Changelog

Every release, every installer.

Release notes and downloads for each CuttleCode desktop build, newest first. Every version keeps its installers for macOS, Windows and Linux.

Latest release

v0.9.29

Choose your platform to download the latest build.

All releases

  1. v0.9.29

    Latest

    Fixes

    • Desktop: the bundled npm no longer crashes, so ACP adapters install again. JS build/ directories are no longer stripped from the app payload.
    • Desktop: in-app "Update & restart" no longer postpones forever when no sessions are running.
    • GitHub: Connect GitHub works on gh older than 2.48 (no more unknown flag: --skip-ssh-key).
    • Setup: the GitHub CLI row turns green once gh is installed. No stray Install button, duplicate "Installing…", or phantom token field.
    • Sessions: enabling a new provider loads its models before Start is allowed.
    • ACP: the context meter no longer reads 100% (it was showing 2.7M/1.0M).
    • Cloud sync: your account's membership is mirrored for every synced workspace.
    • Gauntlet/review: longer critic timeout; critic timeouts and failures are labeled as such.

    New

    • RAN: one-switch launch on your own model and sign-in.
    • Settings: one Settings area at /settings/<section>, split into You / Workspace / System. Phone access, notifications and default-runner links are consolidated.
    • Sessions: import Claude Code conversations into Past sessions. Filter Past sessions by linked PR number or Linear issue.
    • Sessions: launching with no provider opens a setup dialog.
    • Chat: Hide tool calls / Hide thinking toggles in the session ⋯ menu.
    • ACP: mid-turn chat messages steer the running turn. Plan mode auto-allows tool prompts and asks only for the plan.
    • Pull requests: jump-to-session chips on each PR.
    • Pipelines: per-pipeline max run wall-clock.
    • Cloud: "Attach all" in the attach dialog.
    • Computer use: the chosen System One engine (Jev or Laya) is named everywhere.
    • Recommendations: Jev suggests relevant wiki pages for a session's opening prompt.

    Removed

    • The Claude auth badge in the top bar, and the Recent messages list in the session controls popover.

    Known issues

    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are signed (Restart Labs LLC), but SmartScreen may still warn while the publisher builds reputation.
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • Linux has no automated install smoke test yet.
    • v0.9.0 can't auto-update. Reinstall manually once.
  2. v0.9.28

    Changes

    • Sessions: reverts the "work in progress" indicator for background commands and subagents added in v0.9.26.

    Known issues

    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are signed (Restart Labs LLC), but SmartScreen may still warn while the publisher builds reputation.
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  3. v0.9.27

    New

    • Chat: model and context move into the composer toolbar.
    • Desktop launcher: "Recommend agent & model" moves into the Advanced section.

    Fixes

    • Setup: cloud sign-in continues the wizard instead of skipping to the app.
    • Security: the host's GitHub token is never lent to users on a multi-user install.
    • macOS: no Microphone prompt on first click.
    • Chat: a background shell command no longer gets a chat-band pill.

    Removed

    • The discontinued Gemini CLI provider.

    Known issues

    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are signed (Restart Labs LLC), but SmartScreen may still warn while the publisher builds reputation.
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  4. v0.9.26

    Highlights

    • Signed Windows installers. The .exe, .msi and bundled binaries are Authenticode-signed by Restart Labs LLC.
    • Connect GitHub without an OAuth app or a preinstalled gh; an existing gh is found instead of being reported missing.

    New

    • Remote Agentic Nodes: sessions are auto-placed across a cluster; a node tree with per-node drill-down and step-by-step setup diagnostics; "Investigate with an agent" for a setup that didn't complete.
    • Cloud sync: favourite projects and starred agents sync across your machines.
    • Laya: check for and install updates from Providers; CUDA is enabled automatically on NVIDIA hosts.
    • Forge: redesigned page, plus Decider Lab (Jev vs Laya vs Claude).
    • Pipelines: detect and offer built-in template updates for adopted copies.
    • Sessions: the panel and launcher picker are scoped to the selected workspace.
    • Report a bug: opens a pre-filled GitHub issue.
    • Providers: account usage limits auto-refresh when stale.

    Fixes

    • Desktop updates: no stale prompt after "Update & restart", plus an "Updated" toast.
    • Setup: "Cuttle CLI in your terminal" turns green after adding it to PATH, with a one-click fix.
    • Claude Code is no longer auto-installed.
    • ACP: slow-but-healthy boots no longer fail silently; a resumed session starts in the fresh-session permission mode.
    • Search: the command palette keeps keyboard focus contained.

    Known issues

    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are signed (Restart Labs LLC), but SmartScreen may still warn while the publisher builds reputation.
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  5. v0.9.25

    Highlights

    • Redesigned onboarding: five steps, including a Phone step, with SSO in the account card.
    • Recommendations: one prompt recommends an agent and model via Jev or Laya, on its own screen, and can start the recommended agent with your task.
    • Encrypted project sharing, with reversible shared history.
    • Claude Opus 5.5 is in the model registry and picker.

    New

    • System One (Jev/Laya): drives intent autoplay, and is available as pipeline nodes with setup links. Laya can be self-hosted on a Remote Host.
    • Sessions: show when a provider session has a background task, loop or cron armed; account usage and Claude/Codex subscription limits in session headers; a Linked strip with Linear issues; /skill invocations show as a badge.
    • Settings: one "Default for new sessions" (connection + model) for every provider; set the default runner from the Providers page.
    • Scheduler: falls back to Codex/OpenAI when Claude is verifiably unavailable.
    • Repos: AGENTS.md is discovered as a repo context file.
    • Admin: a "Restart now" button on the PTY daemon card; a one-time notice when your Claude Code CLI is stale.

