Releases: RandyNorthrup/muse-spark-code
Release list
v0.9.1
Works with Muse Code 1.4.0, now Meta's stable release, which its launcher
installs by itself.
Fixed
- Rename, conversation rewind and Side chat came back on Windows with
Muse Code 1.4.0, and failed. The panel hid them only up to Muse Code
1.3.0, but 1.4.0 still refusessession/renameandsession/forkon
Windows (meta-models/muse-code-sdk#30, #31). They are now hidden on
Windows for every Muse Code version until a release is verified to fix
them, and the message no longer names a version. - The warning about a workspace under your Windows user profile was
missing with Muse Code 1.4.0. Its sandbox still starts shell commands in
PowerShell's folder there (#26), so the warning is shown again for every
version. It no longer says each command takes half a minute, which is no
longer true on 1.4.0. - Every Muse Code 1.4.0 start logged "MSP schema fingerprint mismatch".
1.4.0's protocol only adds to 1.3.0's; its known fingerprints are now an
info line naming the build, and an unknown one is still a warning.
v0.9.0
Muse Code installs and signs in from the panel, PDFs and text files become
input, and the Model API backend gains subagents, MCP servers, hooks,
memory, goals and scheduled prompts. Conversations can be rewound or
branched into a side chat. Five paid extras arrive, each off until you turn
it on. The extension also works behind corporate proxies and HTTPS
inspection.
Added
- Install and sign in from the panel (M55). Without the Muse Code CLI,
the sign-in screen offers Install Muse Code: it shows Meta's install
command for your system, runs it in a terminal you can watch once you
confirm, and offers sign-in when the CLI appears; a timed-out install can
be retried. Sign in with your Meta account shows Muse Code's approval
code and sign-in link in the panel, with Cancel and a timeout. Account &
usage offers the same install while you use a Model API key, and lets a
Muse Code user add or replace the key. After Sign out, a note in the
extension's state (no credential) keeps an old CLI credential from
signing the window back in until you sign in again; if the logout terminal
cannot open, the extension still stops its host and says how to finish. - PDFs and text files as input (M54, PLAN.md D47). On the Model API
backend, pick, paste or drop a PDF of up to 32 MB (recognised by its
content, whatever its name), and the agent can read workspace PDFs and
images withread_file. A request stays within Meta's limit of 50 images
and PDF pages together: an attachment that would pass it is refused with
the reason, and older media left out of a replay is announced. A picked
UTF-8 text file from the workspace becomes a named text attachment on both
backends (up to 1 MiB each); private files are refused, and files outside
the workspace stay mentions. Muse Code cannot take PDFs over MSP, so it
says so. When the page count of a PDF cannot be read for certain, it
counts as the full 50. Conversation rewind is not offered for a message
with a PDF or a text file. - MCP servers on the Model API backend (M50, PLAN.md D42). The window
runs the MCP servers in Muse Code's settings file itself, local (stdio)
and remote (streamable HTTP): their tools are offered as
mcp__<server>__<tool>, with schemas fitted to Meta's limits, and their
text and pictures reach the model. A call asks like a command in Manual
and Auto (a tool its server marks read-only runs in Auto, as in Muse
Code); Plan refuses all but read-only tools, which ask; "always allow in
this session" works per tool. None runs in Restricted Mode. A local server
sees only a short list of VS Code's environment variables plus its own
env, never the Model API key;${VAR}, timeouts and tool filters from
its entry are honoured. MCP servers… in the palette shows whether each
server is connected and with how many tools, or why not; a failing server
is a warning, and a required one stops the message with the fix. On
Windows each local server runs in a job object, so stopping it ends
everything it started. Remote error bodies and authentication challenges
stay out of tool errors and logs. The extension's diagnostics tool
(getDiagnostics) is offered on this backend too. - Memory, on both backends (M49, PLAN.md D41). Muse Code keeps Markdown
notes in three scopes: yours for this project (the default, outside the
repository), the project's (.agents/memory, shared with the
repository) and yours for every project. Both backends now read and write
the same notes, found on disk and in a live capture of Muse Code 1.3.0.- Memory… in the palette (
/memory, Muse Spark: Memory) lists
up to 500 notes per scope with their scopes and summaries; open one to
read or edit it, create one, or delete one to the trash after a
confirmation. The scope'sMEMORY.mdindex gains a created note's line
and loses a deleted note's lines. - The Model API backend has Muse Code's
read_memory,add_memory
andedit_memory, with its arguments, refusals and JSON results, so
their rows read the same on both backends; at the start of a
conversation the model gets each scope'sMEMORY.mdand its notes'
names, as Muse Code gives them. A new note gets its index line. Writes
ask in Manual, run in Auto and Edit automatically, and are refused in
Plan; a refused path asks nothing. Not offered in Restricted Mode.
