Repository navigation
chore: version packages - #1522
Open
github-actions[bot] wants to merge 1 commit into
Open
github-actions[bot] wants to merge 1 commit into
github-actions[bot] wants to merge 1 commit into
Conversation
github-actions
Bot
force-pushed
the
changeset-release/main
branch
from
September 28, 2026 10:29
a393772 to
2c6fd30
Compare
github-actions
Bot
requested review from
akramcodez and
will-lamerton
as code owners
September 28, 2026 10:29
github-actions
Bot
force-pushed
the
changeset-release/main
branch
27 times, most recently
from
October 3, 2026 12:34
fb2d25c to
d452cb7
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
19 times, most recently
from
October 7, 2026 10:16
a48d910 to
e76fbd4
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
9 times, most recently
from
October 9, 2026 16:18
ce676a5 to
716dd0a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
@nanocollective/nanocoder@1.32.0
/settings providerswizard. Selecting it fills in the base URL (https://futureinfra.ai/v1/ai) so only an API key and a model name (for exampleopenai/gpt-4o-mini) are needed.benchmarks/agent/, run withpnpm run test:agent-eval. It measures pass/fail, steps, tokens and cost per task by shelling out tonanocoder --plain --json run, so a released tag can be measured with the same harness as the working tree. Six vendored task fixtures each carry machine-checkable assertions and distractor files, so a run working from degraded context fails rather than merely finishing cheaper; every result records the fixture-set id and a content hash of the fixtures. It is deliberately outsidepnpm run test:all, since it needs real model calls. Phase 0 of [Feature] Agent evaluation harness, measure steps, tokens and cost per task #1197.nanocoder.autoCommit([Feature] Auto-commit on successful edits (nanocoder.autoCommit) #1482). When set totrueinagents.config.json, every successful agent file edit (write_file,string_replace,diff_edit) is committed on its own, with a Conventional Commit message the current model writes from that file's diff (the/commitprompt), falling back tochore: update <path>if the model call fails. Only the edited file is committed, so the user's own staged and unstaged work is never swept in. Auto-commit is skipped outside a git repository, for ignored files, for no-op edits, and while a merge, rebase, cherry-pick or revert is in progress; a failed commit is logged as a warning and never fails the tool call. Off by default.tscoutput, keeps each failing test's title, location, assertion and expected/received diff, and narrows the original command to the first failing test (for examplenpm test -- jest/auth.test.js -t '...'). It re-runs that narrow command once to report whether the failure reproduces on its own. Only plain runner invocations are narrowed or re-run;!commandinput is distilled but never re-run; short or unrecognised output is unchanged. Closes [Feature] Architecture: Failure distillation into executable capsules #1584.browsertool (navigate, click, type, screenshot) on one shared headless Chromium page. Screenshots reach vision models as images. On OpenAI-compatible providers they follow the tool result as an image message. Models that models.dev lists as text-only get the caption without the image. Localhost is allowed. Private network and cloud metadata addresses are blocked. Chromium itself is installed withnpx playwright install chromium./helpwith categorized command listings and command-specific details, including usage, supported options and subcommands, aliases, and examples. Closes [Feature] Command-specific help (/help <command>) and categorized command listing #1308.nanocoder.formatters: code formatters (Prettier, Biome, gofmt, ...) that run on every file the agent writes whose path matches a glob, beforepost-tool-usehooks fire. The model is told when a formatter changed the file so its next edit starts from what is on disk. Closes [Feature] Formatter-on-save (nanocoder.formatters) #1483.[WARNING: recorded at <commit>, <file> has changed since. Verify before trusting.]prefix, so the model checks the file instead of trusting stale context. Memories saved before this change, and memories saved outside a git repository, are recalled exactly as before. Closes [Feature] Architecture: Scoped, freshness-aware memories for Git-aware RAG #1572./settings mcp) now offers an FXMacroData template on the remote servers tab. It builds a remote HTTP MCP config pointing athttps://mcp.fxmacrodata.com, giving the agent macroeconomic releases, central bank rates, release calendars and FX data across 22 currencies. The API key is optional: leave it empty to use the keyless tier (the last 90 days of USD releases, each readable 15 minutes after publication, the USD release calendar, press releases and data catalogue, plus market sessions for every currency), or enter a key and it is sent as a bearerAuthorizationheader. Keys containing spaces, line breaks or control characters are rejected in the form.?key=valueinline overrides to slash commands. An override is applied via the existing session-override plumbing and restored to its prior value when the command finishes, so users can test a setting for a single command without changing the session state. Closes [Feature] Allow ?config= override on slash commands for one-off tuning #1151.Working examples:
/usage ?context-max=200k- renders context usage against a 200k limit for this command only, then restores the prior limit./compact ?threshold=80- gates the manual compaction on current usage: compacts normally at or above 80%, otherwise reports the usage and skips (mirroring the automatic path's gate). Composes with?context-max, which the gate reads as the limit./compact ?preview,/compact ?auto-on- boolean flags forwarded as their--flaglong forms.Behavior:
thresholdvalues outside 50–95 and unparseable values are ignored (fail open: the command runs un-gated).auto-compactis parsed and round-tripped through the session-override stores (apply then restore), but no built-in slash command currently reads it synchronously during dispatch — reserved plumbing for the automatic compaction path.Unknown
?foo=barkeys are never consumed: the dispatcher forwards them to the command handler verbatim (so each command's own unknown-arg handling runs) and queues one warning naming the key, so a typo cannot silently no-op.Values containing additional
=are preserved (?config=key=value→'key=value').Override applies only to the current command; it does not affect global session state.
Custom commands and MCP prompts bypass override parsing (they receive
?foo=1literally).Added MCP server liveness checks that detect failed pings and transport closures, remove unavailable tools, and show unhealthy servers in
/mcp.Add in-process plugins under .nanocoder/plugins that can block a tool, annotate its result, observe compaction, deny a permission prompt, or append prompt context.
read_file now returns a short stub when the same path and line range is read again and the file has not changed. Compact and /clear force a real read. Refs [Feature] Semantic Context Compiler (Intelligent Context Budget Management) #793.
Add
nanocoder storage, a read-only interactive inspector for saved sessions and artifacts across Nanocoder and timeline/checkpoint data in the current project. Usenanocoder storage --format jsonfor a non-interactive report suitable for scripts.Added voice mode.
/voiceturns it on, with push-to-talk onCtrl+Gor hands-free speech detection, local Whisper speech-to-text and local Piper text-to-speech by default, and opt-in OpenAI cloud STT/TTS. Speaking or pressingCtrl+Ginterrupts a running response. The audio tools are installed on first use, with checksums verified. Hands-free mode is paused in yolo mode so background speech cannot trigger unconfirmed tool calls. Thanks to @RONAK-AI647. Closes [Feature] Realtime Voice Mode for Nanocoder #622.Cancelling a bash command now also stops background processes it left running, and force-kills any that ignore the normal stop signal after two seconds.
The VS Code chat panel now queues follow-up prompts submitted while a turn is still running, instead of firing a second overlapping ACP request (which the agent rejected with "Prompt already in progress") or leaving the thought sitting un-submitted in the composer.
Queued messages appear inline as user bubbles with a Queued badge and a remove button; when the current turn finishes they dequeue in order.
While a turn is running, typing in the composer flips Stop back to Send so clicking it queues the follow-up (Escape or an empty-composer Stop still cancels). The webview parks that follow-up locally and only forwards it after the in-flight ACP
prompt()settles — posting it immediately was what produced the "RequestError: Internal error" toast.Stop / Escape (and New Chat) discard the whole queue so cancelling a runaway agent does not immediately start the next waiting prompt.
Fix the architect review bar's accent border sitting out of line with the composer and every other footer modal.
ArchitectReviewPromptwas missing the shared left-edge wrapperPlanReviewPrompt,FileExplorer,IdeSelectorandModalSelectorsalready use. Closes [Bug] The architect review bar is missing the wrapper every other footer modal has, so it sits out of line with the prompt #1532.Cap the Architect review bar's changed/new-file lists at 5 rows with a "+N more" line, matching the same cap already used for the live tool-count summary. It used to print every file with no limit, so on a turn touching many files the list pushed the Keep / Revert / Revert & Revise choices below the bottom of the screen. Closes [Bug] The architect review bar lists every changed file, so on a large turn the Keep / Revert / Revise choices are pushed off screen #1533.
Restore exact prior git staging state on auto-commit failure and clarify same-file edit behavior in documentation
Fix
nanocoder.autoCommitcommitting other files when the edited file's name looks like a git glob. The path was passed togit add,git diff --cachedandgit commitas a pathspec, so an agent edit to[ab].txtalso matcheda.txtandb.txtand swept the user's uncommitted edits to them into the agent's commit. Auto-commit now runs git with--literal-pathspecs, so only the edited file is committed. Closes [Bug] autoCommit treats the edited file name as a git glob and commits other files too #1654.A shell command that exits non-zero is no longer displayed as a success in the interactive TUI.
execute_bashonly prefixed its result withError:when the command could not be spawned at all, and the display layer decided success purely by sniffing for that prefix, so a broken build or a failing test run rendered as⚒ Ran 1 command, identical to a clean run. The streamed bash path now setsToolResult.isErroron a non-zero exit and the compact display branches on that flag, showing⚒ execute_bash failedinstead. Together with the earlier--plain/--json/ACP fix, this closes [Bug] A failed shell command is displayed as a normal success #1371.Fix /copy argument validation so unknown arguments show a usage warning instead of copying the full assistant response.
A git branch name containing CJK characters or emoji no longer breaks the welcome screen's location line. The row was budgeted by counting characters, but a wide glyph is one character and two terminal columns, so the line overflowed and split into a branch row with a dangling separator and a stranded path. Path truncation now measures display width, which also stops an emoji being cut in half. Closes [Bug] A non-ASCII git branch name breaks the welcome screen's location line #1389.
Fix the compact tool-activity summary showing identical "Ran N git command(s)" rows for
git_status,git_diffandgit_log, making a turn that mixes them indistinguishable. Each git tool now gets its own phrasing. Closes [Bug] git_status, git_diff and git_log all summarize as identical "Ran N git command(s)" rows #1556.Quote custom tool template values for cmd.exe so spaces, command metacharacters, and embedded quotes stay literal on Windows. Values containing percent signs, carriage returns, newlines, or null bytes are rejected because cmd.exe cannot represent them safely in a command string. This is a deliberate cross-platform restriction: values accepted by POSIX shells may be rejected by cmd.exe. Closes [Bug] Custom tool
{{ }}quoting is POSIX-only; cmd.exe is not covered #1084.nanocoder daemon installnow warns when the project isn't trusted yet. The installed service runsnanocoder daemon startunattended on a restart-on-failure policy, anddaemon startrefuses to boot outside a trusted directory - so installing auto-start before ever running nanocoder there produced a service that failed forever with no explanation, while install itself reported plain success. The result message now names both fixes: runnanocoderthere once to accept the trust disclaimer, or pass--trust-directory.Preserve HTML literals inside fenced markdown code blocks by extracting code blocks before HTML entity decoding and
conversion. Adds tests to ensure HTML tags and entities remain unchanged inside code fences. Thanks to @Shreya657. Closes [Bug] Markdown renderer changes HTML literals inside fenced code blocks #1591.
Fixed pressing Enter immediately after typing a slash-command fragment submitting the raw fragment. The completion menu opens a render after the keystroke, so an Enter landing in between saw it closed. Enter now selects from the completions about to be shown, and still submits a command once its completion has been selected. Closes [Bug] Enter pressed the instant a / menu opens submits raw text instead of selecting #1327.
Pressing Enter on a fully typed slash command now runs it on the first press instead of needing a second Enter to dismiss the completion menu. The menu opens with the exact, unambiguous match already highlighted, and Enter used to "select" it - re-applying text that was already there and closing the menu - rather than submitting. Partly typed commands still complete on Enter as before. Closes [Bug] Enter on an exact, unambiguous slash-command match closes the completion menu instead of submitting #1431.
Pressing Escape on an empty composer no longer offers to "clear" it. Escape armed the two-press clear hint unconditionally, so it appeared even when there was no text, no attachments and no active-editor pill to clear. It now only arms when there is something to clear, and Escape still clears an attached VS Code file pill on its own when the composer text and attachments are otherwise empty. Closes [Bug] Escape offers to "clear" an already-empty input box #1430.
Fixed /expand list rows: multi-line command arguments are collapsed to a single line, cut to the width the terminal leaves for the row, and the id column is padded so tool names stay aligned past result 9. Thanks to @theluckystrike. Closes [Bug] /expand's result list breaks when a tool call's command spans multiple lines #1534.
/explorerno longer strands the selection when its list gets shorter. Leaving a search swaps the list from every match back to only the expanded rows, but the selected row was only ever clamped inside the arrow-key handlers, so after a long search it pointed past the end of the tree: no row highlighted, the path readout blank, Up and Enter doing nothing, and Down jumping straight to the last row. The selection is now pulled back into range whenever the list shrinks. Closes [Bug] /explorer: leaving a search strands the selection outside the list, no highlight, Up/Enter inert, Down teleports to the last row #1454.Fixed
TimelineManagerpruning an active session whose directorymtimeMswas older thanMAX_TIMELINE_SESSION_AGE_MS. Each session now holds a per-process lockfile at.nanocoder/timeline/<sessionId>/.lock, published atomically via a temp file plus hardlinkso concurrent readers never observe a half-written lock;pruneStaleSessionsprobes the lock and removes the entry only when the lock is missing, malformed, held by a dead PID, or older than 24h by file mtime. The mtime is refreshed on every capture so long-lived sessions keep their protection, a resumed session reaps a dead predecessor's lock before acquiring,clear()resets the in-memory claim so the next capture re-acquires, and a session whose lock was reaped by another process re-acquires it on its next capture. Closes [Bug] timeline-manager.ts mtime-based prune can delete a session that's mid-tool-call #1149.Keep
globalThis.processintact whenfetch_urlor file caching converts HTML through get-md: pages with an<iframe>make happy-dom windows that null the global after get-md's own restore, and the nextprocessread crashed the app through the fatal-error handler. The logging config, logger provider and shutdown manager now use a module-levelprocessreference, the uncaught-exception and unhandled-rejection handlers fall back to stderr when the logger itself throws, and the conversion calls restore the global afterwards. Closes [Bug] fetch_url sets globalThis.process to null on pages with an <iframe>, and the next error kills nanocoder with a masked TypeError #1553.Fixed Homebrew installs and upgrades failing checksum verification for the 1.31.0 npm tarball by correcting the formula's SHA-256 checksum. Thanks to @niukanen1. Closes [Bug] 1.31.0 fails Homebrew install due to SHA-256 checksum mismatch #1601.
Fix
loadAppConfigstripping the.sourcefield when unwrapping MCP server configs, which silently disabledvalidateProjectConfigSecurity's hardcoded-credential scanner for project-level MCP servers. Closes [Bug]validateProjectConfigSecuritynever runs, hardcoded-credential scanner is dead code #1248.Shift+Enter now adds a line break at the cursor instead of scrambling the message. Typing
one, Shift+Enter,two, Shift+Enter,threeused to submitonetwothreewith two trailing blank lines, because the break was appended to the end of the composer value while the caret stayed put, so every later word landed at the stale offset. Ctrl+J was affected the same way and only looked right because the caret is usually already at the end. Closes [Bug] Shift+Enter scrambles a multi-line message instead of adding a line #1326.Fix
git_logignoring itsbranchargument. It always returned the commits of the checked-out branch while labelling them with the requested one, so asking for thefeaturebranch frommainshowedmain's history under afeatureheader. The branch is now passed togit log, and a branch value starting with-is rejected so it can't be read as a git option. Closes [Bug] git_log ignores branch argument and mislabels current-branch commits #1587.Fixed the prompt box sitting a couple of columns right of the chat transcript in inline mode (
--no-alt-screen). The box and the mode line below it now share the transcript's left edge. Fullscreen is unchanged. Closes [Bug] The chat transcript sits out of alignment with the prompt box in inline mode #1432.Fixed Backspace doing nothing in the MCP setup wizard's custom-server environment variables field. It now removes the last character, including a line break, like every other text field. Closes [Bug] MCP setup wizard's custom-server "environment variables" field has no Backspace/Delete handling #1406.
Editing a renamed GitHub remote MCP server keeps its bearer token (MCP wizard: editing a custom-named template instance falls back to
customand drops the github-remote bearer token #1424).The
(Shift+Tab to cycle)hint in the status line now shows by default instead of only on terminals under 80 columns. It was gated on the narrow-terminal check, so it appeared where space was tightest and never on a normal-width terminal; it is now included whenever the row has room and is dropped by the existing width budget when it doesn't. Closes [Bug] The "(Shift+Tab to cycle)" mode-cycling hint only renders on terminals too narrow to spare the room for it #1453.Ctrl+A, Ctrl+E, Ctrl+U and Ctrl+K in the prompt now act on the current line, not the whole multi-line buffer. Ctrl+U on the last line of a three-line prompt used to clear all three lines with no undo, and Ctrl+A/Ctrl+E jumped to the very start/end of the prompt instead of the current line, matching the
?shortcuts legend's "Move/Delete to start or end of line" only when the prompt had a single line. Closes [Bug] Ctrl+U / Ctrl+K / Ctrl+A / Ctrl+E act on the whole prompt, not the current line, in multi-line input #1530.Added a next-command suggestion after turns that edit files. When a turn makes a successful
write_fileorstring_replaceedit, the empty prompt now suggests a relevant follow-up:/commitwhen changes are already staged, otherwise/checkpoint create. The suggestion is only placeholder text — typing replaces it, Tab inserts the command, Esc dismisses it, and sending a message clears it — and a slash command finishing (the suggested one included) does not bring it back. Closes [Feature] Suggest a relevant next command after a turn completes #1317.Two pastes made back to back no longer fuse in the message sent to the model. The composer showed two tidy placeholders, but they expanded flush against each other at submit, joining the last line of the first paste to the first line of the second. A paste placeholder now goes on its own line wherever it would otherwise touch other text, whether it is appended or spliced in at the caret. Existing whitespace on either side is left as it is. Closes [Bug] Two pastes placed back to back merge their text with no separator #1373.
