Skip to content

Commit 7a66ea1

Browse files
authored
chore(release): prepare 0.26.0 (#24)
Prepare pythinker-code 0.26.0 release.
1 parent 359838a commit 7a66ea1

19 files changed

Lines changed: 83 additions & 54 deletions

File tree

.github/workflows/homebrew-tap.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ on:
77
workflow_dispatch:
88
inputs:
99
version:
10-
description: "Version to push to the tap (e.g. 0.25.0)"
10+
description: "Version to push to the tap (e.g. 0.26.0)"
1111
required: true
1212
type: string
1313

.github/workflows/linux-installer.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ on:
88
workflow_dispatch:
99
inputs:
1010
version:
11-
description: "Version to build (e.g. 0.25.0)"
11+
description: "Version to build (e.g. 0.26.0)"
1212
required: true
1313
type: string
1414

.github/workflows/promote-release.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ on:
1919
workflow_dispatch:
2020
inputs:
2121
tag:
22-
description: "Release tag to promote (e.g. v0.25.0)"
22+
description: "Release tag to promote (e.g. v0.26.0)"
2323
required: true
2424
type: string
2525

.github/workflows/windows-installer.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ on:
88
workflow_dispatch:
99
inputs:
1010
version:
11-
description: "Version to build (e.g. 0.25.0)"
11+
description: "Version to build (e.g. 0.26.0)"
1212
required: true
1313
type: string
1414

CHANGELOG.md

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,19 @@ GitHub Releases page; `0.8.0` is the new starting line.
1515

1616
## Unreleased
1717

18+
## 0.26.0 (2026-05-30)
19+
20+
### What changed in this release
21+
22+
- **Install and update no longer 404 on a freshly published release.** The 0.24.0 "atomic latest" gate turned out to be dead code — it ran only on a `release: published` event that a token-created release never fires, and did not affect `/releases/latest` anyway. The GitHub Release is now created as a **prerelease**, and a new `promote-release.yml` runs on the tag push, waits for every platform asset to finish uploading, then clears the prerelease flag and marks the release latest — the single point at which a version becomes resolvable by installers and the in-app updater. As defense-in-depth, the curl and PowerShell installers now resolve the newest release that actually carries their platform asset (skipping drafts and prereleases) and wait for the archive plus checksum before downloading, so `irm | iex` / `curl | bash` run during the publish window no longer fail on a missing `PythinkerSetup-<ver>.exe` or archive.
23+
- **OpenCode Go model catalog refreshes on every startup without a re-login.** Bundled catalog changes — new models, corrected provider shapes — previously reached an existing install only after a manual `pythinker login --opencode-go`. OpenCode Go is now wired into the every-startup `refresh_managed_models` task with its own discovery and a dedicated apply that upserts and prunes across both its OpenAI- and Anthropic-shaped providers while preserving your `default_model` and `default_thinking`. Discovery failures are isolated so they cannot abort other providers' saves; provider `base_url` repairs still require a re-login.
24+
- **Homebrew install shows the logo and fails fast on a missing tap token.** `brew install` now prints the robot-head banner via a formula `caveats` block — the banner previously lived only in the curl and PowerShell installers, which Homebrew never runs. The tap auto-update workflow now detects an empty `HOMEBREW_TAP_TOKEN` (lost in the org migration, which had frozen the tap at 0.23.0) and fails with an actionable error instead of an opaque git exit-128.
25+
- **Markdown and report rendering hardened against real model output.** Code-span pipes inside Markdown tables are now protected so a `|` inside backticks no longer fractures the table, and a `report` block nested inside an outer documentation fence is no longer wrongly promoted to a report — report fences are extracted via a markdown-it AST walk instead of a flat regex. Backed by a new TUI markdown/report contract test suite grounded in a real security-scan fixture.
26+
- **Steadier agent editing and a restored update prompt.** File-replace edit handling is hardened, subagent prompt persistence and the agent's working language are preserved across turns, and the todo list stays aligned during a turn. The blocking pre-start update prompt — wired in 0.24.0 but again left unwired by a later refactor — is restored so it runs before every interactive session.
27+
- **CI runs required checks on every pull request.** The `check`, `test`, and `release-validate` contexts were path-filtered off docs-only (and `sdks/`/`examples/`-only) PRs, so the required statuses never reported and those PRs stayed BLOCKED under branch protection with no clean override. The `pull_request` path filter is dropped so every PR runs each required context exactly once; the `push` trigger keeps its filter unchanged.
28+
29+
Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.26.0`, or use the native installer for your OS (see the README install table).
30+
1831
## 0.25.0 (2026-05-29)
1932