Linked scope folders below the workspace or data home are refused, so
they cannot expose notes outside their intended roots. - A new note is created exclusively and published whole: a synced hidden
copy is hard-linked into a free name, so it never replaces a racing
writer's note or shows partial bytes, and a filesystem without hard
links refuses the create. Names with spaces, brackets or percent signs
are encoded inMEMORY.md, so a note keeps one index line. - Updates to an existing note replace it atomically but do not take Muse
Code's native memory lock; simultaneous writers can still lose an update.
- Memory… in the palette (
- Session goals (M45, PLAN.md D38).
/goal <objective>sets a goal
the agent keeps working toward; a strip above the task list shows its
status, a progress bar and the work now and next, with Pause, Resume, Edit
and Clear (also/goal pause,resume,edit <objective>,clear).
On Muse Code these are its own goal commands, and a resumed conversation
shows its goal and task list. On the Model API backend the agent gets Muse
Code's four goal tools with the same results, the goal is saved with the
conversation and kept in the instructions while active, Stop pauses it,
and nothing starts a model call you did not ask for. A goal changed while
a request runs does not take that request's tokens or tool calls, and a
rejected/goalkeeps its draft. Built from a live capture of Muse Code
1.3.0. - Your own shell commands:
!(M46, PLAN.md D39). A message that
starts with!runs as a shell command in the workspace, outside any
turn, as Muse Code's!does, and gets its own row: You ran, the
command, its exit code, run time and output. The agent sees it with your
next message. On Muse Code it is the CLI'ssession/userShell; on the
Model API backend it runs through the shell tool's own runner, with a
Stop. Nothing runs in Restricted Mode, a command that could not run
comes back to the prompt with the reason, and one Muse Code could not
start without its Windows sandbox offers the setup, as the shell tool's
failure does. A running Model API!command is saved at once, so
another surface on the conversation shows its row and can stop it.
Markdown export includes a command's termination signal when Muse Code
reports no exit code. - Background work you control (M46). Move to background on a
running shell row, orCtrl+Bwhile the conversation in view runs one,
lets the command go on while the agent carries on; a background task has
Stop on its row and in the Agent map, which also has Stop all
(and the new Muse Spark: Stop Background Tasks command). The header
pill counts running background tasks. Muse Code'stask/background,
task/stopandtask/stopAllon its backend; on the Model API backend a
moved command runs without its time limit until it ends or is stopped,
and what it printed reaches the agent with its next request. Releasing
the last surface of a Muse Code session stops its background tasks;
another surface holding it leaves them running. A resumed or second
surface shows a running foreground shell and can move it withCtrl+B;
while that shell still awaits permission, it shows the same card and
leavesCtrl+Bto VS Code. A fork carries the end or lost-output note
for each inherited background shell. - Explain instead on question cards (M46): an answer in your own words
in place of the options (Muse Code'suserInput/clarify, and the same on
the Model API backend); the row then reads "Explained". - Approvals across panels (M46). A panel joining a conversation shows
its open approval cards on both backends, but never automatically
answers a card that was already pending under another panel's mode. With
several panels attached every approval needs an explicit choice; a sole
Edit automatically panel keeps its automatic plain-edit approval. - Subagents on the Model API backend (M48, PLAN.md D45). With the paid
settingmuseSpark.modelApiSubagentson and its rates accepted, the agent
can start child tasks. Each runs in parallel within fixed limits, with its
own transcript, the same tool approvals and workspace rules, and its usage
counted with the conversation. Every new child task asks first, in every
mode, Bypass included (Plan refuses it), and one consent covers at most
four requests, retries included. The Agent map can steer, stop, read and
reopen children; the child's row and Account & usage show its paid
attempts and tokens. On Muse Code, the map's Read result and Reopen wait
for a capture of Muse Code's replies to them. - Model API hooks (M51, PLAN.md D36). With the machine-scoped
museSpark.modelApiHookson (off by default), the Model API backend runs
Muse Code's hook commands for all 17 documented events: your
administrator's, yours and the project's.muse/hooks.json, in a trusted
workspace only. A hook gets JSON on its standard input (your prompt and
bounded previews of tool and model calls, without images, credential
fields or the Model API key), runs with time and output limits, and is
stopped with everything it started. APreToolUsehook can deny a call or
ask for approval, which a person then answers in every mode; a
PreLLMCallhook can stop a request before it is sent. Unsupported events
and handler types are reported and skipped; not all of Muse Code's
event-specific hook output is supported yet. *...
v0.8.0
The panel in VS Code's display languages: fourteen of them, machine-made
and checked by a gate of their own, with the model's side kept in English.
Added
- The panel in fourteen languages (M40, PLAN.md D33). The panel, its
notices, the Command Palette's commands and the settings follow VS Code's
display language: Simplified and Traditional Chinese, Japanese, Korean,
German, French, Spanish, Brazilian Portuguese, Russian, Italian, Turkish,
Polish, Czech and Hungarian. Any other language gets English.- Machine-made, and checked by the localization gate rather than by
native speakers; the README says how to report a wrong one. - Still English: text sent to the model, and what Muse and the tools
write.
- Machine-made, and checked by the localization gate rather than by
Changed
- The groundwork for the panel in VS Code's display languages (M40,
PLAN.md D33). The panel still reads in English until the translations
land; what changed underneath:- Whole sentences: every text the user reads is in one table
(src/shared/l10n/en.ts). A sentence built around a value is one
template, so a language can put the value where its grammar needs it,
and a count picks its form by the language's own plural rules. - The manifest: the Command Palette's commands, the settings and the
walkthrough take their text frompackage.nls.json. - Text for the model stays English: what goes to the model is kept
apart, so the model behaves the same in every display language. - One file at a time: the host loads the table for VS Code's display
language and hands it to each panel. A missing or damaged table falls
back to English, and the log says so. <html lang>: the panel declares its language to screen readers.
- Whole sentences: every text the user reads is in one table
- Numbers, money and times follow the display language's conventions
(Intl). In English that changes a few:- History's times read "5 min. ago", "3 hr. ago", "yesterday".
- The usage window's reset reads "2h 5m".
- A failed Muse Code or sandbox run names its "exit code".
Fixed
- The Modes menu's highlighted row showed its detail line below 4.5:1
contrast in the Dark Modern theme (WCAG 1.4.3), as M37 had fixed for the
palette; it takes the row's own text colour. - A token count just under a million read "1000K"; it reads "1M".
- Accessibility, found by checking the panel in a pseudo-locale:
- The palette's and History's search box kept pointing at a list that a
search matching nothing had removed (aria-controls, WCAG 4.1.2). It
now controls a list only while one is shown. - A code block's Copy, Insert and Apply buttons are 24 px targets; with
longer labels, spacing alone no longer made up for their height (WCAG
2.5.8).
- The palette's and History's search box kept pointing at a list that a
- The Agent map showed a background task's raw status ("inProgress"); it
reads "running", like the agents above it. - The hooks view counted "3 in your settings"; it says "3 hooks in your
settings".
v0.7.1
The new mark on the Marketplace listing, the README rewritten for 0.7.0,
and a false failure in the log fixed.
Changed
- The Marketplace icon, the README banner and the social preview carry a
squiggled, handwritten blue "m" in the manner of Muse's own mark, in place of
the plain "M" (at the owner's direction). It is drawn from a curve, not
traced from Meta's mark. - The README is rewritten for 0.7.0: a contents list, what is new, the
limits, accessibility, the protected writes, and the corrections below. - A file the Model API tools refuse as too large now says to read part of it
with a shell command; it no longer suggests the search tool, which skips
files over 1 MiB. - Setting descriptions:
attachOpenFilesays it also hides the open-file
chip and sends neither the file nor the selection when off;
cleanupPeriodDaysdeletes when a window lists the conversations, not
when it opens them;backend'sautofalls back to Muse Code's sign-in
when no key is stored.
Fixed
npm run security:sastfinds a semgrep that pip installed into Python's
user Scripts folder when that folder is not on the shell's PATH (an
editor started before it was added), instead of failing with "semgrep is
not recognized".- Resizing the sidebar while the prompt held a draft of several lines could
log a false panel failure ("ResizeObserver loop completed with undelivered
notifications"): the prompt refitted its height inside the browser's own
resize callback. It now refits on the next frame. - The UI harness's
chipsscenario had clicked a button renamed before the
first release, so it never picked a file; it now uses the Attach menu. - Four scenarios of the UI harness (
filter,agents-off,usage-api,
usage) had failed since M38, when a typed/stopped showing the
palette's filter box, and the accessibility gate checked whatever the
broken step left on screen. They open the palette from its button again,
and a scenario that throws now fails the gate.
v0.7.0
What can be built now without Meta: Muse Code's skills, MCP servers, hooks
and worktrees from the panel, conversations exported, a rewind that finds an
edit that moved, an accessibility gate on every screen, / as in Claude
Code, and a log that tells a session's story.
Added
-
MCP servers… and Hooks… (palette and Command Palette, CLI
backend):- The MCP view lists what Muse Code will load from its settings: each
server's transport, where it points, whether it is required, and the
names (never the values) of its environment variables and headers. - A remote server can be signed in to or out of through
muse mcp login
orlogoutin a terminal. - It warns out loud about the two settings mistakes that make Muse Code
load no server at all. - The hooks view shows the project's, your own and managed hooks and
opens each file. - Both views are read-only; the extension never edits Muse Code's
settings.
- The MCP view lists what Muse Code will load from its settings: each
-
New worktree… starts a branch in a folder beside the repository and
opens it in a new window. Remove a worktree… deletes another
worktree's folder (the branch stays), and asks a second time before
discarding uncommitted changes. -
Manage skills… (palette and Command Palette, CLI backend): a
checklist of every skill Muse Code knows, built-in, yours, the project's
and plugins'; unchecking one turns it off throughmuse skills disable.
Muse Code reads skill changes when it starts, so the change ends with an
offer to restart it, and the conversation continues on the next message. -
Import skills…: shows what
muse skills importwould copy from
Claude Code or Codex into your Muse skills folder, imports it once you
confirm, and reports what was imported, skipped or failed. -
"Continue a Claude Code session" and "Continue a Codex session" in the
palette's Context group, where the session offers Muse Code's
resume-claudeandresume-codexskills. -
/exportand Muse Spark: Export Conversation save the conversation as
Markdown (messages, thinking, tool calls with their arguments and visible
output) where you choose, on both backends; on the CLI backend Export
session log… saves Muse Code's own JSON record of the session through
muse export. An export waits for a running reply to finish, and a
conversation too long for Muse Code to replay is pointed to the session
log instead of being written as an empty file. -
Delete in the History dialog archives the highlighted conversation, or
restores an archived one, while the search box is empty. -
An accessibility gate: every screen of the panel's test harness is checked
with axe-core against WCAG 2.2 AA in VS Code's four default themes, with
colours read from a real VS Code, and any violation fails the build.
