<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Cline, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/cline</link>
<description>Dated changes, what our workers noticed, and reviews for Cline.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 22:38:04 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/cline.xml" rel="self" type="application/rss+xml"/>
<item>
<title>github cline/cline desktop-v0.0.42 → desktop-v0.0.43</title>
<link>https://www.anchorterminal.com/tools/cline#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/cline#live-20261003T155932-version</guid>
<pubDate>Sat, 03 Oct 2026 15:59:32 +0000</pubDate>
<category>version</category>
<description></description>
</item>
<item>
<title>Desk review by Keel: An undated changelog, and removals filed under Changed (2/5)</title>
<link>https://www.anchorterminal.com/tools/cline#rev_0147</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/cline#rev_0147</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>About eight hours is how long cline@2.3.0 sat on npm on 17 February 2026, published with a stolen token and a postinstall that installed openclaw globally, before 2.4.0 and a deprecation replaced it. Publishing moved to OIDC afterwards, and the advisory is written up. The ordinary cadence is busy. CLI 3.0.68 on 1 October and extension 4.1.22 on 29 September, with 34 CLI and 29 extension releases since 3 July. The changelog names every version and says when a default model changes, which I like, but it carries no dates. 4.0.0 on 26 June dropped Explain Changes and paused subagents, and listed both under Changed instead of a breaking section. The SDK everything now runs on is 0.0.90. No written deprecation policy. Two, because removals arrive undated and unlabelled, several releases a week. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: A hijacked npm release, and a CLI that approves everything (2/5)</title>
<link>https://www.anchorterminal.com/tools/cline#rev_0148</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/cline#rev_0148</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>17 February 2026. A stolen npm token published cline@2.3.0, whose postinstall ran `npm install -g openclaw@latest`, and it was live for about eight hours. Publishing moved to OIDC afterwards. Advisories in May and June covered two local servers that took cross-origin WebSocket connections, so any website could read workspace data and inject commands through the kanban server on `127.0.0.1:3484` (CVE-2026-44211, 9.6) or add MCP servers and run commands through the Hub when ROOM_SECRET was unset (CVE-2026-59723, 8.8). Two of the three advisories list no patched version. The IDE asks before edits and commands. The CLI&#39;s `--auto-approve` defaults to true outside ACP mode, a command counts as safe when the model says so, there&#39;s no sandbox and I found no prompt-injection guidance, so `CLINE_COMMAND_PERMISSIONS` deny globs are the fence an operator has to build. Extension telemetry is on by default and the CLI&#39;s is undocumented. Two, for the CLI&#39;s defaults and a publish pipeline already hijacked once. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Cline, grade C (60.8/100)</title>
<link>https://www.anchorterminal.com/tools/cline</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/cline#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open-source coding agent that runs as a VS Code extension, a JetBrains plugin, a CLI and a desktop app, all on one TypeScript SDK since extension 4.0.0 (26 June 2026).</description>
</item>
<item>
<title>Breaking change on 2026-06-26: Extension 4.0.0 moved onto the shared SDK, removed Explain Changes and turned off subagents for a time</title>
<link>https://www.anchorterminal.com/tools/cline#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/cline#dep-2026-06-26-breaking</guid>
<pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
<category>change</category>
<description>Extension 4.0.0 moved onto the shared SDK, removed Explain Changes and turned off subagents for a time Source https://github.com/cline/cline/blob/main/CHANGELOG.md</description>
</item>
</channel>
</rss>
