Skip to content

DevProjex v5.2

Latest

Choose a tag to compare

@Avazbek22 Avazbek22 released this 01 Oct 22:34
· 2 commits to master since this release

🚀 What’s New

  • Added Live Context. Connect an agent in Live context mode and it works with the files checked in the DevProjex tree: checked files and folders are its focus, and the filters applied in the window remain the limit of what it can read. Changes apply on the agent’s next call without restarting the session, and the window does not have to stay open.

  • Added one-step MCP client connection. The new Desktop MCP menu, the Terminal Workspace :mcp connect command, and devprojex mcp connect register DevProjex for Claude Code, Codex, Cursor, or VS Code in Live context or Standard mode. Other clients… and --print show a ready configuration for Claude Desktop and any other MCP client.

  • Added the Agent journal — a local history of MCP sessions with the client, mode, calls, estimated tokens, delivered files, and masked values. Any session can be exported as a Markdown or JSON context receipt. File contents, detected secrets, and search text are never stored. Open it from MCP → Journal…, :mcp log, or devprojex mcp log.

  • Added Agent activity. Turn on View → Agent activity and files delivered to a live agent are marked with ✦ in the project tree; the tooltip shows how many times the agent received each file. The Terminal Workspace marks them with A.

  • Added Related files — a static dependency index that answers “what does this file use, and what uses it” for C#, TypeScript and JavaScript, Python, Go, Java, Kotlin, Rust, Ruby, PHP, C and C++, Bash, and Scala. Every link carries its evidence, and ambiguous names are never guessed. Available as the related_files MCP tool, devprojex related, and :related.

  • Added project search to the CLI and Terminal Workspace. devprojex search and :grep find text, regular expressions, or declarations by name with --symbols, and name the declaration each match sits in.

  • Added importance-aware packing (experimental). rank: "importance" in MCP and --rank importance in the CLI and Terminal Workspace spend a token budget on the most important files first; focus orders files by their distance from the ones you name.

  • Added new distribution channels: a Linux AppImage for x86_64 and aarch64, headless archives for Windows, Linux, and macOS on x64 and arm64, a container image at ghcr.io/avazbek22/devprojex, and no-install launch with npx devprojex and dnx devprojex.

🤖 MCP Server

  • Eight read-only tools: list_projects, get_tree, analyze, search_project, related_files, get_file, pack_context, and read_pack.

  • search_project names the declaration each match sits in and includes the body of the best-matching declaration — 1,800 characters by default, adjustable with --search-body-chars. symbols: true searches declaration names such as class Client or Foo|Bar.

  • get_file reads up to eight files and sixteen ranges or declarations in one call through requests, and reads a declaration by name through symbol. An ambiguous name lists the candidate line ranges.

  • pack_context mixes detail levels in one pack with detail_by_pattern and packs files together with their statically resolved neighbours through expand_related.

  • analyze with max_tokens previews which files a budget would admit without producing any content.

  • Large search and dependency results are stored for the session and read back in line ranges through read_pack, like oversized packs.

  • Every result states what was searched and what was cut. A trusted [Search boundary] line tells a complete search from a partial one, and empty selections, active filters, and skipped binary files are reported, never silent. Trusted status lines repeat only when they change.

  • Refusals name the next step: a directory passed to get_file returns the get_tree call that lists it, and several ranges point to the batch form. Every error code is listed in one documented catalog.

  • Brace globs such as src/{api,core}/** select several directories in one pattern.

  • New startup options: --live, --exclude with the default and none tokens, --unrestricted, --allow-agent-exclusions, --remote-hosts, --tool-set reduced, and --search-body-chars.

  • Projects can be addressed as #0 when there is one root, by a unique name, or with the Windows file-URI spelling /C:/path.

  • A lighter tool catalog and fewer calls per task: shorter descriptions, no output schemas, and JSON that escapes only what JSON requires.

⌨️ Command Line and Terminal Workspace

  • Added devprojex search with plain-text, --regex, and --symbols modes, declaration context, and JSON output.

  • Added devprojex related for the files a file uses and the files that use it.

  • Added devprojex mcp connect and devprojex mcp log for client setup and the agent journal from scripts.

  • export context accepts --detail-for "<glob>=<level>" for mixed detail in one document, plus --rank importance and --focus.

  • Added Terminal Workspace commands :select, :open, :profile load|show|reset, :grep, :related, :reveal, :mcp connect, :mcp log, and :set activity. :copy and :export context accept --max-tokens and --rank importance.

  • The Welcome screen command line accepts open, recent, language, help, and quit.

  • The status line shows Live context (<client>) while a live agent is connected.

  • Reworked mouse input: every click is exactly one action, a checkbox changes only from its marker, and Git mode rows act as radio buttons. Selection, dialogs, the command line, Preview, and layout received a broad round of fixes.

✨ Improved

  • The checked tree is saved per project and restored when the project is reopened, in Desktop and the Terminal Workspace alike.

  • The main window title shows the connected live client or the number of live sessions.

  • After a successful client connection, an optional dialog offers terminal PATH setup.

  • Message dialogs size to their text and scroll long messages.

  • Notifications stay visible long enough to read, pause on hover, and close on click. A successful connection that opens the client no longer shows a notification.

  • Icon-only buttons, options, tree rows, and journal rows now have names for screen readers.

  • Long settings labels fit on one line in every interface language.

  • Desktop project loading does much less repeated work: fewer file opens, far fewer allocations, and responsive metrics on large selections.