    Fixes

    • Permissions: desktop update installs, git self-update, Git backup and shared GitHub credential changes are restricted to admins; subproject visibility is enforced.
    • Chat: any scroll-up during streaming stops autoscroll; private GitHub images render inline; attached images show in queued messages.
    • Sessions: resolved approval cards clear after reconnect; stuck watcher pills clear; ACP sessions are named immediately.
    • Providers: fixed model discovery failures and incomplete adapter installs; a fresh Codex connection discovers models.
    • Laya: WSL GPUs are detected.

    Known issues

    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are unsigned, so SmartScreen warns: choose "More info" → "Run anyway".
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  6. v0.9.24

    Fixes the Windows provider bug in 0.9.22 / 0.9.23

    On v0.9.22 and v0.9.23, the Claude Code and Codex providers report "CLI missing or executable unavailable" on Windows and cannot be selected at all. This release is the fix.

    • Local CLI discovery now works on Windows (#2631)
    • Discovery reads Windows' own environment-variable spellings (#2633)

    If you are on Windows and hit that error, this is the build to install.

    Also in this release

    Fixes

    • Desktop update: unblock installs behind auth, prompt on app open, check hourly (#2629)
    • Accept Claude CLI sign-ins that report no email/org metadata (#2627)

    Features

    • cuttle runners list|default and sessions spawn --list-runners (#2630)
    • New-session Scope defaults to the repo for single-repo projects (#2628)
    • New-session Project field uses a picker dialog
    • New-session Agent dropdown replaced with a picker dialog

    Install

    PlatformAsset
    WindowsCuttleCode-Setup-0.9.24.exe (or CuttleCode-0.9.24.msi)
    macOS (Apple silicon)CuttleCode-0.9.24-arm64.dmg
    LinuxCuttleCode-0.9.24-x86_64.AppImage or CuttleCode-0.9.24-amd64.deb

    Known issues

    • macOS is Apple-silicon only. There is no Intel build.
    • Windows installers trip SmartScreen. Choose "More info" -> "Run anyway".
    • .deb installs do not auto-update — the client detects a package install and defers to your package manager. The AppImage does auto-update.
    • Linux has no automated release gate. That lane is less verified than macOS.
    • v0.9.0 cannot auto-update to anything. Those installs need one manual reinstall to rejoin the update channel.
    • LICENSE.md links a repository that is not public, so that link 404s.
  7. v0.9.23

    New

    • Computer Use: Jev-assisted browser and desktop tasks, and optional guided Cua Driver support.
    • Remote Agentic Nodes: saved Remote Hosts join the cluster as workers automatically; pick known clusters and discover execution nodes.
    • New session: power-user fields move under Advanced.

    Fixes

    • Setup: provider setup works without a Cuttle account, and switching between cloud and no-auth takes effect live.
    • macOS: Homebrew bin dirs are on the local CLI's PATH.
    • Sessions: an agent the project doesn't know is refused instead of passed to claude --agent.
    • Shell: project dropdown items that overlap the title bar are clickable.

    Known issues

    • Windows: the Claude Code and Codex providers report "CLI missing or executable unavailable" and can't be selected. Fixed in v0.9.24.
    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are unsigned, so SmartScreen warns: choose "More info" → "Run anyway".
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  8. v0.9.22

    Highlights

    • Providers overhaul: a Providers page with grouped accounts and logos; existing Claude and Codex CLI sign-ins are reused; AmpCode and Custom providers; one shared model picker (provider · account · model) across launch and settings.
    • ACP everywhere: Ralph, BigRalph, Gauntlet, scheduled agents, pipeline nodes and Discord/Slack bridges run on your chosen provider. Local model servers and Offline mode run on a built-in runner without a Claude terminal.
    • Billing: account subscriptions with in-app payments. Every plan includes unlimited devices.

    New

    • Sessions: the New Session popover remembers project and agent, with Reset controls.
    • ACP chat: scroll up to load earlier history inline; cancel a queued message before it sends; project skills in the slash menu; browser and Computer Use tools for local sessions.
    • Remote Agentic Nodes: guided k3s setup for development sessions.
    • Model swap: "Stop and continue" a running Remote Inference session.
    • Setup: first-time setup establishes a working coding provider and guides first-workspace setup and GitHub linking.
    • Integrations: route channels to agents, with chat access policies.
    • Projects: skills, agents and repository removal on the project overview.

    Fixes

    • ACP: the first message sent while a session starts no longer hangs "queued"; sessions survive a server restart; signed-out Claude sessions say "Sign in needed" and can be renewed from the browser.
    • Security: tighter scoping for git status, cloud status, Org Globals and project hierarchy metadata; query strings are no longer logged; device codes expire before session minting.
    • Processes: leaked browsers and session process trees are reaped.
    • Chat: consecutive tool calls fold together; images attached to ACP sessions render.
    • Pipelines: templates repaired, and false-success runs are prevented.
    • Phones: cloud sign-in completes on a phone.

