Skip to content
tongsv1.0.3
GitHub
docsprojectv1.0.1

tongs 1.0.1

Released 2026-09-27. This is the first patch release of tongs 1.0. It fixes the defects found since 1.0.0 in the terminal app, credentials and the desktop app beta, and moves the review actions in the desktop app into a header that every review tab shares. Nothing in your configuration or drafts changes.

Terminal window
pipx install tongs==1.0.1

pip install tongs==1.0.1 and uv tool install tongs==1.0.1 work the same way. To upgrade an existing installation, run pipx upgrade tongs, or uv tool upgrade tongs, or pip install --upgrade tongs. If you use the per-user desktop app, install the matching desktop release after the core:

Terminal window
tongs desktop update

For a first desktop install, run tongs --install-desktop instead. Plain tongs never downloads or starts the desktop app on its own.

These apply to the terminal app, the desktop app and the MCP server, which share the same forge clients.

  • Rotated and expired tokens are picked up. When a request gets a 401, tongs resolves the token again through the same lookup and retries once. For GitLab it first runs glab auth status --hostname <host>, which makes glab refresh and save an expired OAuth login. A second 401 is still reported as an authentication error. You no longer have to restart tongs after rotating a token. (#186, #245)
  • GitLab tokens are read from glab. tongs now reads the token glab stores with glab config get token --host <host>, which covers OAuth logins, personal access tokens and keyring-backed tokens. The 1.0.0 lookup always failed and fell through to ~/.netrc or the keyring, so a stale token there caused 401 errors. (#245)

Security and signing describes the full credential lookup.

  • Retrying or cancelling a job reloads the job list you are on. Ctrl+R on the Pipeline tab refreshes the level you are looking at: the pipeline list, a pipeline’s jobs, or a job log. (#253)
  • The log search box stays visible above its status line, so you can see what you type. (#221)
  • F2 in a job log writes plain text to your editor, without raw ANSI color codes. (#222)
  • “No forges discovered yet” appears only once repository discovery has finished and found nothing, instead of flashing at startup. (#255)
  • The review draft save worker no longer touches the comment editor once the review screen has closed. (#166)
  • Review actions on every tab. Merge, Close, Reopen and Remove approval now sit in a review header next to the Your review button on Overview, Files changed and Discussions. Overview gains the Your review drawer too. An unknown result from any immediate comment, reply or verdict can be acknowledged from the same header on every tab. (#228)
  • Inbox tabs load for any number of repositories. With more than 64 repositories, every inbox tab used to fail with “Too many desktop requests are pending”. Repositories are now read a few at a time, and a repository that fails is counted in a “repository reads failed” line instead of failing the whole tab. (#244)
  • The repository sidebar shows “GitHub · github.com” and “GitLab · gitlab.com”, with a self-hosted hostname kept as written. (#282)
  • F2 opens a loaded job log in your editor whenever no text field holds the keyboard, not only while a log control has focus. (#183)
  • The Your review button shows when a draft needs attention, even if the error arrives while the drawer is closed. (#209)
  • A submission interrupted before it sent anything offers Return draft to editing instead of asking you to reconcile zero steps. (#231)
  • A merge the forge refuses because of conflicts explains that the review may have changed remotely or the branch may conflict with its target, and asks you to refresh and check for conflicts. (#232)
  • Diff hunk headers follow the light theme. (#250)
  • www.tongs.tools is rebuilt on Astro and Starlight, with new pages for first run, review drafts, reviewing on desktop, the MCP server, the desktop lifecycle and releases. Moved pages redirect to their new addresses. (#268)
  • The contributor guide is shorter, and the README and packaging notes match the current code. (#249, #281)
  • The desktop release job finds its draft release by listing releases. On 1.0.0 the lookup could not see the draft, and the release was published by hand. (#243)
  • Fedora RPM source downloads retry transient network failures. Size and hash checks are not retried. (#242)
  • Pull request CI now runs only the lanes a change affects, behind a single aggregate check, and lints the documentation. Several flaky desktop tests were fixed.

The desktop app is built for Linux on Fedora 44, x86_64, GNU ABI. The GitHub Release carries the same set of assets as 1.0.0, for version 1.0.1: the per-user archive with its release manifest and Sigstore attestation, the unsigned Fedora 44 RPMs with their source-built companion packages, the archive SBOM with its attestation, and SHA256SUMS. Install the RPMs together with dnf install ./*.rpm.

The most visible ones:

  • Retry on a failed read does not restart the desktop app’s stopped Python process. Relaunch the app instead.
  • Large diffs that are mostly additions render without syntax color in the desktop app.
  • An empty optional forge field, such as a GitHub job with no workflow name, stops a desktop pipeline, job, commit or review view from loading.

Known issues has the full list, with the issue and milestone for each fix.

Thanks to @tayfuryldz for most of the fixes in this release.