Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ wheels/
.vscode
.env
.env.local
AGENTS.local
/tests_local
uv.toml
.idea/*
Expand Down
7 changes: 7 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,13 @@ This file is the root guidance for AI agents working in this repository. It is i
Pythinker sessions via `PYTHINKER_AGENTS_MD`; keep it durable, portable, and focused on rules
that should apply across many tasks.

## Local-only instructions

If `AGENTS.local` exists at the repository root, read it after this file for machine-specific or
private local instructions. `AGENTS.local` is intentionally gitignored; do not commit it or copy its
contents into tracked files. Local instructions may add workflow details, but they must not weaken
or override this repository's non-negotiable rules.

## Mission

Pythinker CLI is a Python CLI agent for software engineering workflows. It supports an
Expand Down
8 changes: 8 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,14 @@ GitHub Releases page; `0.8.0` is the new starting line.

## Unreleased

## 0.36.0 (2026-06-05)

- **Alibaba DashScope multi-region fallback.** Logging in with a China-region key (`dashscope.aliyuncs.com`) against the default US Virginia endpoint now auto-detects the mismatch and reconfigures for the correct endpoint rather than failing with a misleading "API key is wrong" error.
- **Alibaba Token Plan compatibility (`sk-ws-`).** `/login alibaba` now requires the dedicated workspace Base URL shown in the Token Plan console instead of accepting a public `/models` response as credential validation. Dedicated workspace endpoints hide Kimi K2.6 when Alibaba advertises it without a working route, and use non-streaming Chat Completions for DeepSeek V3.2 because those endpoints return an empty SSE stream. Kimi requests on other Alibaba routes use DashScope's `enable_thinking` parameter.
- **Alibaba model catalog refresh.** Added Qwen3.7 Plus (1M context), Qwen3 Coder Plus, and Qwen3 Coder Flash. Removed `kimi-k2.5`, `glm-5`, and `MiniMax-M2.5` (absent from the live endpoint). Corrected Qwen3.7 Max context window to 1M tokens.

Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.36.0`, or use the native installer for your platform from the [Releases page](https://github.com/Pythoughts-labs/pythinker-code/releases/latest).

## 0.35.0 (2026-06-04)

- **Alibaba DashScope provider and MiniMax M3 catalog.** `/login alibaba` now configures Alibaba Cloud Model Studio / DashScope Token Plan models, including workspace-compatible endpoints and native GLM thinking behavior. MiniMax API-key login now defaults to MiniMax M3 with its larger context and multimodal capabilities.
Expand Down
44 changes: 22 additions & 22 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,13 +50,13 @@ It speaks the [**Agent Client Protocol (ACP)**](https://github.com/agentclientpr

---

## 🆕 What's New in 0.35.0
## 🆕 What's New in 0.36.0

- **`/stats` usage dashboard.** New slash command opens an interactive TUI showing token and cost breakdown by provider/model across Today / This Week / Last Week / All Time. Powered by a static pricing table and a session collector that walks `~/.pythinker/sessions/` wire files.
- **Z AI provider auth.** Login/logout via API key, model discovery, and OAuth selector wired into the TUI and `refresh_managed_models`.
- **Moonshot provider auth.** Login/logout via API key, model discovery (Kimi K2.x catalog), OAuth selector wired into the TUI and `refresh_managed_models`.
- **Alibaba DashScope multi-region fallback.** China-region keys now auto-detect the endpoint mismatch and reconfigure correctly instead of showing a misleading "API key is wrong" error.
- **Alibaba Token Plan compatibility (`sk-ws-`).** `/login alibaba` now asks for the dedicated workspace endpoint, avoids unroutable Kimi entries on those endpoints, and uses DeepSeek V3.2's working non-streaming mode.
- **Alibaba model catalog refresh.** Qwen3.7 Plus, Qwen3 Coder Plus, and Qwen3 Coder Flash added; deprecated `kimi-k2.5`, `glm-5`, and `MiniMax-M2.5` removed.

Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.35.0`, or use the native installer for your platform from the [Releases page](https://github.com/Pythoughts-labs/pythinker-code/releases/latest).
Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.36.0`, or use the native installer for your platform from the [Releases page](https://github.com/Pythoughts-labs/pythinker-code/releases/latest).


---
Expand Down Expand Up @@ -146,7 +146,7 @@ matches your OS — no Python, Node, or `uv` prerequisite.

| Platform | Recommended install | Artifact source |
|---|---|---|
| **🪟 Windows** | `irm https://pythinker.com/install.ps1 \| iex` | `PythinkerSetup-0.35.0.exe` from [Releases](https://github.com/Pythoughts-labs/pythinker-code/releases/latest) |
| **🪟 Windows** | `irm https://pythinker.com/install.ps1 \| iex` | `PythinkerSetup-0.36.0.exe` from [Releases](https://github.com/Pythoughts-labs/pythinker-code/releases/latest) |
| **<img src="https://img.shields.io/badge/-macOS-000000?style=flat-square&logo=apple&logoColor=white" alt="macOS"> / <img src="https://img.shields.io/badge/-Linux-FCC624?style=flat-square&logo=linux&logoColor=black" alt="Linux">** | `curl -fsSL https://pythinker.com/install.sh \| bash` | native tarball from [Releases](https://github.com/Pythoughts-labs/pythinker-code/releases/latest) |
| **<img src="https://img.shields.io/badge/-macOS-000000?style=flat-square&logo=apple&logoColor=white" alt="macOS"> — Homebrew** | `brew install Pythoughts-labs/pythinker/pythinker-code` | auto-published Homebrew tap |
| **🐳 Docker** | `docker run --rm -it ghcr.io/pythoughts-labs/pythinker-code` | GHCR multi-arch image |
Expand Down Expand Up @@ -174,7 +174,7 @@ pythinker # start the interactive TUI

### 🪟 Windows — native installer

`PythinkerSetup-0.35.0.exe` is a signed* Inno Setup wizard. Installs per-user
`PythinkerSetup-0.36.0.exe` is a signed* Inno Setup wizard. Installs per-user
into `%LOCALAPPDATA%\Programs\Pythinker`, registers `pythinker` on your user
PATH (`HKCU\Environment`), broadcasts `WM_SETTINGCHANGE` so new shells see
the change. **No UAC prompt.**
Expand All @@ -185,13 +185,13 @@ irm https://pythinker.com/install.ps1 | iex

# Or manually download the installer + checksum from the Releases page,
# verify with Get-FileHash, then run:
.\PythinkerSetup-0.35.0.exe
.\PythinkerSetup-0.36.0.exe

# Open a fresh PowerShell
pythinker --version
```

**Per-machine install** (IT-managed boxes): `.\PythinkerSetup-0.35.0.exe /ALLUSERS`
**Per-machine install** (IT-managed boxes): `.\PythinkerSetup-0.36.0.exe /ALLUSERS`
installs to `%ProgramFiles%\Pythinker` and writes PATH to HKLM (requires admin).

**Upgrade:** `pythinker update` from inside the running app — it downloads
Expand Down Expand Up @@ -242,26 +242,26 @@ attached to every GitHub Release.

```sh
# Debian / Ubuntu (x86_64)
sudo dpkg -i pythinker-code_0.35.0_amd64.deb
sudo dpkg -i pythinker-code_0.36.0_amd64.deb
sudo apt-get install -f # only if dpkg reports missing deps

