Changelog

What changed in each release. The newest, unreleased entry describes the version being prepared.

v0.6.0

Headline

0.6.0 makes the loop with an AI agent safer and faster without choosing or configuring the agent for you: a checkpoint around every agent turn you can look at and restore, comments on a diff that land in the session's shell, an opt-in automatic test run when a turn ends, and flags on sensitive files before you land. Everything still ends in text typed into your own shell, and nothing presses Enter for you.

New

  • Session checkpoints. When a recognised agent starts and ends a turn, crossweave records the worktree as a hidden git commit (refs/crossweave/checkpoints/<session>/<n>, from a private index; no branch, HEAD or real index moves). cw checkpoint list|take|diff|restore and a Checkpoints… dialog in the session menu show what each turn changed. Restore is a dry run by default, saves a return point and refuses before touching anything it would destroy. The newest 50 are kept.
  • Diff comments. Comment on a line of the Changes pane or the Checkpoints dialog; the notes are pasted into the session's shell as one bracketed paste, never with Enter. Comments are matched back to their lines after a reload; the ones that no longer match are listed.
  • Auto-check (Settings → Checks, off by default). When an agent ends a turn that changed files, the trusted converge.testCommand runs in that worktree, one automatic run at a time. A failing run offers Send test failure to shell (secrets redacted, control characters removed, no Enter).
  • Sensitive-file flags. Files of a diff named like a secret, an automation file (CI, hooks, containers, the repository config), a migration or a dependency manifest carry a labelled badge, with a summary line, in Changes, Checkpoints and Compare. Land asks first for secret-like and automation files, in the same dialog as the failing-tests question. Judged by name only: it can miss and it can over-flag.
  • AI debug loop (from main since 2026-10-01): cw hooks install|remove, cw debug, a Debug pane, a Responses view after a composer send, cw browser errors, status that covers split panes, a live drag preview.
  • A calmer Settings page. No news banner; every section has a one-line lead, a titled first card and its longer explanation folded under Details, and the column no longer shifts when a scrollbar appears. Notifications is grouped, Checks explains how it works, and the auto-run row keeps its safety words (runs code the agent just wrote, outside its sandbox, for every project, off by default) in view.
  • A desktop alert when a check fails while the window is not in front: <session>: tests failed with the exit code and time, never the output. One per failing run; switch When tests fail under Settings → Notifications, on by default.
  • Session panel overview: a count chip on rows with two or more panes lists them so you can focus one.
  • Hardening round 2: a ✗ setup chip, a history filter capped at 500 rows, more cw debug failure shapes and token shapes, opt-in converge.requireCheck (with cw land --skip-check), cw check with the session's lease environment, Compare showing whether the pair would conflict, a cancellable Refine, a corner notice when a newer release exists.

Fixed

  • A shell's cw commands inside a session reach the daemon that owns the session.
  • "Send test failure to shell" cleans the output before redacting it: a key split by a zero-width character, a bidi override or an escape sequence used to escape the redaction and be put back together afterwards; BEL, backspace and DEL are removed too.
  • The rail re-reads when a pane closes; the pane inset no longer disturbs the terminal fit; a stopped session's tick can be unticked.

Upgrading

  • Schema v18 (cw check verdicts survive a restart). An older cw refuses a v18 database; update the CLI and the app together.
  • The new methods (checkpoint.*, the automatic check) need a daemon of this version. Restarting a project's daemon ends its running sessions, so pick a quiet moment.
  • Checkpoint refs are visible to git log --all and to tools that list every ref; they are orphan commits, not branches.
  • Auto-check is a trust decision. It makes an agent's finished turn start a run of a command you already trusted with cw config trust, for every project where you trusted one. Leave it off if you do not want that.
  • The failed-check alert comes from the window, so only projects the window has open raise it; it never shows test output.
  • Limits and ideas not built: docs/superpowers/specs/2026-10-10-{session-checkpoints,diff-comments,auto-check,sensitive-files}-known-limitations.md and 2026-10-11-settings-polish-check-alert-known-limitations.md.

v0.5.0

Headline

0.5.0 gives the cockpit a Settings page in the manner of Cursor's and a Dashboard that shows what your projects and sessions cost in disk and memory — and proposes, never performs, what you could stop or delete to lighten the machine.

