Releases: tower-org/tower
Release list
v0.4.1
Tower v0.4.1
Package: @tower-org/cli@0.4.1
Source commit: a698d587abbb176f564eb765bcf986f2f86102dc
What's changed
Changed
- Pushing a stable
v<version>tag now starts the production release workflow
automatically. GitHub environment approval remains required before npm and
GitHub Release publication. - The protected publication job validates and publishes the npm tarball built
before approval instead of rebuilding the application and rerunning release
gates. - Production Releases publish
install.sh,install.ps1, andSHA256SUMSas
top-level helper assets. The changelog remains the release-notes source, and
the CMD compatibility wrapper remains inside the Windows portable archive.
Installers now report clear download, verification, extraction, and activation
progress.
Fixed
- GitHub Pages retries use attempt-scoped artifacts, preventing a failed
deployment retry from colliding with an artifact uploaded by the prior attempt. - Fresh Workbench sessions no longer re-inject resolved historical batches and
trigger duplicate reviews. - Completing a task from Missions now preserves its running execution, terminal,
and worktree when a merge conflict occurs, sends resolution instructions to
the current agent, and allows completion to be retried after the conflict is
resolved. - Codex connection checks now use isolated, ephemeral probes with user settings
and execution tools disabled, preventing checks from affecting normal sessions. - First-run setup keeps optional extensions unselected by default, opens the first
workspace directly after completion, and restores the finish action after a
save error so setup can be retried. - Guided Tour highlights and actions now follow the active primary theme instead
of using a fixed amber accent. - Development type checks now include Next.js declarations generated under the
custom.next-devoutput directory.
The npm package with provenance remains the standard registry channel. The tower-org-cli-0.4.1.tgz asset is the exact npm pack input for audit and offline npm clients; it still requires npm dependency resolution. Use a platform portable asset for a registry-free installation. GitHub's automatic source archives are source code, not Tower installers.
Portable targets
| OS | CPU | Asset |
|---|---|---|
| darwin | arm64 | tower-portable-darwin-arm64.tar.gz |
| darwin | x64 | tower-portable-darwin-x64.tar.gz |
| linux | arm64 | tower-portable-linux-arm64.tar.gz |
| linux | x64 | tower-portable-linux-x64.tar.gz |
| windows | x64 | tower-portable-windows-x64.tar.gz |
Every listed target passed a native runner smoke covering first database creation, migrations, Prisma Client/Query/Schema Engines, MCP startup, node-pty, ripgrep, and Tower HTTP startup with npm/Prisma download endpoints blocked. Targets that do not pass are not assembled or published.
Node.js
Node.js >=22.0.0 is required and is not bundled or installed by Tower. Node 22 and 24 are tested on every release target. Other versions meeting the minimum continue in best-effort mode unless listed as specifically incompatible.
Verify
Download the asset and SHA256SUMS, then filter the selected filename and run sha256sum -c - (Linux) or shasum -a 256 -c - (macOS); on Windows compare Get-FileHash <asset> -Algorithm SHA256 with the matching line in SHA256SUMS. Review install.sh or install.ps1 before execution.
Install and recovery
The versioned download base is https://github.com/tower-org/tower/releases/download/v0.4.1. On Windows run install.ps1 from PowerShell; use a process-scoped -ExecutionPolicy Bypass only when local policy requires it. Pass --version 0.4.1 / -Version 0.4.1 to pin this release. The installers support --rollback / -Rollback and --uninstall / -Uninstall; uninstall preserves ~/.tower user data. The maintained installation guide is https://tower-org.github.io/tower/guide/getting-started.html (English: https://tower-org.github.io/tower/en/guide/getting-started.html).
v0.4.0
Tower v0.4.0
Package: @tower-org/cli@0.4.0
Source commit: 5a3a496b971b0930bc5e22383d34a392458ee77e
What's changed
Added
- Registry-free portable distributions for macOS arm64/x64, Linux arm64/x64,
and Windows x64, with installers, platform manifests, and SHA-256 checksums. - A five-platform Release Candidate workflow that produces reviewable artifacts
without creating a tag, publishing npm, or creating a GitHub Release. - Durable Gateway-to-Workbench project discussions, work requests, completion
delivery, and bounded OWNER capability routing. - Guaranteed final OWNER notification and recovery states for unattended goals.
- A Windows CMD installer entry point alongside PowerShell installation.