2033
### What changed in this release

README.md

Lines changed: 25 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -50,16 +50,15 @@ It speaks the [**Agent Client Protocol (ACP)**](https://github.com/agentclientpr
5050
5151
---
5252

53-
## 🆕 What's New in 0.25.0
53+
## 🆕 What's New in 0.26.0
5454

55-
- **`Fetch` re-checks every redirect hop against the SSRF guard.** Redirects were followed without re-validating the destination, so a public URL could redirect to a link-local address (e.g. a cloud metadata endpoint) and slip past the guard. Every hop is now re-validated, closing the public→link-local bypass.
56-
- **Web domain allowlist for `Fetch` and `Search`.** Set `web.allowed_domains` to restrict which hosts the web tools may reach — `Fetch` (every redirect hop included) and `Search` reject anything off the list. Leave it unset to keep web access unrestricted.
57-
- **Crash-consistent background tasks.** Task state is serialised under a cross-process lock, terminal updates route through a single finalizer, and recovery reconciles records left divergent by a crash or kill without clobbering a live agent. Bash output is capped (default 50 MiB), kills escalate SIGTERM→SIGKILL, and aged terminal tasks are pruned (default 7 days).
58-
- **Calmer TUI with live tool feedback.** Tool calls show a "preparing" row during approval, stream shell output as a running tail, and render a live Markdown preview as the model writes. The todo list no longer renders twice mid-turn, links open through a detached launcher, and the terminal is restored to a sane state on `SIGTERM`/`SIGQUIT` and at exit.
59-
- **Steadier agent loop.** The model is nudged when a turn ends on a bare statement of intent, steered away from blocking on one background task while siblings run, and a `SetTodoList` whose todos arrive as a JSON string is parsed transparently instead of failing validation.
60-
- **Unified report rendering.** Code review, verify, and security-review output share one standardized renderer, including `report` blocks emitted by skills and agents.
55+
- **Install and update no longer 404 on a freshly published release.** Releases are now published as a prerelease and promoted to "latest" only once every platform asset has uploaded, and the curl/PowerShell installers wait for their archive + checksum before downloading — so `irm | iex` / `curl | bash` run mid-publish no longer fail on a missing installer.
56+
- **OpenCode Go model catalog refreshes on startup without a re-login.** Bundled catalog changes (new models, corrected provider shapes) now reach existing installs through the every-startup refresh, across both OpenAI- and Anthropic-shaped providers, while preserving your default model and thinking settings.
57+
- **Homebrew install shows the logo and fails fast on a missing tap token.** `brew install` now prints the robot-head banner via formula caveats, and the tap workflow reports an actionable error when `HOMEBREW_TAP_TOKEN` is missing instead of an opaque git failure.
58+
- **Markdown and report rendering hardened against real model output.** Code-span pipes inside tables no longer fracture the table, and a `report` block nested inside a documentation fence is no longer wrongly promoted — report fences are now extracted via a markdown-it AST walk.
59+
- **Steadier agent editing and a restored update prompt.** File-replace edit handling is hardened, subagent prompt persistence and the agent's working language are preserved, and the blocking pre-start update prompt is restored so it runs before every interactive session.
6160

62-
Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.25.0`, or use the native installer for your platform from the [Releases page](https://github.com/TechMatrix-labs/pythinker-code/releases/latest).
61+
Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.26.0`, or use the native installer for your platform from the [Releases page](https://github.com/TechMatrix-labs/pythinker-code/releases/latest).
6362

6463

6564
---
@@ -149,7 +148,7 @@ matches your OS — no Python, Node, or `uv` prerequisite.
149148

