Skip to content

Releases: hamedsj/PandoraBox

1.4.1

Choose a tag to compare

@hamedsj hamedsj released this 16 Aug 23:28

PandoraBox 1.4.1 — a patch focused on replay reliability, transparent body decompression, and CLI power tools for large traffic sets.

Fixed

  • Replay no longer drops the request body. A replayed POST's body, Content-Length, and rewind source are pinned to the actual bytes right before send, so the body is never omitted or mismatched.

Changed

  • Transparent body decompression for Python middleware, Match & Replace, and Flows. Response bodies are decompressed (gzip/brotli/zstd/deflate) before res-body rules, middleware, and flow process steps see them, then re-compressed to the original Content-Encoding on the way out — so scripts read plaintext with no manual gzip handling. This also fixes res-body match & replace rules that silently never matched compressed responses.

Added

  • pandorabox traffic search <term> — grep decoded request/response bodies across all traffic (--in, --regex, --content-type).
  • pandorabox traffic get <id> --body response now auto-decompresses (--raw-body for wire bytes), --save-to <file> writes a body to disk, --max-bytes 0 disables the limit, and truncated output shows a size marker.
  • pandorabox sitemap export --content-type <type> filters exports (incl. per-file mode) by response Content-Type.
  • pandorabox matchreplace test <id> — dry-run rules against a captured request (per-rule match/no-match/disabled + why).
  • pandorabox middleware test --code-file <f> --request-id <id> — dry-run a middleware script, surfacing tracebacks and before/after.

See the CHANGELOG for details.

Downloads

Platform File
macOS (Apple Silicon) PandoraBox-1.4.1-arm64.dmg / PandoraBox-1.4.1-arm64-mac.zip
macOS (Intel) PandoraBox-1.4.1.dmg / PandoraBox-1.4.1-mac.zip
Windows (x64) PandoraBox.Setup.1.4.1.exe
Linux (x64) PandoraBox-1.4.1.AppImage

Builds are ad-hoc signed (not notarized) — on first launch macOS may need right-click → Open. Verify downloads against SHA256SUMS. As with 1.4.0, a Debian .deb is not included (it can't be produced reliably from the build host); the AppImage covers x64 Linux.

1.4.0

Choose a tag to compare

@hamedsj hamedsj released this 16 Aug 22:42

PandoraBox 1.4.0 — new editor, richer traffic export, and live CLI replay.

Highlights

  • New code editor (CodeMirror). The request/response inspector, Replay, Intercept, middleware, and notes now use a native DOM-text editor. It inherits the app font and selection, follows the theme live, mounts with no flash, and works fully offline (the editor is no longer fetched from a CDN).
  • Full body syntax highlighting for known content types — JSON, HTML/XML, JavaScript/TypeScript, CSS/SCSS, YAML, GraphQL, Markdown, and Python.
  • Single-scroll inspection. Request/response, Replay, Intruder results, and the GraphQL panel no longer nest an editor scrollbar inside the pane — the pane is the one scroll container (large bodies still virtualize).
  • Traffic export from the CLI. pandorabox sitemap export bulk-exports captured traffic as json, har, or a new files mode (each response body written to its own file, extension inferred from Content-Type), with --decode, --skip-request, --no-response-headers, and the usual host/method/search/status filters.
  • Live CLI replay. pandorabox replay send results now show up in the Repeater in real time, and pandorabox replay queue <id> adds a request to the Repeater queue without sending it.
  • Editor typography tuned to the UI — the Editor Font Size setting works again, with a denser default, tighter line-height, muted line-number gutter, and ligatures.

See the CHANGELOG for the full list.

Downloads

Platform File
macOS (Apple Silicon) PandoraBox-1.4.0-arm64.dmg / PandoraBox-1.4.0-arm64-mac.zip
macOS (Intel) PandoraBox-1.4.0.dmg / PandoraBox-1.4.0-mac.zip
Windows (x64) PandoraBox.Setup.1.4.0.exe
Linux (x64) PandoraBox-1.4.0.AppImage

The builds are ad-hoc signed (not notarized), so on first launch macOS may need right-click → Open to bypass Gatekeeper. Verify downloads against SHA256SUMS.

