JD Davis
34a5517562
chore: release 0.36.5 ( #3214 )
...
🤖 I have created a release *beep* *boop*
---
##
[0.36.5](https://github.com/headroomlabs-ai/headroom/compare/v0.36.4...v0.36.5 )
(2026-08-22)
### Bug Fixes
* **codex:** detect ChatGPT auth from id_token claims so wrap/init emit
requires_openai_auth
([#3212 ](https://github.com/headroomlabs-ai/headroom/issues/3212 ))
([2f81fa5 ](2f81fa5931 ))
* **doctor:** report project-scoped Claude routing instead of a false
negative
([#3213 ](https://github.com/headroomlabs-ai/headroom/issues/3213 ))
([8f3e33a ](8f3e33a00e ))
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-22 16:22:48 -07:00
JD Davis
91186b40d8
chore: release 0.36.4 ( #3189 )
...
🤖 I have created a release *beep* *boop*
---
##
[0.36.4](https://github.com/headroomlabs-ai/headroom/compare/v0.36.3...v0.36.4 )
(2026-08-22)
### Bug Fixes
* **dashboard:** pin MIME types for the vendored static assets
([#3193 ](https://github.com/headroomlabs-ai/headroom/issues/3193 ))
([b485768 ](b4857685ff ))
* **proxy/responses:** keep the Codex additional_tools carrier on the
wire ([#3194 ](https://github.com/headroomlabs-ai/headroom/issues/3194 ))
([1617f83 ](1617f839a1 ))
* **security:** validate caller-supplied upstreams on every resolution
path ([#3195 ](https://github.com/headroomlabs-ai/headroom/issues/3195 ))
([3e3c409 ](3e3c409436 ))
* skip cross-turn dedup pointers on OpenAI chat streaming
([#3191 ](https://github.com/headroomlabs-ai/headroom/issues/3191 ))
([9c30b62 ](9c30b62962 ))
* **wrap:** make the Serena pre-index stall budget configurable
([#3183 ](https://github.com/headroomlabs-ai/headroom/issues/3183 ))
([202c189 ](202c1895e1 ))
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-21 23:29:15 -07:00
JD Davis
87e71dd100
chore: release 0.36.3 ( #3188 )
...
🤖 I have created a release *beep* *boop*
---
##
[0.36.3](https://github.com/headroomlabs-ai/headroom/compare/v0.36.2...v0.36.3 )
(2026-08-21)
### Bug Fixes
* **proxy/responses:** lift Codex >= 0.149.0 additional_tools into
top-level tools
([#3186 ](https://github.com/headroomlabs-ai/headroom/issues/3186 ))
([25ca580 ](25ca580825 ))
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-21 14:57:44 -07:00
JD Davis
5e0ce242e9
chore: release 0.36.2 ( #3157 )
...
🤖 I have created a release *beep* *boop*
---
##
[0.36.2](https://github.com/headroomlabs-ai/headroom/compare/v0.36.1...v0.36.2 )
(2026-08-21)
### Bug Fixes
* **copilot:** bind the minted token to the integration ID we forward
([#3164 ](https://github.com/headroomlabs-ai/headroom/issues/3164 ))
([397803a ](397803a942 ))
* **kompress:** accept ccr_original on the remote compressor
([#3162 ](https://github.com/headroomlabs-ai/headroom/issues/3162 ))
([45cb1b9 ](45cb1b9c48 ))
* **proxy:** count output tokens from the stream's text, not its wire
size ([#3163 ](https://github.com/headroomlabs-ai/headroom/issues/3163 ))
([4006964 ](4006964a03 ))
### Dependencies
* bump ai from 6.0.138 to 7.0.59 in /sdk/typescript
([#2281 ](https://github.com/headroomlabs-ai/headroom/issues/2281 ))
([0891062 ](08910624fb ))
* bump ai from 6.0.149 to 7.0.59 in /docs
([#2277 ](https://github.com/headroomlabs-ai/headroom/issues/2277 ))
([f7e5d37 ](f7e5d37f52 ))
* bump md-5 from 0.10.6 to 0.11.0
([#3146 ](https://github.com/headroomlabs-ai/headroom/issues/3146 ))
([c6dd823 ](c6dd823384 ))
* bump ruff from 0.16.2 to 0.16.3 in the pip-minor-patch group
([#3143 ](https://github.com/headroomlabs-ai/headroom/issues/3143 ))
([c8db13d ](c8db13d5ad ))
* bump the cargo-minor-patch group with 8 updates
([#3145 ](https://github.com/headroomlabs-ai/headroom/issues/3145 ))
([9c14e3a ](9c14e3aa95 ))
* bump tiktoken-rs from 0.11.0 to 0.12.0
([#3147 ](https://github.com/headroomlabs-ai/headroom/issues/3147 ))
([a307c11 ](a307c11109 ))
* bump tokenizers from 0.22.2 to 0.23.1
([#3149 ](https://github.com/headroomlabs-ai/headroom/issues/3149 ))
([6e2e10f ](6e2e10f67a ))
* bump typescript from 5.9.3 to 7.0.2 in /plugins/openclaw
([#2279 ](https://github.com/headroomlabs-ai/headroom/issues/2279 ))
([85774fc ](85774fcb70 ))
* bump typescript from 5.9.3 to 7.0.2 in /plugins/opencode
([#2280 ](https://github.com/headroomlabs-ai/headroom/issues/2280 ))
([a382137 ](a382137844 ))
* update mcp requirement from <2.0.0,>=1.28.1 to
>=1.28.1,<3.0.0
([#3144 ](https://github.com/headroomlabs-ai/headroom/issues/3144 ))
([6928d19 ](6928d1932c ))
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-20 23:09:18 -07:00
JD Davis
37faf2f247
chore: release 0.36.1 ( #3152 )
...
## Description
Release 0.36.1, generated by Release Please, containing the security
fixes from #2207 (WEB-01–07). This updates the changelog and keeps
Python, TypeScript SDK, plugin package, marketplace, server, and release
metadata versions aligned at 0.36.1.
## Type of Change
- [x] Release / version metadata
## Changes Made
- Updated the release manifest and generated changelog for 0.36.1.
- Synchronized `pyproject.toml`, TypeScript SDK, OpenClaw, OpenCode,
agent-hook plugin, marketplace, server, and release metadata versions.
- Included the 0.36.1 changelog entry for the security assessment fixes
merged in #2207 .
## Testing
- [x] CI and release validation pass
### Test Output
All current required checks are complete and passing, including version
sync, package builds, wheel smoke imports, security scans, Python test
shards, native wrapper checks, and devcontainer validation.
## Real Behavior Proof
- Environment: GitHub Actions release and CI workflows for commit
`52c0a0c61dce0af81af3ff73a34efe8b451501cb`.
- Observed result: all generated version-bearing files report 0.36.1;
build and smoke-import jobs produced and validated the release
artifacts.
- Not exercised: publishing jobs are intentionally skipped for a pull
request and run only after the release receives final human approval and
is merged.
## Runtime Rollout Safety
- Rollout-managed features: none; this PR packages already-merged
behavior.
- Stable/default behavior changed: no additional runtime behavior beyond
the included, already-reviewed security fixes.
- Kill switch / disable path: not applicable to generated release
metadata.
- Qualification impact: release artifact construction and smoke-import
validation are green.
- Rollback path: do not merge the release PR, or revert the release
commit before publishing.
## Review Readiness
- [x] I have performed a self-review
- [x] This PR is ready for human review
## Release Notes
### Bug Fixes
- **security:** address u9up assessment findings (WEB-01–07) (#2207 )
This PR was generated with Release Please and then its description was
expanded to document review and qualification evidence. It still
requires final human review; no publishing or merge has been performed.
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-20 17:20:18 -07:00
JD Davis
b88b9078d8
chore: release 0.36.0 ( #3067 )
...
🤖 I have created a release *beep* *boop*
---
##
[0.36.0](https://github.com/headroomlabs-ai/headroom/compare/v0.35.0...v0.36.0 )
(2026-08-20)
### Features
* add deterministic runtime rollout controls
([#1490 ](https://github.com/headroomlabs-ai/headroom/issues/1490 ))
([3077ac8 ](3077ac81e8 ))
* **proxy:** let extensions report cost savings and their own latency
([#3051 ](https://github.com/headroomlabs-ai/headroom/issues/3051 ))
([f9807fd ](f9807fd69e ))
* **proxy:** unify savings attribution across stats, perf, metrics, and
dashboard
([1b0b0b8 ](1b0b0b89a4 )),
closes [#2976 ](https://github.com/headroomlabs-ai/headroom/issues/2976 )
* **wrap/claude:** make the --1m fallback model configurable via
HEADROOM_1M_MODEL
([#2983 ](https://github.com/headroomlabs-ai/headroom/issues/2983 ))
([2a84725 ](2a8472525d ))
### Bug Fixes
* **anthropic:** honor the [1m] 1M-context tier, and price it correctly
([#3073 ](https://github.com/headroomlabs-ai/headroom/issues/3073 ))
([6d2254d ](6d2254dfb5 ))
* **ccr:** make --no-ccr disable server-side response handling too
([#3101 ](https://github.com/headroomlabs-ai/headroom/issues/3101 ))
([131b119 ](131b119c05 )),
closes [#3082 ](https://github.com/headroomlabs-ai/headroom/issues/3082 )
* **ccr:** make StreamingCCRHandler work on OpenAI streams
([#3069 ](https://github.com/headroomlabs-ai/headroom/issues/3069 ))
([7ef736f ](7ef736fb1a ))
* **ccr:** only buffer a stream when a marker is actually redeemable
([#3092 ](https://github.com/headroomlabs-ai/headroom/issues/3092 ))
([c502087 ](c502087db7 ))
* **ccr:** re-inject headroom_retrieve when history references it on the
sessionless path
([942af56 ](942af56f11 ))
* **ccr:** relay a successful upstream turn when post-processing fails
([#3094 ](https://github.com/headroomlabs-ai/headroom/issues/3094 ))
([0ec73fa ](0ec73faa28 ))
* **ccr:** send Accept: application/json on a buffered stream:false turn
([#3102 ](https://github.com/headroomlabs-ai/headroom/issues/3102 ))
([139c7cb ](139c7cbdde )),
closes [#3078 ](https://github.com/headroomlabs-ai/headroom/issues/3078 )
* **ccr:** verify a scanned marker's hash before advertising it
([#2908 ](https://github.com/headroomlabs-ai/headroom/issues/2908 ))
([41dab2d ](41dab2d099 ))
* **ci:** prevent native detector from hanging test shards
([#2996 ](https://github.com/headroomlabs-ai/headroom/issues/2996 ))
([a708c05 ](a708c0571e ))
* **ci:** scope the release credential and stop persisting it to disk
([#3062 ](https://github.com/headroomlabs-ai/headroom/issues/3062 ))
([ac8646a ](ac8646aa3c ))
* **ci:** unjam release and Docker publishing
([#2958 ](https://github.com/headroomlabs-ai/headroom/issues/2958 ))
([e269afb ](e269afb935 ))
* **claude:** reject conflicting auth before proxy startup
([#2993 ](https://github.com/headroomlabs-ai/headroom/issues/2993 ))
([2d88e31 ](2d88e31a40 ))
* **cli/install:** resolve the deployment profile instead of dead-ending
on default
([#2832 ](https://github.com/headroomlabs-ai/headroom/issues/2832 ))
([8252619 ](82526191a1 ))
* **cli:** stop the macOS malloc re-exec replacing an embedder's process
([#3064 ](https://github.com/headroomlabs-ai/headroom/issues/3064 ))
([96c25f5 ](96c25f5181 ))
* **copilot:** route VS Code inline completions to Copilot, not OpenAI
([#3077 ](https://github.com/headroomlabs-ai/headroom/issues/3077 ))
([204e751 ](204e751d2f ))
* **copilot:** send VS Code inline completions to the host that serves
them ([#3112 ](https://github.com/headroomlabs-ai/headroom/issues/3112 ))
([b77d612 ](b77d612913 ))
* **deps:** bump datasets past PYSEC-2026-3716
([#3136 ](https://github.com/headroomlabs-ai/headroom/issues/3136 ))
([df6ff6b ](df6ff6bd5b ))
* **deps:** clear the two Rust advisories and make cargo audit blocking
([#3121 ](https://github.com/headroomlabs-ai/headroom/issues/3121 ))
([93c474e ](93c474e84b ))
* **deps:** raise the GitPython floor to 3.1.58 to clear 9 open
advisories
([#3120 ](https://github.com/headroomlabs-ai/headroom/issues/3120 ))
([8156d4d ](8156d4dc3a ))
* **docker:** publish compose ports on loopback only
([#3061 ](https://github.com/headroomlabs-ai/headroom/issues/3061 ))
([481e0b8 ](481e0b83d5 ))
* **docker:** ship Bedrock auth and current registry
([#2982 ](https://github.com/headroomlabs-ai/headroom/issues/2982 ))
([eafdf11 ](eafdf11a2c ))
* **doctor:** surface that Claude Desktop agent sessions bypass the
proxy ([#2987 ](https://github.com/headroomlabs-ai/headroom/issues/2987 ))
([be5b26d ](be5b26d807 ))
* **install:** consolidate Windows fallback and cleanup safety
([#2980 ](https://github.com/headroomlabs-ai/headroom/issues/2980 ))
([ddd2a25 ](ddd2a259ec ))
* **install:** honor HEADROOM_PORT in install apply and deploy
([#3085 ](https://github.com/headroomlabs-ai/headroom/issues/3085 ))
([58f28dc ](58f28dc7a6 ))
* **install:** stop the PowerShell installer leaking temp dirs into the
real user PATH
([#2985 ](https://github.com/headroomlabs-ai/headroom/issues/2985 ))
([ddd9f76 ](ddd9f76729 ))
* **learn:** include stdout in CLI failure messages, not just stderr
([#3080 ](https://github.com/headroomlabs-ai/headroom/issues/3080 ))
([c5563d3 ](c5563d3a7d ))
* **mcp:** restore SDK v1 compatibility cap
([#2978 ](https://github.com/headroomlabs-ai/headroom/issues/2978 ))
([6077e5a ](6077e5a149 ))
* **memory:** sanitize entity_refs to prevent dict-shaped entries
crashing search
([#2951 ](https://github.com/headroomlabs-ai/headroom/issues/2951 ))
([2d1e96b ](2d1e96b85c ))
* **onnx:** enforce Rust API-24 runtime compatibility
([#2979 ](https://github.com/headroomlabs-ai/headroom/issues/2979 ))
([a3fe5cb ](a3fe5cb65b ))
* **openclaw-plugin:** circuit breaker + per-request timeout for proxy
resilience
([#639 ](https://github.com/headroomlabs-ai/headroom/issues/639 ))
([6576ef6 ](6576ef639c ))
* **opencode:** send x-headroom-project header on all proxied requests
([#2868 ](https://github.com/headroomlabs-ai/headroom/issues/2868 ))
([eeb038b ](eeb038bc0c ))
* **policy:** price net-cost mutations with the 1h cache-write tier
([#2780 ](https://github.com/headroomlabs-ai/headroom/issues/2780 ))
([ef7e07e ](ef7e07e0f5 ))
* **providers:** don't crash on a non-object HEADROOM_MODEL_LIMITS /
models.json
([#3089 ](https://github.com/headroomlabs-ai/headroom/issues/3089 ))
([3ed8f76 ](3ed8f76019 ))
* **proxy/anthropic:** don't buffer a CCR stream when passthrough
discards the stream flip
([#2953 ](https://github.com/headroomlabs-ai/headroom/issues/2953 ))
([f1c34d3 ](f1c34d336c ))
* **proxy/anthropic:** don't replay recorded prefix over live history
([#3026 ](https://github.com/headroomlabs-ai/headroom/issues/3026 ))
([#3052 ](https://github.com/headroomlabs-ai/headroom/issues/3052 ))
([c16be9b ](c16be9bbbe ))
* **proxy/anthropic:** repair headroom_retrieve history references the
tools array cannot support
([#2876 ](https://github.com/headroomlabs-ai/headroom/issues/2876 ))
([7de3573 ](7de35739c6 ))
* **proxy/anthropic:** stop answering a non-streaming turn with an event
stream
([#3142 ](https://github.com/headroomlabs-ai/headroom/issues/3142 ))
([0e26fb8 ](0e26fb80de ))
* **proxy/cache:** strip cache_control from messages in the semantic
cache key
([#3086 ](https://github.com/headroomlabs-ai/headroom/issues/3086 ))
([2cae0f8 ](2cae0f8eaf ))
* **proxy/gemini:** guard CCR continuation usage against present-null
counts
([#3035 ](https://github.com/headroomlabs-ai/headroom/issues/3035 ))
([a01897c ](a01897c791 ))
* **proxy/openai:** propagate provider usage on the Responses
WS->HTTP fallback
([#2988 ](https://github.com/headroomlabs-ai/headroom/issues/2988 ))
([536c949 ](536c949a69 ))
* **proxy:** adapt 200 SSE upstream replies on buffered /v1/responses
instead of 502
([#2622 ](https://github.com/headroomlabs-ai/headroom/issues/2622 ))
([d76fce0 ](d76fce04a3 ))
* **proxy:** align signed-thinking wire accounting
([#3015 ](https://github.com/headroomlabs-ai/headroom/issues/3015 ))
([b3f4436 ](b3f443636d ))
* **proxy:** complete stateless Responses and buffered CCR lifecycle
([#2997 ](https://github.com/headroomlabs-ai/headroom/issues/2997 ))
([8a1d38b ](8a1d38bc5d ))
* **proxy:** guard feedback endpoints and add CSRF checks to loopback
writes
([#3060 ](https://github.com/headroomlabs-ai/headroom/issues/3060 ))
([a6ab359 ](a6ab359a5d ))
* **proxy:** keep prefixed core tools resident
([#3046 ](https://github.com/headroomlabs-ai/headroom/issues/3046 ))
([2f4d001 ](2f4d001c9f ))
* **proxy:** preserve Codex WebSocket model attribution
([#3029 ](https://github.com/headroomlabs-ai/headroom/issues/3029 ))
([a06a51e ](a06a51eca6 ))
* **proxy:** relocate stray system-role messages to the top-level system
param ([#765 ](https://github.com/headroomlabs-ai/headroom/issues/765 ))
([#1357 ](https://github.com/headroomlabs-ai/headroom/issues/1357 ))
([9fde127 ](9fde127534 ))
* **proxy:** restore the buffered-CCR heartbeat behind a grace window
([#3091 ](https://github.com/headroomlabs-ai/headroom/issues/3091 ))
([a29d201 ](a29d2015e5 ))
* **proxy:** scope the signed-thinking lock to blocks that actually
changed
([#3124 ](https://github.com/headroomlabs-ai/headroom/issues/3124 ))
([17522fb ](17522fb0a1 ))
* **proxy:** stop a lone surrogate turning a thinking body into a 500
([#3134 ](https://github.com/headroomlabs-ai/headroom/issues/3134 ))
([284ff31 ](284ff31947 ))
* **proxy:** stop cached responses replaying the producing turn's wire
framing
([#3024 ](https://github.com/headroomlabs-ai/headroom/issues/3024 ))
([9d37059 ](9d370592b0 ))
* **proxy:** stop operator secrets following a client-chosen upstream
([#3122 ](https://github.com/headroomlabs-ai/headroom/issues/3122 ))
([05f5ef4 ](05f5ef47cb ))
* **proxy:** tune macOS libmalloc and trim allocator pages so long-lived
RSS stays bounded
([#2879 ](https://github.com/headroomlabs-ai/headroom/issues/2879 ))
([6d87825 ](6d87825f62 ))
* **reporting:** show net vs gross savings, real skip thresholds, and
the effective profile
([#3123 ](https://github.com/headroomlabs-ai/headroom/issues/3123 ))
([250ede2 ](250ede2f7f ))
* tool_search_tool_regex deferred and falsely resolved on
direct-Anthropic path
([#2971 ](https://github.com/headroomlabs-ai/headroom/issues/2971 ))
([8ea87e7 ](8ea87e7804 ))
* **vscode:** persist compatible Claude modes and route Copilot CAPI
([#2986 ](https://github.com/headroomlabs-ai/headroom/issues/2986 ))
([1aa701a ](1aa701adaa ))
* **wrap:** set xAI upstream for grok-build proxy
([#2772 ](https://github.com/headroomlabs-ai/headroom/issues/2772 ))
([c831081 ](c8310819a4 ))
* **wrap:** stop the Serena pre-index stalling the launch path for 300s
([#2945 ](https://github.com/headroomlabs-ai/headroom/issues/2945 ))
([6147883 ](6147883d5e ))
* **wrap:** verify proxy deps before mutating Codex config
([#1628 ](https://github.com/headroomlabs-ai/headroom/issues/1628 ))
([b7f342c ](b7f342c153 ))
### Performance Improvements
* **perf:** skip rotated logs outside the requested window
([#3081 ](https://github.com/headroomlabs-ai/headroom/issues/3081 ))
([6c9f41e ](6c9f41e08c ))
### Dependencies
* bump axum from 0.7.9 to 0.8.9
([#2966 ](https://github.com/headroomlabs-ai/headroom/issues/2966 ))
([5731be7 ](5731be7e68 ))
* bump criterion from 0.5.1 to 0.8.2
([#2965 ](https://github.com/headroomlabs-ai/headroom/issues/2965 ))
([b30f339 ](b30f339d69 ))
* bump ruff from 0.15.22 to 0.16.2 in the pip-minor-patch group across 1
directory
([#2962 ](https://github.com/headroomlabs-ai/headroom/issues/2962 ))
([ff17961 ](ff17961cd7 ))
* bump sha2 from 0.10.9 to 0.11.0
([#2288 ](https://github.com/headroomlabs-ai/headroom/issues/2288 ))
([322425c ](322425c43b ))
* bump the cargo-minor-patch group across 1 directory with 4 updates
([#2964 ](https://github.com/headroomlabs-ai/headroom/issues/2964 ))
([888a9f4 ](888a9f4e14 ))
* bump tokio-tungstenite from 0.24.0 to 0.30.0
([#2967 ](https://github.com/headroomlabs-ai/headroom/issues/2967 ))
([bbe9013 ](bbe901319d ))
* update mcp requirement from <2.0.0,>=1.28.1 to
>=1.28.1,<3.0.0
([#2963 ](https://github.com/headroomlabs-ai/headroom/issues/2963 ))
([d6fb536 ](d6fb5365f6 ))
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-19 21:14:59 -07:00
Tejas Chopra
93f2d7a2da
chore: release main ( #2792 )
...
🤖 I have created a release *beep* *boop*
---
<details><summary>0.35.0</summary>
##
[0.35.0](https://github.com/headroomlabs-ai/headroom/compare/v0.34.0...v0.35.0 )
(2026-08-12)
### Features
* **beacon:** allowlist the routing summary key
([#2818 ](https://github.com/headroomlabs-ai/headroom/issues/2818 ))
([7940c05 ](7940c05ebf ))
* **beacon:** hourly R2 compaction, per-strategy savings, and a stack
that reports
([#2853 ](https://github.com/headroomlabs-ai/headroom/issues/2853 ))
([e0870ef ](e0870ef931 ))
* **cli,pricing:** add CLI extension seam and prompt-cache TTL pricing
([#2802 ](https://github.com/headroomlabs-ai/headroom/issues/2802 ))
([6ec3e34 ](6ec3e3478a ))
### Bug Fixes
* **anthropic:** strip first-party tool search on custom upstreams
([#2539 ](https://github.com/headroomlabs-ai/headroom/issues/2539 ))
([7f6950b ](7f6950be34 ))
* **backends/anyllm:** convert Anthropic tools and tool_choice to OpenAI
shape
([0d6866b ](0d6866b91a ))
* **backends/anyllm:** stream tool_use blocks and map finish_reason on
the streaming path
([e4904e2 ](e4904e23a6 ))
* **backends/litellm:** None-guard core token counts in OpenAI usage
block ([#2324 ](https://github.com/headroomlabs-ai/headroom/issues/2324 ))
([12f9f58 ](12f9f58cb3 ))
* **beacon:** report all-layers savings, not context-compression only
([#2796 ](https://github.com/headroomlabs-ai/headroom/issues/2796 ))
([e9a24f3 ](e9a24f3ec1 ))
* **beacon:** split session failures by status code
([#2815 ](https://github.com/headroomlabs-ai/headroom/issues/2815 ))
([2954e37 ](2954e37048 ))
* **cache:** bound compression cache bookkeeping
([0ae948c ](0ae948c151 ))
* **cache:** enforce Anthropic's 1h-before-5m cache_control ordering
before forwarding
([#2941 ](https://github.com/headroomlabs-ai/headroom/issues/2941 ))
([3752458 ](3752458022 ))
* **cache:** mirror client cache_control positions instead of
single-marker consolidation
([def3d76 ](def3d76e5a ))
* **cache:** stabilize Anthropic block-growing lineages
([#2917 ](https://github.com/headroomlabs-ai/headroom/issues/2917 ))
([1a04c95 ](1a04c957f5 ))
* **ccr:** avoid injecting tool on chat streaming
([d0c1f5b ](d0c1f5b8ad ))
* **ccr:** preserve exact SQLite TTL boundary
([#2669 ](https://github.com/headroomlabs-ai/headroom/issues/2669 ))
([d0a86d4 ](d0a86d409f ))
* **ccr:** report embedded hashes from compress endpoint
([#717 ](https://github.com/headroomlabs-ai/headroom/issues/717 ))
([685ebe4 ](685ebe457d ))
* **ccr:** resolve <<ccr:...>> markers inline when no
retrieve-tool path exists
([#2512 ](https://github.com/headroomlabs-ai/headroom/issues/2512 ))
([ce8ce83 ](ce8ce8313f ))
* **ccr:** tolerate null/malformed OpenAI data in response handling
([#2467 ](https://github.com/headroomlabs-ai/headroom/issues/2467 ))
([e583e08 ](e583e082d8 ))
* **ci:** publish latest from the root Docker manifest
([#2252 ](https://github.com/headroomlabs-ai/headroom/issues/2252 ))
([5568d73 ](5568d738af ))
* **claude:** stop forcing tool search on Foundry
([#2477 ](https://github.com/headroomlabs-ai/headroom/issues/2477 ))
([7981396 ](798139608c ))
* **cli/update:** let install ownership win over bare /.dockerenv so
venv installs self-update
([#2830 ](https://github.com/headroomlabs-ai/headroom/issues/2830 ))
([7092b53 ](7092b53c46 ))
* **codex:** route alpha search through the Codex backend
([#2538 ](https://github.com/headroomlabs-ai/headroom/issues/2538 ))
([a540eb2 ](a540eb2c61 ))
* **content-router:** protect custom-tag blocks before mixed-content
section split
([d7bc1e2 ](d7bc1e275f ))
* **deps:** bump h2 to 4.4.1 for CVE-2026-71554
([#2839 ](https://github.com/headroomlabs-ai/headroom/issues/2839 ))
([564e0a8 ](564e0a8d0f ))
* **deps:** enforce audited transitive dependency floors
([#2791 ](https://github.com/headroomlabs-ai/headroom/issues/2791 ))
([64e2039 ](64e203931b ))
* **doctor:** flag `ollama launch claude` proxy bypass instead of
misdirecting
([#2566 ](https://github.com/headroomlabs-ai/headroom/issues/2566 ))
([7f24d69 ](7f24d695ee ))
* emit SSE ping before message_start on Bedrock streaming path (issue
[#902 ](https://github.com/headroomlabs-ai/headroom/issues/902 ))
([#1080 ](https://github.com/headroomlabs-ai/headroom/issues/1080 ))
([4dab254 ](4dab254d52 ))
* **gemini:** resolve native CCR retrieval calls
([#2253 ](https://github.com/headroomlabs-ai/headroom/issues/2253 ))
([2483f57 ](2483f57002 ))
* **health:** label kompress as degraded/optional when not yet loaded
([#2865 ](https://github.com/headroomlabs-ai/headroom/issues/2865 ))
([8949371 ](89493714d2 ))
* **image:** decouple routing types from trained_router so importing the
compressor doesn't import torch
([#2513 ](https://github.com/headroomlabs-ai/headroom/issues/2513 ))
([#2537 ](https://github.com/headroomlabs-ai/headroom/issues/2537 ))
([d7cf981 ](d7cf981093 ))
* **install/windows:** register persistent-task from S4U hidden XML
([#2453 ](https://github.com/headroomlabs-ai/headroom/issues/2453 ))
([#2459 ](https://github.com/headroomlabs-ai/headroom/issues/2459 ))
([1edaeb8 ](1edaeb8b76 ))
* **install:** don't crash the PowerShell installer when $PROFILE is
unset ([#2469 ](https://github.com/headroomlabs-ai/headroom/issues/2469 ))
([fc5c4e2 ](fc5c4e239c ))
* **install:** trust Docker bridge for dashboard metadata
([e044139 ](e044139001 ))
* **install:** use --userns=keep-id under Podman so bind-mount writes
don't fail
([#2846 ](https://github.com/headroomlabs-ai/headroom/issues/2846 ))
([3488f8d ](3488f8d4b5 ))
* **learn/gemini:** stop double-counting session tokens
([#2230 ](https://github.com/headroomlabs-ai/headroom/issues/2230 ))
([29d8a5e ](29d8a5e563 ))
* **learn/grok:** detect a Windows absolute project path
([#2283 ](https://github.com/headroomlabs-ai/headroom/issues/2283 ))
([e240df2 ](e240df2b69 ))
* **learn:** stop classifying a successful exit code 0 as an error
([#2289 ](https://github.com/headroomlabs-ai/headroom/issues/2289 ))
([a24fe7d ](a24fe7dcbf ))
* **litellm:** add async_post_call_success_hook to HeadroomCallback
([#1322 ](https://github.com/headroomlabs-ai/headroom/issues/1322 ))
([3107994 ](3107994aed ))
* **litellm:** don't forward a caller key the target cannot accept
([#2883 ](https://github.com/headroomlabs-ai/headroom/issues/2883 ))
([2f2950a ](2f2950a626 ))
* **memory:** bound the TrafficLearner pending-pattern accumulator
(memory leak)
([#2579 ](https://github.com/headroomlabs-ai/headroom/issues/2579 ))
([1f5feff ](1f5fefffd3 ))
* **memory:** close DirectMem0 resources
([6596182 ](65961827cf ))
* **memory:** close MCP backend on shutdown
([4bd8ecd ](4bd8ecd1e3 ))
* **memory:** don't crash inline memory extraction on a non-object
<memory> block
([#2470 ](https://github.com/headroomlabs-ai/headroom/issues/2470 ))
([e00c6ff ](e00c6ff81c ))
* **memory:** keep vector metadata in sync
([#2295 ](https://github.com/headroomlabs-ai/headroom/issues/2295 ))
([c471800 ](c471800e8e ))
* **memory:** make explicit-project and user store keys
collision-resistant
([#2231 ](https://github.com/headroomlabs-ai/headroom/issues/2231 ))
([f840d5f ](f840d5f2fe ))
* **memory:** skip <system-reminder> blocks when building the
retrieval query
([#2195 ](https://github.com/headroomlabs-ai/headroom/issues/2195 ))
([#2541 ](https://github.com/headroomlabs-ai/headroom/issues/2541 ))
([4e5a67a ](4e5a67a342 ))
* **memory:** sync FTS5 and vector indexes on CLI
delete/edit/prune/purge
([fd4628d ](fd4628d821 ))
* **oauth2:** make repository lint checks pass
([c85abf7 ](c85abf7a87 ))
* **observability:** aggregate tool savings in OTEL
([#2936 ](https://github.com/headroomlabs-ai/headroom/issues/2936 ))
([941c25d ](941c25d31e ))
* **onnx:** stop ONNX thread pools from spinning idle cores
([#2495 ](https://github.com/headroomlabs-ai/headroom/issues/2495 ))
([#2540 ](https://github.com/headroomlabs-ai/headroom/issues/2540 ))
([5c561bd ](5c561bd913 ))
* **openai:** skip Responses tool-search deferral for clients that
cannot execute it
([#2696 ](https://github.com/headroomlabs-ai/headroom/issues/2696 ))
([54ea28d ](54ea28d983 ))
* **opencode:** ship the transport hook-shim so wheel installs route
Node child traffic
([702dbc5 ](702dbc5902 ))
* **providers/anthropic:** don't crash token estimation on null
tool_calls
([#2472 ](https://github.com/headroomlabs-ai/headroom/issues/2472 ))
([08466f3 ](08466f3cae ))
* **providers/openai:** bound tiktoken vocab loads with the guarded
loader
([#2554 ](https://github.com/headroomlabs-ai/headroom/issues/2554 ))
([0805e8e ](0805e8e410 ))
* **proxy/anthropic:** inject headroom_retrieve whenever a CCR marker is
present, not only for new markers
([#2848 ](https://github.com/headroomlabs-ai/headroom/issues/2848 ))
([3808f60 ](3808f60ca6 ))
* **proxy/anthropic:** None-guard usage token counts on the direct
buffered path
([#2434 ](https://github.com/headroomlabs-ai/headroom/issues/2434 ))
([2b5ee7c ](2b5ee7cde8 ))
* **proxy/anthropic:** run tool-search history repair after turn hooks
([c6f9948 ](c6f99482e1 ))
* **proxy/batch:** don't crash an OpenAI batch on a valid-JSON
non-object line
([#2316 ](https://github.com/headroomlabs-ai/headroom/issues/2316 ))
([1f2c681 ](1f2c681c0b ))
* **proxy/bedrock:** report uncached input tokens from backend usage,
not the live-zone count
([#2318 ](https://github.com/headroomlabs-ai/headroom/issues/2318 ))
([c19e412 ](c19e412b33 ))
* **proxy/gemini:** keep streaming-parity baseline so eligible_pct can't
exceed 100
([#2824 ](https://github.com/headroomlabs-ai/headroom/issues/2824 ))
([b97c7c6 ](b97c7c6e99 ))
* **proxy/metrics:** cap client-supplied model label cardinality
([#2480 ](https://github.com/headroomlabs-ai/headroom/issues/2480 ))
([e24a7e6 ](e24a7e66b9 ))
* **proxy/metrics:** escape label values in the Prometheus export
([#2463 ](https://github.com/headroomlabs-ai/headroom/issues/2463 ))
([6a53861 ](6a53861063 ))
* **proxy/openai:** don't crash the Responses memory tool loops on null
arguments
([#2273 ](https://github.com/headroomlabs-ai/headroom/issues/2273 ))
([a30db2c ](a30db2cae4 ))
* **proxy/openai:** feed Codex WS traffic into the traffic learner
([#2334 ](https://github.com/headroomlabs-ai/headroom/issues/2334 ))
([f669149 ](f669149769 ))
* **proxy/openai:** run response hooks on Responses, and bill their
re-drives
([#2872 ](https://github.com/headroomlabs-ai/headroom/issues/2872 ))
([675d13f ](675d13f08d ))
* **proxy:** allow settings routes for trusted gateway/dashboard clients
([#2491 ](https://github.com/headroomlabs-ai/headroom/issues/2491 ))
([a5b0a8f ](a5b0a8f4cc ))
* **proxy:** cache litellm model resolution to stop repeated Provider
List spam
([99f07e7 ](99f07e7bbd ))
* **proxy:** cancel periodic TOIN task on shutdown
([739fdef ](739fdef423 ))
* **proxy:** close the upstream stream when a streaming body is never
consumed
([0951663 ](0951663562 ))
* **proxy:** compress cache-mode cold starts and tag prefix-mismatch
passthrough
([#2365 ](https://github.com/headroomlabs-ai/headroom/issues/2365 ))
([aaeba0a ](aaeba0a319 ))
* **proxy:** emit request log timestamps in UTC
([620028f ](620028fa18 ))
* **proxy:** enable tool search by default and repair poisoned
transcripts
([#2807 ](https://github.com/headroomlabs-ai/headroom/issues/2807 ))
([0237cbf ](0237cbffbb ))
* **proxy:** gate mid-turn message coalescing to Claude Code clients
([#1643 ](https://github.com/headroomlabs-ai/headroom/issues/1643 ))
([a4bd2e6 ](a4bd2e62a5 ))
* **proxy:** give each Codex /v1/responses WS turn a unique request_id
([#2164 ](https://github.com/headroomlabs-ai/headroom/issues/2164 ))
([d02df10 ](d02df10758 ))
* **proxy:** graceful shutdown and reliable Ctrl+C exit
([#621 ](https://github.com/headroomlabs-ai/headroom/issues/621 ))
([17cdb18 ](17cdb185bc ))
* **proxy:** guard telemetry and TOIN endpoints
([cde1513 ](cde1513c91 ))
* **proxy:** include tool_search_deferral savings in the savings ledger
([12149f7 ](12149f7446 ))
* **proxy:** pass through cross-region prefixed Bedrock model IDs
directly
([#2330 ](https://github.com/headroomlabs-ai/headroom/issues/2330 ))
([64cb46e ](64cb46e24b ))
* **proxy:** port session-sticky beta headers to the Rust proxy
([#2381 ](https://github.com/headroomlabs-ai/headroom/issues/2381 ))
([f6398a6 ](f6398a6476 ))
* **proxy:** preserve merged session and quarantine contracts
([#2943 ](https://github.com/headroomlabs-ai/headroom/issues/2943 ))
([039cd24 ](039cd2431a ))
* **proxy:** preserve signed Anthropic thinking blocks on outbound
re-serialize
([#2254 ](https://github.com/headroomlabs-ai/headroom/issues/2254 ))
([dc163bc ](dc163bcd1c ))
* **proxy:** stop discarding compressed Codex WS later-frame payloads
([#2823 ](https://github.com/headroomlabs-ai/headroom/issues/2823 ))
([4ec416d ](4ec416df88 ))
* **proxy:** time-cap the compression timeout-debt quarantine
([#2360 ](https://github.com/headroomlabs-ai/headroom/issues/2360 ))
([#2412 ](https://github.com/headroomlabs-ai/headroom/issues/2412 ))
([c5a08d2 ](c5a08d22e0 ))
* **proxy:** unwrap Hermes tool_call bridge in tool name map
([#2717 ](https://github.com/headroomlabs-ai/headroom/issues/2717 ))
([a97b824 ](a97b82413b ))
* publish headroom-opencode in release workflow
([#2372 ](https://github.com/headroomlabs-ai/headroom/issues/2372 ))
([7859154 ](78591545ce ))
* **settings:** accept documented HEADROOM_* env names as settings keys
([#2833 ](https://github.com/headroomlabs-ai/headroom/issues/2833 ))
([de9e052 ](de9e0523da ))
* **subscription:** dedup transcript usage by message id
([#2340 ](https://github.com/headroomlabs-ai/headroom/issues/2340 ) token
inflation)
([#2408 ](https://github.com/headroomlabs-ai/headroom/issues/2408 ))
([74275b7 ](74275b7c3e ))
* **toin:** bound private query and pattern retention
([8cd1380 ](8cd138039e ))
* **tokenizer:** coerce non-string tool_call fields before counting
([#2801 ](https://github.com/headroomlabs-ai/headroom/issues/2801 ))
([b6f9877 ](b6f9877c78 ))
* **tokenizer:** price CJK in the Rust fixed-ratio estimator (Python
parity)
([#2260 ](https://github.com/headroomlabs-ai/headroom/issues/2260 ))
([6840153 ](6840153473 ))
* **transforms/adaptive-sizer:** honor max_k on small-input fast path
([#2319 ](https://github.com/headroomlabs-ai/headroom/issues/2319 ))
([8a90523 ](8a90523209 ))
* **transforms/smart_crusher:** don't crash on a tool call with a null
function
([#2232 ](https://github.com/headroomlabs-ai/headroom/issues/2232 ))
([3bb02f8 ](3bb02f8f75 ))
* Vertex model pricing shows $0.00 for versioned model names and
vertex:anthropic provider
([#2517 ](https://github.com/headroomlabs-ai/headroom/issues/2517 ))
([eb5b5e4 ](eb5b5e4198 ))
* **wrap/claude:** keep --1m effective when an explicit --model is
passed through
([c093bf1 ](c093bf11eb ))
* **wrap/opencode:** verify the opencode binary before mutating config
([ae38486 ](ae384862a4 ))
* **wrap/serena:** install Serena from the serena-agent PyPI wheel, not
the git source
([d7b25ae ](d7b25ae3bb ))
* **wrap:** honor Copilot OAuth wire-api override and model default
([#2387 ](https://github.com/headroomlabs-ai/headroom/issues/2387 ))
([1db6d88 ](1db6d88ab4 ))
* **wrap:** serialize shared proxy startup
([#2946 ](https://github.com/headroomlabs-ai/headroom/issues/2946 ))
([e540d64 ](e540d64feb ))
* **wrap:** stop the launch cwd from shadowing the installed package in
the proxy subprocess
([#2843 ](https://github.com/headroomlabs-ai/headroom/issues/2843 ))
([c49be26 ](c49be269a1 ))
### Performance Improvements
* cut hot-path latency 27% (token-count memo, startup preloads, JSON
scan memo)
([#2838 ](https://github.com/headroomlabs-ai/headroom/issues/2838 ))
([53af90d ](53af90d68c ))
* **proxy:** bound upstream calls and hot-path costs
([#2852 ](https://github.com/headroomlabs-ai/headroom/issues/2852 ))
([f624d3a ](f624d3a00a ))
* **subscription:** skip transcripts older than the window in
compute_window_tokens
([#2861 ](https://github.com/headroomlabs-ai/headroom/issues/2861 ))
([91d6bf3 ](91d6bf33cd ))
### Dependencies
* bump brace-expansion from 5.0.7 to 5.0.9 in /docs
([#2751 ](https://github.com/headroomlabs-ai/headroom/issues/2751 ))
([56ee57b ](56ee57be98 ))
* bump bytesize from 1.3.3 to 2.4.2
([#2286 ](https://github.com/headroomlabs-ai/headroom/issues/2286 ))
([6448545 ](6448545a7f ))
* bump hf-hub from 0.4.3 to 0.5.0
([#2285 ](https://github.com/headroomlabs-ai/headroom/issues/2285 ))
([4925bf6 ](4925bf6a82 ))
* bump next from 16.2.10 to 16.3.0 in /docs
([#2750 ](https://github.com/headroomlabs-ai/headroom/issues/2750 ))
([0fd0b99 ](0fd0b996a4 ))
* bump postcss from 8.5.19 to 8.5.25 in /plugins/openclaw
([#2749 ](https://github.com/headroomlabs-ai/headroom/issues/2749 ))
([cd60ee9 ](cd60ee9ae8 ))
* bump postcss from 8.5.19 to 8.5.25 in /plugins/opencode
([#2748 ](https://github.com/headroomlabs-ai/headroom/issues/2748 ))
([ff4e016 ](ff4e0167bb ))
* bump postcss from 8.5.19 to 8.5.25 in /sdk/typescript
([#2747 ](https://github.com/headroomlabs-ai/headroom/issues/2747 ))
([267c2bd ](267c2bdcb5 ))
* bump postcss from 8.5.19 to 8.5.26 in /docs
([#2881 ](https://github.com/headroomlabs-ai/headroom/issues/2881 ))
([e6e5826 ](e6e5826423 ))
* bump ruff from 0.15.17 to 0.15.22 in the pip-minor-patch group
([#2501 ](https://github.com/headroomlabs-ai/headroom/issues/2501 ))
([ecf130d ](ecf130d3ac ))
* bump rusqlite from 0.32.1 to 0.40.1
([#2287 ](https://github.com/headroomlabs-ai/headroom/issues/2287 ))
([522faa1 ](522faa1a59 ))
* bump the cargo-minor-patch group across 1 directory with 22 updates
([#2916 ](https://github.com/headroomlabs-ai/headroom/issues/2916 ))
([148d860 ](148d8605e2 ))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: JD Davis <mxjerrett@gmail.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-12 19:02:51 -05:00
Tejas Chopra
9fd5ae3d53
chore: release main ( #2679 )
...
