🪟 Windows TippsMicrosoft bringt Emoji 17.0 auf Windows 11(31.08.2026 um 08:16 Uhr)
🕵️ SicherheitslückenDropbox-Hack: Tausende Konten kompromittiert(02.09.2026 um 11:02 Uhr)
⚠️ Malware / Trojaner / VirenAtombomben-Frage trickst KI-Malware-Scanner aus(02.09.2026 um 12:46 Uhr)
🪟 Windows TippsWindows 11: Diese Tastenkürzel sollten Sie kennen(03.09.2026 um 09:53 Uhr)
🪟 Windows TippsMicrosoft bringt Emoji 17.0 auf Windows 11(31.08.2026 um 08:16 Uhr)
🕵️ SicherheitslückenDropbox-Hack: Tausende Konten kompromittiert(02.09.2026 um 11:02 Uhr)
⚠️ Malware / Trojaner / VirenAtombomben-Frage trickst KI-Malware-Scanner aus(02.09.2026 um 12:46 Uhr)
🪟 Windows TippsWindows 11: Diese Tastenkürzel sollten Sie kennen(03.09.2026 um 09:53 Uhr)

17 🕛 kürzlich 6 Min Lesezeit CVE-RADAR
0

GitHub: v0.9.3

↗ Quelle (GitHub · github.com)
🗣️ Stimme:
📑 Inhaltsübersicht
🐙
$ git clone https://github.com/Hmbown/CodeWhale.git

Codewhale is the public product from Shannon Labs. The codewhale

command, npm package, and release-asset names remain lowercase technical

identifiers. The legacy npm package deepseek-tui is deprecated and

receives no further releases. Users coming from v0.8.x legacy deepseek /

deepseek-tui names should migrate with docs/REBRAND.md.



Install


Recommended — npm (one command, all three entrypoints)


npm install -g codewhale

The wrapper downloads the matched codewhale, codew, and codewhale-tui

binaries from this Release and places them in the same directory.


Docker / GHCR


docker run --rm -it \
-e DEEPSEEK_API_KEY="$DEEPSEEK_API_KEY" \
-v codewhale-home:/home/codewhale/.codewhale \
ghcr.io/hmbown/codewhale:v0.9.3

The image ships the codewhale dispatcher, codew shim, and codewhale-tui runtime. The latest tag is also updated on release.


Cargo (Linux / macOS)


cargo install codewhale-cli codewhale-tui --locked

Both crates are required — codewhale-cli produces the codewhale dispatcher and codew shim, while codewhale-tui produces the interactive runtime that the dispatcher delegates to. Installing only one crate will fail at runtime with a MISSING_COMPANION_BINARY error.


Manual download — platform archives (recommended)


Each archive below contains the codewhale dispatcher, codew shim, and codewhale-tui runtime, plus an install script:





Platform
Archive
Install script




Linux x64
codewhale-linux-x64.tar.gz
install.sh


Linux ARM64
codewhale-linux-arm64.tar.gz
install.sh


Android ARM64 (Termux)
codewhale-android-arm64.tar.gz
install.sh


macOS x64
codewhale-macos-x64.tar.gz
install.sh


macOS ARM
codewhale-macos-arm64.tar.gz
install.sh


Windows x64 (installer)
CodeWhaleSetup.exe
NSIS setup


Windows x64
codewhale-windows-x64.zip
install.bat


Windows x64 (portable)
codewhale-windows-x64-portable.zip



Windows ARM64
codewhale-windows-arm64.zip
install.bat


Windows ARM64 (portable)
codewhale-windows-arm64-portable.zip




Unix (Linux / macOS):


tar xzf codewhale-<platform>.tar.gz
cd codewhale-<platform>
./install.sh

Windows:



  • For the installer path, run CodeWhaleSetup.exe; it installs codewhale.exe, codew.exe, and codewhale-tui.exe under %LOCALAPPDATA%\Programs\CodeWhale\bin and adds that directory to the current-user PATH.

  • Extract the archive for your machine: codewhale-windows-x64.zip or

    codewhale-windows-arm64.zip

  • Run install.bat (copies to %USERPROFILE%\bin)

  • Add %USERPROFILE%\bin to your PATH


The portable Windows archive skips the install script — extract and run from any directory. The NSIS installer is currently unsigned and may trigger Windows SmartScreen until a signing certificate is wired into the release pipeline.


Each platform also has bare, unarchived binaries attached below (codewhale-<platform>, codew-<platform>, and codewhale-tui-<platform>) — the npm wrapper and the in-app codewhale update download the matched runtime binaries, whereas the .tar.gz / .zip archives above are the recommended manual download and additionally bundle an install script. The legacy npm package deepseek-tui is deprecated and is not republished. For migration from v0.8.x legacy binary names, see docs/REBRAND.md.


Verify (recommended)


Download the checksum manifests from this Release and verify:


# Linux — archive bundles
sha256sum -c codewhale-bundles-sha256.txt --ignore-missing

# Linux — individual binaries
sha256sum -c codewhale-artifacts-sha256.txt --ignore-missing

# macOS
shasum -a 256 -c codewhale-bundles-sha256.txt --ignore-missing
shasum -a 256 -c codewhale-artifacts-sha256.txt --ignore-missing

What's in v0.9.3


This is the Codewhale v0.9.3 source candidate. It is not a published release

until the matching tag, packages, checksums, and release assets exist.


DeepSeek V4 Flash is now a first-class Codewhale route, and the agent-facing

tool surface has been reduced to the canonical action tools that current

models actually need. This release also hardens credential, authorization,

durability, compaction, and macOS File Provider boundaries while deleting

stale runtime and dependency surface.


Added



  • Native deepseek-v4-flash support over DeepSeek's Responses API, including

    stateless reasoning-item replay, semantic SSE terminal events, structured

    function calls and outputs, apply_patch, and model-aware wire-format

    selection. Exact current Flash IDs use Responses; future direct

    deepseek-vN-* model IDs inherit that route conservatively, while custom

    DeepSeek-compatible endpoints retain Chat Completions unless configured

    otherwise.

  • A pipe-only codewhale auth print-api-key handoff for explicitly selected

    providers. It shares Codewhale's home-scoped credential authority, refuses

    terminal output, and prevents sentinel placeholders from becoming live

    credentials.

  • Per-turn max_tool_calls enforcement at the engine admission gate, plus a

    named-file write scope with a separate read seam. The runtime now rejects

    over-budget calls before execution and keeps the operator's write boundary

    explicit (, ).

  • Skill discovery caches the merged catalog behind watched-mtime validation;

    large skill, engine, subagent, UI, and ambient-ocean test blocks now live in

    owned test seams.

  • Reasoning summaries stay in the user's language, complete jellyfish

    silhouettes relocate around transcript text, and cached ocean frames include

    their palette identity ().


Fixed



  • macOS sandbox extensions cover CloudStorage/File Provider workspaces without

    broadening unrelated paths; thanks report and

    reproduction.

  • Foreground shell state detaches before steering, so an interrupted command

    cannot keep owning the composer (PR .


Contributors


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf github.com.
↗ Original-Artikel auf github.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 38%
🟡 In Evaluierung 32%
🟢 Keine Auswirkung 10%
Spannende Innovation 20%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
5 Quellen
OpenAI’s new Astra model is finally here – why safety experts are worried
1 Quelle
Microsoft bringt Emoji 17.0 auf Windows 11
1 Quelle
Dropbox-Hack: Tausende Konten kompromittiert