v0.4.0
Tower v0.4.0
Package: @tower-org/cli@0.4.0
Source commit: 5a3a496b971b0930bc5e22383d34a392458ee77e
What's changed
Added
- Registry-free portable distributions for macOS arm64/x64, Linux arm64/x64,
and Windows x64, with installers, platform manifests, and SHA-256 checksums. - A five-platform Release Candidate workflow that produces reviewable artifacts
without creating a tag, publishing npm, or creating a GitHub Release. - Durable Gateway-to-Workbench project discussions, work requests, completion
delivery, and bounded OWNER capability routing. - Guaranteed final OWNER notification and recovery states for unattended goals.
- A Windows CMD installer entry point alongside PowerShell installation.
Changed
- Workbench availability now follows provider turns and durable pending work;
terminal lifetime and delayed stop hooks no longer keep an idle Workbench busy. - Assistant sessions use bounded Tower-owned history, preserve explicit
workspace/project bindings per session, and hide internal CLI carrier sessions. - Missions presents localized Workbench status, pending count, and heartbeat
without exposing internal generation numbers. - Backups remain an explicit Settings action; Tower no longer starts an
undocumented, default-enabled scheduled backup loop in the server process. - GitHub Pages documentation now separates product features, Gateway,
Workbench, durable protocol, MCP, OpenClaw integration, and AI Provider
extensions. Version-specific guide pages moved into this changelog. - Release Candidate and production workflow downloads expose separate platform
artifacts with stable names such astower-macos-arm64and
tower-windows-x64, without a redundant all-platform bundle.
Fixed
- Restored Workbench queue draining after idle resume and fenced delayed provider
callbacks from newer turns. - Hardened Windows portable builds, Prisma path normalization, npm invocation,
and native probe shutdown. - Restored Assistant attachment/goal-mode tools and built-in CLI Provider
registration after the runtime refactor. - Removed a company-environment Feishu screenshot from the public documentation.
Security
- Production startup now rejects wildcard and LAN bind addresses; supported CLI
and unattended-service startup paths remain loopback-only. - Release identity is bound to one tag, commit, package version, repository, and
explicit approval value; recovery refuses moved tags or conflicting assets. - Candidate metadata is passed through environment variables rather than direct
workflow expression interpolation in shell commands. - GitHub publication uploads and verifies assets on a recoverable draft, then
publishes once so repository-level immutable releases can lock the tag and assets.
The npm package with provenance remains the standard registry channel. The tower-org-cli-0.4.0.tgz asset is the exact npm pack input for audit and offline npm clients; it still requires npm dependency resolution. Use a platform portable asset for a registry-free installation. GitHub's automatic source archives are source code, not Tower installers.
Portable targets
| OS | CPU | Asset |
|---|---|---|
| darwin | arm64 | tower-portable-darwin-arm64.tar.gz |
| darwin | x64 | tower-portable-darwin-x64.tar.gz |
| linux | arm64 | tower-portable-linux-arm64.tar.gz |
| linux | x64 | tower-portable-linux-x64.tar.gz |
| windows | x64 | tower-portable-windows-x64.tar.gz |
Every listed target passed a native runner smoke covering first database creation, migrations, Prisma Client/Query/Schema Engines, MCP startup, node-pty, ripgrep, and Tower HTTP startup with npm/Prisma download endpoints blocked. Targets that do not pass are not assembled or published.
Node.js
Node.js >=22.0.0 is required and is not bundled or installed by Tower. Node 22 and 24 are tested on every release target. Other versions meeting the minimum continue in best-effort mode unless listed as specifically incompatible.
Verify
Download the asset and SHA256SUMS, then filter the selected filename and run sha256sum -c - (Linux) or shasum -a 256 -c - (macOS); on Windows compare Get-FileHash <asset> -Algorithm SHA256 with the matching line in SHA256SUMS. Review install.sh, install.cmd, and install.ps1 before execution.
Install and recovery
The versioned download base is https://github.com/tower-org/tower/releases/download/v0.4.0. On Windows keep install.cmd and install.ps1 together; the CMD wrapper forwards to the PowerShell installer with a process-scoped execution-policy bypass. Pass --version 0.4.0 / -Version 0.4.0 to pin this release. The installers support --rollback / -Rollback and --uninstall / -Uninstall; uninstall preserves ~/.tower user data. The maintained installation guide is https://tower-org.github.io/tower/guide/getting-started.html (English: https://tower-org.github.io/tower/en/guide/getting-started.html).