Releases: akadeepesh/contextzip
Release list
v0.4.4 — self-update command, apply-zip structure fixes, backups removed
Added
contextzip update/cz update— checks PyPI for a newer release and
updates in place, matching however you installed it (pip, pipx, or
uv tool).--checkto just see if one's available,--yesto skip
the confirm..contextzip/inbox/now comes with aREADME.txt, created the moment
the workspace is first set up, explaining what the folder is for and
how to use it.
Fixed
apply-zipwas dumping a zip's wrapper folder verbatim (e.g.
project/app/dashboard/...instead ofapp/dashboard/...) in two
related cases: when the wrapper's name happened to match a real folder
already in the project, and when the manifest used to check was scoped
to a small subset of the project (e.g. a git-diff manifest) and
couldn't settle the decision either way. Both now resolve correctly —
the first via manifest match-rate comparison, the second via a
fallback to the project's real on-disk directory layout.apply-zip <path>was writing its.apply-report.txtnext to the
zip's own location — so pointing it at a zip outside
.contextzip/inbox/(e.g. one sitting in your project root) left a
stray report cluttering the repo. Reports now always go to
.contextzip/inbox/.- Auto-cleanup wasn't pruning old
apply-report.txtfiles left loose in
.contextzip/inbox/— they now get cleaned up like everything else.
Removed
- The
.contextzip/backups/per-apply backup mechanism, entirely.
apply-zipno longer backs up overwritten files before writing them;
the manifest-diff confirmation and the always-archived applied zip
remain the safety net. Any leftoverbackups/folder from an older
install is now wiped outright by auto-cleanup.
Full Changelog: v0.4.2...v0.4.4
v0.4.3 — apply-zip structure fix, self-update command
Added
contextzip update/cz update— checks PyPI for a newer release and
updates in place, matching however you installed it (pip, pipx, or
uv tool). Use--checkto just see if one's available,--yesto
skip the confirm.
Fixed
apply-zipwas dumping a nested copy of your project at the root
instead of updating files in place, whenever the AI-returned zip's
wrapper folder happened to share a name with a real folder already in
your project (very common — e.g. a zip wrapped inmyproject/when
your package dir is alsomyproject/). It's now resolved using the
zip manifest instead of guessing from what's on disk.contextzip config --uinow closes its own browser tab after you save,
instead of just telling you that you can.
Full Changelog: v0.4.2...v0.4.3
v0.4.2 — Secrets stay out, workspace stays local
Added
- Secret redaction, for real this time.
limits.redact_secrets
was persisted in config since 0.4.0 but never actually enforced.
Now, text files going into the archive are scanned for
secret-shaped values (API keys, tokens, private-key blocks, JWTs)
and matches are replaced with[REDACTED]before zipping. Binary
and oversized files are never scanned. Every redaction is called out
in the terminal and itemized in the.report.txtfile — nothing
happens silently.
Changed
.contextzip/is fully local by default now.config.jsonused
to be the one file in the workspace that stayed trackable
automatically. That exception is gone — the whole workspace is
git-ignored with no carve-outs. If your team wants to share
config.json, it's one explicitgit add -f .contextzip/config.json
away, same as it's always been for everything else in there.
v0.4.1 — Quieter terminal, clearer workspace, enforced redaction
Changed
- Terminal output redesigned. Every command now prints a compact,
one-line-per-step log (✓ / ! / ✗) instead of boxed Rich panels and
tables — matching the register of tools likepnpm,vite, and
ruff. A full-width terminal is no longer needed to read a run. - "Scanned" and "Packed" are now one line, e.g.
Scanned 1518 files & Packed 42 files · 42 included (394 KB), 1476 excluded, 394 KB → 126 KB, ↓68% smaller. - Removed the
contextzip vX.X.X/ project-path banner — output now
starts directly at the first real step. .gitignore patterns appliedand "folder opened" confirmations are
no longer printed.apply-zip's manifest auto-detection now searches recursively, so
it keeps finding the right manifest under the new folder layout
below.
Added
- Per-mode output folders.
