Upgrading to TokenPak 1.27.0¶
Companion forecasts¶
Interactive tokenpak claude launches enable the native forecast footer by
default. Interactive tokenpak codex launches enable an owned tmux display pane,
starting a private tmux session when needed. Install tmux to use the Codex pane;
if it is missing, the default launcher explains this and starts Codex normally.
Use --status-surface=off to disable the TokenPak display. Use auto to preserve
a custom Claude status line and use an existing tmux session only. Saved client
settings remain intact. Noninteractive, print, exec and install-only commands
do not start the display. See terminal forecasts.
tokenpak status --line --session ID reads a compact forecast for an exact native
session. The same selector works for full and JSON economics. Private session
binding, bounded local reads, idle refresh and cache expiry prevent selecting
unrelated session history. Learning, no-data, stale and unavailable states stay
explicit. Estimates require eligible observations; they are not guaranteed bills,
calibrated savings claims or a substitute for measured spend.
Upgrade and rollback¶
Back up configuration and state using consistent database backups. Retain
previous artifacts and settings throughout the observation period. Install
tokenpak==1.27.0, preserving existing extras. The standard service profile uses
tokenpak[serve,tokens,telemetry]==1.27.0. Restart the relevant services after
checking active work has finished. Start a new companion launch to use the
default footer; running client sessions are preserved.
Pro users also need the separately distributed Pro 0.4.1 package, which supports OSS 1.26.0 through 1.27.0 with TIP-1.0. Pro 0.4.0 supports only OSS 1.26.0. Normative docs/schema pins, persisted economics and optional accounting settings are unchanged. The display adds no provider requests or automatic rerouting.
Rollback with pip install tokenpak==1.26.0, retaining the same extras, and
restore Pro 0.4.0 if rolling back the pair. Preserve newer state before restoring
any backup. Existing tags and published artifacts are never replaced.
Known security findings¶
This release accepts the open High NLTK advisory GHSA-8mgp-746c-j5xp in the optional compression/full and llamaindex integrations. NLTK 3.10.3 remains the latest published version with no listed fix. This is a new assessment for this release only; the finding remains open. The base and standard service profiles do not select NLTK. Optional embedding applications must avoid untrusted model import/export paths and must not rely on pathsec to confine those APIs.
The separate Moderate Accelerate 1.14.0 advisory GHSA-4j2p-28q2-5m79 affects untrusted sharded checkpoint paths in optional compression/full integrations. Use trusted model repositories and checkpoints. This is separate tracked debt, not part of the NLTK exception. See SECURITY.md for the scope and limits. Audits and all other release checks remain required.
Validation and completion¶
The release uses focused companion, exact-session privacy, CLI, artifact, installed-version, local proxy, upgrade and rollback checks, plus required hosted CI. Native terminal rendering was exercised with Claude Code and Codex at three widths using local fixtures without provider prompts. Fixtures do not establish empirical forecast calibration or human comprehension. Publication, deployment and the 24-hour observation period are separate milestones.