Skip to content

Tale v0.5.75

Choose a tag to compare

@github-actions github-actions released this 07 Oct 00:20
· 69 commits to main since this release
5b6ab36

Highlights

  • First pages load faster. Each page now brings its interface text by topic, together with the
    code that reads it, instead of the whole catalog: the cold load drops from 891 to 792 KB gzip,
    and every first page carries 26 KB gzip less render-blocking CSS. A German or French session
    fetches about 36 KB gzip of its language before the first frame instead of the whole 124 KB
    catalog. Switching language fetches the new language's text for the pages already open, and
    the next page opens in that language. The document preview and the New project dialog load
    on demand, the embedding alert loads only for an organization that needs it, and the API docs
    page and its stylesheet load only when opened. Language files are named by locale, such as
    de-auth-….js, so a browser's network panel shows which language a session loads.
  • Long task, chat, project and comment lists render the rows near the current view with shared
    row measurements, and keep keyboard focus, edits, menus and drag state. Repeated markdown and
    pagination work is reused, organization hints are requested in batches, and each active read
    refreshes once after a reconnect.
    Task views
  • Website scans render a page again only when it changed. A scan probes each page once; changed
    pages also require a browser fetch. A 304 Not Modified answer, or plain HTML whose text reads
    as it did at the last visit, leaves the page as it is, and only a changed page is rendered in
    the browser and indexed again. Pages drawn by their JavaScript are still rendered on every scan.
    On a measured 700-page site, a scan of unchanged pages drops from about 8,000 requests and 2 GiB
    to about 700 requests of compressed HTML. Scan now runs the same scan as the schedule.
    Crawling
    · #4439
  • Admins can paste a Claude OAuth token as an Anthropic Subscription key and replace it later
    from the credential's row menu. Claude Code receives it as CLAUDE_CODE_OAUTH_TOKEN. A pasted
    token does not refresh; the AI gateway broker remains the way to refresh automatically.
    Providers
    · #4369
  • Task previews show a project agent's details, and the task timeline no longer shows a deleted
    agent's id or preview. Failed agent runs have simpler controls with an aligned retry action,
    and the hint for commenting on a task assigned to an agent is clearer. Long dropdown menus
    stay within the viewport, and skill menus in dialogs scroll with the mouse wheel again.
    #4438
  • Feedback filtered to comments now finds older matching comments even when the newest ratings
    have none. Usage charts keep the selected period's totals in the summary cards, comparisons
    and detail tables when you change the chart's granularity, for example from daily to monthly.
    #4328,
    #4411
  • Task agents stage at most the newest 64 prior task deliverables into a run. Older deliverables
    remain on the task, and the run is told when older outputs were omitted. Attached files are
    unaffected.
    #4448
  • Two-factor grace periods are anchored to the first sign-in that required two-factor
    authentication. Shortening the grace period takes effect at once, and lengthening it extends
    from the same anchor. Accounts already in a grace period before this release keep their stored
    deadline, because their original sign-in time is unknown.
    #4437
  • Image processing uses sharp 0.35.5 with librsvg 2.63.2, which fixes GHSA-wq5f-xc86-pv6w
    (CVE-2026-96889): a memory-safety flaw in SVG decoding that can allow remote code execution
    under certain conditions on glibc-based Linux. The platform, web and sandbox runtime images
    carry the update.
    #4450
  • All projects board and list views no longer show the Archived badge of the project kept in
    the URL; an archived project's own pages still show it.
    #4416

Upgrade notes

  • Back up the application and knowledge databases, configuration, keys and external stores
    before deploying. On startup, the knowledge database container (knowledge-db in Compose)
    applies the knowledge-corpus migration 00000000000013_website_url_change_check.sql from this
    release's db image to tale_knowledge. It adds a probe_hash column to
    public_web.website_urls and clears the stored etag and last_modified values once. The
    change is additive and safe during a rolling deploy, because the previous platform image
    neither reads nor writes these columns. The new crawler keeps its change check in them, so
    upgrade the knowledge database container to this release's db image and wait for its
    migrations to finish before starting the new platform images. Keep the columns during a
    rollback: the migration has no down step. The first scan of each website after the upgrade
    still renders every HTML page; later scans skip unchanged pages.
    Upgrade and recover
    · #4439
  • The backend applies database migration 0153_two_factor_first_required_sign_in.sql when it
    starts. It adds a nullable first_required_sign_in_at_ms column to app.two_factor_grace, so
    the previous backend keeps working on the migrated database during a rolling deploy; existing
    rows keep their stored deadline. Keep the column during an image rollback: numbered migrations
    are forward-only. No environment variable is added.
    #4437
  • Update a pinned SANDBOX_RUNTIME_IMAGE to this release's image as well: changing the
    application alone does not update it, and its document tools carry the sharp security update.
    #4450
  • This release's Tale CLI can update a retained 0.5 Compose runtime to a release that adds a
    named volume, such as static-assets from v0.5.74. Compose creates the volume and recreates
    only the service that mounts it. Earlier CLIs refused such an update with "Existing runtime
    mounts differ from the managed topology." Every existing data volume and host mount must still
    match the managed topology: a missing host mount, or a named volume that already exists
    without its mount, is still refused as drift.
    #4436
  • Known issues in this release:
    • In a task discussion, an unsaved comment edit, an open delete confirmation or an actor
      preview can be dropped when the discussion grows past 100 rows while that row is out of
      view. Save an edit before loading earlier comments in a long discussion.
      #4431
    • If the code for the embedding alert or the New project dialog fails to load, for example
      while offline, the page shows the error screen instead of the dashboard until it reloads once
      the service answers. A document preview that fails to load replaces the chat transcript; the
      composer stays.
      #4434
    • Usage charts read daily rows for every granularity, so a large organization viewing 90 days
      reaches the 20,000-row read cap sooner; the totals are then marked partial.
      #4440
    • In a task's agent preview, keyboard focus can't reach View more: the preview closes as
      focus moves into it. Open the agent from the project's agents tab instead.
      #4438
    • A page whose plain HTML carries at least nine tenths of its visible text is checked by that
      text alone, so a change only in its JavaScript-drawn part isn't picked up until the plain text
      changes too.
      #4439
    • When a task holds more than 64 deliverables, a run that replaces an existing deliverable under
      the same name can leave that newest copy out of the next run's staged inputs; it stays on the
      task.
      #4448

API contract changes

None in this range. The contract stays at 3.16.0: 141 operations.

What's Changed

Full Changelog: v0.5.74...v0.5.75