Skip to content

Releases: codewhale-hq/Codewhale

v0.10.0

Choose a tag to compare

@github-actions github-actions released this 22 Sep 17:28
1be1a70

Codewhale is the public product from Shannon Labs. The codewhale
command, npm package, and release-asset names remain lowercase technical
identifiers. The legacy npm package deepseek-tui is deprecated and
receives no further releases. Users coming from v0.8.x legacy deepseek /
deepseek-tui names should migrate with docs/REBRAND.md.

Install

Recommended — official GitHub release

New macOS/Linux install (checksummed binaries from this release):

curl -fsSL https://codewhale.net/install.sh | CODEWHALE_VERSION="v0.10.0" sh
"$HOME/.local/bin/codewhale" --version

For Windows, use the matching installer or archive below. For an existing
direct install, run codewhale update; it prints the executable path and
keeps newer builds. If the install directory is occupied by a different build,
use the fresh-directory migration in the installation guide.

Secondary packaging — npm and Cargo

npm install -g codewhale
# or build from source
cargo install codewhale-cli --locked

The wrapper downloads the matched codewhale and codew command assets
from this Release. Both contain the same compiled runtime.

Docker / GHCR

docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.10.0

The image exposes the same runtime as both codewhale and codew. The
latest tag is also updated on release.

Cargo (Linux / macOS)

cargo install codewhale-cli --locked

The Cargo package installs codewhale. Cargo cannot create a second command
alias from one binary target; users who want the shorter spelling can add a
codew symlink to that installed executable. The npm, Homebrew, archive,
shell-installer, and container channels install both command names directly.

Manual download — platform archives (recommended)

Each archive below contains the same runtime under the codewhale and
codew command names, plus an install script:

Platform Archive Install script
Linux x64 codewhale-linux-x64.tar.gz install.sh
Linux ARM64 codewhale-linux-arm64.tar.gz install.sh
Android ARM64 (Termux) codewhale-android-arm64.tar.gz install.sh
macOS x64 codewhale-macos-x64.tar.gz install.sh
macOS ARM codewhale-macos-arm64.tar.gz install.sh
Windows x64 (installer) CodeWhaleSetup.exe NSIS setup
Windows x64 codewhale-windows-x64.zip install.bat
Windows x64 (portable) codewhale-windows-x64-portable.zip —
Windows ARM64 codewhale-windows-arm64.zip install.bat
Windows ARM64 (portable) codewhale-windows-arm64-portable.zip —

Unix (Linux / macOS):

tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:

  • For the installer path, run CodeWhaleSetup.exe; it installs
    codewhale.exe, codew.exe, and codewhale.bat under
    %LOCALAPPDATA%\Programs\CodeWhale\bin, adds that directory to the
    current-user PATH, and creates a Start Menu shortcut that prefers
    Windows Terminal (wt.exe) when it is installed.
  • Extract the archive for your machine: codewhale-windows-x64.zip or
    codewhale-windows-arm64.zip
  • Double-click codewhale.bat (not the raw .exe) to launch
  • Run install.bat to copy the binaries and launcher to %USERPROFILE%\bin
  • Add %USERPROFILE%\bin to your PATH

The portable Windows archive skips the install script — extract and run codewhale.bat from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has bare, unarchived codewhale-<platform> and
codew-<platform> assets. The seven codewhale-tui-<platform> filenames
attached to v0.9.5 are byte-identical compatibility copies used only to let
already-installed v0.9.4 clients discover and cross this single-binary
transition; current installers do not expose a third runtime. The legacy npm
package deepseek-tui is deprecated and is not republished. For migration
from v0.8.x legacy binary names, see docs/REBRAND.md.

Verify (recommended)

Download the checksum manifests from this Release and verify:

# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.10.0

Codewhale v0.10.0 brings a redesigned terminal workbench, clearer settings, and
more reliable session and runtime behavior. It supersedes the unpublished
v0.9.14 candidate.

Security

  • Children never inherit desktop or computer-control tools. Desktop control is
    the most machine-wide capability in the catalog, and a verifier child
    inherited it by default: on 2026-09-17 one opened the host Terminal and typed
    a blocked shell command into the user's live session. A family classifier now
    removes those tools when a child's registry is built, so they are neither
    eager nor searchable, and execute_full refuses the family at dispatch for
    every child role — visibility is a grant, and hiding is not the only defense
    (#6296).

  • Runtimes can be held to an organization's plugin allowlist. A managed policy
    document (managed-policy.json beside state.json, or
    CODEWHALE_MANAGED_POLICY_PATH) lists the plugin ids a Runtime may run,
    with an allow_unlisted flag and a schema version checked exactly like
    PluginStateFile. Enforcement sits inside apply_state, so a plugin
    enabled before the policy arrived — or hand-edited to enabled: true —
    never comes back enabled, and enable() re-reads the document so a policy
    landing after discovery refuses with a reason that names it. A malformed
    document fails closed rather than degrading to unenforced. With no policy
    present, behaviour is bit-for-bit what it was. This is the enforcement
    primitive only; the authority that decides the allowlist is still local,
    so it binds a cooperating Runtime, not a hostile one.

  • Approving an apply_patch "for the session" is now scoped to the file you
    approved. The grouping key that scopes a session grant was built by a second,
    weaker patch parser that read only +++ b/ headers and the replace array:
    it saw no target at all for the documented apply_patch{path, patch}
    override, for --no-prefix diffs, or for delete-only diffs, and collapsed
    every one of them to a single shared key. One approval therefore pre-approved
    every later patch of that shape, to any file, with no card and no notice. The
    key now comes from the same resolver the executor and the permission path
    already use, and an input that cannot be resolved gets its own key rather
    than a shared one (#6247).

Added

  • The statusline's performance readings survive compact mode and are separately
    configurable. Measured TTFT and average output rate are kept when space
    allows, shedding help text and secondary counts first; the existing metrics
    and statusline settings gain individual toggles with a migration that
    preserves a legacy single setting, and the picker takes mouse selection and
    scrolling.
  • Tasks can be given their own run name. NewTaskRequest, TaskRecord and
    TaskSummary carry an optional name, stored as given and omitted when
    absent, so queues still fall back to prompt-derived titles; a run started by
    an automation inherits the automation's name. The tasks tool's schema
    extends backward-compatibly and legacy records decode through serde defaults
    (APPS-153).
  • The offline catalog seeds Xiaomi's MiMo 2.6 family — xiaomi/mimo-v2.6-pro
    and xiaomi/mimo-v2.6-flash — so a first boot without network no longer shows
    the 2.5 generation. DEFAULT_XIAOMI_MIMO_MODEL stays on mimo-v2.5-pro, and
    the rows carry no price because the published rates cover only sk- keys.
  • Native memory is a reviewed store, not a model-writable file. codewhale-memory
    backs the TUI with SQLite as the authority instead of Markdown, and the
    remember tool now only proposes candidates — a model can no longer write
    an active memory. /memory and the Runtime API commit through
    remember_reviewed, and a Context Lens surface (/v1/memory/lens,
    /lens/actions, /events) shows what was kept and why.
  • Code mode (Experimental, default off): execute_tools runs a JavaScript
    program against a QuickJS host surface so a model can express several tool
    calls as one program. Nested calls must be read-only and auto-approved; the
    tool is hidden in Plan and refused under worker authority. Enable with
    [features] code_mode.
  • Two new built-in providers: ZenMux (ZENMUX_API_KEY) and CSDN 星图
    (CSDN_API_KEY, Coding Plan quota billing), each with its own key slot,
    bootstrap model and catalog rows.
  • The Runtime API gained the surface a native client actually needs: jobs with
    stdin, kill and cursor reads; context, secrets, git, diagnostics, targets,
    LSP and voice routes; GET /v1/commands for the slash-command catalog;
    GET /v1/workspace/instructions; account-wide GET /v1/approvals; plan and
    to-do inventory; /v1/settings/schema, with POST /v1/config now persisting
    every declared settings.toml key rather than a curated allowlist; PTY byte
    replay, resize and exit; and tool images as session artifacts.
  • Codewhale holds the host's idle-sleep assertion while a turn is in flight
    (caffeinate -i on macOS, systemd-inhibit on Linux), so an unattended
    machine no longer sleeps mid-run. You will see one child process per turn.
  • Skills are reachable in one call. The pinned ## Skills index told the model
    to call load_skill, but the tool was def...
Read more

v0.9.13

Choose a tag to compare

@github-actions github-actions released this 14 Sep 03:48

Codewhale is the public product from Shannon Labs. The codewhale
command, npm package, and release-asset names remain lowercase technical
identifiers. The legacy npm package deepseek-tui is deprecated and
receives no further releases. Users coming from v0.8.x legacy deepseek /
deepseek-tui names should migrate with docs/REBRAND.md.

Install

Recommended — official GitHub release

New macOS/Linux install (checksummed binaries from this release):

curl -fsSL https://codewhale.net/install.sh | CODEWHALE_VERSION="v0.9.13" sh
"$HOME/.local/bin/codewhale" --version

For Windows, use the matching installer or archive below. For an existing
direct install, run codewhale update; it prints the executable path and
keeps newer builds. If the install directory is occupied by a different build,
use the fresh-directory migration in the installation guide.

Secondary packaging — npm and Cargo

npm install -g codewhale
# or build from source
cargo install codewhale-cli --locked

The wrapper downloads the matched codewhale and codew command assets
from this Release. Both contain the same compiled runtime.

Docker / GHCR

docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.9.13

The image exposes the same runtime as both codewhale and codew. The
latest tag is also updated on release.

Cargo (Linux / macOS)

cargo install codewhale-cli --locked

The Cargo package installs codewhale. Cargo cannot create a second command
alias from one binary target; users who want the shorter spelling can add a
codew symlink to that installed executable. The npm, Homebrew, archive,
shell-installer, and container channels install both command names directly.