  • Secret detection no longer treats assignments such as password=<identifier> in ordinary source code as credentials.

  • Structured secret values in dotenv, connection strings, JSON, YAML, XML, Python, Dockerfile, .netrc, and .npmrc are masked within their format’s own boundaries; quotes, delimiters, and neighbouring fields stay intact.

  • Hide private data also masks the project root shown in context documents and absolute paths in diagnostics.

  • Code Compression reports a missing or unusable grammar with DPX-COMPRESSION-UNAVAILABLE and keeps the affected files complete; Desktop marks the compression switch instead of failing silently.

🛡️ Security and Reliability

  • Git process safety. Opening a repository never runs programs configured inside it. Every Git call uses a fixed safety profile that disables fsmonitor, hooks, clean, smudge, and process filters, external diff and textconv, pagers, aliases, and credential helpers, and Git is never resolved from inside the project. This applies to Desktop, Terminal Workspace, CLI, and MCP.

  • The changes scope refuses a comparison that would need a repository-defined clean or process filter (DPX-GIT-UNSAFE-FILTER) instead of running it.

  • MCP refuses a project path that names a network host before touching the file system, so no connection to that host is attempted.

  • Remote Git sources refuse the local file:// transport, and --remote-hosts limits MCP remote access to the named hosts without following redirects.

  • Inline markers such as gitleaks:allow in project content no longer exempt it from redaction. Redaction exceptions are controlled only by the operator.

  • Code transformations cannot weaken redaction: detection runs on both the source and the transformed text, and the union is masked.

  • Profile and client configuration writes are atomic, and a corrupt profile store is never overwritten. The journal recovers from truncated or deleted files and reports lost events instead of hiding them.

  • Cursor and VS Code configuration merges keep other servers and change an existing DevProjex entry only with --replace.

⚠️ Behavior Changes

  • MCP default filters. A server started without exclusion flags now applies only smart-ignore and empty-folders, so agents see dot-files, .github/, Dockerfile, LICENSE, and empty files the way Git does. Use --exclude to choose the set, or --exclude default --exclude <token> to extend it.

  • .gitignore mode follows git status. An undeclared embedded repository is one opaque folder, declared submodules use their own ignore rules, and .git/info/exclude is read. Turn Git filtering off (--git-mode none, or --unrestricted in MCP) for the previous view.

  • The .git folder is excluded in every Git mode, including when Git filtering is off.

  • MCP results are text only. list_projects and analyze no longer declare outputSchema or return structuredContent; their JSON is returned as protected text and now always includes baseline and exclusions. Clients that read the structured result should parse the text.

  • Unsupported glob syntax is rejected. ! negation and [...] classes in MCP patterns used to match nothing silently; they now fail with DPX-MCP-INVALID-PATTERN.

  • Portable profiles use schema 2: null means “all” and [] means “none”. Version 1 files are still read.

  • The Microsoft Store package requires Windows 10 version 1903 (build 18362) or newer, so the Store app and the terminal share the same project profiles.

🐞 Fixed

  • Fixed Code Compression being unavailable in the Microsoft Store build, which shipped without its grammars.

  • Fixed a mouse click in the Terminal Workspace tree toggling a checkbox twice.

  • Fixed devprojex open switching the Desktop interface to the terminal’s language.

  • Fixed JSON and XML context exports with the content view, and the matching pack_context output, naming files by absolute path instead of project-relative path.

  • Fixed error headers appearing in English when the terminal uses another interface language.

  • Fixed long message-dialog text being cut off.

  • Fixed project export to a folder or ZIP dropping Unix file modes and executable bits.

  • Fixed selection, profile, and journal state racing with project switches, window closing, and cancellation in Desktop and the Terminal Workspace.

⚙️ Technical

  • Updated the pinned .NET SDK from 10.0.303 to 10.0.400.

  • Updated Avalonia from 12.1.1 to 12.1.3, with upstream fixes for theme switching, ghost list rows, popup placement, and Linux and macOS desktop reliability.

  • Added a Tree-sitter dependency index shared by the CLI, Terminal Workspace, and MCP.

  • Added a closed Git operation registry with three safety profiles: local read, managed checkout, and explicit network.

  • Vendored native grammars are built from pinned sources and verified by hash on every platform.

  • Added a release-candidate workflow that runs every gate against one pinned commit, with completeness gates and real-entry-point smoke tests for the AppImage, headless archives, npm, NuGet, container, and Store packages.

🧪 Quality

  • DevProjex now contains more than 20,000 automated test cases across Unit, Integration, Terminal, and UI projects.

  • MCP is tested as a real process through the official C# client, and the connection payload is held to a fixed budget.

  • Dependency facts are validated against pinned real-world repositories.

  • A contract test keeps the error-code catalog in sync with the sources.

📝 Notes

  • Importance ranking is experimental. Without rank or --rank, output order is unchanged.

  • Related files are static: runtime dependency injection, generated code, templates, and Python import hooks are not inferred, and an ambiguous name stays unresolved instead of being guessed.

  • In Live Context the window’s filters are the access boundary. A file outside the checked focus can still be read by name when those filters allow it, and the response says so.

  • The agent journal stays on this computer. Its token counts are estimates derived from returned characters.

  • The npm and NuGet packages and the container image contain the CLI, Terminal Workspace, and MCP server, but not the desktop application. npm requires Node.js 20 or later and glibc on Linux; dnx requires the .NET SDK 10.0.100 or later.