@overdeck/core. Install or upgrade with npm install -g @overdeck/core@latest, then run pan install so the terminal backend and synced skills match the new version.
This page starts at v0.60.0, the release that removed Overdeck’s state layer. Older releases are listed on GitHub Releases.
2026-10-08
New
- Claude Haiku 5.5:
claude-haiku-5-5, released by Anthropic on 2026-10-07, is in the model pickers, the model catalog and cost tracking. It has a 1M-token context, 128K output and adaptive thinking (default effortmedium). Cost tracking applies its tiered pricing: $0.10 / $0.50 per MTok in/out for prompts up to 100K tokens, and five times that above 100K. Launching it needs Claude Code 2.1.293 or newer; Overdeck refuses the launch on an older CLI and says so. The built-in cheap and background defaults still use Haiku 4.5.
Fixed
- The configured Claude model is the one that launches: the Command Deck status review and the planner relaunch that delivers a dashboard message passed the short
opusandhaikualiases to Claude Code for Opus 4.8, 4.7, 4.6 and Haiku 4.5. Current Claude Code resolves those aliases to Opus 5.5 and Haiku 5.5, so those two paths could run a newer model than configured. Every model now launches by its full ID. Regular agent launches (work, plan, review, Flywheel) always passed the full ID and were not affected. - Default expensive model is Opus 5.5: the built-in default for the expensive workhorse (plan, review, strike, sequencer, knowledge) and the Flywheel moves from
claude-opus-4-8toclaude-opus-5-5, matching the eval-backed Anthropic defaults preset. Opus 5.5 is also cheaper ($4 / $20 per MTok against $5 / $25). Installs that set these models explicitly keep their setting; installs on the built-in defaults now run Opus 5.5 for these roles. - Sonnet 5.5 cache reads cost $0.10 per MTok, matching Anthropic’s 2026-10-07 price cut.
- Starting the Flywheel again works:
pan flywheel start --freshand the Flywheel page’s Start failed with “FOREIGN KEY constraint failed” once the previous Flywheel conversation had a handed-off successor. The old conversation is now kept under a retired name and archived instead of deleted. - Workspaces rail: a project’s main checkout no longer appears as an anonymous “main” row in the sidebar’s Workspaces list (it only appeared for some projects). Each project’s Home has a Main checkout button next to Terminal and Web that opens it, creating its workspace the first time. Favorite a main checkout to keep it in the rail, where it shows under the project’s name; Cmd-K lists every main checkout by project name.
2026-10-04
Fixed
- Projects find their GitHub tracker themselves: a project registered without
tracker,github_repoorissue_prefixused to show “No tracker configured … set tracker: or issue_prefix: in projects.yaml” and an empty Issues panel. When the project’s origin remote is on GitHub, the dashboard (at startup),pan syncand project setup now writegithub_repo: owner/repointo~/.overdeck/projects.yamland log what they set. Projects with no GitHub origin still show the message, which now namesgithub_repo:ortracker:instead ofissue_prefix:. - First message to a new conversation is no longer refused: a Claude Code conversation started in a directory Claude Code had never trusted stopped at the “Do you trust the files in this folder?” dialog, and Herdr refused the first message with
agent_blocked. Conversation launches are now pre-trusted like issue agents, and~/.claude.jsonis created if it does not exist yet. When an agent is waiting at a dialog for any other reason, the delivery error now quotes the dialog and tells you to answer it in the Terminal tab. - The Codex authentication banner clears after
codex login: signing in withcodex loginin your own terminal refreshed~/.codex/auth.json, but the banner kept showing “expired” from CLIProxy’s stale copy until the dashboard restarted. The status check now re-copies the newer credentials first. An access token that has lapsed but still has a refresh token no longer counts as expired, because Codex and CLIProxy refresh it on next use, so it no longer blocks Codex spawns either. The banner now names which copy (~/.codexor the CLIProxy copy) is bad.
2026-10-04
New
- Scoped API tokens:
pan token create <name> --scopes <list>creates a bearer token (odk_…) that a program such as an event sidecar or a notifier can use instead of a full device session. The scopes areread:events,read:state,read:conversations,tell,operateandadmin; a request outside them gets403withinsufficient_scope. The token is printed once, works over HTTP, the event stream and WebSocket upgrades, and can never create a session, a pairing credential or another token.pan token listshows tokens andpan token revoke <id>closes a token’s live connections at once. See Remote access. (#4441) - Access tokens in Settings: Settings → Access Tokens lists tokens with their scopes and times, creates one and shows it once with a Copy button, and revokes one after a confirmation. A browser signed in as a paired device can see the list but cannot create or revoke. The same section has Require a token to sign in, which turns on
dashboard.require_token_mintat once, with no restart. (#4450) - Pair a device from the dashboard: Settings → Anywhere has Pair a device, which makes a pairing link and QR code for an address you pick, and can add a new address to the trusted origins with no restart (stored in
~/.overdeck/trusted-origins.json). Only a browser on the machine itself can make links or add addresses. The section lists paired devices with Revoke, and an Anywhere status card, also on the Health page, shows this machine’s label, the addresses it is reachable at, the number of paired devices and the Session Vault state, with a fix for each problem. (#4449) - Session Vault in the dashboard: with the dashboard running, conversations started from it are saved to the vault 30 seconds after they go quiet and synced every 5 minutes, with no hook. Settings → Session Vault shows the backend, the last sync, any blocked lines with the
pan vault allow-secretcommand, the machines that have synced, and the transcripts waiting for deletion, which you can review and delete there (#4444). The same section now sets up a new vault (a dialog shows the recovery phrase, and any generated passphrase, once), joins an existing vault with the passphrase or the recovery phrase, unlocks a machine whose key is missing or was rotated, and has Sync now. Only the Claude Code Stop hook still needspan vault setup --hooks(#4461). - Conversations from your other machines: Claude Code and Codex conversations saved to the vault by another machine appear in the conversation list marked “from
<machine>”. They are read-only copies; the composer shows thepan vault resume <id>command instead of an input. (#4448) - Continue here: a read-only copy has a Continue here button that adopts the conversation on this machine and opens it. It shows where it will continue and the code snapshot it will apply, asks how to proceed when the directory’s branch, commit or dirty state differs, offers to clone and register the project when no registered project matches, and puts the code snapshot in a new workspace when the checkout has uncommitted changes. If another machine continued it first, it says so and changes nothing. (#4454)
- Continue on another device: a conversation’s ⋮ menu (in its header or on its row) has Continue on another device. Open on another screen shows a link to the conversation, a Copy button and a QR code, offers only trusted addresses other devices can reach, and in a browser on this machine can add a one-time pairing credential so an unpaired device pairs and opens the conversation in one step. Hand off to another machine saves the conversation and its code snapshot to the vault right away and says which version to continue; a running conversation then shows Keep working here and Stop this session. A line that looks like a credential blocks the save and the dialog names the
pan vault allow-secretcommand. On the receiving machine, Check for new conversations in a vault row’s menu syncs at once. Hand-off works for Claude Code and Codex conversations. (#4472) - Model presets: Settings → Model Routing has Apply Anthropic defaults, Apply Anthropic cost-saver (pilot) and Apply OpenAI defaults, and the CLI has
pan models preset list|show|apply|undo. A preset sets the workhorse slots, roles, review lanes, existing tiers, default conversation model and background models to one provider’s lineup in one step. Before applying you see every setting that will change, before and after, and the ones the preset leaves alone. Only those settings are written into~/.overdeck/config.yaml; comments and other lines keep their text. The whole preset is blocked when the provider has no credentials or its harness CLI is not installed. Undo restores the values the last apply replaced, except settings you changed since. The Anthropic presets cite the 2026-09-29 eval run; the OpenAI preset is research-backed and not yet eval-tested in Overdeck. A newer preset version is shown for review and never applied automatically. See Model presets. (#4412) - Operator decisions: a work agent that cannot continue without your decision runs
pan ask <issue> "<question>" --option <a> --option <b>(2 to 4 options, optional--context). The issue moves to Needs you with the question and its options, and God View marks it on the shelf. Answering from the dashboard, or any message delivered to that agent from the dashboard orpan tell, closes the question;pan ask <issue> --withdrawwithdraws it. Work agents are told to use it for blocking questions. (#4387) - Effort for conversations: the Home composer and the Command Deck sidebar have an effort picker next to the model picker, with the levels the model supports.