Manual download — platform archives (recommended)

Each archive below contains the same runtime under the codewhale and
codew command names, plus an install script:

Platform Archive Install script
Linux x64 codewhale-linux-x64.tar.gz install.sh
Linux ARM64 codewhale-linux-arm64.tar.gz install.sh
Android ARM64 (Termux) codewhale-android-arm64.tar.gz install.sh
macOS x64 codewhale-macos-x64.tar.gz install.sh
macOS ARM codewhale-macos-arm64.tar.gz install.sh
Windows x64 (installer) CodeWhaleSetup.exe NSIS setup
Windows x64 codewhale-windows-x64.zip install.bat
Windows x64 (portable) codewhale-windows-x64-portable.zip —
Windows ARM64 codewhale-windows-arm64.zip install.bat
Windows ARM64 (portable) codewhale-windows-arm64-portable.zip —

Unix (Linux / macOS):

tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:

  • For the installer path, run CodeWhaleSetup.exe; it installs
    codewhale.exe, codew.exe, and codewhale.bat under
    %LOCALAPPDATA%\Programs\CodeWhale\bin, adds that directory to the
    current-user PATH, and creates a Start Menu shortcut that prefers
    Windows Terminal (wt.exe) when it is installed.
  • Extract the archive for your machine: codewhale-windows-x64.zip or
    codewhale-windows-arm64.zip
  • Double-click codewhale.bat (not the raw .exe) to launch
  • Run install.bat to copy the binaries and launcher to %USERPROFILE%\bin
  • Add %USERPROFILE%\bin to your PATH

The portable Windows archive skips the install script — extract and run codewhale.bat from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has bare, unarchived codewhale-<platform> and
codew-<platform> assets. The seven codewhale-tui-<platform> filenames
attached to v0.9.5 are byte-identical compatibility copies used only to let
already-installed v0.9.4 clients discover and cross this single-binary
transition; current installers do not expose a third runtime. The legacy npm
package deepseek-tui is deprecated and is not republished. For migration
from v0.8.x legacy binary names, see docs/REBRAND.md.

Verify (recommended)

Download the checksum manifests from this Release and verify:

# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.9.13

Codewhale v0.9.13 addresses integrity issues in 0.9.12:
multiline paste is one paste again, truncated tool arguments can no longer execute, strict
ACP clients connect again, concurrent instances stop destroying each
other's queued text, and the Computer Use bundle includes plugin 0.3.1
with an accessibility-first pointer that no longer steals focus. DeepSeek V4.1 Flash
(deepseek-flash) is the default DeepSeek model, reasoning-capable routes
keep reasoning out of the answer even when a model id carries no version
number, and /mcp reload no longer freezes the interface while servers
reconnect. The Codewhale pet arrives with /pet: a full-screen habitat that
shows what the Engine is doing and reveals the answer when it is done.

Added

  • /pet turns the terminal over to the Codewhale pet. /pet on (or bare
    /pet) gives the habitat the whole content viewport now and on every
    accepted turn, reveals the actual answer or error when the turn completes,
    and Escape returns to the composer without cancelling anything. /pet off
    closes the view and stops automatic entry while the durable companion keeps
    the pet alive; /pet appearance|window|source|sound|export|status address
    the shared companion. The pet no longer lives in the workbar: the Watch
    panel and /workbar watch … are gone (#6109, #6110).
  • Codewhale Computer Use 0.3.1 ships as its own notarized Mac app. Download
    the disk image from codewhale.net/computer-use
    or the v0.3.1 release
    (Codewhale-Computer-Use-0.3.1-macos-universal.dmg, drag into
    Applications; the ZIP stays for the in-app updater). The bundled plugin and
    the first-party marketplace pin the same 0.3.1 sources, so the app, the
    computer-use plugin and /mcp see one implementation.

Fixed

  • The website's Computer Use download page resolves its state without the
    GitHub API (using GITHUB_TOKEN only when bound), and every page regenerates
    on the Worker again: the Open Graph image route read brand SVGs at import
    time, which the Workers runtime cannot do, so codewhale.net had been serving
    its build-time snapshot.
  • Operate can run structured workflows directly, with named phases, model
    assignments from Fleet, prerequisite results and shared budgets. Independent
    steps run together; dependent work waits for its required results and gates.
    Detached runs return their outcome to the owning conversation, and headless
    sessions stay alive between phases until the final handback is consumed.
  • Computer Use 0.3.1: mouse actions no longer steal focus or reclaim the
    foreground when the user switches apps mid-action; background typing,
    scrolling and selection use semantic input, and screenshots stay scoped to
    the targeted app. The bundled plugin and the first-party marketplace pin
    carry the same 0.3.1 sources. A registered macOS helper stays in charge of
    input through its Pause and Stop controls; an unavailable registered helper
    produces an error instead of silently bypassing those controls.
  • The Fleet editor uses the standard model picker to manage sub-agent model
    and thinking assignments. Enter edits the selected row without changing the
    running session's model. Unconfigured providers are refused, failed saves
    retain the previous assignment, and a changed or removed team file must be
    reopened before a pick can overwrite it.
  • The provider catalog includes Baseten and the other compatible-provider
    templates as selectable rows, opening their existing prefilled setup forms.
    DeepSeek routes with clock-based pricing show the current peak or off-peak
    tier beside session cost, with translated labels.
  • Extensions, teams, workflows and automations support mouse-wheel scrolling.
    Plugin and MCP rows have keyboard enable/disable controls and two-step
    removal; MCP OAuth can retry with narrower scopes after a scope rejection.
  • Healthy sub-agents continue after an ordinary parent reply. Headless runs
    keep the existing Engine alive for child results within the run deadline.
    Explicit cancellation remains authoritative when result queues are full or
    a completion starts a followup turn.
  • Sub-agent followup supports multiple targets and all parked children, keeps
    old IDs connected to their current continuation, and saves continuation
    identity before starting work. Repeated followup does not fork duplicates.
  • Sub-agents validate declared output files and distinguish real edit claims
    from file citations and unrelated workspace changes. Disjoint file claims
    can run together; overlapping writers receive the actual conflict and remedies.
    Explicit read-only shell analysis requires an enforcing native sandbox and
    refuses execution when that protection is unavailable.
  • Delegation depth stays absolute through saved profiles, nested workers and
    continuations. Per-call token, step and time limits narrow inherited limits;
    continuation retains ancestor usage and deadlines. Workers reserve room for
    one tools-disabled partial report inside those limits, then run the declared-
    output checks. Missing usage or unavailable reporting room produces an
    explicit fallback; partial work is never marked c...
Read more

v0.9.12

Choose a tag to compare

@github-actions github-actions released this 05 Sep 09:59
dcd4c20

Codewhale is the public product from Shannon Labs. The codewhale
command, npm package, and release-asset names remain lowercase technical
identifiers. The legacy npm package deepseek-tui is deprecated and
receives no further releases. Users coming from v0.8.x legacy deepseek /
deepseek-tui names should migrate with docs/REBRAND.md.

Install

Recommended — official GitHub release

New macOS/Linux install (checksummed binaries from this release):

curl -fsSL https://codewhale.net/install.sh | CODEWHALE_VERSION="v0.9.12" sh
"$HOME/.local/bin/codewhale" --version

For Windows, use the matching installer or archive below. For an existing
direct install, run codewhale update; it prints the executable path and
keeps newer builds. If the install directory is occupied by a different build,
use the fresh-directory migration in the installation guide.

Secondary packaging — npm and Cargo

npm install -g codewhale
# or build from source
cargo install codewhale-cli --locked

The wrapper downloads the matched codewhale and codew command assets
from this Release. Both contain the same compiled runtime.

Docker / GHCR

docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.9.12

The image exposes the same runtime as both codewhale and codew. The
latest tag is also updated on release.

Cargo (Linux / macOS)

cargo install codewhale-cli --locked

The Cargo package installs codewhale. Cargo cannot create a second command
alias from one binary target; users who want the shorter spelling can add a
codew symlink to that installed executable. The npm, Homebrew, archive,
shell-installer, and container channels install both command names directly.

Manual download — platform archives (recommended)

Each archive below contains the same runtime under the codewhale and
codew command names, plus an install script:

Platform Archive Install script
Linux x64 codewhale-linux-x64.tar.gz install.sh
Linux ARM64 codewhale-linux-arm64.tar.gz install.sh
Android ARM64 (Termux) codewhale-android-arm64.tar.gz install.sh
macOS x64 codewhale-macos-x64.tar.gz install.sh
macOS ARM codewhale-macos-arm64.tar.gz install.sh
Windows x64 (installer) CodeWhaleSetup.exe NSIS setup
Windows x64 codewhale-windows-x64.zip install.bat
Windows x64 (portable) codewhale-windows-x64-portable.zip —
Windows ARM64 codewhale-windows-arm64.zip install.bat
Windows ARM64 (portable) codewhale-windows-arm64-portable.zip —

Unix (Linux / macOS):

tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:

  • For the installer path, run CodeWhaleSetup.exe; it installs
    codewhale.exe, codew.exe, and codewhale.bat under
    %LOCALAPPDATA%\Programs\CodeWhale\bin, adds that directory to the
    current-user PATH, and creates a Start Menu shortcut that prefers
    Windows Terminal (wt.exe) when it is installed.
  • Extract the archive for your machine: codewhale-windows-x64.zip or
    codewhale-windows-arm64.zip
  • Double-click codewhale.bat (not the raw .exe) to launch
  • Run install.bat to copy the binaries and launcher to %USERPROFILE%\bin
  • Add %USERPROFILE%\bin to your PATH

The portable Windows archive skips the install script — extract and run codewhale.bat from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has bare, unarchived codewhale-<platform> and
codew-<platform> assets. The seven codewhale-tui-<platform> filenames
attached to v0.9.5 are byte-identical compatibility copies used only to let
already-installed v0.9.4 clients discover and cross this single-binary
transition; current installers do not expose a third runtime. The legacy npm
package deepseek-tui is deprecated and is not republished. For migration
from v0.8.x legacy binary names, see docs/REBRAND.md.

