Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
b2f146a
fix(tui): keep interrupted footer hidden during edit resubmission (#332)
hetaoBackend Sep 23, 2026
ffbfff6
fix(tui): restore chat viewport after autocomplete shrinks (#331)
hetaoBackend Sep 23, 2026
76262af
fix(tui): restore chat after transient layout shrink (#333)
hetaoBackend Sep 23, 2026
47d1424
fix(skills): discover linked workspace skill directories (#337)
hetaoBackend Sep 23, 2026
782f64d
fix(tui): reset rewound todos and preserve local commands during edit…
hetaoBackend Sep 23, 2026
67afb61
feat(tui): select plugins with durable identity mentions (#334)
hetaoBackend Sep 23, 2026
a914a30
chore(tui): restore source ESLint rules and verification gate (#341)
hetaoBackend Sep 23, 2026
61c4c31
feat: improve local Bash execution contracts
zephyr-fallow Sep 23, 2026
2afb1ae
test: reuse existing suites for Bash regressions
zephyr-fallow Sep 23, 2026
2943a87
fix: bound background Bash receipt purpose
zephyr-fallow Sep 23, 2026
ba92d63
fix(goal): keep unbound tool rejections recoverable
zephyr-fallow Sep 23, 2026
18e7278
fix: validate Windows managed updates through the package entry (#351)
1anZhang Sep 24, 2026
6bd59b5
chore: release MiniMax Code 0.5.3 (#352)
hetaoBackend Sep 24, 2026
0dbdc0b
fix(tui): preserve detached scrolling across layout changes (#350)
1anZhang Sep 24, 2026
45d9680
test(tui): cover permission picker table restoration (#353)
hetaoBackend Sep 24, 2026
f4e2285
feat(tui): add model favorites to the /model picker (#342)
yujiachen-y Sep 24, 2026
76deb1c
perf: reduce repeated work in long sessions (#314)
SaladDay Sep 24, 2026
135584a
chore: bump version to 0.5.4 (#354)
1anZhang Sep 24, 2026
8b55164
feat(tui): improve session titles and terminal notifications (#355)
1anZhang Sep 24, 2026
4198174
fix: remove forced branching from bash guidance (#358)
AdhereZ Sep 25, 2026
258adde
feat: sync reviewed 0.5.5 runtime improvements (#367)
hetaoBackend Sep 27, 2026
a30a898
docs: publish feedback and private security contact channels (#360)
hetaoBackend Sep 27, 2026
0f6ad52
fix(tui): distinguish Bash recaps and import models during onboarding…
hetaoBackend Sep 27, 2026
13f52a8
chore(sync): port upstream 0.5.5 into the public distribution
weekbin Sep 27, 2026
51ac3b2
fix: measure token speed over model generation time (#373)
hetaoBackend Sep 28, 2026
836580e
chore: bump version to 0.5.6 (#374)
hetaoBackend Sep 28, 2026
0b7403c
feat(config): add M3.1 Flash Preview to the fallback catalog (#375)
hetaoBackend Sep 28, 2026
2aed5ca
chore: bump version to 0.5.7 (#377)
hetaoBackend Sep 28, 2026
e2f5c3e
chore(sync): merge main into the upstream 0.5.5 sync
weekbin Sep 28, 2026
a6da443
chore(sync): extend the port to upstream 0.5.7
weekbin Sep 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .agents/skills/testing-workflow/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ suites are outside this distribution's verification.
| Sandbox on macOS | `pnpm test:sandbox` |
| Source-sync, workflow and release tools | `pnpm test:release-tools` |
| npm release archive installation | `MCODE_RELEASE_TAG=vX.Y.Z MCODE_RELEASE_ARCHIVE=/path/to/package.tar.gz pnpm verify --profile package` |
| TUI source and test lint | `pnpm lint:tui` |
| Types and standalone build boundary | `pnpm typecheck`, `pnpm build`, `pnpm check:standalone` |
| Published files and generated paths | `pnpm check:source`, `pnpm check:tsconfig` |

Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ pnpm install --frozen-lockfile
pnpm verify
```

`pnpm verify` runs the complete gate list in the same order as GitHub CI. Normal PR and main-branch checks use Node.js 24 on Linux and macOS. The Linux job runs the full profile; the macOS job uses `pnpm verify --profile platform`, which omits only the duplicate TypeScript compiler check. Windows runs the focused `pnpm verify --profile windows` contract on PRs; the profile is Windows-only and fails closed elsewhere. It checks source inventory, release tooling, build boundaries, artifacts, and Windows-specific tests without running the full capability suite. Gates that depend on platform behaviour are selected by platform rather than skipped silently; run `pnpm verify --list`, `pnpm verify --profile platform --list`, or `pnpm verify --profile windows --list` to inspect each plan. Individual gates remain available as their own scripts, such as `pnpm typecheck` or `pnpm test:byok`, while you iterate.
`pnpm verify` runs the complete gate list in the same order as GitHub CI. Normal PR and main-branch checks use Node.js 24 on Linux and macOS. The Linux job runs the full profile; the macOS job uses `pnpm verify --profile platform`, which omits only the duplicate TypeScript compiler check. Windows runs the focused `pnpm verify --profile windows` contract on PRs; the profile is Windows-only and fails closed elsewhere. It checks source inventory, release tooling, build boundaries, artifacts, and Windows-specific tests without running the full capability suite. Gates that depend on platform behaviour are selected by platform rather than skipped silently; run `pnpm verify --list`, `pnpm verify --profile platform --list`, or `pnpm verify --profile windows --list` to inspect each plan. Individual gates remain available as their own scripts, such as `pnpm typecheck` or `pnpm test:byok`, while you iterate. This distribution ships no ESLint stack or lint gate; the source repository's `lint:tui` step and its Airbnb/TypeScript/import configuration are not part of the public source.

CI writes per-gate timing and exit metadata to the Job Summary and a seven-day `verification-<os>-node-<version>-<attempt>` artifact. For a local report, set `MCODE_VERIFY_REPORT_DIR` to a directory outside the repository. Reports distinguish `PASS`, `FAIL`, intentional `SKIP`, and `NOT_RUN` after a failure. JSON is checkpointed before and after each gate; a cancelled run may leave `RUNNING`, which is not a pass. If installation fails before verification starts, no verification report is available. Reports do not collect command output, environment variables, or runtime data; read the corresponding gate's job log for failure details, including the existing bounded BYOK timeout diagnostics. CI jobs have a 15-minute verification limit and a 10-minute release-audit limit.

Expand Down
12 changes: 12 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -280,6 +280,18 @@ The Web UI originated as the community **mcode-webui** plugin and was migrated i

This repository also hosts issue reporting for the MiniMax Code desktop app. The published source covers the terminal TUI, headless CLI, and ACP; it does not include the desktop application's source. Select the affected product when filing an issue. For a desktop bug, include the app version, operating system, and a log upload ID if available from **Settings → General → Upload logs**. For a CLI bug, include `mcode --version`, your interface, and a minimal reproduction. Remove credentials and private project content from reports.

## Feedback and contact

| Channel | Use it for |
| --- | --- |
| [GitHub Issues](https://github.com/MiniMax-AI/minimax-code/issues/new/choose) | Public bug reports, feature requests, and questions about the CLI or desktop app. |
| [MiniMaxCode@minimax.io](mailto:MiniMaxCode@minimax.io) | General feedback and support inquiries. |
| [security.mcode@minimax.io](mailto:security.mcode@minimax.io) | Private vulnerability reports. Send reproduction details and redacted evidence here; see [Security](SECURITY.md). |
| [Discord](https://minimax.io/discord) | Community discussion and feedback. |
| [Feishu feedback group QR code](https://cdn.hailuoai.com/hailuo-video-web/public_assets/minimax_code_feishu_group_url.png) | Chinese-language community feedback. Scan with Feishu, or find the QR code in the Chinese desktop app under the user menu → **Contact us → Feishu**. |

