caveman v2.4.0

v2.4.0
Fixed 9
  • Scope repo intelligence to project source and require direct evidence in proxy
  • Handle stdout/stderr 'error' in UserPromptSubmit hook
  • Honor HTTP_PROXY/HTTPS_PROXY for outbound requests in CLI
  • Block sensitive directory names in compression
  • Add Claude 5 model output pricing to stats
  • Scope caveman mode to the session
Removed 1
  • Remove deprecated hooks alias from codex

From caveman

Caveman 2.4.0 closes the full weekly issue and PR queue with adversarial review, targeted fixes, and release-grade validation.

Highlights:

  • Hardened proxy redirect, authentication, cancellation, and TLS behavior.
  • Request-scoped MCP recovery and per-session native-runtime locking.
  • Safer Windows hooks and lifecycle handling.
  • Stronger compression masking, isolation, accounting, and semantic doctor checks.
  • Integrated accepted contributor work with explicit attribution and closure messages.
  • Restored documented caveman --version behavior.

Artifacts:

  • CLI: npm install -g @caveman-ai/cli@1.3.1
  • Signed binaries: bin-v1.1.4

Validation:

  • Full CLI suite: 665 tests, 647 passed, 18 skipped, 0 failed.
  • Required Linux, macOS, Windows, Go, TypeScript, Python, extension, and root CI passed.
  • Clean npm install, signed-binary checksum verification, direct wrap, compression, and byte-exact retrieval smoke passed.
What's Changed
New Contributors

Full Changelog: https://github.com/JuliusBrussee/caveman/compare/v2.3.1...v2.4.0

View original

Upgraded? How did it go?

Discussion