150149
| Platform | Recommended install | Artifact source |
151150
|---|---|---|
152-
| **🪟 Windows** | `irm https://pythinker.com/install.ps1 \| iex` | `PythinkerSetup-0.25.0.exe` from [Releases](https://github.com/TechMatrix-labs/pythinker-code/releases/latest) |
151+
| **🪟 Windows** | `irm https://pythinker.com/install.ps1 \| iex` | `PythinkerSetup-0.26.0.exe` from [Releases](https://github.com/TechMatrix-labs/pythinker-code/releases/latest) |
153152
| **<img src="https://img.shields.io/badge/-macOS-000000?style=flat-square&logo=apple&logoColor=white" alt="macOS"> / <img src="https://img.shields.io/badge/-Linux-FCC624?style=flat-square&logo=linux&logoColor=black" alt="Linux">** | `curl -fsSL https://pythinker.com/install.sh \| bash` | native tarball from [Releases](https://github.com/TechMatrix-labs/pythinker-code/releases/latest) |
154153
| **<img src="https://img.shields.io/badge/-macOS-000000?style=flat-square&logo=apple&logoColor=white" alt="macOS"> — Homebrew** | `brew install TechMatrix-labs/pythinker/pythinker-code` | auto-published Homebrew tap |
155154
| **<img src="https://img.shields.io/badge/-Linux-FCC624?style=flat-square&logo=linux&logoColor=black" alt="Linux"> — system package** | Download the `.deb` or `.rpm` for your distro below | [Releases](https://github.com/TechMatrix-labs/pythinker-code/releases/latest) |
@@ -174,7 +173,7 @@ pythinker # start the interactive TUI
174173

175174
### 🪟 Windows — native installer
176175

177-
`PythinkerSetup-0.25.0.exe` is a signed* Inno Setup wizard. Installs per-user
176+
`PythinkerSetup-0.26.0.exe` is a signed* Inno Setup wizard. Installs per-user
178177
into `%LOCALAPPDATA%\Programs\Pythinker`, registers `pythinker` on your user
179178
PATH (`HKCU\Environment`), broadcasts `WM_SETTINGCHANGE` so new shells see
180179
the change. **No UAC prompt.**
@@ -185,13 +184,13 @@ irm https://pythinker.com/install.ps1 | iex
185184
186185
# Or manually download the installer + checksum from the Releases page,
187186
# verify with Get-FileHash, then run:
188-
.\PythinkerSetup-0.25.0.exe
187+
.\PythinkerSetup-0.26.0.exe
189188
190189
# Open a fresh PowerShell
191190
pythinker --version
192191
```
193192

194-
**Per-machine install** (IT-managed boxes): `.\PythinkerSetup-0.25.0.exe /ALLUSERS`
193+
**Per-machine install** (IT-managed boxes): `.\PythinkerSetup-0.26.0.exe /ALLUSERS`
195194
installs to `%ProgramFiles%\Pythinker` and writes PATH to HKLM (requires admin).
196195

197196
**Upgrade:** `pythinker update` from inside the running app — it downloads
@@ -242,26 +241,26 @@ attached to every GitHub Release.
242241

243242
```sh
244243
# Debian / Ubuntu (x86_64)
245-
sudo dpkg -i pythinker-code_0.25.0_amd64.deb
244+
sudo dpkg -i pythinker-code_0.26.0_amd64.deb
246245
sudo apt-get install -f # only if dpkg reports missing deps
247246

248247
# Debian / Ubuntu (ARM64)
249-
sudo dpkg -i pythinker-code_0.25.0_arm64.deb
248+
sudo dpkg -i pythinker-code_0.26.0_arm64.deb
250249

