NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1352 by repository stars
Last release today
07 Oct 2026
Ships fairly regularly
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
5 months old
205 releases · first in 2026
One column per month.
Nothing published for this version
Nothing published for this version
Serialized each reused SSH lease's complete workspace lifecycle across clients and watch iterations, from hydration-state and fingerprint inspection t
HEAD, the index, the requested tree, and sync fingerprints coherent without advancing symbolic branches. Thanks @vincentkoc.dev instead of the stale 0.15.0 release identity while preserving injected release versions and tagged Go module build information. Thanks @coygeek.PATH entries across managed SSH logins, including when users add or switch login-profile files after bootstrap. Thanks @coygeek.run --id and watch --id reuse through the provider recorded in the local lease claim before validating the configured provider. Thanks @coygeek.Nothing published for this version
Updated the checksum-pinned Ubuntu 26.04 Apple VM image to the current immutable Canonical release. Thanks @coygeek .
Nothing published for this version
Made caller-supplied warmup --lease-id creation idempotent across direct AWS and coordinator restarts, with exact-PUT coordinator recovery, exactly-on
warmup --lease-id creation idempotent across direct AWS and coordinator restarts, with exact-PUT coordinator recovery, exactly-once post-lock acquisition acknowledgment, at-most-once and attempt-attested direct AWS launch reconciliation, explicit SSH-CIDR intent binding, downgrade-safe aws-fixed-v1 claims, stable conflicts on request drift, and compact terminal tombstones that prevent operation-ID reuse after release or missing-resource cleanup.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Added provider: cloud-run-sandbox (gcrun-sandbox, google-cloud-run-sandbox, cloudrun-sandbox) for Google Cloud Run sandboxes in public preview: statef
provider: cloud-run-sandbox (gcrun-sandbox, google-cloud-run-sandbox, cloudrun-sandbox) for Google Cloud Run sandboxes in public preview: stateful lifecycle through the in-container sandbox CLI or a durable-routing gateway, archive sync, local claim scoping, doctor checks, and live smoke hooks. Thanks @zozo123.cp over resolved SSH leases and a readiness-gated, loopback-only tunnel command with owned process-tree teardown. Thanks @onmax.skills/crabbox convention while retaining its repo-discoverable .agents
projection, plus digest-verified domain discovery under
/.well-known/agent-skills/ and a draft-compatible cross-vendor AI Catalog.cp over resolved SSH prefer rsync secluded arguments whenever the remote rsync supports them, so remote paths travel over the rsync protocol instead of the remote shell command line. This sidesteps an upstream rsync 3.4.4 safe_arg() bug that appends one uninitialized heap byte after a backslash-escaped wildcard (e.g. \[), which intermittently corrupted remote copy paths; remotes without secluded-args support (such as macOS openrsync) keep the previous shell-transported behavior. Thanks @zozo123.crabbox init Agent Skill include standards-compliant
SKILL.md metadata, enforced conformant skill destinations, and allowed
--skill to target multiple agent discovery paths with an all-target
existence preflight..crabbox.yml suffix.Added external-provider desktop access for remote macOS, Windows, and WSL2 machines while keeping desktop credentials local. Thanks @MuduiClaw.
open --editor=<name> lease handoff for external editors, starting with Zed Remote Projects and preserving lease activity while the editor is connected. Thanks @zozo123.Restored native Homebrew verification by using the supported GitHub Actions artifact archive media type.
Nothing published for this version
Made provider IP and loopback VNC waits return promptly when their context is cancelled. Thanks @SebTardif.
Publication blocked because the protected signed tag annotation did not satisfy release policy.
Nothing published for this version
Exposed authoritative AWS instance-profile attachment state in inspect --json provider metadata for admission-policy enforcement across direct and bro
inspect --json provider metadata for admission-policy enforcement across direct and brokered leases.Nothing published for this version
Nothing published for this version
Added a dedicated ECS Fargate deployment for small private AWS workspaces with task-role credentials, exact account/Region and instance allowlist pref
Nothing published for this version
Added Orgo Linux workspaces with API-key authentication, image and region selection, exact workspace-bound claims, WebVNC support, guarded cleanup, cr
Added Sealos DevBox Linux SSH leases through the Kubernetes CRD with exact provider/resource-bound claims, conflict-safe explicit --reclaim adoption,
--reclaim adoption, claim-locked release and cleanup, controller-owned Secret SSH routing, and guarded zero-residue lifecycle proof. Thanks @coygeek.crabbox run --attest and integrity verification through crabbox verify, with collision-safe signing-key handling and explicit self-signed trust reporting. Thanks @yetval.sync-plan --json with candidate and dirty-delta sizes, configured guardrail status, deleted-path counts, and ranked file and directory hotspots for automation. Thanks @zozo123.use or manage shares from receiving direct sandbox credentials. Thanks @coygeek.--open calls reuse and focus the existing lease viewer tab when the browser supports cross-tab handoff.--reclaim. Thanks @coygeek..crabboxignore negations, including case aliases, from re-including Crabbox-owned env profiles, uploaded scripts, logs, captures, and run artifacts in sync manifests. Thanks @zozo123.! re-includes in .crabboxignore and sync.exclude, with \! for literal leading-bang paths. Thanks @chsong1.lsof metadata scans slow.dd option, and preserved complete Phala gateway hostnames so later status and SSH reconnects keep working.--sync-only and --force-sync-large work while preserving brokered Crabbox rsync. Thanks @zozo123.external.config values on process arguments without an exact, trusted non-secret argv contract. Thanks @coygeek.POST with a read-only GET confirmation page, preventing cross-site top-level navigation from clearing portal cookies or revoking isolated Code viewer sessions. Thanks @coygeek.--reclaim adoption for claimless resources and recovery-safe Vultr instance/key rollback ordering. Thanks @coygeek and @vincentkoc.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
…environment variables keep working as deprecated aliases, existing leases and claims stay manageable, and the state directory migrates automatically.
Renamed the apple-vz provider to apple-vm; the old provider name/aliases, appleVZ: config keys, --apple-vz-* flags, and CRABBOX_APPLE_VZ_* environment variables keep working as deprecated aliases, existing leases and claims stay manageable, and the state directory migrates automatically.
Replaced the Code-Hex/vz cgo dependency with crabbox-apple-vm-vmd, a dependency-free Swift Virtualization.framework daemon embedded in the now pure-Go crabbox-apple-vm-helper; the helper installs and entitlement-signs the daemon itself, so Crabbox no longer copies or codesigns helper binaries.
Updated Go SSH and OS support libraries, including upstream authentication-attempt, malformed-session, key-size, KDF, and known-host validation hardening.
Updated the Node/PostgreSQL coordinator to pg 8.22 and pg-boss 12.25, including current protocol parsing, startup retry, queue-cache, migration-deadlock, and scheduling fixes.
doctor diagnostics, covering configured secrets, authorization headers, signed URLs, secret-bearing JSON fields, and private keys, and applied it to Sprites API errors. Thanks @coygeek.CRABBOX_CONFIG files inside the active repository in the repository trust domain, including symlink aliases, so they cannot redirect inherited provider credentials. Thanks @coygeek.login, whoami, and doctor text and JSON output. Thanks @coygeek.config show --json while preserving non-secret routing metadata. Thanks @coygeek.--reclaim adoption for unclaimed or legacy pods. Thanks @coygeek.Nothing published for this version
Documented the deterministic perf evidence contract for future reproducible metric budgets, separating fuel/instruction-style gates from existing wall
crabbox shard to fork a checkpoint into parallel leases, run templated commands through the normal sync/history pipeline, stream per-shard output, merge JUnit results, and release every fork on success, failure, or interruption. Thanks @yetval.crabbox watch to reuse one warm SSH lease, coalesce qualifying local changes into sequential runs through the normal sync/history pipeline, and release newly acquired leases on bounded idle or exit. Thanks @yetval.crabbox checkpoint fork -- <command...> to run the normal crabbox run flow across fork fan-out leases with {{index}}, {{total}}, {{lease}}, and {{slug}} template variables.CRABBOX_WEBVNC_AGENT_BASE_URL override for deployments that route portal APIs and outbound WebVNC agent sockets separately.config show output while preserving useful failure detail. Thanks @coygeek.stop --reclaim deployment claim before stopping an out-of-band Railway service, binding adoption to the configured endpoint, project, environment, service, and deployment. Thanks @coygeek.crabbox=true tags as ownership; destructive operations now require canonical Azure ownership tags and an exact matching lease ID, and successful deletion removes local lease keys. Thanks @coygeek.--reclaim adoption before stop. Thanks @coygeek.Added configurable Azure snapshot and restored OS-disk storage SKUs, concurrent snapshot-fork prerequisites, and verified parallel resource cleanup. T
Added configurable Azure snapshot and restored OS-disk storage SKUs, concurrent snapshot-fork prerequisites, and verified parallel resource cleanup. Thanks @fcoury-oai.
