NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1352 by repository stars
Last release 2 days ago
05 Oct 2026
Ships fairly regularly
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
5 months old
203 releases · first in 2026
One column per month.
More reliable managed macOS runners. Start with working Node/npm, acquire workspace ownership without extra lock utilities, and let detached daemons r
testbox download (verified in Blacksmith 0.4.57 and 0.4.58), OpenSSH scp, and compatible ps on macOS or Linux. Existing limits remain 256 files, 10 MiB compressed, and one 30-second collection deadline covering transfer and validation. PR 2043.nohup can detach in the user's launchd context, retain key-only authentication, and use fresh bootstrap connections. Close internal command-wrapper pipes before user execution so detached daemons do not hold completed commands open. PR 2051. Thanks @steipete.flock or lockf is not required, while preserving fail-closed recovery. PR 2051. Thanks @steipete.admin hosts reservation inspection and guarded admin hosts clear recovery without terminating instances or discarding cleanup obligations. PR 2057. Thanks @steipete.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
More reliable managed WSL2 runners. Run Linux workloads as the non-root crabbox user with Node/npm ready on PATH, keep detached daemons alive between
crabbox user with Node/npm ready on PATH, keep detached daemons alive between commands, and avoid headless WSLg and cloud-init startup stalls.crabbox with passwordless sudo and writable work/cache directories; use sudo for operations that require root. PR 1996, PR 2005, PR 2016.guiApplications=false in the Windows SSH user's .wslconfig, preserving other settings. Explicit desktop/browser requests retain the existing GUI configuration. WSL2 status probes allow up to 30 seconds; other SSH targets retain four seconds. PR 1996, PR 2005.linux_os=ubuntu:24.04 or ubuntu:26.04, defaulting to 26.04. Standalone Linux minting accepts CRABBOX_OS; explicit image overrides still take precedence, so the selector alone does not verify the guest OS or qualify an image. PR 2028.crabbox user with passwordless sudo, writable work/cache directories, and the managed Node path available. Keep the distribution alive between commands so detached Linux daemons survive until lease cleanup. PR 2008, PR 2016. Thanks @steipete.bunx checks. Preserve operator-owned tool paths across rebakes. PR 2009. Thanks @vincentkoc.Nothing published for this version
Less waiting for runners and coordinator requests. Use HTTP/2 where supported, close idle control connections promptly, and overlap AWS network discov
PUT /v1/runs/<run-id>; older coordinators cannot support the new recovery path. Updated coordinators retain the legacy POST route for older clients, and existing run IDs remain readable. PR 1970.crabbox-devtools-image-proof/v2 and cover failed and incomplete outcomes. Baseline measurements are descriptive; only candidate and promoted cohorts apply the benchmark policy. PR 1986.Nothing published for this version
Nothing published for this version
Faster runner startup. Reuse verified SSH endpoints within an operation, publish diagnostics while the workload continues, and overlap AWS quota check
crabbox bench check applies sample, failure, and p95 runner-time limits to every matched local benchmark group, with deterministic JSON and a failing exit status when the policy is not met.pnpm/action-setup with an exact version, including workflows that set up pnpm before Node, and keep the managed pnpm available to later steps.--no-sync runs. SSH access rebinding rejects conflicting provider identities, artifact validation is distinguished from workload exits, and readiness timeouts retain their real cause.bench check requires --max-p95-runner-total. Defaults are three successful samples and zero failures per matched group; p95 always needs at least three runner-total samples. No matches or missing telemetry fail the check. PR 1899.pnpm/action-setup requires an exact major.minor.patch version. Version inference, ranges, and other pnpm inputs require --github-runner; setup-node's cache: pnpm runs without caching during local hydration. PR 1953.7 but report blockedStage=artifacts and errorKind=provider-error; a workload that exits 7 remains command-exit. Automation should distinguish these outcomes. PR 1934.checkpoint create --json can emit crabbox.checkpoint.create.failure.v1 with outcome=not_submitted on a nonzero exit after verified local reservation removal. This does not certify source rollback or readiness; uncertain and post-submission failures keep their recovery state. PR 1952, PR 1963.crabbox bench check to enforce successful-sample, failure-count, and p95 runner-time limits across every matched local group; expose runner-total sample counts in benchmark reports. PR 1899. Thanks @vincentkoc.pnpm/action-setup with an exact version, including pnpm-before-Node workflows, preserve managed pnpm for later commands, and accept setup-node's cache: pnpm as an explicitly uncached run. PR 1953.7 and artifact enforcement. PR 1934, Issue 1894. Thanks @coygeek.--no-sync runs even when sync deletion is enabled, retaining normal replacement behavior for archive sync. PR 1959.--keep-on-failure for bound setup failures, retain reused sessions after admitted Tailscale preparation fails, and preserve primary codes and causes through cleanup or timing errors while distinguishing provider/artifact failures from command exits. PR 1947.Nothing published for this version