    Known issues

    • Windows: the Claude Code and Codex providers report "CLI missing or executable unavailable" and can't be selected. Fixed in v0.9.24.
    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are unsigned, so SmartScreen warns: choose "More info" → "Run anyway".
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  9. v0.9.21

    Desktop installers for CuttleCode v0.9.21.

    Changes since v0.9.20:

    • Features: native Codex sign-in and Cursor, Grok, and OpenCode providers; filterable session history; pipeline loop visualization and sandboxed Rust transforms; themed browser companion with per-user access controls; streamlined remote SSH key setup.
    • Fixes: preserve session artifact links; persist local ACP connections across server restarts; resume saved ACP sessions and improve model-swap recovery; retire lost daemon sessions and expose saved recovery; isolate Remote Inference connections and credentials by user; keep the ACP Discover entry within its use-case limit.
    • Release: bump desktop installer version to 0.9.21.

    Known limitations:

    • macOS is Apple Silicon (arm64) only; no Intel installer.
    • Windows may trigger SmartScreen. The Windows signing certificate has not been verified.
    • MSI installs require rerunning the MSI; .deb installs require the package manager. Automatic downloads are enabled for supported updater lanes; applying an update must safely stop running services.
    • Linux has no equivalent of the macOS release smoke gate.
    • v0.9.0 users need a manual reinstall to enter the supported update path.
    • The license's private source-repository link is inaccessible to public users.

    The macOS app, DMG, and update ZIP are configured for signing and notarization. Installation and update behavior on Windows/Linux has not been manually verified for this release.

  10. v0.9.18

    Fixes

    • macOS: builds no longer die at launch. The app name now matches its helper, and the update feed is verified end to end.
    • BigRalph: a dozen accuracy fixes. Cards and the task graph name the models actually used, show iteration durations and what a blocked story is waiting on, stop calling live loops "pending" or dead runs "running", and the Edit-graph sheet no longer queues edits the server rejects.
    • Mobile: back arrow instead of a down chevron in the session header.

    New

    • Mobile: account preferences match desktop, and the launch sheet has the runner picker.
    • Intents: the autoplay strip reads as a card with a live badge.

    Known issues

    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are unsigned, so SmartScreen warns: choose "More info" → "Run anyway".
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  11. v0.9.17

    Highlights

    • External agents as sessions (experimental): Cuttle can act as an ACP client, so agents like Codex (via Zed's codex-acp adapter) run as first-class sessions. Enable under Account → Experimental features.
    • BigRalph: the task graph is the default loop view, shows run phase, waves and lanes live, and can be edited mid-run. Waves are on by default.

    New

    • Browser extension: drives the tabs you share.
    • Files: download a folder path chip as a streamed zip.
    • Chat: running background subagents dock below the log.
    • Intents: sessions spawned by an intent's sessions inherit the intent link.
    • Sessions: running Ralph/BigRalph loops show in the sessions pane.
    • Pipelines: the running node animates.
    • Workspaces: fresh installs land on the linked home workspace instead of a Default workspace.
    • Cloud dashboard: account, devices and workspace pages redesigned; you can create workspaces and revoke devices yourself.

    Fixes

    • Desktop: the packaged server no longer dies on boot from a missing dependency.
    • BigRalph: about 20 fixes to run cards, status labels, failure reasons and the launch dialog, so a run's status is truthful; lane worktrees are pruned instead of leaked.
    • Auth: protocol-relative next redirects after login are rejected.
    • Mobile: the "Show hidden sessions" toggle appears in the mobile list.
    • Sessions panel: "you are here" highlighting fixed for intent chats and hidden rows.
    • Intents: one toast when research completes, not two.

    Known issues

    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are unsigned, so SmartScreen warns: choose "More info" → "Run anyway".
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  12. v0.9.15

    Desktop installers for CuttleCode 0.9.15.

    The previous public release was 0.9.12 — 0.9.13 and 0.9.14 were tagged but never published, so this release carries 83 commits since the last thing you could download.

    Downloads

    PlatformFile
    macOS (Apple Silicon)CuttleCode-0.9.15-arm64.dmg
    WindowsCuttleCode-Setup-0.9.15.exe (or CuttleCode-0.9.15.msi)
    LinuxCuttleCode-0.9.15-x86_64.AppImage (or CuttleCode-0.9.15-amd64.deb)

    What changed since 0.9.12

    Setup & sign-in (the big one) — the first-run wizard was rebuilt into a single funnel: one "Get started" CTA, the account step is now the only sign-in fork, the Cuttle cloud account is preselected and marked recommended, prerequisites are clickable/copyable and installable in place, the Cuttle CLI is a required prerequisite, the device-code link step is cancellable, and there's a scannable Tailscale QR in the integrations step. A fresh install now boots ready to sign in without a restart, and a stranded local install can "Continue without an account".

    Ralph / BigRalph — task graph view for PRDs, story dependencies and a stories-per-iteration knob, parallel subagent fan-out over disjoint ready stories, the PRD as a living document during a run, and for BigRalph: waves, a mid-run checkpoint judge, a fan-out knob for inner runs, and parallel lanes as the escalation layer.

    Intents v2 — a full overhaul (#2326) plus ~15 follow-up fixes: plan steps tick live as Ralph iterations finish, a spawn_session autoplay verb, a judge that can see the PR, the priority label is back, and the post-PR/post-merge autoplay lifecycle works again.

    Sessions & chat — fork a session into a new one with the same context, a "Wrap session names" view option, pasted images render in the transcript, swipe/arrow navigation in the image viewer.