🤖 I have created a release *beep* *boop*
---
<details><summary>0.34.0</summary>
##
[0.34.0](https://github.com/headroomlabs-ai/headroom/compare/v0.33.0...v0.34.0 )
(2026-08-05)
### Features
* **claude:** support Claude Code in VS Code
([#2752 ](https://github.com/headroomlabs-ai/headroom/issues/2752 ))
([13a310a ](13a310a00d ))
* **code:** add PHP support to CodeAwareCompressor
([#2423 ](https://github.com/headroomlabs-ai/headroom/issues/2423 ))
([6d5516d ](6d5516dcb8 ))
* **compress:** accept config.frozen_message_count on /v1/compress
([#2718 ](https://github.com/headroomlabs-ai/headroom/issues/2718 ))
([2797099 ](2797099bec ))
* **compress:** reach the lossless provider seam on the general path and
default /v1/compress to marker-free output
([#2691 ](https://github.com/headroomlabs-ai/headroom/issues/2691 ))
([f2c48e2 ](f2c48e26c6 ))
* **copilot:** proxy VS Code models transparently
([#2687 ](https://github.com/headroomlabs-ai/headroom/issues/2687 ))
([007446c ](007446c73a ))
### Bug Fixes
* **ccr:** stop persisting retrieval markers as original content
([#2694 ](https://github.com/headroomlabs-ai/headroom/issues/2694 ))
([#2703 ](https://github.com/headroomlabs-ai/headroom/issues/2703 ))
([3e348f3 ](3e348f327f ))
* **ci:** restrict Codecov shard uploads
([#2745 ](https://github.com/headroomlabs-ai/headroom/issues/2745 ))
([3f2ca99 ](3f2ca99fe1 ))
* **compression:** honor qualified CCR names across integrations
([#2698 ](https://github.com/headroomlabs-ai/headroom/issues/2698 ))
([dcb674b ](dcb674b5e4 ))
* **compress:** resolve the /v1/compress tokenizer per model, and
document the real contract
([#2743 ](https://github.com/headroomlabs-ai/headroom/issues/2743 ))
([6422a80 ](6422a80a58 ))
* **cost:** send litellm the total prompt so --budget stops seeing $0
([#2757 ](https://github.com/headroomlabs-ai/headroom/issues/2757 ))
([a033ac4 ](a033ac4176 ))
* **deps:** bump aiohttp and cryptography to clear the CVEs blocking
0.34.0
([#2753 ](https://github.com/headroomlabs-ai/headroom/issues/2753 ))
([0221e7f ](0221e7f240 ))
* **kompress:** let orgs run Kompress on their own inference stack
([#2736 ](https://github.com/headroomlabs-ai/headroom/issues/2736 ))
([3d23d76 ](3d23d76248 ))
* **kompress:** load merged.pt for the v2 checkpoint instead of the
unmerged PEFT safetensors
([#2716 ](https://github.com/headroomlabs-ai/headroom/issues/2716 ))
([46da91b ](46da91b2f1 ))
* **kompress:** reject artifacts that fail at run, and prefetch model
files at startup
([#2740 ](https://github.com/headroomlabs-ai/headroom/issues/2740 ))
([224578e ](224578e80b ))
* **learn:** filter ambient user-role scaffolding
([#2275 ](https://github.com/headroomlabs-ai/headroom/issues/2275 ))
([3eb0122 ](3eb0122068 ))
* **learn:** run project discovery off the event loop
([#2731 ](https://github.com/headroomlabs-ai/headroom/issues/2731 ))
([a70e5ff ](a70e5ff78d ))
* normalize /p/<project> prefix on WebSocket upgrades so the
Responses WS route is not rejected with 403
([#2379 ](https://github.com/headroomlabs-ai/headroom/issues/2379 ))
([789a4f3 ](789a4f3060 ))
* **providers:** give every model exactly one tokenizer
([#2761 ](https://github.com/headroomlabs-ai/headroom/issues/2761 ))
([cd92ed5 ](cd92ed52ff ))
* **providers:** stop a shorter model family shadowing a longer one
([#2762 ](https://github.com/headroomlabs-ai/headroom/issues/2762 ))
([0cb72f4 ](0cb72f45b2 ))
* **providers:** stop pricing modern content blocks at zero
([#2760 ](https://github.com/headroomlabs-ai/headroom/issues/2760 ))
([06add9e ](06add9e9d8 ))
* **proxy/cost:** mark estimated-basis budget records and add an
enforcement policy
([#2713 ](https://github.com/headroomlabs-ai/headroom/issues/2713 ))
([#2725 ](https://github.com/headroomlabs-ai/headroom/issues/2725 ))
([01df245 ](01df245252 ))
* **proxy/debug:** reconcile Kompress warmup state in /debug/warmup
([#2711 ](https://github.com/headroomlabs-ai/headroom/issues/2711 ))
([3a27c4d ](3a27c4dacb ))
* **proxy/openai:** run tool-description compaction on chat-completions
([#2741 ](https://github.com/headroomlabs-ai/headroom/issues/2741 ))
([f9db5b5 ](f9db5b5060 ))
* **proxy:** route Codex Live voice through a dedicated /v1/live
transport
([#2709 ](https://github.com/headroomlabs-ai/headroom/issues/2709 ))
([232fb49 ](232fb49c73 ))
* **proxy:** skip OpenAI tool_search deferral for Codex client
([#2729 ](https://github.com/headroomlabs-ai/headroom/issues/2729 ))
([56b3e4c ](56b3e4c1b1 ))
* **proxy:** stop toggling headroom_retrieve in the Anthropic tools
array ([#2672 ](https://github.com/headroomlabs-ai/headroom/issues/2672 ))
([08fce29 ](08fce29b47 ))
* remove rtk and lean-ctx CLI context tools
([#2677 ](https://github.com/headroomlabs-ai/headroom/issues/2677 ))
([e0ce4b1 ](e0ce4b1d48 ))
* **router:** stop counting an image's base64 payload as suffix tokens
([#2778 ](https://github.com/headroomlabs-ai/headroom/issues/2778 ))
([f03cc6d ](f03cc6d88b ))
* **savings:** surface request growth the tok_saved clamp swallows
([#2708 ](https://github.com/headroomlabs-ai/headroom/issues/2708 ))
([184146b ](184146b688 ))
* **stats:** report one "Tokens Saved" headline across every harness
([#2737 ](https://github.com/headroomlabs-ai/headroom/issues/2737 ))
([8262a4a ](8262a4a321 ))
* **telemetry:** anonymous compression stats — no prompts, no data
([#2728 ](https://github.com/headroomlabs-ai/headroom/issues/2728 ))
([9cfb008 ](9cfb00838a ))
* **telemetry:** stop mixing tokenizer scales in RequestOutcome, and fix
the overhead framing
([#2756 ](https://github.com/headroomlabs-ai/headroom/issues/2756 ))
([04e1517 ](04e1517ede ))
* **tokenizers:** count HuggingFace chat templates, and resolve gpt-5 /
gateway-wrapped names
([#2758 ](https://github.com/headroomlabs-ai/headroom/issues/2758 ))
([0ed306b ](0ed306b22b ))
* **tokenizers:** resolve gpt-5 and mixed-case model names to the right
encoding
([#2776 ](https://github.com/headroomlabs-ai/headroom/issues/2776 ))
([fc4680b ](fc4680b37a ))
* **transforms:** stop ContentRouter recompressing headroom_retrieve
results
([#2654 ](https://github.com/headroomlabs-ai/headroom/issues/2654 ))
([677e097 ](677e09735a ))
* **wrap/serena:** stop creating serena_config.yml, unbricking Serena on
fresh installs
([#2676 ](https://github.com/headroomlabs-ai/headroom/issues/2676 ))
([759209c ](759209cff3 ))
### Code Refactoring
* **pricing:** make LiteLLM the source of truth, not the hardcoded table
([#2779 ](https://github.com/headroomlabs-ai/headroom/issues/2779 ))
([0e1d6bf ](0e1d6bfa79 ))
* remove the dead headroom/prediction module
([#2692 ](https://github.com/headroomlabs-ai/headroom/issues/2692 ))
([b7a79ac ](b7a79ac31a ))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-04 19:39:34 -07:00
Tejas Chopra
28aa53dc7c
chore: release main ( #2339 )
...
🤖 I have created a release *beep* *boop*
---
<details><summary>0.33.0</summary>
##
[0.33.0](https://github.com/headroomlabs-ai/headroom/compare/v0.32.0...v0.33.0 )
(2026-07-29)
### Features
* **lossless:** factor shared directory prefix in the grep search fold
([#2547 ](https://github.com/headroomlabs-ai/headroom/issues/2547 ))
([7dc9a97 ](7dc9a978ca ))
* **metrics:** record per-extension token savings
([#2371 ](https://github.com/headroomlabs-ai/headroom/issues/2371 ))
([02eb90f ](02eb90f243 ))
* **opencode:** ship the transport plugin in pip installs
([#2601 ](https://github.com/headroomlabs-ai/headroom/issues/2601 ))
([f54f04f ](f54f04f5bf ))
* **opencode:** support Copilot subscription backend for headroom models
([#2441 ](https://github.com/headroomlabs-ai/headroom/issues/2441 ))
([#2445 ](https://github.com/headroomlabs-ai/headroom/issues/2445 ))
([9089e7f ](9089e7f7d3 ))
* **proxy/hooks:** run fold-only (stream-safe) turn hooks on streaming
OpenAI chat
([#2549 ](https://github.com/headroomlabs-ai/headroom/issues/2549 ))
([a6d4921 ](a6d4921e82 ))
* **proxy/savings:** aggregate tool-schema savings into Metrics + all
reporting sinks
([#2546 ](https://github.com/headroomlabs-ai/headroom/issues/2546 ))
([9f1ffef ](9f1ffefe83 ))
* **proxy:** label GitHub Copilot traffic as "copilot" in the outcome…
([#2377 ](https://github.com/headroomlabs-ai/headroom/issues/2377 ))
([d7a8cdb ](d7a8cdbee1 ))
* **proxy:** make /v1/compress usable as a gateway/Kong sidecar
([#2458 ](https://github.com/headroomlabs-ai/headroom/issues/2458 ))
([1329ed7 ](1329ed7f1a ))
* **proxy:** model-aware cold-prefix hook — reasoning compaction
(Kimi/GLM) + cold recompaction (CC)
([#2555 ](https://github.com/headroomlabs-ai/headroom/issues/2555 ))
([cb8f4b6 ](cb8f4b6436 ))
* **proxy:** route selected external compressors through the content
router
([#2388 ](https://github.com/headroomlabs-ai/headroom/issues/2388 ))
([e3c7964 ](e3c7964038 ))
* **proxy:** select built-in compressors via --compressor + registry
inventory
([#2373 ](https://github.com/headroomlabs-ai/headroom/issues/2373 ))
([56c7d4a ](56c7d4a59e ))
* **rust:** add structured prose offload plumbing
([#334 ](https://github.com/headroomlabs-ai/headroom/issues/334 ))
([#2378 ](https://github.com/headroomlabs-ai/headroom/issues/2378 ))
([9e07785 ](9e0778553f ))
* **rust:** port CodeCompressor AST compressor to Rust (parity-only)
([#1154 ](https://github.com/headroomlabs-ai/headroom/issues/1154 ))
([e530de5 ](e530de5ad2 ))
* **rust:** port Kompress ML prose compressor to Rust (parity-only)
([#1153 ](https://github.com/headroomlabs-ai/headroom/issues/1153 ))
([83e27e5 ](83e27e5036 ))
* **telemetry:** record provider cache read/write/uncached tokens per
request
([#2450 ](https://github.com/headroomlabs-ai/headroom/issues/2450 ))
([bec4cce ](bec4cce8a9 ))
* **transforms:** add compressed signal + dispatch code_aware/html/diff
via registry
([#2400 ](https://github.com/headroomlabs-ai/headroom/issues/2400 ))
([7ebda67 ](7ebda67ef6 ))
* **transforms:** add pluggable compressor registry +
headroom.compressor entry point
([#2370 ](https://github.com/headroomlabs-ai/headroom/issues/2370 ))
([a02073e ](a02073e332 ))
* **transforms:** dispatch kompress/text via the compressor registry +
forward question
([#2411 ](https://github.com/headroomlabs-ai/headroom/issues/2411 ))
([446ec26 ](446ec26003 ))
* **transforms:** dispatch smart_crusher via the compressor registry
(defer kompress/text ML boundary)
([#2404 ](https://github.com/headroomlabs-ai/headroom/issues/2404 ))
([7c7bf43 ](7c7bf43057 ))
* **transforms:** make built-in compressors real Compressor
implementations (adapters)
([#2391 ](https://github.com/headroomlabs-ai/headroom/issues/2391 ))
([981616c ](981616c60e ))
* **wrap:** boost Serena — symbol-first guidance, wrap-time pre-index,
repo-language scoping
([#2425 ](https://github.com/headroomlabs-ai/headroom/issues/2425 ))
([fd0e1a8 ](fd0e1a8afe ))
* **wrap:** default code-memory to Serena (dashboard browser off) behind
unified --code-memory
([#2413 ](https://github.com/headroomlabs-ai/headroom/issues/2413 ))
([6e4425a ](6e4425a6bd ))
* **wrap:** reduce-at-source — SAFE quiet-CLI env defaults for the
launched agent
([#2548 ](https://github.com/headroomlabs-ai/headroom/issues/2548 ))
([c990cfb ](c990cfb803 ))
### Bug Fixes
* **backends/litellm:** guard None completion_tokens in usage mapping
([#2322 ](https://github.com/headroomlabs-ai/headroom/issues/2322 ))
([44a174f ](44a174fef4 ))
* **backends:** don't crash the OpenAI->Anthropic converter on empty
choices
([#2484 ](https://github.com/headroomlabs-ai/headroom/issues/2484 ))
([43a7b57 ](43a7b578a1 ))
* **cache:** preserve cache_control ttl when re-anchoring a breakpoint
([#2651 ](https://github.com/headroomlabs-ai/headroom/issues/2651 ))
([e0d2cd0 ](e0d2cd0c5a ))
* **cache:** preserve client cache_control ttl when consolidating
breakpoints
([#2382 ](https://github.com/headroomlabs-ai/headroom/issues/2382 ))
([8906d3a ](8906d3a676 ))
* **ccr:** guard empty/malformed OpenAI choices in
_extract_assistant_message
([#2389 ](https://github.com/headroomlabs-ai/headroom/issues/2389 ))
([89319fb ](89319fbcad ))
* **ccr:** sliding idle-window TTL with max-lifetime ceiling in the Rust
core backends
([#2604 ](https://github.com/headroomlabs-ai/headroom/issues/2604 ))
([#2631 ](https://github.com/headroomlabs-ai/headroom/issues/2631 ))
([e825588 ](e825588bfb ))
* **ci:** align Ruff tooling versions
([#2406 ](https://github.com/headroomlabs-ai/headroom/issues/2406 ))
([2bb14d1 ](2bb14d1ab2 ))
* **cli:** warn when Headroom proxy URL leaks into the shell after
unwrap claude
([#2238 ](https://github.com/headroomlabs-ai/headroom/issues/2238 ))
([#2571 ](https://github.com/headroomlabs-ai/headroom/issues/2571 ))
([904bc67 ](904bc675b3 ))
* **codex:** detect keyring-backed ChatGPT auth
([#2478 ](https://github.com/headroomlabs-ai/headroom/issues/2478 ))
([46293f4 ](46293f4daf ))
* **compression:** report source-line span in CCR compression marker
([#2597 ](https://github.com/headroomlabs-ai/headroom/issues/2597 ))
([18e1c3c ](18e1c3c9ba ))
* **copilot:** derive GHE credential host from API URL
([#800 ](https://github.com/headroomlabs-ai/headroom/issues/800 ))
([#2511 ](https://github.com/headroomlabs-ai/headroom/issues/2511 ))
([4a8157f ](4a8157fa0a ))
* **copilot:** normalize subscription API routing
([#2441 ](https://github.com/headroomlabs-ai/headroom/issues/2441 ))
([#2455 ](https://github.com/headroomlabs-ai/headroom/issues/2455 ))
([2eca5ee ](2eca5ee114 ))
* **copilot:** preserve /v1 for the Anthropic /v1/messages endpoint
([#2409 ](https://github.com/headroomlabs-ai/headroom/issues/2409 ))
([#2414 ](https://github.com/headroomlabs-ai/headroom/issues/2414 ))
([c400f90 ](c400f90810 ))
* **deps:** bump mcp to 1.28.1 to clear 3 high-severity CVEs
([#2348 ](https://github.com/headroomlabs-ai/headroom/issues/2348 ))
([a90be94 ](a90be94e32 ))
* **grok:** preserve business-seat auth while routing only inference
([#2514 ](https://github.com/headroomlabs-ai/headroom/issues/2514 ))
([e4076bb ](e4076bbe99 ))
* **image:** reuse image models instead of rebuilding them per request
([#2513 ](https://github.com/headroomlabs-ai/headroom/issues/2513 ))
([#2536 ](https://github.com/headroomlabs-ai/headroom/issues/2536 ))
([2a63ec7 ](2a63ec70b6 ))
* **install:** carry upstream-routing env overrides into supervised
deployments
([#2429 ](https://github.com/headroomlabs-ai/headroom/issues/2429 ))
([170b04a ](170b04a74d ))
* **install:** default to cache mode, matching `headroom proxy`
([#1893 ](https://github.com/headroomlabs-ai/headroom/issues/1893 )
follow-up)
([#2563 ](https://github.com/headroomlabs-ai/headroom/issues/2563 ))
([b121223 ](b121223ec9 ))
* **install:** migrate deployments off the retired chopratejas image
repo ([#2427 ](https://github.com/headroomlabs-ai/headroom/issues/2427 ))