# Debian / Ubuntu (ARM64)
sudo dpkg -i pythinker-code_0.35.0_arm64.deb
sudo dpkg -i pythinker-code_0.36.0_arm64.deb

# Fedora / RHEL / openSUSE (x86_64)
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.35.0/pythinker-code-0.35.0.x86_64.rpm
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.35.0/pythinker-code-0.35.0.x86_64.rpm.sha256
sha256sum -c pythinker-code-0.35.0.x86_64.rpm.sha256
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.36.0/pythinker-code-0.36.0.x86_64.rpm
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.36.0/pythinker-code-0.36.0.x86_64.rpm.sha256
sha256sum -c pythinker-code-0.36.0.x86_64.rpm.sha256
# Fedora / RHEL:
sudo dnf install ./pythinker-code-0.35.0.x86_64.rpm
sudo dnf install ./pythinker-code-0.36.0.x86_64.rpm
# openSUSE:
sudo zypper install ./pythinker-code-0.35.0.x86_64.rpm
sudo zypper install ./pythinker-code-0.36.0.x86_64.rpm

# Fedora / RHEL (aarch64)
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.35.0/pythinker-code-0.35.0.aarch64.rpm
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.35.0/pythinker-code-0.35.0.aarch64.rpm.sha256
sha256sum -c pythinker-code-0.35.0.aarch64.rpm.sha256
sudo dnf install ./pythinker-code-0.35.0.aarch64.rpm
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.36.0/pythinker-code-0.36.0.aarch64.rpm
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.36.0/pythinker-code-0.36.0.aarch64.rpm.sha256
sha256sum -c pythinker-code-0.36.0.aarch64.rpm.sha256
sudo dnf install ./pythinker-code-0.36.0.aarch64.rpm
```

Both packages drop a small `/usr/bin/pythinker` launcher that execs the real
Expand All @@ -270,8 +270,8 @@ binary under `/usr/lib/pythinker/`, so your `$PATH` stays tidy.
**Verify before install:**

```sh
sha256sum -c pythinker-code_0.35.0_amd64.deb.sha256 # Debian/Ubuntu
sha256sum -c pythinker-code-0.35.0.x86_64.rpm.sha256 # Fedora/RHEL
sha256sum -c pythinker-code_0.36.0_amd64.deb.sha256 # Debian/Ubuntu
sha256sum -c pythinker-code-0.36.0.x86_64.rpm.sha256 # Fedora/RHEL
```

**Upgrade:** download the new `.deb`/`.rpm` from Releases and `dpkg -i` /
Expand Down
2 changes: 1 addition & 1 deletion docs/en/guides/getting-started.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ On Windows, run the PowerShell bootstrap. It downloads the native installer, ver
irm https://pythinker.com/install.ps1 | iex
```

You can also download `PythinkerSetup-0.35.0.exe` manually from the [latest release](https://github.com/Pythoughts-labs/pythinker-code/releases/latest).
You can also download `PythinkerSetup-0.36.0.exe` manually from the [latest release](https://github.com/Pythoughts-labs/pythinker-code/releases/latest).

Verify the installation:

Expand Down
4 changes: 4 additions & 0 deletions docs/en/release-notes/breaking-changes.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@ This page documents breaking changes in Pythinker Code releases and provides mig

## Unreleased

## 0.36.0 (2026-06-05)

No breaking changes. This release is compatible with 0.35.0 user configuration, native installs, and session data.

## 0.35.0 (2026-06-04)

## 0.34.0 (2026-06-03)
Expand Down
8 changes: 8 additions & 0 deletions docs/en/release-notes/changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,14 @@ GitHub Releases page; `0.8.0` is the new starting line.

## Unreleased

## 0.36.0 (2026-06-05)

- **Alibaba DashScope multi-region fallback.** Logging in with a China-region key (`dashscope.aliyuncs.com`) against the default US Virginia endpoint now auto-detects the mismatch and reconfigures for the correct endpoint rather than failing with a misleading "API key is wrong" error.
- **Alibaba Token Plan compatibility (`sk-ws-`).** `/login alibaba` now requires the dedicated workspace Base URL shown in the Token Plan console instead of accepting a public `/models` response as credential validation. Dedicated workspace endpoints hide Kimi K2.6 when Alibaba advertises it without a working route, and use non-streaming Chat Completions for DeepSeek V3.2 because those endpoints return an empty SSE stream. Kimi requests on other Alibaba routes use DashScope's `enable_thinking` parameter.
- **Alibaba model catalog refresh.** Added Qwen3.7 Plus (1M context), Qwen3 Coder Plus, and Qwen3 Coder Flash. Removed `kimi-k2.5`, `glm-5`, and `MiniMax-M2.5` (absent from the live endpoint). Corrected Qwen3.7 Max context window to 1M tokens.

