0.2.0 - 2026-08-16
Release Notes
Added
-
Codex local back-end — a fourth dispatch target backed by the Codex app-server protocol,
with persistent sessions, model-catalog discovery, IR-driven multi-agent Ask and dashboard
execution, Setup and context-enrichment flows, and typed event/render contracts. The package
remains private and is versioned in lockstep with the rest of the workspace. -
Native interactive sessions — Claude Code and Codex launch specifications now carry an
explicit purpose, bounded scope, least-privilege Wren/MCP discovery, typed Setup recovery, and
retained answer/dashboard delivery. Emitted agents receive one profile-level session envelope,
scope prompt, andRUN.md, with deterministic snapshots guarding the complete emitted tree. -
Runtime semantic-context injection — dispatchers can receive schema plus knowledge at run
time without rebuilding the compiled profile. A newgenbi-enrich-contextprofile provides
read-only inspection and host-mediated enrichment proposals, whilegenbi-monitoradds
scheduled freshness checks. -
Expanded eval tooling — back-end-aware runner adapters, repeated sampling, trace caching,
compliance-version validation, live freshness-pair scoring, pinned Driftwood fixtures, and
committed GenBI/Driftwood goldens. Pull requests that change emitted agent context are covered
by a byte-for-byte structural snapshot without forcing paid model calls on every dispatcher PR. -
Provider composition and authenticated model catalogs — capabilities are resolved from
provider fragments instead of target-specific component names, with consistent loud-fail walls
across Rust, Claude Agent SDK, and Codex back-ends. -
warble_ir_versionbumped to0.4—bind:values authored on a profile mount now actually
reach the IR. Each component node gains an additivebindsfacet (present only when the
component has at least one profile-bound param) carrying the effective value for every such
param: the mount-supplied value, or else the param's declareddefault.context_precondition[].args
may reference a bound param with$param:<name>, which compile now resolves to that effective
value before evaluating the predicate (previously this template was never substituted, so
binding_mode: pinnedwas unimplemented). An unsupplied optional bind with no default resolves
to nothing, which loud-fails the referencing precondition as unanswerable rather than evaluating
against an empty value;$param:naming an undeclared param is a compile-time error.
model_has_timestampnow honors a pinnedargs.modelthe same waymetric_additivehonors a
pinned metric, instead of only ever answering existentially. -
Components may now author an optional
brief— a free-form string shared across every step
of a component, rendered with the same{{project}}/{{project_name}}placeholder
substitution as step prompts and emitted once on the IR node (not per-step). Every back-end that
assembles a system prompt places it in the same spot — after the machine-generated preamble,
before the body — on the driver and on every subagent; thevercelback-end carries it onto
AgentBundle.brieffor the harness to place. A profile mount may override a component'sbrief
wholesale (components[].brief, never merged). A component with nobriefcompiles to IR
byte-identical to before this field existed. Sincecomponent.ymlis parsed with
deny_unknown_fields, a component that authorsbriefwill loud-fail on an older warble
binary that does not yet recognize the field — seedocs/spec/authoring.md. -
warble_ir_versionbumped to0.5— thebriefaddition above is a shape change to the
IR (a new optional field on the component node), and per the IR version contract in
docs/spec/ir-schema.md, any change to the IR shape requires a version bump, including a purely
additive one. Every lockstep-checked location (core's emitted literal, every back-end's
SUPPORTED_IR_VERSION(S)and advisoryMIN/MAX_SUPPORTED_IR_VERSIONpair, and this spec
document's own title) now names0.5, and every committed golden IR, conformance fixture, and
emitted bundle/manifest snapshot has been regenerated against it. Anything built against a
compiled0.4IR (a savedir.golden.json, avercelbundle, acodex-localmanifest) must be
regenerated — a stale0.4artifact will be rejected by every back-end, loudly, at load time. -
@warble/claude-agent-sdkis now publishable to npm — first-publication metadata
(publishConfig.access: public,repository.directory,homepage,bugs,keywords,
engines.node), aprepublishOnlyscript gatingcheck-types+build+testso a
stale/missingdist/can never ship, and a clearer, actionable error when thewarblebinary
isn't found onPATH(namescargo install warble-cli, the one channel that's genuinely public
and needs no authentication —@warble/claude-agent-sdkdeliberately does not depend on
@warble/cli, which is unpublished and would need an authenticated GitHub Release download from
this private-until-launch repo). Nonpm publishhas been run yet; this only makes the package
ready to publish.
Fixed
- Native interactive output is presented conversationally while preserving structured answers and
dashboard artifacts for follow-ups. Setup terminals now enforce their exact JSON and string-slot
contracts, and test-only transport timeouts no longer race the runner's production timeouts. - Interactive context-enrichment proposals now use the host submission channel without changing
the byte-exact headless JSON delivery contract or granting project-write authority. - Profile-level scope artifacts are emitted exactly once, and generated
RUN.mdfiles no longer
diverge between components. dispatcher/vercel— awhenguard on a conditional step whose guard string falls outside
the closed vocabulary (on_failure/on_flag/on_missing), or a step declaring
conditional: truewith nowhenat all (or vice versa), now fails loudly at emit time instead
of being silently folded into a realization it doesn't match (invariant #1). Guard shapes already
in the closed vocabulary — includingon_flag/on_missingand non-adjacenton_failure, which
realize asGuardedSkip— are unaffected.claude-agent-sdk: awren-prefixed compound Bash command could hide a.envread past the
read-only guard (e.g.wren --version && cat .env), on both the runtime (guardrails.ts) and
emit --standalone's inlined copy of the same guard. The runtime path is now enforced through a
PreToolUsehook (canUseToolalone does not see an in-cwdReadin the real SDK), and the
inlined--standaloneguard now carries the same dotenv-read denylist, checked first. A
behavioral test (tests/guard-drift.test.ts) now runs both guard implementations against a
shared case table and fails if either one falls out of sync with the other, or if the runtime
guard grows new denial behavior the standalone copy hasn't caught up to.
Install warble-cli 0.2.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/Canner/Warble/releases/download/v0.2.0/warble-cli-installer.sh | shInstall prebuilt binaries into your npm project
npm install @warble/cli@0.2.0Download warble-cli 0.2.0
| File | Platform | Checksum |
|---|---|---|
| warble-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| warble-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| warble-cli-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| warble-cli-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |