Skip to content

Releases: EverMind-AI/Raven

Raven 0.2.3 (2026-09-27)

Choose a tag to compare

@github-actions github-actions released this 27 Sep 04:05
a9765e5

Raven 0.2.3 is a patch release with two things worth reading before you upgrade. Bare raven now opens the browser page, the way raven web does, and falls back to the terminal UI only where no browser can be opened; raven tui still opens the TUI outright. And the page's own update row now works on a normal raven web install and shows the download's progress, but only once the page is served by this release: a page served by 0.2.2 or earlier still refuses it, so this one upgrade goes through the command line as before (#806). No command, flag or config key is removed or renamed. Two smaller removals on the page: the file viewer no longer offers a download button, and HTML previews run their scripts by default instead of asking (#805).

Highlights

Upgrade from the page

  • The update row at the bottom of the sidebar upgrades a raven web install: the gateway hands the page its own graceful stop on every mount, exits cleanly on upgrade, and the helper waits for the supervisor, installs, and relaunches raven web --supervise on the same port with the same token and cookie, so the page reloads itself still signed in. It is refused, each with its own reason, while a turn, a sub-agent or a question waiting for an answer is running (including in an IM channel), and for a Raven started by hand with raven gateway or raven web --foreground, which has nothing to restart it (#806).

  • The page shows what is moving. The helper downloads the release itself so the bytes can be counted, then answers /upgrade/status on the page's own port with phase, bytes and rate while the old Raven is gone; the card measures the bar while bytes are counted and says when the new Raven is starting. A failed install is held for the page to read before the old version comes back, instead of relaunching it silently. The twenty-minute ceiling now counts silence, not the whole upgrade, so a slow download that is visibly moving is not given up on (#806).

  • The terminal raven upgrade prints each asset's size and the total before downloading, then a live progress line, so a large release on a slow link no longer reads as a stalled install. The downloaded wheels stay under ~/.raven/cache/upgrade/<version> (about 75 MB for a release with its engines); earlier versions' files are cleared (#806).

  • raven gateway refuses a half-written install the way raven serve already did: a gateway that starts inside an upgrade window waits it out and exits instead of serving the placeholder page until restarted by hand. The gateway also closes its websockets on shutdown, so raven web --stop with a page open no longer waits on the page's own socket (46 seconds down to 4 ms in the PR's run) (#806).

  • Bare raven opens the page, leaving the resident gateway that raven web always leaves. Where no browser can be opened it runs the TUI instead, decided before anything starts. raven web and raven tui are unchanged (#806).

Desk panes

  • Every desk pane has one header that names what is on screen. The file path bar, the task status line and the node card's back-and-title row fold into it: a glyph or a back chevron, the title, a muted facts line, then the controls that act on the object. A picked node reads as "task > node"; narrow panes drop the parent crumb and keep the facts on their own line. Dragging a pane by its title works again (#805).

  • Stop leaves the palette's task list and lives in the task pane header, shown only while the task or the picked node is running. The runtime has no per-node cancel for a graph, so on a graph node it stops the whole run, and its tooltip says so (#805).

  • The file viewer no longer offers a download or the binary note's save-a-copy link; the conversation's delivery cards keep theirs. HTML previews run their scripts by default under sandbox="allow-scripts", never allow-same-origin, so the page keeps an opaque origin, and the "preview does not run scripts" note and its run button are gone. Trade-off: a previewed page can now make network requests of its own without a click (#805).

Grok Build and GitHub Copilot as coding agents

  • Each connection problem the agent sheet asks about gets a named failure, and the command in each sentence is one the CLI's own help prints. A credential refusal says to run grok login or copilot login; a binary that is installed but not on the login PATH Raven launches with is named by its location (Homebrew's prefix, /usr/local/bin, ~/.local/bin) instead of being reported as missing; an invalid key, an expired sign-in, a model not served, no credit, an expired Copilot subscription, a rate limit, a network failure, an ACP server that did not start and a CLI too old to speak ACP are each their own sentence. A Copilot refusal that arrives as the assistant text of a finished turn is a failure, not a success (#792, #799).

Unattended turns and research

  • A question that an unattended turn could ask nobody is recorded instead of vanishing: a sub-agent ask_user or elicitation with no page subscribed, a question that gives up waiting for the conversation lock, and a host ask_user call whose answer comes back empty. The session stores a question_unanswered notice that a reopened session draws, and raven agent -m prints the questions after the reply. The model is still told to proceed, and the exit status is unchanged: a refusal is still the run that exits 3 (#807).

  • An interrupted research turn keeps the configured report structure. The tool-free synthesis is buffered, one format repair is requested when sections are missing, and only the selected reply is emitted; a failed synthesis produces a structured fallback, and wall-clock exhaustion gets an accurate time-limit fallback. The research flow's turn settings (wall-clock and retry budgets, ask labels, interrupted-reply guidance) now reach the loop (#808).

Experimental: the Curator

  • The repository gains experimental/, a first version of worker self-improvement: a Curator that shapes a Raven worker's harness (memory, planning, capability, action) from the task, the materials handed to it and feedback, at both levels of a harness-of-harnesses whose child agents are hosted over ACP. It is not in the wheel and raven/ does not import it; the design is in experimental/docs/design.md, and the README's self-evolution section now describes it (#802, #803).

Install

New install on Linux, macOS, or WSL2:

curl -fsSL https://raven.evermind.ai/install.sh | bash

New install on native Windows, in PowerShell:

irm https://raven.evermind.ai/install.ps1 | iex

Windows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:

irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iex

The installer puts uv, Node.js 22, Raven and its plugins in place, downloads the
browser runtime, installs or offers LibreOffice, and then finishes by opening
Raven in your browser. First-run setup happens on that page. The installer holds
the terminal while the page is up; press Ctrl-C to stop it, then start Raven
again with:

raven web

That keeps Raven running in the background and opens the page; raven web --stop
stops it. From this release on, bare raven does the same, and opens the TUI
only where no browser can be opened. Prefer the terminal? raven tui runs the
same first-run setup and opens the TUI, and raven onboard stays the explicit
way to reconfigure later. Set
RAVEN_MINIMAL=1 to skip the browser and LibreOffice downloads, or
RAVEN_NO_LAUNCH=1 to have the installer return without opening the page.

Upgrade

Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved. From this release on the update row at the bottom of the page's
sidebar does this too, but a page served by 0.2.2 or earlier refuses it, so for
this upgrade stop the page first, then upgrade:

raven web --stop
raven upgrade

On Linux and macOS raven upgrade runs the install in the foreground and
returns when it is done. On native Windows it hands the install to a separate
helper and returns at once; wait for the helper's completion message. Then
start Raven again:

raven web

raven upgrade installs the latest stable release together with the plugin
wheels it ships. It never picks up a pre-release unless this install has joined
the beta channel (a ~/.raven/beta.json that only the beta installer writes).
raven upgrade --check reports whether a newer release exists without
installing it. Editable source checkouts are never overwritten: raven upgrade
reports the checkout path and how far it is ahead of or behind origin/main,
and the remedy is git pull && ./install.sh in the checkout. Rerunning the
one-line installer also upgrades, and ends on the running page.

Release Status

  • Version: 0.2.3
  • Tag: v0.2.3
  • Stability: public preview patch
  • Assets: the raven wheel and source distribution, the three plugin wheels
    ...
Read more

Raven Technical Report v1 (2026-09-27)

Choose a tag to compare

@LivXue LivXue released this 27 Sep 10:47
a9765e5

Raven: The Harness of Harnesses for Composable Agentic Intelligence

EverMind AI, September 2026

As large language models advance, AI agents are moving beyond isolated, domain-specific tasks toward long-horizon, cross-domain workflows. This transition exposes two challenges: increasing harness complexity makes manual design difficult to scale, while tighter coupling to specific domains limits the generality of a single harness. The central question thus shifts from how to engineer a stronger harness for one domain to how to autonomously construct specialized harnesses, improve them through experience, and orchestrate them across domains. We introduce Raven, The Harness of Harnesses, an open-source multi-agent ecosystem that automatically constructs and evolves modular harnesses for specific models and domains, treating each executable model–harness pair as a composable unit of intelligence. To support an All-Domain Collaboration Network, its Host Agent decomposes goals, matches subtasks to specialized agents, coordinates execution dependencies, and integrates results, while a host archive and EverOS preserve experience across tasks and Skill Forge makes that experience available as reusable procedures. Our theory establishes sufficient conditions for such composition to expand reliable task coverage beyond that of the available individual agents under a shared resource budget. On complex and long-horizon tasks, Raven significantly outperforms the state-of-the-art agent systems, pushing the frontier of composable agentic intelligence.

  • PDF: technical-report.pdf, 82 pages, SHA-256 14832f50de158ca431d63acf5dd06dfcad05c54a70a8607a50ecd79170fff831
  • The tech-report-v1 tag points at the commit of Raven v0.2.3, the latest software release when this report was published.

This is a documentation release, not a software release. To install Raven, use the latest release.

@techreport{evermind2026raven,
  title       = {{Raven: The Harness of Harnesses for Composable Agentic Intelligence}},
  author      = {{EverMind AI}},
  institution = {EverMind AI},
  year        = {2026},
  month       = sep,
  url         = {https://github.com/EverMind-AI/Raven/releases/tag/tech-report-v1}
}

Raven 0.2.2 (2026-09-25)

Choose a tag to compare

@github-actions github-actions released this 25 Sep 12:02
f49359e

Raven 0.2.2 is a patch release with one thing worth reading before you upgrade: memory runs on native Windows now. No command, flag or config key is removed or renamed, and no configured default changes. The memory plugin's EverOS pin moves from 1.2.3 to 1.4.1, which runs on Windows without WSL, so the platform gate that made memory unavailable there is gone. Two guards found while verifying against a copy of a real 1.2.x store come with it: an embedding model narrower than the memory index is refused rather than left to answer 500 on every store and search, and an upgrade no longer leaves the old server answering on the port (#791).

Highlights

Memory on native Windows

  • The platform gate is gone. everos_platform_note and its five call sites, the UNSUPPORTED service state, the import scan's refusal and the wizard's WSL notice are removed, and Raven looks for everos.exe on Windows. Spawning, probing and reusing the server were already portable; identifying and stopping one was not. The command line now comes from WMI through PowerShell, the listening port from the TCP table, walking the launcher's descendants to the interpreter that actually holds the socket.

  • The server is spawned in a process group of its own, so a Ctrl-C at the gateway's console does not take it down with it, and stopped with Ctrl-Break, which uvicorn takes as a shutdown; one that ignores it for ten seconds is terminated as before. Because Windows cannot replace a running executable, raven upgrade stops whatever still runs from under the tool environment before it installs -- the memory server outlives the gateway by design, and without that stop uv failed on Scripts\everos.exe.

Two guards for the memory store

  • An embedding model narrower than the 1024-wide memory index is refused where it is pinned, and withheld from the server it would otherwise have started. A 768-dimension model saved from the settings page had left every memory store and search answering 500 about a mismatched width, with nothing on the page saying why. EverOS then runs keyword recall and keeps storing, and the notice names the model and its width. A probe that cannot reach the provider is not a verdict: the pin is written and a warning logged.

  • A running EverOS whose version no longer matches the installed one is replaced rather than reused, through the same precheck, stop and spawn chain a rotated credential takes. An upgrade used to leave the old server serving until something unrelated restarted it. A root you manage yourself is never touched. And a gateway that finds nothing listening and no lock held starts the server again, at most once every thirty seconds, so a server that goes away no longer leaves that gateway without memory until you restart it by hand.

Recall and the memory page

  • Recall on the Cases and Know-how tracks searches by vector when no reranker is configured, instead of asking for an LLM rerank that the four-second recall budget can never wait out.

  • The memory page reads the /api/v2 routes, asks /health before a search the way the chat adapter does, and shows the server's own sentence on a refusal. A recalled profile is drawn as lines rather than a namespace(...) repr, a tool-call-only row stores empty content rather than the string "None", an empty query asks nothing, and top_k stays within 1..100.

  • The first-run wizard accepts an embedding model wider than 1024 (EverOS keeps the first 1024, as the settings page already allowed) and re-prompts on a refusal instead of showing a traceback.

Under the wire

  • Every request body the plugin and the memory page send is validated against EverOS 1.4.1's own request models in the suite, so a schema move on the next upgrade fails a test rather than a gateway log. The upgrade is recorded in docs/memory-plugin-architecture.md section 7.4.

Install

New install on Linux, macOS, or WSL2:

curl -fsSL https://raven.evermind.ai/install.sh | bash

New install on native Windows, in PowerShell:

irm https://raven.evermind.ai/install.ps1 | iex

Windows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:

irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iex

The installer puts uv, Node.js 22, Raven and its plugins in place, downloads the
browser runtime, installs or offers LibreOffice, and then finishes by opening
Raven in your browser. First-run setup happens on that page. The installer holds
the terminal while the page is up; press Ctrl-C to stop it, then start Raven
again with:

raven web

That keeps Raven running in the background and opens the page; raven web --stop
stops it. Prefer the terminal? raven runs the same first-run setup and opens
the TUI, and raven onboard stays the explicit way to reconfigure later. Set
RAVEN_MINIMAL=1 to skip the browser and LibreOffice downloads, or
RAVEN_NO_LAUNCH=1 to have the installer return without opening the page.

Upgrade

Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved. Stop the page first, then upgrade:

raven web --stop
raven upgrade

On Linux and macOS raven upgrade runs the install in the foreground and
returns when it is done. On native Windows it hands the install to a separate
helper and returns at once; wait for the helper's completion message. Then
start Raven again:

raven web

raven upgrade installs the latest stable release together with the plugin
wheels it ships. It never picks up a pre-release unless this install has joined
the beta channel (a ~/.raven/beta.json that only the beta installer writes).
raven upgrade --check reports whether a newer release exists without
installing it. Editable source checkouts are never overwritten: raven upgrade
reports the checkout path and how far it is ahead of or behind origin/main,
and the remedy is git pull && ./install.sh in the checkout. Rerunning the
one-line installer also upgrades, and ends on the running page.

Release Status

  • Version: 0.2.2
  • Tag: v0.2.2
  • Stability: public preview patch
  • Assets: the raven wheel and source distribution, the three plugin wheels
    (everos_memory, design_engine, ppt_engine), the locked constraints file
    raven-constraints.txt, and the plugin list raven-plugins.txt

Notes

  • Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
  • PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.

Raven 0.2.1 (2026-09-24)

Choose a tag to compare

@github-actions github-actions released this 24 Sep 14:25
e176941

Raven 0.2.1 is a patch release: no command, flag or config key is removed or renamed and no configured default changes, but three behaviour changes are worth reading before you upgrade. The web first-run wizard now asks only for a model and, optionally, a search tool; its agents and data-sync steps are held back until they are ready, so a first run no longer offers to connect local agents, and until the step returns an import runs from raven import on the CLI (#784). exec on this computer now refuses a typed ssh to a machine the connection registry knows and names the two paths meant for it, while scp and rsync are untouched and an unreadable registry refuses nothing (#552). And a permissions.tools deny rule now stops the program it names however the command runs it, so bash -c, env, sudo, xargs, find -exec, a $(...) substitution or a redirection no longer walk past it (#783). The rest of the release is the agent connector (what a refused connect says, and where it is drawn), a round of web page fixes, and a -P guard that keeps a source checkout off the engine's sys.path.

Highlights

Connecting coding agents

  • A failed connect or test is now said under the agent rather than instead of it. Every card keeps one fixed shape with a slot that always speaks -- a grey word for the row's state, a single-line strip naming what failed and a short reason read off the remedy, amber while a write is in flight -- and the sheet keeps its 520x500 box, with the why and the how as a note at the top of the body: a title per remedy kind, the fix, the command on its own line, and the agent's own sentence folded under it. The card no longer carries the raw English sentence a server returned (#754, #785).

  • A refused Qwen Code connect names the fix and the command. A provider status the agent reports is classified (401/unset credential, 404 for a model it will not serve, 402 for credit, 429 for a rate limit, an unreachable provider, a launch that quit, a binary too old for --acp), and the sheet shows the fix as two numbered steps: run qwen, then type /auth there. /auth, not /model -- /model only picks among the models already registered in ~/.qwen/settings.json, and qwen 0.24.4's own OpenRouter preset registers two free models that OpenRouter has since withdrawn (#779, #786).

  • A Qwen Code started on a Node.js that is too old says so. Qwen Code runs on whichever node comes first on its launch PATH, and on 18.x it dies at import with a SyntaxError that names no version. Raven now resolves the interpreter from the agent's shebang, reads the floor from the agent's own package.json (>=22.0.0), and names both versions, with nvm install 22 && nvm alias default 22 or brew upgrade node only where the installer shows in the path (#786).

  • A refused Kimi Code connect says why instead of always asking for a sign-in. Kimi Code reports a session it cannot start as a bare Authentication required, so Raven asks it once more the way a reader in a terminal would (kimi -p, in the launch's own environment, capped at 20 s), checks a config it cannot parse with kimi doctor config, and reads a signed-in account's own plan limits (a spent usage window as 403, a model above the tier as 401, an unverifiable membership as 402) before the status (#781).

  • A missing npx is answered with Node.js, not with the agent's own npm installer, and a connect gives a first download time to finish: the start gets the row's readyTimeoutMs (120000 ms on the npx presets) with the answer keeping its 60 s cap, and an npx fetch that failed is named by npm's own error-code line rather than reported as an agent that did not answer (#754).

  • "Check again" finds an agent installed after the gateway started. The login-shell environment is captured once per process, so an installer's new PATH line was invisible until a restart; the sheet's re-check now asks subagents.list for a fresh capture (refresh_login_env, default false, so no other listing pays for a login-shell run), and the connect that follows launches on the PATH the probe found (#768).

  • A row that has just connected stops wearing a stale warning. The writes a server answers by running the agent now ask for the probe on their follow-up read instead of carrying the previous verdict over it, the card's dot and the sheet's status line read one ranked verdict, and a write refused while a later one landed repaints from a fresh listing instead of from the rows it started with (#773, #769). The TUI's /subagents overlay gets the same fix for its ! glyph (#774).

  • An API key already stored for an agent can be replaced from the sheet. An openai row whose stored key the endpoint rejects used to offer Connect, be refused with "change the key and press Retry", and have no field to change it in; the field is now drawn at every stage but live and stale, a typed key turns the press into Connect, and saving a key on a row that is off is followed by the switch that proves it (#788).

The web page

  • The first-run wizard draws its step before the data lands. The model step used to hold a "Loading..." line for 6.4 s on a warm install while the whole settings payload arrived; it now draws its real (empty) cards at 148 ms and fills in behind them (#771).

  • Task-board DAG edges no longer hide under the boxes they pass. Layout moves to @dagrejs/dagre for in-layer ordering and edge routing: an edge that skips a layer bends through the gap, edges meeting one face of a box get their own ports, and a root that feeds only a deep node stays on the first layer (#761).

  • Running tasks get a stop button in the floating tasks list, so a stuck sub-agent can be stopped without opening its read-only context view. It reuses the existing calls -- subagent.cancel_instance for a spawn, subagent.interrupt for a task graph (#764).

  • The file bar gains a download button for every kind, so a file read on a remote serve can be saved to the reader's own machine; a file this session delivered is saved from its delivery, anything else from the route the viewer already reads it through (#770). In the same bar the rendered/source pair is now offered only on md, svg, html, csv and json, where the two positions actually differ -- a PDF no longer fetches its whole body to draw it as numbered lines -- and the new-tab, download and folder buttons form one group (#778).

  • A spawn's task row opens the task pane however soon it is clicked. A click landing before the tasks store had filed the run used to open the agents panel's instance window instead; the opener now reads that one row with tasks.list and retries while the record is still being written, falling back to the tasks list (#772).

  • Settings pages get real empty states that tell "nothing here" apart from "service down": usage, archive, plugins, skills, providers, schedules, channels and memory share one shape (a mark, a title, one line, at most one control), a failed memory read takes the whole frame with a retry, and only rows with a panel to expand look clickable. The memory pager no longer slides under the pointer on a page turn (#775). Reopening the dialog no longer swallows the first click either: a reload that answers the same values leaves the page mounted instead of rebuilding every control about 670 ms in (#782).

Runtime, tools and providers

  • The machine registry has one reader and one writer, and the coding agent can add a machine. A sub-agent reads the owner's registry in RAVEN_HOME rather than the empty state directory beside its rendered config, a host started with --config keeps the list beside that config, and ops_connection_add is a trunk tool served on tools.connectionAdd (off by default; on in raven-code and raven-oncall). It probes a machine the way the owner's own terminal would resolve it (ssh -G, each candidate key offered on its own) and writes nothing until the machine answers; raven ops connection add calls the same functions (#690).

  • A user exec deny rule stops its program however the command runs it. Deny rules are asked first, about every command the string can be seen to run: shell wrappers and runners, $(...) and backtick substitutions read off the raw text, a keyword in front of a command, env -S, find -exec, a redirection, and the program compared by its bare name so a path prefix or a Windows .exe suffix does not hide it. Allow and ask rules are unchanged, and a heredoc body no shell reads is dropped first (#783).

  • DeepSeek's shown API base is now https://api.deepseek.com, not https://api.deepseek.com/beta, so saving a working key stops answering Couldn't verify (http_404), saved anyway; `/b...

