Skip to content

Releases: Lee-take/dsagent

DS Agent v1.3.0

Choose a tag to compare

@Lee-take Lee-take released this 19 Jul 15:36
4eab7f9

DS Agent v1.3.0 publishes Step 3 exact-task grouped authorization from exact main commit 4eab7f90dba81bbc70ad7076b6e42186f1383121.

Exact-task authorization

  • A normal queued chat task may carry a bounded descriptive capability proposal; only the local Kernel validates/freezes the same Goal and derives the manifest, risk, and preview.
  • The matching chat message displays one Kernel-derived authorization card for that exact task.
  • Approve, reject, and revoke bind the exact task, group, projection, manifest, preview, revision, fingerprint, hash, expiry, scope, and target; per-capability audit remains durable.
  • Approval creates exact authority only. It does not execute a Tool, resume a task, create an external effect, or mark the Goal complete.
  • Malformed, stale, cross-task, scope/target-changed, expired, rejected, revoked, tampered, secret/path/provider-reference/claim/token input fails closed.

This release does not add automatic task execution/resume, an Office golden path, connector or Computer Use expansion, background external writes, or production account access.

Reproducible Windows package

The previous independent builds were blocked because GNU COFF symbol/string tables embedded target-specific temporary paths, PE headers contained build timestamps, and NSIS stored payload mtimes. v1.3.0 strips the target-path-bearing symbol table, omits linker PE timestamps, and excludes variable payload mtimes from NSIS.

Two final fresh, distinct CARGO_TARGET_DIR builds were byte-identical:

  • ds-agent.exe: 34,253,824 bytes
  • application SHA-256: 342C0DABDB9AD3401496E8F7A11D63841CECD604AADBC3B18CAE5EDC3AE997AA
  • DS.Agent_1.3.0_x64-setup.exe: 11,323,811 bytes
  • installer SHA-256: 7EB672A7AE1030AF992A84169FED696636FAB46AEA3CEB4EC96A37FDF9EA27ED

Verification

Unsigned release

Both the application executable and installer are intentionally Authenticode NotSigned; there is no signer. Windows may show Unknown publisher or Microsoft Defender SmartScreen. Download only over HTTPS from this Release and verify the exact byte size and SHA-256 above before running it.

The SignPath Foundation application remains submitted and approval is pending. This Release is not represented as signed or SignPath-approved. If signing becomes available later, it begins with a subsequent new version and does not replace this immutable tag, Release, or asset.

No real API key, production account, paid API, production tenant, installed DS Agent overwrite, or external target was used in release verification.

DS Agent v1.2.0

Choose a tag to compare

@Lee-take Lee-take released this 19 Jul 07:01
02ea26f

DS Agent v1.2.0

DS Agent v1.2.0 is the stable Step 2 GoalEnvelope release for Windows x64.

Unsigned Windows release: both the packaged ds-agent.exe and DS.Agent_1.2.0_x64-setup.exe are intentionally Authenticode NotSigned, with no signer certificate. Windows may display Unknown publisher or a Microsoft Defender SmartScreen warning. Download only over HTTPS from this official Release and verify the SHA-256 before running the installer. This Release is not represented as signed or SignPath-approved.

What is included

  • DeepSeek can propose the bounded, versioned ds-agent.goal-envelope-proposal/v1 contract, but cannot grant authority or declare completion.
  • The local Kernel alone validates capabilities, readiness, policy, verifiers, workspace/target bindings, revisions, and fingerprints, then freezes the accepted envelope.
  • Existing databases receive additive lifecycle and completion projection tables. Legacy v1.1.0 data defaults to no goal and not complete; duplicate/restart processing is idempotent.
  • Chat receives only a bounded read-only goal projection. The frontend cannot write validation, freeze, evidence, or completion authority.
  • Completion requires authoritative passing evidence bound to the exact goal, frozen revision/fingerprint, verifier, done-when condition, evidence kind, and required artifact identity. Missing, failed, stale, wrong, unknown, duplicate, or mismatched evidence fails closed.
  • Secret, provider-body, absolute app-data/vault path, local-authority, internal-claim, and false-completion leakage guards remain enforced.

