Download Latest Version kilo-darwin-arm64.zip (50.0 MB)
Email in envelope

Get an email when there's a new version of Kilo Code

Home / v7.1.23
Name Modified Size InfoDownloads / Week
Parent folder
kilo-vscode-darwin-arm64.vsix 2026-04-07 54.1 MB
kilo-vscode-win32-arm64.vsix 2026-04-07 71.4 MB
kilo-vscode-win32-x64.vsix 2026-04-07 73.1 MB
kilo-vscode-alpine-arm64.vsix 2026-04-07 69.3 MB
kilo-vscode-alpine-x64.vsix 2026-04-07 69.2 MB
kilo-vscode-darwin-x64.vsix 2026-04-07 55.6 MB
kilo-vscode-linux-arm64.vsix 2026-04-07 71.9 MB
kilo-vscode-linux-x64.vsix 2026-04-07 71.9 MB
README.md 2026-04-07 1.2 kB
v7.1.23 source code.tar.gz 2026-04-07 70.7 MB
v7.1.23 source code.zip 2026-04-07 73.1 MB
kilo-windows-arm64.zip 2026-04-07 66.4 MB
kilo-windows-x64-baseline.zip 2026-04-07 68.3 MB
kilo-darwin-x64-baseline.zip 2026-04-07 51.8 MB
kilo-windows-x64.zip 2026-04-07 68.3 MB
kilo-darwin-x64.zip 2026-04-07 51.8 MB
kilo-darwin-arm64.zip 2026-04-07 50.0 MB
kilo-linux-x64-baseline-musl.tar.gz 2026-04-07 64.8 MB
kilo-linux-arm64-musl.tar.gz 2026-04-07 64.5 MB
kilo-linux-arm64.tar.gz 2026-04-07 67.1 MB
kilo-linux-x64-baseline.tar.gz 2026-04-07 67.5 MB
kilo-linux-x64-musl.tar.gz 2026-04-07 64.8 MB
kilo-linux-x64.tar.gz 2026-04-07 67.5 MB
Totals: 23 Items   1.4 GB 0

Core

  • Guard against prompt injection in commits
  • Add scope context and better git commands to review prompt
  • Inject --rm flag for Docker MCP containers to prevent accumulation (@johnnyeric)
  • Comment out specific conditions in ID check logic
  • Add support for GLM, Kimi, and Qwen reasoning models
  • Follow-up execution is now aware of the saved plan file (@shssoichiro)
  • Update minimatch, @modelcontextprotocol/sdk, and @aws-sdk dependencies
  • Update Hono to fix authentication bypass and server vulnerabilities
  • Update simple-git dependency to fix critical remote code execution vulnerability
  • Preserve specific MCP tool rules when propagating permissions to sub-agents
  • Propagate MCP restrictions to sub-agents alongside edit and bash
  • Preserve inherited restrictions across multi-hop sub-agent chains
  • Apply read-only bash and MCP restrictions to plan mode and propagate bash restrictions to sub-agents
  • Plan mode now respects edit restrictions and sub-agents inherit caller's file access permissions

Thank you to 2 community contributors:

  • @shssoichiro:
  • fix(core): make follow-up execution aware of the saved plan file
  • @johnnyeric:
  • fix(mcp): inject --rm flag for Docker MCP containers to prevent accumulation
Source: README.md, updated 2026-04-07