The Debian .deb is not included in this release — it could not be produced reliably from the build host. AppImage covers x64 Linux; a .deb can be attached later.

1.3.0

Choose a tag to compare

@hamedsj hamedsj released this 24 Jun 21:30

Added

  • The pandorabox CLI now covers every feature the app has, not just traffic/replay/intercept: scope, matchreplace, middleware, converter, organizer, flows, intruder, and collaborator command groups. See wiki/cli.md for the full reference.
  • flows run <id> executes a flow's HTTP-request and Python-process steps in order, threading variables through exactly like the UI does.
  • intruder start/status/results/cancel runs marker-driven fuzzing attacks (sniper/battering_ram/pitchfork/cluster_bomb) from the terminal, with live progress visible in the Intruder panel.
  • collaborator start/poll/stop/url runs out-of-band (interactsh) sessions from the terminal, with interactions visible live in the Collaborator panel.
  • Every CLI mutation is reflected live in the running UI over the same WebSocket the browser uses — no separate sync step.

Fixed

  • project.updated WebSocket events were missing the converter field entirely, which silently wiped the Converter page's stack list to empty on any unrelated project change (scope, match & replace, etc.) — from the browser or the CLI. Now included.

Downloads

Platform File
macOS Apple Silicon PandoraBox-1.3.0-arm64.dmg
macOS Intel PandoraBox-1.3.0.dmg
Windows x64 PandoraBox Setup 1.3.0.exe
Linux x64 AppImage PandoraBox-1.3.0.AppImage
Linux x64 deb pandorabox_1.3.0_amd64.deb

See SHA256SUMS to verify downloads.

1.2.2

Choose a tag to compare

@hamedsj hamedsj released this 24 Jun 17:14

Changed

  • Settings → Agent CLI now leads with Terminal Command and Agent Skill (the things most agents need first); legacy MCP access/status moved to the bottom of the tab.
  • Agent Skill now has a copyable install prompt — paste it into Codex, Claude Code, or another coding agent so it clones the skill from the repo into /tmp, installs it, and cleans up after itself.

Fixed

  • The app icon's rounded-square background filled the entire canvas edge-to-edge, making it visibly larger than neighboring app icons in the Dock/taskbar. Rescaled to the standard ~80% live-area margin so it matches other apps' icon size.

Downloads

Platform File
macOS Apple Silicon PandoraBox-1.2.2-arm64.dmg
macOS Intel PandoraBox-1.2.2.dmg
Windows x64 PandoraBox Setup 1.2.2.exe
Linux x64 AppImage PandoraBox-1.2.2.AppImage
Linux x64 deb pandorabox_1.2.2_amd64.deb

See SHA256SUMS to verify downloads.

1.2.1

Choose a tag to compare

@hamedsj hamedsj released this 24 Jun 15:08

Added

  • Settings → Agent CLI now has an Install Command button that symlinks the bundled pandorabox binary onto your shell's PATH (/usr/local/bin on macOS/Linux, a PATH entry on Windows). Previously the CLI shipped inside the app bundle but wasn't reachable from a terminal after installing — this fixes that.

Fixed

  • The app icon (dock icon on macOS, taskbar icon on Windows, AppImage/deb icon on Linux) rendered with the logo far too small inside the rounded-square background. Regenerated the icon so the glyph fills the frame properly.
  • v1.2.0's Intel Mac (x64) build shipped with a stale pre-1.2.0 backend binary (missing the agent CLI and MCP-opt-in changes) due to a Makefile bug. Fixed — all platforms in this release are built from the same, current source.

Downloads

Platform File
macOS Apple Silicon PandoraBox-1.2.1-arm64.dmg
macOS Intel PandoraBox-1.2.1.dmg
Windows x64 PandoraBox Setup 1.2.1.exe
Linux x64 AppImage PandoraBox-1.2.1.AppImage
Linux x64 deb pandorabox_1.2.1_amd64.deb

See SHA256SUMS to verify downloads.