Added direct Azure Windows managed OS-disk checkpoints and snapshot-backed forks with source restart, fresh SSH/Windows/VNC credentials, and loopback-only desktop access. Thanks @fcoury-oai.
Added a foreground, loopback-only crabbox vnc --native-handoff contract for native viewers, including one-time workspace grants that relay VNC through the coordinator without exposing its SSH key; credentials and grants use private pipes and tunnel lifetime remains owned by the client process.
Enabled desktop-capable runtime-adapter workspaces instead of discarding Crabfleet's requested desktop capability, and report native VNC separately from browser VNC.
Added direct FastAPI Cloud application and deployment inspection through status, list, and doctor, including configured default application support. Thanks @zozo123.
Added crabbox checkpoint fork --count for provider-neutral fan-out from archive checkpoints, native checkpoints, and direct Parallels snapshots without adding runtime-specific fork flags.
Added provider: vultr for direct Linux SSH leases with per-lease keys, account-bound cleanup, optional existing firewall/VPC attachment, and guarded live smoke coverage. Thanks @coygeek.
Added the Crownest delegated-run provider for hosted Linux Workspace Runs with staged archive sync, streamed output, reusable sandbox claims, and guarded lifecycle cleanup. Thanks @tristanmanchester.
Added normalized provider runtime, reachability, and lifecycle capabilities plus matching --runtime, --reachability, and --lifecycle filters to crabbox providers and crabbox providers recommend.
Added crabbox providers recommend profiles for fan-out testing, offline validation, failure diagnostics, warm starts, resource observability, code interpretation, disposable execution, web-app smoke, and interactive debugging.
Added a provider live-smoke contract for adapters that need credentials, quota, local runtimes, or private control planes, and kept credentialless local runtime smoke paths visible in crabbox providers recommend live-smoke.
Expanded the guarded scripts/live-smoke.sh matrix to Apple Container, Local Container, Docker Sandbox, SmolVM, Superserve, Vercel Sandbox, Linode, DigitalOcean, Nebius, OVHcloud, NVIDIA Brev, Phala, Anthropic Sandbox Runtime, OpenSandbox, Proxmox, XCP-ng, Multipass, and Tart.
Added live-smoke documentation and dispatch regression coverage for Agent Sandbox, Scaleway, KubeVirt, Daytona, Namespace Devbox, Namespace Compute, Semaphore, Sprites, and W&B.
Added live-smoke workflow, configuration, and credential preflight coverage for Blacksmith Testbox, Incus, External, E2B, Modal, Tenki, and Morph.
Documented local runtime live-smoke coverage for Apple Container, Local Container, Multipass, Tart, and Apple VZ.
Added reusable --lease-output run-session metadata for Cloudflare Sandbox, Vercel Sandbox, CodeSandbox, OpenSandbox, Upstash Box, Azure Dynamic Sessions, Freestyle, Tensorlake, Superserve, SmolVM, OpenComputer, Agent Sandbox, and Apple Machine.
--reclaim adoption and read-only canonical-name recovery. Thanks @coygeek.image delete requests fail closed unless stored Crabbox-created metadata proves ownership of the AWS, Azure, or GCP image or snapshot./work/crabbox while preserving explicit work roots, restoring access for the unprivileged guest user. Thanks @hxy91819.npm or Corepack is missing, preventing source installers from failing on otherwise valid images.--ssh-port lease-creation override so provider warmups can select the target SSH port without environment-only configuration.Nothing published for this version
Nothing published for this version
…as trusted project automation, and separated vulnerability reporting from compatibility-preserving hardening.
provider: nebius for direct Nebius AI Cloud Linux SSH leases through the native CLI, with profile-owned authentication, managed networking and disks, and claim-backed lifecycle hardening. Thanks @coygeek.--keep --lease-output. Thanks @kiranmagic7.--keep --lease-output. Thanks @kiranmagic7.--keep --lease-output.manage recipients while keeping shared leases visible to use recipients. Thanks @coygeek.config show output. Thanks @coygeek.CRABBOX_ENV_ALLOW authoritative over selected profile allowlists while preserving explicit --allow-env additions. Thanks @coygeek.crabbox list query the user's active orchestrator leases directly, reserving admin-wide machine inventory for --all and avoiding stale admin-token warnings during ordinary listing.Nothing published for this version
Nothing published for this version
Nothing published for this version
Documented the end-to-end runtime adapter topology, trust boundaries, request paths, startup order, and failure signals.