([17ff13c ](17ff13ccbe ))
* **install:** use CREATE_NO_WINDOW instead of DETACHED_PROCESS on
Windows
([#2527 ](https://github.com/headroomlabs-ai/headroom/issues/2527 ))
([045f3df ](045f3dfe6f ))
* **kompress:** raise the default execution-slot wait
([#2456 ](https://github.com/headroomlabs-ai/headroom/issues/2456 ))
([5bd2266 ](5bd2266f16 ))
* **learn:** detect the active OpenCode database
([#2587 ](https://github.com/headroomlabs-ai/headroom/issues/2587 ))
([f74d874 ](f74d874777 ))
* **learn:** keep traceback tail in tool-error digest preview
([#2596 ](https://github.com/headroomlabs-ai/headroom/issues/2596 ))
([85e8699 ](85e8699451 ))
* **learn:** treat unreadable candidate paths as absent in project
decode
([#2446 ](https://github.com/headroomlabs-ai/headroom/issues/2446 ))
([a09ba6c ](a09ba6c087 ))
* **mcp:** pin mcp dependency to <2.0.0 to prevent server startup
crash ([#2642 ](https://github.com/headroomlabs-ai/headroom/issues/2642 ))
([b3f016b ](b3f016b866 ))
* **proxy/cost:** count Gemini thinking tokens in output usage
([#2639 ](https://github.com/headroomlabs-ai/headroom/issues/2639 ))
([22b707f ](22b707fd31 ))
* **proxy/cost:** record each request's savings exactly once (drop 3
double-counts)
([#2545 ](https://github.com/headroomlabs-ai/headroom/issues/2545 ))
([0845b26 ](0845b26ee6 ))
* **proxy/cost:** warn once per model when pricing lookup fails
([#2504 ](https://github.com/headroomlabs-ai/headroom/issues/2504 ))
([#2535 ](https://github.com/headroomlabs-ai/headroom/issues/2535 ))
([fa47637 ](fa4763761b ))
* **proxy/gemini:** None-guard token counts from usageMetadata
([#2347 ](https://github.com/headroomlabs-ai/headroom/issues/2347 ))
([f64aac9 ](f64aac9733 ))
* **proxy/gemini:** tolerate malformed parts on the compression path
([#2486 ](https://github.com/headroomlabs-ai/headroom/issues/2486 ))
([07cf547 ](07cf547607 ))
* **proxy/metrics:** move the savings-ledger append off the event loop
([#2439 ](https://github.com/headroomlabs-ai/headroom/issues/2439 ))
([4aac068 ](4aac068814 ))
* **proxy/openai:** cache under looked-up messages
([#2420 ](https://github.com/headroomlabs-ai/headroom/issues/2420 ))
([7052d52 ](7052d52dcb ))
* **proxy/openai:** don't record Codex WS savings without input
accounting
([#2493 ](https://github.com/headroomlabs-ai/headroom/issues/2493 ))
([2195ba7 ](2195ba7d91 ))
* **proxy/openai:** feed chat/completions traffic into the traffic
learner
([#2333 ](https://github.com/headroomlabs-ai/headroom/issues/2333 ))
([6cdfd3f ](6cdfd3f64d ))
* **proxy/openai:** None-guard usage token counts on the chat path
([#2431 ](https://github.com/headroomlabs-ai/headroom/issues/2431 ))
([313c290 ](313c290df9 ))
* **proxy/openai:** replay incremental events in buffered Responses SSE
([#2410 ](https://github.com/headroomlabs-ai/headroom/issues/2410 ))
([#2415 ](https://github.com/headroomlabs-ai/headroom/issues/2415 ))
([0cbc0e8 ](0cbc0e8e54 ))
* **proxy/output-shaping:** tolerate a non-string system block text in
steering
([#2435 ](https://github.com/headroomlabs-ai/headroom/issues/2435 ))
([3e97671 ](3e976712e7 ))
* **proxy/perf:** count turn-hook message folds in token accounting
([#2520 ](https://github.com/headroomlabs-ai/headroom/issues/2520 ))
([c371d5a ](c371d5ad60 ))
* **proxy/perf:** tokenizer-consistent token accounting + surface
tool-schema savings
([#2542 ](https://github.com/headroomlabs-ai/headroom/issues/2542 ))
([1cc53c9 ](1cc53c9c92 ))
* **proxy/streaming:** tolerate malformed content in _response_to_sse
([#2481 ](https://github.com/headroomlabs-ai/headroom/issues/2481 ))
([77b26c0 ](77b26c093c ))
* **proxy:** keep buffered CCR streams alive
([#2479 ](https://github.com/headroomlabs-ai/headroom/issues/2479 ))
([a2e42fb ](a2e42fb877 ))
* **proxy:** keep core tools and the client's ToolSearch resident for
PascalCase clients
([#2647 ](https://github.com/headroomlabs-ai/headroom/issues/2647 ))
([1d29738 ](1d29738818 ))
* **proxy:** offload OpenAI and Gemini tokenizer counting off the event
loop ([#2498 ](https://github.com/headroomlabs-ai/headroom/issues/2498 ))
([806d2e4 ](806d2e468a ))
* **proxy:** promote Kompress health after runtime load
([#2402 ](https://github.com/headroomlabs-ai/headroom/issues/2402 ))
([54526bc ](54526bc858 ))
* **proxy:** reassemble server_tool_use.input from streamed partial_json
([#2449 ](https://github.com/headroomlabs-ai/headroom/issues/2449 ))
([8c8fae0 ](8c8fae0d0b ))
* **proxy:** report deferred Kompress status and promote health from
cache ([#2564 ](https://github.com/headroomlabs-ai/headroom/issues/2564 ))
([d50cfab ](d50cfabedc ))
* **proxy:** skip max_tokens rename for backend-routed openai chat
([#2401 ](https://github.com/headroomlabs-ai/headroom/issues/2401 ))
([d6a1af4 ](d6a1af40d5 ))
* **release:** publish Windows wheel + sdist (disable PyPI attestations,
[#112 ](https://github.com/headroomlabs-ai/headroom/issues/112 ))
([#2405 ](https://github.com/headroomlabs-ai/headroom/issues/2405 ))
([f9cbdd6 ](f9cbdd6e39 ))
* **release:** sync generated version metadata on the release branch
([#2659 ](https://github.com/headroomlabs-ai/headroom/issues/2659 ))
([5383c6b ](5383c6bf2f ))
* **rust:** port CJK-aware relevance-query matching to CodeCompressor
([#2634 ](https://github.com/headroomlabs-ai/headroom/issues/2634 ))
([e86c639 ](e86c6390ce ))
* **security:** exclude compromised ast-grep-cli 0.44.1 (supply-chain
trojan)
([#2342 ](https://github.com/headroomlabs-ai/headroom/issues/2342 ))
([494fb5a ](494fb5a60e ))
* **tokenizers:** price Claude against a real BPE (tiktoken o200k) not a
char estimate
([#2543 ](https://github.com/headroomlabs-ai/headroom/issues/2543 ))
([285176b ](285176be54 ))
* **transforms/cross-turn-dedup:** don't renumber-fold zero-padded line
prefixes
([#2369 ](https://github.com/headroomlabs-ai/headroom/issues/2369 ))
([f4070c4 ](f4070c44cb ))
* **transforms/kompress-remote:** keep compress fail-open on malformed
200 ([#2320 ](https://github.com/headroomlabs-ai/headroom/issues/2320 ))
([b759990 ](b75999017f ))
* **wrap:** emit bare dotted keys for Codex --config overrides
([#2383 ](https://github.com/headroomlabs-ai/headroom/issues/2383 ))
([f57e959 ](f57e959a50 ))
* **wrap:** make RTK opt-in (off by default) across wrap subcommands
([#2344 ](https://github.com/headroomlabs-ai/headroom/issues/2344 ))
([44136ed ](44136ed042 ))
* **wrap:** skip Serena project setup outside real project roots
([#2574 ](https://github.com/headroomlabs-ai/headroom/issues/2574 ))
([0994ea0 ](0994ea04c8 ))
* **wrap:** stop same-port persistent routing during claude unwrap
([#2340 ](https://github.com/headroomlabs-ai/headroom/issues/2340 ))
([#2350 ](https://github.com/headroomlabs-ai/headroom/issues/2350 ))
([cf5fa64 ](cf5fa644b6 ))
### Performance Improvements
* **content_router:** dedupe content detection
([#2419 ](https://github.com/headroomlabs-ai/headroom/issues/2419 ))
([9b016f2 ](9b016f2b64 ))
### Dependencies
* bump the cargo-minor-patch group with 10 updates
([#2284 ](https://github.com/headroomlabs-ai/headroom/issues/2284 ))
([3266ed7 ](3266ed7641 ))
* bump the npm-minor-patch group across 3 directories with 7 updates
([#2276 ](https://github.com/headroomlabs-ai/headroom/issues/2276 ))
([961866b ](961866ba7c ))
### Code Refactoring
* **transforms:** dispatch simple built-in strategies via the compressor
registry
([#2399 ](https://github.com/headroomlabs-ai/headroom/issues/2399 ))
([fc9c63f ](fc9c63f18c ))
* **wrap:** retire tokensave; Serena is the code-memory MCP
([#2499 ](https://github.com/headroomlabs-ai/headroom/issues/2499 ))
([5d23a0a ](5d23a0aec2 ))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-29 15:54:23 -07:00
Tejas Chopra
4381388d56
chore: release main ( #1923 )
...
## Description
Release Please generated the 0.33.0 release PR for main. This updates
release metadata, package versions, and the generated changelog for the
0.33.0 release.
I also aligned the agent-hook plugin manifests, marketplace metadata,
editable lockfile package version, and canonical MCP `server.json`
descriptor to 0.33.0 so all package/plugin/registry version declarations
match the Release Please version bump.
## Type of Change
- [x] Documentation update
- [x] Release / packaging metadata
## Changes Made
- Updated `.release-please-manifest.json`, `pyproject.toml`,
`plugins/openclaw/package.json`, and `sdk/typescript/package.json` to
0.33.0.
- Updated the generated `CHANGELOG.md` release notes for 0.33.0.
- Synced `plugins/headroom-agent-hooks` plugin manifests and marketplace
metadata to 0.33.0.
- Synced `uv.lock` editable `headroom-ai` package version to 0.33.0.
- Regenerated the canonical MCP `server.json` descriptor to 0.33.0.
## Testing
- [x] Version verification passes
- [x] Version-sync tests pass
- [x] MCP server descriptor test passes
- [x] Whitespace check passes
### Test Output
```text
uv run python scripts/verify-versions.py
All versions aligned at 0.33.0
uv run pytest scripts/tests/test_version_sync.py scripts/tests/test_sync_plugin_versions.py -q
14 passed in 0.80s
uv run pytest tests/test_mcp_registry/test_server_json.py -q
4 passed in 0.42s
git diff --check
# no output
```
## Real Behavior Proof
- Environment: Windows 11, local checkout of the Release Please branch.
- Exact command / steps: Ran version verification and MCP descriptor
tests after syncing release metadata, plugin marketplace versions,
lockfile version, and `server.json`.
- Observed result: All package, plugin manifest, marketplace, lockfile,
and MCP descriptor release versions are aligned at 0.33.0.
2026-07-16 21:27:08 -07:00
Tejas Chopra
63945abe3a
chore: sync version state to released 0.31.0 to unblock release-please (v0.32.0) ( #2338 )
...
## Description
**Fixes the Release Please pipeline so it emits `v0.32.0`.** pip /
Docker / npm are out of sync because 0.32.0 was never actually released.
### Root cause
Same failure mode as #1916 . #2175 (a `fix(deps)` PR) bumped
`pyproject.toml` + `.release-please-manifest.json` to **0.32.0
out-of-band**, so release-please reads 0.32.0 as the *current* version
and computes the next release as **0.33.0** (#1923 ) — **skipping 0.32.0,
which was never tagged, GitHub-released, or published to PyPI/Docker.**
The last real release is `v0.31.0` (2026-07-09). The plugin/marketplace
manifests were also left at 0.31.0, so version state was split-brained:
```
pyproject.toml / openclaw / sdk-typescript : 0.32.0 <- #2175
plugin.json (x2) / marketplace.json (x2) : 0.31.0
manifest : 0.32.0
```
### Fix
Realign every version-tracked file **and** the RP manifest to the last
real release, **0.31.0**, via the repo's own `scripts/version-sync.py
--version 0.31.0`. Versions only — no code change.
## What happens after merge
1. Release Please runs on `main`, sees `manifest = 0.31.0` + releasable
commits since `v0.31.0`, and **rewrites its release PR (#1923 ) to
`chore: release 0.32.0`** (bumping every version file).
2. Merging that PR tags `v0.32.0` and fires `release: published`, which
publishes **PyPI + npm (SDK + openclaw) + Docker** at 0.32.0 in one shot
— bringing all registries back in sync.
## Changes Made
- `.release-please-manifest.json` → `0.31.0`
- `pyproject.toml`, `sdk/typescript/package.json`,
`plugins/openclaw/package.json`, `.releasemetadata` → `0.31.0` (via
`version-sync.py`)
- Plugin/marketplace manifests were already `0.31.0` (unchanged).
## Testing
```text
$ python scripts/verify-versions.py
All versions aligned at 0.31.0
```
## Real Behavior Proof
- Environment: local `.venv`.
- Steps: `version-sync.py --version 0.31.0`, reset manifest,
`verify-versions.py`.
- Observed: all 9 version entries aligned at 0.31.0; no CHANGELOG
touched (Changelog Guard passes).
- Not tested: the live release-please recompute (will run on merge —
expected to rewrite #1923 to `chore: release 0.32.0`).
## Note on downstream publish
The release-please workflow only triggers `release.yml`/`docker.yml` if
`RELEASE_PLEASE_TOKEN` (a PAT) is set — with the `GITHUB_TOKEN` fallback
the release is created but downstream publishes don't fire. #1916
shipped 0.31.0 fully via this path, so the PAT was set then; if the
0.32.0 publish doesn't fire on merge, verify that secret still exists.
2026-07-16 21:06:51 -07:00
JD Davis
ea3d5a86b7
fix(deps): clear Dependabot lockfile alerts ( #2175 )
...
## Description
Clears the current dependency/security-audit blockers that are making
unrelated PRs red:
- `transformers 5.3.0` / `CVE-2026-5241`, fixed by requiring
`transformers>=5.5.0` in the locked optional dependency set.
- `sqlitedict <=2.1.0` via the optional `benchmark` extra's
`lm-eval[api]` dependency. There is no patched `sqlitedict` release, so
this PR removes the published/locked `benchmark` extra instead of
shipping a known-vulnerable transitive dependency.
- `esbuild >=0.27.3,<0.28.1` in the OpenCode plugin lockfile, fixed by
forcing `esbuild@0.28.1` through the OpenCode npm override and
regenerated lockfile.
The benchmark code still invokes `python -m lm_eval`; researchers who
need that harness should install `lm-eval[api]` in their benchmark
environment until its transitive vulnerability has a patched release.
## Type of Change
- [x] Bug fix (non-breaking change that fixes an issue)
- [ ] New feature (non-breaking change that adds functionality)
- [ ] Breaking change (fix or feature that would cause existing
functionality to change)
- [ ] Documentation update
- [ ] Performance improvement
- [ ] Code refactoring (no functional changes)
## Changes Made
- `pyproject.toml`: remove the `benchmark` optional extra, document
external `lm-eval[api]` installation guidance, and require
`transformers>=5.5.0`.
- `uv.lock`: regenerate without the `benchmark` extra, removing
`lm-eval` and `sqlitedict` lock entries and locking the patched
transformers floor.
- `plugins/opencode/package.json`: add an `overrides` entry for
`esbuild@0.28.1`.
- `plugins/opencode/package-lock.json`: regenerate the OpenCode lockfile
with `esbuild@0.28.1`.
## Testing
- [x] Unit tests pass (`pytest`)
- [x] Linting passes (`ruff check .`)
- [ ] Type checking passes (`mypy headroom`)
- [ ] New tests added for new functionality
- [x] Manual testing performed
### Test Output
```text
uv lock --check
rg -n -F 'sqlitedict' uv.lock # no matches
rg -n -F 'name = "lm-eval"' uv.lock # no matches
rg -n -F "extra == 'benchmark'" uv.lock # no matches
rg -n -F '0.27.7' plugins/opencode/package-lock.json plugins/opencode/package.json # no matches
npm ls esbuild --package-lock-only
npm audit --package-lock-only # found 0 vulnerabilities
git diff --check
```
Previous GitHub checks were green. After merging current `main`, fresh
GitHub checks are running again; local targeted validation still passes.
