Releases: andre-motta/tongs
Release list
v1.0.3
Released 2026-09-27. This patch release fixes crashes and a data-loss risk in
the terminal app and the desktop app beta. The desktop inbox now loads a page
at a time, so a repository with thousands of open pull requests no longer
stops the desktop service. Nothing in your configuration or drafts changes.
Install
pipx install tongs==1.0.3pip install tongs==1.0.3 and uv tool install tongs==1.0.3 work the same
way. To upgrade an existing installation, run pipx upgrade tongs, or
uv tool upgrade tongs, or pip install --upgrade tongs. If you use the
per-user desktop app, install the matching desktop release after the core:
tongs desktop updateThe desktop app (beta)
- The inbox loads a page at a time. A repository with thousands of open
pull requests, such aspytorch/pytorch, used to return every one of them
in a single response, which the desktop app rejected, stopping the desktop
service. Each repository now shows its newest 100 reviews as soon as they
arrive. All Open merges repositories by update time and loads more from
whichever repository comes next when you scroll to the end, so one large
repository no longer buries the others or spends your rate limit on old pull
requests. CI status is fetched only for the reviews on screen.
(#344) - Large discussions no longer stop the desktop service. A merge request
with about 1,200 comment threads produced a response the desktop app
rejected. Discussions now load in pages, and any response that is still too
large fails only its own request, with a clear message, instead of stopping
the service.
(#292) - The header shows "Local service not running" as soon as the desktop service
stops, instead of still saying it is connected.
(#345) - The marker that shows where a link really goes is styled from the shared
stylesheet, so themes can restyle it.
(#341,
#346)
Review drafts
- tongs starts even when a saved submission is missing or damaged. A
submission attempt that another tongs process cancelled, or that can no
longer be read, used to stop the terminal app, the desktop app and the MCP
server from starting, and the only way out was deletingdrafts.db. Startup
now skips a missing attempt. A damaged one returns its draft to editing with
all of its content kept, and tongs shows a one-time warning that part of the
review may already be on the forge, so check it before submitting again.
(#291)
The terminal app
- Square brackets in a merge request title, label, author, file path or
repository name are shown as written. A title such asFix [/] parsing
used to crash the app on every launch, and[skip ci]or[WIP]silently
disappeared.
(#290)
Requirements
- tongs now requires Textual 4.0 or later. The terminal app already used
features from Textual 3.1 and newer, so the old minimum of 1.0 was wrong.
pipx,uvandpipupgrade Textual for you, and Fedora 44 ships Textual
4.0.
Documentation
- The homepage and the first-run guide say that only github.com, gitlab.com
and hosts listed under[hosts.*]are recognized, matching the change in
1.0.2.
(#347)
Continuous integration
- Renderer tests wait up to five seconds for asynchronous updates and print a
short message when a wait fails, instead of failing on busy runners.
(#338) - Re-running only the failed jobs of a pull request can turn the required
check green again.
(#339) - The contributor guides give memory guard values that work for the site and
desktop builds on machines with many CPU cores.
(#342)
Release assets
The GitHub Release
carries the same set of assets as 1.0.2, for version 1.0.3: the per-user
archive with its release manifest and Sigstore attestation, the unsigned Fedora
44 RPMs with their source-built companion packages, the archive SBOM with its
attestation, and SHA256SUMS. Install the RPMs together with
dnf install ./*.rpm.
Known issues
Known issues lists the defects known in 1.0.3, with
the issue and milestone for each fix.
Thanks to @nightcityblade for their first
contribution to tongs.
v1.0.2
Released 2026-09-27. This patch release fixes two security issues in how
tongs handles forge credentials, shows where links point in the desktop app,
and pins every dependency the release builds install. Everyone should upgrade,
and especially anyone who runs the tongs-mcp server. Nothing in your
configuration or drafts changes, unless you relied on one of the behaviors
described under Security.