Nothing published for this version
Faster command startup. Commands begin without waiting for best-effort telemetry uploads, while run completion retains baseline samples and verified t
--keep-on-failure during preparation, and report retained recovery sessions when cleanup fails. Coordinator leases keep local credentials until provider cleanup is confirmed.--no-sync and required-artifact globs. SSH readiness stops promptly on host-key rejection, including Windows/WSL connections.cleanupCompletedAt and clears remote access after confirmed deletion. Older coordinators and historical leases without that evidence leave local claims and SSH credentials intact; after upgrading, retry stop for the exact lease when its provider identity is recorded. Missing identity without explicit no-resource evidence requires operator reconciliation. PR 1901.bench report now separates groups by source; records without one use unknown. Consumers should include the source in group keys and tolerate absent phase summaries on legacy records. Only successful observations contribute timing distributions. PR 1896.--no-sync and every --require-artifact glob in suggested failure retries, avoiding an unintended workspace reset or weakened evidence checks. PR 1933, Issue 1875, Issue 1895. Thanks @coygeek.localContainer.noHostname and CRABBOX_LOCAL_CONTAINER_NO_HOSTNAME to omit the explicit hostname for runtimes sharing a host UTS namespace; reject incompatible fixed-ID reuse while preserving default fingerprints. PR 1813, PR 1924. Thanks @atrawog.stop can finish cleanup after the container disappears, retaining recovery state for ambiguous or inaccessible runtimes. PR 1922.crabbox inspect --json. PR 1892. Thanks @vincentkoc.--keep-on-failure during preparation, and preserve successful clone commits across backend reporting failures. PR 1913.--keep-on-failure errors, and preserve command outcomes while distinguishing native transport failures. PR 1914.--keep-on-failure during preparation, and preserve primary outcomes through cleanup and timing errors, retaining provider keep policy and separate profile/resource cleanup budgets. PR 1908.--keep-on-failure for early failures, report retained recovery sessions after failed cleanup, and preserve command outcomes and native error causes through timing output; keep profile cleanup warning-only. PR 1905. Thanks @steipete.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
See where runner time goes. Final timing JSON and benchmark records now report total runner wall time and a bounded phase breakdown, including time sp
sync-plan --json now previews each provider's actual archive guardrails without contacting it.--keep-on-failure during preparation, report recovery sessions when cleanup fails, and preserve the original command result through cleanup and timing output.sync-plan --json. --force-sync-large keeps its normal override but cannot bypass Freestyle's 64 MiB compressed upload cap. SmolVM preparation failures preserve the existing workspace, while a later injection failure can still occur after clearing it. PR 1880, PR 1869, PR 1882.inspect CLI flag. PR 1889.sync-plan --json preview the configured provider's full-archive or dirty-delta guardrails accurately, without credentials or provider API calls. PR 1882. Thanks @steipete.--keep-on-failure, failed deletion reports a kept recovery session, and cleanup/timing errors preserve the primary exit; keep delegated command receipts when secondary cleanup fails. PR 1885. Thanks @steipete.--keep-on-failure, and timing errors preserve command exits; retain POSIX bridge cancellation and timeout causes. PR 1886. Thanks @steipete.--keep-on-failure, and timing errors no longer mask command exits; preserve observed abnormal exit codes. PR 1850. Thanks @steipete.--keep-on-failure; preserve cancellation and timeout causes and distinguish transport errors from command exits. PR 1845. Thanks @steipete.--keep-on-failure, and timing errors preserve the command outcome. PR 1843. Thanks @steipete.--restore-receipt, retire the failed candidate, and reject stale failed-revision updates. PR 1879. Thanks @vincentkoc.This tag was signed with the committer’s verified signature .
