Updates

Every release, and what changed.

What each version of ranwhat added and fixed, newest first. Get the next one by email or RSS. The commit history has the reasoning behind every change, including what the tool got wrong.

01 / Follow

Get the next release.

One short email when a version ships, saying what changed. Nothing else, and every email has a link to stop. The emails are sent by Resend (privacy).

Or follow the RSS feed

https://ranwhat.com/rss.xml

Paste it into any feed reader, or open the feed. GitHub has a feed of its own for every commit.

02 / Releases

Releases, newest first.

Run the newest with uvx ranwhat@latest check, or bring an install up to date with pipx upgrade ranwhat.

0.5.0

Twelve coding agents

  • check, watch and clean read twelve coding agents, each from where it keeps its history: Claude Code, Codex, Gemini CLI, GitHub Copilot CLI, Qwen Code, Grok Build, Droid, Kimi Code, Kimi CLI, Pi, Muse Code and OpenClaw.
  • New: ranwhat sources lists every agent and where it looked. --source ID reads one agent, and --path ID=PATH reads one from somewhere else.
  • clean knows each value by a salted fingerprint, so masking it once masks every copy, including one another program wrote with different escaping.
  • Agents’ databases, such as Codex’s thread index and OpenClaw’s, are searched for secrets read only, and the report says how to remove one in the agent itself.
  • On Windows, suggested commands are quoted to paste into cmd or PowerShell.

0.4.0

Sharper watch and clean

  • watch spots a local file sent off the machine: piped or posted to curl, wget or nc, including through head, gzip, jq or sed.
  • watch reads what the shell really runs inside quotes, $'...' and a wrapped shell, and ranks deleting your home directory critical however it is spelled, \rm included.
  • watch masks the secrets in the commands it quotes, and check masks in its watch section every secret its clean section found.
  • Reads the transcripts that subagents write.
  • Fewer false alarms: placeholders, settings constants and AWS ARNs read as what they are, not as secrets.
  • clean and watch stay linear in time on hostile input, such as a megabyte of crafted text or one enormous shell command.

0.3.0

One command for both, and a faster clean

  • New: ranwhat check runs watch and clean in one read-only pass. It changes nothing; masking stays a choice you make in clean.
  • clean went from 89 seconds to 2.1 on a 39 MB transcript, with the same findings. It no longer searches pasted screenshots, which cannot hold a credential.
  • Output fits your terminal’s width, and NO_COLOR is honoured.

0.2.1

Commands you can run

  • Run through uvx, the overview suggests uvx ranwhat demo, because a bare ranwhat is not on your PATH there.
  • The capability catalogue covers HubSpot, Discord, GitLab, Atlassian, Microsoft Graph, Sentry and Shopify.

0.2.0

A catalogue that can be refreshed

  • ranwhat update refreshes the capability catalogue from ranwhat’s feed, for Plus subscribers once Plus opens. It sends the subscription token and nothing else.
  • Without a feed every command still runs on the catalogue bundled with the release, and a damaged cache falls back to it.

0.1.1

A first run that answers

  • A bare ranwhat prints what each command does and where to start, instead of a usage error.

0.1.0

First release

  • watch reads what Claude Code and OpenClaw ran and surfaces the irreversible actions worth knowing about.
  • clean finds credentials left in Claude Code’s transcripts and masks them when you ask.
  • scan and live score what an agent’s credentials allow, and demo shows a scan on an example.