Exact source and release identity

  • Source commit: 02ea26fc92c932ab9fc263e2e19a98a18547792a
  • Pull request: #12
  • PR CI: 29676296609 — success
  • Exact-main CI: 29676628870 — success
  • Annotated tag: v1.2.0 (immutable; peels to the exact source commit above)
  • Sole asset: DS.Agent_1.2.0_x64-setup.exe
  • Asset size: 12,859,905 bytes
  • Asset SHA-256: 43871c0b8a8a7e40da120f48635fd02c1314ca53afb1df2b1f29390647212c90
  • Installer product/file version: 1.2.0
  • Installer Authenticode: NotSigned; signer: none
  • Packaged ds-agent.exe: 44,985,449 bytes; SHA-256 f8aa5be3126d77a18b46946ddef67d6fe3b5539bcfce3a96031ec80f590f1b6f; product/file version 1.2.0; Authenticode NotSigned; signer: none
  • Exact-main standalone exe before Tauri's three-byte NSIS bundle-marker patch: 44,985,449 bytes; SHA-256 47c2bb3ff2f728fb633770564d8f50a1c988881850b5c2797e79d12d84c19851; Authenticode NotSigned; signer: none

Verification

Focused GoalEnvelope proposal/lifecycle/completion/UI tests, production frontend build, cargo fmt --check, the complete pinned pnpm@9.15.9 test, release-source and secret scans, migration/restart/idempotence/fail-closed regressions, isolated candidate and exact-main packaged UI/workflow smoke, PR CI, and exact-main CI all passed. The full local suite reported 919 passed, 7 deliberately ignored live/installed-dependency tests, and 0 failed. No real API key, paid API/resource, production account, user DS Agent AppData, or installer execution was used. The cancelled formal 20-run Windows lab was not performed and is not claimed.

Scope boundary

This Release does not include Step 3/C3A, grouped authorization, a new Office executor, connector or Computer Use expansion, production external accounts, or new external-write authority. Microsoft/Google production registration and live mail/calendar writes remain disabled.

The SignPath Foundation application remains submitted/pending. If approval arrives later, signing starts only with a subsequent new version; the immutable v1.1.0 and v1.2.0 tags, Releases, and assets will not be moved, overwritten, or replaced.

DS Agent v1.1.0

Choose a tag to compare

@Lee-take Lee-take released this 19 Jul 05:18
31f9e6e

DS Agent v1.1.0

Windows unsigned release: ds-agent.exe and the x64 NSIS installer are intentionally Authenticode NotSigned. Windows may show Unknown publisher or a Microsoft Defender SmartScreen warning. This release is not code-signed or SignPath-approved.

Download only over HTTPS from this official GitHub Release and verify the installer before running it:

  • File: DS.Agent_1.1.0_x64-setup.exe
  • Version: 1.1.0
  • Size: 12,720,779 bytes
  • SHA-256: 392841dfed6936d91e62fe5b41c32b27f0b546d64e84700b3be72d0c47014502
  • Source commit: 31f9e6e5fe45b254a2c81d959c9b900c098b0ece
  • Tag: annotated v1.1.0, pointing to that exact source commit

What is included

  • One user-supplied DeepSeek API Key stored in a dedicated Windows DPAPI-protected vault, with the environment Key retained only as an explicit compatibility fallback.
  • Explicit DeepSeek authentication/balance and deepseek-v4-flash / deepseek-v4-pro availability verification.
  • Secret-free readiness and stable repair codes; ordinary UI, events, logs, work packages, and release evidence exclude raw Keys, provider response bodies, account details, balance amounts, and absolute vault paths.
  • Workspace doctor with a bounded writability probe and managed directory setup.
  • V4 Flash/Pro release-smoke defaults and isolated-profile hygiene for APPDATA, LOCALAPPDATA, WebView2, workspace, and reports.

Existing workspace settings remain readable, environment-only operators remain supported after explicit verification, existing conversations are not rewritten, and connector credential vaults are untouched.

Scope

This is the C1B Step 1 onboarding/readiness release only. It does not include GoalEnvelope or any Step 2 work, Office executor work, connectors, Computer Use, automation, external accounts, or external writes. DS Agent is an independent open-source project and is not an official DeepSeek product.