Install
pipx install tongs==1.0.2pip install tongs==1.0.2 and uv tool install tongs==1.0.2 work the same
way. To upgrade an existing installation, run pipx upgrade tongs, or
uv tool upgrade tongs, or pip install --upgrade tongs. If you use the
per-user desktop app, install the matching desktop release after the core:
tongs desktop updateSecurity
Both issues affect tongs 1.0.0 and 1.0.1 and are fixed in 1.0.2.
tongs-mcponly talks to configured hosts.
(GHSA-4cw3-82cv-q28x,
high) The MCP server accepted any hostname that containedgithubor
gitlab, looked up a token for it and sent that token to the host. Because
MCP tools are driven by a language model that also reads merge request text,
untrusted text could steer a tool call toward such a host. The MCP server now
accepts onlygithub.com,gitlab.comand the hosts in yourconfig.toml,
exactly like the terminal and desktop apps, and rejects anything else before
any credential lookup or request. tongs also no longer guesses the forge type
from a hostname anywhere: a self-hosted GitHub or GitLab instance must be
listed inconfig.toml, as the configuration reference
already required.~/.netrcis read more strictly.
(GHSA-v7v3-jh3w-pj3h,
medium) tongs used thedefaultentry of~/.netrcwhen nomachineline
named the forge host, and sent that password as a forge token. Only a
machineentry that names the host is used now. A~/.netrcthat cannot be
parsed produces an error that names the line, never its contents. Error text
returned by the MCP server is redacted, and redaction now also coversghr_
andglrt-tokens and credentials written into URLs.
If you kept a forge token in the default entry of ~/.netrc, move it to a
machine <host> entry. Security and signing describes
the full credential lookup.
Reviews
These apply to the terminal app and the desktop app.
- A comment or approval the forge rejects as invalid (GitHub 422, GitLab 400)
is reported as a rejected request that you can correct, instead of an
unknown outcome that asks you to reconcile the review. Approving your own
pull request on GitHub says that GitHub does not allow it.
(#315,
#333)
The desktop app (beta)
- Links show where they go. Every link in a merge request description or
comment names its destination host in its tooltip and to screen readers.
When the link text looks like a web address on a different host, such as a
link readinggithub.com/org/repothat points elsewhere, the real host is
shown next to it.
(#321) - Desktop plugin assets are checked for symlinks along the whole path from
the plugin package, including packages split across several directories,
and archive entries with extended tar headers are rejected before they are
read. (#329,
#334) - An unexpected failure while submitting a review says so, offers Retry, and
no longer suggests refreshing. The desktop service logs the operation and a
redacted cause.
(#233,
#280)
The terminal app
- The inbox has a Forge column that shows GH or GL for each merge
request, matching the repository list.
(#254,
#262)
Release and packaging
- Pinned release builds. The jobs that sign and publish the desktop
release, and the job that builds the PyPI packages, install only
hash-locked Python packages, including the build backend. The desktop archive
builder installs only pinned, hash-checked RPMs with every package repository
disabled. Every CI workflow keeps its checkout credentials out of the working
tree and has a timeout, and a test checks all of this for every workflow.
(#303) - The companion Python RPM changelogs name the project's packaging address.
(#327,
#335) - The pull request template reminds contributors to update the known issues
page when a fix lands.
(#332)
Release assets
The GitHub Release
carries the same set of assets as 1.0.1, for version 1.0.2: the per-user
archive with its release manifest and Sigstore attestation, the unsigned Fedora
44 RPMs with their source-built companion packages, the archive SBOM with its
attestation, and SHA256SUMS. Install the RPMs together with
dnf install ./*.rpm.
Known issues
Known issues lists the defects known in 1.0.2, with
the issue and milestone for each fix. The next patch releases, 1.0.3 through
1.0.9, each fix one group of them.
Several fixes in this release were planned for later patch releases and
arrived early as community contributions. Thanks to
@GhostCoder6969,
@tayfuryldz and
@Tiyatrotist for their work.
v1.0.1
Released 2026-09-27. This is the first patch release of tongs 1.0. It fixes
the defects found since 1.0.0 in the terminal app, credentials and the desktop
app beta, and moves the review actions in the desktop app into a header that
every review tab shares. Nothing in your configuration or drafts changes.