Upgrade with `pythinker update`, `pip install --upgrade pythinker-code==0.36.0`, or use the native installer for your platform from the [Releases page](https://github.com/Pythoughts-labs/pythinker-code/releases/latest).

Comment thread
elkaix marked this conversation as resolved.
## 0.35.0 (2026-06-04)

- **Alibaba DashScope provider and MiniMax M3 catalog.** `/login alibaba` now configures Alibaba Cloud Model Studio / DashScope Token Plan models, including workspace-compatible endpoints and native GLM thinking behavior. MiniMax API-key login now defaults to MiniMax M3 with its larger context and multimodal capabilities.
Expand Down
26 changes: 13 additions & 13 deletions packages/linux-installer/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,19 +8,19 @@ End-user install from the current GitHub Release:

```sh
# Debian / Ubuntu
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.35.0/pythinker-code_0.35.0_amd64.deb
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.35.0/pythinker-code_0.35.0_amd64.deb.sha256
sha256sum -c pythinker-code_0.35.0_amd64.deb.sha256
sudo dpkg -i pythinker-code_0.35.0_amd64.deb
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.36.0/pythinker-code_0.36.0_amd64.deb
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.36.0/pythinker-code_0.36.0_amd64.deb.sha256
sha256sum -c pythinker-code_0.36.0_amd64.deb.sha256
sudo dpkg -i pythinker-code_0.36.0_amd64.deb
sudo apt-get install -f # only needed if dependencies fail to resolve

# Fedora / RHEL / openSUSE
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.35.0/pythinker-code-0.35.0.x86_64.rpm
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.35.0/pythinker-code-0.35.0.x86_64.rpm.sha256
sha256sum -c pythinker-code-0.35.0.x86_64.rpm.sha256
sudo dnf install ./pythinker-code-0.35.0.x86_64.rpm
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.36.0/pythinker-code-0.36.0.x86_64.rpm
curl -LO https://github.com/Pythoughts-labs/pythinker-code/releases/download/v0.36.0/pythinker-code-0.36.0.x86_64.rpm.sha256
sha256sum -c pythinker-code-0.36.0.x86_64.rpm.sha256
sudo dnf install ./pythinker-code-0.36.0.x86_64.rpm
# or, on openSUSE:
sudo zypper install ./pythinker-code-0.35.0.x86_64.rpm
sudo zypper install ./pythinker-code-0.36.0.x86_64.rpm
```

The package drops a single executable at `/usr/bin/pythinker` and a license
Expand All @@ -36,17 +36,17 @@ file at `/usr/share/doc/pythinker-code/LICENSE`.
## Build

```sh
bash packages/linux-installer/build.sh 0.35.0
bash packages/linux-installer/build.sh 0.36.0
```

Outputs to `dist/`:

- `pythinker-code_0.35.0_amd64.deb`
- `pythinker-code-0.35.0.x86_64.rpm`
- `pythinker-code_0.36.0_amd64.deb`
- `pythinker-code-0.36.0.x86_64.rpm`

The portable tarball used by `scripts/install-native.sh` is published by
the existing `release-pythinker-cli.yml` workflow under the cargo-dist
target-triple naming (e.g. `pythinker-0.35.0-x86_64-unknown-linux-gnu.tar.gz`).
target-triple naming (e.g. `pythinker-0.36.0-x86_64-unknown-linux-gnu.tar.gz`).