crabbox connect <lease-id-or-slug> to open an interactive SSH session to key-, certificate-, and proxy-authenticated provider targets while keeping crabbox ssh as the print-only command surface for token-as-username providers.crabbox adapter ingress as a provider-neutral authenticated HTTP and WebSocket bridge for loopback fleet services.--keep --lease-output. Thanks @zozo123.use share viewers. Thanks @coygeek.apple-container provider fallback image with the portable OS default while preserving explicit image choices. Thanks @coygeek.apple-container inventory parsing for Apple container 1.0 object-form status and nested network addresses. Thanks @coygeek.Nothing published for this version
Nothing published for this version
Added configurable organization-wide workspace prewarming with cross-owner adoption, immediate replenishment while busy, and automatic idle drain.
crabbox webvnc local on macOS and Linux for token-gated browser access to an existing loopback VNC tunnel, with the VNC password accepted only through stdin and kept out of process arguments, environment variables, URLs, and viewer files.crabbox adapter connect, an outbound ticket-authenticated relay for the narrow crabfleet/v1 runtime-adapter API, with a current-user-owned peer-verified Unix-socket transport, per-request local-token reload, bounded bodies, configurable desktop request timeouts, and reconnecting coordinator login refresh.crabbox adapter serve, a generic authenticated Linux/macOS-hosted workspace lifecycle API with a no-follow descriptor-verified lock in a private current-user-owned state directory, read-only state validation, crash-owned lifecycle children including bounded provider discovery, fixed TTL/idle and machine-shape override policy, explicit idempotent fixed-ID provider contracts, immutable full-identity status adoption and full-identity pre-release validation even before claim persistence, per-attempt provider route/config scopes, exact fixed external identities with crash-reclaimable fully fsynced slug reservations, restart-safe gated provider-side-effect durability with immediate memory-retried credential-bridge revocation on failed terminal writes, adapter-only side-effect-free WebVNC restarts with ordinary daemon heartbeats preserved, scope/state/resource-bound daemon reuse, per-workspace daemon OS locking, verified WebVNC supervisor/process-tree revocation, exact remote websockify socket/process ownership plus authenticated noVNC WebSocket readiness, full-identity refreshed-absence cleanup, bounded process-tree orchestration, no-follow token loading, exact-owned non-forking loopback SSH tunnels on Linux/macOS/Windows, and a public open-source Linux desktop bootstrap with noVNC/websockify, private user-owned VNC credentials, and a narrowly privileged desktop reset helper.provider: ovh for direct OVHcloud Public Cloud Linux SSH leases with signed API authentication, local claim-backed ownership, guarded recovery, and live lifecycle coverage. Thanks @coygeek.provider: codesandbox for delegated CodeSandbox Linux environments with archive sync, retained lifecycle, pause/resume, preview URLs, exact SDK pinning, truthful running-state checks, command exit propagation, and live lifecycle coverage; archive-sync orchestration is now shared across CodeSandbox, OpenComputer, OpenSandbox, Superserve, and Vercel Sandbox. Thanks @coygeek.provider: cloudflare-dynamic-workers for authenticated Worker-runtime module execution through Cloudflare Dynamic Workers, including blocked-by-default egress, stable caching, durable run metadata, lifecycle commands, and isolated live smoke coverage. Thanks @coygeek.provider: agent-sandbox for delegated Linux runs through Agent Sandbox v0.5.0rc1 v1beta1 warm pools, using the operator's kubectl for dependency-light discovery, lifecycle, archive sync, exec, guarded ownership cleanup, and live smoke coverage. Thanks @coygeek.provider: vercel-sandbox for delegated Linux microVM runs through the official Vercel Sandbox SDK, including archive sync, streamed output, retained-session resume, ownership-guarded lifecycle operations, and guarded live smoke coverage. Thanks @coygeek.