steipete Peter Steinberger
SSH Key Fingerprint: 0R9sOfREAbuojItYW9O6fvh2RHbgqVJyvk8FBS/35dk Verified Learn about vigilant mode .
Nothing published for this version
Nothing published for this version
Nothing published for this version
Users upgrading from v0.48.1 also receive the v0.49.0 changes , previously available through the Go module release.
Users upgrading from v0.48.1 also receive the v0.49.0 changes, previously available through the Go module release.
--script and --script-stdin through private SSH with literal arguments, environment profiles, activity refreshes, and cancellation support.compute.instances.get and compute.disks.get for typed identity operations. PR 1620, PR 1621.tenki login to select the workspace for new leases. PR 1741..git/crabbox-artifact-root symlink, pinning the artifact directory before the workload and rejecting invalid bindings before execution while retaining existing exit and publication guards. PR 1840. Thanks @steipete.--script and --script-stdin commands through the private SSH runner with literal trailing arguments, environment profiles, and provider activity refreshes; keep managed SSH credentials out of process arguments. PR 1781. Thanks @steipete.inspect --json. PR 1799. Thanks @steipete.Nothing published for this version
Nothing published for this version
Nothing published for this version
Sync that keeps working. Unreachable Git origins fall back to full-file sync, symlink retargets reach the runner, and Git overlays transfer a consiste
--class, while preserving custom and checkpoint snapshots.crabbox capacity require an updated coordinator; older coordinators reject these requests without falling back to ordinary creation or direct providers. PR 1692, PR 1752.tmpfs; preparation failures stop before image creation. PR 1692.timeout support for --kill-after; incompatible timeout implementations now fail preflight before the user command starts. PR 1736.checkpoint fork --lease-id for coordinator-managed native checkpoints, reusing the same child for matching requests while refusing changed, canceled, or terminal attempts. PR 1692. Thanks @Copilot.crabbox capacity and GET /v1/capacity for read-only snapshots of the authenticated owner's admission-equivalent count and effective limit across all months and orgs, without changing monthly usage or allocating resources. PR 1752. Thanks @steipete.409 create_canceled result and reason, and kept cleanup confirmation separate from cancellation. PR 1743.sync.baseRef before inferred defaults, avoiding deleted topic or stale default branches when a valid containing branch exists while preserving the selected commit and tree. PR 1759.inspect and non-wait status --json and conservative unknown-capacity fallback that preserves the workload exit. PR 1734.result..json and rejecting explicit .git or .crabbox paths before lease acquisition while preserving traversal checks. Issue 1751. Thanks @coygeek.DAYTONA_CONFIG_DIR and preserving explicit credentials and API-key precedence; expired tokens direct users to daytona login. PR 1772.ttl and idleTimeout in config show text and JSON without changing defaults or lease behavior. PR 1757.doctor --help and -h show diagnostic modes and primary options before the complete provider flag reference, so the installed CLI explains how to inspect providers, leases, recorded runs, and ponds. Issue 1754. Thanks @coygeek.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Corrected nested JUnit totals and preserved failed-case details so --fail-on-test-failures catches failures even when suite counters are missing or ze