## CI

Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[project]
name = "pythinker-code"
version = "0.35.0"
version = "0.36.0"
description = "Pythinker — an agentic CLI developed by Pythoughts-labs."
readme = "README.md"
requires-python = ">=3.12"
Expand Down
2 changes: 2 additions & 0 deletions src/pythinker_code/agents/default/code_reviewer.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,8 @@ agent:
- Build a review context packet: base ref/diff scope or Reviewflow feature IDs, changed behavior, likely tests, user-visible impact, valid evidence paths, omitted/truncated context, and validation evidence.
- Flag only issues introduced or made reachable by the diff.
- Prefer no finding over vague speculation. Every finding must cite concrete evidence and a failure mode.
- Run the production guardrail gate before finalizing: check for cache stampedes, connection/resource leaks, missing boundary schemas, unhandled race conditions, naive retry loops, unbounded event callbacks/listeners, and IDOR/tenant-scope mistakes.
- Treat missing `finally` cleanup, absent schema validation at trust boundaries, unprotected shared-state mutation, non-jittered immediate retries, or identity from mutable client parameters as reject-level findings when reachable in the changed code.

Freshness check (run BEFORE flagging third-party library or framework misuse):
- For every third-party API, SDK call, framework primitive, or "best practice" the diff turns on, verify the current canonical usage. Prefer a context7 MCP query (e.g. `mcp__context7__query-docs` with the library id) when registered with the parent runtime; otherwise use `SearchWeb` to locate the official documentation and `FetchURL` to read the current page.
Expand Down
1 change: 1 addition & 0 deletions src/pythinker_code/agents/default/judge.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ agent:
- Fidelity: the draft summary matches the actual diff and changes, with no overclaiming.
- Verification: the checks the parent ran are relevant to the change and actually ran, not assumed.
- Safety and scope: no unsafe or destructive action, no secret or PII exposure, no scope creep beyond the request.
- Production guardrails: changed code that touches caches, resources, trust boundaries, shared state, outbound requests, long-lived listeners, or authorization context has explicit defenses for stampedes, cleanup, schemas, races, retry storms, leaks, and IDOR risks.
- Findings quality: for reports, each finding is actionable, correctly severity-ranked, and anchored to evidence.
Do not rubber-stamp, and do not pad: prefer a few concrete blockers over broad style notes.

Expand Down
2 changes: 2 additions & 0 deletions src/pythinker_code/agents/default/review.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,8 @@ agent:
- If `.pythinker/review-guidelines.md` exists, read it before scoring findings.
- Read the diff or target files before scoring.
- Use Grep/Glob to check sibling call sites, similar patterns, and existing tests.
- Apply the production guardrail gate: look specifically for cache stampedes, connection/resource leaks, missing boundary schemas, unhandled race conditions, naive retry loops, unbounded event callbacks/listeners, and IDOR/tenant-scope mistakes.
- Reject happy-path code as BLOCKER or MAJOR when the changed path mutates shared state, crosses a trust boundary, acquires resources, retries outbound calls, or registers long-lived callbacks without the matching defensive pattern.
- Score each finding as BLOCKER, MAJOR, MINOR, or NIT.
- Order findings by severity, BLOCKER first.
- Do not request tests unless they cover a distinct behavior or risk introduced by the change.
Expand Down
1 change: 1 addition & 0 deletions src/pythinker_code/agents/default/security_reviewer.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ agent:

Security review discipline:
- Build a threat context before judging: changed trust boundaries, inputs/outputs, authz/authn, filesystem/network access, secrets, serialization, command execution, and persistence.
- Apply the production guardrail gate to security-relevant changes: reject missing boundary schemas, IDOR/tenant-scope mistakes, unprotected shared-state mutations, unsafe retries for non-idempotent outbound calls, and resource leaks that can become denial-of-service vectors.
- Report only reachable or plausibly reachable vulnerabilities backed by evidence. Prefer no finding over speculative risk.
- For each finding, include exploit preconditions, impact, severity rationale, and the smallest safe mitigation.
- Treat secrets/PII carefully: never print raw secret values; redact if needed.
Expand Down
Loading
Loading