--require-artifact and --download support, with provider capability gating and secret-safe archive upload errors. Thanks @zozo123.webvnc local --security-type vnc mode that forces standard VNC password authentication when a server advertises account authentication first.ssh2 dependency.json-lease output, complete declarative and protocol-command inventory, and an exact cloudId argument in every declarative release command, fsynced external routing temporaries before rename plus the installed directory and full ancestor chain afterward, made confirmed-absence claim/routing/reservation deletions directory-durable before terminal acknowledgment, boot-bound Linux slug-reservation owners to the kernel boot ID plus PID/start ticks, required full WebVNC provider identity checks, ignored unrelated partial inventory while failing closed on partial target matches, failed closed on oversized inventory without repeating successful release, gated startup child recovery on a directory-synced state snapshot, suppressed ordinary registered auto-WebVNC daemons during controller child warmup, honored controller policy flag precedence before validating environment duration fallbacks, namespaced direct-SSH WebVNC identities by a domain-separated public controller/provider owner ID while keeping raw owner tokens out of daemon argv, status, and logs, allocated their remote loopback ports under a host-wide lock with occupied-port and bind-collision retries plus exact chosen-port persistence, bound Linux controller and WebVNC process identities to the current boot plus PID/start/nonce, required exact local listener ownership before direct-SSH credential retrieval, authentication, or viewer URL emission, restricted remote reset termination to the complete persisted process identity, budgeted SSH tunnel readiness across the configured connect timeout plus listener verification, restarted WebVNC after foreground SSH tunnel death, installed noVNC, Websockify, and util-linux in generated Linux desktop bootstraps, honored absolute XDG_CONFIG_HOME overrides for external routing state on every platform while rejecting invalid values, used native Windows process APIs for daemon identity checks, and fixed the desktop reset helper to trusted absolute commands.Nothing published for this version
Added an idempotent workspace adapter over coordinator leases, with durable owner-scoped lifecycle mapping and truthful capability negotiation for ext
provider: nvidia-brev for direct Linux GPU workspaces through the Brev CLI and generated SSH config, including normal Crabbox sync/run access, guarded ownership cleanup, and live nvidia-smi smoke coverage. Thanks @coygeek.provider: superserve for delegated Linux sandbox runs through the Superserve control and data planes, including archive sync, retained leases, ownership-guarded lifecycle operations, and credentialed live smoke coverage. Thanks @coygeek.provider: namespace-instance (namespace-compute) for short-lived Namespace Compute Linux leases through nsc, including per-lease SSH keys, proxy-backed sync/run, duration safeguards, ownership-filtered cleanup, and guarded live smoke coverage. Thanks @coygeek.provider: linode for direct Linux SSH leases with per-lease keys, account-bound cleanup, preserved operator tags, interface-aware existing firewalls, and guarded live smoke coverage. Thanks @coygeek.provider: windows-sandbox for disposable native Windows runs through Microsoft Windows Sandbox, including mapped workspace sync, streamed output, timeout and cancellation cleanup, and keep-on-failure inspection. Thanks @zozo123.provider: smolvm for delegated Linux microVM runs through the hosted smolfleet API, including archive sync, retained leases, status, cleanup, and repository-scoped ownership checks. Thanks @zozo123.tagOwners guidance while preserving the raw API error.tailscale up process arguments.Nothing published for this version
Nothing published for this version
Added repeatable --local-container-volume host:container[:ro] bind mounts for explicit local-container runs. Thanks @anagnorisis2peripeteia.
--local-container-volume host:container[:ro] bind mounts for explicit local-container runs. Thanks @anagnorisis2peripeteia.crabbox pause and crabbox resume lifecycle commands, with Islo sandbox pause/resume support that preserves local lease claims. Thanks @zozo123.provider: opensandbox for delegated Linux sandbox runs through the OpenSandbox API, including archive sync, retained lease reuse, off-argv environment forwarding, status, and cleanup. Thanks @coygeek.provider: anthropic-sandbox-runtime (srt) for local one-shot command execution through Anthropic Sandbox Runtime, including filesystem/network policy handoff, doctor checks, config overrides, and live enforcement coverage. Thanks @coygeek.provider: hostinger for direct Linux VPS leases with read-only catalog and payment-method discovery, explicit purchase opt-in, setup-time SSH keys, ambiguous-purchase recovery, stopped-VPS reuse, and stop-only billing-aware release. Thanks @coygeek.provider: apple-vz for full ARM64 Ubuntu VMs through Apple's Virtualization.framework, including verified cloud images, secret-safe signed URL handling, loopback VSOCK SSH, retained leases, native helper packaging, failure rollback, and live lifecycle coverage. Thanks @coygeek.provider: digitalocean for direct Linux SSH leases backed by DigitalOcean Droplets, including flat-tag ownership, per-lease SSH keys, docs, and guarded live smoke coverage. Thanks @coygeek.provider: hyperv for local Windows VM SSH leases through Microsoft Hyper-V, including differencing-disk provisioning, OpenSSH and MinGit bootstrap, password-less dev-image initialization, retained lease reuse, and cleanup. Thanks @anagnorisis2peripeteia.