    Other — Claude Fable 5.1 added and set as the Fable default; the PTY daemon lane defaults ON for native installs; cloud moved to cuttlecode.dev (auth email now from noreply@send.cuttlecode.dev, api.codecc.ai shimmed so pre-move builds keep working); "CCC" purged from user-facing copy.

    37 features, 33 fixes, 1 perf fix (intent detail page loaded three times).

    Known limitations — please read

    • macOS is Apple Silicon only. No Intel build. The app, the zip and the dmg are signed with a Developer ID, notarized and stapled — it opens without a Gatekeeper prompt.
    • Windows installers are unsigned and will trip SmartScreen. Verified in this build's log: electron-builder reports no signing info identified, signing is skipped. Choose "More info" → "Run anyway".
    • .deb installs do not auto-update. The client detects a package-manager install and defers to it. The AppImage auto-updates normally; so do Windows and macOS.
    • Linux has no automated release gate. macOS installers are smoke-tested end-to-end on real hardware before publish (signature, staple, node-pty, a live 10s session); Windows and Linux are not. The Linux lane is the least verified.
    • v0.9.0 installs cannot auto-update to this. They shipped unsigned, before the updater's darwin lane worked. Those users need one manual reinstall.
    • LICENSE.md still links a private repo and will 404.
  13. v0.9.12

    Desktop installers for CuttleCode 0.9.12. 18 commits since v0.9.11.

    Install

    PlatformFile
    macOS (Apple silicon)CuttleCode-0.9.12-arm64.dmg
    WindowsCuttleCode-Setup-0.9.12.exe (installer) or CuttleCode-0.9.12.msi
    LinuxCuttleCode-0.9.12-x86_64.AppImage or CuttleCode-0.9.12-amd64.deb

    Read this before you install

    • macOS is Apple silicon only. There is no Intel build.
    • The Windows installers are unsigned and will trip SmartScreen — "More info" → "Run anyway". This build's log confirms it: every signing with signtool.exe line is followed by no signing info identified, signing is skipped … cscInfo=null. No Authenticode certificate is wired up.
    • .deb installs do not auto-update. The client detects a package install and defers to your package manager. The AppImage does auto-update.
    • Linux has no automated release gate. macOS installers are smoke-tested on real hardware before publish (signature, notarization, staple, a live session); Windows and Linux are not.
    • v0.9.0 cannot auto-update to anything. It shipped before the updater's macOS lane worked. If you are on 0.9.0, install this one by hand once.
    • LICENSE.md still links a private repo that 404s for the public.

    macOS is signed, notarized and stapled — app, zip and dmg. Windows and the Linux AppImage self-update; macOS auto-update works from 0.9.1 onward.

    Features

    • Discover: plain-English "what is it" and use cases on every feature page
    • Advisor: the Auto/Off digest mode follows the user, not the browser
    • Mobile: one header row instead of two

    Fixes

    • Runtime link: an unusable runtime credential no longer strands the runtime unlinkable (the desktop 401)
    • Sessions: Resume revives the same session instead of duplicating it
    • Chat: an image attachment no longer leaves a duplicate stuck bubble; the answer you gave an AskUserQuestion is now shown
    • Web: the socket has a working fallback transport, so a dead websocket is no longer a dead app
    • macOS: reclaims the two /dev/ptmx fds node-pty leaked per spawn
    • Pipelines: a node whose handoff file is missing required keys now fails instead of hanging, and handoff-contract failures surface in status and events
    • Git: falls back to your global config / GitHub identity before the ccc@local placeholder
    • Discord: retries bot startup with backoff when the boot-time connect fails
    • Dev-instance reaper: discovers instances owned by non-server checkouts

    Plus the rename to the full name CuttleCode in the app chrome and tray.

  14. v0.9.11

    Desktop installers for CuttleCode 0.9.11. 62 commits since v0.9.10.

    Install

    PlatformFile
    macOS (Apple silicon)CuttleCode-0.9.11-arm64.dmg
    WindowsCuttleCode-Setup-0.9.11.exe (installer) or CuttleCode-0.9.11.msi
    LinuxCuttleCode-0.9.11-x86_64.AppImage or CuttleCode-0.9.11-amd64.deb

    Read this before you install

    • macOS is Apple silicon only. There is no Intel build.
    • The Windows installers are unsigned and will trip SmartScreen — "More info" → "Run anyway". This build's log confirms it: every signing with signtool.exe line is followed by no signing info identified, signing is skipped … cscInfo=null. No Authenticode certificate is wired up.
    • .deb installs do not auto-update. The client detects a package install and defers to your package manager. The AppImage does auto-update.
    • Linux has no automated release gate. macOS installers are smoke-tested on real hardware before publish (signature, notarization, staple, a live session); Windows and Linux are not.
    • v0.9.0 cannot auto-update to anything. It shipped before the updater's macOS lane worked. If you are on 0.9.0, install this one by hand once.
    • LICENSE.md still links a private repo that 404s for the public.

    macOS is signed, notarized and stapled — app, zip and dmg. Windows and the Linux AppImage self-update; macOS auto-update works from 0.9.1 onward.

