You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fix (affects 1.5.0): a first-use model download from Hugging Face could not complete. Observed against the live Hub on 2026-10-03: non-LFS files redirect same-origin to /api/resolve-cache/models/<id>/<revision>/<file>, which the default network policy denied (POLICY_DENIED), and interrupted CDN downloads could never resume because the signed redirect URL changes per request and was compared as part of the object location. The exact pinned model/revision/file resolve-cache path is now trusted (size/SHA-256 verification unchanged) and resume matches by origin and path, including partial staging written by 1.5.0. Verified by a complete live prefetch of the pinned default profile with every file SHA-256 checked.
Fix (CI, Windows): the 1.5.0 remote CI run failed 3 of 22 jobs, all windows-2025, in npm run test:quality. The CLI test built its script path from URL.pathname (D:\D:\a\...), and Git's CRLF conversion changed the byte-hashed quality fixtures (LOCAL_FIXTURE_INTEGRITY). The path now uses fileURLToPath, and .gitattributes marks scripts/quality/fixtures/** as -text. The full remote CI matrix (19 of 22 jobs; the other 3 are opt-in real-model lanes that are skipped) passes on commit ef501ed, including all three windows-2025 jobs.
Fix (Windows): Node image inputs such as D:\photo.png were mistaken for URLs with a one-letter scheme and rejected as non-HTTP; drive-letter paths are now read as local paths (the same canonical file authorization applies). The cache permission test no longer asserts POSIX mode bits on Windows.
Add opt-in hybrid document retrieval: caller-supplied DocumentEmbedder, DocumentIndex.searchHybrid and askDocuments({ embedder, embedding }) combine BM25 with cosine ranking by reciprocal-rank fusion. Neko.js bundles no embedding model; embedder output is validated as untrusted, vectors are cached per index by content version under a fixed 128 MiB bound, and retrieval remains non-exhaustive.
Add runToolLoop: a bounded select, approve/execute, feed-back and re-infer loop over inferTools and executeToolCalls. Approval stays mandatory and sequential; calls requested by the terminal selection are returned, never executed.
Add opt-in onEvent observability: content-free request lifecycle and engine-load events (ids, timings, token counts, error codes, model identity). Observer failures never change request results; worker forwarding is best-effort.
Document every 1.5.0 API and the items above in the English and Traditional Chinese usage guides.
Packaging checks now fail on sync-conflict duplicate files (the working tree is iCloud-synced and produced * 2/* 3 copies) and bundle neko.js, neko.js/documents, neko.js/web and neko.js/report with esbuild under browser conditions.
Verified on macOS arm64, Node.js 26.7.0 CPU, default profile: 217 Node tests, 27 quality-tool tests, 21 browser contracts (Chromium, Firefox, WebKit), site smoke, packed-artifact check, the state-reuse smoke against the real model (cached continuation equal to baseline text and usage, branch isolation, abort leaves the cache unchanged, vision feature hits), one synthetic image OCR, one synthetic scanned-PDF OCR and native PDF extraction without inference. Remote CI passes its contract matrix on Linux, macOS and Windows for Node 22, 24 and 26 (the real-model lanes are opt-in and were not run). Observed, not asserted as quality: document QA on the PDF fixture returned insufficient-evidence, and a 128-token budget truncated structured JSON (STRUCTURED_OUTPUT). Not verified: browser WebGPU, browser PDF extraction, the new hybrid retrieval with a real embedding model, and real-model inference on other platforms.