## Real Behavior Proof
- Environment: Windows 11, Python 3.13.3, uv, npm in `plugins/opencode`,
Dependabot/pip-audit alert metadata from the failing PR jobs.
- Exact command / steps: inspected the regenerated Python and npm
lockfiles with `rg`, checked the uv lock with `uv lock --check`, checked
OpenCode's dependency tree with `npm ls esbuild --package-lock-only`,
and ran `npm audit --package-lock-only`.
- Observed result: `uv.lock` no longer contains `sqlitedict`, `lm-eval`,
or a `benchmark` extra marker; `transformers` resolves at the patched
`>=5.5.0` floor; OpenCode's lock resolves `esbuild@0.28.1`; `npm audit
--package-lock-only` reports 0 vulnerabilities; GitHub `Dependency audit
(pip-audit)` passes.
- Not tested: running the external `lm-eval` harness after installing it
separately.
## Review Readiness
- [x] I have performed a self-review
- [x] This PR is ready for human review
## Checklist
- [x] My code follows the project's style guidelines
- [x] I have performed a self-review of my code
- [ ] I have commented my code, particularly in hard-to-understand areas
- [x] I have made corresponding changes to the documentation
- [x] My changes generate no new warnings
- [ ] I have added tests that prove my fix is effective or that my
feature works
- [x] New and existing unit tests pass locally with my changes
- [x] I have updated the CHANGELOG.md if applicable
## Screenshots (if applicable)
N/A - dependency and lockfile security fix.
## Additional Notes
The `benchmark` extra can be restored once the upstream `lm-eval[api]`
dependency chain stops pulling a vulnerable `sqlitedict` release.
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-14 20:40:28 -07:00
github-actions[bot]
a9515155c7
chore: release main ( #1918 )
...
🤖 I have created a release *beep* *boop*
---
<details><summary>0.31.0</summary>
##
[0.31.0](https://github.com/headroomlabs-ai/headroom/compare/v0.30.0...v0.31.0 )
(2026-07-09)
### Features
* **cache:** provider-agnostic cache-mode delta + cc-agnostic prefix
comparison
([#1868 ](https://github.com/headroomlabs-ai/headroom/issues/1868 ))
([7c2f0ea ](7c2f0ea079 ))
* **ccr:** wire retrieve-tool interception into OpenAI Responses handler
([#1898 ](https://github.com/headroomlabs-ai/headroom/issues/1898 ))
([62cd307 ](62cd3072a2 ))
* **compression:** add audit-safe mode with protected pattern matching
([#1899 ](https://github.com/headroomlabs-ai/headroom/issues/1899 ))
([bb112dd ](bb112dd176 ))
* **content-router:** accept any real compression (remove min-savings
floor)
([#1771 ](https://github.com/headroomlabs-ai/headroom/issues/1771 ))
([6c31db9 ](6c31db97fb ))
* **content-router:** lossless-first dispatch, cross-turn dedup, and A7
lossy-after-fold
([#1818 ](https://github.com/headroomlabs-ai/headroom/issues/1818 ))
([60af15f ](60af15f96f ))
* **proxy:** add provider-only HTTP proxy
([#1807 ](https://github.com/headroomlabs-ai/headroom/issues/1807 ))
([ebe0a3b ](ebe0a3bd7b ))
* **proxy:** add turn-hook extension point for buffered model turns
([#1891 ](https://github.com/headroomlabs-ai/headroom/issues/1891 ))
([ec950f7 ](ec950f7ef1 ))
### Bug Fixes
* **build:** enable Intel macOS pip installs via ort-load-dynamic
([#1538 ](https://github.com/headroomlabs-ai/headroom/issues/1538 ))
([32ce99e ](32ce99e4b4 ))
* **cache:** avoid fallback session collisions
([#1827 ](https://github.com/headroomlabs-ai/headroom/issues/1827 ))
([0f606b6 ](0f606b6281 ))
* **ccr:** make expired retrieve misses terminal
([#1781 ](https://github.com/headroomlabs-ai/headroom/issues/1781 ))
([9cbdba4 ](9cbdba4dc1 ))
* **ccr:** preserve Anthropic re-stream shape
([#1854 ](https://github.com/headroomlabs-ai/headroom/issues/1854 ))
([f663894 ](f663894f60 ))
* **ccr:** preserve thinking blocks in buffered stream re-synthesis
([#1897 ](https://github.com/headroomlabs-ai/headroom/issues/1897 ))
([ede085c ](ede085cc11 ))
* **cli/proxy:** preserve explicit HEADROOM_MIN_TOKENS=0 / MAX_ITEMS=0
([#1886 ](https://github.com/headroomlabs-ai/headroom/issues/1886 ))
([3a33af1 ](3a33af1af3 ))
* **code-compressor:** CJK-aware relevance-query symbol matching
([#1747 ](https://github.com/headroomlabs-ai/headroom/issues/1747 ))
([b38315c ](b38315cf72 ))
* **codex:** discover updated Codex state stores
([#1889 ](https://github.com/headroomlabs-ai/headroom/issues/1889 ))
([9d42eba ](9d42ebaa1a ))
* **codex:** OpenCode Zen telemetry attribution
([#1648 ](https://github.com/headroomlabs-ai/headroom/issues/1648 ))
([f18c6bd ](f18c6bd896 ))
* **content-detector:** detect and compress space-separated JSON objects
([#1742 ](https://github.com/headroomlabs-ai/headroom/issues/1742 ))
([5194bdc ](5194bdc5a6 ))
* **content-router:** token-measure lossless folds at the acceptance
gate ([#1772 ](https://github.com/headroomlabs-ai/headroom/issues/1772 ))
([c5493ea ](c5493ea93b ))
* **copilot:** normalize subscription routing host
([#1836 ](https://github.com/headroomlabs-ai/headroom/issues/1836 ))
([afd9cbd ](afd9cbdfaf ))
* **copilot:** route mixed-model requests per model
([#1785 ](https://github.com/headroomlabs-ai/headroom/issues/1785 ))
([5af5e22 ](5af5e22862 ))
* **dashboard:** deduplicate repeated savings metrics
([#1804 ](https://github.com/headroomlabs-ai/headroom/issues/1804 ))
([88f935a ](88f935a1eb ))
* **dashboard:** distinguish unavailable RTK from zero stats in Docker
([#1900 ](https://github.com/headroomlabs-ai/headroom/issues/1900 ))
([87f6e93 ](87f6e93c14 ))
* **dashboard:** distinguish unavailable RTK from zero stats in Docker
([#1901 ](https://github.com/headroomlabs-ai/headroom/issues/1901 ))
([361adcd ](361adcd1a0 ))
* **dashboard:** price proxy savings without litellm
([#1728 ](https://github.com/headroomlabs-ai/headroom/issues/1728 ))
([188e382 ](188e382b44 ))
* detect and clear stale ANTHROPIC_BASE_URL from crashed wrap sessions
([#1768 ](https://github.com/headroomlabs-ai/headroom/issues/1768 ))
([#1837 ](https://github.com/headroomlabs-ai/headroom/issues/1837 ))
([84509a4 ](84509a4b89 ))
* **docker:** persist headroom workspace in compose
([#1839 ](https://github.com/headroomlabs-ai/headroom/issues/1839 ))
([5e29c06 ](5e29c06aaf ))
* **docker:** report source build version
([#1862 ](https://github.com/headroomlabs-ai/headroom/issues/1862 ))
([3807488 ](38074888ac ))
* **evals:** default unparseable judge scores below pass threshold
([#1892 ](https://github.com/headroomlabs-ai/headroom/issues/1892 ))
([42ebbc6 ](42ebbc6cce ))
* **install:** pass sc.exe create as raw command line so binPath=
quoting survives
([#1654 ](https://github.com/headroomlabs-ai/headroom/issues/1654 ))
([#1702 ](https://github.com/headroomlabs-ai/headroom/issues/1702 ))
([d6e0710 ](d6e0710228 ))
* **install:** persist --no-http2 override through install apply
([#1676 ](https://github.com/headroomlabs-ai/headroom/issues/1676 ))
([6fb5f3b ](6fb5f3bc3d ))
* **mcp:** isolate ClaudeRegistrar CLI config env
([#1888 ](https://github.com/headroomlabs-ai/headroom/issues/1888 ))
([1c947b1 ](1c947b1103 ))
* **mcp:** surface dead proxy state
([#1786 ](https://github.com/headroomlabs-ai/headroom/issues/1786 ))
([931eed8 ](931eed879d ))
* **memory:** resolve Trae cwd metadata from user reminders
([#1737 ](https://github.com/headroomlabs-ai/headroom/issues/1737 ))
([#1887 ](https://github.com/headroomlabs-ai/headroom/issues/1887 ))
([3e85eb1 ](3e85eb1880 ))
* **opencode:** use local MCP config
([#1383 ](https://github.com/headroomlabs-ai/headroom/issues/1383 ))
([4bd3ddf ](4bd3ddfaa5 ))
* **proxy/openai:** thread savings-profile kwargs into chat completions
([#1606 ](https://github.com/headroomlabs-ai/headroom/issues/1606 ))
([7ff842d ](7ff842da17 ))
* **proxy/openai:** translate max_tokens -> max_completion_tokens on
chat path
([#1774 ](https://github.com/headroomlabs-ai/headroom/issues/1774 ))
([285808b ](285808b90e ))
* **proxy:** bound Codex WS compression fallback latency
([#1802 ](https://github.com/headroomlabs-ai/headroom/issues/1802 ))
([d24a3f8 ](d24a3f8425 ))
* **proxy:** bound HF tokenizer load and offload token counting off
event loop
([#1738 ](https://github.com/headroomlabs-ai/headroom/issues/1738 ))
([46d5d68 ](46d5d685d9 ))
* **proxy:** cancel retry backoff on shutdown
([#1834 ](https://github.com/headroomlabs-ai/headroom/issues/1834 ))
([da2d8dc ](da2d8dc9db ))
* **proxy:** compress Anthropic user text blocks when enabled
([#1875 ](https://github.com/headroomlabs-ai/headroom/issues/1875 ))
([e36439a ](e36439a941 ))
* **proxy:** freeze must forward cached (compressed) prefix
byte-identical — stop token-mode cache busting
([#1850 ](https://github.com/headroomlabs-ai/headroom/issues/1850 ))
([248ae0f ](248ae0f3e0 ))
* **proxy:** fsync savings dir after atomic rename
([#1764 ](https://github.com/headroomlabs-ai/headroom/issues/1764 ))
([7de2c1e ](7de2c1e4c2 ))
* **proxy:** keep cache_control bounded + stable so the freeze overlay
stops busting
([#1852 ](https://github.com/headroomlabs-ai/headroom/issues/1852 ))
([4820134 ](48201345be ))
* **proxy:** persist lifetime cache-read savings across restarts
([#1665 ](https://github.com/headroomlabs-ai/headroom/issues/1665 ))
([908997e ](908997ef61 ))
* **proxy:** preserve streaming passthrough beta headers
([#1783 ](https://github.com/headroomlabs-ai/headroom/issues/1783 ))
([0f553a8 ](0f553a8ebb ))
* **proxy:** release _active_streams session lock on setup-phase errors
([#1864 ](https://github.com/headroomlabs-ai/headroom/issues/1864 ))
([2ccd831 ](2ccd831032 ))
* **proxy:** retry HTTP/2 stream resets instead of 502ing
([#1645 ](https://github.com/headroomlabs-ai/headroom/issues/1645 ))
([2ce19c2 ](2ce19c2c55 ))
* **proxy:** retry passthrough on transient upstream connection close
([#1513 ](https://github.com/headroomlabs-ai/headroom/issues/1513 ))
([5d14080 ](5d14080c94 ))
* **proxy:** route Foundry Anthropic messages
([#1878 ](https://github.com/headroomlabs-ai/headroom/issues/1878 ))
([739f654 ](739f654bbd ))
* **proxy:** serve /favicon.ico locally instead of tunneling upstream
([#1787 ](https://github.com/headroomlabs-ai/headroom/issues/1787 ))
([#1847 ](https://github.com/headroomlabs-ai/headroom/issues/1847 ))
([3076e32 ](3076e32172 ))
* **proxy:** stop rtk stat failures from corrupting session baseline
([#1693 ](https://github.com/headroomlabs-ai/headroom/issues/1693 ))
([681b9a8 ](681b9a8c1a ))
* **proxy:** strip 1m model suffix before upstream forwarding
([#1840 ](https://github.com/headroomlabs-ai/headroom/issues/1840 ))
([e22d745 ](e22d7453d4 ))
* **proxy:** subtract cache write premiums from net savings
([#1800 ](https://github.com/headroomlabs-ai/headroom/issues/1800 ))
([53a465b ](53a465b121 ))
* **router:** honor MCP aliases in excluded tools
([#1822 ](https://github.com/headroomlabs-ai/headroom/issues/1822 ))
([#1863 ](https://github.com/headroomlabs-ai/headroom/issues/1863 ))
([140d6e4 ](140d6e4f96 ))
* **rtk:** link managed rtk onto PATH instead of mutating the hook
([#1698 ](https://github.com/headroomlabs-ai/headroom/issues/1698 ))
([140cb05 ](140cb05fbc ))
* **streaming:** preserve server_tool_use sse blocks
([#1826 ](https://github.com/headroomlabs-ai/headroom/issues/1826 ))
([4ac5493 ](4ac54934cb ))
* **toin:** publish skip compression recommendations
([#1782 ](https://github.com/headroomlabs-ai/headroom/issues/1782 ))
([be51008 ](be51008c70 ))
* **transforms:** normalize diff compressor context
([#1801 ](https://github.com/headroomlabs-ai/headroom/issues/1801 ))
([838c523 ](838c5234a8 ))
* **transforms:** pass through ragged tables instead of misaligning
columns
([#1713 ](https://github.com/headroomlabs-ai/headroom/issues/1713 ))
([c7665ca ](c7665ca088 ))
* use rtk native Cursor hook instead of injecting .cursorrules
([#756 ](https://github.com/headroomlabs-ai/headroom/issues/756 ))
([#1846 ](https://github.com/headroomlabs-ai/headroom/issues/1846 ))
([1573f1f ](1573f1fd07 ))
* **wrap:** replace stale-proxy detection with Vite-style port fallback
([#1406 ](https://github.com/headroomlabs-ai/headroom/issues/1406 ))
([b4205c6 ](b4205c68e6 ))
### Performance Improvements
* **proxy:** cap compression workers to CPU count
([#1803 ](https://github.com/headroomlabs-ai/headroom/issues/1803 ))
([0a3851b ](0a3851b240 ))
* **savings:** batch tracker persistence off the request hot path
([#1817 ](https://github.com/headroomlabs-ai/headroom/issues/1817 ))
([451b9f0 ](451b9f0867 ))
### Dependencies
* bump the cargo-minor-patch group across 1 directory with 7 updates
([#1909 ](https://github.com/headroomlabs-ai/headroom/issues/1909 ))
([45601d9 ](45601d93bc ))
* bump the npm-minor-patch group across 4 directories with 18 updates
([#1907 ](https://github.com/headroomlabs-ai/headroom/issues/1907 ))
([8872bbc ](8872bbc6a2 ))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-09 07:47:54 -07:00
Tejas Chopra
2990b7457d
chore: sync version state to released 0.30.0 to unblock release-please ( #1916 )
...
## Description
**Fixes the Release Please pipeline**, which stopped opening the release
PR, leaving pip / Docker / npm out of sync.
### Root cause
Recent releases (0.28 → 0.30) were cut **out-of-band** (manual tag +
release), so Release Please's state drifted from reality:
- `.release-please-manifest.json` was frozen at **0.29.0**, and the
in-repo version files at **0.29.0** — even the `v0.30.0` tag commit has
`pyproject.toml = 0.29.0`. The plugin/marketplace manifests were frozen
even further back, at **0.22.3**.
- `v0.30.0` was tagged and published to PyPI (CI stamps the version from
the tag at build time via `version-sync.py`, which is why PyPI got
0.30.0 despite the committed 0.29.0).
- With the manifest at 0.29.0, RP kept computing the next version as
**0.30.0**, saw that tag already exists, and produced **no PR** — so
nothing new could ship, and Docker/npm fell behind.
### Fix
Realign the repo with the last real release (0.30.0) so RP can drive the
next one:
- `.release-please-manifest.json` → `0.30.0`
- `pyproject.toml`, `sdk/typescript/package.json`,
`plugins/openclaw/package.json`, both `plugin.json`, both
`marketplace.json` → `0.30.0` (via `scripts/version-sync.py --version
0.30.0`, which also fixes the 0.22.3 drift).
### What happens after merge
1. Release Please runs on `main`, sees manifest = 0.30.0 + 69 releasable
commits since `v0.30.0`, and opens a clean **`chore: release 0.31.0`**
PR (bumping every version file).
2. Merging that PR tags `v0.31.0` and fires `release: published`, which
publishes **PyPI + npm (SDK + openclaw) + Docker** at 0.31.0 in one shot
— bringing all three registries back in sync.
No behavior/code change — versions only.
## Type of Change
- [x] Bug fix (non-breaking change that fixes an issue)
- [ ] New feature
- [ ] Breaking change
- [ ] Documentation update
- [ ] Performance improvement
- [ ] Code refactoring (no functional changes)
## Changes Made
- Advance the Release Please manifest to the last released version
(0.30.0).
- Sync all 7 version-tracked files to 0.30.0 with the repo's own
`version-sync.py`.
## Testing
- [x] Linting passes (`ruff check .`)
- [x] Manual testing performed (`scripts/verify-versions.py`)
### Test Output
```text
$ python scripts/version-sync.py --version 0.30.0
Version synchronized to 0.30.0
$ python scripts/verify-versions.py
All versions aligned at 0.30.0
Packages: pyproject.toml, plugins/openclaw/package.json, sdk/typescript/package.json,
plugins/headroom-agent-hooks/.claude-plugin/plugin.json,
plugins/headroom-agent-hooks/.github/plugin/plugin.json,
.claude-plugin/marketplace.json, .github/plugin/marketplace.json
```
## Real Behavior Proof
- Environment: local macOS, project `.venv` (Python 3.12.6).
- Exact command / steps: ran `scripts/version-sync.py --version 0.30.0`,
set the RP manifest to 0.30.0, then `scripts/verify-versions.py`.
- Observed result: `verify-versions.py` reports all seven version
locations aligned at 0.30.0; `git diff` shows version-field changes only
(no code). Confirmed PyPI latest is 0.30.0 and a `v0.30.0` tag/release
exists, while the manifest was 0.29.0 — the drift this PR corrects.
- Not tested: the downstream release itself (that runs when the
follow-up `chore: release 0.31.0` PR is merged); npm registry state
could not be read from this environment (network), but the `publish-npm`
job in `release.yml` publishes both npm packages on release.
## Review Readiness
- [x] I have performed a self-review
- [x] This PR is ready for human review
## Checklist
- [x] My code follows the project's style guidelines
- [x] I have performed a self-review of my code
- [x] My changes generate no new warnings
- [x] New and existing unit tests pass locally with my changes
2026-07-09 07:08:06 -07:00
github-actions[bot]
660fa8cfb6
chore: release main ( #1574 )
...
🤖 I have created a release *beep* *boop*
---
<details><summary>0.29.0</summary>
##
[0.29.0](https://github.com/headroomlabs-ai/headroom/compare/v0.28.0...v0.29.0 )
(2026-07-03)
### Features
* **proxy:** add --lossless no-CCR mode with format-native compaction
([#1721 ](https://github.com/headroomlabs-ai/headroom/issues/1721 ))
([c75ebde ](c75ebdee6d ))
* **stats:** surface Codex WS compression counters in /stats summary
([#1680 ](https://github.com/headroomlabs-ai/headroom/issues/1680 ))
([2fe19c3 ](2fe19c39e4 ))
* **transforms:** adaptive Otsu KEEP/DROP threshold (+ land relevance
split on main)
([#1726 ](https://github.com/headroomlabs-ai/headroom/issues/1726 ))
([eea667a ](eea667a720 ))
### Bug Fixes
* **bedrock:** fail fast when session-token auth lacks botocore
([#1553 ](https://github.com/headroomlabs-ai/headroom/issues/1553 ))
([54cfa36 ](54cfa361d3 ))
* **bedrock:** route ARNs via converse, named AWS profiles, and au. re…
([#1456 ](https://github.com/headroomlabs-ai/headroom/issues/1456 ))
([7d87aa2 ](7d87aa2f1c ))
* **ccr:** honor workspace dir for sqlite store
([#1564 ](https://github.com/headroomlabs-ai/headroom/issues/1564 ))
([96e1dfe ](96e1dfe395 ))
* **claude:** surface Remote Control proxy incompatibility
([#1610 ](https://github.com/headroomlabs-ai/headroom/issues/1610 ))
([4bf7f92 ](4bf7f92417 ))
* **cli:** stop advertising unwired compression tuning env vars in
banner
([#1634 ](https://github.com/headroomlabs-ai/headroom/issues/1634 ))
([d5bf98d ](d5bf98df31 ))
* **codex:** avoid duplicate headroom provider config
([#1431 ](https://github.com/headroomlabs-ai/headroom/issues/1431 ))
([ddd4adf ](ddd4adf911 ))
* **compression:** reject lossy unmarked tool output in unit router path
([#1479 ](https://github.com/headroomlabs-ai/headroom/issues/1479 ))
([de24cd5 ](de24cd5fc0 ))
* **cortex-code:** migrate to current Cortex REST API endpoints + add
e2e benchmarks
([#1474 ](https://github.com/headroomlabs-ai/headroom/issues/1474 ))
([f00ace6 ](f00ace6da5 ))
* **dashboard:** align token savings headline denominator
([#1653 ](https://github.com/headroomlabs-ai/headroom/issues/1653 ))
([646e705 ](646e705514 ))
* **dashboard:** derive per-project setup URL from live origin
([#1511 ](https://github.com/headroomlabs-ai/headroom/issues/1511 ))
([e035aef ](e035aefce2 ))
* **detection:** contain unidiff panic on orphaned +++ target line
([#1548 ](https://github.com/headroomlabs-ai/headroom/issues/1548 ))
([e386c09 ](e386c097d6 ))
* **evals:** CJK-aware F1 tokenization + token estimation
([#1527 ](https://github.com/headroomlabs-ai/headroom/issues/1527 ))
([99a8540 ](99a8540e65 ))
* **install:** close parent log fd in start_detached_agent
([#1576 ](https://github.com/headroomlabs-ai/headroom/issues/1576 ))
([816cb85 ](816cb85fa8 ))
* **install:** use Windows-safe PID liveness probe in runtime_status
([#1544 ](https://github.com/headroomlabs-ai/headroom/issues/1544 ))
([#1560 ](https://github.com/headroomlabs-ai/headroom/issues/1560 ))
([6b227b9 ](6b227b9c90 ))
* **learn:** aggregate verbosity baselines across projects instead of
overwriting
([#1288 ](https://github.com/headroomlabs-ai/headroom/issues/1288 ))
([27a5468 ](27a5468349 ))
* **mcp:** show lifetime totals and label rolling session scope in
headroom_stats
([#1428 ](https://github.com/headroomlabs-ai/headroom/issues/1428 ))
([1c0e152 ](1c0e15243e ))
* **memory:** cap local embedder CPU thread oversubscription
([#198 ](https://github.com/headroomlabs-ai/headroom/issues/198 ))
([#1559 ](https://github.com/headroomlabs-ai/headroom/issues/1559 ))
([b84afbf ](b84afbfb83 ))
* **memory:** singleflight LocalBackend init to stop cold-start races
([#1691 ](https://github.com/headroomlabs-ai/headroom/issues/1691 ))
([bec47a1 ](bec47a1898 ))
* **openclaw:** detect uv-installed headroom binary in ~/.local/bin
([#1459 ](https://github.com/headroomlabs-ai/headroom/issues/1459 ))
([adaeb88 ](adaeb88a4d ))
* **opencode:** preserve custom OpenAI gateway paths
([#1596 ](https://github.com/headroomlabs-ai/headroom/issues/1596 ))
([c19347c ](c19347c310 ))
* **opencode:** route native providers + load transport plugin, fix
Serena context
([#1573 ](https://github.com/headroomlabs-ai/headroom/issues/1573 ))
([ad0034f ](ad0034f981 ))
* preserve anthropic passthrough tool order
([#1427 ](https://github.com/headroomlabs-ai/headroom/issues/1427 ))
([a932247 ](a9322477e3 ))
* **proxy/auth:** match real Anthropic OAuth token prefix (sk-ant-oat)
([#1672 ](https://github.com/headroomlabs-ai/headroom/issues/1672 ))
([8cddf9b ](8cddf9b58e ))
* **proxy:** expose persistent savings metrics
([#1647 ](https://github.com/headroomlabs-ai/headroom/issues/1647 ))
([5fe4e7b ](5fe4e7b195 ))
* **proxy:** fail open when kompress saturation would exhaust
pre-upstream budget
([#1430 ](https://github.com/headroomlabs-ai/headroom/issues/1430 ))
([15ac650 ](15ac650d40 ))
* **proxy:** handle streaming CCR retrieval
([#1451 ](https://github.com/headroomlabs-ai/headroom/issues/1451 ))
([d337e3b ](d337e3b828 ))
* **proxy:** include system/tools/sampling in cache key
([#1473 ](https://github.com/headroomlabs-ai/headroom/issues/1473 ))
([312129a ](312129a8e7 ))
* **proxy:** preserve Responses passthrough bytes
([#1598 ](https://github.com/headroomlabs-ai/headroom/issues/1598 ))
([2a34a82 ](2a34a822f2 ))
* **proxy:** strip Codex lite header on the HTTP /responses path
([#1663 ](https://github.com/headroomlabs-ai/headroom/issues/1663 ))
([9fbd47b ](9fbd47ba6b ))
* **proxy:** wire --compression-max-workers /
HEADROOM_COMPRESSION_MAX_WORKERS
([#1632 ](https://github.com/headroomlabs-ai/headroom/issues/1632 ))
([814ffa3 ](814ffa36a4 ))
* **savings:** count cache-read tokens in input cost estimate
([#1429 ](https://github.com/headroomlabs-ai/headroom/issues/1429 ))
([72ade37 ](72ade37112 ))
* skip Magika backend on x86 CPUs without AVX2
([#1162 ](https://github.com/headroomlabs-ai/headroom/issues/1162 ))
([64783d8 ](64783d8824 ))
* **transforms/content-router:** route grep/log output away from HTML
extractor
([#1719 ](https://github.com/headroomlabs-ai/headroom/issues/1719 ))
([0d18ef2 ](0d18ef26f4 ))
* **transforms:** bound native content detection with a Windows watchdog
([#575 ](https://github.com/headroomlabs-ai/headroom/issues/575 ))
([#1563 ](https://github.com/headroomlabs-ai/headroom/issues/1563 ))
([95abca3 ](95abca3abd ))
* Vertex AI support for Claude Code with ANTHROPIC_VERTEX_BASE_URL
([#1393 ](https://github.com/headroomlabs-ai/headroom/issues/1393 ))
([cff7247 ](cff7247efd ))
* **wrap:** detach the shared proxy on Windows so it survives an
ungraceful agent close
([#1464 ](https://github.com/headroomlabs-ai/headroom/issues/1464 ))
([6cba441 ](6cba4419d0 ))
* **wrap:** preserve custom Vertex base URL
([#1477 ](https://github.com/headroomlabs-ai/headroom/issues/1477 ))
([75427bb ](75427bbd4a ))
* **wrap:** remove rtk instructions from Codex AGENTS.md on unwrap
([#1604 ](https://github.com/headroomlabs-ai/headroom/issues/1604 ))
([c9d717c ](c9d717c13c ))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-02 22:54:04 -07:00
github-actions[bot]
aea3c35177
chore: release main ( #1441 )
...
🤖 I have created a release *beep* *boop*
---
<details><summary>0.28.0</summary>
##
[0.28.0](https://github.com/headroomlabs-ai/headroom/compare/v0.27.0...v0.28.0 )
(2026-06-29)
### Features
* add --disable-kompress-fallback to restore legacy PASSTHROUGH fallback
([#1185 ](https://github.com/headroomlabs-ai/headroom/issues/1185 ))
([f309244 ](f309244a77 ))
* add first-class OpenCode support (wrap, learn, mcp install)
([#559 ](https://github.com/headroomlabs-ai/headroom/issues/559 ))
([91cd210 ](91cd2102d7 ))
* add HEADROOM_KEEPALIVE_EXPIRY to keep upstream connections warm
([#1124 ](https://github.com/headroomlabs-ai/headroom/issues/1124 ))
([85786b3 ](85786b33a3 ))
* **azure-foundry:** derive upstream URL from ANTHROPIC_FOUNDRY_RESOURCE
([#1138 ](https://github.com/headroomlabs-ai/headroom/issues/1138 ))
([e5031b0 ](e5031b0121 ))
* **cache:** attribute prompt-cache misses to TTL lapse vs prefix change
([#1313 ](https://github.com/headroomlabs-ai/headroom/issues/1313 ))
([#1343 ](https://github.com/headroomlabs-ai/headroom/issues/1343 ))
([4658721 ](4658721ea0 ))
* **code:** add Perl support to code-aware compressor
([#1125 ](https://github.com/headroomlabs-ai/headroom/issues/1125 ))
([f39858c ](f39858c233 ))
* headroom wrap opencode / unwrap opencode CLI
([#1105 ](https://github.com/headroomlabs-ai/headroom/issues/1105 ))
([b4571cc ](b4571cc346 ))
* **learn:** weight loops in Headroom Learn + RTK-loop eval
([#1160 ](https://github.com/headroomlabs-ai/headroom/issues/1160 ))
([14e8dc4 ](14e8dc4c84 ))
* **learn:** write per-project learnings to CLAUDE.local.md by default
([#1115 ](https://github.com/headroomlabs-ai/headroom/issues/1115 ))
([ced75e4 ](ced75e4718 ))
* **proxy:** add request timeout config
([#738 ](https://github.com/headroomlabs-ai/headroom/issues/738 ))
([c0745d4 ](c0745d4161 ))
* **proxy:** pilot hardening — inbound auth, security headers, audit
log, air-gap switch
([#1537 ](https://github.com/headroomlabs-ai/headroom/issues/1537 ))
([546ab55 ](546ab553dc ))
* **proxy:** support glob patterns in exclude_tools
([#870 ](https://github.com/headroomlabs-ai/headroom/issues/870 ))
([#1259 ](https://github.com/headroomlabs-ai/headroom/issues/1259 ))
([a2159c0 ](a2159c0b66 ))
* **read-maturation:** activity-based hold-back Read maturation
(Mechanism B)
([#1068 ](https://github.com/headroomlabs-ai/headroom/issues/1068 ))
([723b80c ](723b80c091 ))
* **savings:** durable savings ledger + headroom savings command
([#1127 ](https://github.com/headroomlabs-ai/headroom/issues/1127 ))
([978ffa0 ](978ffa0a6a ))
* **wrap:** add --1m to preserve the 1M context window on wrap claude
([#1158 ](https://github.com/headroomlabs-ai/headroom/issues/1158 ))
([#1351 ](https://github.com/headroomlabs-ai/headroom/issues/1351 ))
([b50d9c1 ](b50d9c17ce ))
* **wrap:** make tokensave the primary coding-task compressor, Serena
the backup
([#1230 ](https://github.com/headroomlabs-ai/headroom/issues/1230 ))
([dca9853 ](dca9853ed9 ))
### Bug Fixes
* **agent-evals:** Phase 0 — coding-agent accuracy A/B framework
([#1037 ](https://github.com/headroomlabs-ai/headroom/issues/1037 ))
([84f9871 ](84f9871e30 ))
* **agno:** tolerate streaming tool-call SDK objects in parser
([#1312 ](https://github.com/headroomlabs-ai/headroom/issues/1312 ))
([#1336 ](https://github.com/headroomlabs-ai/headroom/issues/1336 ))
([5986c22 ](5986c2260f ))
* **bedrock:** add boto3 1.41 + CRT for aws login credentials
([#1486 ](https://github.com/headroomlabs-ai/headroom/issues/1486 ))
([4db3bc9 ](4db3bc91d9 ))
* bump codebase-memory-mcp to v0.8.1
([#1284 ](https://github.com/headroomlabs-ai/headroom/issues/1284 ))
([530318b ](530318b425 ))
* **ccr:** make headroom_retrieve a hash-only full-content lookup
([#1532 ](https://github.com/headroomlabs-ai/headroom/issues/1532 ))
([c2fc4d3 ](c2fc4d3753 ))
* **ccr:** propagate --no-ccr-marker flag to all compressors
([#1022 ](https://github.com/headroomlabs-ai/headroom/issues/1022 ))
([#1197 ](https://github.com/headroomlabs-ai/headroom/issues/1197 ))
([0c9b42a ](0c9b42a919 ))
* **ccr:** skip Anthropic marker emission when tool injection is
deferred
([#1273 ](https://github.com/headroomlabs-ai/headroom/issues/1273 ))
([2cae13d ](2cae13dd79 ))
* **ci:** extend gitleaks allowlist to cover test fixtures + verified
examples
([#1539 ](https://github.com/headroomlabs-ai/headroom/issues/1539 ))
([d2565a6 ](d2565a6983 ))
* **ci:** guarantee model present in test shards to end cache-miss
flakiness
([#1399 ](https://github.com/headroomlabs-ai/headroom/issues/1399 ))
([2e29c72 ](2e29c7223f ))
* **ci:** normalize Windows CRLF line endings in PR governance script
([#1012 ](https://github.com/headroomlabs-ai/headroom/issues/1012 ))
([5194388 ](5194388b66 ))
* **cli:** add explicit UTF-8 encoding to file I/O in wrap commands
([#1126 ](https://github.com/headroomlabs-ai/headroom/issues/1126 ))
([#1164 ](https://github.com/headroomlabs-ai/headroom/issues/1164 ))
([a0cb798 ](a0cb7982e3 ))
* **cli:** fall back gracefully when embedding-server sidecar is absent
([#1206 ](https://github.com/headroomlabs-ai/headroom/issues/1206 ))
([38f1404 ](38f1404432 ))
* **cli:** harden all CLI surfaces + fix docs accuracy
([#1491 ](https://github.com/headroomlabs-ai/headroom/issues/1491 ))
([bd76235 ](bd76235f5c ))
* **cli:** wire --http2/--no-http2 (HEADROOM_HTTP2) into proxy command
([#1373 ](https://github.com/headroomlabs-ai/headroom/issues/1373 ))
([e06b616 ](e06b61671f ))
* **cli:** wire --rpm/--tpm and HEADROOM_RPM/HEADROOM_TPM to the Click
proxy command
([#1375 ](https://github.com/headroomlabs-ai/headroom/issues/1375 ))
([8aab8f2 ](8aab8f22cb ))
* **code:** slice tree-sitter byte offsets as UTF-8
([#1332 ](https://github.com/headroomlabs-ai/headroom/issues/1332 ))
([8238402 ](82384022bd ))
* **code:** validate Python compressed syntax
([#1302 ](https://github.com/headroomlabs-ai/headroom/issues/1302 ))
([cbd361d ](cbd361de2a ))
* **code:** verify a real parse in tree-sitter availability check
([#1231 ](https://github.com/headroomlabs-ai/headroom/issues/1231 ))
([#1299 ](https://github.com/headroomlabs-ai/headroom/issues/1299 ))
([5e0bb69 ](5e0bb69725 ))
* **codex:** retag threads on init so Codex Desktop history stays
visible ([#961 ](https://github.com/headroomlabs-ai/headroom/issues/961 ))
([#1349 ](https://github.com/headroomlabs-ai/headroom/issues/1349 ))
([e6bbc40 ](e6bbc40b11 ))
* **codex:** stop pinning Codex memory MCP to one project db
([#1269 ](https://github.com/headroomlabs-ai/headroom/issues/1269 ))
([ad7993b ](ad7993bf15 ))
* **dashboard:** include RTK stats in the historical tab
([#1324 ](https://github.com/headroomlabs-ai/headroom/issues/1324 ))
([35939c3 ](35939c3536 ))
* **deps:** remediate dependency CVEs and publish SBOM
([#1509 ](https://github.com/headroomlabs-ai/headroom/issues/1509 ))
([5771a80 ](5771a8020e ))
* **docker:** persist session history across container revisions
([#1118 ](https://github.com/headroomlabs-ai/headroom/issues/1118 ))
([5912d65 ](5912d65674 ))
* **gemini:** offload compression to the executor
([#1382 ](https://github.com/headroomlabs-ai/headroom/issues/1382 ))
([615848e ](615848eba4 ))
* **gemini:** resolve Google model capabilities through ModelRegistry
([#1276 ](https://github.com/headroomlabs-ai/headroom/issues/1276 ))
([17ecad9 ](17ecad9d89 ))
* **install:** guard install_agent_ensure against duplicate runtime
spawns
([#1301 ](https://github.com/headroomlabs-ai/headroom/issues/1301 ))
([8da0b4e ](8da0b4e565 ))
* **install:** repair macOS launchd restart/start lifecycle
([#1290 ](https://github.com/headroomlabs-ai/headroom/issues/1290 ))
([da1a397 ](da1a3973ed ))
* **install:** stop duplicating ENTRYPOINT in persistent-docker runtime
command ([#833 ](https://github.com/headroomlabs-ai/headroom/issues/833 ))
([#1348 ](https://github.com/headroomlabs-ai/headroom/issues/1348 ))
([feedead ](feedead077 ))
* **io:** use UTF-8 with locale fallback and preserve line endings on
config/text I/O
([#1498 ](https://github.com/headroomlabs-ai/headroom/issues/1498 ))
([1baa04e ](1baa04ef65 ))
* **kompress:** hard override keeps must-keep tokens regardless of model
score ([#1400 ](https://github.com/headroomlabs-ai/headroom/issues/1400 ))
([42612c8 ](42612c86df ))
* **langchain:** disable streaming on wrapped model during ainvoke()
([#1287 ](https://github.com/headroomlabs-ai/headroom/issues/1287 ))
([3590046 ](359004646b ))
* **mcp:** register managed installs with a resolvable headroom command
([#1386 ](https://github.com/headroomlabs-ai/headroom/issues/1386 ))
([22def93 ](22def93177 ))
* **mcp:** report correct savings_percent in headroom_compress
([#1106 ](https://github.com/headroomlabs-ai/headroom/issues/1106 ))
([f216e43 ](f216e43055 ))
* **opencode:** write local MCP config
([#1381 ](https://github.com/headroomlabs-ai/headroom/issues/1381 ))
([6c83790 ](6c83790680 ))
* **packaging:** move hnswlib to optional [vector] extra so [all] needs
no C++ toolchain
([#1499 ](https://github.com/headroomlabs-ai/headroom/issues/1499 ))
([80fa086 ](80fa086660 ))
* patch rtk hook script to use absolute path after register_claude_hooks
([#571 ](https://github.com/headroomlabs-ai/headroom/issues/571 ))
([b618d2d ](b618d2d11a ))
* **perf:** surface RTK/CLI context-tool savings in perf and the session
card ([#1433 ](https://github.com/headroomlabs-ai/headroom/issues/1433 ))
([9362747 ](93627471b7 ))
* **proxy:** add --protect-tool-results to prevent lossy compression of
exact-output Bash results
([#1374 ](https://github.com/headroomlabs-ai/headroom/issues/1374 ))
([51d4bcf ](51d4bcfc11 ))
* **proxy:** add an Anthropic buffered read-timeout override
([#1331 ](https://github.com/headroomlabs-ai/headroom/issues/1331 ))
([3be2526 ](3be2526b76 ))
* **proxy:** add versionless Vertex AI routes for Claude Code
compatibility
([#1321 ](https://github.com/headroomlabs-ai/headroom/issues/1321 ))
([bb3e040 ](bb3e040a46 ))
* **proxy:** bind before eager preload so a hung compressor load can't
block startup
([#1500 ](https://github.com/headroomlabs-ai/headroom/issues/1500 ))
([d5ac07f ](d5ac07fc45 ))
* **proxy:** build SSL contexts for custom CA bundles
([#1134 ](https://github.com/headroomlabs-ai/headroom/issues/1134 ))
([561ba17 ](561ba17ec2 ))
* **proxy:** forward request-id headers on the streaming path
([#1100 ](https://github.com/headroomlabs-ai/headroom/issues/1100 ))
([#1258 ](https://github.com/headroomlabs-ai/headroom/issues/1258 ))
([3d59df7 ](3d59df7be8 ))
* **proxy:** gate CCR retrieve/compress endpoints to loopback
([#1338 ](https://github.com/headroomlabs-ai/headroom/issues/1338 ))
([acafb2d ](acafb2d0f6 ))
* **proxy:** honor force_kompress routing profile
([#996 ](https://github.com/headroomlabs-ai/headroom/issues/996 ))
([b4682d6 ](b4682d6f91 ))
* **proxy:** keep large compression results on the critical path
([#296 ](https://github.com/headroomlabs-ai/headroom/issues/296 ))
([#1352 ](https://github.com/headroomlabs-ai/headroom/issues/1352 ))
([90734b6 ](90734b691a ))
* **proxy:** offload /v1/compress to the compression executor to stop
blocking the loop
([#1501 ](https://github.com/headroomlabs-ai/headroom/issues/1501 ))
([27e010e ](27e010e38f ))
* **proxy:** preserve Responses memory continuations with store=false
([#1103 ](https://github.com/headroomlabs-ai/headroom/issues/1103 ))
([cdfeeac ](cdfeeacc63 ))
* **proxy:** queue mid-turn user messages on non-Bedrock streaming path
([#1377 ](https://github.com/headroomlabs-ai/headroom/issues/1377 ))
([b09f027 ](b09f027062 ))
* **proxy:** register interceptor in explicit transforms list when
HEADROOM_INTERCEPT_ENABLED
([#1376 ](https://github.com/headroomlabs-ai/headroom/issues/1376 ))
([55c700c ](55c700c686 ))
* **proxy:** report real input tokens on streaming message_start
([#1132 ](https://github.com/headroomlabs-ai/headroom/issues/1132 ))
([#1305 ](https://github.com/headroomlabs-ai/headroom/issues/1305 ))
([70cc96a ](70cc96a386 ))
* **proxy:** retry upstream 429 with Retry-After on both forwarders
([#1329 ](https://github.com/headroomlabs-ai/headroom/issues/1329 ))
([90bee89 ](90bee89243 ))
* **proxy:** retry upstream 529 overloaded like 429 on both forwarders
([#1495 ](https://github.com/headroomlabs-ai/headroom/issues/1495 ))
([547b15d ](547b15dab2 ))
* **proxy:** stop re-compressing headroom_retrieve output and emitting
unredeemable markers
([#1323 ](https://github.com/headroomlabs-ai/headroom/issues/1323 ))
([43494ff ](43494ff526 ))
* **proxy:** strip Codex lite header from OpenAI WebSockets
([#1543 ](https://github.com/headroomlabs-ai/headroom/issues/1543 ))
([5d3803a ](5d3803a21c ))
* **read-lifecycle:** persist STALE Read originals in the CCR store
([#1488 ](https://github.com/headroomlabs-ai/headroom/issues/1488 ))
([9157173 ](9157173018 ))
* recover persistent proxy feature checks and reject non-Copilot
exchange URL
([#1465 ](https://github.com/headroomlabs-ai/headroom/issues/1465 ))
([16c638b ](16c638bc21 ))
* remove agents.md
([#1540 ](https://github.com/headroomlabs-ai/headroom/issues/1540 ))
([a7d3360 ](a7d3360a05 ))
* respect COPILOT_PROVIDER_TYPE env var when provider_type is auto
([#549 ](https://github.com/headroomlabs-ai/headroom/issues/549 ))
([24cf256 ](24cf256e50 ))
* restore token-mode compression on frozen prefixes
([#1489 ](https://github.com/headroomlabs-ai/headroom/issues/1489 ))
([8e0dadf ](8e0dadfe02 ))
* **router:** degrade to pure-Python detection on native panic
([#1123 ](https://github.com/headroomlabs-ai/headroom/issues/1123 ))
([#1260 ](https://github.com/headroomlabs-ai/headroom/issues/1260 ))
([a00fb67 ](a00fb6761e ))
* **rtk:** stop hook registration timing out on a forked daemon
([#1314 ](https://github.com/headroomlabs-ai/headroom/issues/1314 ))
([9758817 ](9758817979 ))
* **smart-crusher:** honor enable_ccr_marker on the opaque-blob path
([#1130 ](https://github.com/headroomlabs-ai/headroom/issues/1130 ))
([27d6f8e ](27d6f8e2a7 ))
* **subscription:** only reset 5h contribution on real rollover, not API
jitter
([#1255 ](https://github.com/headroomlabs-ai/headroom/issues/1255 ))
([8d6c175 ](8d6c175d60 ))
* **subscription:** run transcript token scan off the event loop
([#1263 ](https://github.com/headroomlabs-ai/headroom/issues/1263 ))
([f03021f ](f03021f1b6 ))
* surface output reduction without a restart, and explain $0.00 savings
on Python 3.14
([#1296 ](https://github.com/headroomlabs-ai/headroom/issues/1296 ))
([c30ec4c ](c30ec4cda8 ))
* **tests:** reset whole headroom logger subtree so caplog stays
deterministic
([#1117 ](https://github.com/headroomlabs-ai/headroom/issues/1117 ))
([fda4670 ](fda4670ef8 ))
* **tls:** add HEADROOM_TLS_STRICT=0 toggle for corporate SSL inspection
([#1308 ](https://github.com/headroomlabs-ai/headroom/issues/1308 ))
([#1341 ](https://github.com/headroomlabs-ai/headroom/issues/1341 ))
([52068dd ](52068dd650 ))
* **tokenizers:** price CJK/Kana/Hangul at ~1 token per char in
EstimatingTokenCounter
([#1093 ](https://github.com/headroomlabs-ai/headroom/issues/1093 ))
([a35fe86 ](a35fe86e87 ))
* **transforms:** gate tool string output from lossy compression
([#1307 ](https://github.com/headroomlabs-ai/headroom/issues/1307 ))
([#1387 ](https://github.com/headroomlabs-ai/headroom/issues/1387 ))
([c6c921a ](c6c921a7c1 ))
* **websocket:** harden responses websocket origin handling
([#1481 ](https://github.com/headroomlabs-ai/headroom/issues/1481 ))
([c632023 ](c632023cc1 ))
* **windows:** pin UTF-8 encoding on text-mode subprocess calls
([#1311 ](https://github.com/headroomlabs-ai/headroom/issues/1311 ))
([d633e81 ](d633e8172c ))
* **wrap:** add Copilot unwrap command
([#1251 ](https://github.com/headroomlabs-ai/headroom/issues/1251 ))
([b4fde0c ](b4fde0c3a4 ))
* **wrap:** isolate proxy stdio from proxy.log on Windows
([#1191 ](https://github.com/headroomlabs-ai/headroom/issues/1191 ))
([959ab0d ](959ab0de47 ))
* **wrap:** keep agent savings opt-in
([#1294 ](https://github.com/headroomlabs-ai/headroom/issues/1294 ))
([b829ceb ](b829ceba84 ))
* **wrap:** show the dashboard URL when the proxy is already running
([#1313 ](https://github.com/headroomlabs-ai/headroom/issues/1313 ))
([b0146c4 ](b0146c4ccd ))
### Performance Improvements
* **compression:** take large cold-start contexts off the synchronous
kompress path
([#1171 ](https://github.com/headroomlabs-ai/headroom/issues/1171 ))
([#1298 ](https://github.com/headroomlabs-ai/headroom/issues/1298 ))
([6c68ff4 ](6c68ff4e9f ))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-29 12:53:17 -07:00
github-actions[bot]
95b2333ee5
chore: release main ( #1274 )
...
🤖 I have created a release *beep* *boop*
---
<details><summary>0.27.0</summary>
##
[0.27.0](https://github.com/chopratejas/headroom/compare/v0.26.0...v0.27.0 )
(2026-06-22)
### Features
* **cli:** add headroom doctor setup diagnostics
([#926 ](https://github.com/chopratejas/headroom/issues/926 ))
([e45cf4e ](e45cf4e061 ))
* **cli:** add headroom update command and release banner
([#1088 ](https://github.com/chopratejas/headroom/issues/1088 ))
([26be2c3 ](26be2c39cb ))
* compression extraction — Rust knob exposure, CCR hardening, traffic
audits ([#818 ](https://github.com/chopratejas/headroom/issues/818 ))
([b7be381 ](b7be3814f1 ))
* measure and surface token throughput (tokens/sec) through the proxy
([#983 ](https://github.com/chopratejas/headroom/issues/983 ))
([0d89c67 ](0d89c674cd ))
* output-token reduction — verbosity shaper, per-user learning,
counterfactual savings
([#965 ](https://github.com/chopratejas/headroom/issues/965 ))
([a99dc61 ](a99dc61424 ))
* **policy:** decay P_alive from idle time near cache TTL
([#856 ](https://github.com/chopratejas/headroom/issues/856 ) P3b)
([#1028 ](https://github.com/chopratejas/headroom/issues/1028 ))
([fe4f9ee ](fe4f9ee478 ))
* **providers:** add Cortex Code (Snowflake CoCo) as a supported agent
([#1190 ](https://github.com/chopratejas/headroom/issues/1190 ))
([d9d0bf4 ](d9d0bf4b79 ))
* **proxy:** cc-switch reconciler — keep Headroom in the request path
alongside cc-switch
([#1030 ](https://github.com/chopratejas/headroom/issues/1030 ))
([e8fc8a0 ](e8fc8a0d18 ))
* **proxy:** hot-reload live env knobs so a reused proxy picks them up
without a restart
([#1090 ](https://github.com/chopratejas/headroom/issues/1090 ))
([6904d47 ](6904d47a01 ))
* **proxy:** make COMPRESSION_TIMEOUT_SECONDS configurable via env
([#946 ](https://github.com/chopratejas/headroom/issues/946 ))
([#991 ](https://github.com/chopratejas/headroom/issues/991 ))
([addebdb ](addebdb29c ))
* **transforms:** tabular + spreadsheet (.xlsx/.xls) compression
([#1128 ](https://github.com/chopratejas/headroom/issues/1128 ))
([d789a7c ](d789a7c528 ))
* **vertex:** turnkey Claude Code + Vertex compression (+ fixes from the
Vertex review)
([#1113 ](https://github.com/chopratejas/headroom/issues/1113 ))
([0e05915 ](0e0591506c ))
### Bug Fixes
* **ccr:** accept 12-char SmartCrusher hashes in tool injection
([#1095 ](https://github.com/chopratejas/headroom/issues/1095 ))
([#1141 ](https://github.com/chopratejas/headroom/issues/1141 ))
([9f7f3ad ](9f7f3adfea ))
* **ccr:** return stored content when headroom_retrieve query matches
nothing ([#1213 ](https://github.com/chopratejas/headroom/issues/1213 ))
([#1236 ](https://github.com/chopratejas/headroom/issues/1236 ))
([08fb845 ](08fb845fe3 ))
* **content-router:** honor target_ratio in compression cache + add
proxy --target-ratio flag
([#1108 ](https://github.com/chopratejas/headroom/issues/1108 ))
([8894ee0 ](8894ee0c18 ))
* **dashboard:** light-mode backgrounds + aligned savings tables
([#1064 ](https://github.com/chopratejas/headroom/issues/1064 ))
([5eae32b ](5eae32ba47 ))
* **deps:** make litellm optional on Python 3.14
([#956 ](https://github.com/chopratejas/headroom/issues/956 ))
([#993 ](https://github.com/chopratejas/headroom/issues/993 ))
([b2f04e4 ](b2f04e4ef7 ))
* **e2e:** align Codex wrap e2e with global-only RTK guidance
([#1240 ](https://github.com/chopratejas/headroom/issues/1240 ))
([#1254 ](https://github.com/chopratejas/headroom/issues/1254 ))
([bc12ace ](bc12acef59 ))
* **init:** set ENABLE_TOOL_SEARCH=true so Claude Code keeps deferring
tools ([#746 ](https://github.com/chopratejas/headroom/issues/746 ))
([#995 ](https://github.com/chopratejas/headroom/issues/995 ))
([500ec2b ](500ec2b7fa ))
* **kompress:** never block the request path on the cold-cache model
download ([#1161 ](https://github.com/chopratejas/headroom/issues/1161 ))
([3fc2a78 ](3fc2a78a5e ))
* **memory:** use ONNX embedder for `wrap --memory` sync
([#1092 ](https://github.com/chopratejas/headroom/issues/1092 ))
([#1262 ](https://github.com/chopratejas/headroom/issues/1262 ))
([4f9feda ](4f9fedaa7a ))
* **openclaw:** wrap plugin export as {register} object for OpenClaw
2026.x compatibility
([#1218 ](https://github.com/chopratejas/headroom/issues/1218 ))
([2e6c442 ](2e6c442dc8 ))
* **providers:** update DeepSeek V3 context limit from 128K to 1M
([#1038 ](https://github.com/chopratejas/headroom/issues/1038 ))
([#1137 ](https://github.com/chopratejas/headroom/issues/1137 ))
([bcabc5c ](bcabc5cb11 ))
* **proxy:** allow disabling periodic TOIN stats logging
([#1265 ](https://github.com/chopratejas/headroom/issues/1265 ))
([b5f63d8 ](b5f63d8fa9 ))
* **proxy:** honor HEADROOM_EXCLUDE_TOOLS for Codex /v1/responses tool
outputs ([#940 ](https://github.com/chopratejas/headroom/issues/940 ))
([#1053 ](https://github.com/chopratejas/headroom/issues/1053 ))
([f03e77b ](f03e77bec0 ))
* **proxy:** preserve byte-faithful Anthropic tool forwarding
([#1222 ](https://github.com/chopratejas/headroom/issues/1222 ))
([1f18d59 ](1f18d59809 ))
* **proxy:** route Codex OAuth image requests
([#1215 ](https://github.com/chopratejas/headroom/issues/1215 ))
([381d771 ](381d771e46 ))
* **proxy:** scope CORS to loopback + gate operator/content endpoints
([#1226 ](https://github.com/chopratejas/headroom/issues/1226 ))
([bd55a42 ](bd55a426bc ))
* **proxy:** stamp X-Client: codex on Responses endpoint for
unidentified callers
([#1036 ](https://github.com/chopratejas/headroom/issues/1036 ))
([b0cd032 ](b0cd0329c7 ))
* **proxy:** treat NODE_EXTRA_CA_CERTS as additive, not replacement
([#998 ](https://github.com/chopratejas/headroom/issues/998 ))
([#1031 ](https://github.com/chopratejas/headroom/issues/1031 ))
([c987283 ](c98728363a ))
* **telemetry:** switch anonymous telemetry to opt-in (off by default)
([#1223 ](https://github.com/chopratejas/headroom/issues/1223 ))
([b998697 ](b99869778b ))
* **tokenizers:** bound tiktoken vocab load so a stalled download cannot
hang requests
([#956 ](https://github.com/chopratejas/headroom/issues/956 ))
([#994 ](https://github.com/chopratejas/headroom/issues/994 ))
([7e86baf ](7e86bafb90 ))
* **unwrap:** remove ANTHROPIC_BASE_URL + ENABLE_TOOL_SEARCH and init
hooks on unwrap
([#992 ](https://github.com/chopratejas/headroom/issues/992 ))
([5b84691 ](5b84691770 ))
* **wrap:** keep Codex RTK guidance global
([#1240 ](https://github.com/chopratejas/headroom/issues/1240 ))
([7c26a54 ](7c26a54d53 ))
* **wrap:** percent-encode non-ASCII cwd names in X-Headroom-Project
header ([#1071 ](https://github.com/chopratejas/headroom/issues/1071 ))
([9f712cc ](9f712ccbd7 ))
* **wrap:** write env.ANTHROPIC_BASE_URL to settings.json so
daemon-spawned conversations inherit proxy
([#951 ](https://github.com/chopratejas/headroom/issues/951 ))
([#1078 ](https://github.com/chopratejas/headroom/issues/1078 ))
([a554c3a ](a554c3a0e6 ))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-21 22:28:55 -07:00
github-actions[bot]
b81a4a7a16
chore: release main ( #931 )
...
🤖 I have created a release *beep* *boop*
---
<details><summary>0.26.0</summary>
##
[0.26.0](https://github.com/chopratejas/headroom/compare/v0.25.0...v0.26.0 )
(2026-06-16)
### Features
* add Copilot BYOK provider wrapper utilities and CLI support
([#1041 ](https://github.com/chopratejas/headroom/issues/1041 ))
([e67ee2a ](e67ee2af65 ))
* add dashboard agent usage stats
([#814 ](https://github.com/chopratejas/headroom/issues/814 ))
([6d3f39f ](6d3f39f213 ))
* Add support for Mistral Vibe CLI
([#935 ](https://github.com/chopratejas/headroom/issues/935 ))
([0932b8b ](0932b8bef4 ))
* attribute reread waste to over-compression via marker check
([#901 ](https://github.com/chopratejas/headroom/issues/901 ))
([f928576 ](f9285766dd ))
* **bedrock:** cross-region + Converse compression; bundle proxy binary
in images ([#999 ](https://github.com/chopratejas/headroom/issues/999 ))
([0dc2e1c ](0dc2e1cb3f ))
* **dashboard:** surface compression-vs-cache net impact in Prefix Cache
panel ([#913 ](https://github.com/chopratejas/headroom/issues/913 ))
([2a4d300 ](2a4d300841 ))
* **evals:** adversarial-input robustness grid for compressors
([#918 ](https://github.com/chopratejas/headroom/issues/918 ))
([5939004 ](5939004185 ))
* **parser:** detect re-issued identical tool calls as reread waste
([#909 ](https://github.com/chopratejas/headroom/issues/909 ))
([7d4ae86 ](7d4ae86ec0 ))
* **policy:** batch deep edits through one cache-bust
([#856 ](https://github.com/chopratejas/headroom/issues/856 ) P3a)
([#1015 ](https://github.com/chopratejas/headroom/issues/1015 ))
([c2e52fe ](c2e52fe743 ))
* **policy:** consume net-cost mutation gate in ContentRouter
([#856 ](https://github.com/chopratejas/headroom/issues/856 ) P2)
([#905 ](https://github.com/chopratejas/headroom/issues/905 ))
([553ade4 ](553ade4ec6 ))
* **proxy:** compress AWS Bedrock InvokeModel requests via configurable
upstream ([#720 ](https://github.com/chopratejas/headroom/issues/720 ))
([7edb27a ](7edb27ab24 ))
### Bug Fixes
* **anthropic:** strip styled Claude model ids
([#651 ](https://github.com/chopratejas/headroom/issues/651 ))
([0c5c89d ](0c5c89d05c ))
* **anyllm:** forward openai api_base/api_key to the any-llm backend
([#942 ](https://github.com/chopratejas/headroom/issues/942 ))
([#954 ](https://github.com/chopratejas/headroom/issues/954 ))
([a7ee8a6 ](a7ee8a60a7 ))
* **cache:** guard None exemplar embeddings in dynamic detector
([#950 ](https://github.com/chopratejas/headroom/issues/950 ))
([1ec9320 ](1ec9320888 ))
* **cache:** name the missing piece in semantic detector guard
([#1018 ](https://github.com/chopratejas/headroom/issues/1018 ))
([3b0bcee ](3b0bceecf4 ))
* **ci:** check out repo in PR Governance label job
([#1021 ](https://github.com/chopratejas/headroom/issues/1021 ))
([4558bc2 ](4558bc2465 ))
* **ci:** make PR governance advisory
([#1047 ](https://github.com/chopratejas/headroom/issues/1047 ))
([74dff94 ](74dff94fb8 ))
* **codex:** compute waste signals on the OpenAI Responses path
([#898 ](https://github.com/chopratejas/headroom/issues/898 ))
([b9e2761 ](b9e27614c6 ))
* **codex:** poll /wham/usage for subscription limits (handshake no
longer sends x-codex-* headers)
([#924 ](https://github.com/chopratejas/headroom/issues/924 ))
([8c00f71 ](8c00f7103c ))
* **codex:** PR health label check state
([#986 ](https://github.com/chopratejas/headroom/issues/986 ))
([99c874d ](99c874d423 ))
* **codex:** retag thread providers so history menu stays whole across
the proxy boundary
([#1034 ](https://github.com/chopratejas/headroom/issues/1034 ))
([74ae781 ](74ae781644 ))
* **codex:** write canonical hooks feature flag and migrate deprecated
codex_hooks ([#743 ](https://github.com/chopratejas/headroom/issues/743 ))
([dff6a19 ](dff6a19946 ))
* **compression:** convert tree-sitter byte offsets to char offsets
([#892 ](https://github.com/chopratejas/headroom/issues/892 ))
([b1f700f ](b1f700fc27 ))
* **compression:** correct JSON array item counting and entropy gate
([#887 ](https://github.com/chopratejas/headroom/issues/887 ))
([d6f0f0f ](d6f0f0f642 ))
* **compression:** keep container bodies compressible in code handler
([#890 ](https://github.com/chopratejas/headroom/issues/890 ))
([16ed73b ](16ed73bca6 ))
* **compression:** measure short-value threshold on payload, not token
([#889 ](https://github.com/chopratejas/headroom/issues/889 ))
([65b0e8c ](65b0e8c58d ))
* **compression:** use thread-local tree-sitter parsers in code handler
([#893 ](https://github.com/chopratejas/headroom/issues/893 ))
([6cdb846 ](6cdb846200 ))
* **gemini:** surface functionResponse payloads to waste-signal
detection ([#897 ](https://github.com/chopratejas/headroom/issues/897 ))
([9b0c840 ](9b0c840dd7 ))
* **learn:** decode directory names with spaces in Windows project paths
([#997 ](https://github.com/chopratejas/headroom/issues/997 ))
([#1027 ](https://github.com/chopratejas/headroom/issues/1027 ))
([2d3701b ](2d3701b59e ))
* **learn:** scan subagent and workflow transcripts
([#1045 ](https://github.com/chopratejas/headroom/issues/1045 ))
([0ddd4ed ](0ddd4ed9e9 ))
* **openclaw:** declare headroom_retrieve tool contract
([#947 ](https://github.com/chopratejas/headroom/issues/947 ))
([7c8c909 ](7c8c909c85 ))
* **policy:** correct warm-cache penalty in net_mutation_gain to (S +
dT) ([#903 ](https://github.com/chopratejas/headroom/issues/903 ))
([0632eba ](0632eba6c3 ))
* **proxy:** add native Bedrock converse-stream route
([#917 ](https://github.com/chopratejas/headroom/issues/917 ))
([b08ec15 ](b08ec15b0d ))
* **proxy:** keep codex image-generation WS turns alive through the
relay ([#1000 ](https://github.com/chopratejas/headroom/issues/1000 ))
([7dbbb40 ](7dbbb4077e ))
* **proxy:** make budget enforcement actually work
([#885 ](https://github.com/chopratejas/headroom/issues/885 ))
([a14ab45 ](a14ab45cf0 ))
* **proxy:** read RTK gain stats globally by default
([#957 ](https://github.com/chopratejas/headroom/issues/957 ))
([b70fccb ](b70fccbe17 ))
* route v1internal code assist requests to cloudcode-pa.googleapis…
([#821 ](https://github.com/chopratejas/headroom/issues/821 ))
([e20f16b ](e20f16b1a6 ))
* **serena:** stop the Serena dashboard popup and make --no-serena
actually disable Serena
([#1003 ](https://github.com/chopratejas/headroom/issues/1003 ))
([919379a ](919379a8a1 ))
* support Copilot Business subscription auth
([#641 ](https://github.com/chopratejas/headroom/issues/641 ))
([0b4a4bd ](0b4a4bd483 ))
* wire HEADROOM_EXCLUDE_TOOLS / HEADROOM_TOOL_PROFILES into Click proxy
entrypoint ([#943 ](https://github.com/chopratejas/headroom/issues/943 ))
([9b7b436 ](9b7b436b04 ))
* **wrap:** avoid duplicate top-level keys when injecting codex provider
([#884 ](https://github.com/chopratejas/headroom/issues/884 ))
([dd22cfd ](dd22cfd72a ))
### Code Refactoring
* DRY cache logic, add thread safety, fix Bash exclusion
([#704 ](https://github.com/chopratejas/headroom/issues/704 ))
([e36fccd ](e36fccd8cf ))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-16 15:35:00 -07:00
github-actions[bot]
8a53c8ec3b
chore: release main ( #891 )
...
🤖 I have created a release *beep* *boop*
---
<details><summary>0.25.0</summary>
##
[0.25.0](https://github.com/chopratejas/headroom/compare/v0.24.0...v0.25.0 )
(2026-06-12)
### Features
* add differential network capture harness
([#761 ](https://github.com/chopratejas/headroom/issues/761 ))
([11ab5f8 ](11ab5f83a1 ))
* add light mode for dashboard
([#834 ](https://github.com/chopratejas/headroom/issues/834 ))
([c425893 ](c425893d12 ))
* add OAuth2 client-credentials upstream-auth proxy extension
([#778 ](https://github.com/chopratejas/headroom/issues/778 ))
([#784 ](https://github.com/chopratejas/headroom/issues/784 ))
([eb2e50f ](eb2e50feb2 ))
* add Vertex AI proxy routing
([#793 ](https://github.com/chopratejas/headroom/issues/793 ))
([3c77e52 ](3c77e52ce4 ))
* **cli:** comprehensive help text, validation, and exception handling
improvements
([#640 ](https://github.com/chopratejas/headroom/issues/640 ))
([028efab ](028efabb4e ))
* compression safety rails — error-output protection, pipeline circuit
breaker, library inflation guard
([#851 ](https://github.com/chopratejas/headroom/issues/851 ))
([c0cadcc ](c0cadccff9 ))
* **dashboard:** per-model savings breakdown and expected-vs-actual cost
on historical charts
([#807 ](https://github.com/chopratejas/headroom/issues/807 ))
([34dafe6 ](34dafe69d9 ))
* detect re-served tool results as over-compression waste signal
([#854 ](https://github.com/chopratejas/headroom/issues/854 ))
([5f1d88a ](5f1d88ad27 ))
* **evals:** add zero-cost tool schema compaction integrity eval
([#817 ](https://github.com/chopratejas/headroom/issues/817 ))
([53a08c6 ](53a08c63bf ))
* gated Markdown-KV compaction formatter (serialization-aware output)
([#859 ](https://github.com/chopratejas/headroom/issues/859 ))
([06b2625 ](06b2625b17 ))
* **kompress:** warn on unrecognized HEADROOM_KOMPRESS_BACKEND +
document backend selection
([#204 ](https://github.com/chopratejas/headroom/issues/204 ))
([6367d0b ](6367d0b722 ))
* **memory:** add opt-in Apple-GPU (MPS) embedding runtime
([#766 ](https://github.com/chopratejas/headroom/issues/766 ))
([c71592d ](c71592d421 ))
* net-cost cache mutation formula on CompressionPolicy
([#856 ](https://github.com/chopratejas/headroom/issues/856 ) P1)
([#857 ](https://github.com/chopratejas/headroom/issues/857 ))
([d5f5802 ](d5f58026e2 ))
* **plugins:** Hermes agent headroom_retrieve plugin
([#824 ](https://github.com/chopratejas/headroom/issues/824 ))
([058bced ](058bcedab8 ))
* probe-based retention scoring of recorded compression events
([#862 ](https://github.com/chopratejas/headroom/issues/862 ))
([c2106cb ](c2106cbdab ))
* **proxy:** add CLI opt-outs for CCR injection (compression-only mode)
([#823 ](https://github.com/chopratejas/headroom/issues/823 ))
([693d9d2 ](693d9d20e2 ))
* **proxy:** attribute savings history rollups per provider
([#791 ](https://github.com/chopratejas/headroom/issues/791 ))
([0b8b8d9 ](0b8b8d92de ))
* **proxy:** log compressed messages alongside original request
([#261 ](https://github.com/chopratejas/headroom/issues/261 ))
([2269e40 ](2269e40bde ))
* **proxy:** per-project savings breakdown on the dashboard (claude,
codex, aider, copilot, cursor)
([#803 ](https://github.com/chopratejas/headroom/issues/803 ))
([914a60a ](914a60a2b0 ))
* support Python 3.14+ via pyo3 abi3 stable ABI
([#516 ](https://github.com/chopratejas/headroom/issues/516 ))
([19eac8e ](19eac8e00d ))
* switch Kompress default to kompress-v2-base with weight-only int8 ONNX
([#799 ](https://github.com/chopratejas/headroom/issues/799 ))
([74392b2 ](74392b238e ))
* **transforms:** attribute read_lifecycle + smart_crush tags
([#249 ](https://github.com/chopratejas/headroom/issues/249 ))
([8f37426 ](8f374263d3 ))
### Bug Fixes
* **anthropic:** CCR exception must re-raise, not silently swallow
([#838 ](https://github.com/chopratejas/headroom/issues/838 ))
([8db5efc ](8db5efc6f9 ))
* **ccr:** key Rust search/diff/log markers with explicit_hash
([#852 ](https://github.com/chopratejas/headroom/issues/852 ))
([bfcb07d ](bfcb07d78e ))
* **ccr:** make retrieval TTL configurable
([#715 ](https://github.com/chopratejas/headroom/issues/715 ))
([2533f77 ](2533f7703e ))
* **ccr:** skip CCR when model calls headroom_retrieve alongside user
tools ([#839 ](https://github.com/chopratejas/headroom/issues/839 ))
([30078f8 ](30078f8465 ))
* **ccr:** use shared compression store
([#875 ](https://github.com/chopratejas/headroom/issues/875 ))
([249af6c ](249af6cc7b ))
* **ci:** correct comments, timeouts, and pip reliability in native e2e
workflows ([#878 ](https://github.com/chopratejas/headroom/issues/878 ))
([b716c8c ](b716c8c2ee ))
* **ci:** pin cosign-installer to v3 (v4 does not exist)
([#774 ](https://github.com/chopratejas/headroom/issues/774 ))
([199d693 ](199d693f98 ))
* **codex:** respect CODEX_HOME for wrap config
([#731 ](https://github.com/chopratejas/headroom/issues/731 ))
([96abf38 ](96abf38b09 ))
* **content_router:** guard against empty compression output causing
Anthropic 400
([#771 ](https://github.com/chopratejas/headroom/issues/771 ))
([2f9ff07 ](2f9ff07e6c ))
* **copilot:** use responses API for subscription reasoning models
([#647 ](https://github.com/chopratejas/headroom/issues/647 ))
([84ac332 ](84ac332d14 ))
* correct preserved-entry index mapping in Gemini content round-trip
([#836 ](https://github.com/chopratejas/headroom/issues/836 ))
([0ffe2b6 ](0ffe2b6ea4 ))
* **dashboard:** stable 'Proxy $ Saved' hero tile under --workers > 1
([#481 ](https://github.com/chopratejas/headroom/issues/481 ))
([fd73b88 ](fd73b88368 ))
* don't inject empty tools:[] when client omitted the tools field
([#772 ](https://github.com/chopratejas/headroom/issues/772 ))
([574bbae ](574bbae2cb ))
* harden Copilot API auth token handling
([#557 ](https://github.com/chopratejas/headroom/issues/557 ))
([6b0c09f ](6b0c09ffd5 ))
* **health:** readyz verifies upstream connectivity, not just process
liveness ([#744 ](https://github.com/chopratejas/headroom/issues/744 ))
([5dfb446 ](5dfb446da1 ))
* **init:** guard persistent task startup
([#616 ](https://github.com/chopratejas/headroom/issues/616 ))
([9252d85 ](9252d852c5 ))
* **init:** normalize Windows hook paths to forward slashes
([#788 ](https://github.com/chopratejas/headroom/issues/788 ))
([6ea6e31 ](6ea6e31f09 ))
* **init:** suppress hook recovery output
([#760 ](https://github.com/chopratejas/headroom/issues/760 ))
([b439599 ](b4395993ae ))
* **learn:** claude-cli streams output with idle timeout
([#373 ](https://github.com/chopratejas/headroom/issues/373 ))
([9bff575 ](9bff5752bb ))
* make headroom wrap readiness probe timeout configurable for slow ML
imports ([#581 ](https://github.com/chopratejas/headroom/issues/581 ))
([163677b ](163677b405 ))
* **parser:** detect waste signals in Anthropic tool_result content
blocks ([#815 ](https://github.com/chopratejas/headroom/issues/815 ))
([929698a ](929698af10 ))
* **proxy:** F4 — trust X-Forwarded-* only behind allow-listed gateway
([d10bd5f ](d10bd5f59c ))
* **proxy:** lazy-import server to avoid fastapi crash
([#442 ](https://github.com/chopratejas/headroom/issues/442 ))
([93c6937 ](93c69372e6 ))
* **proxy:** make CCR multi-worker warning conditional on backend
([#770 ](https://github.com/chopratejas/headroom/issues/770 ))
([d76a729 ](d76a7296df ))
* **proxy:** make Kompress eager preload cache-only so a cold cache
can't block startup
([#783 ](https://github.com/chopratejas/headroom/issues/783 ))
([841663d ](841663da16 ))
* **proxy:** restore Codex usage headers on WS and streaming SSE
transports ([#577 ](https://github.com/chopratejas/headroom/issues/577 ))
([#794 ](https://github.com/chopratejas/headroom/issues/794 ))
([0ce68de ](0ce68dedd7 ))
* schema compaction must not drop property names that match DROP_KEYS
([#785 ](https://github.com/chopratejas/headroom/issues/785 ))
([ae2122f ](ae2122fda8 ))
* **security:** block DNS-rebinding on /debug/* and /stats/reset via
Host-header allowlist
([#605 ](https://github.com/chopratejas/headroom/issues/605 ))
([b4b5025 ](b4b50253f1 ))
* **ssl:** upstream httpx client inherits SSL_CERT_FILE,
REQUESTS_CA_BUNDLE, NODE_EXTRA_CA_CERTS
([#745 ](https://github.com/chopratejas/headroom/issues/745 ))
([e50fbb3 ](e50fbb3e0d ))
* suppress LiteLLM provider banner before import
([#874 ](https://github.com/chopratejas/headroom/issues/874 ))
([f9384ef ](f9384ef4b7 ))
* **transforms:** use thread-local tree-sitter parsers to prevent pyo3
Unsendable panic
([#604 ](https://github.com/chopratejas/headroom/issues/604 ))
([2ad300a ](2ad300aff8 ))
* **wrap:** track shared proxy clients with markers
([#877 ](https://github.com/chopratejas/headroom/issues/877 ))
([05bd56b ](05bd56bcb6 ))
### Code Refactoring
* extract litellm model resolution to shared utility
([ec7d006 ](ec7d0065cc ))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-11 22:18:46 -08:00
github-actions[bot]
01762b1ec7
chore: release main ( #607 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-08 11:21:23 -07:00
github-actions[bot]
f7c2552264
chore: release main
2026-06-04 14:05:56 +00:00
github-actions[bot]
cc71e07d01
chore: release main
2026-05-26 03:54:25 +00:00
chopratejas
8e4ab187e9
ci(release): align manifest + pyproject + package.json to 0.22.3
...
The repo had drifted: pyproject.toml said 0.9.1 but PyPI's latest
published headroom-ai was 0.22.3. release_version.py papered over
this by taking max(canonical, latest_tag) at release time;
release-please does NOT do that — it trusts the manifest verbatim.
Left as-is, release-please would propose 0.9.2 on the next merge
and PyPI would reject it ("400 Cannot publish version lower than
latest"), looping the bot forever.
Fix: align every version-bearing file to 0.22.3 (the truth on
PyPI). Done via `scripts/version-sync.py --version 0.22.3`:
- .release-please-manifest.json
- pyproject.toml
- sdk/typescript/package.json
- plugins/openclaw/package.json (+ headroom-ai dep range -> ^0.22.3)
- .claude-plugin/marketplace.json
- .github/plugin/marketplace.json
- plugins/headroom-agent-hooks/.claude-plugin/plugin.json
- plugins/headroom-agent-hooks/.github/plugin/plugin.json
After this lands, the bot's next release PR will propose 0.22.4
(patch) or 0.23.0 (minor) depending on conventional-commit traffic
since v0.22.3.
2026-05-25 18:41:38 -07:00
chopratejas
c8e347f1ac
ci(release): adopt release-please for gated publishes
...
Replace "every push to main = release" with release-please's
release-PR pattern: the bot watches main and maintains a single
"chore: release vX.Y.Z" PR aggregating conventional commits; merging
that PR creates the tag + GitHub Release, which fires the
release:published event that release.yml now triggers on.
Why
---
Per-merge releases burned PyPI's 10 GiB per-project storage quota
(one fresh wheel matrix ~= 200 MB per merged fix/feat PR).
publish-pypi has failed on every main merge since PR #482 with
"400 Project size too large". Consolidating many fixes into one
release cuts upload frequency ~5x.
What changed
------------
- .github/workflows/release-please.yml: bot watching main
- .release-please-config.json: python release-type + extra-files
for sdk/typescript and plugins/openclaw package.json
- .release-please-manifest.json: tracks current 0.9.1
- .github/workflows/release.yml:
* trigger: push to main -> release: published
* detect-version: reads tag from github.event.release.tag_name
(strips leading "v") so release_version.py does not re-bump
past the bot's tag
* create-release: when release already exists (typical
release-please path), do not pass --notes-file -- that would
clobber the bot's auto-generated changelog body
Tests
-----
Five new regression tests in test_release_workflows.py prevent
silent reversion to per-push triggering and assert the bot
workflow + config invariants.
Note
----
This commit does NOT fix the existing quota breach. Request a
PyPI quota increase, yank old releases, or shrink the wheel
matrix to free immediate space. This PR ensures the future
release cadence stops growing the problem.
2026-05-25 18:21:37 -07:00