Install
pipx install tongs==1.0.1pip install tongs==1.0.1 and uv tool install tongs==1.0.1 work the same
way. To upgrade an existing installation, run pipx upgrade tongs, or
uv tool upgrade tongs, or pip install --upgrade tongs. If you use the
per-user desktop app, install the matching desktop release after the core:
tongs desktop updateFor a first desktop install, run tongs --install-desktop instead. Plain
tongs never downloads or starts the desktop app on its own.
Credentials
These apply to the terminal app, the desktop app and the MCP server, which
share the same forge clients.
- Rotated and expired tokens are picked up. When a request gets a 401,
tongs resolves the token again through the same lookup and retries once. For
GitLab it first runsglab auth status --hostname <host>, which makes glab
refresh and save an expired OAuth login. A second 401 is still reported as
an authentication error. You no longer have to restart tongs after rotating
a token.
(#186,
#245) - GitLab tokens are read from glab. tongs now reads the token glab stores
withglab config get token --host <host>, which covers OAuth logins,
personal access tokens and keyring-backed tokens. The 1.0.0 lookup always
failed and fell through to~/.netrcor the keyring, so a stale token there
caused 401 errors.
(#245)
Security and signing describes
the full credential lookup.
The terminal app
- Retrying or cancelling a job reloads the job list you are on.
Ctrl+Ron
the Pipeline tab refreshes the level you are looking at: the pipeline list,
a pipeline's jobs, or a job log.
(#253) - The log search box stays visible above its status line, so you can see what
you type. (#221) F2in a job log writes plain text to your editor, without raw ANSI color
codes. (#222)- "No forges discovered yet" appears only once repository discovery has
finished and found nothing, instead of flashing at startup.
(#255) - The review draft save worker no longer touches the comment editor once the
review screen has closed.
(#166)
The desktop app (beta)
- Review actions on every tab. Merge, Close, Reopen and Remove approval
now sit in a review header next to the Your review button on
Overview, Files changed and Discussions. Overview gains the
Your review drawer too. An unknown result from any immediate comment,
reply or verdict can be acknowledged from the same header on every tab.
(#228) - Inbox tabs load for any number of repositories. With more than 64
repositories, every inbox tab used to fail with "Too many desktop requests
are pending". Repositories are now read a few at a time, and a repository
that fails is counted in a "repository reads failed" line instead of failing
the whole tab.
(#244) - The repository sidebar shows "GitHub · github.com" and "GitLab ·
gitlab.com", with a self-hosted hostname kept as written.
(#282) F2opens a loaded job log in your editor whenever no text field holds the
keyboard, not only while a log control has focus.
(#183)- The Your review button shows when a draft needs attention, even if the
error arrives while the drawer is closed.
(#209) - A submission interrupted before it sent anything offers Return draft to
editing instead of asking you to reconcile zero steps.
(#231) - A merge the forge refuses because of conflicts explains that the review may
have changed remotely or the branch may conflict with its target, and asks
you to refresh and check for conflicts.
(#232) - Diff hunk headers follow the light theme.
(#250)
Documentation
- www.tongs.tools is rebuilt on Astro and
Starlight, with new pages for first run, review drafts, reviewing on
desktop, the MCP server, the desktop lifecycle and releases. Moved pages
redirect to their new addresses.
(#268) - The contributor guide is shorter, and the README and packaging notes match
the current code.
(#249,
#281)
Release and packaging
- The desktop release job finds its draft release by listing releases. On
1.0.0 the lookup could not see the draft, and the release was published by
hand.
(#243) - Fedora RPM source downloads retry transient network failures. Size and hash
checks are not retried.
(#242) - Pull request CI now runs only the lanes a change affects, behind a single
aggregate check, and lints the documentation. Several flaky desktop tests
were fixed.