.contextzip/output/now splits by
run mode —codebase/,git-changes/,prompt/(vibe.zip), and
watch/— so it's unambiguous which zip came from which command,
without guessing. - Automatic workspace cleanup. After every successful command,
old zip/manifest/report sets, backups, and archived applied-zips
are pruned automatically down to the most recent one. Controlled by
newcleanup.enabled/cleanup.keep_recentproject settings
(default: keep 1, no prompts). - Enforced
limits.redact_secrets. Previously persisted in
config but never actually applied — now, text files going into the
archive are scanned for secret-shaped values (API keys, tokens,
private-key blocks, JWTs) and matches are replaced with
[REDACTED]before zipping. Binary and oversized files are never
scanned. .report.txtfiles. Every run now writes a full plain-text
report alongside its ZIP with everything that used to fill the
terminal — exclusion breakdown, full file list, per-file warnings.
-v/--verbosestill prints the same detail inline.
v0.4.0 — Config UI redesign & expanded project preferences
This release rebuilds contextzip config --ui and roughly doubles
what's configurable per project. No breaking changes — existing
.contextzip/config.json files keep working as-is; new fields default
to their prior hardcoded behavior when absent.
Config UI redesign
contextzip config --ui is now five tabs instead of one pane:
Files, AI selection, Workspace, Advanced, and a live
Raw JSON preview. The file tree and pattern list now render as a
diff — a solid gutter and +/- marks on every row — instead of
checkboxes. Still a single dependency-free HTML file: no build step,
no Node.js, no network calls from the page itself.
New project preferences
All editable from the UI or by hand in .contextzip/config.json:
ai.prompt_template— house conventions prepended to every generated
prompt.txt.limits.max_file_size_mb— per-project large-file threshold (was a
fixed 1 MB).applied_zip_retention— how many pastapply-ziparchives to keep
before pruning (was hardcoded to 1).webui.auto_open/webui.port— skip auto-launching a browser tab
and/or pin the UI to a fixed local port.
Full changelog: see CHANGELOG.md
v0.3.9 — Security hardening & apply-zip structure fixes
This release focuses on tightening secret handling and fixing a real
correctness bug in apply-zip. No breaking changes.
Security
- Config file (
~/.config/contextzip/config.json) permissions are now
locked to0600on every write, not just creation — closes a gap
where a pre-existing or loosely-created config file could stay
group/world-readable and expose a plaintext Gemini API key. - The local config UI (
contextzip config --ui) now compares its
session token withhmac.compare_digestinstead of==, removing a
timing side-channel. - Massively expanded the list of secret/credential files that are
always excluded from packaged zips: SSH private keys, keystores
(.jks,.keystore,.p12,.pkcs12,.ppk), CLI credential files
(.npmrc,.netrc,.pypirc,.pgpass,.dockercfg), cloud
provider credentials (.aws/credentials, service-account JSON,
kubeconfig), and Terraform state (*.tfstate*,.terraform/).
Fixed
apply-zipnow detects when an AI-returned zip has everything nested
under one incidental wrapper folder (the shape produced byzip -r
or GitHub's "Download ZIP") and strips it automatically when doing so
clearly improves the match against your project's manifest.apply-zipnow warns — instead of silently proceeding — when a zip's
structure barely matches the project at all.
Changed
.contextzip/inbox/applied/now keeps only the most recently applied
zip instead of growing indefinitely.
Full changelog: see CHANGELOG.md
v0.3.8 — Close the loop with apply-zip
contextzip has always handled getting your code out to an AI tool. This release handles the trip back in.
contextzip apply-zip
Once an AI tool hands you back a ZIP with its changes, drop it into .contextzip/inbox/ and run:
contextzip apply-zipNo manual unzip-and-hope, no wondering whether you've overwritten something you meant to keep.
How it stays safe
Every ZIP contextzip creates now gets a small manifest — a hash of each included file — written next to it in .contextzip/output/. It's local only and never goes in the ZIP itself, so it's never uploaded and nothing an AI model (or a teammate) would ever notice or ask about.
apply-zip uses that manifest to classify every file before touching anything:
| Status | Meaning | Applied automatically? |
|---|---|---|
| New | Wasn't part of the original zip | ✅ |
| Modified | Sent, changed, and your copy hasn't moved since | ✅ |
| Unchanged | Identical to what's on disk | Skipped |
| Drifted | You edited (or deleted) it locally after zipping | ⏸️ asks first |
| Untracked | No baseline to compare against | ⏸️ asks first |
The common case — zip it, AI edits it, nothing else changes in the meantime — applies straight through with just a summary. Anything riskier stops and asks.