Follow [MiniMax on X](https://x.com/MiniMaxAgent) for updates. Keep vulnerability details, credentials, and private project content out of public issues and community chats.

## License

First-party code defaults to [MIT](LICENSE). Existing file-level and package-level licenses remain in place. See [third-party notices](THIRD_PARTY_NOTICES.md) and [license status](LICENSE-STATUS.md) for dependencies, assets, and `mcode-tools`.
12 changes: 12 additions & 0 deletions README_ZH.md
Original file line number Diff line number Diff line change
Expand Up @@ -279,6 +279,18 @@ Web UI 源自社区的 **mcode-webui** 插件,现已作为一等公民包迁

本仓库也承接 MiniMax Code 桌面版的问题反馈。公开源码范围为终端 TUI、Headless CLI 和 ACP,不包含桌面应用源码。提交 Issue 时请选择对应产品。桌面版问题请注明应用版本、操作系统,以及「设置 → 通用 → 上传日志」生成的日志上传 ID(如可用);CLI 问题请注明 `mcode --version`、运行入口与最小复现。报告中请移除凭据和私人项目内容。

## 反馈与联系我们

| 渠道 | 适用场景 |
| --- | --- |
| [GitHub Issues](https://github.com/MiniMax-AI/minimax-code/issues/new/choose) | 公开报告 CLI 或桌面版的 Bug、提出功能建议与使用问题。 |
| [MiniMaxCode@minimax.io](mailto:MiniMaxCode@minimax.io) | 一般反馈与支持咨询。 |
| [security.mcode@minimax.io](mailto:security.mcode@minimax.io) | 私密报告安全漏洞。请通过此邮箱发送复现步骤和脱敏证据,详见[安全报告指南](SECURITY.md)。 |
| [Discord](https://minimax.io/discord) | 社区交流与反馈。 |
| [飞书反馈群二维码](https://cdn.hailuoai.com/hailuo-video-web/public_assets/minimax_code_feishu_group_url.png) | 中文社区反馈。使用飞书扫码,或在中文版桌面应用的用户菜单 → **联系我们 → 飞书** 中查看二维码。 |

也可关注 [MiniMax 的 X 账号](https://x.com/MiniMaxAgent) 获取动态。请勿在公开 Issue 或社区聊天中发布漏洞细节、凭据和私人项目内容。

## 许可

第一方代码默认采用 [MIT](LICENSE);文件或子包已有独立声明时保留原许可。依赖、资源与 `mcode-tools` 的许可分别见 [第三方声明](THIRD_PARTY_NOTICES.md) 和 [许可状态](LICENSE-STATUS.md)。
6 changes: 4 additions & 2 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,11 @@

This project is a source preview. Maintainers prioritize security issues on the default branch; no support period for older versions or response SLA has been committed.

Report vulnerabilities privately through **Security → Advisories → Report a vulnerability** on GitHub. If that entry is not enabled, open an issue without vulnerability details asking maintainers for a private channel. Share reproduction details only after that channel is available. Do not put credentials, exploit details, or real user data in public issues.
Report vulnerabilities privately by emailing [security.mcode@minimax.io](mailto:security.mcode@minimax.io). You can send reproduction details and redacted evidence directly to this address without opening a public issue first. Do not put credentials, exploit details, or real user data in public issues or community chats.

The release coordinator, @hetaoBackend, coordinates security triage; see [Maintainers](docs/maintainers.md). GitHub private vulnerability reporting is not currently enabled, and no public fallback security email is listed. Until a private channel is available, open an issue without vulnerability details as described above. No response SLA is currently promised.
If **Security → Advisories → Report a vulnerability** is available on GitHub, you can also use that private reporting channel. If it is unavailable, use the security email above.

The release coordinator, @hetaoBackend, coordinates security triage; see [Maintainers](docs/maintainers.md). No response SLA is currently promised.

Include the affected version, operating system and Node.js version, a minimal reproduction, expected and actual permission boundaries, and necessary redacted evidence. Use synthetic files and dedicated test accounts; do not test other people's accounts or infrastructure.

Expand Down
2 changes: 2 additions & 0 deletions docs/examples.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,8 @@ Use `/model` in the interactive TUI to select a model or choose **+ Add 3rd-part

Preset IDs come from models.dev and do not select entries in the bundled inference registry. Onboarding saves the chosen URL under `custom_provider`; subsequent requests use that saved URL.

In **Custom provider**, enter the name, Base URL, protocol, and API key first. Then choose **Import models from /models** to fetch the list using that key. Search and select a model to test; a successful test saves all imported models and selects the chosen one. Importing alone does not save configuration. If discovery fails or returns no models, retry, press **Esc** to edit the key, or choose **Enter a model ID manually**. Saved connections also support **refresh models** in `/provider`.

Before adding a custom provider, set a key in your current shell rather than putting it in command arguments or source:

```bash
Expand Down
56 changes: 56 additions & 0 deletions docs/source-sync-0.5.5.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# Reviewed source update for 0.5.5

This update ports the public-compatible 0.5.5 behavior from source revision
`d28ae33c08a907f5e1ef17d70725eea0d0c667a0` onto the existing public distribution.
It preserves public fixes and distribution adaptations rather than replacing the
repository with a product build's source tree.

## Included behavior

- Managed foreground Bash defaults to a one-hour total timeout and caps larger
requests at one hour. The 60-second foreground yield preserves the running
process and its original deadline. Explicit background tasks use a one-hour
runtime watchdog by default; explicit command timeouts remain separate.
- Automatic context compaction reserves output space before reaching the context
limit. Checkpoint output scales with the model window; reasoning-only output
exhaustion advances to a smaller candidate. Provider errors get one bounded
logical retry. Automatic failures retain the original history; valid manual
checkpoints are committed even when a local next-request estimate rejects them.
- Update downloads reuse the TUI's proxy and loopback-bypass policy and load
their network dependency lazily. Existing public installation ownership and
registry selection remain intact.
- Memory-tool results have a 16 KiB model-facing limit with a head/tail preview
and guidance for reading more. This does not upload memory or change its storage.

The root and TUI source versions are 0.5.5. This source update does not republish
the existing npm package or move an existing release tag.

## Privacy and publication decisions

| Surface | Decision |
| --- | --- |
| Usage, metrics and diagnostics | Keep the public independent opt-ins, disabled defaults, and `DO_NOT_TRACK` / `MCODE_DISABLE_TELEMETRY` overrides. |
| Evaluation capture and data contribution | Do not import automatic capture wiring, evaluation payload/transport expansions, or default-enabled contribution behavior. |
| Workspace collection and indexing | Keep snapshot collection, archive creation, background upload/retry and semantic-index activation excluded. |
| Feedback and automatic error reports | Keep the public reviewed-text/count-only feedback projection and allowlisted diagnostic schemas; no raw conversations, tool output or workspace files. |
| Compaction observations | Import only local content-free count/budget/outcome facts; preserve the existing public telemetry consent boundary. |
| Managed account, BYOK, plugins, connectors, search and user-requested deployments | Preserve supported public clients and behavior. No private endpoints, generated service contracts or new cloud authorization dependencies are introduced. |

The reviewed update is selective. The older `release/extraction.json`
`sourceRevision` remains the base for future three-way comparisons: changing it
would incorrectly mark the remaining runtime ownership migrations, service
integrations and source-tree moves as synchronized. Those changes need their own
public dependency and privacy review. Private candidate reports remain outside
this repository and are not publication artifacts.

## Validation boundary

Imported tests exercise compaction failure/recovery, budget boundaries and real
Bash execution using synthetic data. Public privacy tests inspect the outgoing
telemetry/diagnostic data, including the final feedback archive. The repository's
full verifier additionally checks source export, types, build boundaries, TUI,
headless BYOK, ACP, permissions and platform-applicable sandbox behavior.

Offline tests are not evidence of live-service ingestion, model quality or
Windows/Linux runtime acceptance. Actual check results belong in the pull
request's validation record.
8 changes: 8 additions & 0 deletions docs/source-sync.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,11 @@ Output includes `report.json`, `candidates/`, and `.private-review`. Candidates
5. Scan complete history and current source before creating the public PR. Include public changes, validation results, and capability descriptions, never private review reports.

After accepted public changes are ported back, subsequent three-way comparisons should show them as synchronized or cleanly mergeable while retaining standalone adaptations. Synchronization is not a blind overwrite: conflicts, missing source, and new files require maintainer judgment.

## Selective release updates

A bounded release update can port reviewed behavior without adopting unrelated
runtime ownership migrations or private service integrations. Keep the existing
three-way baseline until the entire target revision has been reviewed; record
the selected revision, included behavior and excluded boundaries separately.
See the [0.5.5 review](source-sync-0.5.5.md) for the current selective update.
Loading
Loading