--tailscale. Thanks @zozo123.provider: xcpng for SSH leases on XCP-ng pools through the XenAPI control plane, including template cloning, fresh ISO installs, retained lease reuse, cleanup, diagnostics, and guarded live E2E coverage. Thanks @coygeek.stop and pond release to preserve claims, SSH credentials, lifecycle metadata, and restart routing when providers intentionally retain reusable stopped resources.local-container stop cleanup when a Docker container was removed externally, including stale claim and stored-key removal. Thanks @hxy91819.Added provider: opencomputer for delegated Linux sandbox runs through the OpenComputer REST API, including archive sync, retained leases, optional bur
provider: opencomputer for delegated Linux sandbox runs through the OpenComputer REST API, including archive sync, retained leases, optional burst capacity, status, and cleanup. Thanks @zozo123.provider: morph for Morph Cloud Linux SSH leases, including snapshot boot, Morph API key/config plumbing, per-instance SSH key retrieval, pause-on-release reuse, and provider docs. Thanks @coygeek.CRABBOX_AZURE_WINDOWS_ARM64_IMAGE broker configuration for ARM64 validation.apple-machine provider.Nothing published for this version
Added ordered declarative external lifecycle steps with optional acquire rollback, allowing multi-command private provider setup without shell wrapper
Added declarative external.lifecycle command configuration, provider resource-name mapping, and coordinator-free WebVNC over SSH for deterministic pri
external.lifecycle command configuration, provider resource-name mapping, and coordinator-free WebVNC over SSH for deterministic private devbox CLIs.provider: local-container, including runtime selection, provider flags on SSH commands, and Podman-safe local lease claim scopes. Thanks @sallyom.sync.include / sync.includes whitelists for root-relative sync plans, SSH sync, native Windows sync, local Actions hydration, and archive-sync providers. Thanks @anagnorisis2peripeteia.kubevirt SSH leases and a versioned external executable provider so private or proprietary VM/devbox control planes can integrate through configuration without provider-specific Crabbox forks.status --wait does not resume the sandbox.CRABBOX_USER_TOKEN_TTL_SECONDS.CRABBOX_GITHUB_ADMIN_OWNERS and CRABBOX_GITHUB_ADMIN_LOGINS, and removed committed capacity-admin identities from the reusable Worker config.--require-artifact and --artifact-glob before one-shot lease cleanup.--wait-timeout while allowing Tenki readiness probes without resuming paused sessions. Thanks @aki-luxor.use viewers from mutating lease heartbeat or Tailscale metadata, and hardened archive sync for option-like filenames while preserving sync cancellation. Thanks @zozo123.Nothing published for this version
Added provider: multipass for local Ubuntu VM SSH leases through Canonical Multipass, including cloud-init bootstrap, Crabbox sync/run lifecycle, clea
provider: multipass for local Ubuntu VM SSH leases through Canonical Multipass, including cloud-init bootstrap, Crabbox sync/run lifecycle, cleanup, and cache-volume support. Thanks @jwmoss.Nothing published for this version
Added provider: apple-container for local Apple silicon macOS Linux leases, including SSH sync/run lifecycle and provider-backed cache volumes. Thanks
provider: apple-container for local Apple silicon macOS Linux leases, including SSH sync/run lifecycle and provider-backed cache volumes. Thanks @zozo123.crabbox prewarm to lease and hydrate reusable test-ready boxes from configured GitHub Actions, with provider-owned handling for delegated runners such as Blacksmith Testbox.prewarm --pool, run --pool, pool ready/register/borrow/return/ensure, and the broker ready-pool API.crabbox doctor --all --prepare-check to report provider matrix readiness, resolved test machine types, and hydration workflow/job setup without creating leases.crabbox webvnc daemon list to show alive and stale local WebVNC helper daemons after agent runs.x11vnc, 60fps WayVNC, and low-compression noVNC defaults.--apple-container-extra-run-args --dns overrides.Nothing published for this version
Added provider-backed cache volumes for rebuildable dependency caches, including cache.volumes, CRABBOX_CACHE_VOLUMES, repeatable --cache-volume [name
cache.volumes, CRABBOX_CACHE_VOLUMES, repeatable --cache-volume [name=]key:path, crabbox cache volumes, Blacksmith Testbox sticky-disk forwarding, Local Container Docker volume mounts, and claim-backed required-volume checks for reused leases.?event=push so it reflects tag-push release runs instead of cancelled workflow_dispatch runs. Fixes https://github.com/openclaw/crabbox/issues/189. Thanks @zozo123.Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →