v0.3.1 — Security patch + reasoning model support
Security
file_deleteelevated from T2 → T3 — recursive directory deletion now requires explicit approval whenauto_approve_up_tois set to T2. Previously, an LLM could delete entire directory trees (including~/Repos) without confirmation.
Fixes
- Reasoning/thinking stream parsing — SSE
reasoningandreasoning_contentfields (used by Qwen 3.5, DeepSeek-R1, etc.) are now properly deserialized and emitted asThinkingDeltaevents. - Thinking-only response fallback — When a reasoning model produces only thinking content with no visible text (common via OpenAI-compat APIs), the thinking is promoted to text so the user gets a response.
- Provider preset defaults applied from config file —
base_urlandextra_headersfor known providers (Ollama, Cerebras, Groq, etc.) were only applied when using env-var fallback config. Now correctly applied when loading fromconfig.toml. - RunError event publishing — When the agent encounters an LLM error (e.g., expired API key), a
RunErrorevent is now published so the channel dispatcher doesn't hang indefinitely.
Full Changelog
Full Changelog: v0.3.0...v0.3.1