Security
- On the Model API backend a write under
.muse/asks in every mode but
Bypass, like.gitand.vscode:.muse/hooks.jsonnames commands Muse
Code runs outside its sandbox and approvals, so an agent on the key could
otherwise have planted one without asking. Muse Code itself already asks
before writing it (checked live with 1.3.0).
Fixed
- A Model API reply whose stream sends nothing for five minutes ends, saying
so, instead of holding the turn until Stop. - The file tools refuse a file over 10 MiB before loading it, rather than
holding any file whole. - Opened tool-output documents are limited to 32 million characters
together, as well as 20. - An image that cannot be read says so in the banner.
- A rewind whose file cannot be read (a permission problem) says why,
instead of "no longer matches". - A Muse Code install that cannot be read is named in the log, instead of
looking like no install at all. - Accessibility (WCAG 2.2 AA):
- Diff line numbers, a failed tool's reason and the detail line of a
selected menu row now meet 4.5:1 contrast in every default theme. A
failure keeps its red as a bar beside the reason. - The palette's and History's lists can be scrolled from the keyboard:
each is a Tab stop, the dialog stays open while the focus is in it,
and Escape works from there. - Screen readers no longer meet buttons nested inside list rows. The
effort row is set with Left and Right, and History rows archive with
Delete; the dots and the × remain for the mouse. - Question answers have 24 px rows, so each radio or checkbox is easy to
hit, and each effort dot in the Modes menu is a 24 px target.
- Diff line numbers, a failed tool's reason and the detail line of a
- Rewind code to here no longer skips an edit just because you added or
removed lines above it since. The edit's own lines, matched exactly, are
found where they moved to when they appear in exactly one place. An edit
whose lines you changed, or whose lines appear more than once, is still
refused with the reason, never guessed at. - A path with a typographic apostrophe, such as
C:\Users\O’Brien, no
longer breaks the Windows job helper's PowerShell scripts. PowerShell
reads ‘ ’ ‚ ‛ as quote characters, and only the plain'was being
escaped. - The terminals the extension opens (sign-in, Open in Terminal, MCP
sign-in) single-quote the CLI's path and every argument for the shell
they run, so nothing in them is expanded. - On macOS, dictation from the panel asks for speech recognition and the
microphone as the helper itself (muse-dictate, with its own usage
descriptions) instead of as Visual Studio Code, which declares no
speech-recognition purpose and so was refused without being asked
(microsoft/vscode#307364). The grants cover the helper alone; an update
that changes the helper asks again.
Changed
- The log tells the whole story (Muse Spark: Show Logs):
- Failures: every failure the panel or a popup showed, and any that
failed unseen, with a stack where there is one. That covers panel
actions, commands, background restarts and errors inside the panel
itself. The panel reports its errors at most ten a minute. - Sessions and turns: each session started, resumed or forked, with
its id. Each turn with its result, duration and time to first output. - Also: approvals (the tool and the answer), sign-in changes, the
backend in use, and why the backends restarted. - At Trace level: each Muse Code command's and Model API request's
time. - Never logged: prompt text, file contents, dictated words and model
output. An invalid setting now warns once, not on every read.
- Failures: every failure the panel or a popup showed, and any that
- Faster when replies stream: streamed text reaches the panel at most once
a frame, and the panel stops saving its state every second while a reply
streams (it saves when the turn ends). - Smaller:
- The Model API's git facts are gathered in parallel.
- The editor selection is read once it settles, not on every arrow key.
- Tool output previews are cut at 2,000 characters as well as 12 lines.
- The diagnostics server starts when a session first needs it.
/in the prompt works as in Claude Code. A/on an empty prompt
stays in the box and shows the palette above it, and the box keeps the
keyboard: Up and Down,EnterandEscwork the palette. Type a letter
more and the palette gives way to a list of slash commands narrowed as you
type, names that start with your letters first.Enterruns a command,
or completes a skill so you can add its arguments;Tabcompletes the
name. New names in that list:/model,/resume,/permissions,
/config, and/mcpand/hookson the CLI backend. The/button
still opens the palette with its own filter box.- The Agent map and the header's agents pill show running and finished
agents in the panel's blue, as a running tool's dot is, instead of green. - The Marketplace publish runs in a
marketplaceenvironment that only
version tags can use, holding the publishing token; no other workflow
run can read it.
v0.6.0
The hardening release: the findings of a full audit of the code against
other harnesses' bug trackers and the platform documentation, fixed.