    Features

    • Chat pops out into a floating Picture-in-Picture window
    • Sessions: infinite-scroll past sessions, Mark unread, Go to intent
    • Mobile: the desktop sessions panel in a phone's shape, long-press context menu, Intents in the bottom nav
    • Admin: a Diagnostics tab for machine health and worktree management
    • Intents: per-intent base branch for PRs and worktrees
    • Auth: one-button "Log in with your browser"
    • Install: one-click tailnet address for copy-paste install commands
    • Agents: roomier wizard with an expandable system prompt
    • A live compaction animation in the session chat view

    Fixes

    • PTY daemon: survives a Windows in-app update instead of dying with the server; no longer dies with the server's cgroup; an isolated worktree's daemon is no longer immortal; a test process can never take over the real daemon
    • Chat: a queued message no longer vanishes on a Chat ⇄ Terminal toggle; project-skill slash commands actually run; every blocking TUI dialog is surfaced; bare https image URLs embed inline; the compaction row stays in sync across a re-entry
    • Desktop: right-click Cut/Copy/Paste; the chat pop-out works and pins to the session you popped out; macOS self-update restart timeout fixed
    • Install: the node check works on PowerShell 5.1, and an apostrophe in the machine name no longer breaks the install command
    • Ralph: a session waiting on a live background task is no longer idle-killed; iteration sessions render their conversation in chat view
    • Stalled updates and prompt answers recover; Retry escalates to a reload when the socket can't come back

    Plus the rename to CuttleCode across every surface, and the update feed now points at this repo.

  15. v0.9.10

    Highlights

    • Code Command Center is now Cuttle Code. The app is renamed, and the ccc CLI is now cuttle (ccc still works as an alias).
    • New layout: the sessions pane docks on every page and the nav shrinks to a rail.

    New

    • Cloud: linked-devices management, with 3 device slots on the free plan. Approving a device link signs you in, and cloud-linked runtimes sync their projects by default.
    • Desktop (Linux): the AppImage gets a launcher entry and an install flow, and the entry stays valid across updates.
    • Repos: registered repo checkouts stay current with their remote.
    • Settings: a cloud-sync toggle.
    • PTY daemon (opt-in): Docker lane.

    Fixes

    • Updates: the page reloads after a self-update instead of stalling on the old bundle; launchd supervision survives self-updates on macOS.
    • Sign-in: OAuth works in installed web apps; SSO starts from the handoff callback instead of dead-ending at /signup; the first sign-in can claim admin on an instance with none.
    • Sessions: a nested claude no longer hijacks its parent session's chat.
    • Connection: the Retry button actually retries, and a zombie socket heals even on a tab that never backgrounds.
    • Themes: the five light palettes are readable.
    • Chat: question preambles are no longer cut off at a numbered list.
    • Desktop: a page that loads without its stylesheet recovers.
    • Ralph: the ExitPlanMode menu is auto-approved; invalid plan models are rejected at run creation.

    Removed

    • Browser voice input (wake word and dictation) in the coding assistant.

    Known issues

    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are unsigned, so SmartScreen warns: choose "More info" → "Run anyway".
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  16. v0.9.9

    New

    • Chat: plan review gets a proper reading surface.
    • Chat: live subagent status on the Agent row.

    Fixes

    • Sessions: idle sessions are no longer reaped on a timer, only under PTY pressure.
    • Sessions: a dropped single-digit answer is re-sent instead of stranding you; the reconciler waits for the screen to settle before reading it.
    • Chat: the code-block copy button works and confirms with a toast.
    • Chat: a staged free-text answer on a batched question is shown instead of swallowed.
    • Windows setup: setup checks read the full persisted PATH (HKLM + HKCU).
    • UI: the setup banner no longer covers the bottom of the app.

    Known issues

    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are unsigned, so SmartScreen warns: choose "More info" → "Run anyway".
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  17. v0.9.8

    Two operator-reported desktop bugs, both reproduced before the fix and verified after.

    Fixed

    Fresh install skipped onboarding. The tray opened the app window as soon as the web port was listening, without waiting for the API server. AuthGuard's single /api/auth/me probe lost that race, and its .catch(() => {}) failed open — the app rendered as system@ccc.local and never offered cloud sign-in until the user quit and relaunched. Fixed on both layers: the guard now retries (8 attempts, ~14s) before failing open, and the tray waits on the API port as well as the web port.

    Cloud sign-in dropped the provider profile (name + avatar). Discord's handle lives in user_metadata.user_name, which the name chain never checked, and createUser() had no avatarUrl parameter at all — so users landed with an email-prefix name and no avatar. Both are now extracted and refreshed on every sign-in across all three identity branches. The provider metadata is treated as untrusted: type-checked, length-capped, and the avatar restricted to http(s) URLs.

    Changes since v0.9.7

    Fixes

    • df82681ea first-run: close the first-launch race that silently skipped onboarding
    • 5c60b66c6 auth: carry the provider profile (name + avatar) through cloud sign-in
    • 02f9672e3 auth: resolve the browser cookie on public paths so setup writes stop 403ing admins
    • b9cdc84a1 pipeline: single-node watchdog no longer force-succeeds unfinished nodes (#2038)

    CI / tests

    • c966af7be e2e: install the claude CLI on the runner — 55 failures shared one cause
    • 53b4e3adc wal: assert the drained WAL at block end, not a load-sensitive poll count

    How far the verification goes

    Both fixes were reproduced-before and verified-after in an isolated instance, and the tray half of the first-run fix was exercised under a real Electron shell (Xvfb, with the API port unbound).

    Not verified: the packaged installer on a fresh machine, and a live Discord sign-in round-trip. No gate in this pipeline covers either.

