- User-cancelled streams now remain cancelled when provider socket shutdown appears as a clean end-of-stream.
- Partial tool calls from cancelled generations remain non-executable and cannot enter automatic incomplete-stream recovery.
- Provider terminal markers take precedence over late cancellation, preserving already-completed responses.
Changelog Momentum, made visible
What changed, and when.
Selected reviewed release milestones from committed metadata. Linked release pages provide their available notes and source; the current release also publishes checksums, SBOM, and provenance.
- macOS code intelligence and session resume now share one protected system-alias identity.
- Repository-controlled and user-owned symlink paths remain outside that narrow compatibility rule.
- Package CI verifies the release archive beside its basename-scoped checksum file.
- macOS workspaces now accept protected system path aliases while repository-controlled symlinks remain blocked.
- Clean source checkouts generate deterministic runtime SBOMs without importing or executing package code.
- Python 3.10 and subscription preflight release gates are now deterministic across CI runners.
- Audited model routing keeps native and subscription modes explicit and consistent.
- Provider and MCP credentials are now endpoint-bound and fail closed; older unbound CLI keys may need to be entered once again.
- Release provenance, public-site inventory, and deployment gates bind published bytes to reviewed source.
- A refined full-screen terminal experience for long-running agent work.
- Smoother concurrent TUI rendering while an agent keeps working.
- Release archives rebuilt and verified against the published source.
- Correct context budgeting when a resumed session stored the 32k default.
- Resume behavior now preserves the configured model window exactly.
- Site and release manifests promoted from the same verified bytes.
- Standing goals, autonomous verification gates, and continuation handoffs.
- Persistent Python code-action mode and scrubbed training export.
- A structured VS Code/Cursor surface for goals, tools, diffs, and plans.
- Follow-up reliability fixes after the 0.21 security release.
- Tighter provider and session edge-case handling.
- Published checksums and reproducible release metadata.
- OS sandboxing and canonical workspace confinement.
- Expanded permission rules, hooks, MCP, and tool-output boundaries.
- Security-focused hardening across the terminal and editor protocols.
- Local and OpenAI-compatible provider setup from one CLI.
- Permission modes, plan review, artifacts, sessions, and model switching.
- A stable baseline for subsequent reliability and interface releases.
Extension VS Code · Cursor
Editor releases.
- Protocol v5 with explicit route state and complete reasoning-effort support
- Acknowledgement-driven settings and MCP changes with rollback-safe persistence
- Identity-bound remote MCP secrets plus polished goals, tools, diffs, and streaming status
- Protocol v5 with explicit route state and complete reasoning-effort support
- Acknowledgement-driven settings and MCP changes with rollback-safe persistence
- Identity-bound remote MCP secrets plus polished goals, tools, diffs, and streaming status
- Standing goals and plan feedback
- Structured tool cards and diffs
- Protocol v4 lifecycle controls
- Subscription-backed engines
- Multi-root workspace context
- Correlated permission decisions
- Self-hosted VSIX channel
- Cursor installation flow
- Editor reliability fixes