pan handoffandpan forktake--effort <level>; without it the new conversation inherits its source’s effort, clamped to the new model, and switch-model keeps the effort the same way (#4489). Changing the level in a running Claude Code conversation or agent sends/effortand keeps the new level only after Claude Code confirms it in the transcript; a session that is mid-turn or waiting on a permission prompt is refused. The picker now shows the effective level and where it came from, such asHigh · defaultorLow · set, instead of “Effort unverified”, andterminalwhen someone ran/effortin the native CLI. Claude Code also saveslowthroughxhighas the default for your own newclaudesessions of that model in~/.claude/settings.json(#4495). - New conversation with options: the
+in the Command Deck header is now a split button. The+still creates a conversation at once; the caret beside it, and a command palette action, open New conversation with options…, which sets the project, a working directory inside it, model, harness, effort (with the default’s source shown), context, skills, a linked issue and an optional first message for that one conversation. Skill choices there are stored on the conversation and apply at every launch, resume, restart and fork, ahead of issue, project and global settings (#4491). The Skills field shows each skill’s description, filters by name or description, and groups skills into collapsible sections (Project skills, Overdeck, Personal, and one per pack) with on counts (#4537). - Compare any two refs: the diff panel has a Compare… view that diffs any two branches, tags or commits of the conversation’s repository, with no remote or pull request needed. Choose A..B for every difference or A…B for the head’s changes since the two diverged. The selection is kept in the URL, so a popped-out comparison can be bookmarked. An ignore whitespace toggle in the panel header hides re-indented and re-spaced lines in every view and is remembered per browser. (#4505)
- Conversation bookmarks: click the icon beside a user or assistant message to bookmark it; click it again to rename or remove the bookmark. The Bookmarks header button lists them, and clicking one scrolls to that message and outlines it. Bookmarks survive reloads and new messages, are never written into the agent’s transcript, and are not copied by a handoff or fork. A conversation holds up to 500. (#4521)
- Handoff options:
pan handoff --skill <name>and--pack <id>turn skills or a cached skill pack on for the new conversation only.pan handoff --holdcreates and launches the new conversation without sending the kickoff; its dashboard composer shows the kickoff text, which you can edit and send, or you can runpan handoff start <conv>. A held kickoff is sent once. (#4502) - Blocker wake:
pan task block <issue> <item> --on <ref>...records which issues or PRs must merge first (an issue ID,#N,owner/repo#Nor a PR URL). Within about two minutes of the last of them merging, the dashboard sends the issue’s work agent oneBLOCKERS MERGEDmessage telling it to sync with main and unblock the item, or raises Needs you once if the agent cannot be reached. SetOVERDECK_DISABLE_BLOCKER_WAKE=1to turn it off. (#4452) - Deft Directive profile: add the
deftpack withpan skills pack add deft https://github.com/eltmon/directive --ref <ref>and turn it on to mount seven read-only Deft skills that need no Deft engine. Each carries a notice telling the agent not to run Deft’s CLIs, install packages or change git hooks, and outside a Directive project Claude Code launches also deny those commands. In a project that already uses Deft Directive,pan skills deft status|enable|disable --project <key>shows who owns each concern and stores managed mode, where Overdeck owns worktrees, review and merge; turning the pack off at the issue or project level hides the project’s Deft pointer skills and writes Deft’s own.deft-directive-disableflag in issue worktrees, which Deft engines from v0.92.0 honor. Overdeck never runs a Deft CLI or writes a tracked file in your project. See Skills. (#4428) - SageOx pack (off by default): the
sageoxpack records Claude Code sessions with SageOx, using anoxyou build from the eltmon/ox fork. That build writes nothing into your repository, adds no attribution to commits or PRs, and stays offline unless Overdeck allows the network. With uploads off, the default, nothing leaves the machine;pan skills pack sageox upload on --project <key>uploads redacted session transcripts to the SageOx cloud ledger, andpan skills pack sageox statusshows each project’s state. Ifoxor the repository’s.sageox/is missing, the launch continues without SageOx and prints a warning. Codex launches never get it.pan doctorhas a SageOx row while the pack is registered. See Skills. (#4430)
Improved
- Effort across agent launches: an agent keeps its effort across resume, restart, crash recovery, session rotation, crash respawn and model handoff, clamped to the relaunch’s model; a later
roles.<role>.effortchange reaches new spawns only (#4488). The review parent, test dispatch, Flywheel and remote Fly work agents launch at theirroles.<role>.effort, andpan worker runandpan spawntake--effort <level>(#4536).pan plan --effortaccepts all five levels, the Plan dialog offers them and defaults tohigh, and the planning prompt no longer callsxhighormaxlow effort (#4518). Tier slots launch at their crew’s effort unless you pass--effort, and Settings has an Effort select per tiered-execution crew and per review sub-role (#4520). Kimi K3 accepts all five levels (Medium launches as High, Extra High as Max), Pi and Muse sendxhighformax, and a launch with no resolved effort now fails instead of falling back to the harness’s own default (#4533). Each newsessions.jsonentry and cost-ledger row records its effort,pan cost effort [--issue <id>] [--json]groups spend by effort, and the Agents page,pan statusandpan showshow an agent’s effort and its source (#4526). - Find a conversation by its title: Cmd+K conversation results are one row per conversation, labelled by its title, with the best-matching excerpt and a hit count. Title matches rank first, then matches in message text, then matches only in paths, code or tool output. Archived conversations are included and marked, and title matching works even when conversation search indexing is off. (#4375)
- PR badges on issue rows: an issue’s row in the Command Deck project tree and in the sidebar Workspaces rail shows its PR number, colored by state and review, with
