the old steering note and has
no hold toggle.
The task-brief limits listed for
0.6.4,
the shell-tab, plan-limit, and Desktop first-launch limits listed for
0.6.3,
and the auto-merge, auto-fix, review judge and draft limits listed for
0.6.2,
still apply.
Native dependency advisories still include upstream maintenance notices and a
locked Linux-only glib warning. Full clean-machine provider journeys, a
human-observed Desktop upgrade across this version, broad OS coverage, and
cross-machine restore remain incomplete. Task export excludes repositories and
provider sessions; it is not a complete backup or an import format. Permanent
deletion is logical, not forensic erasure. This release is not a security
certification.
Release assets
The release contains these ten immutable assets:
wisp-v0.6.5-linux-x86_64release-manifest.jsonSHA256SUMSwisp-v0.6.5-darwin-arm64.tar.gzrelease-manifest-darwin-arm64.jsonSHA256SUMS-darwin-arm64wisp-desktop-v0.6.5-darwin-arm64.tar.gz- `wi...
Wisp 0.6.4
Wisp 0.6.4
Wisp 0.6.4 adds optional task briefs, loads faster, and fixes a few terminal
and Desktop rough edges.
- Task briefs. Switch a task's brief on and, at the end of each turn, the
agent saves a short report that Wisp shows under the task header beside
your latest message. - Wisp's own text is marked. Everything Wisp adds to an agent's input now
sits in one<wisp>section, apart from your words. - Faster first load. The daemon serves its page gzip-compressed, and the
task list and background cleanup do less repeated work.
What changed since 0.6.3
- Optional task briefs (#305). Off by default, per task: turn it on from
the task ⋯ menu, the create toggle,wisp new --brief, or
wisp brief enable.- An eligible turn gets a one-line reminder to save a JSON brief with
wisp brief set --stdin. A missing brief never blocks, fails, or
restarts a turn. - The collapsible Brief band under the task header shows your latest
message, recorded by Wisp, then the agent's report. It says when the
report is older than your latest message. - claude, codex, cursor, and droid can publish briefs. opencode and custom
harnesses that override the command cannot, unless configured. wisp brief showstrips terminal control sequences from agent-written
text.
- An eligible turn gets a one-line reminder to save a JSON brief with
- Wisp's text goes in a
<wisp>section (#305) on every task: the
first-turn preamble, standing notes, attached-files notes, auto-fix rounds,
heartbeat wakes, scheduled steers, and plugin control lines. The old
Task:label is gone. Stored messages and the transcript are unchanged. - Faster first load and background work (#304). The embedded page is
compressed once at startup and served gzip to clients that accept it
(about 5.7 MB down to 1.7 MB). Task lists read their rows and latest turns
in one query, obsolete search, diff, and file reads are cancelled, and
inactive Desktop tasks refresh less often. - One status mark per Desktop connection tab (#306). An unreachable tab
shows only the red crossed-out cloud, and clicking it reconnects without
switching tabs. - Terminal and daemon fixes (#301). A closed shell tab can no longer
write into, or close, a file descriptor the daemon opened afterwards, which
could leave shells dead or reportEBADF. The compiled daemon now starts
in about 75 MB instead of about 3 GB, so it no longer stalls on a
low-memory host before it listens. - Release hygiene: scripted release checks and closeout (#301), and the
0.6.3 publication record (#303).
Install or upgrade
Apple Silicon macOS (12.3 configured minimum):
brew install Pepewitch/tap/wisp Pepewitch/tap/wisp-desktop
open -a WispThe Cask installs the separate daemon Formula as a dependency. Name both:
Homebrew trusts only the fully qualified names you install from a non-official
tap, so the Cask alone refuses to load that Formula. Existing updater-capable
Desktop builds can use Updates → Check now, then Update Desktop and
relaunch. Update Local daemon separately. The legacy alpha
channel URL remains compatible and advertises the regular 0.6.4 version.
For Homebrew recovery or older builds without an updater:
brew update
brew upgrade Pepewitch/tap/wisp
brew upgrade --cask --greedy Pepewitch/tap/wisp-desktop
brew services restart wisp
open -a WispLinux (Ubuntu 24.04 LTS, x86_64, glibc):
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/Pepewitch/wisp/v0.6.4/scripts/install.sh | shBack up task state and the original Git repositories before upgrading.
Follow backup and restore; copying .wisp
alone does not preserve linked worktrees or unpublished Git objects.
This release adds database migration 14 and 15, so a 0.6.3 daemon cannot reopen a profile that 0.6.4 has opened.
Scope and known limits
This release is for a trusted single OS user. Worktrees separate checkouts;
they do not sandbox agents or their credentials. There is no multi-user
permission boundary. Closing Desktop leaves daemons and agents running.
Intel macOS and non-Apple-Silicon Desktop builds are unsupported.
Desktop publication requires Developer ID signing, notarization, a stapled
ticket, and a verified updater signature. The public macOS daemon application
also requires Developer ID signing, notarization, and a stapled ticket.
Automated release gates verify immutable downloads and promote the Formula,
Cask, daemon channel, and Desktop channel together. At source
preparation, the 0.6.4 artifact gates are pending; the qualification ledger
records the final outcome separately from these immutable release notes.
Task briefs:
- A brief is the agent's own report, not a verified result. Wisp never shows
it as done or complete. - Whether an agent publishes depends on the model. In testing, some models
skipped the brief on read-only requests, and some narrowed the brief's goal
to the current turn. - An older daemon advertises no brief support, so the band does not appear
when a newer client connects to it.