251250
# Fedora / RHEL / openSUSE (x86_64)
252-
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.25.0/pythinker-code-0.25.0.x86_64.rpm
253-
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.25.0/pythinker-code-0.25.0.x86_64.rpm.sha256
254-
sha256sum -c pythinker-code-0.25.0.x86_64.rpm.sha256
251+
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.26.0/pythinker-code-0.26.0.x86_64.rpm
252+
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.26.0/pythinker-code-0.26.0.x86_64.rpm.sha256
253+
sha256sum -c pythinker-code-0.26.0.x86_64.rpm.sha256
255254
# Fedora / RHEL:
256-
sudo dnf install ./pythinker-code-0.25.0.x86_64.rpm
255+
sudo dnf install ./pythinker-code-0.26.0.x86_64.rpm
257256
# openSUSE:
258-
sudo zypper install ./pythinker-code-0.25.0.x86_64.rpm
257+
sudo zypper install ./pythinker-code-0.26.0.x86_64.rpm
259258

260259
# Fedora / RHEL (aarch64)
261-
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.25.0/pythinker-code-0.25.0.aarch64.rpm
262-
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.25.0/pythinker-code-0.25.0.aarch64.rpm.sha256
263-
sha256sum -c pythinker-code-0.25.0.aarch64.rpm.sha256
264-
sudo dnf install ./pythinker-code-0.25.0.aarch64.rpm
260+
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.26.0/pythinker-code-0.26.0.aarch64.rpm
261+
curl -LO https://github.com/TechMatrix-labs/pythinker-code/releases/download/v0.26.0/pythinker-code-0.26.0.aarch64.rpm.sha256
262+
sha256sum -c pythinker-code-0.26.0.aarch64.rpm.sha256
263+
sudo dnf install ./pythinker-code-0.26.0.aarch64.rpm
265264
```
266265

267266
Both packages drop a small `/usr/bin/pythinker` launcher that execs the real
@@ -270,8 +269,8 @@ binary under `/usr/lib/pythinker/`, so your `$PATH` stays tidy.
270269
**Verify before install:**
271270

272271
```sh
273-
sha256sum -c pythinker-code_0.25.0_amd64.deb.sha256 # Debian/Ubuntu
274-
sha256sum -c pythinker-code-0.25.0.x86_64.rpm.sha256 # Fedora/RHEL
272+
sha256sum -c pythinker-code_0.26.0_amd64.deb.sha256 # Debian/Ubuntu
273+
sha256sum -c pythinker-code-0.26.0.x86_64.rpm.sha256 # Fedora/RHEL
275274
```
276275

277276
**Upgrade:** download the new `.deb`/`.rpm` from Releases and `dpkg -i` /
@@ -301,7 +300,7 @@ at `~/.local/bin/pythinker`.
301300
curl -fsSL https://pythinker.com/install.sh | bash
302301

303302
# Pin a specific version
304-
curl -fsSL https://pythinker.com/install.sh | bash -s -- --version 0.25.0
303+
curl -fsSL https://pythinker.com/install.sh | bash -s -- --version 0.26.0
305304

306305
# Custom prefix (defaults to $HOME/.local)
307306
curl -fsSL https://pythinker.com/install.sh | bash -s -- --prefix /opt/pythinker

docs/en/guides/getting-started.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ Run the native installation script to complete the installation. The canonical e
3131
curl -fsSL https://pythinker.com/install.sh | bash
3232

3333
# Pin a specific version
34-
curl -fsSL https://pythinker.com/install.sh | bash -s -- --version 0.25.0
34+
curl -fsSL https://pythinker.com/install.sh | bash -s -- --version 0.26.0
3535

3636
# Custom prefix (defaults to $HOME/.local)
3737
curl -fsSL https://pythinker.com/install.sh | bash -s -- --prefix /opt/pythinker
@@ -44,7 +44,7 @@ On Windows, run the PowerShell bootstrap. It downloads the native installer, ver
4444
irm https://pythinker.com/install.ps1 | iex
4545
```
4646

47-
You can also download `PythinkerSetup-0.25.0.exe` manually from the [latest release](https://github.com/TechMatrix-labs/pythinker-code/releases/latest).
47+
You can also download `PythinkerSetup-0.26.0.exe` manually from the [latest release](https://github.com/TechMatrix-labs/pythinker-code/releases/latest).
4848

4949
Verify the installation:
5050

docs/en/release-notes/breaking-changes.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,10 @@
22

