Skip to content

Commit 1bd2fb5

Browse files
committed
chore(release): prepare 0.25.0
Prepare pythinker-code 0.25.0 release.
1 parent 8a8f266 commit 1bd2fb5

18 files changed

Lines changed: 199 additions & 52 deletions

File tree

.github/workflows/homebrew-tap.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ on:
77
workflow_dispatch:
88
inputs:
99
version:
10-
description: "Version to push to the tap (e.g. 0.24.0)"
10+
description: "Version to push to the tap (e.g. 0.25.0)"
1111
required: true
1212
type: string
1313

.github/workflows/linux-installer.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ on:
88
workflow_dispatch:
99
inputs:
1010
version:
11-
description: "Version to build (e.g. 0.24.0)"
11+
description: "Version to build (e.g. 0.25.0)"
1212
required: true
1313
type: string
1414

.github/workflows/windows-installer.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ on:
88
workflow_dispatch:
99
inputs:
1010
version:
11-
description: "Version to build (e.g. 0.24.0)"
11+
description: "Version to build (e.g. 0.25.0)"
1212
required: true
1313
type: string
1414

CHANGELOG.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,20 @@ GitHub Releases page; `0.8.0` is the new starting line.
1515

1616
## Unreleased
1717

18+
## 0.25.0 (2026-05-29)
19+
20+
### What changed in this release
21+
22+
- **`Fetch` now re-checks every redirect hop against the SSRF guard.** Redirects were followed without re-validating the destination, so a public URL could redirect to a link-local address (e.g. a cloud metadata endpoint) and slip past the guard that only inspected the original URL. Redirects are now followed manually and every hop is re-validated, closing the public→link-local bypass.
23+
- **Web domain allowlist for `Fetch` and `Search`.** A new `web.allowed_domains` config option restricts which hosts the web tools may reach. When set, `Fetch` (including every redirect hop) and `Search` reject any host outside the list; leave it unset to keep web access unrestricted.
24+
- **Crash-consistent background tasks.** Task and agent-task state is now serialised under a cross-process per-task lock, so a worker heartbeat landing mid-update is no longer lost. Every terminal agent-task update routes through a single finalizer that writes the authoritative runtime first, and recovery reconciles records left divergent by a crash or kill without ever clobbering a live agent. Bash task output is capped (default 50 MiB) so a chatty task cannot exhaust disk, terminated processes get a SIGTERM→SIGKILL fallback, and aged terminal task directories are pruned (default 7 days).
25+
- **Calmer, more reliable TUI.** The todo list no longer renders twice during an in-flight turn, OAuth and feedback links open through a detached browser launcher so browser output cannot corrupt the terminal or steal key presses, and the terminal is restored to a sane state on `SIGTERM`/`SIGQUIT` and at exit.
26+
- **Live tool-execution feedback.** Tool calls now show a calm "preparing" row during approval and hooks, switch to a live status once execution starts, and stream shell `stdout`/`stderr` as a running tail before the final result lands. The composing assistant block renders a live Markdown preview as the model writes, code blocks gain clearer framing, and the active spinner uses smoother braille dots.
27+
- **Steadier agent loop.** The model is nudged once when a turn ends on a bare statement of intent with no tool call, steered away from blocking on a single background task while siblings are still running, and a `SetTodoList` call whose todos arrive as a JSON-encoded string is now parsed transparently instead of failing validation.
28+
- **Unified report rendering.** Code review, verify, and security-review output now share one standardized, muted report renderer — including `report` blocks emitted by skills and agents; a malformed block falls back to ordinary markdown rather than being swallowed.
29+
30+
Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.25.0`, or use the native installer for your OS (see the README install table).
31+
1832
## 0.24.0 (2026-05-28)
1933

2034
### What changed in this release

README.md

Lines changed: 26 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -50,15 +50,16 @@ It speaks the [**Agent Client Protocol (ACP)**](https://github.com/agentclientpr
5050
5151
---
5252