×for failing checks, within seconds ofpan doneopening the PR. Operator conversations working inside the issue’s workspace get the PR link too, and in a project’s main checkout a conversation is linked by branch only while its terminal is running. (#4463) - Conversation targets for agent commands:
pan tell,pan pause,pan unpause,pan untroubledandpan killacceptconv/2972,conv:2972or a dashboard conversation URL as well as an issue or agent ID. A bare number that matches both an issue agent and a conversation is refused with every candidate listed. (#4468) - One-click Linear sign-in: the Linear authentication banner has one Connect Linear button. It opens the authorization link, asking a blocked agent for a fresh one when the last link expired, checks access when you return to the dashboard tab (or with Check now), and resumes every blocked agent. Blocked-agent rows link to their conversation or issue. Pasting the callback URL is now a fallback, open by default only when the dashboard is not on a loopback address. (#4469)
- Continued-on markers: after a conversation continues on another machine, its row and composer on the first machine read “Continued on
<machine>” with a link to the other copy. Turns typed there afterwards are saved as a separate fork, and the composer names the fork’s id. (#4462) - Jev settings in the dashboard: Settings → Background AI sets the Jev route (OpenCode Zen or TypeSafe direct), model and timeout, saving as you edit with no restart, and refuses to turn a Jev toggle on while no model is set. Under each toggle it shows calls in the last 24 hours, the last call time and the last error, from a usage log in
~/.overdeck/jev/usage/that never records the API key, the text sent or the answer. (#4524) - Silent reviewers are recovered: a reviewer that was dispatched but wrote nothing for
roles.review.stallMinutes(default 15) is stopped and dispatched again once per run; if it is still silent, the issue goes to Needs you.pan showlists these asreview.stalledandreview.stall-escalated. (#4440) - Click an image thumbnail in the composer, or under a sent message, to view the image full size. (#4496)
- Idle dashboard terminals stay connected behind proxies with idle timeouts of 30 seconds or more, because the terminal WebSocket now exchanges a heartbeat every 20 seconds. Programmatic clients opt in with
?heartbeat=1. (#4458)
Changed
- TLDR removed: the TLDR Read hook, its index daemon, the
pan admin tldrandpan status --tldrcommands, the Health and Metrics TLDR panel, the Settings toggle and thepan-tldr/pan-admin-tldrskills are gone. A 14-day audit of 2,071 agent transcripts found 282 reads the hook replaced with an outline. Within the next 8 tool calls, 74.5% re-read the file with offset/limit, 13.8% read it through Bash, 3.9% re-read it in full, and only 7.8% worked from the outline, so each denial cost an extra model turn instead of saving tokens. New workspaces no longer install a ~1.5 GB Python venv or start a daemon, and creating a workspace now refuses to run with under 10 GiB free.pan syncandpan installunregister the two hooks from~/.claude/settings.json(and from workspace-local.claude/settings.jsoncopies) before deleting their scripts, and the dashboard stops leftover daemons when it starts. Leftover.venvand.tldr/directories are not deleted;pan synctells you when some exist. Anagents.tldrkey inconfig.yamlis ignored and dropped on the next Settings save. Restart agents started before the upgrade so their sessions stop loading the old hooks. (#4431) - The diff panel’s vs main view, for conversations and agents, now compares committed changes against the project’s configured default branch, so a project on
masterortrunkgets a correct view, and All turns and vs main list the changed files. A popped-out vs main link from before the upgrade shows this new comparison. (#4504) - The sidebar’s context checkboxes are gone; choose a conversation’s context in New conversation with options… instead. (#4491)
- The
mattpocockskill pack’s default source is now the fork eltmon/skills, pinned atv1.2.3, so upstream changes arrive when the fork is synced and you re-pin withpan skills pack update mattpocock --ref <tag>. Adding the pack still turns nothing on, andsetup-matt-pocock-skillsstays opt-in. (#4427) - The GitHub issue poller backs off while nothing changes: each unchanged poll doubles the interval from 30 seconds up to 5 minutes. A changed poll, the Refresh button, a cache clear, loading the issue list or a GitHub
issueswebhook returns it to 30 seconds. Subscribe your GitHub App to Issues events, or an issue edited on GitHub can take up to 5 minutes to appear./api/cache-statusreports the reason for the current interval. (#4516) - An agent’s AskUserQuestion call that is empty, a placeholder or a status update is rejected before it reaches you, so only real decisions open a dialog. Work agents are told they may end their turn to wait for background work. (#4519)
Fixed
- Permission prompts with long commands: a Claude Code permission prompt taller than the conversation’s terminal can now be answered from the dashboard; it used to show in Needs you with no buttons. Needs you shows the command and the next step, and Open terminal opens the conversation’s terminal. (#4471)
- Conflict repair reaches more PRs: an approved PR that turns conflicting is repaired without waiting for CI, which GitHub never runs on a conflicting PR (#4452), and a PR approved at an older commit is repaired too and re-reviewed at its new head (#4470). The merge gate is unchanged: the repaired head still needs green CI and an approval at that head.
- CI test failures reach the work agent: a red CI test job now sends its failure to the issue’s work agent, including when GitHub’s check event lists no pull request; before, the relay never fired and the PR sat. A CI failure message the agent does not accept raises Needs you. (#4442)
- Test-removal waiver is back:
pan review waive-test-removal <id> --reason "…", or the waiver control under a failedtest-skipgate in the dashboard’s Test/Lint panel, lets you approve a deliberate test removal for the current head. Nothing could grant one sincepan verify waive-test-removalwas removed. The waiver is stored untracked in the workspace, so granting it changes no file in git, and the command refuses agents, including the Flywheel. Runpan review request <id>afterwards. (#4443) - God View: after a dashboard restart, busy issues no longer show as frozen “1h idle” (#4538). The shelf and Doldrums labels no longer overprint, the shelf shows at most 8 orbs, merged issues waiting only for close-out leave through MERGE instead of sticking on the shelf, and the PLAN, REVIEW and TEST counts include only live agents (#4539).