The task-brief band and the gzip page have been checked in a browser; they
have not been observed in a packaged Desktop build before this release.
The shell-tab, plan-limit, and Desktop first-launch limits listed for
0.6.3,
and the auto-merge, auto-fix, review judge and draft limits listed for
0.6.2,
still apply.
Native dependency advisories still include upstream maintenance notices and a
locked Linux-only glib warning. Full clean-machine provider journeys, a
human-observed Desktop upgrade across this version, broad OS coverage, and
cross-machine restore remain incomplete. Task export excludes repositories and
provider sessions; it is not a complete backup or an import format. Permanent
deletion is logical, not forensic erasure. This release is not a security
certification.
Release assets
The release contains these ten immutable assets:
wisp-v0.6.4-linux-x86_64release-manifest.jsonSHA256SUMSwisp-v0.6.4-darwin-arm64.tar.gzrelease-manifest-darwin-arm64.jsonSHA256SUMS-darwin-arm64wisp-desktop-v0.6.4-darwin-arm64.tar.gzwisp-desktop-v0.6.4-darwin-arm64.tar.gz.sigrelease-manifest-desktop-darwin-arm64.jsonSHA256SUMS-desktop-darwin-arm64
Wisp 0.6.3
Wisp 0.6.3
Wisp 0.6.3 gives shell tabs real lifetimes, and makes the usage ring follow
the window that moves turn to turn.
- Closing a shell tab ends its shell. Tabs are kept by the daemon, so
every window shows the same ones. Each tab has a ⋯ menu and a find bar. - The usage ring shows the shortest main window and refreshes shortly
after a turn ends, for that turn's harness. - Desktop opens a new version zoomed and focused, including after an
in-app update.
What changed since 0.6.2
- Shell tabs belong to the daemon (#300). Closing a tab now hangs up its
shell and everything in its process group, the way closing a terminal
window does. Before, closing a tab only forgot it in that browser, and the
next new tab could reattach to the old shell.- Every window of a task shows the same tabs. Tab numbers never repeat
within a task, so a new tab is never a closed tab's number. - Tabs are named after the user's rename, then the program running in the
foreground, then the shell's title, then "Shell N". - The ⋯ menu has Rename, Find, Clear, Restart shell and Close shell.
Closing or restarting a tab with a program still running asks first. - Find in the terminal: ⌘F on Apple platforms, Ctrl+Alt+F elsewhere, with
match count, match case, whole word and regex. ⌘K clears on Apple
platforms; elsewhere Ctrl+K stays readline's kill-line. - A shell that exits on its own drops its tab. The last tab stays as an
exited tab you can restart. - The 30-minute idle reaper is gone. A shell lives until its tab closes,
its task is archived, or the daemon stops. - A daemon older than 0.6.3 keeps the old per-browser tabs.
- Every window of a task shows the same tabs. Tab numbers never repeat
- The usage ring shows the shortest main window (#297): claude's 5h,
codex's 5h (7d on plans without one), and droid's standard 5h. Per-model
windows and droid's core pool no longer count toward the ring.- The arc is neutral, amber from 80%, and red from 99%. It also turns red
when any other main window reaches 99%, and its accessible name says
which one. - Wisp pages ask for limits every 2 minutes instead of every minute. About
5 seconds after a turn ends, the daemon re-reads that turn's harness, at
most once every 30 seconds per harness.
- The arc is neutral, amber from 80%, and red from 99%. It also turns red
- Connection tabs stay green while switching (#298). Opening a
connection's update stream shows a subtle green ring instead of a yellow
outage. Yellow now means a failed update stream or one that took over
three seconds, and red means the server check failed. - Desktop focuses and zooms a new version on its first launch (#299),
including a relaunch after an in-app update. Later launches keep the
window where you left it. The zoom fills the usable screen area without
entering a full-screen Space. - Release hygiene: the 0.6.2 publication record (#296).
Install or upgrade
Apple Silicon macOS (12.3 configured minimum):
brew install Pepewitch/tap/wisp Pepewitch/tap/wisp-desktop
open -a WispThe Cask installs the separate daemon Formula as a dependency. Name both:
Homebrew trusts only the fully qualified names you install from a non-official
tap, so the Cask alone refuses to load that Formula. Existing updater-capable
Desktop builds can use Updates → Check now, then Update Desktop and
relaunch. Update Local daemon separately. The legacy alpha
channel URL remains compatible and advertises the regular 0.6.3 version.
For Homebrew recovery or older builds without an updater:
brew update
brew upgrade Pepewitch/tap/wisp
brew upgrade --cask --greedy Pepewitch/tap/wisp-desktop
brew services restart wisp
open -a WispLinux (Ubuntu 24.04 LTS, x86_64, glibc):
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/Pepewitch/wisp/v0.6.3/scripts/install.sh | shBack up task state and the original Git repositories before upgrading.
Follow backup and restore; copying .wisp
alone does not preserve linked worktrees or unpublished Git objects.
This release adds no database migration.
Scope and known limits
This release is for a trusted single OS user. Worktrees separate checkouts;
they do not sandbox agents or their credentials. There is no multi-user
permission boundary. Closing Desktop leaves daemons and agents running.
Intel macOS and non-Apple-Silicon Desktop builds are unsupported.
Desktop publication requires Developer ID signing, notarization, a stapled
ticket, and a verified updater signature. The public macOS daemon application
also requires Developer ID signing, notarization, and a stapled ticket.