53-
## 🆕 What's New in 0.24.0
53+
## 🆕 What's New in 0.25.0
5454

55-
- **Update prompt is now wired and highlighted.** The blocking 4-choice update menu was defined but never invoked — users only ever saw the passive toast. It now runs before the auto-update path in every interactive session, and the status-line notice renders in bold bright-yellow.
56-
- **Complete native installer `Fetch` fix.** The `.exe`, `.deb`, and `.rpm` builds now bundle both `trafilatura` and `justext` data files so `Fetch` no longer crashes with `FileNotFoundError` on stoplists in native installs. PyPI / `pip install` was unaffected.
57-
- **Atomic "latest" release gating.** `/releases/latest` is no longer flipped until every platform asset is attached, preventing the in-app updater from serving a partially-built release.
58-
- **Smarter `/update` command.** Gets a fresh PyPI version and verifies the platform binary exists on the release before initiating a native upgrade.
59-
- **Repository transferred to TechMatrix-labs.** All URLs now point to `github.com/TechMatrix-labs/pythinker-code`.
55+
- **`Fetch` re-checks every redirect hop against the SSRF guard.** Redirects were followed without re-validating the destination, so a public URL could redirect to a link-local address (e.g. a cloud metadata endpoint) and slip past the guard. Every hop is now re-validated, closing the public→link-local bypass.
56+
- **Web domain allowlist for `Fetch` and `Search`.** Set `web.allowed_domains` to restrict which hosts the web tools may reach — `Fetch` (every redirect hop included) and `Search` reject anything off the list. Leave it unset to keep web access unrestricted.
57+
- **Crash-consistent background tasks.** Task state is serialised under a cross-process lock, terminal updates route through a single finalizer, and recovery reconciles records left divergent by a crash or kill without clobbering a live agent. Bash output is capped (default 50 MiB), kills escalate SIGTERM→SIGKILL, and aged terminal tasks are pruned (default 7 days).
58+
- **Calmer TUI with live tool feedback.** Tool calls show a "preparing" row during approval, stream shell output as a running tail, and render a live Markdown preview as the model writes. The todo list no longer renders twice mid-turn, links open through a detached launcher, and the terminal is restored to a sane state on `SIGTERM`/`SIGQUIT` and at exit.
59+
- **Steadier agent loop.** The model is nudged when a turn ends on a bare statement of intent, steered away from blocking on one background task while siblings run, and a `SetTodoList` whose todos arrive as a JSON string is parsed transparently instead of failing validation.
60+
- **Unified report rendering.** Code review, verify, and security-review output share one standardized renderer, including `report` blocks emitted by skills and agents.
6061

61-
Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.24.0`, or use the native installer for your platform from the [Releases page](https://github.com/TechMatrix-labs/pythinker-code/releases/latest).
62+
Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.25.0`, or use the native installer for your platform from the [Releases page](https://github.com/TechMatrix-labs/pythinker-code/releases/latest).
6263

6364

6465
---
@@ -148,7 +149,7 @@ matches your OS — no Python, Node, or `uv` prerequisite.
148149

149150
| Platform | Recommended install | Artifact source |
150151
|---|---|---|
151-
| **🪟 Windows** | `irm https://pythinker.com/install.ps1 \| iex` | `PythinkerSetup-0.24.0.exe` from [Releases](https://github.com/TechMatrix-labs/pythinker-code/releases/latest) |
152+
| **🪟 Windows** | `irm https://pythinker.com/install.ps1 \| iex` | `PythinkerSetup-0.25.0.exe` from [Releases](https://github.com/TechMatrix-labs/pythinker-code/releases/latest) |
152153
| **<img src="https://img.shields.io/badge/-macOS-000000?style=flat-square&logo=apple&logoColor=white" alt="macOS"> / <img src="https://img.shields.io/badge/-Linux-FCC624?style=flat-square&logo=linux&logoColor=black" alt="Linux">** | `curl -fsSL https://pythinker.com/install.sh \| bash` | native tarball from [Releases](https://github.com/TechMatrix-labs/pythinker-code/releases/latest) |
153154
| **<img src="https://img.shields.io/badge/-macOS-000000?style=flat-square&logo=apple&logoColor=white" alt="macOS"> — Homebrew** | `brew install TechMatrix-labs/pythinker/pythinker-code` | auto-published Homebrew tap |
154155
| **<img src="https://img.shields.io/badge/-Linux-FCC624?style=flat-square&logo=linux&logoColor=black" alt="Linux"> — system package** | Download the `.deb` or `.rpm` for your distro below | [Releases](https://github.com/TechMatrix-labs/pythinker-code/releases/latest) |
@@ -173,7 +174,7 @@ pythinker # start the interactive TUI
173174

174175
### 🪟 Windows — native installer
175176

176-
`PythinkerSetup-0.24.0.exe` is a signed* Inno Setup wizard. Installs per-user
177+
`PythinkerSetup-0.25.0.exe` is a signed* Inno Setup wizard. Installs per-user
177178
into `%LOCALAPPDATA%\Programs\Pythinker`, registers `pythinker` on your user
178179
PATH (`HKCU\Environment`), broadcasts `WM_SETTINGCHANGE` so new shells see
179180
the change. **No UAC prompt.**
@@ -184,13 +185,13 @@ irm https://pythinker.com/install.ps1 | iex
184185
185186
# Or manually download the installer + checksum from the Releases page,
186187
# verify with Get-FileHash, then run:
187-
.\PythinkerSetup-0.24.0.exe
188+
.\PythinkerSetup-0.25.0.exe
188189
189190
# Open a fresh PowerShell
190191
pythinker --version
191192
```
192193

193-
**Per-machine install** (IT-managed boxes): `.\PythinkerSetup-0.24.0.exe /ALLUSERS`
194+
**Per-machine install** (IT-managed boxes): `.\PythinkerSetup-0.25.0.exe /ALLUSERS`
194195
installs to `%ProgramFiles%\Pythinker` and writes PATH to HKLM (requires admin).
195196

196197
**Upgrade:** `pythinker update` from inside the running app — it downloads
@@ -241,26 +242,26 @@ attached to every GitHub Release.
241242

242243
```sh
243244
# Debian / Ubuntu (x86_64)
244-
sudo dpkg -i pythinker-code_0.24.0_amd64.deb
245+
sudo dpkg -i pythinker-code_0.25.0_amd64.deb
245246
sudo apt-get install -f # only if dpkg reports missing deps
246247

247248
# Debian / Ubuntu (ARM64)
248-
sudo dpkg -i pythinker-code_0.24.0_arm64.deb
249+
sudo dpkg -i pythinker-code_0.25.0_arm64.deb
249250

250251
# Fedora / RHEL / openSUSE (x86_64)
251-
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.24.0/pythinker-code-0.24.0.x86_64.rpm
252-
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.24.0/pythinker-code-0.24.0.x86_64.rpm.sha256
253-
sha256sum -c pythinker-code-0.24.0.x86_64.rpm.sha256
252+
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.25.0/pythinker-code-0.25.0.x86_64.rpm
253+
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.25.0/pythinker-code-0.25.0.x86_64.rpm.sha256
254+
sha256sum -c pythinker-code-0.25.0.x86_64.rpm.sha256
254255
# Fedora / RHEL:
255-
sudo dnf install ./pythinker-code-0.24.0.x86_64.rpm
256+
sudo dnf install ./pythinker-code-0.25.0.x86_64.rpm
256257
# openSUSE:
257-
sudo zypper install ./pythinker-code-0.24.0.x86_64.rpm
258+
sudo zypper install ./pythinker-code-0.25.0.x86_64.rpm
258259

259260
# Fedora / RHEL (aarch64)
260-
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.24.0/pythinker-code-0.24.0.aarch64.rpm
261-
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.24.0/pythinker-code-0.24.0.aarch64.rpm.sha256
262-
sha256sum -c pythinker-code-0.24.0.aarch64.rpm.sha256
263-
sudo dnf install ./pythinker-code-0.24.0.aarch64.rpm
261+
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.25.0/pythinker-code-0.25.0.aarch64.rpm
262+
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.25.0/pythinker-code-0.25.0.aarch64.rpm.sha256
263+
sha256sum -c pythinker-code-0.25.0.aarch64.rpm.sha256
264+
sudo dnf install ./pythinker-code-0.25.0.aarch64.rpm
264265
```
265266

266267
Both packages drop a small `/usr/bin/pythinker` launcher that execs the real
@@ -269,8 +270,8 @@ binary under `/usr/lib/pythinker/`, so your `$PATH` stays tidy.
269270
**Verify before install:**
270271

271272
```sh
272-
sha256sum -c pythinker-code_0.24.0_amd64.deb.sha256 # Debian/Ubuntu
273-
sha256sum -c pythinker-code-0.24.0.x86_64.rpm.sha256 # Fedora/RHEL
273+
sha256sum -c pythinker-code_0.25.0_amd64.deb.sha256 # Debian/Ubuntu
274+
sha256sum -c pythinker-code-0.25.0.x86_64.rpm.sha256 # Fedora/RHEL
274275
```
275276

276277
**Upgrade:** download the new `.deb`/`.rpm` from Releases and `dpkg -i` /
@@ -300,7 +301,7 @@ at `~/.local/bin/pythinker`.
300301
curl -fsSL https://pythinker.com/install.sh | bash
301302

302303
# Pin a specific version
303-
curl -fsSL https://pythinker.com/install.sh | bash -s -- --version 0.24.0
304+
curl -fsSL https://pythinker.com/install.sh | bash -s -- --version 0.25.0
304305

305306
# Custom prefix (defaults to $HOME/.local)
306307
curl -fsSL https://pythinker.com/install.sh | bash -s -- --prefix /opt/pythinker

docs/en/guides/getting-started.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ Run the native installation script to complete the installation. The canonical e
3131
curl -fsSL https://pythinker.com/install.sh | bash
3232

3333
# Pin a specific version
34-
curl -fsSL https://pythinker.com/install.sh | bash -s -- --version 0.24.0
34+
curl -fsSL https://pythinker.com/install.sh | bash -s -- --version 0.25.0
3535

3636
# Custom prefix (defaults to $HOME/.local)
3737
curl -fsSL https://pythinker.com/install.sh | bash -s -- --prefix /opt/pythinker
@@ -44,7 +44,7 @@ On Windows, run the PowerShell bootstrap. It downloads the native installer, ver
4444
irm https://pythinker.com/install.ps1 | iex
4545
```
4646

47-
You can also download `PythinkerSetup-0.24.0.exe` manually from the [latest release](https://github.com/TechMatrix-labs/pythinker-code/releases/latest).
47+
You can also download `PythinkerSetup-0.25.0.exe` manually from the [latest release](https://github.com/TechMatrix-labs/pythinker-code/releases/latest).
4848

4949
Verify the installation:
5050

docs/en/release-notes/breaking-changes.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,10 @@
22

33
This page documents breaking changes in Pythinker Code releases and provides migration guidance.
44

5+
## 0.25.0 (2026-05-29)
6+
7+
No breaking changes. This release is compatible with 0.24.0 user configuration, native installs, and session data.
8+
59
## 0.24.0 (2026-05-28)
610

711
No breaking changes. This release is compatible with 0.23.0 user configuration, native installs, and session data.

0 commit comments

Comments
 (0)