- A review whose kickoff text contained a split emoji was rejected by Herdr, so the reviewer never started and was dispatched again forever. Overdeck now sends well-formed text, and a kickoff the backend rejects goes to Needs you. (#4517)
- A composer message to Claude Code on Herdr sometimes sat in the input box without being submitted. Overdeck now waits for the paste to show, presses Enter, and presses it once more if the message is still there and no menu or prompt is on screen. (#4494)
- After
/clearin a conversation, the old row and the new one shared one terminal session, so listing revived the old row and stop or resume acted on both. The newest conversation now owns the session: stop and resume on the old row act on it, deleting or archiving the old row stops nothing, and prompts can no longer be answered from the old row. (#4490) - Idle Claude Code conversations no longer jump to the top of Chats as “active just now” every hour; a row’s last activity is now its last message, not the transcript file’s modified time. (#4525)
- Conversation timeline rows no longer overlap when you scroll back through a long conversation, resize the window or toggle tool calls. (#4500)
pan closeno longer refuses an issue that landed and deployed. A verification run cut short by the merge is recorded as skipped instead of left running, and shown muted in the dashboard; the verification check passes when the work landed and main verification passed; and the deploy check retries the dashboard health probe 3 times before reporting it unreachable. (#4545)
2026-09-29
New
- GPT-6.1 Sol: OpenAI’s
gpt-6.1-solis in the model pickers, the Settings catalog and the cost tables ($2/M input, $0.10/M cached input, $10/M output, 1.05M context, 128K output). It is selectable only; no default or tier mapping changed. On the Codex harness with a ChatGPT login it needs Codex CLI 0.159.0 or newer, because older Codex gets a 400 from OpenAI for this model. Overdeck refuses the launch below that version and names the upgrade command (npm install -g @openai/codex). (#4423) - Session Vault:
pan vaultsaves your agents’ conversations, encrypted on your machine, into a private git repository you own, and lets another machine continue them.pan vault setup <git-url>creates the vault and prints a 24-word recovery phrase once;pan vault join <git-url>adds another machine.pan vault save,sync,list,showandstatusmanage what is saved, andpan vault resume <id>takes a conversation over on this machine (or<id>@<version>to fork at an earlier version). Before resuming, it compares the directory’s branch, commit and dirty state with the saved state and asks how to proceed. Claude Code and Codex resume natively; other harnesses get a markdown digest to paste into a new session. A line that looks like a credential blocks the save and is named by line number and pattern, never by value.pan vault excludekeeps paths, git origins or single conversations off the vault, andsetup --hooksadds a Claude Code Stop hook that saves after every turn. Overdeck provides no backend, never sees the contents, andpan vaultcommands send no telemetry. Losing every device and the recovery phrase loses the vault. See Session Vault. (#4385) - Session Vault on Windows: continuing a Linux conversation under WSL2 is verified end to end, including the uncommitted-code snapshot with its line endings, file modes and symlinks. Native Windows is not supported yet: it needs the Herdr terminal backend, which does not run there, and a few vault and dashboard steps still fail. The Session Vault docs list what works today. (#4421)
- Vault passphrase unlock: a new machine can join the vault with a passphrase instead of the 24 words. Setup offers a generated six-word passphrase or your own (16 characters or more), and
pan vault passphrase set|removechanges it later. The vault key is stored wrapped under the passphrase, so anyone who can read your vault repository can try to guess it offline; each guess is deliberately slow, which protects a generated passphrase but not a weak one. The recovery phrase still works, and removing the passphrase never locks you out. (#4388) - Uncommitted code travels with the conversation: each vault save also takes an encrypted snapshot of the working tree (tracked and untracked files, plus local commits you have not pushed; files matched by
.gitignoreare left out).pan vault resumefetches origin, checks out the saved commit and applies the changes unstaged. Use--worktree <dir>to apply into a new worktree or--no-codeto skip the code. The snapshot is stored only in your vault, never pushed to your git host, so it works while the first machine is off. The target checkout must be clean. Snapshots over 50 MB are skipped, and code that looks like it contains a credential is not uploaded until you allow it withpan vault allow-secret <id> --file <path>. (#4389) - Vault key rotation: after losing a device,
pan vault rotate-keyre-encrypts the vault under a new key and prints a new recovery phrase. Other machines stop syncing until they re-join with the new phrase or passphrase, and keep their own conversations when they do. Rotation protects only what you save afterwards: the lost machine can still read everything saved before it. Upgrade Overdeck on every machine before rotating, because older versions cannot read conversations saved before a rotation, and revoke the lost machine’s git credentials too. (#4414) - Opt-in transcript eviction: with
"evict": truein the vault config,pan vault evictlists the local transcripts that are fully saved and verified by reading them back, with a fingerprint of that list, and deletes nothing.pan vault evict --confirm <fingerprint>deletes exactly those files, skips anything that changed since the review, and refuses a list that no longer matches.pan vault restore <id>rebuilds an evicted transcript byte for byte. Eviction is off by default and never runs on its own. (#4385) - Pair another device with a dashboard:
pan pair --url <address>prints a one-time link that lets a laptop, tablet or second desktop open this machine’s dashboard with its own revocable session. The link works once, expires after 10 minutes, and carries its credential in the URL fragment so it never reaches a server or proxy log.pan devices listandpan devices revoke <id>manage paired devices; revoking one closes its open connections at once. Each machine still owns its own projects, agents and conversations. See Remote access. (#4417) - Claude Code version check and upgrade: Overdeck knows the oldest Claude Code each model needs (Claude Fable 5.1 needs 2.1.255, Claude Sonnet 5.5 needs 2.1.284) and refuses a launch on an older Claude Code before creating a terminal session, naming the installed and required versions and the upgrade command. The dashboard shows a banner while any configured model’s minimum is unmet. For a user-writable npm, native or Homebrew install it offers an Upgrade Claude Code button; for a root-owned npm prefix, an unrecognized install or Windows it shows a command to copy, since Overdeck never runs
sudo. Running agents keep their current Claude Code.pan doctorreports the version, install method, per-model minimums and any otherclaudebinaries on yourPATH. (#4378) - Codex version floor for GPT-6: with a ChatGPT login,
gpt-6-solandgpt-6-lunaneed Codex CLI 0.156.1 or newer, and OpenAI returns a 400 below it. Overdeck now refuses such a launch up front on every start path, names the required version and never substitutes another model. API-key auth has no floor.pan installdoes not manage the Codex CLI; upgrade it withnpm install -g @openai/codex.pan doctorshows one Codex model floor row per model. (#4386) - External skill packs: add a third-party git repository of skills, such as mattpocock/skills, with
pan skills pack add <id> <url> --ref <tag>. Overdeck shows a preview, pins the commit you approve, and mounts the pack through the harness’s own plugin system, so pack skills never land in your shared skill folders. Packs and single pack skills are off until you turn them on, at global, project or issue level (pan skills set --pack <id> on, or the Skills page, project settings and issue view).pan skills pack updatere-previews before moving the pin. Packs apply to Overdeck-managed Claude Code and Codex launches only, not to other harnesses or remote launches. Only skill folders are mounted: a pack’s hooks, MCP servers, commands and scripts are listed as Not applied and never reach the agent. The dashboard can turn packs on and off but cannot add them. See Skills. (#4353) - Jev judgment client (optional, off by default): Overdeck can ask TypeSafe AI’s Jev model small typed questions, through OpenCode Zen or directly through TypeSafe. It needs a