--fail-on-test-failures catches failures even when suite counters are missing or zero, without double-counting parent aggregates.stop use one five-minute cancellation budget across inspection, claim waits, cleanup, release, and observation; local daemon lock waits now honor cancellation without reversing confirmed cleanup.config show text and JSON, including effective work-root defaults when selected, without Docker discovery or daemon access.checkpoint abandon for unresolved ordinary Machine0 captures: dispose of the verified source through its existing ownership claim while retaining the unresolved image record and blocking image reuse, deletion, or pruning.--ssh-port, ssh.port, or CRABBOX_SSH_PORT settings to retain automatic selection; explicit selection disables port fallback.env.allow, results.junit, and run.preflightTools lists now clear inherited values. Omit the key to inherit instead; clearing JUnit paths does not disable results.auto, and profile allowlists remain additive..crabbox/scripts store. Explicitly select additional files you need; use --download-on-failure for eligible Linux SSH failure downloads.Nothing published for this version
Keep the evidence when a run fails. Linux SSH runs can download selected artifacts after a confirmed workload failure with --download-on-failure ; --r
--download-on-failure; --require-artifact-change can reject stale, unchanged evidence instead of accepting files left by an earlier run.wsl2-sftp probe before upgrading; the v0.47.0 stdin fallback has been removed.--reclaim does not bypass this requirement.--no-sync. Remove it from runs, prewarm probes, and named jobs; Testbox manages workspace synchronization.amd64, must match fresh host evidence; remove the explicit setting to use automatic discovery.--download-on-failure retrieval after an owned nonzero workload exit, preserving the exit code and collecting selected evidence before failure bundles and teardown.--require-artifact-change checks with bounded content snapshots, created/changed/unchanged/missing timing states, and collection of only accepted bytes.--checkpoint-id, --retire-source, read-only --prepare-only admission, and explicit --discard-failed recovery on supported providers; Hetzner source retirement remains unavailable.providers sizes machine0 --with-context --json to show effective native size and region selection alongside the live catalog, preserving configured defaults and exact fixed-lease replay.amd64, now require fresh matching evidence after read-only ownership checks and before guarded claim publication; remove explicit architecture settings for automatic discovery, with measured or unknown evidence reported separately from offline defaults.wsl2-sftp probe before upgrading). Thanks @vincentkoc.pond release by leaving claim finalization to the provider.pond connect flags after the pond name so the documented pond connect <name> --export form starts tracked daemons instead of blocking in foreground mode.--no-sync with exit 2 before acquisition or reuse instead of silently delegating sync, including nonblank prewarm --probe-command and named jobs with noSync: true before warmup or dry-run planning.CRABBOX_CONFIG, matching the file selected for reads and writes. Thanks @coygeek.config show --json, with endpoint credential redaction and no daemon access.native in config diagnostics without probing the runtime or changing explicit architecture assertions. Thanks @coygeek.&& failure diagnostics for compound shell commands while retaining simple-chain explanations and workload exit behavior. Thanks @coygeek.cp --help. Thanks @coygeek.This tag was signed with the committer’s verified signature .
steipete Peter Steinberger
SSH Key Fingerprint: 1Xxneec8ppOSh9sXXimCjnfrcK2/SbQLeDV+WenvPiQ Verified Learn about vigilant mode .
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Added direct Daytona filesystem checkpoints with explicit stop consent, source restart, verified snapshot forks, and ownership-bound snapshot cleanup.
stop --force recovery through verified provider adoption or exact coordinator lease inspection without weakening ownership checks.--lease-id replay to local-container warmups, with exact container-intent matching and single-use released IDs.stop cannot verify the sandbox, instead of reporting release from an unverified not-found response.inspect --json, preserving pending, error, and retry signals plus the distinction between omitted and explicit releaseDeletesServer: false.This tag was signed with the committer’s verified signature .
steipete Peter Steinberger
SSH Key Fingerprint: 0R9sOfREAbuojItYW9O6fvh2RHbgqVJyvk8FBS/35dk Verified Learn about vigilant mode .