Other guarantees
- Path-traversal protection — any zip entry resolving outside the project is refused outright, no override.
- Automatic backups — every overwritten file is copied to
.contextzip/backups/<timestamp>/first. - No silent deletions — v1 only adds and modifies; nothing is ever removed from disk based on a zip's contents.
- Archived, not deleted — consumed zips move to
.contextzip/inbox/applied/, so there's always a trail back to what was applied and when.
Usage
contextzip apply-zip # auto-detect from .contextzip/inbox/
contextzip apply-zip fix.zip # explicit path overrides the inbox
contextzip apply-zip --dry-run -v # preview every file's status first
contextzip apply-zip -y # skip confirmation, even if riskyAlso available from Python:
from contextzip import apply_zip
result = apply_zip()
print(f"Wrote {len(result.written)} files, backup at {result.backup_dir}")Full Changelog: v0.3.7...v0.3.8
v0.3.7 — Visual config UI
Set up include/exclude by clicking, not writing patterns
contextzip config --ui opens a local browser tab where you can see your actual project tree, toggle files/folders on and off, and watch the included file count and packed size update live — no more hand-writing glob patterns in config.json.
It also suggests things you probably want excluded but haven't yet: PDFs, Office docs, fonts, video/audio, design files, and anything over 1MB that isn't already caught by contextzip's default rules. One click on a suggestion chip excludes the whole group.
If you run contextzip in a project with no config at all, it'll offer to open this for you automatically — decline once and it won't ask again.
Everything stays local. The server only binds to 127.0.0.1, every request needs a random per-session token (same approach Jupyter Notebook uses), and the page makes zero network calls beyond talking back to that local server — no CDN scripts, no telemetry, nothing about your project structure ever leaves your machine.
contextzip config --uiFull changelog
See CHANGELOG.md
v0.3.6 — CLI alias, project workspace, and configuration
Added
czCLI alias.czcan now be used as a shorthand forcontextzip, with the same commands and behavior.- Project workspace. Contextzip now uses a
.contextzip/workspace containingconfig.jsonand anoutput/directory for generated context archives. - Project configuration. Added
.contextzip/config.jsonfor persistent project preferences such asalways_includeandalways_exclude. - AI preferences. Added configuration for AI-assisted file selection, including the provider, enabled state, and maximum number of files.
- Configured file selection.
always_includeandalways_excludepreferences are now applied during context generation. - AI file limits. The configured
ai.max_filesvalue is now respected by the AI selection pipeline.
Changed
- Generated context archives are now stored under
.contextzip/output/. - Project configuration is now handled through
.contextzip/config.json. - The existing personal configuration remains available for machine-specific settings and credentials such as API keys.
Deprecated
.contextzip.jsonproject configuration. Project configuration is moving to.contextzip/config.json.
Full changelog: see CHANGELOG.md
v0.3.5 — Monorepo-aware detection, configurable workspace location
Added
- Monorepo detection. contextzip now scans a shallow, bounded subdirectory
tree (not just the project root) for framework markers, so a layout like
frontend/package.json+backend/requirements.txtgets both ecosystems
detected and both rule sets applied — instead of silently falling back to
only base exclusion rules. Detection output shows where each ecosystem was
found:Next.js (frontend/) + FastAPI (backend/). - Configurable workspace location.
.contextzip/still defaults to your
git root, but can now be pinned per-machine (contextzip config --set-workspace cwd|git-root|<path>) or shared with your team via a
committed.contextzip.json. Full precedence order in the README.
Fixed
.gitignoreregistration for.contextzip/no longer assumes the
workspace directory's parent is always the git root — fixes a case that
would've broken under a custom workspace location.
Removed
eodandhandoffcommands, and the Claude.ai session-key config option
they used. Both depended on an undocumented Claude.ai endpoint. See
CHANGELOG.md for the full list of removed internals.
Full changelog: see CHANGELOG.md