Changed
- Workbench availability now follows provider turns and durable pending work;
terminal lifetime and delayed stop hooks no longer keep an idle Workbench busy. - Assistant sessions use bounded Tower-owned history, preserve explicit
workspace/project bindings per session, and hide internal CLI carrier sessions. - Missions presents localized Workbench status, pending count, and heartbeat
without exposing internal generation numbers. - Backups remain an explicit Settings action; Tower no longer starts an
undocumented, default-enabled scheduled backup loop in the server process. - GitHub Pages documentation now separates product features, Gateway,
Workbench, durable protocol, MCP, OpenClaw integration, and AI Provider
extensions. Version-specific guide pages moved into this changelog. - Release Candidate and production workflow downloads expose separate platform
artifacts with stable names such astower-macos-arm64and
tower-windows-x64, without a redundant all-platform bundle.
Fixed
- Restored Workbench queue draining after idle resume and fenced delayed provider
callbacks from newer turns. - Hardened Windows portable builds, Prisma path normalization, npm invocation,
and native probe shutdown. - Restored Assistant attachment/goal-mode tools and built-in CLI Provider
registration after the runtime refactor. - Removed a company-environment Feishu screenshot from the public documentation.
Security
- Production startup now rejects wildcard and LAN bind addresses; supported CLI
and unattended-service startup paths remain loopback-only. - Release identity is bound to one tag, commit, package version, repository, and
explicit approval value; recovery refuses moved tags or conflicting assets. - Candidate metadata is passed through environment variables rather than direct
workflow expression interpolation in shell commands. - GitHub publication uploads and verifies assets on a recoverable draft, then
publishes once so repository-level immutable releases can lock the tag and assets.
The npm package with provenance remains the standard registry channel. The tower-org-cli-0.4.0.tgz asset is the exact npm pack input for audit and offline npm clients; it still requires npm dependency resolution. Use a platform portable asset for a registry-free installation. GitHub's automatic source archives are source code, not Tower installers.
Portable targets
| OS | CPU | Asset |
|---|---|---|
| darwin | arm64 | tower-portable-darwin-arm64.tar.gz |
| darwin | x64 | tower-portable-darwin-x64.tar.gz |
| linux | arm64 | tower-portable-linux-arm64.tar.gz |
| linux | x64 | tower-portable-linux-x64.tar.gz |
| windows | x64 | tower-portable-windows-x64.tar.gz |
Every listed target passed a native runner smoke covering first database creation, migrations, Prisma Client/Query/Schema Engines, MCP startup, node-pty, ripgrep, and Tower HTTP startup with npm/Prisma download endpoints blocked. Targets that do not pass are not assembled or published.
Node.js
Node.js >=22.0.0 is required and is not bundled or installed by Tower. Node 22 and 24 are tested on every release target. Other versions meeting the minimum continue in best-effort mode unless listed as specifically incompatible.
Verify
Download the asset and SHA256SUMS, then filter the selected filename and run sha256sum -c - (Linux) or shasum -a 256 -c - (macOS); on Windows compare Get-FileHash <asset> -Algorithm SHA256 with the matching line in SHA256SUMS. Review install.sh, install.cmd, and install.ps1 before execution.
Install and recovery
The versioned download base is https://github.com/tower-org/tower/releases/download/v0.4.0. On Windows keep install.cmd and install.ps1 together; the CMD wrapper forwards to the PowerShell installer with a process-scoped execution-policy bypass. Pass --version 0.4.0 / -Version 0.4.0 to pin this release. The installers support --rollback / -Rollback and --uninstall / -Uninstall; uninstall preserves ~/.tower user data. The maintained installation guide is https://tower-org.github.io/tower/guide/getting-started.html (English: https://tower-org.github.io/tower/en/guide/getting-started.html).
Tower v0.3.1
What's Changed
- feat(workbench): ship the durable gateway architecture by @jp-liu in #24
- fix(mcp): harden explicit gateway task continuation by @jp-liu in #25
- refactor(workbench): establish event module boundaries by @jp-liu in #26
- fix(mcp): restore CI workflow startup by @jp-liu in #27
- feat(settings): integrate extension platform foundation by @jp-liu in #28
- feat(workbench): observe operational data lifecycle by @jp-liu in #29
- refactor(mcp): scope tool catalogs by runtime role by @jp-liu in #30
- refactor(mcp): isolate unattended goal and gateway recovery by @jp-liu in #31
- feat(mcp): complete unattended capability runtime by @jp-liu in #32
- fix(release): install Playwright browser in publish workflow by @jp-liu in #33
Full Changelog: v0.3.0...v0.3.1