Nothing published for this version
Added fixed idempotent --lease-id replay to the Machine0 provider: an identical warmup adopts the existing VM instead of creating a second one, a drif
--lease-id replay to the Machine0 provider: an identical warmup adopts the existing VM instead of creating a second one, a drifted request fails with lease_id_conflict, and a released ID is single-use.--keep-on-failure for sync and setup failures.status --wait now actually waits, Blaxel stops its remote process when polling is interrupted, and status waits bound each in-flight provider call by the requested timeout.This tag was signed with the committer’s verified signature .
steipete Peter Steinberger
SSH Key Fingerprint: 1Xxneec8ppOSh9sXXimCjnfrcK2/SbQLeDV+WenvPiQ Verified Learn about vigilant mode .
Added a built-in Machine0 SSH-lease provider with live size and GPU pricing, persistent VM lifecycle, explicit suspend/resume, native versioned images
tiny and small machine classes for lower-cost smoke checks and small repositories.cmake --version preflight probe for POSIX, WSL2, and native Windows targets. Thanks @coygeek.Added credential-free crabbox providers describe discovery for canonical provider-scoped run flags and compiled defaults. Thanks @coygeek .
crabbox providers describe discovery for canonical provider-scoped run flags and compiled defaults. Thanks @coygeek.go install as a CLI-only installation channel, with clean module dependency semantics, source-derived release and revision versions, and hermetic release verification. Thanks @coygeek.raw_socket preflight probe that distinguishes direct, non-interactive-sudo, unavailable, and missing-interpreter states without sending packets or elevating workloads. Thanks @coygeek.checkpoint prune --unused-for cleanup for inactive local records and provider artifacts.crabbox heartbeat so external SSH drivers can refresh owned lease idle deadlines and optionally update the idle timeout.crabbox claims list output for deterministic, secret-safe inspection of unverified local lease claims across providers. Thanks @coygeek.--lease-output run-session handles with pre-sync emission and exact cleanup on output failure. Thanks @coygeek.dev identity instead of trusting Go 1.26 pseudo-versions synthesized from VCS metadata in another checkout.run --stop-after always teardown from racing workspace-owner renewal and replacing successful, evidence-backed runs with exit 7. Thanks @coygeek.crabbox claims list inventory reads to 1 MiB per local claim while preserving valid partial output for oversized files. Thanks @coygeek.crabbox heartbeat identifiers before configuration or provider resolution, preventing malformed commands from reaching lease mutation. Thanks @coygeek.cmd.exe limits, preserve finite stdin and nonzero exits, and clean up promptly.Nothing published for this version
Added opt-in python and python3 preflight probes that check the literal executable on POSIX, WSL2, and native Windows targets.
python and python3 preflight probes that check the literal executable on POSIX, WSL2, and native Windows targets.run --emit-proof headings context-neutral instead of claiming every run occurred after a patch or fix.Nothing published for this version
Added a checksummed, validated archive fallback for SSH-backed cp from POSIX operator hosts to native Linux or macOS leases (not WSL2) when local rsyn
cp from POSIX operator hosts to native Linux or macOS leases (not WSL2) when local rsync is missing or older than 3.4.3, including stock macOS OpenRsync. Thanks @coygeek.--no-sync. Thanks @atimmer.Nothing published for this version
Restricted sensitive generated local files, including managed attestation keys and signed-URL artifact outputs, to the current OS user on POSIX and Wi
/bin/sh launcher, fixing static macOS sync under zsh, Bash, and Fish. Thanks @osouthgate and @hosmelq.status and inspect lease identifiers through the provider recorded in local claims before initializing the configured provider, while preserving explicit-provider precedence and missing-claim fallback. Thanks @coygeek.cache stats --json emit an empty array for empty inventories while live smoke accepts legacy null and object reports but rejects other scalar shapes before workloads. Thanks @excelsier.Nothing published for this version
Kept Git-tracked regular files under ambiguous built-in artifact directories in sync manifests while preserving authoritative project excludes, untrac
run --script uploads a content-hashed standalone copy whose $0 points under .crabbox/scripts/, and documented synced-path execution for scripts that need adjacent repository assets. Thanks @coygeek.crabbox doctor report compiled-default provider provenance and skip that unchosen provider's credential readiness without weakening explicitly configured provider checks. Thanks @coygeek.Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →