Skip to content

Releases: akadeepesh/contextzip

v0.4.4 — self-update command, apply-zip structure fixes, backups removed

Choose a tag to compare

@akadeepesh akadeepesh released this 21 Sep 21:15

Added

  • contextzip update / cz update — checks PyPI for a newer release and
    updates in place, matching however you installed it (pip, pipx, or
    uv tool). --check to just see if one's available, --yes to skip
    the confirm.
  • .contextzip/inbox/ now comes with a README.txt, created the moment
    the workspace is first set up, explaining what the folder is for and
    how to use it.

Fixed

  • apply-zip was dumping a zip's wrapper folder verbatim (e.g.
    project/app/dashboard/... instead of app/dashboard/...) in two
    related cases: when the wrapper's name happened to match a real folder
    already in the project, and when the manifest used to check was scoped
    to a small subset of the project (e.g. a git-diff manifest) and
    couldn't settle the decision either way. Both now resolve correctly —
    the first via manifest match-rate comparison, the second via a
    fallback to the project's real on-disk directory layout.
  • apply-zip <path> was writing its .apply-report.txt next to the
    zip's own location — so pointing it at a zip outside
    .contextzip/inbox/ (e.g. one sitting in your project root) left a
    stray report cluttering the repo. Reports now always go to
    .contextzip/inbox/.
  • Auto-cleanup wasn't pruning old apply-report.txt files left loose in
    .contextzip/inbox/ — they now get cleaned up like everything else.

Removed

  • The .contextzip/backups/ per-apply backup mechanism, entirely.
    apply-zip no longer backs up overwritten files before writing them;
    the manifest-diff confirmation and the always-archived applied zip
    remain the safety net. Any leftover backups/ folder from an older
    install is now wiped outright by auto-cleanup.

Full Changelog: v0.4.2...v0.4.4

v0.4.3 — apply-zip structure fix, self-update command

Choose a tag to compare

@akadeepesh akadeepesh released this 20 Sep 06:27

Added

  • contextzip update / cz update — checks PyPI for a newer release and
    updates in place, matching however you installed it (pip, pipx, or
    uv tool). Use --check to just see if one's available, --yes to
    skip the confirm.

Fixed

  • apply-zip was dumping a nested copy of your project at the root
    instead of updating files in place, whenever the AI-returned zip's
    wrapper folder happened to share a name with a real folder already in
    your project (very common — e.g. a zip wrapped in myproject/ when
    your package dir is also myproject/). It's now resolved using the
    zip manifest instead of guessing from what's on disk.
  • contextzip config --ui now closes its own browser tab after you save,
    instead of just telling you that you can.

Full Changelog: v0.4.2...v0.4.3

v0.4.2 — Secrets stay out, workspace stays local

Choose a tag to compare

@akadeepesh akadeepesh released this 03 Sep 03:18

Added

  • Secret redaction, for real this time. limits.redact_secrets
    was persisted in config since 0.4.0 but never actually enforced.
    Now, text files going into the archive are scanned for
    secret-shaped values (API keys, tokens, private-key blocks, JWTs)
    and matches are replaced with [REDACTED] before zipping. Binary
    and oversized files are never scanned. Every redaction is called out
    in the terminal and itemized in the .report.txt file — nothing
    happens silently.

Changed

  • .contextzip/ is fully local by default now. config.json used
    to be the one file in the workspace that stayed trackable
    automatically. That exception is gone — the whole workspace is
    git-ignored with no carve-outs. If your team wants to share
    config.json, it's one explicit git add -f .contextzip/config.json
    away, same as it's always been for everything else in there.

v0.4.1 — Quieter terminal, clearer workspace, enforced redaction

Choose a tag to compare

@akadeepesh akadeepesh released this 30 Aug 18:00

Changed

  • Terminal output redesigned. Every command now prints a compact,
    one-line-per-step log (✓ / ! / ✗) instead of boxed Rich panels and
    tables — matching the register of tools like pnpm, vite, and
    ruff. A full-width terminal is no longer needed to read a run.
  • "Scanned" and "Packed" are now one line, e.g.
    Scanned 1518 files & Packed 42 files · 42 included (394 KB), 1476 excluded, 394 KB → 126 KB, ↓68% smaller.
  • Removed the contextzip vX.X.X / project-path banner — output now
    starts directly at the first real step.
  • .gitignore patterns applied and "folder opened" confirmations are
    no longer printed.
  • apply-zip's manifest auto-detection now searches recursively, so
    it keeps finding the right manifest under the new folder layout
    below.