    Known limitations

    • macOS is arm64-only. No Intel build.
    • Windows installers may trip SmartScreen. No Authenticode certificate is wired through electron-builder.yml. Something on the Windows build host does invoke signtool.exe, but that certificate has not been identified — treat Windows signing as unconfirmed rather than assuming either way.
    • .deb installs do not auto-update — the client detects a package-manager install and defers to it. Upgrade with your package manager. The AppImage does auto-update.
    • Linux has no packaging QA gate. macOS is verified against the shipped bytes (verify-mac); Windows and Linux are not.
    • LICENSE.md:1 still links a private repo, which 404s for the public.

    macOS is signed, notarized and stapled (app, zip and dmg) and auto-updates via the Squirrel.Mac .zip. Windows and the Linux AppImage self-update.

  18. v0.9.7

    New

    • Chat: images render inline in chat turns.
    • PTY daemon (opt-in, off by default): sessions and Ralph iterations can survive a server restart. Phases 2–5 ship behind a flag.

    Fixes

    • Context meter: no longer shows 100% on Claude 5 models (assumes the 1M window).
    • Cloud: token verification uses the built-in default and says why it fails.

    Known issues

    • macOS builds are Apple Silicon (arm64) only.
    • Windows installers are unsigned, so SmartScreen warns: choose "More info" → "Run anyway".
    • .deb installs don't auto-update; update through your package manager. The AppImage, Windows and macOS builds auto-update.
    • v0.9.0 can't auto-update. Reinstall manually once.
  19. v0.9.6

    CCC 0.9.6 — desktop installers.

    What changed since 0.9.5

    fix(login): a denied window.open in the desktop shell is not a blocked popup (#2170)

    On Windows, "Continue with Discord" failed with "Enable pop-ups to sign in with this provider" on machines with no popup blocker involved. 0.9.5 correctly routed the desktop shell to the handoff flow; the failure simply moved one line further down. Handoff opens the cloud callback with window.open and treated a null return as a blocked popup. Inside the shell null means something else: the link policy opens the URL in your system browser and then denies the in-app window, so the renderer gets null even though the browser tab opened correctly. The popup worked — the check misread it.

    popupWasBlocked() now only treats null as a block outside the shell, and the notice tells shell users to finish signing in in their browser rather than pointing at a tab that isn't in the app.

    How far this is verified

    The popup check itself is unit-tested in both directions: a genuinely blocked popup in a normal browser still reports as blocked, and a null from the shell's deny-after-open policy does not — invert the guard and the tests fail.

    The full Discord sign-in round-trip is still unverified end-to-end. Proving it needs a real Electron shell plus a live provider login, which no CI gate covers. In particular, whether pollHandoff completes after you sign in has not been observed by anyone yet. This is the third fix on this path (0.9.5 fixed the redirect branch, 0.9.6 fixes the popup check). Treat cloud sign-in as improved, not as known-good — and please report what you see.

    Known issues — stated up front, not surprises

    • macOS is arm64-only. No Intel build.
    • Windows installers will likely trip SmartScreen. No Authenticode certificate is wired through electron-builder.yml. The Windows build host does invoke signtool.exe, but that certificate has not been identified, so treat these installers as unsigned and expect the "Windows protected your PC" prompt (More info → Run anyway).
    • .deb installs do not auto-update — the app detects a package install and defers to your package manager. The AppImage does auto-update.
    • Linux ships without a QA gate. macOS has a signed-and-notarized smoke gate on the shipped bytes; Windows and Linux have no equivalent, so those lanes are less verified.
    • 0.9.0 installs cannot auto-update to anything — they shipped before the updater was unblocked. Those users need one manual reinstall.
    • LICENSE.md links a private repo that 404s for the public.

    macOS is signed, notarized and stapled (app, zip, and dmg), and auto-updates via the .zip. Windows and the Linux AppImage self-update.

    Assets

    CCC-Setup-0.9.6.exe / CCC-0.9.6.msi (Windows) · CCC-0.9.6-arm64.dmg (macOS, Apple silicon) · CCC-0.9.6-x86_64.AppImage / CCC-0.9.6-amd64.deb (Linux). The -mac.zip and latest*.yml files are the auto-update payloads.

  20. v0.9.5

    CCC desktop installers for macOS (Apple silicon), Windows, and Linux.

    Why this release exists

    v0.9.4 was installed on a real Windows machine and cloud sign-in — the default account path — did not work. This release is that single fix (#2167). Nothing else changed.

    Clicking "Continue with Discord" left the app permanently dead. The provider page opened in Chrome, sign-in succeeded there, and the app window sat on /login forever with every provider button greyed out, with no way back. The desktop shell hands any non-app URL to the system browser, so the provider redirect could never return to the app window — and the button state was never reset on that branch. The shell now uses the handoff flow instead (open the cloud callback, poll for the session, no redirect needed), and the buttons re-enable after 10 seconds so this class of failure cannot leave dead UI again.

    Reopening the app flipped between "Welcome to CCC" and "Loading" forever. An authenticated instance with no users yet reports both "setup complete" and "needs setup", so two redirects bounced off each other indefinitely. That state now goes to /login, which is where the next action actually is.

    Honest caveat on the first fix: the loop fix was reproduced and confirmed settling on /login. The OAuth handoff change has not been verified end-to-end — that needs a real Electron shell and a live Discord round-trip, which nobody has run yet. If cloud sign-in still misbehaves for you, please say so.