Security
- The Model API backend's file tools resolve every path through the file
system before using it: a symbolic link or junction inside the workspace
that leads outside it is refused, for reads as well as writes, and the
search skips such files. Edit Review and the rewind check the same way
before writing a file back. Windows alternate data streams (a.txt:x),
device names (NUL,COM1) and names ending in a dot or a space are
refused. - On the Model API backend, a committed
AGENTS.md,CLAUDE.md, memory
index or project skill that is a link leading outside the workspace is
skipped, with the reason in the log; its target used to reach the model. - Protected writes: on the Model API backend, writing git's hooks and
config,.husky,.vscode,.idea,.devcontainer, CI workflows,
.agents,AGENTS.md,CLAUDE.md,.envrcor.gitmodulesshows an
approval card in every mode but Bypass, whatever the session's "always
allow" rules say. Auto used to write them without asking. - No
gitin Restricted Mode: a repository's own.git/configcan name
programs git runs, and the@mention index and the Model API prompt ran
git status and log on the first message in an untrusted folder. git, bash
and PowerShell are now started by absolute path from absolutePATH
entries only (never a copy inside the workspace), and the Muse Code CLI
search skips empty and relativePATHentries too; a relative
museBinaryPathis refused. git runs with a 15-second timeout and without
taking the index lock (GIT_OPTIONAL_LOCKS=0). - "Always allow in this session" on a shell command now allows that exact
command line, not every later command. An approval choice the card never
offered is refused instead of counting as a yes. - Bypass permissions ends in every open conversation as soon as
allowDangerouslySkipPermissionsis turned off. In a remote window (where
a dev container definition can write machine settings) a conversation
never starts in Bypass, and entering it asks once. - Resuming a conversation that ran on a contributor-tier model asks as
choosing one does, or, in a confidential workspace, moves it to a
standard model. - The shell tool's environment drops the editor's internal variables
(ELECTRON_RUN_AS_NODE,VSCODE_*IPC handles) exactly as VS Code's own
terminal does, and Windows PowerShell gets its own module path. - The log redacts JWTs, basic credentials, token and password fields and
credentials in URLs; amuse servestderr chunk is capped in the log;
the diagnostics report writes the home directory as~. - The release workflow checks the tag (manifest version, on
main) before
building, hands the Marketplace token to one step after an install that
runs no package scripts, and keeps no token in checkouts. npm auditstill blocks releases, with a reviewed, expiring exception
list for advisories that have no fix.
Added
THIRD_PARTY_NOTICES.txtships in the package.museSpark.cleanupPeriodDays(default 30, as Claude Code's
cleanupPeriodDays): Model API conversations idle longer are deleted
when a window lists them; 0 keeps them.
Fixed
- Edit automatically now does what it says: plain file-write approvals
are answered for you (the row says "Edit automatically"); protected
writes, escalations and commands still show the card. It behaved like
Manual before. - The
searchandlist_filesglob no longer builds a regular expression:
a crafted 37-character pattern held the extension host for 25 seconds.