Automated release gates verify immutable downloads and promote the Formula,
Cask, daemon channel, and Desktop channel together. At source
preparation, the 0.6.3 artifact gates are pending; the qualification ledger
records the final outcome separately from these immutable release notes.
Shell tabs:
- The tab list and tab names live in daemon memory. Restarting the daemon
ends every shell and starts each task's tabs from scratch. - With the idle reaper gone, an open tab's shell keeps running until you
close it, archive its task, or stop the daemon. - Closing a tab ends its whole process group, including programs started
from it that have not detached.
Plan-limit readings still follow each harness's own CLI, not a documented
API, and cursor and opencode still have no limits read. While a Wisp page is
open, the daemon starts an installed claude and codex about every 2
minutes and shortly after their turns end. With a Factory API key set, it
calls api.factory.ai on the same schedule. It skips turn-end reads when no
page has asked for limits in the last 10 minutes.
The Desktop first-launch zoom has not been observed across a signed
two-version update.
The auto-merge, auto-fix, review judge and draft limits listed for
0.6.2
still apply.
Native dependency advisories still include upstream maintenance notices and a
locked Linux-only glib warning. Full clean-machine provider journeys, a
human-observed Desktop upgrade across this version, broad OS coverage, and
cross-machine restore remain incomplete. Task export excludes repositories and
provider sessions; it is not a complete backup or an import format. Permanent
deletion is logical, not forensic erasure. This release is not a security
certification.
Release assets
The release contains these ten immutable assets:
wisp-v0.6.3-linux-x86_64release-manifest.jsonSHA256SUMSwisp-v0.6.3-darwin-arm64.tar.gzrelease-manifest-darwin-arm64.jsonSHA256SUMS-darwin-arm64wisp-desktop-v0.6.3-darwin-arm64.tar.gzwisp-desktop-v0.6.3-darwin-arm64.tar.gz.sigrelease-manifest-desktop-darwin-arm64.jsonSHA256SUMS-desktop-darwin-arm64
Wisp 0.6.2
Wisp 0.6.2
Wisp 0.6.2 shows how much of each harness's plan you have used, and keeps
unsent task drafts.
- A usage ring in the top bar shows the selected task's harness at its
most-used plan window. Its panel lists the windows of claude, codex and
droid, andwisp limitsprints the same readings. - New task keeps your draft. An unsent prompt, its attachments and its
choices come back when you reopen New task for the same project. - Settings takes the API keys: the review judge's Jev key, and a Factory
API key for droid's limits. A daemon run by launchd or systemd never sees a
key exported in a shell profile.
What changed since 0.6.1
- A usage ring for plan limits (#293). A small ring in the top bar shows
the selected task's harness at its most-used window, the limit that stops
its next turn first. It is neutral below 80%, amber from 80%, and red at the
limit. With no task selected, or a harness with no limits read, the ring is
empty. Hover over it, or tap it on touch, to open a panel with a section
for each of claude, codex and droid: each window's share used, and when it
resets. On touch, the ring sits in the drawer footer beside the settings
gear.- claude: the 5-hour and weekly windows, and the per-model week (for
example Opus). Wisp runsclaude -p /usage, a local command that uses no
model tokens and is kept out of session history. - codex: the rate-limit windows its app-server reports, and the plan
name. - droid: the Standard and Core pools, each with 5-hour, weekly and
monthly windows, read from Factory's billing API with a Factory API key.
Save one in Settings → Usage limits, which has a Test button, or
setFACTORY_API_KEYorDROID_API_KEYin the daemon's environment. A
saved key wins. A key that belongs to a different account than the one
droid is signed in to is flagged instead of shown as yours. - A harness with nothing to show says why: not installed, no key, a key for
another account, or a failed read. Only a failed read is red. wisp limitsprints the same readings in a terminal.--refreshreads
again now, and--jsonprints the daemon's answer from
GET /api/harness-limits.- The daemon keeps each reading for a minute. An open Wisp page asks once a
minute while it is visible, and Refresh in the panel reads again. - A daemon older than 0.6.2 reports no limits, so the ring is hidden while
it is the connection in view.
- claude: the 5-hour and weekly windows, and the per-model week (for
- New task keeps an unsent draft for each project (#294). Closing the
dialog no longer discards the prompt, the pending attachments, or the
choices: model, effort, fast mode, worktree or local mode, base branch,
suffix prompt, auto-merge and auto-fix. Reopening New task for the same
project on the same connection restores them, and the global New task
action reopens the project you last picked. A successful create clears only
that project's draft; a refused one keeps it for a retry. - Settings → Review judge (#292). 0.6.1's optional review judge can now
get its Jev key from Settings, not only from the settings API or the
daemon's environment.- The section shows the key's last four characters and where it came from,
Test (one probe call, with how fast it answered or why it failed),
Replace…, Remove for a saved key, and the month's calls,
failures, cost and model. - A daemon older than 0.6.1 has no judge, so the section is hidden there.
- The section shows the key's last four characters and where it came from,
- Both key fields are write-only. Settings never reads a key back and shows
only its last four characters. A saved key is stored in the daemon's
config.json(mode 0600), and it overrides one in the daemon's
environment. - Release hygiene: the 0.6.1 publication record (#291).
Install or upgrade
Apple Silicon macOS (12.3 configured minimum):
brew install Pepewitch/tap/wisp Pepewitch/tap/wisp-desktop
open -a WispThe Cask installs the separate daemon Formula as a dependency. Name both:
Homebrew trusts only the fully qualified names you install from a non-official
tap, so the Cask alone refuses to load that Formula. Existing updater-capable
Desktop builds can use Updates → Check now, then Update Desktop and
relaunch. Update Local daemon separately. The legacy alpha
channel URL remains compatible and advertises the regular 0.6.2 version.
For Homebrew recovery or older builds without an updater:
brew update
brew upgrade Pepewitch/tap/wisp
brew upgrade --cask --greedy Pepewitch/tap/wisp-desktop
brew services restart wisp
open -a WispLinux (Ubuntu 24.04 LTS, x86_64, glibc):
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/Pepewitch/wisp/v0.6.2/scripts/install.sh | shBack up task state and the original Git repositories before upgrading.
Follow backup and restore; copying .wisp
alone does not preserve linked worktrees or unpublished Git objects.
This release adds no database migration.
Scope and known limits
This release is for a trusted single OS user. Worktrees separate checkouts;
they do not sandbox agents or their credentials. There is no multi-user
permission boundary. Closing Desktop leaves daemons and agents running.
Intel macOS and non-Apple-Silicon Desktop builds are unsupported.
Desktop publication requires Developer ID signing, notarization, a stapled
ticket, and a verified updater signature. The public macOS daemon application
also requires Developer ID signing, notarization, and a stapled ticket.
Automated release gates verify immutable downloads and promote the Formula,
Cask, daemon channel, and Desktop channel together. At source
preparation, the 0.6.2 artifact gates are pending; the qualification ledger
records the final outcome separately from these immutable release notes.
Plan-limit readings:
- Each is read the way that harness's own CLI reads it: claude's
/usage
report, codex's app-server, and the Factory endpoint droid's usage panel
calls. None is a documented API, so a harness update can turn its reading
into a failed read until Wisp follows it. - cursor and opencode have no limits read. The ring stays empty for their
tasks, and the panel has no section for them. - While a Wisp page is visible, the daemon starts an installed
claudeand
codexabout once a minute to read their limits. With a Factory API key
set, it also callsapi.factory.aiabout once a minute. - To check a Factory key's account, Wisp reads droid's unencrypted account
cache in~/.factory, never its login files. Without that cache the
account goes unchecked, and the limits are shown anyway.
Create-task drafts stay in the page's memory. Reloading a browser tab or
quitting Desktop loses them, and tabs do not share them.
The auto-merge and auto-fix limits listed for
0.6.1
still apply. The review judge is still an outside service: with a key set,
the review text it judges leaves the daemon host for TypeSafe's API, and its
answers follow the reviewer's wording, since it never sees the code.
Native dependency advisories still include upstream maintenance notices and a
locked Linux-only glib warning. Full clean-machine provider journeys, a
human-observed Desktop upgrade across this version, broad OS coverage, and
cross-machine restore remain incomplete. Task export excludes repositories and
provider sessions; it is not a complete backup or an import format. Permanent
deletion is logical, not forensic erasure. This release is not a security
certification.
Release assets
The release contains these ten immutable assets:
wisp-v0.6.2-linux-x86_64release-manifest.jsonSHA256SUMSwisp-v0.6.2-darwin-arm64.tar.gzrelease-manifest-darwin-arm64.jsonSHA256SUMS-darwin-arm64wisp-desktop-v0.6.2-darwin-arm64.tar.gzwisp-desktop-v0.6.2-darwin-arm64.tar.gz.sigrelease-manifest-desktop-darwin-arm64.jsonSHA256SUMS-desktop-darwin-arm64
Wisp 0.6.1
Wisp 0.6.1
Wisp 0.6.1 refines 0.6.0's auto-merge and auto-fix.
- An optional review judge. With a Jev API key from TypeSafe, Wisp asks a
small classifier two questions GitHub gives no signal for: whether a
reviewer bot's summary comment or review body asks for changes, and whether
an approval lists findings. - Five auto-fix rounds per PR, up from three.
- One last read before merging. Auto-merge reads the PR once more right
before it merges, so words posted while it was deciding are read first.
What changed since 0.6.0
-
An optional review judge (#286). Some reviewer bots report findings only
in a summary comment and keep their own check green. With a
Jev key, Wisp classifies only the words it
could not otherwise read:- a bot's conversation comment whose own check is green or running, or that
has no check and does not say "blocking"; - a bot's review body with no
Verdict:line and no change request; - with auto-fix on, an approval with a body. It is asked only whether the
approval lists findings, not whether they are right.
What the answers do:
- Under auto-fix, a bot's words judged as asking for changes become review
feedback. - An approval that lists findings goes to the agent once, as notes, before
the merge. The approval still counts. - Under auto-merge, a bot's finding about the current head needs you until
a push and that bot's next pass, or its approval of the head. - A finding about an earlier head waits for the bot to speak on the new one,
for at most 20 minutes.
What it sends and where it is set:
- Only the text (up to 8,000 characters), whether a bot or a person wrote
it, and whether it is a comment or a review body. Never the diff, the
repository, the PR number or any login. - Every call is logged beside the round evidence (
judge.jsonl), and a
monthly count is reported byGET /api/settings. - Set the key with
PATCH /api/settings({"jevApiKey": "…"}), or with
TYPESAFE_API_KEYorJEV_API_KEYin the daemon's environment.
POST /api/settings/review-judge/testmakes one probe call. - The key is stored in
config.json(mode 0600) and is never read back.
Without a key nothing is judged. Red checks, review threads, change requests
andVerdict:lines work as in 0.6.0.
The review judge
describes each answer, and what happens when a call fails. - a bot's conversation comment whose own check is green or running, or that
-
Five auto-fix rounds per PR, up from three (#288). Each Resume allows
five more, and the next PR after a merge starts with a fresh five. -
Auto-merge reads the PR once more before merging (#289).
- If a comment, review, thread or check changed while it was deciding, it
does not merge. It looks again a few seconds later, so new words are
read, and judged, first. - With the review judge, a check finishing no longer counts as a pass by
a bot that keeps a summary comment. Such a bot may finish its check a
moment before it rewrites the summary.
- If a comment, review, thread or check changed while it was deciding, it
-
On/off rows in a menu end in a switch (#283), such as Auto-merge and
Auto-fix in a task's…menu. They used to show a checkmark in a slot that
looked empty when off. -
Search indexing no longer stalls on one bad turn (#287). The background
pass that indexes turn prose for search stopped at the first turn it could
not write, and that turn led every later pass, so older turns were never
indexed. A turn left from a deleted task was one such turn. The pass now
skips the turn and continues. -
Release and test hygiene:
Install or upgrade
Apple Silicon macOS (12.3 configured minimum):
brew install Pepewitch/tap/wisp Pepewitch/tap/wisp-desktop
open -a WispThe Cask installs the separate daemon Formula as a dependency. Name both:
Homebrew trusts only the fully qualified names you install from a non-official
tap, so the Cask alone refuses to load that Formula. Existing updater-capable
Desktop builds can use Updates → Check now, then Update Desktop and
relaunch. Update Local daemon separately. The legacy alpha
channel URL remains compatible and advertises the regular 0.6.1 version.
For Homebrew recovery or older builds without an updater:
brew update
brew upgrade Pepewitch/tap/wisp
brew upgrade --cask --greedy Pepewitch/tap/wisp-desktop
brew services restart wisp
open -a WispLinux (Ubuntu 24.04 LTS, x86_64, glibc):
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/Pepewitch/wisp/v0.6.1/scripts/install.sh | shBack up task state and the original Git repositories before upgrading.
Follow backup and restore; copying .wisp
alone does not preserve linked worktrees or unpublished Git objects.
This release adds no database migration.
Scope and known limits
This release is for a trusted single OS user. Worktrees separate checkouts;
they do not sandbox agents or their credentials. There is no multi-user
permission boundary. Closing Desktop leaves daemons and agents running.
Intel macOS and non-Apple-Silicon Desktop builds are unsupported.
Desktop publication requires Developer ID signing, notarization, a stapled
ticket, and a verified updater signature. The public macOS daemon application
also requires Developer ID signing, notarization, and a stapled ticket.
Automated release gates verify immutable downloads and promote the Formula,
Cask, daemon channel, and Desktop channel together. At source
preparation, the 0.6.1 artifact gates are pending; the qualification ledger
records the final outcome separately from these immutable release notes.
Auto-merge merges under your GitHub account, through the daemon host's
authenticated gh. Arm it for work you would merge yourself once CI is green;
leave it off for critical changes. Auto-fix spends agent turns: five rounds
per bound PR before it pauses (each Resume allows five more), each a full
turn with the model the task runs. Both need a GitHub repository and a
worktree task. The limits listed for 0.6.0 still apply: no pull requests from
forks, a stacked PR needs you, and so does a branch behind a base that
requires up-to-date branches. Wisp reads only the newest 100 review threads,
50 reviews and 100 conversation comments. Apart from an approval a branch
rule requires, it waits only for reviewers that have already spoken on the PR. A reviewer bot with no check of its own whose
first review arrives after the checks pass, and after a new head's two
minutes, may arrive after the merge.
The review judge is an outside service:
- With a key set, the review text described above leaves the daemon host for
TypeSafe's API. - The Settings page has no field for the key yet; use the settings API or the
environment. - Its answers follow the reviewer's wording, since it never sees the code.
Native dependency advisories still include upstream maintenance notices and a
locked Linux-only glib warning. Full clean-machine provider journeys, a
human-observed Desktop upgrade across this version, broad OS coverage, and
cross-machine restore remain incomplete. Task export excludes repositories and
provider sessions; it is not a complete backup or an import format. Permanent
deletion is logical, not forensic erasure. This release is not a security
certification.
Release assets
The release contains these ten immutable assets:
wisp-v0.6.1-linux-x86_64release-manifest.jsonSHA256SUMSwisp-v0.6.1-darwin-arm64.tar.gzrelease-manifest-darwin-arm64.jsonSHA256SUMS-darwin-arm64wisp-desktop-v0.6.1-darwin-arm64.tar.gzwisp-desktop-v0.6.1-darwin-arm64.tar.gz.sigrelease-manifest-desktop-darwin-arm64.jsonSHA256SUMS-desktop-darwin-arm64
Wisp 0.6.0
Wisp 0.6.0
Wisp 0.6.0 adds auto-merge and auto-fix: two switches on a task, set up when
you create it, from its … menu, or with wisp pr.
- Auto-merge merges the task's pull request under your GitHub account once
its checks pass (only the required ones, when the base branch has any), its
reviewers allow it, and the task is idle. - Auto-fix sends the idle agent a red check that counts, a merge conflict,
or review feedback it has not seen yet, with the failing logs, as a round.
The release also keeps the end of long turns whose transcript overflows, and
gives long turns five times more room. The PR CI and PR review watch workflows
are removed; auto-fix replaces them.
What changed since 0.5.18
- Auto-merge (#267, #269, #276) binds to the task's own pull request: one
you opened from this repository after the task was created, onto the
default branch or the project's configured base (preferring one onto the
base when there are several). It squash-merges when the
repository allows it (otherwise its one allowed method, or your default),
with--match-head-commit, so whatever it checked is exactly what merges.- Before merging it re-reads everything:
- the required checks, which alone decide when the base branch has any;
- a two-minute floor after every new head, or a draft marked ready;
- each blocking reviewer's pass on the current head;
- GitHub's merge state;
- that the worktree holds no unpushed commits or tracked edits the PR
lacks (untracked files are ignored).
- It never merges mid-turn. Stop holds it until your next turn finishes.
- After a merge both switches stay on for the task's next PR (#278): one
numbered above the merged one (the task's next change, or a PR stacked on
it), never an older open PR. The next PR starts with a fresh round budget. - Closing the PR switches both switches off.
- Every turn is told to push and open the PR and to leave the merge to Wisp
(a slash-command turn, which cannot carry the note, is the exception).
- Before merging it re-reads everything:
- Auto-fix for CI and conflicts (#272, #276). A round points the agent at a
PR-FEEDBACK.mdbeside the task's data (never in the worktree). The file
lists the red check and the jobs that failed beside it, with each job's log
from the step that failed, so an aggregator check's failing shard is read.- Rounds wait until every check that counts on the head, and every job in a
failing run, has finished; wait two minutes after the task's latest turn
(Send now / Skip in the menu); and are never repeated for the same
evidence. - Three rounds per PR, then it pauses; each Resume allows three more.
- A cancelled run (or, when the base branch has no required checks, a failed
one) is rerun once without spending a turn: ordinarypull_requestruns
only, never one with a deployment job. A red that is also red on the base
branch is not the PR's to fix.
- Rounds wait until every check that counts on the head, and every job in a
- Auto-fix for review feedback (#275): review threads, reviews with a body,
and conversation comments.- Only from you, from bots, and from people who can push to the repository.
- Never the agent's own words, which it signs with a marker.
- Never thank-yous, approvals, or a bot's status board.
- A reviewer's burst goes as one round.
- The agent may resolve threads that you or a bot started, once it has
pushed a fix. It answers everyone else's and leaves them for their
author. - An open thread holds the merge only where the repository requires
conversations resolved (#279). Wisp reads that rule from a ruleset
(always readable) or classic protection (readable only by an admin,
though anyone can see whether there is any). Where it cannot read the
rule, a PR GitHub reports blocked, with threads open and no missing
approval or change request, is taken to be blocked on them. Otherwise a
PR GitHub calls mergeable is merged with threads open. With both switches
on, a round carrying review feedback tells the agent to convert the PR to
a draft if it must not merge as it is. - The agent replies to and resolves threads under your GitHub account.
- Where you see it (#269, #272, #276, #279):
- The PR line names the switch and its reason (
Auto-fix will send: test failing,Auto-merge: Waiting for checks (2 running)). - The menu offers Resume, Continue now, Send now and Skip.
- The new-task dialog has a PR picker.
- The sidebar PR icon turns red when either switch needs you.
- A task with either switch on carries a thin rail on its sidebar row, so
one left on is never out of sight: blue while it works, violet once it is
done for now (its PR merged; or, under auto-fix alone, CI green and quiet
for 15 minutes), red when it needs you. Its hover card says which switch
is on and why. - Desktop banners report a merge by Wisp, a needs-you, or a pause.
- Archiving a task whose PR is still being watched asks first.
- Under auto-merge, a branch rule that needs an approving review turns red
after the head has waited 15 minutes for one (30 if a reviewer app has
approved the PR before). When it needs you
lists every reason.
- The PR line names the switch and its reason (
- Long turns keep their end (#270, #271, #273).
- Once a turn overflows its transcript budget, the most recent activity is
kept after a gap note, instead of only the beginning. - For Claude turns, the encrypted signature on empty thinking blocks and the
running thinking-token estimates are no longer written to the turn's
transcript (the diagnostic archive still has them), so they stop filling
the budget. - A capped turn is no longer reported as stuck.
- The default per-turn budget is 25 MB, up from 5 MB. A stored
5000000
from an earlier first run reads as the new default.
- Once a turn overflows its transcript budget, the most recent activity is
- Desktop connection tabs show live status (#274). A dot beside each
connection turns green only when its API and event stream are healthy, and
clicking it reconnects without switching tabs. - The mobile header shows the session's context size (
… · 142.6k ctx),
and the metadata line no longer slides over its separators (#268). - A pending steer image can be previewed before sending (#280): its
thumbnail and filename open the attachment preview. - The PR CI and PR review watch workflows are removed (#265), with their
wisp workflowtypes and flags (--pr,--on-red,--on-green, …), so a
script that starts them fails. Rows already armed complete with a reason
saying so; auto-fix replaces both. The same change fixes Schedule Steer's
--at. - Release and CI hygiene:
Install or upgrade
Apple Silicon macOS (12.3 configured minimum):
brew install Pepewitch/tap/wisp Pepewitch/tap/wisp-desktop
open -a WispThe Cask installs the separate daemon Formula as a dependency. Name both:
Homebrew trusts only the fully qualified names you install from a non-official
tap, so the Cask alone refuses to load that Formula. Existing updater-capable
Desktop builds can use Updates → Check now, then Update Desktop and
relaunch. Update Local daemon separately. The legacy alpha
channel URL remains compatible and advertises the regular 0.6.0 version.
For Homebrew recovery or older builds without an updater:
brew update
brew upgrade Pepewitch/tap/wisp
brew upgrade --cask --greedy Pepewitch/tap/wisp-desktop
brew services restart wisp
open -a WispLinux (Ubuntu 24.04 LTS, x86_64, glibc):
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/Pepewitch/wisp/v0.6.0/scripts/install.sh | shBack up task state and the original Git repositories before upgrading.