jev:block with an explicit model and a TypeSafe or OpenCode Zen key (Settings, Background AI), and each feature has its own toggle, all off. Low-cost mode, which is on by default, turns them all off. With Jev unconfigured nothing is sent and nothing changes. What each toggle sends to TypeSafe: the turn-end assessment sends an idle plan agent’s or conversation’s role and the last 6,000 characters of its last message; the acceptance-criteria review sends the id and title of each acceptance criterion at plan finalize; the memory relevance toggle is not called by anything yet and sends nothing. The API key and request bodies are never logged, and each request is costed in the ledger. See Jev. (#4380) - Jev readings in Needs you and plan finalize: with the turn-end toggle on, an idle Claude Code or Codex plan agent or conversation that stopped without asking through a tool can read Asked you a question, Reported done or Blocked on its Needs-you row instead of the generic label. A reading is shown only at 0.7 confidence or higher, is advisory, and triggers no action; measured precision for the question label is 0.78, below the 0.9 bar for calling it ready. With the acceptance-criteria toggle on,
pan plan finalizeprints warnings about criteria that are not observable or combine several checks, and never changes its exit code. (#4397, #4394) - Conflict repair for approved PRs: an approved PR with green checks that turns conflicting with main no longer sits until someone notices. Once a minute the dashboard finds such PRs and sends the issue’s work agent one repair instruction per head: sync with main, resolve, run the gates, push and request review. If the conflict is still there 45 minutes later, or the agent cannot be reached, the issue goes to Needs you once. A repaired PR whose approval no longer stands at its new head is re-reviewed, and review is requested once if the agent has not done so within 15 minutes. Set
OVERDECK_DISABLE_CONFLICT_REPAIR=1to turn it off. (#4411) - Independent plan critic: planning for an issue labeled
architecture,substrate-improvementorsecurity, or finalized withpan plan finalize --critic, gets a read-only critique from a model of a different family before it can complete. Each blocking finding needs an answer in the PRD; after two rounds finalize proceeds and lists anything unresolved. Set the critic withroles.plan.sub.critic.model. It has no default, so a flagged plan cannot finalize until you set one. (#4382) - CPU pressure awareness: on Linux, Overdeck reads CPU pressure stall information and holds back new gauntlet lanes (HTTP 429
cpu-saturated, override withpan lane start --force) while the CPU is saturated. A dashboard agent start shows a warning you can confirm, and holding Flywheel-started agents is opt-in withresources.governor_cpu_hold_dispatch. Conversations,pan startand dashboard Start are never blocked on CPU. The dashboard gets a larger CPU share, verification runs a smaller one, and batch agents and lanes run at a lower priority, all configurable underresources.*. Runaway processes, such as a tool call that outlived its agent, are reported in the activity feed with the command to stop them; Overdeck never kills them. Where pressure data is unavailable, as on macOS, load per core is the fallback. (#4322)
Improved
- Guardrails for parallel agents, adapted from Deft:
pan task claimrefuses a task that another live agent holds or whose file scope overlaps one, treating an unclear scope as overlapping;--stealoverrides it and says what it overrode (#4357). The agentgitshim refusescommit,push,mergeandcherry-pickin a feature worktree that is on the wrong branch or a detached HEAD (#4351). Forks, handoffs and read-write workers refuse a project’s primary checkout as their working directory; an operator can pass--allow-primarytopan forkorpan handoff(#4354). - An ended work agent that handed its issue to review now reads Handed to review instead of Ended unexpectedly, and a planning session reads Plan finalized when the issue’s plan is. (#4401)
Changed
- The dashboard requires a credential from other machines: every
/apiand/eventsrequest that does not come from this machine now needs a dashboard session, a paired device session or the internal token, or it gets a 401. Every WebSocket connection (terminals, RPC, voice) requires one too, and a browser whose session cannot be created shows an Unauthorized banner with Retry. A LAN device that opened the dashboard without signing in must now pair withpan pair. If a local reverse proxy (Tailscale Serve, cloudflared, Traefik) forwards outside traffic, turn ondashboard.require_token_mint, and add non-default addresses toOVERDECK_TRUSTED_ORIGINS. (#4417, #4317) - Operator-only labels: only you can add or remove the
auto-merge,hold-for-uatandreleasedlabels. Work agents, conversations and the Flywheel have theirghrefuse those label writes and are told to ask you. (#4379) - Planning files are committed, not left in the primary checkout: per-issue continue files and spec status changes are written in the issue’s workspace instead of the project’s primary checkout, and
pan donecommits pending.pan/continues/and.pan/specs/changes before it rebases. Close-out no longer writes the spec; its status comes from the merged PR.pan scopecommits and pushes on main only when the issue has no workspace. (#4377) - A finalized plan can no longer be changed by the work agent. Finalize stamps a
Plan-Finalizedtrailer on the spec’s commit, and a new requiredplan-integrityverification check fails a branch that adds, removes or edits plan items or acceptance criteria after that; status fields are still allowed to change. Work agents record progress withpan task donein the continue file. (#4355) pan spawnruns every worker that can change files in its own item worktree by default.--sharedputs a worker in the issue workspace instead, and only the foreman or an operator can use it. (#4376)- The
/okfskill now comes from a pinned release of eltmon/okf.pan syncinstalls that version and replaces local edits in copied installs, but leaves a copy you symlinked to your own checkout alone.pan doctorwarns when an installed copy’s version differs. (#4415)
Fixed
- Prompt-time memory injection works again: it almost never injected a memory, because query expansion failed, most often for lack of an Anthropic API key, and the fallback search then required every word of the prompt to match. Injection now searches for any of the prompt’s content words, so it finds matches even when expansion fails. A missing or rejected key is reported as
provider-auth-failedinpan memory doctorwith its cause, andpan doctorhas a Memory extraction row. Theanthropicextraction provider needsANTHROPIC_API_KEYorANTHROPIC_AUTH_TOKENin both the dashboard’s and the agents’ environment; a Claude subscription login does not authenticate it. (#4416) - Work that never started is visible: when the automatic work start after planning failed, for example because the workspace’s Docker stack would not rebuild, the issue sat with no work agent and no sign of it. That start is now deferred and retried like a guardrail refusal, and the Command Deck and Needs you show Work start retrying, or Work agent not started with the error and a Start work action. (#4413)
2026-09-29
New
- Claude Sonnet 5.5: Anthropic’s
claude-sonnet-5-5is in the model pickers, the Settings catalog and the cost tables ($2/M input, $10/M output, 1M context), and it is now the default for the Sonnet tier:workhorses.mid, new conversations, status reviews, fork summaries, the tiered-execution supervisor, the test and merge specialists and the provider fallback. A model you chose yourself is unchanged. Claude Code launches now pass the full Sonnet model ID instead of thesonnetalias, so an agent configured for Sonnet 5 keeps running Sonnet 5. Sonnet 5.5 needs Claude Code 2.1.284 or newer; runnpm install -g @anthropic-ai/claude-code@latestfirst. Overdeck no longer sendstemperatureto models that reject it, so memory extraction and the speech summarizer work with Sonnet 5 and newer. (#4336) - Local GPU models (experimental): run Claude Code agents on a model served by a local Ollama (0.14 or newer) with
ollama:<tag>model IDs. Model traffic stays on the machine, no provider API key is needed, and the run is costed at $0. Overdeck checks Ollama and the model before launch,pan upstarts Ollama only when a configured model uses it,pan installoffers setup (skip it with--skip-ollama), andpan doctorreports the server, version, downloaded models and loaded context size. No local model has completed a work-agent task yet; see Local models. (#4271) - Prime Agent harness: Prime Intellect’s Prime Agent (0.8.x) can run work agents and conversations. Set
harness: prime-agenton a role or pick it for a provider under Settings, Providers. Dashboard messages,pan tell, stop, resume, transcripts and cost work as they do for other harnesses, andpan doctorchecks the binary, version and auth. Anthropic models need API-key auth with Prime Agent; subscription auth is blocked. (#4251) - Steer a running Claude Code turn: press Ctrl+Enter (Cmd+Enter on macOS) in the composer, or choose Steer in its delivery selector, to interrupt the current turn and send your message at once instead of queueing it.