33
This page documents breaking changes in Pythinker Code releases and provides migration guidance.
44

5+
## 0.26.0 (2026-05-30)
6+
7+
No breaking changes. This release is compatible with 0.25.0 user configuration, native installs, and session data.
8+
59
## 0.25.0 (2026-05-29)
610

711
No breaking changes. This release is compatible with 0.24.0 user configuration, native installs, and session data.

docs/en/release-notes/changelog.md

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,19 @@ GitHub Releases page; `0.8.0` is the new starting line.
1717

1818
## Unreleased
1919

20+
## 0.26.0 (2026-05-30)
21+
22+
### What changed in this release
23+
24+
- **Install and update no longer 404 on a freshly published release.** The 0.24.0 "atomic latest" gate turned out to be dead code — it ran only on a `release: published` event that a token-created release never fires, and did not affect `/releases/latest` anyway. The GitHub Release is now created as a **prerelease**, and a new `promote-release.yml` runs on the tag push, waits for every platform asset to finish uploading, then clears the prerelease flag and marks the release latest — the single point at which a version becomes resolvable by installers and the in-app updater. As defense-in-depth, the curl and PowerShell installers now resolve the newest release that actually carries their platform asset (skipping drafts and prereleases) and wait for the archive plus checksum before downloading, so `irm | iex` / `curl | bash` run during the publish window no longer fail on a missing `PythinkerSetup-<ver>.exe` or archive.
25+
- **OpenCode Go model catalog refreshes on every startup without a re-login.** Bundled catalog changes — new models, corrected provider shapes — previously reached an existing install only after a manual `pythinker login --opencode-go`. OpenCode Go is now wired into the every-startup `refresh_managed_models` task with its own discovery and a dedicated apply that upserts and prunes across both its OpenAI- and Anthropic-shaped providers while preserving your `default_model` and `default_thinking`. Discovery failures are isolated so they cannot abort other providers' saves; provider `base_url` repairs still require a re-login.
26+
- **Homebrew install shows the logo and fails fast on a missing tap token.** `brew install` now prints the robot-head banner via a formula `caveats` block — the banner previously lived only in the curl and PowerShell installers, which Homebrew never runs. The tap auto-update workflow now detects an empty `HOMEBREW_TAP_TOKEN` (lost in the org migration, which had frozen the tap at 0.23.0) and fails with an actionable error instead of an opaque git exit-128.
27+
- **Markdown and report rendering hardened against real model output.** Code-span pipes inside Markdown tables are now protected so a `|` inside backticks no longer fractures the table, and a `report` block nested inside an outer documentation fence is no longer wrongly promoted to a report — report fences are extracted via a markdown-it AST walk instead of a flat regex. Backed by a new TUI markdown/report contract test suite grounded in a real security-scan fixture.
28+
- **Steadier agent editing and a restored update prompt.** File-replace edit handling is hardened, subagent prompt persistence and the agent's working language are preserved across turns, and the todo list stays aligned during a turn. The blocking pre-start update prompt — wired in 0.24.0 but again left unwired by a later refactor — is restored so it runs before every interactive session.
29+
- **CI runs required checks on every pull request.** The `check`, `test`, and `release-validate` contexts were path-filtered off docs-only (and `sdks/`/`examples/`-only) PRs, so the required statuses never reported and those PRs stayed BLOCKED under branch protection with no clean override. The `pull_request` path filter is dropped so every PR runs each required context exactly once; the `push` trigger keeps its filter unchanged.
30+
31+
Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.26.0`, or use the native installer for your OS (see the README install table).
32+
2033
## 0.25.0 (2026-05-29)
2134

2235
### What changed in this release

docs/public/install.ps1

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
# irm https://pythinker.com/install.ps1 | iex
88
#
99
# To pin a version when running the hosted script, set:
10-
# $env:PYTHINKER_VERSION = "0.25.0"; irm https://pythinker.com/install.ps1 | iex
10+
# $env:PYTHINKER_VERSION = "0.26.0"; irm https://pythinker.com/install.ps1 | iex
1111

1212
$ErrorActionPreference = "Stop"
1313

0 commit comments

Comments
 (0)