1.2.0

Choose a tag to compare

@hamedsj hamedsj released this 24 Jun 14:38

What's new

  • Compact agent CLI (pandorabox status|traffic|replay|intercept|project) — a low-token alternative to MCP for driving PandoraBox from Codex or any LLM agent. Output is terse text by default; pass --json for structured output. See wiki/cli.md.
  • Repository skill at skills/pandorabox-cli/ so Codex-style agents discover and prefer the CLI workflow automatically.
  • Electron windows now set an explicit app identity (dock icon on macOS, taskbar icon + AppUserModelID on Windows).

Changed

  • The legacy MCP server is now opt-in: start it with pandorabox serve --enable-mcp. Settings → Agent CLI (formerly MCP) shows the compact CLI commands first, with legacy MCP endpoint/setup info still available underneath.

Downloads

Platform File
macOS Apple Silicon PandoraBox-1.2.0-arm64.dmg
macOS Intel PandoraBox-1.2.0.dmg
Windows x64 PandoraBox Setup 1.2.0.exe
Linux x64 AppImage PandoraBox-1.2.0.AppImage
Linux x64 deb pandorabox_1.2.0_amd64.deb

See SHA256SUMS to verify downloads.

1.1.0

Choose a tag to compare

@hamedsj hamedsj released this 06 Jun 19:24

What's new

  • Separate App & Editor font sizes — Settings → Typography now has two independent controls: App Font Size (scales all UI text via rem) and Editor Font Size (scales Monaco request/response editors). Default app size raised to 14 px.
  • Sitemap tree collapsed by default — hosts load collapsed; expand what you need.

Bug fixes

  • Raw response packet no longer duplicates the status code (HTTP/2.0 200 200 OK → HTTP/2.0 200 OK).

Downloads

Platform File
macOS Apple Silicon PandoraBox-1.1.0-arm64.dmg
macOS Intel PandoraBox-1.1.0.dmg
Windows x64 PandoraBox-1.1.0-win.zip (portable)
Linux x64 AppImage PandoraBox-1.1.0.AppImage
Linux x64 deb pandorabox_1.1.0_amd64.deb

See SHA256SUMS to verify downloads.

1.0.0

Choose a tag to compare

@hamedsj hamedsj released this 01 Jun 10:25

Changelog

All notable changes to PandoraBox will be documented in this file.

The format is based on Keep a Changelog, and this project follows semantic
versioning for public releases.

[1.0.0] - 2026-06-01

First public release.

Added

  • Programmable HTTP/HTTPS MITM proxy with intercept, replay, scope, sitemap,
    match-and-replace, Python middleware, flows, Intruder, Collaborator, and team
    synchronization.
  • Electron and embedded web UI modes backed by the same Go binary.
  • MCP server over streamable HTTP with legacy SSE compatibility, live generated
    tool documentation, and project-level MCP access controls.
  • Request and response inspection with decoded body views, raw views, hex views,
    syntax highlighting, and WebSocket frame capture.
  • Local SQLite project storage with importable project configuration files.
  • Replay queue persists per project across reloads, with an HTTP/HTTPS scheme
    switch, a Cancel button for in-flight sends, and an editable raw-packet history.
  • The launcher's recent-projects list has a per-entry remove control that drops a
    project from the list without deleting its files.

Fixed

  • Replay traffic is now stored self-contained and no longer leaks into History,
    the SiteMap, or request counts; existing projects are migrated and cleaned on
    first launch. Match-and-replace and middleware now apply to every replay, and
    concurrent replays no longer wedge the server.
  • Replay responses now survive leaving and returning to the Replay page, and the
    back/forward arrows restore each sent packet together with the response it
    produced.
  • The selection-to-Converter popup now tracks a changed selection and dismisses
    on deselect instead of leaving a stale popup, while staying open when you click
    into it.
  • Closing the launcher before opening a project now quits the app instead of
    leaving it running with no visible window.