Matching is linear,[!x]negates and braces nest. - The Modes menu describes each mode truthfully per backend (Muse Code's
Manual applies in-workspace edits without asking; the Model API's Auto
has no safety-check model). - On Windows the focus and new-tab shortcuts are
Ctrl+Alt+Escand
Ctrl+Shift+Alt+Esc; Windows takesCtrl+EscandCtrl+Shift+Esc
itself. The walkthrough, the getting-started tips and the composer's
placeholder name them. - Dictation says why it is unavailable in a remote window; the Windows
helper no longer inherits PowerShell 7's module path; a write to a dead
helper no longer throws. - On macOS, dictation names the app macOS asks, separates speech from
microphone refusals, and explains an early exit. - The crash screen's Reload brings the conversation back as it was: the
transcript, a waiting approval or question and the running turn. A state
that crashes the panel twice is dropped instead of looping. - A stopped or failed turn no longer leaves the reply streaming, tools
running or cards clickable; a tool it cut off reads "Interrupted". - "Rewind code to here" no longer unwinds a subagent's earlier edits after
the Agent map has read the agent's transcript. - New Conversation from its keybinding clears the panel too, and acts on
the panel you last used. - With an input method (Chinese, Japanese, Korean), Enter commits the
candidate instead of sending the message or picking a mention. - Typing and streaming no longer re-render the whole transcript; a code
block being written is highlighted once, when it is complete. - A resumed conversation's thoughts read "Thought", not "Thinking…".
- The transcript stays at the end when its content grows without a new row.
- A tab restored after a window reload keeps its conversation until the
resume succeeds. - A refused message's images no longer linger unseen in the panel's host;
they come back to the composer when the host still holds them. - A question card posts one answer however often Submit is pressed, and
opens again when the answer is refused. - Screen readers get one announcement per event.
- Dialogs keep Tab inside and the chat behind them is inert; message menus
close on a click outside; right-click on a selection offers Copy. - The History dialog's keys keep working after Show archived.
- Images over 10 MB, or past 20, are refused before they are read, and the
banner says why. - Relative links in a reply open the workspace file at the lines they name.
- Right-to-left text reads right to left.
- Reduced motion stops every animation.
- Tasks with the same text no longer collide; approval feedback starts empty
on each step; Windows line ends no longer show in diffs; diffs over 256 KB
keep their line numbers. - A shell command that times out or is stopped now ends with everything it
started (a process group on macOS and Linux,taskkill /Ton Windows),
and a command that leaves a background process running (server &)
returns when it exits instead of holding the turn open; Stop reaches a
running command. A flood of output keeps its beginning and its end. On
Windows each command runs in a job object of its own, so Stop and a
timeout end everything it started at once, including a program it was
starting at that moment and one a launcher left behind (taskkillmissed
those: they ran on, and one stayed suspended for good); a command that
ends normally still leaves its background processes running. Where
Windows policy forbids the job helper, the log says so and a sweep of the
process table stands in. - A restart the extension makes (trust granted, a setting changed, a
sign-in) no longer looks like a crash that blocks every panel: the running
turn is cancelled, and the next message continues the same conversation.
After a real crash the turn ends with the reason and the next message
restarts Muse Code and continues; only an exit that restarting cannot fix
(a configuration Muse Code refuses, a build without the SDK surface) is
shown as an error. - Muse Code gets deadlines: 30 seconds to start, 60 per command (three
minutes to load, copy or compact a session), so a wedged CLI no longer
hangs sign-in, switching or sign-out. - When Muse Code closes or evicts a session, the next message resumes it
instead of failing; two quick messages start one session; two panels on
the same session no longer silence (or, on the Model API backend, cancel)
each other when one closes; a panel closed while its session starts keeps
nothing running. - Signing in with the browser waits for a new sign-in, not a stale
credential file, and pressing the button twice opens one terminal; a
broken OS keyring no longer blocks the Muse Code backend. - Model API retries show in the transcript ("Attempt 2/5 failed …"), Stop
cuts a retry wait short, and aRetry-Aftergiven as a date is honoured. - The IDE tool server restarts if its first start failed, and the session
that needed it waits for it; a failing request answers 500. - New Conversation after a crash or a restart starts a new session
instead of continuing the old one with its first message. - Resuming a conversation that was waiting on an approval or a question
shows its card again, and a turn that was running when you resumed can be
stopped and steered. Each prompt shows one card, however often Muse Code
announces it, and a second panel on the same conversation sees the cards
still open. - A decision or answer that arrives after the request moved on says so as
information instead of an error; a refused decision opens the card again;
a request Muse Code no longer holds loses its card. A step already closed
by an "always" decision is no longer asked again. - Updates Muse Code could not deliver are recovered by reloading the
conversation; a queued message Muse Code withdrew reads "Not sent"; a
model the account cannot serve, and a message another client withdrew,
are notices. Unexpected notifications are logged once each. - On the Model API backend, a tool that fails (a missing folder, a disk
error) or a call Stop cuts off no longer breaks the rest of the
conversation;write_filecreates the folders it needs; ...
v0.5.5
Rewind across subagents, and the repository protected.
Fixed
- Rewind code to here reverts a subagent's edits too. Since 0.5.0 an
agent's rows live in its own transcript in the Agent map, and the rewind
only looked at the conversation, so a delegated run's edits stayed on
disk. Every edit now takes an arrival number when it completes, across
the conversation and its agents, and the rewind unwinds all of them in
the reverse of that order, so edits that overlap unwind cleanly. Found
through a reader's question about overlapping subagent edits.
Changed
- The repository is protected by GitHub rulesets:
maincannot be deleted
or force-pushed and takes changes through pull requests with the CI
checks green;v*tags cannot be deleted or moved; the admin bypasses
both for direct pushes and releases, logged. - Dependabot no longer proposes a new major of
@types/node: the typings
follow the Node major the workflows and the manifest'senginesrun on
(22); the 26.x proposal broke the type-aware lint's module resolution.
The pinned-SHA actions took their weekly bumps (checkout 7.0.1,
setup-node 7.0.0, setup-python 7.0.0, upload-artifact 7.0.1,
download-artifact 8.0.1, gitleaks-action 3.0.0).
v0.5.4
The documentation cleanup; released because the walkthrough, PRIVACY.md and
a setting's description ship inside the package.
Changed
- A documentation cleanup against the code: the walkthrough says dictation
is a Windows and macOS feature; PRIVACY.md says the panel lists models
when it opens while signed in, that the extension only checks whether
the CLI's credential file exists, and that Sign out and/logoutare
one action; SECURITY.md describes the machine-scoped settings and the
two backends' shell commands as they are; AGENTS.md, CONTRIBUTING.md,
CLAUDE.md,.env.example, the knip comment and two script headers no
longer describe the key injection removed in 0.1.0, a CI matrix that
never existed or an interface that does not; theautosavesetting's
description matches what it does; PLAN.md's architecture diagram, gates
table, open questions, budgets and milestone notes are brought up to
date, with a register row for the test-onlySelectioncasts. The
certification folder gains an index, the harness keeps its Chrome
profile in a temporary directory, and the Claude Code reference
screenshots left the repository.
v0.5.3
Added
- A way to support the project: the manifest's
sponsorlink puts a
Sponsor button on the Marketplace listing,.github/FUNDING.ymlputs one
on the repository, and the README ends with the same PayPal link the
author's other projects use.
v0.5.2
The first community fix, and the README brought up to date with the panel.
Fixed
- The prompt box grows with wrapped lines as well as newlines, up to ten
rows, and scrolls inside past that; a long single line no longer hides
behind a one-row box (#4, reported by dhaw97160). - The e2e suite's teardown on Windows no longer fails when the fake CLI's
executable is still held for a moment after its process has exited: the
temporary folders are removed with retries, and one that still cannot go
is reported and left to the OS rather than failing a green suite.
Changed
- The README describes the panel as it is at 0.5.x: the Open diff and
Revert buttons it still promised are gone since 0.4.2 (the diff editor is
behind Click to expand, revert is the rewind menu), subagents and the
Agent map, reply and quote with context, question cards, outputs opening
in the editor and the usage insights are in the highlights, the release
workflow's own Marketplace publish replaces the by-hand recipe, the live
drill's budget and measurements are current, and the three upstream Muse
Code issues are linked from Troubleshooting. Its eleven screenshots are
rendered from the shipped panel by the UI harness (npm run harness:shots) and say so; the 0.1.1 captures are gone.