pan tell --steer <id> "<message>"does the same from a shell. Pi keeps its existing steer. Codex, ACP, OpenCode, Kimi Code, Muse Code and Prime Agent do not steer yet and refuse a steer instead of queueing it silently. (#4314) - Turn skills on and off: each skill has an on/off state at global, project and issue level, and the narrowest level wins. Set it from the Skills page, project settings, the issue view or
pan skills set <skill> on|off|inherit, and list states withpan skills list. Claude Code and Codex launches apply it. The 11 core pipeline skills always stay on. (#4326) - Ended sessions show their outcome: an ended agent session reads Merged, Review approved, Changes requested, Tests passed, Tests failed, Plan finalized, Stopped by operator or Stopped by close-out instead of a bare “Session ended”. Only Ended unexpectedly is highlighted, and it appears only on positive evidence. (#4318)
- Answer permission prompts from the dashboard: a Claude Code permission prompt, including one raised by a subagent, opens a dialog in the conversation, appears in Needs you with how long it has waited, and sends a desktop notification that repeats after 5 and 30 minutes. Messages you send while a prompt is open are held and go out when it clears. (#4284)
- Gauntlet lanes:
pan lane start|list|wait|report|stop|reaplaunches and manages builder, critic, verifier, play and orchestrator conversations from any harness. Lanes nest under the conversation that launched them in the Command Deck and on the Agents page, critics pair with their builder and show their verdict, andpan lane showprints a builder’s critic chain. (#4238) - Type and go from Home: both Simple and Advanced Home have a composer that starts a conversation, a discussion or a terminal command, in a project or with no project. An unscoped conversation can be moved into a project later, and the sidebar always shows the No-project entry. (#4287)
- Add Project dialog: suggests unregistered local repositories to add in one click, snaps a subfolder to its repository root, and imports a folder of repositories as separate projects or as one multi-repo project. The New Workspace title is now a Smart field that recognizes issue references and branch names. (#4289)
- Get set up checklist: Home shows what still needs attention on a new install (Claude and GitHub logins, the terminal backend, memory).
pan installandpan doctornow warn instead of failing on optional tools such as Docker, ast-grep, and tmux when Herdr is the backend. (#4286) - Close-out settings: Settings, Close-out controls whether close-out removes the workspace and deletes the feature branch, shows how much disk closed issues’ workspaces still use, and offers Clean up now for closed, merged workspaces with no uncommitted changes. (#4288)
- Reasoning effort per role, tier and project: set
efforton a role, sub-role, tier or project, and Overdeck resolves it through one precedence chain for every launch, clamping a level the model does not support. See Reasoning effort. (#4261) - The Flywheel page shows issue titles, live agents, headline stats, UAT batches and a Report tab, flags unknown tracker issues and work with no agent, and offers Start fresh for an orphaned session.
pan flywheel statusprints the same detail. (#4215) - The
pan-consolidate-conversationsskill makes the current conversation the owner of a project’s open work: it digests the other open conversations’ pending commitments, archives them and reports a ledger. (6cbb757)
Improved
- Awareness feed: All shows transitions (conversations started, ended or failed) inside a 24 hour window instead of re-dating every working conversation on each poll. A gauntlet run is one card with its lanes on expand, an issue’s activity collapses into one card with a step count, and Project scope keeps the project’s conversations and run cards. The empty Git, Files and Comments tabs are gone. (#4316)
- Faster conversation open: polling aggregates run on their own worker lane, so opening a conversation no longer waits behind them, and an open no longer loads the transcript twice or re-parses it on the main thread. Diffs are polled only while the session is alive and cached for an unchanged transcript. (#4321)
- Degraded mode instead of outage screens: when the dashboard loses its server, pages stay visible and usable under one banner (delayed, unreachable or restarting). Server-backed actions stay visible but disabled with the reason, and composer messages sent meanwhile are held and sent on reconnect. (#4285)
- The issue right-click menu lists only the actions available in the issue’s current state. Three restart entries became one Restart agent dialog, and Plan is one dialog with a start-after-planning checkbox that now actually starts work. (#4220)
- The Agents page Live view shows the current tool and its description on each row, counts subagent activity before calling an agent quiet, starts the preview’s subagent rail collapsed, and puts a conversation that ended on a provider error into Needs you. (#4231)
- Conversation titles and About summaries describe everything still in context, using the latest compaction summary, instead of only the most recent request. (#4252)
- A universal rule tells every agent to use literal paths, never variables, as
rmtargets. (0b5162d) - The
grilling,codebase-design,domain-modelingandimprove-codebase-architectureskills, adapted from mattpocock/skills, now ship with their MIT license notice. (cf9773c)
Changed
close_out.remove_workspacenow defaults totrue, so close-out removes a merged issue’s workspace unless yourcloister.tomlsets the key. Deleting the feature branch stays off by default. (#4288)- The dashboard keeps synced skills and rules current by itself: after a
pan reloador a merge that changes them, it runspan sync --if-changed. The Setup changed banner now appears only when that sync fails or is turned off, and says what changed. Turn it off withcontext.auto_sync: false. (#4272) - A new dashboard profile opens in Simple mode; profiles with dashboard history stay in Advanced. (#4287)
- Memory governor reserves and the spawn guardrail’s memory thresholds now scale with installed RAM, and on macOS the governor uses memory pressure and the same available-memory figure as the header, so small Macs no longer stay in permanent shedding. Reserves you set are normalized against RAM. (#4274)
- Anonymous telemetry, when enabled, also sends an hourly bucketed GitHub API usage sample, a throttled notice when GitHub rate-limits a call, and a daily heartbeat with bucketed project and agent counts. Settings, Telemetry has a new opt-in, off by default, that groups your installs by a pseudonymous hash; GitHub logins, emails and raw IDs are never sent. See Telemetry. (#4277)
Fixed
- Dashboard freezes: the dashboard could stop responding with its main thread stuck, and the watchdog restarted it many times a day. The cause was the native file watcher used for conversation transcripts. Overdeck now polls transcripts every 15 seconds instead. (93468d6)
