Skip to content

Releases: andre-motta/tongs

v1.0.3

Choose a tag to compare

@github-actions github-actions released this 27 Sep 17:53
Immutable release. Only release title and notes can be modified.
v1.0.3
790f758

Released 2026-09-27. This patch release fixes crashes and a data-loss risk in
the terminal app and the desktop app beta. The desktop inbox now loads a page
at a time, so a repository with thousands of open pull requests no longer
stops the desktop service. Nothing in your configuration or drafts changes.

Install

pipx install tongs==1.0.3

pip install tongs==1.0.3 and uv tool install tongs==1.0.3 work the same
way. To upgrade an existing installation, run pipx upgrade tongs, or
uv tool upgrade tongs, or pip install --upgrade tongs. If you use the
per-user desktop app, install the matching desktop release after the core:

tongs desktop update

The desktop app (beta)

  • The inbox loads a page at a time. A repository with thousands of open
    pull requests, such as pytorch/pytorch, used to return every one of them
    in a single response, which the desktop app rejected, stopping the desktop
    service. Each repository now shows its newest 100 reviews as soon as they
    arrive. All Open merges repositories by update time and loads more from
    whichever repository comes next when you scroll to the end, so one large
    repository no longer buries the others or spends your rate limit on old pull
    requests. CI status is fetched only for the reviews on screen.
    (#344)
  • Large discussions no longer stop the desktop service. A merge request
    with about 1,200 comment threads produced a response the desktop app
    rejected. Discussions now load in pages, and any response that is still too
    large fails only its own request, with a clear message, instead of stopping
    the service.
    (#292)
  • The header shows "Local service not running" as soon as the desktop service
    stops, instead of still saying it is connected.
    (#345)
  • The marker that shows where a link really goes is styled from the shared
    stylesheet, so themes can restyle it.
    (#341,
    #346)

Review drafts

  • tongs starts even when a saved submission is missing or damaged. A
    submission attempt that another tongs process cancelled, or that can no
    longer be read, used to stop the terminal app, the desktop app and the MCP
    server from starting, and the only way out was deleting drafts.db. Startup
    now skips a missing attempt. A damaged one returns its draft to editing with
    all of its content kept, and tongs shows a one-time warning that part of the
    review may already be on the forge, so check it before submitting again.
    (#291)

The terminal app

  • Square brackets in a merge request title, label, author, file path or
    repository name are shown as written. A title such as Fix [/] parsing
    used to crash the app on every launch, and [skip ci] or [WIP] silently
    disappeared.
    (#290)

Requirements

  • tongs now requires Textual 4.0 or later. The terminal app already used
    features from Textual 3.1 and newer, so the old minimum of 1.0 was wrong.
    pipx, uv and pip upgrade Textual for you, and Fedora 44 ships Textual
    4.0.

Documentation

  • The homepage and the first-run guide say that only github.com, gitlab.com
    and hosts listed under [hosts.*] are recognized, matching the change in
    1.0.2.
    (#347)

Continuous integration

  • Renderer tests wait up to five seconds for asynchronous updates and print a
    short message when a wait fails, instead of failing on busy runners.
    (#338)
  • Re-running only the failed jobs of a pull request can turn the required
    check green again.
    (#339)
  • The contributor guides give memory guard values that work for the site and
    desktop builds on machines with many CPU cores.
    (#342)

Release assets

The GitHub Release
carries the same set of assets as 1.0.2, for version 1.0.3: the per-user
archive with its release manifest and Sigstore attestation, the unsigned Fedora
44 RPMs with their source-built companion packages, the archive SBOM with its
attestation, and SHA256SUMS. Install the RPMs together with
dnf install ./*.rpm.

Known issues

Known issues lists the defects known in 1.0.3, with
the issue and milestone for each fix.

Thanks to @nightcityblade for their first
contribution to tongs.

v1.0.2

Choose a tag to compare

@github-actions github-actions released this 27 Sep 14:51
Immutable release. Only release title and notes can be modified.
v1.0.2
148b454

Released 2026-09-27. This patch release fixes two security issues in how
tongs handles forge credentials, shows where links point in the desktop app,
and pins every dependency the release builds install. Everyone should upgrade,
and especially anyone who runs the tongs-mcp server. Nothing in your
configuration or drafts changes, unless you relied on one of the behaviors
described under Security.