    Known issues — please read before installing

    • macOS is Apple silicon only. There is no Intel build.
    • Windows installers may trip SmartScreen. No Authenticode certificate is configured in the build, so expect a "Windows protected your PC" prompt — choose More info → Run anyway. Some Windows binaries in this build do carry a signature applied by the build host, but that certificate has not been identified, so treat these installers as unsigned.
    • .deb installs do not auto-update. The app detects a package-manager install and defers to it; update with your package manager. The AppImage does auto-update.
    • Linux is the least verified platform. There is no automated smoke gate for Linux the way there is for macOS.
    • v0.9.0 cannot auto-update to this or any release. It shipped unsigned and before the updater's macOS lane worked. Those installs need one manual reinstall from this page.
    • LICENSE.md links a repository that is not public, so that link 404s.

    macOS is signed, notarized and stapled (app, zip, and dmg), and auto-updates. Windows and the Linux AppImage auto-update.

    Install

    • macOS — CCC-0.9.5-arm64.dmg
    • Windows — CCC-Setup-0.9.5.exe (or CCC-0.9.5.msi)
    • Linux — CCC-0.9.5.AppImage (auto-updates) or ccc_0.9.5_amd64.deb
  21. v0.9.4

    CCC desktop installers for macOS (Apple silicon), Windows, and Linux.

    First run, on a real machine

    This release is mostly about the first fifteen minutes. Six separate first-run and onboarding defects were found on a real Windows install and fixed:

    • The setup wizard was unreachable after upgrading from an earlier install.
    • The Welcome screen could loop, and could report "Admin access required" to the very first user.
    • The claude CLI was not detected on Windows even when it was installed.
    • An existing claude sign-in was not detected, so you were asked to log in again.
    • The bash PATH hint shown during setup was wrong on Windows.
    • The placeholder logo was replaced.

    The sidebar also shows the real application version now. It was hardcoded to v0.1 in every build that has ever shipped; this one reads the version it was actually built from.

    Also in this release

    • Sessions pane grouped by project, and you can arrange it (#2142).
    • PTY internals: Phase 1 of the daemon refactor (#2158) — carves the PtyHandle seam. Internal, no behaviour change intended, but it is the largest change in this release; if you see terminal or session-lifecycle oddities, that is the first place to look.
    • A running session's thinking indicator keeps animating (#2164).
    • Sessions are killed as a whole process tree on macOS/Linux (#2154).
    • A failing database migration now names the version that failed instead of surfacing a bare SQLite error (#2148).
    • Session retention skips the search index scan when nothing is stale (#2153).
    • Packaging: restored the payload build step and added a parse-check over every packaging script. This is the bug that broke v0.9.3 — that version was never published, and the number was burned rather than re-cut.

    Known issues — please read before installing

    • macOS is Apple silicon only. There is no Intel build.
    • Windows installers may trip SmartScreen. No Authenticode certificate is configured in the build, so expect a "Windows protected your PC" prompt — choose More info → Run anyway. Some Windows binaries in this build do carry a signature applied by the build host, but that certificate has not been identified, so treat these installers as unsigned.
    • .deb installs do not auto-update. The app detects a package-manager install and defers to it; update with your package manager. The AppImage does auto-update.
    • Linux is the least verified platform. There is no automated smoke gate for Linux the way there is for macOS.
    • v0.9.0 cannot auto-update to this or any release. It shipped unsigned and before the updater's macOS lane worked. Those installs need one manual reinstall from this page.
    • LICENSE.md links a repository that is not public, so that link 404s.

    macOS is signed, notarized and stapled (app, zip, and dmg), and auto-updates. Windows and the Linux AppImage auto-update.

    Install

    • macOS — CCC-0.9.4-arm64.dmg
    • Windows — CCC-Setup-0.9.4.exe (or CCC-0.9.4.msi)
    • Linux — CCC-0.9.4-x86_64.AppImage or CCC-0.9.4-amd64.deb

    CCC-0.9.4-arm64-mac.zip is the macOS auto-update payload, not the installer.

  22. v0.9.2

    The first build where CCC Cloud sign-in works out of the box, plus a guided first-run setup.

    Install

    PlatformDownload
    macOS (Apple Silicon)CCC-0.9.2-arm64.dmg
    WindowsCCC-Setup-0.9.2.exe or CCC-0.9.2.msi
    LinuxCCC-0.9.2-x86_64.AppImage or CCC-0.9.2-amd64.deb

    On v0.9.1 you do not need this page — the app updates itself.

    What's new

    Cloud sign-in works in a packaged install. This is the headline fix for installers specifically. The CCC Cloud endpoint is now compiled into the build (packages/cloud/src/defaults.ts) instead of being expected from the environment. The web credentials are inlined at build time, and nothing in the release pipeline supplied them, so every installer before this one simply could not sign in to the cloud — and could not be pointed at it afterwards either. It now works from a stock install, with the environment variables still taking precedence for self-hosted deployments.

    First-run setup wizard. A new /setup flow greets a fresh install: an express "quick start" path, or a guided one covering environment, account, prerequisites, integrations and advanced settings. Closed-set settings render as dropdowns rather than free text.

    CCC Cloud is the default account path. Local accounts still work but are marked legacy.

    Instance configuration editor under Settings → Admin, driven by a typed registry. Database-backed settings apply live; environment-backed ones tell you a restart is required.