Fixed
post-tool-usehooks hiding their output from the model when they fail. A hook that exited non-zero was logged for the user and then dropped, so a passing linter or test run reached the model and a failing one never did. Failing output, stdout and stderr both, is now added to the tool result as<hook-output event="post-tool-use" exit="N">. The hook is still observe-only: the tool call succeeds, and a hook killed by a timeout or a signal is still only logged. Closes [Bug] post-tool-use hook output is thrown away when the hook exits non-zero #1558.Prevent Bash completion from suggesting subcommands when a flag expects an arbitrary value. Closes [Bug] Bash completion suggests subcommands where flag values are required #1593.
Queued-message previews, the session label, the active-editor filename, and session titles no longer wrap onto extra rows when the text is CJK or contains emoji. The shared truncate helper budgeted in UTF-16 code units while its callers pass a column count, and a double-width CJK ideograph or emoji is one code unit but two terminal columns, so a "truncated" line could render at roughly twice its intended width. It now truncates by actual terminal column width via
cli-truncate, so a queued message stays on a single row regardless of script. Closes [Bug] Queued-message previews truncate by string length, so a long CJK message wraps to three rows instead of one #1531.Fix a race in the composer where typing, pressing Backspace, or pressing Enter immediately after a paste could silently drop the pasted content or swallow the key. Edits that arrive before the paste is shown are now replayed onto it, and Enter submits what the composer actually holds.
Fixed the UI sometimes not re-laying out after a terminal resize. Layout reactivity came from the clamped box width, so any resize that landed inside a clamp (below 44 or above 204 columns) produced no re-render and left the welcome screen, input box, status bar and session selector sized for the old terminal. Width now derives from a reactive raw column count. Closes [Bug] Resizing the terminal sometimes doesn't re-layout the UI at all #1328.
The interactive directory-trust prompt now resolves trust through the same
isDirectoryTrustedcheck as--plainandnanocoder daemon start, so the matching rule can no longer drift between entry points. Also corrects the--trust-directorywarning, which now namesnanocoder daemon startalongsidenanocoder run. Closes [Bug]isDirectoryTrusteddocstring claims the TUI shares it, butuseDirectoryTruststill has its own copy of the check #1339.Fix the composer input box clipping its left border, prompt marker, and placeholder start on terminals narrower than 40 columns, by clamping the box's width floor to the actual terminal width.
update test - mcp-client-spec.ts
Fixed
/statsdropping arrow-key presses and freezing on a range tab. The range stepped from the value captured in the input handler's closure, but Ink re-registers that handler in a passive effect that runs after the frame is painted — so a press arriving before the effect landed was dispatched with the previous render's range, recomputed the tab it had already moved to, and wedged there until another key broke the tie. The range now steps from the value React holds.Fix the live streaming preview growing unbounded on a response with one very long line and no newlines.
computeStreamingTailsnapped its slice start back to the nearest preceding newline to avoid a partial leading line, but with no newline at all it snapped all the way to 0, discarding the tail bound entirely. It now falls back to the unsnapped tail start instead, accepting one truncated leading line rather than rendering the whole growing message. Closes [Bug] A huge single-line streaming response defeats the tail-truncation bound entirely #1555.After a bash
cd, thestring_replaceapproval preview and the ACP edit diff read the file in that directory. They used to open the same relative path from the directory nanocoder was started in. Closes [Bug] string_replace preview reads the launch directory after cd #1634.Fixed the sub-agent transcript appending "..." to every tool result. The view sliced each result to 100 characters and added the ellipsis unconditionally, so a short result like
OKrendered asOK...and implied output that was never truncated. The ellipsis now appears only when the content is actually past the limit, matching the guarded pattern in the git-commit tool card. Closes [Bug] Subagent transcript view appends "..." to every tool result, even short ones that weren't truncated #1408.Fixed the welcome screen's menu wrapping apart on narrow terminals, with each command landing on its own line. The menu now steps down to the short version, or is left out, when its rows would not fit the terminal width, the same way it already does for height. Closes [Bug] The welcome menu's columns wrap apart on narrow terminals, independent of #1330's height fix #1434.
If there are any problems, feedback or thoughts please drop an issue or message us through Discord! Thank you for using Nanocoder.