Read more

Raven 0.2.0 (2026-09-23)

Choose a tag to compare

@github-actions github-actions released this 23 Sep 21:34
92281ec

Raven 0.2.0 is the first minor release since 0.1.13, and much of what it carries is new to a 0.1.13 install: a Web UI that raven web serves in the browser (rail, composer, transcript, settings dialog, Agent Connector and a desk with file, agent and task panes), permission modes at the tool-dispatch door, four built-in agents under agents/, the playbook engine, the ACP and A2A surfaces, the three plugin wheels the release publishes, and a Dockerfile with a Compose file that run the whole of it in one container. It also retires and moves several things. The built-in deep_research tool goes, with its raven deep-research command group and tools.deepResearch config section, in favour of the research agents; the tracing module's begin_attempt / end_attempt / current_attempt functions go with the span-level attempt.id, attempts now being grouped after recording with raven trajectory merge; and the installers finish by opening Raven in the browser and holding the terminal on raven web --foreground (export RAVEN_NO_LAUNCH=1 before a non-interactive install to exit as before). Conversations are gated by a new permission mode, smart by default; a turn the model loop gives up on now fails instead of answering and raven agent -m exits 3 when an action needed an approval nobody could give; a streamed model call that fails before any reply text is retried on a new ladder (agents.defaults.llmErrorRetryDelays, default 15/30/60 s) where 0.1.13 answered with the first failure, and one that fails after output is retried only where agents.defaults.llmRetryAfterOutput says so; the sub-agent memory block, the EverOS role settings and the retired embedding shape move, most of them with load-time migrations, and tools.toolSearch.enabled is now on by default. On the page, a four-step wizard and a cold-start import replace the terminal first run; the frontend follows the Figma design, with a settings dialog that absorbs skills, plugins, schedules, channels and memory, an Agent Connector, a desk task pane, a composer that starts a conversation in a folder of your choosing and sends a message into a running turn, and typeset mathematics. The provider catalogue grows from 21 to 55, Raven speaks Agent2Agent 1.0, the model can drive the shared browser, playbooks include a many-round stint mode, WhatsApp and WeChat pair from Settings > Channels, raven trajectory gets an interactive browser and a bug-report flow, and a bilingual documentation site takes over the README's reference sections.

Highlights

  • Breaking: The built-in deep_research tool is retired: the raven deep-research command group, the MiroThinker HTTP tool and its unconfigured stand-in, the tools.deepResearch config section, the settings row with its MiroThinker key panel and the deep-research entry in the ACP command menu are all gone. Research keeps two surfaces, the Raven-Research agent and the MiroThinker sub-agent preset. An existing config loses tools.deepResearch / tools.deep_research through a load-time migration that prints one notice (#717)
  • Breaking: install.sh and install.ps1 finish by holding the terminal open on raven web --foreground, which opens the browser, instead of exiting after a hint: after probing raven web --help they run raven web --stop and then raven web --foreground, so a non-interactive install -- a CI job, a Dockerfile RUN step, any piped install with no TTY to Ctrl-C -- hangs unless RAVEN_NO_LAUNCH=1 is exported first, which restores the exit-after-install behaviour. A piped install against a release without that subcommand ends on raven itself instead of exiting 2 with No such command 'web' (#476, #588)
  • Breaking: Tool dispatch is gated. Permission modes are new in 0.2.0 -- permissions.mode takes ask, smart or full and defaults to "smart" -- so a turn now stops and asks where 0.1.13 ran straight through. Smart mode states what ordinary work is -- reading and writing files in the workspace, building, testing, formatting, installing project dependencies with a package manager, committing, pushing a branch -- and escalates by effect: sending files, secrets or conversation content off the machine, touching credentials and keys, changing shell startup files, system services or permission settings, deleting user data outside the workspace, force-pushing or rewriting shared history, dropping databases. The reviewer takes a verdict only from its own report_permission_review call; a timeout, a raising provider or a prose answer escalates to the human (#585, #631, #645)
  • Breaking: Failures fail instead of answering. A model call the loop gives up on -- a first-byte or idle timeout, a stream cut before its terminal chunk, an error from the non-streaming fallback, or an exhausted empty-response recovery -- raises AnswerlessTurnError: the turn is saved with status failed and the error's own words as its reason, the page and the TUI draw "Turn failed - ", raven agent -m no longer exits 0 with the explanation as its reply, a node of a run_subagent_dag graph is recorded as failed rather than counted as finished, and a cron job record carries the turn's own failure sentence rather than a generic one (#666, #705, #675). raven agent -m lists the actions it refused after the reply and exits 3 (EXIT_ACTIONS_REFUSED) when an action needed an approval nobody could give -- a refusal from a deny rule is listed but leaves the status at 0, and --permission-mode full restores a clean exit -- and raven trajectory run with no subcommand on a non-interactive stream prints "Re-run with: raven trajectory list" and exits 2 (#708, #370)
  • Breaking: Config keys and defaults move, most of them with a load-time migration. A sub-agent's memory block is spelled memory -- subagents.agents[].memory in config.json, memory in an agent folder's subagent.json -- and a row still using the old everos spelling keeps working, read under the new name (#414); EverOS's four roles (llm, embedding, rerank, multimodal) are configured in Raven's own config as a model pin plus the vendor serving it, never a credential, reach EverOS as EVEROS_<ROLE>__* environment variables on every spawn, and Raven now writes only [api] into everos.toml (#614); a config still holding the retired embedding endpoint shape is adopted onto the configured provider that answers at that address, or dropped with the address named in the log, instead of breaking every command that reads the extension blocks (#453); a sub-agent row still carrying the stock command of a retired Codex or Claude Code adapter pin is moved onto the current one (#752). tools.toolSearch.enabled now defaults to true: at or below tools.toolSearch.compactionThreshold (default 50) live tools nothing changes; above it most tool schemas are withheld and reached through tool_search and tool_call, a pair reserved from tools.disabledTools (#616). A model no catalogue knows falls back to 200,000 context tokens instead of 65,536, logged once with the hint to pin agents.defaults.contextWindowTokens (#634)
  • Breaking: trace.begin_attempt, trace.end_attempt and trace.current_attempt (raven.tracing.trace, shipped in v0.1.13) and the span-level attempt.id attribute are removed, with no shim. Group attempts after recording instead, with merge_attempts() from raven.trajectory or raven trajectory merge on the CLI; existing logs carrying a span-level attempt.id stay addressable through the reader fallback and need no data migration (#370)
  • Raven has a Web UI. raven web starts a supervisor and a resident gateway that serve a page in your browser -- rail, composer, transcript, settings dialog, Agent Connector and a desk with file, agent and task panes -- from ui-web/dist or the wheel's packaged copy, raven web --stop ends them, and the installers finish by opening the page. 0.1.13 shipped no served page and no web command; the TUI stays, and bare raven still opens it the way raven tui does. Also new since 0.1.13 are permission modes at the tool-dispatch door, the four built-in agents under agents/ (raven-code, raven-design, raven-oncall, raven-research; raven-ppt sits beside them as a hidden engine that Raven-Design routes .pptx work to, not a fifth agent on the roster), the playbook engine, the ACP and A2A surfaces, the three plugin wheels the release publishes, and nine commands or command groups: raven a2a, raven acp, raven agents, raven mcp, raven ops, raven playbook, raven plugin, raven serve and raven web (#476, #588, #612)
  • The settings dialog absorbs Skills, Plugins, schedules, channels and memory, each drawn in a shared two-pane frame; there is no separate Skills, Plugins, Knowledge or Playbooks page, and Knowledge has no page, CLI command or agent tool at all. The memory section has no delete control and the RPC has no `memor...
Read more

Raven 0.1.13 (2026-08-25)

Choose a tag to compare

@github-actions github-actions released this 25 Aug 03:30
9da50ac

A patch release that binds the model to the conversation instead of the process, adds raven trajectory for turning an agent failure into a deterministic regression test, and stops one failed MCP server from cancelling the whole turn. TUI input is more responsive and its clipboard path is honest about which mechanism it used, ask_user keeps the contract its schema advertises, and raven doctor finally says which tool capabilities this install actually has.

Highlights

  • The model follows the conversation, not the process: each session keeps its own choice, switching in one session no longer moves the others, and every turn binds model, provider credential, and context window as one group so a switched model cannot run against a stale credential or window. Concurrent sessions can use different models, and a resumed session keeps the one it had (#284, #349)
  • A failed MCP server no longer takes the turn down with it. A transport or handshake failure collapses into that one server's connection error instead of unwinding the caller as a task-group exception, so the remaining servers still register and the turn reaches the model loop (#365)
  • raven trajectory turns a single agent failure into a permanent regression: record, judge, label, pin, save, and report, with deterministic replay off recorded model responses and tool results rather than live tools. A failing trajectory minimizes into a redacted cassette that pytest can run, and reports strip config secrets, environment credentials, and sensitive paths (#362)
  • web_search is no longer registered when no key resolves, so the model is not offered a tool it cannot run and its setup error stops reaching whoever is in the chat -- the same gate applies to the sub-agent surface. The check asks the tool, so an install that only exports SERPER_API_KEY still counts as configured (#312)
  • raven doctor grows a Tool capabilities section listing all five capabilities configured or not, ordered by how much setup each needs, naming the config key that holds the credential and distinguishing a genuinely reused credential from a missing one. An unconfigured capability does not move the exit code (#312)
  • ask_user keeps one deadline for a whole batch instead of granting each question a fresh timeout, drops the interaction capabilities no client ever implemented, and caps a call at four questions. Duplicate questions, invalid options, and undeliverable prompts fail fast with a specific error. The TUI shows batch progress, the recommended option, and the remaining time, and picking Other by number now opens free-text entry (#354)
  • TUI input keeps up: a coalesced run of bytes over SSH, under tmux, on a busy event loop, or from an IME sending several characters at once is read as typing rather than misclassified as a paste and held in debounce. Continuous input, CJK, and wide characters take the fast echo path (#355)
  • Select-to-copy works on macOS, Linux, and Windows, and the status line names the path actually used -- native, tmux, or OSC 52 -- instead of reporting success the clipboard never received (#360)
  • The full-screen cover drops after the first turn, and user input renders as a filled block so turn boundaries are legible in a long session (#361)
  • Config migration notices move to stderr, so doctor --json and import --json keep stdout parseable as JSON. A new config saves only the values you actually changed instead of freezing the whole default set, so later default upgrades still reach you (#346)
  • An invalid EverOS memory identity names the config key and the legal format instead of presenting itself as a service failure or a bare traceback (#350)
  • Skill Hub truncates a long catalog query at the gateway's real byte limit, so a non-ASCII query no longer loses skill retrieval silently (#348)
  • EverOS moves from 1.2.1 to 1.2.3, with no Raven adapter change and no data migration (#351)

Install

New install on Linux, macOS, or WSL2:

curl -fsSL https://raven.evermind.ai/install.sh | bash

New install on native Windows, in PowerShell:

irm https://raven.evermind.ai/install.ps1 | iex

Windows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:

irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iex

Open a new terminal, then run:

raven

That sets you up on first run and then opens the TUI. raven onboard stays
the explicit way to reconfigure later.