Added

  • Per-mode output folders. .contextzip/output/ now splits by
    run mode — codebase/, git-changes/, prompt/ (vibe.zip), and
    watch/ — so it's unambiguous which zip came from which command,
    without guessing.
  • Automatic workspace cleanup. After every successful command,
    old zip/manifest/report sets, backups, and archived applied-zips
    are pruned automatically down to the most recent one. Controlled by
    new cleanup.enabled / cleanup.keep_recent project settings
    (default: keep 1, no prompts).
  • Enforced limits.redact_secrets. Previously persisted in
    config but never actually applied — now, text files going into the
    archive are scanned for secret-shaped values (API keys, tokens,
    private-key blocks, JWTs) and matches are replaced with
    [REDACTED] before zipping. Binary and oversized files are never
    scanned.
  • .report.txt files. Every run now writes a full plain-text
    report alongside its ZIP with everything that used to fill the
    terminal — exclusion breakdown, full file list, per-file warnings.
    -v/--verbose still prints the same detail inline.

v0.4.0 — Config UI redesign & expanded project preferences

Choose a tag to compare

@akadeepesh akadeepesh released this 26 Aug 16:06

This release rebuilds contextzip config --ui and roughly doubles
what's configurable per project. No breaking changes — existing
.contextzip/config.json files keep working as-is; new fields default
to their prior hardcoded behavior when absent.

Config UI redesign

contextzip config --ui is now five tabs instead of one pane:
Files, AI selection, Workspace, Advanced, and a live
Raw JSON preview. The file tree and pattern list now render as a
diff — a solid gutter and +/- marks on every row — instead of
checkboxes. Still a single dependency-free HTML file: no build step,
no Node.js, no network calls from the page itself.

New project preferences

All editable from the UI or by hand in .contextzip/config.json:

  • ai.prompt_template — house conventions prepended to every generated
    prompt.txt.
  • limits.max_file_size_mb — per-project large-file threshold (was a
    fixed 1 MB).
  • applied_zip_retention — how many past apply-zip archives to keep
    before pruning (was hardcoded to 1).
  • webui.auto_open / webui.port — skip auto-launching a browser tab
    and/or pin the UI to a fixed local port.

Full changelog: see CHANGELOG.md

v0.3.9 — Security hardening & apply-zip structure fixes

Choose a tag to compare

@akadeepesh akadeepesh released this 26 Aug 16:00

This release focuses on tightening secret handling and fixing a real
correctness bug in apply-zip. No breaking changes.

Security

  • Config file (~/.config/contextzip/config.json) permissions are now
    locked to 0600 on every write, not just creation — closes a gap
    where a pre-existing or loosely-created config file could stay
    group/world-readable and expose a plaintext Gemini API key.
  • The local config UI (contextzip config --ui) now compares its
    session token with hmac.compare_digest instead of ==, removing a
    timing side-channel.
  • Massively expanded the list of secret/credential files that are
    always excluded from packaged zips: SSH private keys, keystores
    (.jks, .keystore, .p12, .pkcs12, .ppk), CLI credential files
    (.npmrc, .netrc, .pypirc, .pgpass, .dockercfg), cloud
    provider credentials (.aws/credentials, service-account JSON,
    kubeconfig), and Terraform state (*.tfstate*, .terraform/).

Fixed

  • apply-zip now detects when an AI-returned zip has everything nested
    under one incidental wrapper folder (the shape produced by zip -r
    or GitHub's "Download ZIP") and strips it automatically when doing so
    clearly improves the match against your project's manifest.
  • apply-zip now warns — instead of silently proceeding — when a zip's
    structure barely matches the project at all.

Changed

  • .contextzip/inbox/applied/ now keeps only the most recently applied
    zip instead of growing indefinitely.

Full changelog: see CHANGELOG.md

v0.3.8 — Close the loop with apply-zip

Choose a tag to compare

@akadeepesh akadeepesh released this 24 Aug 03:32

contextzip has always handled getting your code out to an AI tool. This release handles the trip back in.

contextzip apply-zip

Once an AI tool hands you back a ZIP with its changes, drop it into .contextzip/inbox/ and run:

contextzip apply-zip

No manual unzip-and-hope, no wondering whether you've overwritten something you meant to keep.

How it stays safe

Every ZIP contextzip creates now gets a small manifest — a hash of each included file — written next to it in .contextzip/output/. It's local only and never goes in the ZIP itself, so it's never uploaded and nothing an AI model (or a teammate) would ever notice or ask about.

apply-zip uses that manifest to classify every file before touching anything:

Status Meaning Applied automatically?
New Wasn't part of the original zip ✅
Modified Sent, changed, and your copy hasn't moved since ✅
Unchanged Identical to what's on disk Skipped
Drifted You edited (or deleted) it locally after zipping ⏸️ asks first
Untracked No baseline to compare against ⏸️ asks first

The common case — zip it, AI edits it, nothing else changes in the meantime — applies straight through with just a summary. Anything riskier stops and asks.

Other guarantees

  • Path-traversal protection — any zip entry resolving outside the project is refused outright, no override.
  • Automatic backups — every overwritten file is copied to .contextzip/backups/<timestamp>/ first.
  • No silent deletions — v1 only adds and modifies; nothing is ever removed from disk based on a zip's contents.
  • Archived, not deleted — consumed zips move to .contextzip/inbox/applied/, so there's always a trail back to what was applied and when.

Usage

contextzip apply-zip                    # auto-detect from .contextzip/inbox/
contextzip apply-zip fix.zip            # explicit path overrides the inbox
contextzip apply-zip --dry-run -v       # preview every file's status first
contextzip apply-zip -y                 # skip confirmation, even if risky

Also available from Python:

from contextzip import apply_zip
result = apply_zip()
print(f"Wrote {len(result.written)} files, backup at {result.backup_dir}")

Full Changelog: v0.3.7...v0.3.8

v0.3.7 — Visual config UI

Choose a tag to compare

@akadeepesh akadeepesh released this 23 Aug 20:40

Set up include/exclude by clicking, not writing patterns

contextzip config --ui opens a local browser tab where you can see your actual project tree, toggle files/folders on and off, and watch the included file count and packed size update live — no more hand-writing glob patterns in config.json.

It also suggests things you probably want excluded but haven't yet: PDFs, Office docs, fonts, video/audio, design files, and anything over 1MB that isn't already caught by contextzip's default rules. One click on a suggestion chip excludes the whole group.

If you run contextzip in a project with no config at all, it'll offer to open this for you automatically — decline once and it won't ask again.

Everything stays local. The server only binds to 127.0.0.1, every request needs a random per-session token (same approach Jupyter Notebook uses), and the page makes zero network calls beyond talking back to that local server — no CDN scripts, no telemetry, nothing about your project structure ever leaves your machine.

contextzip config --ui

Full changelog

See CHANGELOG.md

v0.3.6 — CLI alias, project workspace, and configuration

Choose a tag to compare

@akadeepesh akadeepesh released this 22 Aug 21:39

Added

  • cz CLI alias. cz can now be used as a shorthand for contextzip, with the same commands and behavior.
  • Project workspace. Contextzip now uses a .contextzip/ workspace containing config.json and an output/ directory for generated context archives.
  • Project configuration. Added .contextzip/config.json for persistent project preferences such as always_include and always_exclude.
  • AI preferences. Added configuration for AI-assisted file selection, including the provider, enabled state, and maximum number of files.
  • Configured file selection. always_include and always_exclude preferences are now applied during context generation.
  • AI file limits. The configured ai.max_files value is now respected by the AI selection pipeline.

Changed

  • Generated context archives are now stored under .contextzip/output/.
  • Project configuration is now handled through .contextzip/config.json.
  • The existing personal configuration remains available for machine-specific settings and credentials such as API keys.

Deprecated

  • .contextzip.json project configuration. Project configuration is moving to .contextzip/config.json.

Full changelog: see CHANGELOG.md

v0.3.5 — Monorepo-aware detection, configurable workspace location

Choose a tag to compare

@akadeepesh akadeepesh released this 09 Aug 14:31

Added

  • Monorepo detection. contextzip now scans a shallow, bounded subdirectory
    tree (not just the project root) for framework markers, so a layout like
    frontend/package.json + backend/requirements.txt gets both ecosystems
    detected and both rule sets applied — instead of silently falling back to
    only base exclusion rules. Detection output shows where each ecosystem was
    found: Next.js (frontend/) + FastAPI (backend/).
  • Configurable workspace location. .contextzip/ still defaults to your
    git root, but can now be pinned per-machine (contextzip config --set-workspace cwd|git-root|<path>) or shared with your team via a
    committed .contextzip.json. Full precedence order in the README.

Fixed

  • .gitignore registration for .contextzip/ no longer assumes the
    workspace directory's parent is always the git root — fixes a case that
    would've broken under a custom workspace location.

Removed

  • eod and handoff commands, and the Claude.ai session-key config option
    they used. Both depended on an undocumented Claude.ai endpoint. See
    CHANGELOG.md for the full list of removed internals.

Full changelog: see CHANGELOG.md