New

  • Settings are re-laid out: grouped icon navigation, one centred column, rounded cards of rows (name and description left, control right), real toggle switches, and a dismissible banner. Search and deep links use the same words as the page.
  • Dashboard (Settings → Dashboard): per project the sessions by state, the disk their worktrees hold, the daemon's memory and the app's own; two charts (each with a table view); a sortable session list.
  • Suggestions to free space: clean up ended sessions, delete a long-idle empty session, land-or-delete a long-idle one that still holds unlanded work, stop an idle shell. Every action asks first and names exactly what would be lost; a clean-up never includes sessions gc would keep.
  • The rail's filter box reads Search and has an icon.

Fixed

  • The active project's frame in the rail no longer changes the rows' size and position when you switch session or project.
  • The "No open tabs" box no longer touches the pane's edges.
  • The daemon measures worktree disk off its event loop (DiskTracker), so a big node_modules no longer stalls it.

Upgrading

  • The Dashboard needs a daemon of this version. A project still running an older daemon shows "restart its daemon to see its numbers"; restarting ends that project's running sessions, so pick a quiet moment.
  • Disk figures are lower bounds (≥) when a measurement hits its time limit. See docs/superpowers/specs/2026-09-30-settings-dashboard-known-limitations.md.

v0.4.0

Headline

0.4.0 is the release where the cockpit and the shell talk to each other, and where running several agents at once gets easier to supervise: a session can say it is done, its work can be tested before you land it, two attempts can be compared, one prompt can go to several sessions, and a whole working setup starts in one click.

It also removes things on purpose (see "Removed"). If you are coming from 0.3.0, read that section first.

New

From a shell into the cockpit

  • cw notify "tests written" [--kind done|ask] — an agent's hook (or you) tells the cockpit a session is done or needs an answer. A ✓ (or an amber row) appears, the words go in the tooltip and the desktop notification, and the next keystroke in the session clears it. Exact where the screen-reading status is a guess. Example: a Claude Code Stop hook running cw notify "Claude finished".
  • cw check [session] — runs the project's trusted converge.testCommand in that session's worktree; the row shows ✓ tests or ✗ tests (dim once the work has moved on). Same trust gate as land (cw config trust); nothing untrusted ever runs. Landing a session whose last tests failed now asks first.
  • cw pane list|split|select|zoom|layout|move|sync|close|open — arrange the running cockpit's panes from a shell. Layout-only commands just happen; closing, synchronizing and opening a page or file ask you.
  • cw browser list|console|network|dom|shot|navigate|click|type|eval — an agent reads and drives a Browser pane, behind a per-pane Agent: Off / Read / Control switch (off by default). Control outside localhost, and eval anywhere, ask you for that one command. Text read from a page is marked untrusted. See the known-limitations note before you turn it on for a logged-in page.
  • A command bridge underneath: the daemon carries a request to the cockpit and its answer back; closed namespaces, and every decision is taken in the cockpit, never in the daemon.

In the window

  • Prompt composer (⌘⇧P, the pen button): write one prompt, optionally Refine it with a program you name (Settings → Prompt; only a proposal comes back), and send it to one or several sessions. The preview shows exactly what goes where; Enter is pressed only if you tick it; a multi-line prompt is never typed into a plain shell.
  • Compare with another… (session menu): two sessions' changes side by side, the files both touched marked, and a Land button per side.
  • Session presets (Settings → Presets, then ⌘T): a launcher, an own worktree or not, extra terminals that each run a command, and a Browser pane on the session's port — in one click.
  • Session history (⌘⇧H, cw session history): what you landed or deleted, kept after the session row is gone.
  • tmux-style panes: Ctrl-A then a key, synchronize panes, a vi-style copy mode, move a pane to another tab, layout presets, next/previous tab. Optional terminal persistence (off by default) reopens extra terminals after a daemon restart.
  • An app icon of its own (a small weave in the agents' colours) instead of Electron's default.
  • A quieter status: nothing for a shell with nothing running, a turning ring while an agent works, a ✓ when one finished and you have not looked, amber when it asks. A failed setup hook shows on its row.

Fixed

  • The rail could miss a session created at the same moment as another, because an older, slower refresh could overwrite a newer one.
  • A plain shell showed a spinner every time you typed (the echo of your own keystrokes counted as work).
  • A session in the project folder could trigger a false "holds 36 GB" disk warning.
  • Dropping a file on a terminal, the context menu at the screen edge, and several concurrency flakes in the port tests.
  • A landed session's leases are released after its teardown, not before; a daemon that does not know a method is told apart from other RPC errors; a broken worktree can no longer freeze the overlap picture for everyone.

