Changelog

Built together

Every release, newest first. Driven by the people actually running agents in the wild.

AI agents are being handed real power now, real credentials, real systems, real consequences, and the security to match hasn't caught up. Closing that gap is the whole reason Crawdad exists, and it's not a problem any single vendor solves in isolation. It gets solved alongside the people actually running agents in the wild, hitting the edges, and shaping what comes next.

So that's how Crawdad is built, with you, not just for you. There's no distance between the people using it and the people building it. When you run into something, it reaches engineering directly, and you can see the result right here on this page: much of what shipped over the last few months started with real users running the tool and showing us where it fell short. Report something on a Tuesday, and it's not unusual for the fix to land that week.

Every release is verified end-to-end before it ships, and every claim is reproducible, including the unflattering ones, because you deserve the real numbers, not the marketing ones. That's the standard we hold ourselves to, and it's the standard the community deserves.

If something's slowing you down, breaking, or just feels wrong, or if you see where this should go next, that's the conversation we want: contact@getcrawdad.dev. We read all of it, and it genuinely shapes what we build. Thank you for building this with us.

What we've shipped

Items tagged FEEDBACK were built because users asked for it.

2026-09-15 v1.7.3, Reliability & Update Restart

FIX RELIABILITY

A reliability release. Applying an update from the dashboard now restarts the service cleanly, the sidecar becomes ready in about a second instead of roughly thirty, the tamper-evident audit trail stays verifiable across upgrades, and an update can advance one platform without disturbing another. No detection or model changes, and a healthy install updates in place.

2026-09-15 v1.7.2, Core Experience

FEATURE FIX FEEDBACK

A release focused on the everyday experience: connecting an agent, understanding what Crawdad is doing, and staying out of your way. Connecting is now guided and one click, the dashboard tells the truth about which mode you are in and what it has caught, and a retrained detection model plus a false-positive fix stop benign coding prompts from being blocked. Detection coverage is unchanged; what improved is first-run accuracy, the honesty of the interface, and how easy it is to connect.

2026-09-03 v1.7.1, Auto-Update & Service Hotfix

FIX SECURITY

A hotfix for the macOS auto-update and service path. No behavior change for a healthy install; this repairs installs that could not start or self-update, and hardens the updater's restart across platforms.

2026-09-02 v1.7.0, Declared Intent & Observe-First

FEATURE SECURITY

Declared intent and an observe-first default. Monitor remains the default posture, and a stock device still inspects and records without installing any OS lock, so upgrading changes nothing until you opt in. What is new: the detection engine now leans observe-first on a fresh install to cut first-run false positives, and an operator can optionally attach an intent descriptor to a governed agent.

2026-08-24 v1.6.1, Auto-Updater Reliability

FIX SECURITY

Fixes the macOS in-app auto-update, which could fail after applying an update, and closes an authorization gap on two config endpoints. macOS installs on 1.6.0 or earlier should take this update with a fresh install (curl -fsSL https://getcrawdad.dev/install.sh | sh), not the in-app updater; the pre-1.6.1 updater is the component being fixed. From 1.6.1 onward, in-app updates place atomically and self-heal.

2026-08-21 v1.6.0, Runtime Governance & Enforce Mode

FEATURE SECURITY

An opt-in enforcement layer on top of detection. The default, Monitor, is unchanged from prior releases, a stock device is byte-for-byte unchanged, so upgrading changes nothing until you opt a device or a fleet into Enforce. Enforce binds a governed agent's egress to Crawdad at the operating-system level.

2026-08-19 v1.5.3, Pre-1.6 Hardening Rollup

SECURITY

2026-07-31 v1.5.1, ONNX Init Resilience

RELIABILITY

2026-07-30 v1.5.0, Multi-Platform Release

FEATURE

2026-07-26 v1.4.0, Guardian UI & API Tier 1

FEATURE

2026-07-25 v1.3.0, Workspace

FEATURE

2026-07-25 v1.2.0, Air-Gap, Clarity Mode & Threat Intelligence

FEATURE SECURITY

Air-gap egress enforcement

Clarity Mode

Enterprise ingestion

Threat intelligence

Security & auth

Release tooling

2026-07-07 v1.0.0, Shipping Release

FEATURE

2026-06-01 v0.12.0, Graduated Trust

FEEDBACK FEATURE

Early testing showed Crawdad was too aggressive out of the box, blocking tool calls for benign dev work. This release introduces a graduated approach: real attacks still block immediately, but ambiguous actions are observed instead of blocked.

2026-05-19 v0.11.0 – v0.11.3, Policy Engine

FEATURE

2026-05-18 v0.10.5 – v0.10.7, Reliability

FEEDBACK RELIABILITY

Driven by friction surfaced during real-world testing.

2026-05-07 v0.10.2 – v0.10.4, Install & ML Activation

INSTALL

2026-05-06 v0.10.0 – v0.10.1, Protection Modes

FEATURE

2026-04-21 v0.9.2, Cross-Platform ML

FEATURE

2026-04-17 v0.9.1, Remote Control Plane & Agent Trust

FEATURE

2026-04-15 v0.9.0, Launch

FEATURE

Not ready to install yet?

Get notified when we ship. No spam, just changelog updates.