- GitHub rate limits: Overdeck’s own polling could use the whole hourly GraphQL budget. The quota sampler now reads GitHub’s real GraphQL counter, close-out stops re-asking about unmerged branches every minute, PR listings are smaller, skip projects without a remote and are cached for idle repositories, and a pause ends when GitHub’s window resets. Every GitHub call is metered by caller: the app bar shows a quota pill with the top callers, a banner states GitHub’s used-of-limit while calls are paused, and
pan doctor github-quotashows the local view. (#4319, #4277) - Herdr agents show their live status: on the Herdr backend the dashboard served every agent as stopped, so God View, the Command Deck and agent counts missed working agents. Panes are now matched to agents by agent key. (#4323)
- Close-out is no longer blocked by exited agents:
pan closeand Close Out check whether an agent recorded as running is actually alive. An exited agent no longer blocks; a live agent or an inconclusive check still does. (#4325) - No more false “Not found in transcript”: long or queued composer messages that Claude Code wraps as pasted content are matched and shown without the
<pasted_content>tags. (#4335) - The Herdr Terminal tab decodes UTF-8, so characters such as
●,·, box-drawing lines and emoji no longer render as mojibake. (#4315) - Messages to a Claude Code conversation reach the main agent: the composer and
pan tellswitch Claude Code’s input back to the main agent before sending and refuse if they cannot. A message that lands in a subagent is labeled Delivered to subagent, and one that never lands moves to the outbox with Resend and Copy instead of waiting forever. (#4276, #4262) - A composer send that was not delivered shows Not delivered with a resend action instead of Sent. (#4284)
- The Command Deck model and effort pickers are no longer clipped and no longer shift the conversation column. (#4273)
- A dead agent is reported once per launch and marked stopped, instead of re-emitting dead and running events every minute. (#4313)
- Review verdicts and merges no longer fail when a PR lookup is rate-limited: transient forge failures are retried, a deferred verdict is replayed, and the open PR on a branch wins over a closed one. (#4270)
- Review is dispatched when the dashboard restarts during verification. (#4232)
- A deferred work-agent hand-off survives a dashboard restart, and
pan plan finalize,pan plan doneandpan showsay when a hand-off is held because dispatch is frozen. (#4227) - The
pan startplan-freshness check no longer refuses plans that create new files; it flags only files deleted after the plan was written. (#4226) - A work model chosen during planning is used by the automatic start that follows. (#4237)
- Tiered execution tiers accept
workhorse:<slot>references, Settings shows when a tier overridesroles.work, andpan admin config tiersprints each tier’s effective model. (#4192) - Agents started by an operator through a planning hand-off are no longer treated as Flywheel agents by the emergency brake and memory shedding. (#4239)
- Plan-artifact pushes no longer leave the local main branch unable to follow origin; conflicting untracked
.pan/files are set aside with a backup and a warning. (#4230)
2026-09-27
Fixed
npx @overdeck/coreworks again. Since 0.60.0 the package listed the test library@effect/vitestas a runtime dependency, which pulled vitest’s optional peer packages into every install. After@vitest/browser-playwright5.0.2 was published, npm crashed while resolving them withCannot read properties of null (reading 'edgesOut'), so a freshnpx @overdeck/coreornpm install -g @overdeck/corefailed before Overdeck started. The dependency is removed, and the build now refuses to publish a test framework as a runtime dependency. If you still see the error, clear the stale npx cache withrm -rf ~/.npm/_npxand run the command again.
2026-09-26
New
- GPT-6 Sol and GPT-6 Luna: OpenAI’s new
gpt-6-solandgpt-6-lunaare in the OpenAI provider, the model pickers and the cost tables, with the Codex 272K context limit applied. Defaults and routing are unchanged; pick them per role. (#4234) - The Agents page opens on a Live view: running and in-pipeline agents are grouped into Needs you, Live and Waiting, each with one reason, in resizable panes with a collapsible preview and a new set of agent state colors. (#4216)
- Start a bare conversation from the Command Deck with the “No context” checkbox: no Overdeck-injected context and a faster spawn. (#4187)
- Pull requests are linked to conversations by branch, so a conversation shows the PR it produced. (#4067)
- Subagents take direct input from their own composer and show a live working indicator. (#3788)
- A project row shows the progress of a
pan reloaddeploy while it builds and restarts. (#4094) - Conversations and
pan handoffrun through the terminal backend, so they live in Herdr panes like every other agent. (#4104)
Improved
- Merge train restored: approved, green, mergeable PRs that opted into auto-merge are scheduled and merged on the merge-train tick again, and
pan merge canceluses the merge-train routes. (#4066, #4111) - Faster CLI startup:
panloads each command’s code only when that command runs, sopan --versiondrops from about 560 ms to 180 ms. (#4205) - The Command Deck issue tree shows a real state badge instead of “Allocated”, one status signal per row, and each resource once as an icon cluster. (#4218)
- Board routes no longer wait on
gh pr listor per-agent derivation, so the parked and auto-merge views load quickly. (#4091) - An issue that was closed out renders as shipped, with its history, instead of as never started. (#4078)
- The status-bar emergency stop shows what it stopped. (#4125)
- The conversation feed shows ACP agents’ thinking, prompt failures and stalled turns as their own rows. (#4142, #4141, #4152)
- Skills, CLI docs and agent-facing messages name only
panverbs that exist after the Cut. (#4143, #4158) pan doctorflags a stalepan syncsource checkout, andpan syncprunes git hooks that were deleted upstream. (#4148, #4161)- Dependency security updates: an in-range refresh with security overrides clears most
bun auditadvisories, the desktop build moves to electron-builder 26 to clear a criticaltaradvisory, and the pinned CLIProxyAPI moves to v7.3.16. (#4202, #4214, #4159) - Internal cleanup: the remaining hardcoded model fallbacks are gone (an unset model now resolves through role routing), and dead sub-roles, stores and
pan inspectleftovers are removed. (#4164, #4170, #4080)
Fixed
- Planning hand-off guardrails: a planning auto-handoff acknowledges advisory guardrails, and a hand-off the guardrails refuse is retried instead of dropped. (#4135, #4177)
- A “troubled” agent can be cleared again:
pan untroubled <id>is back, andpan start --forcealso clears the gate. (#4228) - Herdr agents show up everywhere:
pan status, the agent output API, god view liveness, skills and attach hints now read the Herdr backend, and Herdr issue workspaces are found again after a restore. (#4103, #4089, #4093, #4072, #4099) - Stopping an agent or reaping an idle one closes its Herdr panes, and finished review and one-shot role runs are reaped on Herdr. (#4076, #4162, #4175)
- Only Overdeck’s own agent panes count toward the work-agent limit. (#4207)
- Review synthesis is re-dispatched when every lane reported but the parent died, and pausing an issue also holds its review convoy. (#4153, #4150)
- The Request review menu’s Full, Quick and None choice applies to the run it starts. (#4120)
- Repeated identical UAT failures escalate once instead of looping. (#4063)
- An idle agent resumes after “Connection lost mid-response”. (#4178)
- An unfinished workspace setup resumes instead of starting the agent inside it, and every Claude Code launch is pre-trusted before it starts. (#4176, #4163, #4144)
- Workspace teardown removes its Docker Compose networks, and orphaned workspace networks are swept. (#4181)
pan reloadcarries the running dashboard’s boot gates. (#4179)- The “Reconnecting” banner clears after a restart, and the sidebar refetches projects and conversations on reconnect. (#4075, #4082)
- Conversation search skips deleted transcripts, recovers from watcher errors, and opens hits from unregistered and subagent conversations. (#4157, #4194, #4087)
- A transient pipeline-membership failure is retried instead of latching an error banner. (#4092, #4190)
- Keystrokes typed on
/projects/newbefore the backend settles are kept. (#4147) - Merged strikes clean up their pane, worktree and branch. (#4070)
- Every GitHub App API request has a timeout. (#4060)
- JSONL transcripts outside vendor cleanup roots are preserved. (#3817)
2026-09-24
New
- Agents directory at
/agents: a tree of local, remote and project agents with a list and a conversation, issue and PR context pane. Agents launched by other tools appear there too. (#4022, #4038) pan worker run | wait | report | list: delegate work to a registered, issue-linked worker agent that reports back. (#4027)- Attach the native Codex or OpenCode terminal UI to a running conversation. (#4028, #4025)
- The Flywheel page is back, derived from live data instead of a stored run record. (#3999)
Improved
- One merge gate. Every merge path (the merge-ready set, the dashboard Merge button, auto-merge, the merge train and the per-project queue) asks the same question. A CI-mode project needs its CI test job to succeed on the PR head, and a failed UAT verdict for the current head blocks merge until a later pass. (#4040)
- Review and UAT verdict markers in PR comments count only from the repository’s owners, members and collaborators, or from Overdeck’s own identity. (#4040)
pan handoff, the memory governor,pan start --freshand stuck-agent force kill stop agents through the terminal backend, closing their Herdr panes. (#4048)- Approving a merge after
origin/mainmoved returns a clear 409 with both SHAs and recovery steps. (#4041) - Internal cleanup: the Effect façade layer was cut back to plain Promise and synchronous functions. Some
@overdeck/coreexports were removed or renamed; the full list is in CHANGELOG.md. (#4006, #4057)
Fixed
- A failed UAT is relayed to the work agent again. (#4033)
- The stuck pause holds, and repeated verdict feedback is sent once. (#4039)
- Background subagents keep running until they finish. (#4054)
- The question dialog resets its answer for each new question. (#4058)
- Conversation lifecycle events are attributed to the right launch and row. (#4005)
- Planning, resume and recovery relaunches close the review gaps left by the Herdr move. (#4018)
- Flywheel’s in-flight list excludes merged and closed issues. (#4004)
- Plan homes with a legacy
.pan/gitignore rule are repaired. (#3998) - Desktop builds ship again. (#3997)
2026-09-23
The Cut
Overdeck no longer keeps its own copy of pipeline state. Where an issue stands is read live from git, the issue tracker, the pull request and the terminal backend, so the dashboard can no longer drift from reality. Every feature stays; only the state layer is gone. docs/THE-CUT.md maps each removed piece to its new home. (#3917)What this changes for you:- Herdr is the default terminal backend.
pan install,pan sync,pan upandpan doctorinstall and check Herdr for you. tmux is still supported throughterminal.backend: tmux. See Terminal backend. (#3995) - Planning artifacts live in your repo. Drafts, specs, continues, orders and the backlog sequence are committed under
.pan/in the project (or its plan home), not in a separate state worktree.pan admin migrate-plan-home <project>copies open issues’ artifacts across. - Merge readiness comes from the PR. It is PR approvals, green checks and forge mergeability. Review verdicts are PR reviews, posted by the GitHub App.
- Retired commands.
pan approvebecomesgh pr review --approveor the dashboard Merge button,pan review pendingbecomesgh pr list, andpan inspect,pan reset-to-planned,pan unstick,pan review resync/resetandpan copy-configare gone because there is no stored state left for them to act on. - Simpler background supervisor. The patrol loop is now four routines: nudge stuck work, nudge on API errors, reconcile liveness, and reap closed issues.
New
- Each issue keeps an append-only pipeline journal that
pan showprints, and the work agent is told when verification passes instead of polling. (a4fb7a4) - Tests run once per push on CI, plus the touched tests locally, instead of the full suite on the host. (#3993)
- Claude Opus 5.5 support across launch, routing, model pickers and cost reporting. (#3985)
- A Conversations scope in the Ctrl-K command palette. (#3933)
- The
pan-open-threadsskill collects your unfinished threads across conversations into one checkable page. (d35b93e)
Improved
- Dashboard menus and popovers share one style, keyboard navigation, positioning and focus handling. (#3945)
- The backlog page is one ordered list without the Now, Next, Later and Someday bands, and it loads in a fraction of the time. (7110e02, #3978)
- Transcripts stay findable: each session records its transcript path when it starts, and closing an issue keeps agent state and transcripts. (#3976, #3951, #3979)
- Strikes open a PR for you to merge. (#3987)
Fixed
- Stopping an agent closes its Herdr pane. (#3989)
- OpenCode conversations show their saved history, start and resume on Herdr, and recover from stalled permission prompts. (#3986, #3991, #3970)
- Merge-train batches assemble again, fail loudly, and stop after three consecutive failures. (#3972)
- The command palette shows a search error instead of “No results” when the request fails. (#3980)
- A handed-off agent can resume its saved session. (e35d03e)