v0.65.3

charmbracelet/crushv0.65.3May 4, 2026by github-actions[bot]

AI Summary

This is a bug-fix release for Crush v0.65.3 addressing three main issues: multi-session OAuth token refresh race conditions for Hyper and Copilot integrations, rendering performance improvements through better caching, and SQLite driver enhancements to prevent database corruption under concurrent sub-agents.

Key Highlights

  • Fixed multi-session token refresh race condition - Crush now checks disk for existing refreshed tokens before attempting OAuth refresh when multiple instances are running
  • Improved rendering performance on big sessions through internal caching enhancements
  • SQLite driver enhancements to prevent SQLITE_NOTADB corruption under concurrent sub-agents
  • Glamour renderers are now cached for better performance
  • Markdown cache invalidation now paired with styles mutation

Full Release Notes

# Small fixes

Hey all. This is just some small fixes to start the week.

## Fixed multi-session token refresh

Crush currently support two OAuth-based providers: Hyper and Copilot. For these integrations we need to refresh tokens once they expire.

We fixed an issue affecting users that have multiple Crush instances running at the same time. Before attempting to refresh a tokens, Crush will now look on the disk if it was already refreshed by another instance.

> [!TIP]
> Didn't know about Hyper yet? [Check out our announcement on the past release!](https://github.com/charmbracelet/crush/releases/tag/v0.65.2)

## Rendering performance

We did improvements on some internal caching to boost rendering performance on big sessions.

## SQLite enhancements

@taoeffect helped with enhancements on how our SQLite driver configuration. This will mitigate some edge cases we've seen where Crush databases could be corrupted.

See ya!
Charm

## Changelog
### Fixed
* 99bc5ce850c1da02207ceba39f92afee6cba73fa: fix(config): check config file for newer token before OAuth refresh (@andreynering)
* 401084133df3e7b1895de169c4b67aea0f72b572: fix(db): prevent SQLITE_NOTADB corruption under concurrent sub-agents (#2690) (@taoeffect)
* 19197e30864f22f1b7e29b9f005d3fe6d2bae728: fix(ui): cache glamour renderers (@meowgorithm)
### Other stuff
* ecebe91e2c3bd4882f53429bbfaec2a34ee22041: chore: auto-update files (@charmcli)
* 1ed6f5248c5eb8d86d002d22578b206a09e2ceed: refactor(ui): pair markdown cache invalidation with the styles mutation (@meowgorithm)

---

<details>
<summary>Verifying the artifacts</summary>

First, download the [`checksums.txt` file](https://github.com/charmbracelet/crush/releases/download/v0.65.3/checksums.txt) and the [`checksums.txt.sigstore.json` file](https://github.com/charmbracelet/crush/releases/download/v0.65.3/checksums.txt.sigstore.json) files, for example, with `wget`:

```bash
wget 'https://github.com/charmbracelet/crush/releases/download/v0.65.3/checksums.txt'
wget 'https://github.com/charmbracelet/crush/releases/download/v0.65.3/checksums.txt.sigstore.json'
```

Then, verify it using [`cosign`](https://github.com/sigstore/cosign):

```bash
cosign verify-blob \
  --certificate-identity 'https://github.com/charmbracelet/meta/.github/workflows/goreleaser.yml@refs/heads/main' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  --bundle 'checksums.txt.sigstore.json' \
  ./checksums.txt
```

If the output is `Verified OK`, you can safely use it to verify the checksums of other artifacts you downloaded from the release using `sha256sum`:

```bash
sha256sum --ignore-missing -c checksums.txt
```

Done! You artifacts are now verified!

</details>

<a href="https://charm.land/"><img alt="The Charm logo" src="https://stuff.charm.sh/charm-banner-next.jpg" width="400"></a>

Thoughts? Questions? We love hearing from you. Feel free to reach out on [X](https://x.com/charmcli), [Discord](https://charm.land/discord), [Slack](https://charm.land/slack), [The Fediverse](https://mastodon.social/@charmcli), [Bluesky](https://bsky.app/profile/charm.land).