Verify (recommended)

Download the checksum manifests from this Release and verify:

# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.9.12

Codewhale v0.9.12 puts computer use in the binary, opens two new routes —
Alibaba Model Studio through the data-driven provider table and Concentrate
as an opt-in BYOK Responses gateway — and adds cloud dispatch plus a
config-gated per-session control socket. The shell is the other half of the
release: a new launch card, the work surface docked under the composer, one
focus owner for Tab, tool cells that carry their own state, and fleet as
the public word for the live collective. The complete item-level change
record is retained below the categorized release highlights.

Added

  • Computer use ships with the binary. The computer-use plugin — 38 tools
    across macOS, Windows, Linux and HarmonyOS, accessibility-first observation
    with pixel fallback, screenshots, zoom, screen recording, and registered
    remote computers over ssh and hdc — is embedded in Codewhale and written to
    $CODEWHALE_HOME/builtin-plugins on first run, so every install channel
    carries it. It lists as builtin · not-reviewed and stays disabled until
    you review and enable it: shipping it is not consenting to it. The
    stdlib-Python computer-use server it replaces is gone.
  • Alibaba Model Studio joins the data-driven provider table as an
    openai-compatible descriptor: international compatible-mode endpoint,
    DASHSCOPE_API_KEY credential, live /v1/models discovery. Qwen 3.8
    Flash and Qwen 3.8 Max arrive through the catalog authority — never a
    hard-coded id.
  • Concentrate: first-class opt-in BYOK Responses gateway with live models
    discovery and typed SSE streaming (#5725).
  • Cloud dispatch: remote runner offloads coding agent tasks to isolated
    cloud sandboxes with machine token auth and structured job tracking
    (#5701, #5712).
  • Per-session control socket: config-gated [control_socket] table binds
    <sessions-dir>/<session-id>/control.sock per running session, exposing
    message, interrupt, relaunch, and status JSON-RPC verbs (#5533, #5831).

Changed

  • Anonymous usage counting is on by default. The 0.9.11 release asked
    first; 0.9.12 counts the same aggregate version/platform, session, feature
    and error totals unless you turn it off, and says so once at first launch
    (policy notice version 5, schema 3, notice_version replacing
    consent_version). Every recorded opt-out stays off: a durable
    telemetry = false, a decline recorded under the old opt-in notice,
    unreadable privacy state, and the CODEWHALE_TELEMETRY=0 / --telemetry false kill switches. Showing the disclosure records only that it was
    shown, never an acceptance. codewhale config set telemetry false turns
    it off and wipes queued counts; codewhale config set telemetry true
    deliberately re-enables it. Nothing new is collected: no conversations,
    code, prompts, files, names, model content, credentials, or IP.

  • The launch screen is our own card take: a thin top line
    ⑂ branch path; a centred bordered card with the whale mark,
    Codewhale + version, one announcement line only when it is true (the
    no-model warning, or MCP news), and the menu New worktree / Resume
    session / Changelog / Quit with their real chords right-aligned. Enter
    runs the highlighted entry, Up/Down move it, and typing goes straight to
    the composer. The card dissolves on the first keystroke or command
    (≤240 ms, instant under reduced motion) (#5826, #5801, #5815, #5286).

  • The work surface sits under the composer by default, keeping history
    readable and leaving the stage unencumbered (#5809).

  • Skills command shapes: FEAT-022 command shapes and retained-host
    validation (#5825, #5829).

  • After the card dissolves, the working screen shows ⑂ branch path with
    ⋮ MCP n/m on the right, the transcript starts with the
    ◆ session_start receipt (naming the configured session-start hooks),
    and the composer's bottom rule carries model (effort) · permission —
    the route's one launch reading. The posture bar and metrics line appear
    only once a session exists.

  • Vocabulary: fleet is the public term and Pod is retired from copy —
    roster, setup, detail, worker-runtime and managed-API messages now say
    Fleet (/fleet canonical, /pod alias). The workflow wire accepts the
    canonical role spellings (general/explore/planner/reviewer/implement/
    test/advisor) with the pre-rename ones kept as load-time aliases, and
    serializes canonical names.

  • The Operate mode-picker hint is shortened to fit 80 columns.

  • The footer always shows the permission posture; when only one chip
    fits, the permission chip outranks the mode word (#5796).

  • Local Ollama: the header names a model only when the local catalog can
    serve it, and says unknown until it knows. The startup mark, web and
    app icon carry the new side-view prompt-eye whale (#5795).

  • One focus owner: Tab and Shift+Tab work regardless of what is in the
    composer; Alt shortcuts survive mid-draft; Ctrl+Tab no longer cycles the
    mode by accident (#5798).

  • Tool cells carry their own state: a running, failed or warned tool
    reads as such in the transcript itself, with per-entry rail dots and
    family-coloured glyphs (#5799).

  • Web: docs hub with task search, shared empty/loading/error states, an
    offline-to-back-online banner, /changelog in ever...

Read more

v0.9.11

Choose a tag to compare

@github-actions github-actions released this 23 Aug 17:39
96d13a0

Codewhale is the public product from Shannon Labs. The codewhale
command, npm package, and release-asset names remain lowercase technical
identifiers. The legacy npm package deepseek-tui is deprecated and
receives no further releases. Users coming from v0.8.x legacy deepseek /
deepseek-tui names should migrate with docs/REBRAND.md.

Install

Recommended — npm (one command, both entrypoints)

npm install -g codewhale

The wrapper downloads the matched codewhale and codew command assets
from this Release. Both contain the same compiled runtime.

Docker / GHCR

docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.9.11

The image exposes the same runtime as both codewhale and codew. The
latest tag is also updated on release.

Cargo (Linux / macOS)

cargo install codewhale-cli --locked

The Cargo package installs codewhale. Cargo cannot create a second command
alias from one binary target; users who want the shorter spelling can add a
codew symlink to that installed executable. The npm, Homebrew, archive,
shell-installer, and container channels install both command names directly.

Manual download — platform archives (recommended)

Each archive below contains the same runtime under the codewhale and
codew command names, plus an install script:

Platform Archive Install script
Linux x64 codewhale-linux-x64.tar.gz install.sh
Linux ARM64 codewhale-linux-arm64.tar.gz install.sh
Android ARM64 (Termux) codewhale-android-arm64.tar.gz install.sh
macOS x64 codewhale-macos-x64.tar.gz install.sh
macOS ARM codewhale-macos-arm64.tar.gz install.sh
Windows x64 (installer) CodeWhaleSetup.exe NSIS setup
Windows x64 codewhale-windows-x64.zip install.bat
Windows x64 (portable) codewhale-windows-x64-portable.zip —
Windows ARM64 codewhale-windows-arm64.zip install.bat
Windows ARM64 (portable) codewhale-windows-arm64-portable.zip —

Unix (Linux / macOS):

tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:

  • For the installer path, run CodeWhaleSetup.exe; it installs
    codewhale.exe, codew.exe, and codewhale.bat under
    %LOCALAPPDATA%\Programs\CodeWhale\bin, adds that directory to the
    current-user PATH, and creates a Start Menu shortcut that prefers
    Windows Terminal (wt.exe) when it is installed.
  • Extract the archive for your machine: codewhale-windows-x64.zip or
    codewhale-windows-arm64.zip
  • Double-click codewhale.bat (not the raw .exe) to launch
  • Run install.bat to copy the binaries and launcher to %USERPROFILE%\bin
  • Add %USERPROFILE%\bin to your PATH

The portable Windows archive skips the install script — extract and run codewhale.bat from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has bare, unarchived codewhale-<platform> and
codew-<platform> assets. The seven codewhale-tui-<platform> filenames
attached to v0.9.5 are byte-identical compatibility copies used only to let
already-installed v0.9.4 clients discover and cross this single-binary
transition; current installers do not expose a third runtime. The legacy npm
package deepseek-tui is deprecated and is not republished. For migration
from v0.8.x legacy binary names, see docs/REBRAND.md.

Verify (recommended)

Download the checksum manifests from this Release and verify:

# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.9.11

Codewhale v0.9.11 tightens the long-running agent loop, makes workflow
failures visible instead of successful-looking, adds an experimental
vision-capable DeepSeek route, and prepares reproducible Codewhale-versus-Pi
evaluation without publishing a result before a real run. The complete
item-level change record is retained below the categorized release highlights.

Added

  • Added first-party deepseek-v4-flash-vision-exp discovery and selection for
    DeepSeek, including the flash-vision alias, bundled offline metadata,
    registry and picker entries, and image-input capability on the chat route.
    Context and output limits inherit from V4 Flash until DeepSeek publishes
    distinct values; pricing remains unknown rather than guessed.
  • Added a provider-controlled Codewhale-versus-Pi parity harness with three
    hermetic coding tasks, route and reasoning-effort receipts, doctor/dry-run
    modes, and bounded result artifacts. The repository ships the harness, not a
    benchmark verdict; comparable real runs remain an acceptance gate.
  • Added portable, secret-free config export/import with a reviewable plan,
    explicit headless consent, backup and rollback, and idempotent re-import.
  • Added bounded multi-file diagnostics through the existing model-facing lsp
    tool without increasing the tool-catalog count. Thanks to Isabel Wu
    (@wuisabel-gif)
    for PR #5524.
  • Added portable presentation, media-attachment, and operation-digest facets to
    the command contract, then moved all seven utility handlers onto the
    contract-backed dispatch path. Thanks to Paulo Aboim Pinto
    (@aboimpinto)
    for PR #5525.