Install

pipx install tongs==1.0.2

pip install tongs==1.0.2 and uv tool install tongs==1.0.2 work the same
way. To upgrade an existing installation, run pipx upgrade tongs, or
uv tool upgrade tongs, or pip install --upgrade tongs. If you use the
per-user desktop app, install the matching desktop release after the core:

tongs desktop update

Security

Both issues affect tongs 1.0.0 and 1.0.1 and are fixed in 1.0.2.

  • tongs-mcp only talks to configured hosts.
    (GHSA-4cw3-82cv-q28x,
    high) The MCP server accepted any hostname that contained github or
    gitlab, looked up a token for it and sent that token to the host. Because
    MCP tools are driven by a language model that also reads merge request text,
    untrusted text could steer a tool call toward such a host. The MCP server now
    accepts only github.com, gitlab.com and the hosts in your config.toml,
    exactly like the terminal and desktop apps, and rejects anything else before
    any credential lookup or request. tongs also no longer guesses the forge type
    from a hostname anywhere: a self-hosted GitHub or GitLab instance must be
    listed in config.toml, as the configuration reference
    already required.
  • ~/.netrc is read more strictly.
    (GHSA-v7v3-jh3w-pj3h,
    medium) tongs used the default entry of ~/.netrc when no machine line
    named the forge host, and sent that password as a forge token. Only a
    machine entry that names the host is used now. A ~/.netrc that cannot be
    parsed produces an error that names the line, never its contents. Error text
    returned by the MCP server is redacted, and redaction now also covers ghr_
    and glrt- tokens and credentials written into URLs.

If you kept a forge token in the default entry of ~/.netrc, move it to a
machine <host> entry. Security and signing describes
the full credential lookup.

Reviews

These apply to the terminal app and the desktop app.

  • A comment or approval the forge rejects as invalid (GitHub 422, GitLab 400)
    is reported as a rejected request that you can correct, instead of an
    unknown outcome that asks you to reconcile the review. Approving your own
    pull request on GitHub says that GitHub does not allow it.
    (#315,
    #333)

The desktop app (beta)

  • Links show where they go. Every link in a merge request description or
    comment names its destination host in its tooltip and to screen readers.
    When the link text looks like a web address on a different host, such as a
    link reading github.com/org/repo that points elsewhere, the real host is
    shown next to it.
    (#321)
  • Desktop plugin assets are checked for symlinks along the whole path from
    the plugin package, including packages split across several directories,
    and archive entries with extended tar headers are rejected before they are
    read. (#329,
    #334)
  • An unexpected failure while submitting a review says so, offers Retry, and
    no longer suggests refreshing. The desktop service logs the operation and a
    redacted cause.
    (#233,
    #280)

The terminal app

  • The inbox has a Forge column that shows GH or GL for each merge
    request, matching the repository list.
    (#254,
    #262)

Release and packaging

  • Pinned release builds. The jobs that sign and publish the desktop
    release, and the job that builds the PyPI packages, install only
    hash-locked Python packages, including the build backend. The desktop archive
    builder installs only pinned, hash-checked RPMs with every package repository
    disabled. Every CI workflow keeps its checkout credentials out of the working
    tree and has a timeout, and a test checks all of this for every workflow.
    (#303)
  • The companion Python RPM changelogs name the project's packaging address.
    (#327,
    #335)
  • The pull request template reminds contributors to update the known issues
    page when a fix lands.
    (#332)

Release assets

The GitHub Release
carries the same set of assets as 1.0.1, for version 1.0.2: the per-user
archive with its release manifest and Sigstore attestation, the unsigned Fedora
44 RPMs with their source-built companion packages, the archive SBOM with its
attestation, and SHA256SUMS. Install the RPMs together with
dnf install ./*.rpm.

Known issues

Known issues lists the defects known in 1.0.2, with
the issue and milestone for each fix. The next patch releases, 1.0.3 through
1.0.9, each fix one group of them.

Several fixes in this release were planned for later patch releases and
arrived early as community contributions. Thanks to
@GhostCoder6969,
@tayfuryldz and
@Tiyatrotist for their work.

v1.0.1

Choose a tag to compare

@github-actions github-actions released this 27 Sep 05:24
Immutable release. Only release title and notes can be modified.
v1.0.1
7cd90b5

Released 2026-09-27. This is the first patch release of tongs 1.0. It fixes
the defects found since 1.0.0 in the terminal app, credentials and the desktop
app beta, and moves the review actions in the desktop app into a header that
every review tab shares. Nothing in your configuration or drafts changes.

