* fix(models): keep Sonnet 4.5 as default
* chore(changeset): add release note for Sonnet 4.5 default
* fix(models): remove Sonnet 4.6 from curated model lists
* fix(models): restore Sonnet 4.6 in web recommended list
* feat(cli): add /skills slash command for managing skills
- Add /skills to CLI_ONLY_COMMANDS in slashCommands.ts
- Create SkillsPanelContent component with:
- Display global and workspace skills with toggle indicators
- Enter to use skill (inserts @path into input)
- Space to toggle skill enabled/disabled
- Selectable marketplace link to skills.sh
- Keyboard navigation with arrow keys and vim keys
- Wire up panel in ChatView.tsx
- Add comprehensive tests for keyboard interactions
* refactor(cli): use static skill controller imports
* fix(cli): add React import to skills panel test
* fix(cli): suppress required React import lint in skills test
* fix(cli): harden /skills panel interactions
Revert optimistic skill toggle state when persistence fails, and surface a fallback URL when opening the marketplace fails. Also tighten and extend tests to verify exact marketplace URL handling and rollback behavior.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
* feat: add Sonnet 5 support and make it default across surfaces
* feat: surface Sonnet 5 as free while keeping Sonnet 4.5 defaults
* fix: rename Sonnet 5 support to Sonnet 4.6 across providers and UI
* fix: allow duplicate onboarding model ids across free and frontier
* chore: update Sonnet 4.6 banner to limited-time free messaging
* fix: align Bedrock Sonnet 4.6 model ids with AWS format
* feat: update whats new promo to Sonnet 4.6 free offer
* chore: update Sonnet 4.6 promo copy and timing
Updating CHANGELOG.md format
update changelog
update banner and bump version
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* feat: add z-ai/glm-5 to free models list
Include Z.AI's GLM 5 in the free model whitelist for zero-cost usage
and update the model picker UI to display the free label.
* Adding thinking
* Adding thinking
* Adding thinking
* changeset version bump
* v3.62.0 Release Notes
- Banners now display immediately when opening the extension instead of requiring user interaction first
- Resolved 17 security vulnerabilities including high-severity DoS issues in dependencies (body-parser, axios, qs, tar, and others)
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions <github-actions@github.com>
- Fixes for Minimax model family
- Fixes for Response chaining for OpenAI's Responses API
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
- Add `name` property to minimax, kat-coder-pro, and trinity-large-preview
models that were previously missing it
- Move type annotation from `as FeaturedModel[]` casts to the variable
declaration for proper type checking at assignment time
- Add test to verify all featured models include a display name
* increases banner cache duration to 24 hours so we make one api calls per day per user; implements a circuit breaker that stops retrying after 3 consecutive failures
* add new tests
* Clear banner cache when auth status changes
* revert 5898bc6e0e
* Fixing circuit breaker
* fix: reset circuitBreakerOpenedAt on failed half-open recovery
Previously, circuitBreakerOpenedAt was only set when consecutiveFailures
reached exactly MAX_CONSECUTIVE_FAILURES. This meant that after a failed
half-open recovery attempt, the timestamp wasn't updated, causing the
circuit breaker to immediately enter half-open state again on the next call.
Now circuitBreakerOpenedAt is updated on every failure once the circuit
breaker is tripped, ensuring proper timeout between recovery attempts.
* refactor: BannerService initialization and cache management
- Move BannerService initialization from common.ts to AuthService (which is initialized in controller)
- Re-initialize BannerService after auth state updates to ensure user context
- Add HostRegistryInfo to centralize host/platform information collection
- Improve rate limiting with exponential backoff (5min → 15min → 30min)
- Refactor error handling to better distinguish between rate limits and server errors
- Remove temporary disabled banner fetching comments
This change ensures banners are only fetched when user authentication is
available and implements more robust rate limiting to prevent API hammering.
The banner service now properly tracks user context and respects server
rate limits with progressive backoff delays.