Follow backup and restore; copying .wisp
alone does not preserve linked worktrees or unpublished Git objects.
This release adds no database migration.
Scope and known limits
This release is for a trusted single OS user. Worktrees separate checkouts;
they do not sandbox agents or their credentials. There is no multi-user
permission boundary. Closing Desktop leaves daemons and agents running.
Intel macOS and non-Apple-Silicon Desktop builds are unsupported.
Desktop publication requires Developer ID signing, notarization, a stapled
ticket, and a verified updater signature. The public macOS daemon application
also requires Developer ID signing, notarization, and a stapled ticket.
Automated release gates verify immutable downloads and promote the Formula,
Cask, daemon channel, and Desktop channel together. At source
preparation, the 0.6.0 artifact gates are pending; the qualification ledger
records the final outcome separately from these immutable release notes.
Auto-merge merges under your GitHub account, through the daemon host's
authenticated gh. Arm it for work you would merge yourself once CI is green;
leave it off for critical changes. Auto-fix spends agent turns: three rounds
per bound PR before it pauses (each Resume allows three more), each a full
turn with the model the task runs. Both need a GitHub repository and a
worktree task.
- Pull requests from forks are not supported.
- A PR onto a branch other than the default or the configured base (a stacked
PR) needs you; auto-merge only merges into those. Wisp never deletes a
merged branch, so a PR stacked on it is retargeted only where the
repository deletes head branches automatically; otherwise retarget it
yourself. - While auto-merge is on, every later turn on the task is told to push and
open a PR, and that PR is merged too: switch auto-merge off once the task's
work is done. After...
Wisp 0.5.18
Wisp 0.5.18
Wisp 0.5.18 refreshes every built-in harness catalog and fixes Cursor model
discovery after an upgrade. Claude Opus 5.5 and the latest Codex, Droid,
Cursor, and OpenCode models now appear in Wisp's model controls. Cursor no
longer restores the old 17-model filtered catalog from its persisted cache, so
provider models such as Grok 4.7 become available without waiting for the
cache's 24-hour refresh.
What changed since 0.5.16
- Cursor's model manager now follows the complete output of
cursor-agent modelsimmediately after a Wisp upgrade. The filter that once
kept onlyauto,composer-*, andcursor-*had already been removed, but
the persisted cache still treated its old filtered answer as compatible for
up to 24 hours. Cache identity now includes the discovery implementation, so
a parser or filtering change forces a fresh probe instead of restoring a
semantically stale catalog (#261). - Built-in harness facts now match Claude Code 2.1.280, Codex 0.156.1, Cursor
2026.09.18-9a7762b, Droid 0.225.1, and OpenCode 1.18.31. Claude's curated
picker replaces Opus 5 with Opus 5.5; Codex discovers GPT-6 Sol and GPT-6
Luna and reports GPT-6 Sol as its default; Droid and Cursor include their
newly advertised Claude, GPT, Grok, and Mistral entries; and OpenCode moves
its free MiMo entry tomimo-v2.6-flash-free(#260).
Install or upgrade
Apple Silicon macOS (12.3 configured minimum):
brew install Pepewitch/tap/wisp Pepewitch/tap/wisp-desktop
open -a WispThe Cask installs the separate daemon Formula as a dependency. Name both:
Homebrew trusts only the fully qualified names you install from a non-official
tap, so the Cask alone refuses to load that Formula. Existing updater-capable
Desktop builds can use Updates → Check now, then Update Desktop and
relaunch. Update Local daemon separately. The legacy alpha
channel URL remains compatible and advertises the regular 0.5.18 version.
For Homebrew recovery or older builds without an updater:
brew update
brew upgrade Pepewitch/tap/wisp
brew upgrade --cask --greedy Pepewitch/tap/wisp-desktop
brew services restart wisp
open -a WispLinux (Ubuntu 24.04 LTS, x86_64, glibc):
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/Pepewitch/wisp/v0.5.18/scripts/install.sh | shBack up task state and the original Git repositories before upgrading.
Follow backup and restore; copying .wisp
alone does not preserve linked worktrees or unpublished Git objects.
This release adds no database migration.
Scope and known limits
This release is for a trusted single OS user. Worktrees separate checkouts;
they do not sandbox agents or their credentials. There is no multi-user
permission boundary. Closing Desktop leaves daemons and agents running.
Intel macOS and non-Apple-Silicon Desktop builds are unsupported.
Desktop publication requires Developer ID signing, notarization, a stapled
ticket, and a verified updater signature. The public macOS daemon application
also requires Developer ID signing, notarization, and a stapled ticket.
Automated release gates verify immutable downloads and promote the Formula,
Cask, daemon channel, and Desktop channel together. At source
preparation, the 0.5.18 artifact gates are pending; the qualification ledger
records the final outcome separately from these immutable release notes.
The catalog refresh verifies zero-token CLI surfaces. It does not re-run the
token-spending fixture, steering, and usage probes, or qualify every newly
listed model with a live coding turn. Actual model availability still depends
on the harness provider and account.
Native dependency advisories still include upstream maintenance notices and a
locked Linux-only glib warning. Full clean-machine provider journeys, a
human-observed Desktop upgrade across this version, broad OS coverage, and
cross-machine restore remain incomplete. Task export excludes repositories and
provider sessions; it is not a complete backup or an import format. Permanent
deletion is logical, not forensic erasure. This release is not a security
certification.