Removed

  • In-app voice input. Dictation is better served system-wide (Handy, Superwhisper, macOS Dictation) and works in every app. The last version with it is tag v0.5-voice-input; the composer's Refine keeps the idea for text.
  • Earlier (2026-09-27): the collision guard, tiers / Safe Mode, agent adapters and launch flags, the MCP server and the OS sandbox (tag v0.3-radar), and the browser remote control cw gateway (tag v0.4-remote-web). 0.3.0's notes describe a sandbox that no longer exists.

Upgrading

  • The database schema goes from v14 to v17 the first time a project's daemon starts on 0.4.0 (terminals, the setup hook's exit code, session history). Migrations only add.
  • Restart each project's daemon after installing the app, or cw notify, cw check, cw pane, cw browser and the history will be answered by the old one ("Unknown method"). Restarting ends that project's running sessions.
  • A settings file that still has a voice block loads fine and drops it on the next save.
  • The app is signed with a development certificate and not notarized (that needs an Apple Developer account): on first launch macOS may ask for Open Anyway.

Known limits

Every feature has a *-known-limitations.md next to its spec, and the one-line versions are in docs/superpowers/specs/2026-08-14-known-limitations-digest.md. The ones worth knowing before you rely on them: a verdict from cw check is remembered in memory only and tests the session's worktree, not the merge; page text, screenshots and eval results from cw browser are not redacted; the command bridge's caller is unauthenticated by design (a same-user process can register first); agent detection is a guess from the process tree, so an unrecognised agent is treated as a plain shell by the composer.

v0.3.0

Headline

Two things land in this release: an OS-level sandbox around every session, and the crossweave Cockpit — the desktop client the core was designed for from day one.

New — OS-level session sandbox (macOS)

Safe Mode's tiers intercept what an agent reports about its tool calls, so a write made through a shell, a script, or a subprocess slipped past all of them. Each session now runs inside an OS boundary (macOS seatbelt) where that write is not merely unblocked — it is impossible:

  • a session can write inside its own worktree, its private temp dir, its caches and its own agent state, and nowhere else — not your main checkout, not another session's worktree, not $HOME, not .git/config or git hooks;
  • git commit still works, because the profile opens exactly the object/ref/log shapes a commit writes in the shared .git a linked worktree commits through;
  • network is off unless the workspace opts in.
// crossweave.config.json
{ "sandbox": { "enabled": true, "network": false } }

enabled defaults to true. On a platform with no provider (Linux, Windows) or on a --no-worktree session sharing your checkout, the session runs unconfined and the daemon log says so — the absence is never silent.

Linux (bubblewrap) is specified but not built; see docs/superpowers/specs/2026-09-18-os-sandbox-design.md.

New — crossweave Cockpit (Electron, macOS arm64)

A thin desktop client over the same daemon: real xterm panes, an attention rail (working / needs-you / blocked / landability), and evidence-gated land from the UI. It is built from source (cd apps/cockpit && bun run dist:mac); attaching the installer to releases is the next step. The CLI TUI (cw tui) remains the cross-platform dashboard.

New — cw session start, and honest tier labels

  • cw session start <session> — start an agent without attaching. session new is create-only again (it used to spawn an agent, which failed wherever the binary was not on PATH).
  • Every tier prints what it actually covers — T2 · Edit|Write, T3 · nothing — instead of a bare tier that reads as protection. Bash is watched after the fact and is advisory only: a block stays reserved for a write the daemon actually evaluated.
  • A stopped session is no longer a green "ready" — the badge now reflects whether an agent is actually running.
  • cursor-print (T3) drives cursor-agent --print --output-format stream-json. --agent cursor (T1/ACP) now fails fast with a clear message: current cursor-agent builds dropped ACP, so it used to hang silently.

Fixed — land and lease reliability

  • Land is evidence-gated: trials are recorded against the base commit they ran against, and are re-run when the base moves, so cw land all stops with "nothing to land" rather than landing on stale evidence. --force overrides deliberately.
  • A squash merge whose commits produce no staged diff is a successful no-op, not a false LAND_MERGE_FAILED.
  • PORT can no longer be overridden by ports.named, and the whole port block is probed before it is leased.
  • cw session rm / kill --rm-worktree dispose leased cache directories and copied databases before deleting their records.
  • cw session list shows the port/cache/db lease summary.
  • The ACP adapter times out a handshake that never resolves instead of showing a running session that is silent and dead.

Upgrading

The sandbox is on by default. If a workflow legitimately needs to write outside the session's worktree (a shared build cache, a global tool config), either set sandbox.enabled: false for that repo or opt the network in with sandbox.network: true — the daemon log names the session and the reason whenever no boundary is applied.

Installers and checksums are attached below. install.sh picks the right binary for your platform.