* refactor(banner): simplify banner service initialization and usage
- Remove `getBanners()` wrapper method from Controller class
- Call `BannerService.get().getActiveBanners()` directly in Controller
- Change `BannerService.initialize()` to synchronous, returns instance immediately
- Make banner fetching non-blocking by moving to background
- Remove unused `BannerCardData` import from Controller
- Update tests to handle asynchronous background fetching with timeouts
- Clean up AuthService banner service initialization comment
This change simplifies the banner service API by removing unnecessary abstraction layers and making initialization non-blocking. The service now fetches banners in the background rather than blocking on initialization, improving application startup performance.
* clean up
* apply feedback
* un-skip unit test
* mock
* mock env
* clean up and add debounce fetch
* log fetch time
* revert
* feature flag: remote-banners
* fix loop in authService on auth update
Co-authored-by: Tomás Barreiro <BarreiroT@users.noreply.github.com>
* Fix tests
* small fixes
* use .? for banner
* moves initializeDistinctId to StateManager
* initializeDistinctId
* use v2 endpoint
---------
Co-authored-by: Zhongying Qiao <cryptoque@users.noreply.github.com>
Co-authored-by: Arafatkatze <arafat.da.khan@gmail.com>
Co-authored-by: Tomás Barreiro <BarreiroT@users.noreply.github.com>
Co-authored-by: Tomás Barreiro <52393857+BarreiroT@users.noreply.github.com>
Co-authored-by: BarreiroT <tomasmbarreiroi@gmail.com>
Apply suggestions from code review
Co-authored-by: Max Paulus 🥪 <max@cline.bot>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* changeset version bump
* Updating CHANGELOG.md format
* changeset version bump
* Updating CHANGELOG.md format
* Eve manually updating the banner and the release version
* Manually update the changelog
* Fix GLM 5 model ID in banner
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions <github-actions@github.com>
Co-authored-by: cline-test <132302818+candieduniverse@users.noreply.github.com>
* feat: checkpoint subagent tool workflow and approval UX
* feat: support subagent tool execution without native tool calls
* fix: expose use_subagents when native tool calling is disabled
* fix: stabilize subagent command UX and suppress nested command rows
* chore: tune subagent prompt guidance for context-heavy exploration
* fix: align subagent row spacing with chat row conventions
* fix: keep cancelled subagent state during immediate resume
* feat: implement subagent message rendering for approval prompts and progress updates
* feat: enhance SubagentRunner with tool use ID resolution and fallback handling
* fix: stabilize subagent cline requests with ulid and initial workspace metadata
* refactor: unify subagent chat row rendering
* feat: surface subagent costs in task metrics and status rows
* fix: refine cli subagent tree alignment and wrapping
* fix: refine subagent streaming rows in cli and webview
* fix: ensure unique act mode hint keys in CLI chat
* feat: add subagents settings toggle wiring across webview and cli
* fix(webview): stream subagent stats per prompt while constructing prompts
* fix: remove duplicate subagentsEnabled declaration after rebase
* chore: restore package lockfiles to main
* fix: harden task history usage parsing and clean prompt separators
* chore: refine subagent response formatting guidance
* feat: collapse subagent prompts with show more
* feat: show latest subagent tool call in status rows
* fix: fall back to non-native mode for subagents when native tools are unavailable
* fix: retry empty subagent responses before failing
* fix(subagents): require attempt_completion and dedupe tool result formatting
* feat(subagents): polish prompt guidance and webview status row
* add more shortcuts to help output
* Apply suggestions from code review
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
---------
Co-authored-by: Max Paulus 🥪 <max@cline.bot>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* feat: add double-check completion experimental feature
When enabled, the first attempt_completion call in a task is rejected
with a tool error that instructs the model to re-verify its work
against the original task requirements. The rejection includes the
initial task text for context. The second call proceeds normally.
This is opt-in (default off) and available via:
- Settings > Features > Experimental > Double-Check Completion
- CLI flag: --double-check-completion
- CLI TUI settings panel toggle
Adds completionAttemptCount to TaskState, plumbs the setting through
TaskConfig/ToolExecutor following existing patterns, and includes
9 unit tests.
* chore: add cli:run script for quick CLI testing
* fix: increase task preview to 8000 chars, revert unintended regex change
* fix: preserve existing proto field numbers
The auto-generator renumbered open_ai_headers (175->177) and
openai_codex_oauth_credentials (46->48), and dropped the reserved 146
comment. Restore original field numbers to avoid breaking wire-format
compatibility.
* fix: remove partial completion_result message on double-check rejection
During streaming, handlePartialBlock shows the completion_result in
the chat view. When we reject the first attempt, we need to clean up
that partial message so the user doesn't see a stale completion that
was actually rejected.
* refactor: switch from counter to boolean toggle for double-check
Use a boolean pending flag instead of a counter so that every
attempt_completion gets double-checked, not just the first one in
a task. The flag toggles: reject (set pending), accept (clear pending),
so if the model does more work and tries to complete again later, it
gets double-checked again.
The --thinking flag now accepts an optional number argument to set a
custom thinking budget instead of always using the 1024 default.
cline "prompt" --thinking # 1024 tokens (default)
cline "prompt" --thinking 8000 # 8000 tokens
Invalid values get a warning and fall back to 1024.
* feat: move reasoning effort to model config and update model selection UX
* refactor: dedupe reasoning effort handling and drop lockfile churn
* refactor: default reasoning effort to low
* refactor(cli): sync mode-scoped thinking and reasoning writes
* fix: centralize reasoning effort normalization and avoid implicit openai effort
* fix: restore proto field number for codex credentials and reserve removed fields
- Keep openai_codex_oauth_credentials at field 46 (was incorrectly
changed to 47)
- Add reserved 146 in Settings for removed openai_reasoning_effort
- Add reserved 15 in UpdateSettingsRequest for removed openai_reasoning_effort
- Remove stale openai_reasoning_effort field from UpdateSettingsRequest
* fix: map medium reasoning effort to LOW for Gemini models
Gemini API only accepts LOW and HIGH thinking levels. MEDIUM exists in
the SDK enum but is rejected at the API level. Map medium to LOW and
update the default fallback accordingly.
- Add stdinIsTTY check to shouldUsePlainTextMode() - Ink requires raw mode on stdin
- Only error on empty stdin when no prompt is provided (allows: cline 'prompt' < /dev/null)
- Fixes crash in GitHub Actions and other CI environments
Use refs instead of state values in useInput callback to avoid stale
closures. Also manually update textInputRef before calling setCursorPos
so the bounds check uses the correct new text length.
ChatView was returning empty string when the model ID key didn't exist
in state, causing first-time CLI users to see a blank model name. Added
fallback to getProviderDefaultModelId() to match WelcomeView's behavior.
Previously the animated robot only became static when the user scrolled.
Now it also becomes static when clicking or dragging, giving users more
ways to dismiss the animation. Renamed onScroll to onInteraction to
reflect the broader scope.
* fix: use vscode.env.openExternal for auth in remote environments
Fixes#5109
The OAuth authentication flow was broken in VS Code Server and remote
environments because the code used the npm 'open' package directly, which
tries to launch a browser on the server itself (which has no display).
This change routes browser URL opening through VS Code's native
vscode.env.openExternal() API via the HostBridge pattern, which properly
forwards URLs to the user's local machine in remote environments.
Changes:
- Added openExternal RPC to proto/host/env.proto
- Created VS Code handler using vscode.env.openExternal()
- Updated src/utils/env.ts to use HostProvider.env.openExternal()
- Added openExternal to CLI CliEnvServiceClient (uses npm 'open')
- Added openExternal to CLI ACPEnvServiceClient (uses npm 'open')
Related issues: #5394, #2152, #7971
* chore: add changeset for vscode server auth fix
* refactor: extract shared openUrlInBrowser utility for CLI