Upgrade

Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved:

raven upgrade

raven upgrade installs the latest stable release, so it does not pick up a
pre-release; rerun the installer above for that. Editable source checkouts are
never overwritten -- pull the checkout and rerun its development setup. On
native Windows the upgrade finishes in an external helper; wait for its
completion message before running Raven again.

Release Status

  • Version: 0.1.13
  • Tag: v0.1.13
  • Stability: public preview patch
  • Assets: wheel and source distribution attached to this release

Notes

  • Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
  • PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.

Raven 0.1.12 (2026-08-18)

Choose a tag to compare

@github-actions github-actions released this 18 Aug 03:06
dd82f52

A patch release that makes cron reminders fire where they were created, puts skill hub installs behind a safety policy gate, and lifts the stale 64k context window off upgraded installs, plus fixes to first run, provider auth errors, and the one-line installer. Interactive chat is raven tui now: bare raven agent no longer opens a REPL.

Highlights

  • Breaking: bare raven agent no longer hosts a REPL. It prints a pointer to raven tui and exits 2, while raven agent -m "..." keeps working for scripted one-shot turns. The cli cron channel retires with it, and jobs stored with channel="cli" migrate to tui at load (#329)
  • Breaking: --wait-skill-extract and --flush-skill-buffer are gone. Both promised a boundary-detection workflow that has been a no-op since extraction moved to the memory backend, so a script still passing them now fails on an unknown option (#334)
  • Cron reminders fire at their origin: a job is claimed and delivered only by the runner that owns its creation-time channel binding, ending the case where a reminder created in the CLI never fired while a headless gateway was running (#326)
  • A recurring reminder nobody engages with disables itself once it crosses a per-job fire limit (default 12), and cron list / cron get surface the live counter (#333)
  • Reminders that lapsed while the TUI was closed are shown at startup as one "missed N reminders" block, instead of a warning log the user never sees (#332)
  • Skill hub installs go through a single policy gate: safety scores are actually checked, every install is recorded to disk, and skillForge.blocklist refuses a named skill everywhere (#327)
  • skillForge.autoInstall picks the consent mode (auto / prompt / off, default auto), and skill list gains an Installed column plus a [blocked] marker (#328)
  • An install upgraded from 0.1.10 or earlier is no longer capped at a 64k context window by the contextWindowTokens: 65536 those builds wrote into config.json. The stale pin is dropped once at config load, with a one-line notice, and a value you set yourself is never second-guessed (#341)
  • Model output is no longer capped at 8192 tokens by a shadowed default, and a truncated response is reported as truncation instead of nudging the model into resending the same oversized call (#308)
  • Provider authentication failures print classified guidance and exit non-zero, instead of dumping a raw exception as if it were the agent's reply and exiting 0 (#330)
  • First run is one command again: the installers send a fresh machine to bare raven, a zero-provider install no longer names a vendor you never chose, and the model the wizard recommends is priced again instead of reporting an unknown cost (#342)
  • Choosing to run on the host rather than the sandbox now warns that injected commands would execute with full host privileges, and asks for an explicit confirmation that defaults to No (#321)
  • channels enable stops exiting 0 on missing credentials, and enabling a channel whose allow_from resolves to * (anyone who can message it can command the agent on this host) now requires an acknowledgement (#323)
  • Sessions are auto-titled from the first user message (capped at 40 characters), and sessions create persists immediately so create / list / delete round-trips work (#324)
  • EverOS memory ownership is a recorded decision instead of a per-call guess: onboarding asks once whether Raven runs the server, a root you run yourself is left alone, and a memory failure no longer stalls the session for up to a minute (#310, #343)
  • raven status lists only configured providers and folds the rest into one line, every turn ends with a usage summary, and raven doctor reports the config as valid / invalid / missing and exits 1 on a broken one (#331, #322)
  • The identity block carries the gateway-resolved routed model id, so the agent stops answering "which model are you" from pretraining memory (#325)
  • The tracing dashboard no longer reuses a viewer whose UI files were deleted, which served an unstyled page that never connected (#316)
  • Running the one-line installer from inside a clone no longer silently installs that working tree as an editable checkout instead of the released wheel; an editable install is now an explicit RAVEN_LOCAL_SRC opt-in (#294)
  • When the unauthenticated GitHub API quota is spent, raven upgrade and the installers fall back to the release page to resolve the latest version, and the launch-time update check no longer spends an API request at all (#299)
  • Skill retrieval fusion is retuned: the RRF damping constant is configurable (rrf_k) and the source weights are rebalanced (#290)

Install

New install on Linux, macOS, or WSL2:

curl -fsSL https://raven.evermind.ai/install.sh | bash

New install on native Windows, in PowerShell:

irm https://raven.evermind.ai/install.ps1 | iex

Windows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:

irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iex

Open a new terminal, then run:

raven

That sets you up on first run and then opens the TUI. raven onboard stays
the explicit way to reconfigure later.

Upgrade

Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved:

raven upgrade

raven upgrade installs the latest stable release, so it does not pick up a
pre-release; rerun the installer above for that. Editable source checkouts are
never overwritten -- pull the checkout and rerun its development setup. On
native Windows the upgrade finishes in an external helper; wait for its
completion message before running Raven again.

Release Status

  • Version: 0.1.12
  • Tag: v0.1.12
  • Stability: public preview patch
  • Assets: wheel and source distribution attached to this release

Notes

  • Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
  • PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.

