v2.8.0
The sidebar is rebuilt as an Agent Timeline: the active task and its live plan on top, the conversation collapsible underneath, grouped tool activity, and a run summary (actions / checks / next step). Icons now come from VS Code's own codicon set instead of unicode glyphs, and the view is renamed "Chat" → "Agent Timeline" to match what it actually shows.
Changed
- Agent Timeline workbench. The panel is no longer a plain message list. It
now leads with the active task (title, subtitle, live plan), keeps the
conversation in a collapsible section below it, groups the run's tool calls
under "Recent tool activity" with a count and per-run collapse, and closes
with a "Run summary" strip — actions taken, checks passed/failed, and the
suggested next step. The composer moved into its own shell with attach and
mode controls. - View renamed "Chat" → "Agent Timeline". The view id (
codeep.chat) is
unchanged, so commands, keybindings and saved layouts keep working. - Real icons via
@vscode/codicons. Tool rows, plan steps, status and the
toolbar buttons use the codicon font instead of unicode glyphs, so they match
the editor at every theme and zoom level.npm run build:webviewcopies the
font and stylesheet intomedia/(scripts/copy-codicons.mjs), and the
webview CSP now allowsimg-src/font-srcfrom the extension origin.
Fixed
- The plan panel no longer spins forever.
beginTask()puts a spinning
"Building the plan..." placeholder in the plan area, but only aplan
notification cleared it — so any prompt the agent answered without a plan
ended on a permanent spinner, as did every restored transcript (session
load and window reload both replay a task and complete it immediately).
Completing a run without a plan now shows "No plan steps for this run." - Tool icons follow the ACP tool kind, not the tool's title. The icon was
picked by substring-matching the title with the read/search branch first, so
"Edit src/webview/list.ts" and "Write README.md" drew a magnifying glass, and
theexecutekind wasn't recognised at all. The kind is now mapped directly
(read/search, edit/write/delete/move, execute, fetch, think) and the title
regex is only a fallback for CLIs that don't send one. - "Checks" in the run summary counts commands only. Any tool call whose
title matchedtest|check|lint|build|verify|commandwas counted, so simply
readingchatPanel.test.tsscored a check — and a failed read painted the
summary red. Onlyexecutetool calls count now. - ~267 KB of dead payload dropped from the .vsix.
media/Screenshot-1.png
andScreenshot-2.pngwere still packaged although nothing references them.
Security
- The webview CSP nonce now comes from the CSPRNG. It was
Math.random().toString(36). Not exploitable — every value interpolated into
the page is an extension-controlled webview URI — but the nonce is the only
thing that lets a script run in that document, and this release materially
grows the webview's DOM surface. It'scrypto.randomBytes(16)now.
Internal
- The release workflow asserts the tag matches
package.json.vsce
packages whateverpackage.jsonsays regardless of the--outfilename, so
a mismatched tag would have shipped the previous version's bits and then been
rejected by the Marketplace as a duplicate. It now fails the job instead,
mirroring the CLI'srelease-binaries.yml. - Local audit / design-QA scratch (
.codex-audit/,design-qa.md) is
git-ignored, not just.vscodeignored.