Release assets
The release contains these ten immutable assets:
wisp-v0.5.18-linux-x86_64release-manifest.jsonSHA256SUMSwisp-v0.5.18-darwin-arm64.tar.gzrelease-manifest-darwin-arm64.jsonSHA256SUMS-darwin-arm64wisp-desktop-v0.5.18-darwin-arm64.tar.gzwisp-desktop-v0.5.18-darwin-arm64.tar.gz.sigrelease-manifest-desktop-darwin-arm64.jsonSHA256SUMS-desktop-darwin-arm64
Wisp 0.5.16
Wisp 0.5.16
Wisp 0.5.16 fixes a daemon crash that made 0.5.15 unusable. Opening a terminal
killed the whole daemon rather than just the terminal, so Desktop lost its
connection and every request failed with it. It also keeps a Claude task alive
through a background Monitor's whole run instead of ending it one result early.
Upgrade from 0.5.15; there is nothing to configure.
What changed since 0.5.15
- The published macOS daemon is now signed with the JIT and
unsigned-executable-memory entitlements its hardened runtime requires. The
daemon reaches libc throughbun:ffito open a pty for the embedded terminal,
and the hardened runtime blocks the executable memory that needs unless the
signature grants it. 0.5.15 was signed hardened with no entitlements at all,
so every terminal open trapped inpthread_jit_write_protect_npand took the
daemon down; launchd restarted it and the next attempt did the same. Desktop
reportedcould not open a shell (1006)and thencould not reach the daemon(#256). - The release pipeline refuses to build a signed daemon whose signature lacks
either entitlement, and re-checks both on the published bytes after
anonymous download (#256). - A Claude task that starts a background Monitor now runs to the follow-up its
completion wakes. Each event the monitor delivers drives its own model call
and its own result, and the turn stays open across all of them. Previously a
completion arriving while a call was still in flight closed the turn on that
in-flight result and dropped the follow-up, and a foreground subagent's
completion notification was mistaken for a background one (#258).
If 0.5.15 left your daemon crashing
brew services list may show wisp restarting repeatedly, and Desktop may show
could not open a shell (1006) or could not reach the daemon. Upgrading
replaces the signature and the launchd service together:
brew update
brew upgrade Pepewitch/tap/wisp
brew services restart wispInstall or upgrade
Apple Silicon macOS (12.3 configured minimum):
brew install Pepewitch/tap/wisp Pepewitch/tap/wisp-desktop
open -a WispThe Cask installs the separate daemon Formula as a dependency. Name both:
Homebrew trusts only the fully qualified names you install from a non-official
tap, so the Cask alone refuses to load that Formula. Existing updater-capable
Desktop builds can use Updates → Check now, then Update Desktop and
relaunch. Update Local daemon separately. The legacy alpha
channel URL remains compatible and advertises the regular 0.5.16 version.
For Homebrew recovery or older builds without an updater:
brew update
brew upgrade Pepewitch/tap/wisp
brew upgrade --cask --greedy Pepewitch/tap/wisp-desktop
brew services restart wisp
open -a WispLinux (Ubuntu 24.04 LTS, x86_64, glibc):
curl --proto '=https' --tlsv1.2 -fsSL \
https://raw.githubusercontent.com/Pepewitch/wisp/v0.5.16/scripts/install.sh | shBack up task state and the original Git repositories before upgrading.
Follow backup and restore; copying .wisp
alone does not preserve linked worktrees or unpublished Git objects.
This release adds no database migration.
Scope and known limits
This release is for a trusted single OS user. Worktrees separate checkouts;
they do not sandbox agents or their credentials. There is no multi-user
permission boundary. Closing Desktop leaves daemons and agents running.
Intel macOS and non-Apple-Silicon Desktop builds are unsupported.
Desktop publication requires Developer ID signing, notarization, a stapled
ticket, and a verified updater signature. The public macOS daemon application
also requires Developer ID signing, notarization, and a stapled ticket.
Automated release gates verify immutable downloads and promote the Formula,
Cask, daemon channel, and Desktop channel together. At source
preparation, the 0.5.16 artifact gates are pending; the qualification ledger
records the final outcome separately from these immutable release notes.
The release gates verify that the signed daemon carries both entitlements, but
no gate yet runs the shipped daemon's terminal end to end: 0.5.15 passed every
check while crashing on the first terminal open, because each gate runs the
binary only long enough for wisp version. Upgrading from 0.5.14 or earlier has
not been observed on a clean machine for this version, and the qualification
ledger records what the automated gates do and do not prove. macOS does not
remove App Management records for binaries installed by earlier Wisp releases;
those older rows can still be removed manually in System Settings. Native
dependency advisories still include upstream maintenance notices and a
locked Linux-only glib warning. Full clean-machine provider journeys, a
human-observed Desktop upgrade across this version, broad OS coverage, and
cross-machine restore remain incomplete. Task export excludes repositories and
provider sessions; it is not a complete backup or an import format. Permanent
deletion is logical, not forensic erasure. This release is not a security
certification.
Release assets
The release contains these ten immutable assets:
wisp-v0.5.16-linux-x86_64release-manifest.jsonSHA256SUMSwisp-v0.5.16-darwin-arm64.tar.gzrelease-manifest-darwin-arm64.jsonSHA256SUMS-darwin-arm64wisp-desktop-v0.5.16-darwin-arm64.tar.gzwisp-desktop-v0.5.16-darwin-arm64.tar.gz.sigrelease-manifest-desktop-darwin-arm64.jsonSHA256SUMS-desktop-darwin-arm64