Raven 0.1.11 (2026-08-10)

Choose a tag to compare

@github-actions github-actions released this 10 Aug 16:00
9e2079b

Endpoint failover for provider requests, image attachments for vision-capable models, and a hermes import source, plus fixes to live model switching, OAuth sign-in, and media understanding.

Highlights

  • Provider requests now fail over across endpoints instead of dying on the first unreachable one (#287)
  • User attachments are sent to the model when it supports vision (#285)
  • Hermes joins the cold-start import sources (#264)
  • Sign in to an OAuth provider directly from /model (#279)
  • Switching models mid-session now reaches every provider holder, not just the agent loop (#282)
  • understand_media parsing works again against the current everos parser (#273)
  • Ctrl+C means the same thing across all credential prompts (#266)

Install

New install on Linux, macOS, or WSL2:

curl -fsSL https://raven.evermind.ai/install.sh | bash

New install on native Windows, in PowerShell:

irm https://raven.evermind.ai/install.ps1 | iex

Windows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:

irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iex

Open a new terminal, then run:

raven onboard

Upgrade

Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved:

raven upgrade

raven upgrade installs the latest stable release, so it does not pick up a
pre-release; rerun the installer above for that. Editable source checkouts are
never overwritten -- pull the checkout and rerun its development setup. On
native Windows the upgrade finishes in an external helper; wait for its
completion message before running Raven again.

Release Status

  • Version: 0.1.11
  • Tag: v0.1.11
  • Stability: public preview patch
  • Assets: wheel and source distribution attached to this release

Notes

  • Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
  • PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.

Raven 0.1.10 (2026-07-31)

Choose a tag to compare

@github-actions github-actions released this 31 Jul 17:48
52c76a5

A patch release that opens provider support up to everything LiteLLM routes to, adds an approval flow for protected shell commands, and reworks the TUI transcript into episodes.

Highlights

  • Every provider LiteLLM can route to is now configurable from the onboarding picker: 21 registered providers in four groups (key, OAuth, local, fallback), plus a searchable step for vendors Raven carries no spec for (#252). LiteLLM is now the single execution layer behind them, including knn routing (#249).
  • /model lists the providers that can actually serve a model first, ending with one row that opens the rest, instead of twenty-one rows to scroll (#260).
  • Protected shell commands go through a runtime-owned approval flow: recognized deletion commands ask for one-shot approval in interactive TUI turns, and fail closed for non-interactive origins, expiry, disconnects, and parse failures (#239).
  • The TUI transcript reads as collapsible episodes, one per model call, each holding its reasoning, narration, and tool rows (#217).
  • read_file can read images, and image tokens are now estimated from the image instead of the length of its base64 data URI (#251).
  • MiniMax Token Plan OAuth for both Global and CN regions, with device-flow login and proactive token refresh (#209).
  • The TUI status bar nudges raven upgrade when the running version is behind (#220).
  • A static read no longer starts a login: resolving a model's metadata with no token file on disk used to print device codes and block for minutes (#255).
  • /model <bare-id> no longer keeps the previously pinned provider, which could send one vendor's key to another (#256).
  • Back on a required EverOS memory role no longer drops back into the provider picker forever (#258).
  • Switching provider after a failed verification no longer carries the credential flags into the next pass (#253).
  • raven[sandbox] installs on Windows again; boxlite is marked posix-only and the unused retrieval extra is gone (#226).

Install

New install on Linux, macOS, or WSL2:

curl -fsSL https://raven.evermind.ai/install.sh | bash

New install on native Windows, in PowerShell:

irm https://raven.evermind.ai/install.ps1 | iex

Windows PowerShell 5.1 (the version built into Windows) rejects that URL with
Permanent Redirect; use the direct one instead:

irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iex

Open a new terminal, then run:

raven onboard

Upgrade

Already running Raven? Upgrade in place -- configuration, sessions, and memory
are preserved:

raven upgrade

raven upgrade installs the latest stable release, so it does not pick up a
pre-release; rerun the installer above for that. Editable source checkouts are
never overwritten -- pull the checkout and rerun its development setup. On
native Windows the upgrade finishes in an external helper; wait for its
completion message before running Raven again.

Release Status

  • Version: 0.1.10
  • Tag: v0.1.10
  • Stability: public preview patch
  • Assets: wheel and source distribution attached to this release

Notes

  • Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
  • PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.

Raven 0.1.9 (2026-07-23)

Choose a tag to compare

@github-actions github-actions released this 23 Jul 14:49
85c7a5b

A patch release with reliability and CLI/TUI polish fixes.

Highlights

  • Add a configurable llm_call_timeout so a stalled LLM call is bounded instead of hanging a turn indefinitely (#204).
  • Make raven onboard readable on light-background terminals (#199).
  • Pick the first Node >= 22 found across all PATH entries, fixing setup on machines with multiple Node versions (#189).
  • Surface the real turn-failure detail in the TUI instead of just an error code (#190).
  • Unify commit and PR length limits to a single header-max-length rule (#196).

Install

curl -fsSL https://raven.evermind.ai/install.sh | bash

Then reload your shell and run:

raven onboard

Release Status

  • Version: 0.1.9
  • Tag: v0.1.9
  • Stability: public preview patch
  • Assets: wheel and source distribution attached to this release

Notes

  • Raven is still pre-1.0; CLI surfaces, plugin contracts, and runtime internals may continue to evolve.
  • PyPI publishing is not enabled yet; the supported public install path uses the GitHub Release wheel asset.