v0.1.1 2026-09-03 [RELEASE] - Preserve Loop revisions, resumed usage, provider imports, and cross-workspace session boundaries without losing user configuration - Make automatic updates notification-only until the user explicitly runs wukong upgrade - Require HTTPS and bounded plugin archives, support SHA-256 verification, install disabled first, and roll back atomically on failure - Discover checks only from real root or workspace-member declarations and retain explainable provenance - Improve local Web reconnects, permission controls, keyboard navigation, workspace persistence, dialogs, and side chats - Keep the release free, local-first, and BYOK without adding commands, paid plans, hosted inference, or managed model credits Why v0.1.1 shipped this way
v0.1.0 2026-08-08 [RELEASE] - Add one editable Preflight for the Goal, Finish Line, checks or versioned no-check decision, provider destination, permissions, workspace state, and runtime limits - Enforce provider-call and optional token ceilings and stop blind retry when a provider outcome is unknown - Require complete and fresh Gate evidence; incomplete, stale, conflicting, interrupted, or corrupt evidence cannot become PASS - Show deterministic terminal results, decisive evidence, file attribution, checks, usage, blocker, recovery, and next action - Preserve direct upgrade and local-state compatibility from v0.0.22 - Publish six immutable native ZIPs with adjacent SHA-256 files and exact-source provenance; macOS binaries are intentionally unsigned and unnotarized Why v0.1.0 shipped this way
v0.0.22 2026-07-31 [RELEASE] - Fall back from modelpricelab.com to models.dev when the primary provider catalog fails; the published ZIPs still require one remote catalog because the intended embedded snapshot was omitted - Include common GLM and Kimi provider entries in the source-tree fallback catalog - Apply --skills-dir to interactive terminal sessions as well as headless runs - Present -r, --resume as the canonical session-resume option while retaining -S, --session as a hidden compatibility alias - Explain guarded Auto, YOLO, Plan, headless prompts, --yes confirmation, and additional workspace access more clearly - Describe judge as a deterministic local merge gate rather than a guarantee that a workspace is safe to merge - Publish six native ZIP files and six matching SHA-256 files for macOS, Linux, and Windows Why v0.0.22 shipped this way
v0.0.21 2026-07-30 [RELEASE] - Derive built-in risk evidence identity from the complete occurrence: kind, severity, message, file, line, and evidence - Preserve distinct occurrences of the same risk kind instead of rejecting later findings as duplicate broker input - Keep identical occurrences deterministic so exact duplicate input can still be deduplicated - Pass the complete bounded risk evidence set to the Loop reviewer without weakening deterministic Gate failures - Publish the same focused patch across six native targets with matching ZIP and SHA-256 assets - Exclude isolated worktrees, Safe Promote, Windows FFI, hosted execution, payments, quota, source upload, and telemetry backend Why v0.0.21 shipped this way
v0.0.20 2026-07-25 [RELEASE] - Discover strict verification criteria from existing personal, project, monorepo package, trusted local, and built-in Skill sources - Keep deterministic suggestions unselected until the user confirms exact source, full provenance digest, criteria, and order - Use one isolated fresh reviewer with bounded evidence broker tools instead of arbitrary workspace, shell, Skill, MCP, or web access - Require separate local broker trust and per-run confirmation of the exact BYOK provider destination and allowed input origins - Ship optional API compatibility, migration safety, log security, and frontend design reference recipes - Publish six native ZIP files and six SHA-256 files, including a verified Intel macOS SEA compatibility fallback - Keep the release free, local-first, and BYOK with no Skill command runtime, hosted inference, payments, quota, cloud sync, or telemetry metrics backend Why v0.0.20 shipped this way
v0.0.19 2026-07-25 [RELEASE] - Confirm Goal, optional Done when, Must not constraints, real checks, warnings, and the run limit before creating a Loop - Preview the same Finish Line with headless --dry-run and require exact Gate, warning, and workspace trust confirmation - Freeze required-check command, source locator, definition, order, policy, workspace, and approval digests - Reject known inline credentials and recognizable destructive or upload commands before persistence or spawn - Join checks, scan, reviewer, aggregate, evidence, attempt completion, and terminal results with durable local IDs and digests - Create a new traceable continuation run for terminal work and a revised Goal/contract when the Finish Line changes - Keep the release free, local-first, and BYOK with no hosted inference, payments, quota, cloud sync, or telemetry storage backend Why v0.0.19 shipped this way
v0.0.18 2026-07-22 [RELEASE] - Keep the default TUI command surface focused on Resume → Loop → Gate, with advanced tools under /help advanced - Resume local Kimi Code and Grok sessions through bounded, read-only imports - Confirm Device Login on the Wukong website with Google or GitHub, while allowing an honest empty model catalog - Preserve the user’s BYOK default model when no Wukong-hosted models are available - Accept explicit text-only /feedback without login, attachments, logs, prompts, source code, or local evidence - Retain feedback for at most 90 days and apply edge rate limiting without storing IP or device identifiers - Keep hosted inference, payments, monthly Loop quotas, Hosted Terminal, cloud sync, and Web/D1 product telemetry out of this release Why v0.0.18 shipped this way
