Releases: hamedsj/PandoraBox
Release list
1.4.1
PandoraBox 1.4.1 — a patch focused on replay reliability, transparent body decompression, and CLI power tools for large traffic sets.
Fixed
- Replay no longer drops the request body. A replayed POST's body,
Content-Length, and rewind source are pinned to the actual bytes right before send, so the body is never omitted or mismatched.
Changed
- Transparent body decompression for Python middleware, Match & Replace, and Flows. Response bodies are decompressed (gzip/brotli/zstd/deflate) before
res-bodyrules, middleware, and flowprocesssteps see them, then re-compressed to the originalContent-Encodingon the way out — so scripts read plaintext with no manual gzip handling. This also fixesres-bodymatch & replace rules that silently never matched compressed responses.
Added
pandorabox traffic search <term>— grep decoded request/response bodies across all traffic (--in,--regex,--content-type).pandorabox traffic get <id> --body responsenow auto-decompresses (--raw-bodyfor wire bytes),--save-to <file>writes a body to disk,--max-bytes 0disables the limit, and truncated output shows a size marker.pandorabox sitemap export --content-type <type>filters exports (incl. per-file mode) by response Content-Type.pandorabox matchreplace test <id>— dry-run rules against a captured request (per-rule match/no-match/disabled + why).pandorabox middleware test --code-file <f> --request-id <id>— dry-run a middleware script, surfacing tracebacks and before/after.
See the CHANGELOG for details.
Downloads
| Platform | File |
|---|---|
| macOS (Apple Silicon) | PandoraBox-1.4.1-arm64.dmg / PandoraBox-1.4.1-arm64-mac.zip |
| macOS (Intel) | PandoraBox-1.4.1.dmg / PandoraBox-1.4.1-mac.zip |
| Windows (x64) | PandoraBox.Setup.1.4.1.exe |
| Linux (x64) | PandoraBox-1.4.1.AppImage |
Builds are ad-hoc signed (not notarized) — on first launch macOS may need right-click → Open. Verify downloads against SHA256SUMS. As with 1.4.0, a Debian .deb is not included (it can't be produced reliably from the build host); the AppImage covers x64 Linux.
1.4.0
PandoraBox 1.4.0 — new editor, richer traffic export, and live CLI replay.
Highlights
- New code editor (CodeMirror). The request/response inspector, Replay, Intercept, middleware, and notes now use a native DOM-text editor. It inherits the app font and selection, follows the theme live, mounts with no flash, and works fully offline (the editor is no longer fetched from a CDN).
- Full body syntax highlighting for known content types — JSON, HTML/XML, JavaScript/TypeScript, CSS/SCSS, YAML, GraphQL, Markdown, and Python.
- Single-scroll inspection. Request/response, Replay, Intruder results, and the GraphQL panel no longer nest an editor scrollbar inside the pane — the pane is the one scroll container (large bodies still virtualize).
- Traffic export from the CLI.
pandorabox sitemap exportbulk-exports captured traffic asjson,har, or a newfilesmode (each response body written to its own file, extension inferred fromContent-Type), with--decode,--skip-request,--no-response-headers, and the usual host/method/search/status filters. - Live CLI replay.
pandorabox replay sendresults now show up in the Repeater in real time, andpandorabox replay queue <id>adds a request to the Repeater queue without sending it. - Editor typography tuned to the UI — the Editor Font Size setting works again, with a denser default, tighter line-height, muted line-number gutter, and ligatures.
See the CHANGELOG for the full list.
Downloads
| Platform | File |
|---|---|
| macOS (Apple Silicon) | PandoraBox-1.4.0-arm64.dmg / PandoraBox-1.4.0-arm64-mac.zip |
| macOS (Intel) | PandoraBox-1.4.0.dmg / PandoraBox-1.4.0-mac.zip |
| Windows (x64) | PandoraBox.Setup.1.4.0.exe |
| Linux (x64) | PandoraBox-1.4.0.AppImage |
The builds are ad-hoc signed (not notarized), so on first launch macOS may need right-click → Open to bypass Gatekeeper. Verify downloads against SHA256SUMS.