Install

pipx install tongs==1.0.1

pip install tongs==1.0.1 and uv tool install tongs==1.0.1 work the same
way. To upgrade an existing installation, run pipx upgrade tongs, or
uv tool upgrade tongs, or pip install --upgrade tongs. If you use the
per-user desktop app, install the matching desktop release after the core:

tongs desktop update

For a first desktop install, run tongs --install-desktop instead. Plain
tongs never downloads or starts the desktop app on its own.

Credentials

These apply to the terminal app, the desktop app and the MCP server, which
share the same forge clients.

  • Rotated and expired tokens are picked up. When a request gets a 401,
    tongs resolves the token again through the same lookup and retries once. For
    GitLab it first runs glab auth status --hostname <host>, which makes glab
    refresh and save an expired OAuth login. A second 401 is still reported as
    an authentication error. You no longer have to restart tongs after rotating
    a token.
    (#186,
    #245)
  • GitLab tokens are read from glab. tongs now reads the token glab stores
    with glab config get token --host <host>, which covers OAuth logins,
    personal access tokens and keyring-backed tokens. The 1.0.0 lookup always
    failed and fell through to ~/.netrc or the keyring, so a stale token there
    caused 401 errors.
    (#245)

Security and signing describes
the full credential lookup.

The terminal app

  • Retrying or cancelling a job reloads the job list you are on. Ctrl+R on
    the Pipeline tab refreshes the level you are looking at: the pipeline list,
    a pipeline's jobs, or a job log.
    (#253)
  • The log search box stays visible above its status line, so you can see what
    you type. (#221)
  • F2 in a job log writes plain text to your editor, without raw ANSI color
    codes. (#222)
  • "No forges discovered yet" appears only once repository discovery has
    finished and found nothing, instead of flashing at startup.
    (#255)
  • The review draft save worker no longer touches the comment editor once the
    review screen has closed.
    (#166)

The desktop app (beta)

  • Review actions on every tab. Merge, Close, Reopen and Remove approval
    now sit in a review header next to the Your review button on
    Overview, Files changed and Discussions. Overview gains the
    Your review drawer too. An unknown result from any immediate comment,
    reply or verdict can be acknowledged from the same header on every tab.
    (#228)
  • Inbox tabs load for any number of repositories. With more than 64
    repositories, every inbox tab used to fail with "Too many desktop requests
    are pending". Repositories are now read a few at a time, and a repository
    that fails is counted in a "repository reads failed" line instead of failing
    the whole tab.
    (#244)
  • The repository sidebar shows "GitHub · github.com" and "GitLab ·
    gitlab.com", with a self-hosted hostname kept as written.
    (#282)
  • F2 opens a loaded job log in your editor whenever no text field holds the
    keyboard, not only while a log control has focus.
    (#183)
  • The Your review button shows when a draft needs attention, even if the
    error arrives while the drawer is closed.
    (#209)
  • A submission interrupted before it sent anything offers Return draft to
    editing
    instead of asking you to reconcile zero steps.
    (#231)
  • A merge the forge refuses because of conflicts explains that the review may
    have changed remotely or the branch may conflict with its target, and asks
    you to refresh and check for conflicts.
    (#232)
  • Diff hunk headers follow the light theme.
    (#250)

Documentation

  • www.tongs.tools is rebuilt on Astro and
    Starlight, with new pages for first run, review drafts, reviewing on
    desktop, the MCP server, the desktop lifecycle and releases. Moved pages
    redirect to their new addresses.
    (#268)
  • The contributor guide is shorter, and the README and packaging notes match
    the current code.
    (#249,
    #281)

Release and packaging

  • The desktop release job finds its draft release by listing releases. On
    1.0.0 the lookup could not see the draft, and the release was published by
    hand.
    (#243)
  • Fedora RPM source downloads retry transient network failures. Size and hash
    checks are not retried.
    (#242)
  • Pull request CI now runs only the lanes a change affects, behind a single
    aggregate check, and lints the documentation. Several flaky desktop tests
    were fixed.

Release assets

The desktop app is built for Linux on Fedora 44, x86_64, GNU ABI. The
GitHub Release
carries the same set of assets as 1.0.0, for version 1.0.1: the per-user
archive with its release manifest and Sigstore attestation, the unsigned Fedora
44 RPMs with their source-built companion packages, the archive SBOM with its
attestation, and SHA256SUMS. Install the RPMs together with
dnf install ./*.rpm.

Known issues

The most visible ones:

  • Retry on a failed read does not restart the desktop app's stopped Python
    process. Relaunch the app instead.
  • Large diffs that are mostly additions render without syntax color in the
    desktop app.
  • An empty optional forge field, such as a GitHub job with no workflow name,
    stops a desktop pipeline, job, commit or review view from loading.

Known issues has the full
list, with the issue and milestone for each fix.

Thanks to @tayfuryldz for most of the fixes in
this release.

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 10 Sep 04:59
Immutable release. Only release title and notes can be modified.
v1.0.0
a511751

tongs 1.0.0

First stable release. tongs is a terminal-native code review inbox that spans
GitHub and GitLab: one inbox, real diffs, inline comments, discussions,
suggestions, durable review drafts, pipeline and CI drill-down, an SQLite
cache, a plugin system and an MCP server.

Install

pip install tongs==1.0.0
tongs --install-desktop

pipx install tongs works the same way. The second command is optional: it
downloads and verifies the desktop workspace attached to this release for the
core you just installed. Plain tongs never does that on its own.

The terminal application

Everything previously shipped is here, plus two features from the development
branch:

  • Split diff view, toggled with v, with h and l moving focus between the
    old and new side.
  • Durable review drafts: Ctrl+G starts review mode, comments collect
    locally, and the whole set submits as one review with a verdict. Drafts
    survive a crash, and an interrupted submission is reconciled rather than
    replayed.

The desktop workspace, first release

An optional Electron workspace over the same repositories, reviews and drafts.
The terminal stays the default; plain tongs never downloads or starts it.

Reviewing happens on the diff: hover a line for the gutter control, and the
composer opens under that line. Two buttons keep the same shape throughout,
Start a review or Add to review as the primary and Add comment now
as the secondary, so an immediate comment and a pending one are never the same
gesture. Pending comments render inline under their anchor with a Pending
badge and can be edited or deleted in place. Insert suggestion pre-fills a
suggestion block from the selected new-side lines. A Your review button
carries the pending count and opens a drawer holding the pending comments, the
summary, the verdict tiles, Submit review and Discard review, along
with the submission progress and recovery. A draft that changed elsewhere
presents both texts and a real choice instead of wedging.

What this release carries

The desktop is built for Linux on Fedora 44, x86_64, GNU ABI. The assets
attached to this release are:

  • tongs-desktop-1.0.0-fedora44-x86_64.tar.gz, the per-user archive, with
    desktop-manifest-v1.json and desktop-manifest-v1.sigstore.json, the
    release manifest and its GitHub-managed Sigstore attestation. These are what
    tongs --install-desktop downloads and verifies.
  • tongs-desktop-1.0.0-*.rpm, python3-tongs-1.0.0-*.rpm and
    python3-tongs+mcp-1.0.0-*.rpm, the Fedora 44 packages, with the
    source-built companion packages they require. Install them together with
    dnf install ./*.rpm. They are not GPG signed.
  • tongs-desktop-1.0.0.spdx.json and its .sigstore.json bundle, the archive
    SBOM and its attestation.
  • SHA256SUMS covering every asset above.

Every asset was verified with the installer's own release policy before this
release was created, and the release is immutable.

Fixed in this release

Split diff navigation no longer crashes the terminal, log search opens
correctly in the terminal pipeline view, the per-user installer accepts a real
pipx installation, the installed menu entry launches, diff reads no longer
fail on an empty field, every redesigned review surface has its own background
and colour tokens on the dark theme, and a merge the forge refuses with HTTP
405 is reported as a known conflict instead of an unknown outcome.

Known limitations

See the known limitations page.
The notable ones: lifecycle actions are reachable only from the Discussions
tab, a failed read's Retry does not restart a dead sidecar, a rotated token is
not re-resolved without a restart, and large addition-heavy diffs render
without syntax colouring.

Next

v1.0.1 carries the deferred acceptance runs and the discoverability fix for
the lifecycle actions.