v0.0.17 2026-07-22 [RELEASE] - Released as the current public download for macOS, Linux, and Windows - Make /resume the primary TUI command while retaining /sessions as a compatibility alias - Keep /login account-only and move every model API-key workflow to /provider - Remove Guest and Free Loop allowances; local BYOK Loops have no Wukong monthly limit - Migrate local Loop recovery records from quota-era lifecycle v1 to content-free lifecycle v2 - Remove Hosted Terminal, legacy Companion routes, managed model claims, Checkout, and preview plans from the website - Keep existing opt-out-aware CLI telemetry without adding a Web or D1 product-metrics backend Why v0.0.17 shipped this way
v0.0.16 2026-07-21 [RELEASE] - Released as the current public download for macOS, Linux, and Windows - Keep each Loop focused on the goal and finish condition you gave it - Remember earlier blockers so review cannot silently move the target - Stop repeated no-progress cycles with a clear result and next step - Make Auto guarded and non-interactive while keeping YOLO explicit and bounded by hard safety rules - Add bounded Resume suggestions, Role contracts, compact task status, and local session prompt search Why v0.0.16 shipped this way
v0.0.15 2026-07-20 [RELEASE] - Released as the current public download for macOS, Linux, and Windows - Recover an active Loop after restart, or end it as cancelled without fabricating a Gate result - Run objective, model, workspace, Goal, and project-check preflight before reserving Loop quota - Retry failed lifecycle completion through a private local outbox with bounded backoff - Show shorter first-run and terminal result surfaces with an actionable primary blocker - Expose real active, stale, completed, cancelled, and abandoned lifecycle states in Dashboard and protected metrics Why v0.0.15 shipped this way
v0.0.14 2026-07-18 [RELEASE] - Released as the current public download for macOS, Linux, and Windows - Resume unfinished Codex, Claude, and Cursor sessions from the TUI with /resume - Continue a resumed task directly or turn it into an editable /loop objective - Show clear Gate stages and reasons instead of ambiguous Verify / Proof labels - Discover real Python, Rust, and Go project checks and report unavailable tools explicitly - Keep Hosted Report and report-upload workflows retired Why v0.0.14 shipped this way
- Return multiple structured review findings and only block the Loop on blocking defects - Add project-specific review criteria through .wukong/review-policy.md - Add local finding feedback, review-cycle counts, and invalid reviewer-output diagnostics - Add an optional independent BYOK reviewer model with --review-model - Unify TUI and Web copy around Goal → Write → Check → Review → Fix Why v0.0.13 shipped this way
- Make Loop the primary workflow with real project checks and a fresh-context read-only reviewer - Return durable PASS, NEEDS_WORK, or ERROR results with structured blockers and stable exit codes - Add one Guest trial and 10 signed-in Free Loop sessions per month without charging internal checks - Discover nested monorepo checks, share one workspace snapshot, and reject stale gate conclusions - Add experimental Role Profiles and preserve legacy Goal records and --until flags - Add non-blocking, version-targeted TUI announcements with safe action links - Refine local verification output and proof diagnostics - Reorganize Dashboard around account and Loop status - Refine TUI welcome, proof actions, loop status, and footer alignment across terminal widths - Publish the versioned announcement endpoint, operator JSON contract, and five-minute cache policy - Sync with Wukong Code CLI v0.0.10: OAuth host fix and quieter startup refresh - Canonical docs redirect: wukong.today/docs → docs.wukong.today - Marketing copy aligned to proof/loop/today narrative - Sync with Wukong Code CLI v0.0.9: wukong today and loop-driven TUI chrome - Add authenticated Loop usage and account status endpoints - Expose CDN version endpoints /latest and /latest.json for CLI upgrade checks - Health API reads app version from package.json - Expand Vitest coverage for marketing pages and API routes - Sync with Wukong Code CLI v0.0.8: OAuth device-code flow and managed platform API endpoints - Refresh homepage copy around the AI coding + verification workflow and proof-layer positioning - Update public assets, favicon, and pixel mascot for the Wukong Code brand - Simplify dashboard with reports, subscription, and settings tabs - Add CLI OAuth approval page at /auth/device for device-code login - Point the CLI default OAuth host to wukong.today so wukong login uses the website device-code flow - Rebrand the TUI welcome card to Wukong Code with a compact startup layout - Simplify the login platform selector to OAuth only, removing API-key platform options - Refreshed Wukong Code homepage around the AI coding + verification workflow - Added the animated pixel Wukong mascot and matching favicon/social assets - Simplified the download page around one-line install, verify, and start commands - Updated footer navigation with the Today blog link - Tightened landing copy, terminal demo, and public launch polish - Rebrand the CLI as Wukong Code: npm package @wukong.today/code and public release repository mutnpc/wukong-code - Add TUI /verify, /scan, and /guard commands and a verification agent - Terminal-native AI coding agent - Built-in verification suite: /verify, /scan, /guard - Multi-model provider support (DeepSeek, Moonshot, OpenAI-compatible) - CLI web UI via `wukong web` - Native binary distribution for macOS, Linux, and Windows - Cloudflare Pages deployment