The Debian
.debis not included in this release — it could not be produced reliably from the build host. AppImage covers x64 Linux; a.debcan be attached later.
1.3.0
Added
- The
pandoraboxCLI now covers every feature the app has, not just traffic/replay/intercept:scope,matchreplace,middleware,converter,organizer,flows,intruder, andcollaboratorcommand groups. See wiki/cli.md for the full reference. flows run <id>executes a flow's HTTP-request and Python-process steps in order, threading variables through exactly like the UI does.intruder start/status/results/cancelruns marker-driven fuzzing attacks (sniper/battering_ram/pitchfork/cluster_bomb) from the terminal, with live progress visible in the Intruder panel.collaborator start/poll/stop/urlruns out-of-band (interactsh) sessions from the terminal, with interactions visible live in the Collaborator panel.- Every CLI mutation is reflected live in the running UI over the same WebSocket the browser uses — no separate sync step.
Fixed
project.updatedWebSocket events were missing theconverterfield entirely, which silently wiped the Converter page's stack list to empty on any unrelated project change (scope, match & replace, etc.) — from the browser or the CLI. Now included.
Downloads
| Platform | File |
|---|---|
| macOS Apple Silicon | PandoraBox-1.3.0-arm64.dmg |
| macOS Intel | PandoraBox-1.3.0.dmg |
| Windows x64 | PandoraBox Setup 1.3.0.exe |
| Linux x64 AppImage | PandoraBox-1.3.0.AppImage |
| Linux x64 deb | pandorabox_1.3.0_amd64.deb |
See SHA256SUMS to verify downloads.
1.2.2
Changed
- Settings → Agent CLI now leads with Terminal Command and Agent Skill (the things most agents need first); legacy MCP access/status moved to the bottom of the tab.
- Agent Skill now has a copyable install prompt — paste it into Codex, Claude Code, or another coding agent so it clones the skill from the repo into
/tmp, installs it, and cleans up after itself.
Fixed
- The app icon's rounded-square background filled the entire canvas edge-to-edge, making it visibly larger than neighboring app icons in the Dock/taskbar. Rescaled to the standard ~80% live-area margin so it matches other apps' icon size.
Downloads
| Platform | File |
|---|---|
| macOS Apple Silicon | PandoraBox-1.2.2-arm64.dmg |
| macOS Intel | PandoraBox-1.2.2.dmg |
| Windows x64 | PandoraBox Setup 1.2.2.exe |
| Linux x64 AppImage | PandoraBox-1.2.2.AppImage |
| Linux x64 deb | pandorabox_1.2.2_amd64.deb |
See SHA256SUMS to verify downloads.
1.2.1
Added
- Settings → Agent CLI now has an Install Command button that symlinks the bundled
pandoraboxbinary onto your shell's PATH (/usr/local/binon macOS/Linux, a PATH entry on Windows). Previously the CLI shipped inside the app bundle but wasn't reachable from a terminal after installing — this fixes that.
Fixed
- The app icon (dock icon on macOS, taskbar icon on Windows, AppImage/deb icon on Linux) rendered with the logo far too small inside the rounded-square background. Regenerated the icon so the glyph fills the frame properly.
- v1.2.0's Intel Mac (x64) build shipped with a stale pre-1.2.0 backend binary (missing the agent CLI and MCP-opt-in changes) due to a Makefile bug. Fixed — all platforms in this release are built from the same, current source.
Downloads
| Platform | File |
|---|---|
| macOS Apple Silicon | PandoraBox-1.2.1-arm64.dmg |
| macOS Intel | PandoraBox-1.2.1.dmg |
| Windows x64 | PandoraBox Setup 1.2.1.exe |
| Linux x64 AppImage | PandoraBox-1.2.1.AppImage |
| Linux x64 deb | pandorabox_1.2.1_amd64.deb |
See SHA256SUMS to verify downloads.