    Safe restart. Restarting from the UI now warns you first, with counts of the running pipelines, automations and live terminal sessions it is about to interrupt.

    Optional ccc-cli prerequisite check in setup — informational only. It never blocks and never asks for elevation.

    Fixes. A chat message rejected by the terminal's modal is handed back instead of lost; an in-flight /compact no longer marks a session that ended mid-turn; a session that boots into a blocking dialog now leaves starting; the question card is restored when an answer never reached the terminal.

    Known limitations

    • macOS is Apple Silicon only. No Intel build.
    • Windows installers show a SmartScreen warning — no Authenticode certificate is configured.
    • .deb installs do not auto-update — the app defers to your package manager. The AppImage does auto-update.
    • The AppImage needs FUSE 2 (libfuse2), or run it with --appimage-extract-and-run.
    • Still on v0.9.0? Download and reinstall once. v0.9.0 shipped before the update lane was unblocked and cannot pull this release automatically.
    • Linux has no dedicated QA target; that lane ships less verified than macOS.

    Changes since v0.9.1

    15 commits across 8 PRs.

    • feat — first-run setup wizard, instance config editor and safe restart; CCC Cloud as the default account path; closed-set settings as dropdowns
    • fix — chat message returned when the terminal modal refuses it; /compact on a session that ended mid-turn; sessions stuck in starting behind a blocking dialog; question card restored when the answer never reached the PTY; migration v216 locked; cloud-web config guard kept env-only
    • refactor — load guard de-tenanted to operator-declared heavy models
    • chore/docs/test — advisor triage brief removed (stops spending quota by default), Motion Studio brought current for the Linux server, added setup and auth route test coverage
  23. v0.9.1

    The first signed and notarized CCC release — and the first to be launched and smoke-tested by CI before being published.

    Install

    PlatformDownload
    macOS (Apple Silicon)CCC-0.9.1-arm64.dmg
    WindowsCCC-Setup-0.9.1.exe or CCC-0.9.1.msi
    LinuxCCC-0.9.1-x86_64.AppImage or CCC-0.9.1-amd64.deb

    What's new

    macOS is signed, notarized and stapled. The app, the auto-update payload, and the .dmg itself all carry an Apple-notarized Developer ID signature (Restart Labs LLC). No more "unidentified developer" warning, and no right-click → Open dance. Because the ticket is stapled, this verifies even offline.

    macOS auto-update now works. Squirrel.Mac refuses unsigned updates, which is why earlier builds could never update themselves. That blocker is gone.

    Every release is now launch-tested before it goes public. A new pre-publish gate installs the actual shipped .dmg on a real Mac, verifies Gatekeeper acceptance and the stapled ticket, then launches the app and confirms it can spawn a live terminal session. If any check fails the release stays a draft and never reaches you.

    Clearer error when the host is out of pseudo-terminals. A machine that has exhausted its pty pool used to produce a bare posix_spawnp failed.; it now says what actually happened and how to find the leak.

    Known limitations

    • Coming from v0.9.0? You must download and reinstall once. v0.9.0 shipped before the update lane was unblocked, so it cannot pull this release automatically. This is the last manual step on macOS.
    • macOS is Apple Silicon only. No Intel build.
    • Windows installers show a SmartScreen warning — no Authenticode certificate.
    • .deb installs do not auto-update — the app tells you to use your package manager. The AppImage does auto-update.
    • The AppImage needs FUSE 2 (libfuse2), or run it with --appimage-extract-and-run.
    • Linux has no dedicated QA target; that lane ships less verified than macOS.

    Changes since v0.9.0

    9 commits: macOS signing + notarization (app, zip, dmg container), the pre-publish verify-mac gate, the pty-exhaustion error message, and CI runner fixes.

  24. v0.9.0

    CCC has not publicly launched, so the installer line has been reset to a pre-1.0 version. All previous releases (1.0.0–1.0.4) have been deleted from both repos. This is the first release of the 0.x line.

    Install

    PlatformDownload
    macOS (Apple Silicon)CCC-0.9.0-arm64.dmg
    WindowsCCC-Setup-0.9.0.exe (installer) or CCC-0.9.0.msi
    LinuxCCC-0.9.0-x86_64.AppImage (recommended) or CCC-0.9.0-amd64.deb

    Known limitations

    • Coming from a 1.0.x install? You must download and reinstall manually. 0.9.0 is a lower version number, so no 1.0.x install will ever be offered this as an update.
    • macOS cannot auto-update. The app is not signed with an Apple Developer ID, and Squirrel.Mac refuses unsigned updates — the updater reports "code signing required" and points you at this page instead of failing silently. Every macOS update is a manual .dmg download until a certificate is in place.
    • macOS is Apple Silicon only. No Intel build.
    • macOS and Windows installers are unsigned. macOS shows "unidentified developer" — right-click the app → Open once to bypass permanently. Windows shows a SmartScreen warning; the publisher name check is a no-op.
    • .deb installs do not auto-update — the app detects the package install and tells you to update via your package manager. The AppImage does auto-update.
    • Linux ships without a dedicated desktop QA target — that lane is explicitly untested.
    • The AppImage needs FUSE 2 (libfuse2) to run directly, or use --appimage-extract-and-run.

    Changes

    224 commits since the previous build: 115 fixes, 57 features, 20 performance, 8 docs, 6 tests, 2 refactors.