Releases
Lingua v1.5.1
macOS
Windows
Not code-signed yet, so Windows shows a "Windows protected your PC" screen on first run. Choose More info, then Run anyway. The checksum below is how you verify the file is the one we published.
Linux
Verify your download
Download SHA256SUMS.txt alongside your binary, then run:
shasum -a 256 -c SHA256SUMS.txtmacOS and Linux ship with shasum. On Windows use certutil -hashfile <file> SHA256 and compare against the listing.
What's new in v1.5.1
- Selected code can travel with a safe reference. Copy reference and Copy with context are Free editor and modified-diff actions that require an explicit selection, use a relative file name, and never copy hidden content or an absolute path.
- A Run Capsule can move from the app to the CLI. Export the latest run as JSON in Free, inspect it, validate it without execution, then explicitly replay trusted source to compare status and output. A deterministic example and English/Spanish walkthrough document the boundary.
- Runtime availability is explained where actions are chosen. Menus, the command palette, and Settings distinguish browser limitations, license gates, and missing local Node, Go, Rust, Deno, Bun, or Ruby installations instead of treating payment as an installation step.
- Dead-code checks now cover every independently locked package. CI analyzes the root app, website, license Worker and update Worker with explicit package boundaries, proves each boundary with a temporary negative fixture, and runs for stacked pull requests as well as pull requests targeting
main.
Older releases (5)
v1.5.0
Sep 17, 2026- The desktop app's local MCP server no longer ships a vulnerable request parser.
honomoves to 4.13.7, clearing three advisories:toSSG()writing files outside its output directory, unbounded dot-notation nesting inparseBody()exhausting memory, and query parameters read after the URL fragment. The license service picks up the same fix. - The desktop app now runs on Electron 44. The upgrade brings the matching Chromium security fixes. The main process's bundled HTTP client moves to
undici8 and its WebSocket client tows8.21.3, both still covered by the bundled-dependency audit gate. - The first TypeScript run is faster. The TypeScript toolchain now warms up while you type in a TypeScript tab, so the first run no longer waits for it. The first run measured about a third faster, and a real session gives the warm-up more time than the benchmark did.
- Running a JavaScript notebook cell no longer downloads the TypeScript compiler. Notebook cells previously pulled about 0.9 MB of compiler on their first run, whatever their language; TypeScript cells now transpile with esbuild instead.
- The desktop app's local MCP server no longer ships a vulnerable request parser.
v1.4.1
Aug 31, 2026- The Windows desktop installer is back in the release payload. Version 1.4.0 published without a Windows build, so Windows installs and auto-updates stayed on 1.3.0. This release restores the NSIS installer and its update manifest with no other changes.
v1.4.0
Aug 31, 2026- Agent verification now installs through native client workflows instead of manual file copying. Lingua ships one portable
lingua-verifyskill through the Agent Plugins 1.0 package and a native Claude Code marketplace, with managed install, update, reload, and uninstall commands plus bilingual setup guidance for VS Code, Codex, and Claude. The skill turns trusted local CLI runs, Capsule validation or replay, and utility transformations into structured evidence while adding no hook, credential, MCP server, or hidden execution authority. - Paid checkout and license issuance now run through Lemon Squeezy. The pricing site uses the live Lemon Squeezy checkout destinations, while the existing Ed25519 license token contract remains unchanged for the app and CLI. The license Worker validates signed webhook bodies, pins the accepted store and variant identities, deduplicates deliveries with merchant IDs, stores merchant-neutral order and subscription references, and keeps unknown products and incomplete configuration fail-closed.
- Packaged and custom-environment CLI runs now select host runtimes consistently. Standalone builds invoke the host Node.js executable instead of recursively launching themselves for JavaScript or TypeScript, while Python discovery follows Windows launcher and
PATHEXTsemantics, requires executable candidates on POSIX, and resolvesPATHandPYTHONagainst the same filtered child environment used for execution. The standalone release packager now proves the JavaScript path with a real runtime smoke. - Refunded subscriptions can no longer regain a paid access window when later cancellation events arrive. Refund status is terminal across cancellation and renewal webhook paths, delayed deliveries cannot revive the license or mint a fresh token, and order refunds revoke both lifetime and subscription licenses through their stored merchant order identity.
- Agent verification now installs through native client workflows instead of manual file copying. Lingua ships one portable
v1.3.0
Aug 12, 2026- The headless CLI now installs directly through Homebrew without asking users to run npm.
brew install johnny4young/tap/lingua-cliconsumes the checksum-pinned CLI tarball from the immutable GitHub Release, installs Homebrew's Node 24 runtime, exposeslinguaonPATH, and places Bash, Zsh, and Fish completions in Homebrew's native directories; the existing npm channel remains available. Other channels can runlingua completionfor a guided, fail-closed installer that detects supported shells, previews every target, asks once before writing, and keeps Zsh activation idempotent. The formula stays separate from the Desktop cask so either surface—or both—can be installed intentionally. - Missing CLI runtimes now end with a recovery path instead of a bare PATH error. Python, Go, Rust/Cargo, Ruby, and Lua failures name the missing tool, show a platform-aware installation command, provide the matching version check, and link to the setup guide. JSON mode adds the same information as a structured
recoveryobject so scripts can help users without parsing prose.
- The headless CLI now installs directly through Homebrew without asking users to run npm.
v1.2.0
Aug 12, 2026- Scratchpad now keeps live values and failures beside JavaScript, TypeScript, and Python source. Top-level expressions render inline by default, thrown values use the error treatment without losing their full console detail, and one failed capture no longer prevents later expressions from reporting results. Python selects expressions with CPython's AST inside Pyodide so multiline syntax, indentation, declarations, control flow, function bodies, and docstrings retain their normal semantics; Settings and per-tab controls remain available when a quieter editor is preferred.