1.2.0
What's new
- Compact agent CLI (
pandorabox status|traffic|replay|intercept|project) — a low-token alternative to MCP for driving PandoraBox from Codex or any LLM agent. Output is terse text by default; pass--jsonfor structured output. See wiki/cli.md. - Repository skill at
skills/pandorabox-cli/so Codex-style agents discover and prefer the CLI workflow automatically. - Electron windows now set an explicit app identity (dock icon on macOS, taskbar icon + AppUserModelID on Windows).
Changed
- The legacy MCP server is now opt-in: start it with
pandorabox serve --enable-mcp. Settings → Agent CLI (formerly MCP) shows the compact CLI commands first, with legacy MCP endpoint/setup info still available underneath.
Downloads
| Platform | File |
|---|---|
| macOS Apple Silicon | PandoraBox-1.2.0-arm64.dmg |
| macOS Intel | PandoraBox-1.2.0.dmg |
| Windows x64 | PandoraBox Setup 1.2.0.exe |
| Linux x64 AppImage | PandoraBox-1.2.0.AppImage |
| Linux x64 deb | pandorabox_1.2.0_amd64.deb |
See SHA256SUMS to verify downloads.
1.1.0
What's new
- Separate App & Editor font sizes — Settings → Typography now has two independent controls: App Font Size (scales all UI text via rem) and Editor Font Size (scales Monaco request/response editors). Default app size raised to 14 px.
- Sitemap tree collapsed by default — hosts load collapsed; expand what you need.
Bug fixes
- Raw response packet no longer duplicates the status code (
HTTP/2.0 200 200 OK→HTTP/2.0 200 OK).
Downloads
| Platform | File |
|---|---|
| macOS Apple Silicon | PandoraBox-1.1.0-arm64.dmg |
| macOS Intel | PandoraBox-1.1.0.dmg |
| Windows x64 | PandoraBox-1.1.0-win.zip (portable) |
| Linux x64 AppImage | PandoraBox-1.1.0.AppImage |
| Linux x64 deb | pandorabox_1.1.0_amd64.deb |
See SHA256SUMS to verify downloads.
1.0.0
Changelog
All notable changes to PandoraBox will be documented in this file.
The format is based on Keep a Changelog, and this project follows semantic
versioning for public releases.
[1.0.0] - 2026-06-01
First public release.
Added
- Programmable HTTP/HTTPS MITM proxy with intercept, replay, scope, sitemap,
match-and-replace, Python middleware, flows, Intruder, Collaborator, and team
synchronization. - Electron and embedded web UI modes backed by the same Go binary.
- MCP server over streamable HTTP with legacy SSE compatibility, live generated
tool documentation, and project-level MCP access controls. - Request and response inspection with decoded body views, raw views, hex views,
syntax highlighting, and WebSocket frame capture. - Local SQLite project storage with importable project configuration files.
- Replay queue persists per project across reloads, with an HTTP/HTTPS scheme
switch, a Cancel button for in-flight sends, and an editable raw-packet history. - The launcher's recent-projects list has a per-entry remove control that drops a
project from the list without deleting its files.
Fixed
- Replay traffic is now stored self-contained and no longer leaks into History,
the SiteMap, or request counts; existing projects are migrated and cleaned on
first launch. Match-and-replace and middleware now apply to every replay, and
concurrent replays no longer wedge the server. - Replay responses now survive leaving and returning to the Replay page, and the
back/forward arrows restore each sent packet together with the response it
produced. - The selection-to-Converter popup now tracks a changed selection and dismisses
on deselect instead of leaving a stale popup, while staying open when you click
into it. - Closing the launcher before opening a project now quits the app instead of
leaving it running with no visible window.