Changed

  • Sub-agent, Fleet-worker, workflow-task, and thread-runtime model turns no
    longer inherit a hidden role-based step ceiling. An omitted or zero
    max_steps is unbounded; a positive user/config value remains an explicit
    cap and is still clamped to the runtime safety ceiling. Wall-clock, provider,
    heartbeat, cancellation, and admission safeguards are unchanged.
  • /rc now mirrors one shared session rather than transferring terminal
    ownership: local and web prompts remain available while idle, approvals use
    first-decision-wins semantics, and transport/integrity failures remain
    fail-closed.
  • The terminal status rows around the composer are now two stable bands:
    provider · model · thinking level is the persistent identity row below
    the composer in every phase, and a separate activity row above the
    composer carries the live phase, notices, and cost/metrics. Sending a
    prompt no longer relocates the route identity above the composer, and
    neither row ever duplicates it.
  • The embedded local Web client now uses the current CWC Ocean hierarchy and
    readable control sizing, follows the shared Enter/Shift+Enter composer
    grammar, and chooses a provider plus model per new thread without mutating
    Runtime defaults. Exact image-input capability is labelled honestly; a
    vision-capable route does not imply that browser attachments exist.
  • The runtime now has one authoritative model-turn loop. The placeholder
    crates/core engine tree is gone, while the active TUI loop and its extracted
    tool-call stages retain existing policy, hook, cancellation, and budget
    behavior. Thanks to Sun Zhenyuan
    (@bistack)
    for PR #5523.

Fixed

  • Chat Completions streams now require terminal proof from [DONE] or a
    non-empty finish_reason. Protocol-only frames no longer count as answer
    content or time-to-first-token, and a provider continuation that ends after
    tool results with no answer or tool call fails durably instead of producing
    a false Completed receipt.
  • A selected v2 Fleet now drives one bounded, deterministic Agent roster across
    terminal and runtime surfaces. Fleet operator/member/explicit-route
    precedence, resolved member identity, and exact vision requirement
    admission now fail visibly instead of silently falling back, first-matching,
    or rerouting.
  • A workflow whose task() dispatch was rejected no longer loses that failure
    inside a parallel() null slot or presents a successful-looking run. Rejected
    dispatches now fail the run, persist as typed bounded receipts with an exact
    count, and appear in transcript, activity detail, and workflow-panel views.
  • Provider readiness, credential-source explanations, focused-agent scrolling,
    compact /status and /help rendering, shell/web output bounds, MCP
    lifecycle reporting, and narrow-terminal onboarding received the detailed
    fixes recorded below.
  • Portable config import/export now preserves typed tables, arrays, numbers,
    booleans, and datetimes without stringifying them, while refusing
    machine-bound trust overlays, credential readers, automatically executable
    hooks/LSP definitions, local-path authority, machine-local network proxy
    routes, cookies, redaction placeholders, and nested or camel/dotted
    credential keys. Project and global bundle operations now load and validate
    the document for their actual scope in both directions, including a
    workspace whose document still lives under the legacy app directory.
  • codewhale login now means Codewhale account sign-in (the same browser
    device flow as codewhale account login, with --no-open and
    --timeout-seconds); provider API keys are configured exclusively through
    codewhale auth set --provider <provider>, and the hidden legacy
    --api-key/--provider flags redirect loudly instead of silently writing
    a key.
  • Account sessions prefer the OS credential manager and now fall back
    automatically to the private 0600 Codewhale secrets file on headless
    hosts, SSH boxes, and containers; the CODEWHALE_CLOUD_ALLOW_FILE_SESSION_STORE
    opt-in is deprecated and ignored.
  • /update gained a Ctrl+Shift+U install chord (catalogued...
Read more

v0.9.10

Choose a tag to compare

@github-actions github-actions released this 20 Aug 09:58

Codewhale is the public product from Shannon Labs. The codewhale
command, npm package, and release-asset names remain lowercase technical
identifiers. The legacy npm package deepseek-tui is deprecated and
receives no further releases. Users coming from v0.8.x legacy deepseek /
deepseek-tui names should migrate with docs/REBRAND.md.

Install

Recommended — npm (one command, both entrypoints)

npm install -g codewhale

The wrapper downloads the matched codewhale and codew command assets
from this Release. Both contain the same compiled runtime.

Docker / GHCR

docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.9.10

The image exposes the same runtime as both codewhale and codew. The
latest tag is also updated on release.

Cargo (Linux / macOS)

cargo install codewhale-cli --locked

The Cargo package installs codewhale. Cargo cannot create a second command
alias from one binary target; users who want the shorter spelling can add a
codew symlink to that installed executable. The npm, Homebrew, archive,
shell-installer, and container channels install both command names directly.

Manual download — platform archives (recommended)

Each archive below contains the same runtime under the codewhale and
codew command names, plus an install script:

Platform Archive Install script
Linux x64 codewhale-linux-x64.tar.gz install.sh
Linux ARM64 codewhale-linux-arm64.tar.gz install.sh
Android ARM64 (Termux) codewhale-android-arm64.tar.gz install.sh
macOS x64 codewhale-macos-x64.tar.gz install.sh
macOS ARM codewhale-macos-arm64.tar.gz install.sh
Windows x64 (installer) CodeWhaleSetup.exe NSIS setup
Windows x64 codewhale-windows-x64.zip install.bat
Windows x64 (portable) codewhale-windows-x64-portable.zip —
Windows ARM64 codewhale-windows-arm64.zip install.bat
Windows ARM64 (portable) codewhale-windows-arm64-portable.zip —

Unix (Linux / macOS):

tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:

  • For the installer path, run CodeWhaleSetup.exe; it installs
    codewhale.exe, codew.exe, and codewhale.bat under
    %LOCALAPPDATA%\Programs\CodeWhale\bin, adds that directory to the
    current-user PATH, and creates a Start Menu shortcut that prefers
    Windows Terminal (wt.exe) when it is installed.
  • Extract the archive for your machine: codewhale-windows-x64.zip or
    codewhale-windows-arm64.zip
  • Double-click codewhale.bat (not the raw .exe) to launch
  • Run install.bat to copy the binaries and launcher to %USERPROFILE%\bin
  • Add %USERPROFILE%\bin to your PATH

The portable Windows archive skips the install script — extract and run codewhale.bat from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has bare, unarchived codewhale-<platform> and
codew-<platform> assets. The seven codewhale-tui-<platform> filenames
attached to v0.9.5 are byte-identical compatibility copies used only to let
already-installed v0.9.4 clients discover and cross this single-binary
transition; current installers do not expose a third runtime. The legacy npm
package deepseek-tui is deprecated and is not republished. For migration
from v0.8.x legacy binary names, see docs/REBRAND.md.

Verify (recommended)

Download the checksum manifests from this Release and verify:

# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.9.10

  • Show the full slash-command or /model completion row in a bounded, wrapping hover popover whenever narrow terminals truncate it, closing the remaining scoped gap from #998. Thanks @AiurArtanis and @formp3 for identifying the affected surfaces.
  • registry_sync no longer ships the full MCP Registry catalog into the
    conversation. It takes a required query, scores the local snapshot
    host-side, and returns at most eight matches; the complete catalog stays on
    disk, and the compaction and spillover exemptions that let a multi-hundred-
    kilobyte dump reach the model unchanged are gone.
  • Providers that mirror the outgoing (reasoning omitted) replay placeholder
    back as a reasoning delta no longer have that echo ingested as real
    thinking: the exact transport placeholder is dropped on arrival, so live
    sessions stop showing a stream of placeholder reasoning blocks and saved
    transcripts stay free of them.
  • Mid-stream connection drops during an interactive turn no longer persist a
    synthetic [runtime] user message. Retry state is a typed engine-internal
    descriptor; a thinking-only drop re-issues the request without claiming a
    partial reply was preserved, the retry budget is enforced in mechanism, and
    recovery produces exactly one authoritative final answer.

Codewhale v0.9.10 is a retention, identity, and product-clarity release: the shell and
transcript can no longer retain unbounded tool output in memory or on disk,
mid-turn history inserts no longer strand in-flight tool rows, every agent
that ran this session is visible from /agents list, the PTY acceptance
lane has a stall watchdog and bounded CI steps, approval outcomes are
durable and fail closed (cyq1017, #5360), and three $HOME disk leaks are
reclaimed. Extension surfaces now name their real state and act only
through the reviewed install and trust flows, and sub-agent, shell, task,
and workflow state is owned by the session that created it (#5518). Test
threads get an 8 MiB stack so the lib suite can no longer
abort under load.

Fixed

  • First run starts on the welcome screen again. A missing key no longer
    skips Welcome and auto-opens the local-provider list: Enter walks to the
    calm provider explanation, then Enter opens the picker so a first API key
    can be set. Returning missing-key recovery still opens the picker on
    launch.
  • A foreground bash command that named no timeout is bounded again. The
    model-facing bash tool left an omitted timeout_ms at the internal
    ceiling (~24.8 days) instead of the 120 s default its own schema
    advertises, so a CLI that blocked on an interactive prompt or a hung
    network call held the turn open indefinitely — one report sat on a single
    unauthenticated CLI call for over two hours with the tool row simply
    counting seconds. The advertised default now applies, which arms the
    existing recovery: the process is killed and the model is told to rerun
    with background=true and poll with action="wait". An explicit
    timeout_ms is still honored for genuinely long foreground work, and
    background and interactive runs keep their own lifetimes.
  • The Extensions (/plugin) Marketplace is no longer a read-only list.
    Every recommendation and stored candidate names its truthful state and
    primary action — Add, Enable, Configured, or Unavailable — and Enter or a
    mouse click runs that action through the existing reviewed /mcp add recommended, /mcp enable, and /plugin install/trust controllers, so
    no second trust path exists. Browser Use and Sandbox Runtime stay
    honestly Unavailable with their real setup routing instead of implying an
    install Codewhale cannot perform.
  • The Extensions MCP tab now renders one honest inventory: the header count
    and the visible rows derive from the same configured-server set, so
    MCP (6) can no longer sit above two rendered rows. Disabled servers
    stay visible and labeled disabled instead of silently disappearing, and
    configured servers absent from the live snapshot list as not-yet-inspected
    with their own explicit reload affordance through the MCP command
    controller.
  • Installed plugin rows now act on their real state: Enter opens an active
    bundle (/plugin show), offers Enable for a trusted-but-disabled bundle,
    or routes an untrusted bundle to the existing trust review — through the
    same confirmation and persistence controllers as the slash commands.
  • Sub-agent handoffs and rosters, background shell jobs, durable tasks,
    delayed continuations, and workflow controls are now scoped to the
    session that owns them. Records carry immutable root-session ownership,
    stale completion-channel payloads are rejected before deduplication,
    background work drains and reports only to its owning session, and
    legacy ownerless jobs fail closed (#5518 failure class reported by
    @hxfhd; the report's exact JavaScript provenance was not claimed as
    reproduced).
  • The resolved route envelope now reaches every outbound model call: all
    wire dialects and auxiliary calls clamp at the shared transport seam
    under one wire/reservation budget, provider input limits are honored, and
    switching models on the same protocol no longer inherits the previous
    model's limits (#5516, #5518).
  • First-run continuity: the chosen onboarding provider persists across
    restarts, a missing first-run config no longer interrupts the flow, and
    the automatic working-agreement checkpoint renders as a standalone setup
    handoff instead of regressing the onboarding rail to the full wizard's
    4/10 progress.
  • Explicitly worded natural-language /goal declarations now create a
    durable goal in the provider-neutral engine before model dispatch, while
    ordinary tasks and quoted transcripts stay out of goal mode and prose
    acknowledgemen...
Read more

v0.9.9

Choose a tag to compare

@github-actions github-actions released this 18 Aug 14:09

Codewhale is the public product from Shannon Labs. The codewhale
command, npm package, and release-asset names remain lowercase technical
identifiers. The legacy npm package deepseek-tui is deprecated and
receives no further releases. Users coming from v0.8.x legacy deepseek /
deepseek-tui names should migrate with docs/REBRAND.md.

Install

Recommended — npm (one command, both entrypoints)

npm install -g codewhale

The wrapper downloads the matched codewhale and codew command assets
from this Release. Both contain the same compiled runtime.

Docker / GHCR

docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.9.9

The image exposes the same runtime as both codewhale and codew. The
latest tag is also updated on release.

Cargo (Linux / macOS)

cargo install codewhale-cli --locked

The Cargo package installs codewhale. Cargo cannot create a second command
alias from one binary target; users who want the shorter spelling can add a
codew symlink to that installed executable. The npm, Homebrew, archive,
shell-installer, and container channels install both command names directly.

Manual download — platform archives (recommended)

Each archive below contains the same runtime under the codewhale and
codew command names, plus an install script:

Platform Archive Install script
Linux x64 codewhale-linux-x64.tar.gz install.sh
Linux ARM64 codewhale-linux-arm64.tar.gz install.sh
Android ARM64 (Termux) codewhale-android-arm64.tar.gz install.sh
macOS x64 codewhale-macos-x64.tar.gz install.sh
macOS ARM codewhale-macos-arm64.tar.gz install.sh
Windows x64 (installer) CodeWhaleSetup.exe NSIS setup
Windows x64 codewhale-windows-x64.zip install.bat
Windows x64 (portable) codewhale-windows-x64-portable.zip —
Windows ARM64 codewhale-windows-arm64.zip install.bat
Windows ARM64 (portable) codewhale-windows-arm64-portable.zip —

Unix (Linux / macOS):

tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:

  • For the installer path, run CodeWhaleSetup.exe; it installs
    codewhale.exe and codew.exe under
    %LOCALAPPDATA%\Programs\CodeWhale\bin and adds that directory to the
    current-user PATH.
  • Extract the archive for your machine: codewhale-windows-x64.zip or
    codewhale-windows-arm64.zip
  • Run install.bat (copies to %USERPROFILE%\bin)
  • Add %USERPROFILE%\bin to your PATH

The portable Windows archive skips the install script — extract and run from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has bare, unarchived codewhale-<platform> and
codew-<platform> assets. The seven codewhale-tui-<platform> filenames
attached to v0.9.5 are byte-identical compatibility copies used only to let
already-installed v0.9.4 clients discover and cross this single-binary
transition; current installers do not expose a third runtime. The legacy npm
package deepseek-tui is deprecated and is not republished. For migration
from v0.8.x legacy binary names, see docs/REBRAND.md.

Verify (recommended)

Download the checksum manifests from this Release and verify:

# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.9.9

Codewhale v0.9.9 is a truth-and-resilience release: the shell tool can no
longer wedge a session when the host runs out of disk or descriptors,
unverified context windows and output ceilings are labeled honestly at every
surface, DeepSeek V4 is priced on the published peak/off-peak tiers, SSE
UTF-8 fails closed in every dialect, Fleet shadowing is visible, bwrap gets
container essentials and extra roots, the dsh skin rides the bundle
profile, the agent tool schema is down to 12 fields, and README/website
locales grow to 18 and 8.

Fixed

  • The lowercase bash tool no longer wedges when its complete-output spill
    file cannot be created: a full temp volume or exhausted descriptor table
    used to fail every call — echo ok included — with the harness-internal
    "Failed to create streaming shell output" and never recover until the
    host was cleaned up. The spill is now best-effort (the bounded tail is
    still returned and the truncation notice says why the full-output path is
    missing), and any remaining spawn/stream failure names the exhausted
    resource — disk, file descriptors, memory — and says the next call is safe
    to retry (#5465; the wedge that took out the owner's own 0.9.9 session).
  • A concrete route/offering output limit now outranks the conservative
    8,192-token compatibility guess for an uncatalogued model. Routes that
    publish no output limit remain fail-closed, documented model ceilings stay
    authoritative, and a route limit can never raise the requested cap (#5460).
  • Context-window honesty at every surface (#5239, #5441): the
    model-name hint and fallback rungs of the context-window ladder are
    guesses, and every surface that renders one now says so — the status line,
    /status, /config, the context-pressure message, the model picker chips,
    and the auto-router inventory. Unverified windows still drive real budgets
    (compaction trigger, context meter, output reservation); they just stop
    reading as capabilities anyone checked. A window parsed from an _Nk
    model-name suffix (qwen3-32b-256k → 256K) is now its own
    model-name hint rung below catalog, because it is optimistic rather
    than conservative — a catalog or provider-reported value beats it. The
    [providers.<name>] context_window override remains the hard fix and
    renders as configured with no marker.
  • Output-ceiling honesty (#5440): an Anthropic-family model the catalog does
    not describe keeps the 64K Messages floor as its clamp and the ChatGPT/
    Codex OAuth route keeps its 4K policy, but OutputCeilingSource gained an
    unverified rung for both, so exec-stream receipts and the model picker
    label them unverified/"assumed floor" instead of documented. Clamp
    values are unchanged.
  • Telemetry default-on is visible (#5441): codewhale doctor's
    runtime-posture section gained a telemetry=on (default)-style row with
    the source that decided it (cli | env | config | default), and
    codewhale config get telemetry reports the resolved consent with its
    source instead of key not found on a machine whose batches ship. Truth
    change only; resolution and behavior are untouched.
  • Fleet: a scout's read-only shell carve-out (#5428) is now honored by both
    the posture gate and the execution envelope, so git log, find | head,
    npm view and the other bounded read-only commands run in-place instead
    of being refused as "Executes" (#5426). Delegation still never widens
    authority: the role-isolation test and docs/SUBAGENTS.md pin that a child
    cannot exceed its parent's posture (#5426, #5435).
  • /rename and /title now apply mid-first-turn: the session file does
    not exist until the first autosave, so the rename fell through with
    NotFound; the shared path now prefers the per-session checkpoint and
    rebuilds from App state, with a PTY regression test through the live
    event loop (#5430).
  • integrations dsh plan no longer refuses DeepSeek's default
    Responses-dialect route (deepseek-v4-flash); Responses and
    Anthropic-Messages routes are carried through pi-ai
    openai-responses / anthropic-messages instead of being approximated
    or refused; only credentialed base URLs are still refused, with an error
    that names provider and model (#5434).
  • Session cost no longer sits at unverified_live_pricing when live pricing
    cannot be verified (control-plane 503, Models.dev capabilities-only
    overlays): provider-docs bundled fallback rates for the DeepSeek V4
    family on Fireworks / OpenCode Zen restore a usable figure, live
    per-provider rows still win, and kimi-k3 stays unpriced until a
    published rate exists (#5241; harvested from #5402).
  • Release assets: release.yml asset-freshness checks compare against the
    release job's own started_at, so job-level reruns of the npm step are no
    longer poisoned by earlier uploads (#5429).
  • macOS CI: the agent_focus_pty auto-review receipt test waited on a
    worker that had already completed and raced the rail's focus; it now holds
    the child's wrap-up and waits for a settled live row (refs #5056, #5403).
  • DeepSeek V4 pricing follows the published peak/off-peak tiers (peak
    01:00–04:00 and 06:00–10:00 UTC; off-peak is half of peak) for
    deepseek-v4-flash and deepseek-v4-pro in USD and CNY, resolved from
    each turn's recorded time; the stale single-tier rows understated cost up
    to ~4×. Because every direct DeepSeek first-party rate is now
    time-windowed, the scorecard fails closed (missing_recorded_time) on an
    undated DeepSeek turn instead of guessing a tier (#5470; #5241 follow-up,
    verified against api-docs.deepseek.com on 2026-08-17).
  • SSE UTF-8 split across HTTP/2 DATA frames now fails closed in every
    streaming dialect: a shared strict decoder, tail flush, and
    decode_failed propagation (InvalidSseUtf8) replace the per-dialect
    approximations, with byte-chunk decoder tests (#5374; supersedes draft
    #5404).
  • CI: release_four_read_only_fleet_roles_launch_with_canonical_prompts
    answered Fleet children with SSE while they call the blocking JSON path;
    the parse failure was retried and double-count...
Read more

v0.9.8

Choose a tag to compare

@github-actions github-actions released this 16 Aug 19:25
f0a5c52

Codewhale is the public product from Shannon Labs. The codewhale
command, npm package, and release-asset names remain lowercase technical
identifiers. The legacy npm package deepseek-tui is deprecated and
receives no further releases. Users coming from v0.8.x legacy deepseek /
deepseek-tui names should migrate with docs/REBRAND.md.

Install

Recommended — npm (one command, both entrypoints)

npm install -g codewhale

The wrapper downloads the matched codewhale and codew command assets
from this Release. Both contain the same compiled runtime.

Docker / GHCR

docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.9.8

The image exposes the same runtime as both codewhale and codew. The
latest tag is also updated on release.

Cargo (Linux / macOS)

cargo install codewhale-cli --locked

The Cargo package installs codewhale. Cargo cannot create a second command
alias from one binary target; users who want the shorter spelling can add a
codew symlink to that installed executable. The npm, Homebrew, archive,
shell-installer, and container channels install both command names directly.

Manual download — platform archives (recommended)

Each archive below contains the same runtime under the codewhale and
codew command names, plus an install script:

Platform Archive Install script
Linux x64 codewhale-linux-x64.tar.gz install.sh
Linux ARM64 codewhale-linux-arm64.tar.gz install.sh
Android ARM64 (Termux) codewhale-android-arm64.tar.gz install.sh
macOS x64 codewhale-macos-x64.tar.gz install.sh
macOS ARM codewhale-macos-arm64.tar.gz install.sh
Windows x64 (installer) CodeWhaleSetup.exe NSIS setup
Windows x64 codewhale-windows-x64.zip install.bat
Windows x64 (portable) codewhale-windows-x64-portable.zip —
Windows ARM64 codewhale-windows-arm64.zip install.bat
Windows ARM64 (portable) codewhale-windows-arm64-portable.zip —

Unix (Linux / macOS):

tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:

  • For the installer path, run CodeWhaleSetup.exe; it installs
    codewhale.exe and codew.exe under
    %LOCALAPPDATA%\Programs\CodeWhale\bin and adds that directory to the
    current-user PATH.
  • Extract the archive for your machine: codewhale-windows-x64.zip or
    codewhale-windows-arm64.zip
  • Run install.bat (copies to %USERPROFILE%\bin)
  • Add %USERPROFILE%\bin to your PATH

The portable Windows archive skips the install script — extract and run from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has bare, unarchived codewhale-<platform> and
codew-<platform> assets. The seven codewhale-tui-<platform> filenames
attached to v0.9.5 are byte-identical compatibility copies used only to let
already-installed v0.9.4 clients discover and cross this single-binary
transition; current installers do not expose a third runtime. The legacy npm
package deepseek-tui is deprecated and is not republished. For migration
from v0.8.x legacy binary names, see docs/REBRAND.md.

Verify (recommended)

Download the checksum manifests from this Release and verify:

# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.9.8

Codewhale v0.9.8 ships the remaining assigned finish. Remaining web
settings polish moves to v0.9.9. Prefab third-party templates that have
a published OpenAI-compatible host ship here (#5350).

Fixed

  • sudo (and su/setuid helpers) work again for wheel-group administrators
    who want Codewhale to be able to escalate: the Linux startup hardening's
    irreversible PR_SET_NO_NEW_PRIVS flag — inherited by every child process —
    is now skippable with CODEWHALE_NO_NEW_PRIVS=0 (#5413). The flag stays on
    by default; the no-ptrace and no-core-dump measures are never skipped.

  • Abort-class process deaths no longer poison the terminal (#5424). A
    stack overflow, allocation failure, or double panic skips the panic hook
    and every cleanup guard, which is how a v0.9.7 user's mid-turn exit left
    mouse capture leaking SGR sequences into their shell. An
    async-signal-safe handler now restores the terminal modes and appends a
    one-line cause marker to ~/.codewhale/crashes/last-fatal-signal.log
    before re-raising, keeping the honest 128+signal wait status. A SIGKILL
    (OOM killer) remains uninterceptable by design.

Changed

  • Prompt-cache prefix is pinned for the session. The tool loop no longer
    recomposes the system prompt from disk on every model step, so an agent
    writing a file no longer busts the provider KV prefix cache mid-turn. The
    system prompt and tool catalog are re-composed only on a declared header
    change (/model, mode, goal, session resume), which re-pins under a logged
    reason; an undeclared change is reported as drift and the original pin is
    kept instead of silently becoming the new baseline. Workspace, AGENTS.md,
    skills, memory, and goal drift now reaches the model as one bounded
    <context_update> user message at the next user turn — a history append,
    not a header rewrite. /cache stats shows the pin reason, the last-miss
    reason, the undeclared-drift count, and the context-update count. See
    docs/CACHE.md.

  • Plugin compatibility is now per-component. A reviewed, trusted, enabled
    bundle that mixes Skills or MCP with unsupported commands, agents, hooks,
    LSP, native, filesystem-roots, or lifecycle-mutation declarations keeps the
    supported adapters active and reports the rest as inactive (full /
    partial / unsupported). All-unsupported bundles still cannot be enabled.
    The capability hash is now v2 and binds this build's activation policy, so
    older v1 receipts and any later adapter-enablement change fail closed as
    needs-review. Skills and each MCP transport re-request their own capability
    at the consumption boundary.

Added

  • Composer multiline mode is available in /settings. When enabled, Enter inserts a new line and Shift+Enter sends the message (#5345, reported and tracked by @AiurArtanis).

  • /plugin marketplace add|list|show|remove|install completes the
    federated marketplace journey (#5311). add reads one LOCAL catalog
    document in the real published schemas (Kimi, Claude, Codex, or
    Codewhale native) — no network, regular files only — and persists it
    beside the plugin state with the same hardened, fail-closed store.
    list/show render every candidate with per-entry diagnostics,
    display-only tiers, and honest install plans that say when Codewhale
    cannot fetch a source; install routes through the existing reviewed
    installer, so installed bundles still enter disabled and untrusted.
    Foreign auto-install policy (Codex INSTALLED_BY_DEFAULT) is visibly
    ignored; nothing is auto-installed, auto-trusted, or granted vendor
    trust.

  • /rc attach now includes an observed owner/name git remote when the
    folder has a GitHub, CNB, or Gitee origin, so CWC can label the paired
    session. Paths stay off the wire. Reconnect after both this client and
    CWC #202 land to backfill existing empty rows.

  • The local Runtime web client keeps the thread rail clipped so New
    thread
    cannot paint over the session fact chips. Chips wrap instead
    of sliding under the rail.

  • Z.ai GLM-5.3 is live on the Coding Plan and is now the default direct
    Z.ai model: DEFAULT_ZAI_MODEL resolves to GLM-5.3 in both
    codewhale-tui and codewhale-config, and it is the first /model row
    after /provider zai. Explicit GLM-5.2 selections (model = "GLM-5.2"
    and its glm-5.2 aliases) keep their own id — only the default moved.
    Limits and reasoning options still inherit from GLM-5.2 until Z.ai
    publishes distinct 5.3 numbers. No USD price is claimed. A live call
    can still 429 with entitlement code 1311 on accounts that are not
    provisioned for 5.3.

  • The TUI transcript renders Markdown blockquotes (> lines) with a quote
    rail — nested quotes, inline bold/code/links, wrapped continuation rows, and
    selection copy that keeps the quote text and skips the rail chrome.

  • Sub-agent details show the resolved model, fleet role, and type. Labels
    use the session/role name instead of a generic Agent N (#5371, #5287).

  • Documented catalogue output ceilings (DeepSeek V4 384K) are honored on
    the request. A clean output-limit stop continues the turn instead of
    killing it (#5373).

  • Ollama Cloud is a first-class hosted provider (/provider ollama-cloud)
    on the official OpenAI-compatible https://ollama.com/v1 route. Local
    Ollama stays keyless. The exact released ollama + Cloud URL tuple keeps
    a bounded compatibility path across saved sessions, Fleet, and nested
    subagents; neighboring remotes stay custom and fail closed against
    inherited official credentials.

  • Homebrew ships a codewhale formula. brew tap Hmbown/deepseek-tui && brew install codewhale is the install path; brew upgrade codewhale
    updates it. The legacy deepseek-tui formula remains a deprecated alias
    for one overlap release.

  • Terminal tab/window titles now carry the existing saved session name before
    the live state (Codewhale, reasoning…, using tool…, done), so parallel
    sessions are identifiable at a glance without a second title setting.
    /title <name> is a discoverable alias for /rename; both update the ...

Read more

v0.9.7

Choose a tag to compare

@github-actions github-actions released this 13 Aug 08:36
5e3ac84

Codewhale is the public product from Shannon Labs. The codewhale
command, npm package, and release-asset names remain lowercase technical
identifiers. The legacy npm package deepseek-tui is deprecated and
receives no further releases. Users coming from v0.8.x legacy deepseek /
deepseek-tui names should migrate with docs/REBRAND.md.

Install

Recommended — npm (one command, both entrypoints)

npm install -g codewhale

The wrapper downloads the matched codewhale and codew command assets
from this Release. Both contain the same compiled runtime.

Docker / GHCR

docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.9.7

The image exposes the same runtime as both codewhale and codew. The
latest tag is also updated on release.

Cargo (Linux / macOS)

cargo install codewhale-cli --locked

The Cargo package installs codewhale. Cargo cannot create a second command
alias from one binary target; users who want the shorter spelling can add a
codew symlink to that installed executable. The npm, Homebrew, archive,
shell-installer, and container channels install both command names directly.

