tongs 1.0.1
Released 2026-09-27. This is the first patch release of tongs 1.0. It fixes the defects found since 1.0.0 in the terminal app, credentials and the desktop app beta, and moves the review actions in the desktop app into a header that every review tab shares. Nothing in your configuration or drafts changes.
Install
Section titled “Install”pipx install tongs==1.0.1pip install tongs==1.0.1 and uv tool install tongs==1.0.1 work the same
way. To upgrade an existing installation, run pipx upgrade tongs, or
uv tool upgrade tongs, or pip install --upgrade tongs. If you use the
per-user desktop app, install the matching desktop release after the core:
tongs desktop updateFor a first desktop install, run tongs --install-desktop instead. Plain
tongs never downloads or starts the desktop app on its own.
Credentials
Section titled “Credentials”These apply to the terminal app, the desktop app and the MCP server, which share the same forge clients.
- Rotated and expired tokens are picked up. When a request gets a 401,
tongs resolves the token again through the same lookup and retries once. For
GitLab it first runs
glab auth status --hostname <host>, which makes glab refresh and save an expired OAuth login. A second 401 is still reported as an authentication error. You no longer have to restart tongs after rotating a token. (#186, #245) - GitLab tokens are read from glab. tongs now reads the token glab stores
with
glab config get token --host <host>, which covers OAuth logins, personal access tokens and keyring-backed tokens. The 1.0.0 lookup always failed and fell through to~/.netrcor the keyring, so a stale token there caused 401 errors. (#245)
Security and signing describes the full credential lookup.
The terminal app
Section titled “The terminal app”- Retrying or cancelling a job reloads the job list you are on.
Ctrl+Ron the Pipeline tab refreshes the level you are looking at: the pipeline list, a pipeline’s jobs, or a job log. (#253) - The log search box stays visible above its status line, so you can see what you type. (#221)
F2in a job log writes plain text to your editor, without raw ANSI color codes. (#222)- “No forges discovered yet” appears only once repository discovery has finished and found nothing, instead of flashing at startup. (#255)
- The review draft save worker no longer touches the comment editor once the review screen has closed. (#166)
The desktop app (beta)
Section titled “The desktop app (beta)”- Review actions on every tab. Merge, Close, Reopen and Remove approval now sit in a review header next to the Your review button on Overview, Files changed and Discussions. Overview gains the Your review drawer too. An unknown result from any immediate comment, reply or verdict can be acknowledged from the same header on every tab. (#228)
- Inbox tabs load for any number of repositories. With more than 64 repositories, every inbox tab used to fail with “Too many desktop requests are pending”. Repositories are now read a few at a time, and a repository that fails is counted in a “repository reads failed” line instead of failing the whole tab. (#244)
- The repository sidebar shows “GitHub · github.com” and “GitLab · gitlab.com”, with a self-hosted hostname kept as written. (#282)
F2opens a loaded job log in your editor whenever no text field holds the keyboard, not only while a log control has focus. (#183)- The Your review button shows when a draft needs attention, even if the error arrives while the drawer is closed. (#209)
- A submission interrupted before it sent anything offers Return draft to editing instead of asking you to reconcile zero steps. (#231)
- A merge the forge refuses because of conflicts explains that the review may have changed remotely or the branch may conflict with its target, and asks you to refresh and check for conflicts. (#232)
- Diff hunk headers follow the light theme. (#250)
Documentation
Section titled “Documentation”- www.tongs.tools is rebuilt on Astro and Starlight, with new pages for first run, review drafts, reviewing on desktop, the MCP server, the desktop lifecycle and releases. Moved pages redirect to their new addresses. (#268)
- The contributor guide is shorter, and the README and packaging notes match the current code. (#249, #281)
Release and packaging
Section titled “Release and packaging”- The desktop release job finds its draft release by listing releases. On 1.0.0 the lookup could not see the draft, and the release was published by hand. (#243)
- Fedora RPM source downloads retry transient network failures. Size and hash checks are not retried. (#242)
- Pull request CI now runs only the lanes a change affects, behind a single aggregate check, and lints the documentation. Several flaky desktop tests were fixed.
Release assets
Section titled “Release assets”The desktop app is built for Linux on Fedora 44, x86_64, GNU ABI. The
GitHub Release
carries the same set of assets as 1.0.0, for version 1.0.1: the per-user
archive with its release manifest and Sigstore attestation, the unsigned Fedora
44 RPMs with their source-built companion packages, the archive SBOM with its
attestation, and SHA256SUMS. Install the RPMs together with
dnf install ./*.rpm.
Known issues
Section titled “Known issues”The most visible ones:
- Retry on a failed read does not restart the desktop app’s stopped Python process. Relaunch the app instead.
- Large diffs that are mostly additions render without syntax color in the desktop app.
- An empty optional forge field, such as a GitHub job with no workflow name, stops a desktop pipeline, job, commit or review view from loading.
Known issues has the full list, with the issue and milestone for each fix.
Thanks to @tayfuryldz for most of the fixes in this release.