Release assets
The desktop app is built for Linux on Fedora 44, x86_64, GNU ABI. The
GitHub Release
carries the same set of assets as 1.0.0, for version 1.0.1: the per-user
archive with its release manifest and Sigstore attestation, the unsigned Fedora
44 RPMs with their source-built companion packages, the archive SBOM with its
attestation, and SHA256SUMS. Install the RPMs together with
dnf install ./*.rpm.
Known issues
The most visible ones:
- Retry on a failed read does not restart the desktop app's stopped Python
process. Relaunch the app instead. - Large diffs that are mostly additions render without syntax color in the
desktop app. - An empty optional forge field, such as a GitHub job with no workflow name,
stops a desktop pipeline, job, commit or review view from loading.
Known issues has the full
list, with the issue and milestone for each fix.
Thanks to @tayfuryldz for most of the fixes in
this release.
v1.0.0
tongs 1.0.0
First stable release. tongs is a terminal-native code review inbox that spans
GitHub and GitLab: one inbox, real diffs, inline comments, discussions,
suggestions, durable review drafts, pipeline and CI drill-down, an SQLite
cache, a plugin system and an MCP server.
Install
pip install tongs==1.0.0
tongs --install-desktoppipx install tongs works the same way. The second command is optional: it
downloads and verifies the desktop workspace attached to this release for the
core you just installed. Plain tongs never does that on its own.
The terminal application
Everything previously shipped is here, plus two features from the development
branch:
- Split diff view, toggled with
v, withhandlmoving focus between the
old and new side. - Durable review drafts:
Ctrl+Gstarts review mode, comments collect
locally, and the whole set submits as one review with a verdict. Drafts
survive a crash, and an interrupted submission is reconciled rather than
replayed.
The desktop workspace, first release
An optional Electron workspace over the same repositories, reviews and drafts.
The terminal stays the default; plain tongs never downloads or starts it.
Reviewing happens on the diff: hover a line for the gutter control, and the
composer opens under that line. Two buttons keep the same shape throughout,
Start a review or Add to review as the primary and Add comment now
as the secondary, so an immediate comment and a pending one are never the same
gesture. Pending comments render inline under their anchor with a Pending
badge and can be edited or deleted in place. Insert suggestion pre-fills a
suggestion block from the selected new-side lines. A Your review button
carries the pending count and opens a drawer holding the pending comments, the
summary, the verdict tiles, Submit review and Discard review, along
with the submission progress and recovery. A draft that changed elsewhere
presents both texts and a real choice instead of wedging.
What this release carries
The desktop is built for Linux on Fedora 44, x86_64, GNU ABI. The assets
attached to this release are:
tongs-desktop-1.0.0-fedora44-x86_64.tar.gz, the per-user archive, with
desktop-manifest-v1.jsonanddesktop-manifest-v1.sigstore.json, the
release manifest and its GitHub-managed Sigstore attestation. These are what
tongs --install-desktopdownloads and verifies.tongs-desktop-1.0.0-*.rpm,python3-tongs-1.0.0-*.rpmand
python3-tongs+mcp-1.0.0-*.rpm, the Fedora 44 packages, with the
source-built companion packages they require. Install them together with
dnf install ./*.rpm. They are not GPG signed.tongs-desktop-1.0.0.spdx.jsonand its.sigstore.jsonbundle, the archive
SBOM and its attestation.SHA256SUMScovering every asset above.
Every asset was verified with the installer's own release policy before this
release was created, and the release is immutable.
Fixed in this release
Split diff navigation no longer crashes the terminal, log search opens
correctly in the terminal pipeline view, the per-user installer accepts a real
pipx installation, the installed menu entry launches, diff reads no longer
fail on an empty field, every redesigned review surface has its own background
and colour tokens on the dark theme, and a merge the forge refuses with HTTP
405 is reported as a known conflict instead of an unknown outcome.
Known limitations
See the known limitations page.
The notable ones: lifecycle actions are reachable only from the Discussions
tab, a failed read's Retry does not restart a dead sidecar, a rotated token is
not re-resolved without a restart, and large addition-heavy diffs render
without syntax colouring.
Next
v1.0.1 carries the deferred acceptance runs and the discoverability fix for
the lifecycle actions.