Manual download — platform archives (recommended)

Each archive below contains the same runtime under the codewhale and
codew command names, plus an install script:

Platform Archive Install script
Linux x64 codewhale-linux-x64.tar.gz install.sh
Linux ARM64 codewhale-linux-arm64.tar.gz install.sh
Android ARM64 (Termux) codewhale-android-arm64.tar.gz install.sh
macOS x64 codewhale-macos-x64.tar.gz install.sh
macOS ARM codewhale-macos-arm64.tar.gz install.sh
Windows x64 (installer) CodeWhaleSetup.exe NSIS setup
Windows x64 codewhale-windows-x64.zip install.bat
Windows x64 (portable) codewhale-windows-x64-portable.zip —
Windows ARM64 codewhale-windows-arm64.zip install.bat
Windows ARM64 (portable) codewhale-windows-arm64-portable.zip —

Unix (Linux / macOS):

tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:

  • For the installer path, run CodeWhaleSetup.exe; it installs
    codewhale.exe and codew.exe under
    %LOCALAPPDATA%\Programs\CodeWhale\bin and adds that directory to the
    current-user PATH.
  • Extract the archive for your machine: codewhale-windows-x64.zip or
    codewhale-windows-arm64.zip
  • Run install.bat (copies to %USERPROFILE%\bin)
  • Add %USERPROFILE%\bin to your PATH

The portable Windows archive skips the install script — extract and run from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has bare, unarchived codewhale-<platform> and
codew-<platform> assets. The seven codewhale-tui-<platform> filenames
attached to v0.9.5 are byte-identical compatibility copies used only to let
already-installed v0.9.4 clients discover and cross this single-binary
transition; current installers do not expose a third runtime. The legacy npm
package deepseek-tui is deprecated and is not republished. For migration
from v0.8.x legacy binary names, see docs/REBRAND.md.

Verify (recommended)

Download the checksum manifests from this Release and verify:

# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.9.7

Codewhale v0.9.7 keeps the catalog ordinary. Grok 4.6 lands as a normal catalog
row instead of a provider-shaped pile of special cases, OrcaRouter joins as a
named provider, and a panic-safety advisory in lru is cleared by lifting the
pin that caused it rather than living around it.

Added

  • Grok 4.6 is the direct xAI default, with the grok alias moving onto it and
    grok-4.5 still explicitly selectable. Its 500K context, text/image input,
    tool and structured-output support, low/medium/high/xhigh reasoning
    efforts (default high), and server-side web search all come from the
    Models.dev-shaped catalog rather than model-specific code. reasoning_effort
    reaches the wire only on the exact first-party https://api.x.ai/v1 route,
    and the usage-aware 200K-token pricing boundary is scoped to direct xAI so
    aggregator routes reusing the model slug cannot inherit xAI billing.
  • OrcaRouter is a first-class named provider: ORCAROUTER_API_KEY, default base
    URL https://api.orcarouter.ai/v1, deepseek/deepseek-v4-pro default,
    orcarouter/auto routing, CLI --provider selector, and TUI picker entries
    (#5321).

Changed

  • Reasoning-effort normalization and the model picker read a model's published
    reasoning_options list from the catalog instead of collapsing every route to
    the historic Low/Medium ladder. Any catalog row that publishes an effort list
    keeps its own vocabulary.
  • Docs record DeepSeek's live DeepSeek-V4-Pro-0813 backend label while the
    callable API ID stays deepseek-v4-pro. No aliases are remapped and no
    deepseek-v4-pro[1m] selector is sent.

Fixed

  • Copying a user or assistant message takes its canonical content instead of
    reserialized transcript lines, keeping role glyphs, continuation rails, and
    visual wrapping out of the clipboard while preserving authored Unicode,
    Markdown, and hard line breaks. Tool and Thinking cells stay on the existing
    full-transcript path (#5319).
  • load_session no longer runs crash recovery on every read. Snapshot reads go
    through a side-effect-free load_session_snapshot and recovery is explicit
    via recover_session_for_resume, so an embedding host inspecting a durable
    session while a tool is still running no longer gets a spurious crash repair
    (#5320).

Security

  • lru moves to 0.18 to clear RUSTSEC-2026-0253, where LruCache::pop() was
    not panic-safe and could leave dangling list pointers. The ratatui-core
    =0.1.0 pin that transitively forced lru ^0.16 is lifted, so
    ColorCompatBackend now answers get_cursor_position() from tracked cursor
    state — the upstream-recommended workaround for the startup CPR race
    (ratatui/ratatui#2483, ratatui/ratatui#2640) that the pin originally worked
    around. ratatui itself stays pinned at =0.30.0, so the API surface is
    unchanged.

Known issues

  • The integration test
    exec_persistent_service::failed_exec_kills_pending_service_and_exits_nonzero
    is a confirmed flake under parallel load ("service pid file never appeared").
    It passes in isolation and is unrelated to any v0.9.7 change.

Contributors

See CHANGELOG.md for full notes and docs/CHANGELOG_ARCHIVE.md for older releases.

v0.9.6

Choose a tag to compare

@github-actions github-actions released this 12 Aug 08:47

Codewhale is the public product from Shannon Labs. The codewhale
command, npm package, and release-asset names remain lowercase technical
identifiers. The legacy npm package deepseek-tui is deprecated and
receives no further releases. Users coming from v0.8.x legacy deepseek /
deepseek-tui names should migrate with docs/REBRAND.md.

Install

Recommended — npm (one command, both entrypoints)

npm install -g codewhale

The wrapper downloads the matched codewhale and codew command assets
from this Release. Both contain the same compiled runtime.

Docker / GHCR

docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.9.6

The image exposes the same runtime as both codewhale and codew. The
latest tag is also updated on release.

Cargo (Linux / macOS)

cargo install codewhale-cli --locked

The Cargo package installs codewhale. Cargo cannot create a second command
alias from one binary target; users who want the shorter spelling can add a
codew symlink to that installed executable. The npm, Homebrew, archive,
shell-installer, and container channels install both command names directly.

Manual download — platform archives (recommended)

Each archive below contains the same runtime under the codewhale and
codew command names, plus an install script:

Platform Archive Install script
Linux x64 codewhale-linux-x64.tar.gz install.sh
Linux ARM64 codewhale-linux-arm64.tar.gz install.sh
Android ARM64 (Termux) codewhale-android-arm64.tar.gz install.sh
macOS x64 codewhale-macos-x64.tar.gz install.sh
macOS ARM codewhale-macos-arm64.tar.gz install.sh
Windows x64 (installer) CodeWhaleSetup.exe NSIS setup
Windows x64 codewhale-windows-x64.zip install.bat
Windows x64 (portable) codewhale-windows-x64-portable.zip —
Windows ARM64 codewhale-windows-arm64.zip install.bat
Windows ARM64 (portable) codewhale-windows-arm64-portable.zip —

Unix (Linux / macOS):

tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:

  • For the installer path, run CodeWhaleSetup.exe; it installs
    codewhale.exe and codew.exe under
    %LOCALAPPDATA%\Programs\CodeWhale\bin and adds that directory to the
    current-user PATH.
  • Extract the archive for your machine: codewhale-windows-x64.zip or
    codewhale-windows-arm64.zip
  • Run install.bat (copies to %USERPROFILE%\bin)
  • Add %USERPROFILE%\bin to your PATH

The portable Windows archive skips the install script — extract and run from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has bare, unarchived codewhale-<platform> and
codew-<platform> assets. The seven codewhale-tui-<platform> filenames
attached to v0.9.5 are byte-identical compatibility copies used only to let
already-installed v0.9.4 clients discover and cross this single-binary
transition; current installers do not expose a third runtime. The legacy npm
package deepseek-tui is deprecated and is not republished. For migration
from v0.8.x legacy binary names, see docs/REBRAND.md.

Verify (recommended)

Download the checksum manifests from this Release and verify:

# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.9.6

Codewhale v0.9.6 is a subtractive release: fewer runtime guards, one stable
prompt, truthful provider endings, and a smaller compaction path that preserves
the provider cache. The changes were grounded by matched Terminal-Bench 2.1
runs against Pi 0.8.41 and by dogfooding repeated manual compaction.

Added

  • web_search defaults to Firecrawl Cloud without an API key; keyless requests
    are headerless and quota-bounded, while an optional user key raises limits.
  • Green web builds on main now emit an actionable manual-deploy reminder, so
    site changes cannot quietly appear shipped while Cloudflare still serves an
    older revision.
  • Mistral AI is a first-class provider route, including Codestral models,
    first-party reasoning support, authentication, picker entries, and aliases.
  • Headless Bash can transfer explicitly requested persistent Unix services
    out of an exec run, with ownership and cleanup receipts.
  • /remote-env opens hosted Work from the current GitHub or CNB branch tip and
    states exactly which unpushed, dirty, ignored, secret, and session state stays
    local.
  • Linux ARM64 release and nightly assets are static musl builds with native
    launch checks.
  • Maintainers can report observed daily active installs from the same anonymous,
    aggregate telemetry dataset; no additional client data is collected.
  • Fleet-dispatched members under a read-only evidence (no-network) ceiling now
    keep the Web tool's read-only search and fetch actions — parity with an
    ordinary scout — while every reaching surface (web.run, fetch_url,
    github, MCP) stays denied and the sentinel-backed capability envelope
    remains the fail-closed backstop.
  • /fleet setup can show an optional, deterministic, unratified role-to-model
    advisory built only from configured ready routes. Accept, edit, and reject
    all remain inside the existing human-reviewed profile save boundary; the
    advisory never launches a Fleet or writes a second configuration.
  • /update checks for a newer Codewhale release and installs it from inside
    the TUI, while tui_help gives agents the same command and key map users see.
  • Markdown file paths render as OSC 8 links where the terminal supports them,
    and every agent row can open that agent's transcript directly.
  • ACP editor sessions can execute multi-round file, search, Git, patch, and
    explicitly enabled shell tool calls through the shared Runtime registry.
    Shell access requires both the client's terminal capability and Codewhale's
    headless shell opt-in, and cancellation stops an in-flight tool before the
    turn returns (#5225 by @rafaelcavalheri).
  • Lowercase read returns bounded typed PNG, JPEG, GIF, and WebP results to
    image-capable Chat, Responses, Anthropic, and ACP routes. Text-only routes
    receive an explicit omission receipt; image bytes never spill into ordinary
    transcript, export, compaction, or relay text.

Changed

  • Anonymous usage counting is on by default for fresh installs and disclosed in
    a native first-run Codewhale modal with an immediate opt-out. Prior declines
    remain off. Codewhale does not collect conversations, code, prompts, files,
    repo or branch names, credentials, model content, or per-turn activity
    timelines.
  • Wide terminals use a responsive, full-screen ocean canvas with modest
    gutters: prose keeps a readable measure while tools, diffs, work surfaces,
    the composer, and status chrome can use the available width. Turn and major
    activity seams breathe without padding every call inside a tool group.
  • Root CLI help describes product actions directly instead of exposing internal
    TUI/runtime layers.
  • Bash action="wait" now blocks by default when a wait is requested; callers
    can still ask for a nonblocking snapshot, and persistent service ownership
    remains explicit.
  • Compaction is one cache-stable summary request followed by one committed
    replacement summary and a bounded recent-message tail. Older saved sessions
    still restore.
  • Ask, Work, Auto-Review, and Full Access share one stable base prompt. Modes
    continue to differ through permissions and the live tool catalog; the former
    Act label is now Work throughout the product and shipped locales.
  • Full Access now auto-approves non-bypassable tools consistently, and the
    default choice shown on ordinary approval cards is configurable.
  • Model, context-window, dispatch-name, and nested-agent spawn receipts report
    the route and limits actually used rather than silently substituting a
    guessed identity.
  • Child-agent launches mint one immutable route receipt before admission and
    preserve it through status, interruption, completion, resume, Work Graph,
    and ledger projections, so provider/model attribution cannot drift (#5305).
  • Goal runs no longer stop because of internal continuation, repeated-gap, or
    unanswered-question guards. Explicit user limits and terminal goal states
    remain authoritative.
  • Account-owned /rc remote control now keeps exclusive ownership and a
    crash-recoverable delivery journal until the server acknowledges terminal,
    approval, failure, and snapshot state.
  • todo_write is an optional progress surface rather than required model
    ceremony.
  • New turns use one small, stable toolbox: read, write, edit, bash,
    agent, todo_write, and tool_search. The optional progress tool stays
    visible as familiar working memory; specialized native, Web, MCP, plugin,
    memory, task, and verification tools are policy-filtered and searchable;
    activated schemas stay in a bounded per-conversation cache. Every sub-agent
    keeps its own search and cache, including policy-allowed Web research, while
    forked context and parent activations remain warm starts rather than allowlists.
  • The direct file and shell schemas follow Pi's deliberately small contract:
    bounded complete-line reads, hash-free writes, unambiguous multi-edit with
    BOM/CRLF preservation and conservative fuzzy matching, and one foreground
    bash command with a bounded chronological output tail. Modes change
    execution authority, not those primitive names.
  • Codewhale n...
Read more

v0.9.5

Choose a tag to compare

@github-actions github-actions released this 08 Aug 16:39
853cb70

Codewhale is the public product from Shannon Labs. The codewhale
command, npm package, and release-asset names remain lowercase technical
identifiers. The legacy npm package deepseek-tui is deprecated and
receives no further releases. Users coming from v0.8.x legacy deepseek /
deepseek-tui names should migrate with docs/REBRAND.md.

Install

Recommended — npm (one command, both entrypoints)

npm install -g codewhale

The wrapper downloads the matched codewhale and codew command assets
from this Release. Both contain the same compiled runtime.

Docker / GHCR

docker run --rm -it \
  -e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
  -v codewhale-home:/home/codewhale/.codewhale \
  ghcr.io/hmbown/codewhale:v0.9.5

The image exposes the same runtime as both codewhale and codew. The
latest tag is also updated on release.

Cargo (Linux / macOS)

cargo install codewhale-cli --locked

The Cargo package installs codewhale. Cargo cannot create a second command
alias from one binary target; users who want the shorter spelling can add a
codew symlink to that installed executable. The npm, Homebrew, archive,
shell-installer, and container channels install both command names directly.

Manual download — platform archives (recommended)

Each archive below contains the same runtime under the codewhale and
codew command names, plus an install script:

Platform Archive Install script
Linux x64 codewhale-linux-x64.tar.gz install.sh
Linux ARM64 codewhale-linux-arm64.tar.gz install.sh
Android ARM64 (Termux) codewhale-android-arm64.tar.gz install.sh
macOS x64 codewhale-macos-x64.tar.gz install.sh
macOS ARM codewhale-macos-arm64.tar.gz install.sh
Windows x64 (installer) CodeWhaleSetup.exe NSIS setup
Windows x64 codewhale-windows-x64.zip install.bat
Windows x64 (portable) codewhale-windows-x64-portable.zip —
Windows ARM64 codewhale-windows-arm64.zip install.bat
Windows ARM64 (portable) codewhale-windows-arm64-portable.zip —

Unix (Linux / macOS):

tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:

  • For the installer path, run CodeWhaleSetup.exe; it installs
    codewhale.exe and codew.exe under
    %LOCALAPPDATA%\Programs\CodeWhale\bin and adds that directory to the
    current-user PATH.
  • Extract the archive for your machine: codewhale-windows-x64.zip or
    codewhale-windows-arm64.zip
  • Run install.bat (copies to %USERPROFILE%\bin)
  • Add %USERPROFILE%\bin to your PATH

The portable Windows archive skips the install script — extract and run from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.

Each platform also has bare, unarchived codewhale-<platform> and
codew-<platform> assets. The seven codewhale-tui-<platform> filenames
attached to v0.9.5 are byte-identical compatibility copies used only to let
already-installed v0.9.4 clients discover and cross this single-binary
transition; current installers do not expose a third runtime. The legacy npm
package deepseek-tui is deprecated and is not republished. For migration
from v0.8.x legacy binary names, see docs/REBRAND.md.

Verify (recommended)

Download the checksum manifests from this Release and verify:

# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.9.5

Codewhale v0.9.5 consolidates the terminal application into one compiled
runtime while preserving the familiar codewhale and codew commands. It
also expands the managed Runtime API, makes session and Fleet work easier to
inspect and resume, and removes the hidden local continuation backstop that
could end productive work without a final assistant response.

Added

  • model = "auto" for prompt-based tier selection: When set, the
    dispatcher analyses the user's prompt before delegating to the TUI and
    selects deepseek-v4-pro for complex tasks or deepseek-v4-flash for simple
    tasks (PR #5257).
  • Runtime API controls for persistent goals, bounded memory inspection, MCP
    server and skill lifecycle management, and durable Fleet receipt evidence.
  • Append-only session-tree history with /tree, /branch, /fork, and
    /resume, plus /rc remote control and managed login.
  • A unified Fleet roster for built-in dispatch postures and a pinned indicator
    that keeps active background work visible above the composer.
  • Incremental MCP registry refreshes that return the local snapshot immediately
    and update it in the background.
  • Scout and Reviewer agents can use a bounded direct-command evidence shell for
    read-only workspace, Git, and GitHub inspection, and can keep private working
    notes in their own To-do while the durable transcript retains their evidence.

Changed

  • codewhale-cli now contains the terminal runtime directly. Release installers
    expose byte-identical codewhale and codew commands without a separate TUI
    executable. The v0.9.5 asset set alone retains deprecated
    codewhale-tui-* filenames as byte-identical compatibility copies so
    installed v0.9.4 clients can discover and complete this upgrade.
  • Startup release checks cache successful lookups for one hour. The updater
    downloads and verifies the primary runtime once, then refreshes any existing
    codew or legacy codewhale-tui command paths from the same bytes.
  • Headless codewhale exec runs and verifier benchmark rollouts no longer
    impose a 100-step default. --max-turns remains available as an explicit
    opt-in ceiling; Fleet workers retain their separately configured budget.
  • Goal token and time budgets are telemetry rather than default stop
    conditions, and automatic goal continuation is unlimited unless the user
    explicitly configures a continuation ceiling.
  • Command-palette and slash-completion shadowing now share one alias-aware
    discovery contract.
  • The website install guidance, localized product copy, navigation controls,
    social metadata, and Cloudflare build pipeline now describe and deploy the
    same one-runtime release contract.

Fixed

  • The hidden 20-step no-user-input backstop no longer ends productive turns.
    Tool results, queued steering, child completions, REPL feedback, and goal
    continuations can all reach the next provider step and a final assistant
    response; explicit user-configured limits and genuine stuck-loop guards remain.
  • Complete error details are directly inspectable after a failure instead of
    leaving the terminal with a clipped, unrecoverable error fragment.
  • A newly minted OAuth credential is adopted in the same provider-selection
    flow instead of requiring a second picker trip.
  • Fresh session titles can replace a stale cached New Session placeholder,
    unknown model context limits fail loudly, and release/source-install fallbacks
    no longer request binaries removed by the single-runtime conversion.

Contributors

  • Sh1Zuku (@SparkofSpike) fixed stale
    cached session titles that could pin the New Session placeholder.
  • Paulo Aboim Pinto (@aboimpinto) built the
    shared alias-aware command discovery contract and acceptance coverage.
  • Sun Zhenyuan (@bistack) contributed the
    background incremental MCP Registry refresh.
  • SKY ZHAO (@skyzhao1223) contributed
    prompt-based model = "auto" routing in PR #5257.

See CHANGELOG.md for full notes and docs/CHANGELOG_ARCHIVE.md for older releases.