The SignPath Foundation application remains submitted/pending. If approved later, signing will begin only with a subsequent new version; this v1.1.0 tag, Release, and asset will not be moved, overwritten, or replaced.

Release verification covered focused and full tests, production frontend build, Rust formatting, migration/recovery regressions, release-source and secret scans, isolated candidate/final UI and workflow smoke, PR CI, exact-main CI, and the final source/tag/asset/Latest/fresh-download binding checks. No formal 20-run Windows lab is claimed.

DS Agent v1.0.2

Choose a tag to compare

@Lee-take Lee-take released this 16 Jul 06:15

DS Agent v1.0.2

v1.0.2 is an urgent compatibility and trust/UI patch for the stable DS Agent
1.0 line. It fixes two user-visible regressions reported against the published
v1.0.1 desktop app. The v1.0.1 commit, tag, Release, notes, and installer
remain immutable.

Package, desktop, Tauri and Cargo metadata are 1.0.2, and the updater identity
is v1.0.2.

User-facing reply isolation

  • Fenced DeepSeek protocol responses that use subagent_plan: null are parsed
    as an empty optional plan instead of falling back to raw text.
  • Protocol JSON is never shown in place of the user-facing reply when another
    optional envelope field has an unexpected shape. DS Agent extracts only
    reply_to_user; malformed or incomplete actions remain fail-closed and are
    not executed.
  • Previously saved affected messages are cleaned at presentation time after the
    updated app starts. Conversation storage is not silently rewritten.

Run-step terminal state

  • The right-side workflow inspector now selects the latest parent run from the
    active conversation. Once that durable run is complete, the six fixed steps
    converge to Done / 已完成 instead of retaining stale waiting states.
  • Calling DeepSeek with the user's configured API Key is not a per-run approval
    action. A missing or unusable DeepSeek configuration is shown as blocked, not
    as a permission confirmation request.
  • This patch does not weaken approval policy for local writes, Computer Use,
    external effects, or other risk-bearing capabilities. The Kernel remains the
    authority for permission, execution, evidence, audit, verification, and
    recovery.

Scope and compatibility

This patch adds no new connector, Computer Use, automation, memory, Subagent,
or Skill feature. A valid DeepSeek API Key supplied by each user remains
required. Production Microsoft/Google account registration and live external
writes remain disabled.

Windows download and integrity

  • Asset: DS.Agent_1.0.2_x64-setup.exe
  • File and product version: 1.0.2
  • Architecture: Windows x64
  • Authenticode status: unsigned (NotSigned)

Verify the final byte size and SHA-256 against the published GitHub Release
before running the installer. The installer embeds the Microsoft WebView2
bootstrapper.

The release artifact was built and inspected without launching the installer
or changing the installed DS Agent application or its data.

The final offline release gate covers the source secret scan, TypeScript/Vite
production build, focused reply/run-state regressions, all Node/UI checks, the
source-only release guard, and the complete Rust suite. Live DeepSeek and
installed Office/rendering checks remain separately permission-gated.

Deterministic briefing fixtures

For deterministic Operations Briefing checks,
docs/templates/operations-briefing-smoke-evidence contains the warning
SMOKE SAMPLE evidence for local verification only and every file says
Replace before operational use. The bundled smoke files are marked as
non-operational test data. Separately,
docs/templates/operations-briefing-evidence contains blank operator templates
that the desktop can seed into a user-selected evidence folder.

Code signing policy

DS Agent v1.0.2 remains unsigned and its Authenticode status is NotSigned.
It is not represented as a signed release.

For future releases accepted into the open-source signing program: Free code
signing provided by SignPath.io, certificate by SignPath Foundation.
See the
Code signing policy
and Privacy policy.

Immutable v1.0.2 asset identity:

  • Size: 12,714,353 bytes
  • SHA-256: 21459D5A8CFF2606171CBD52B9D5508A40434101693BEFA81E8DC2D9EBF50E3D

DS Agent v1.0.1

Choose a tag to compare

@Lee-take Lee-take released this 15 Jul 15:32
496fba3

DS Agent v1.0.1

v1.0.1 is a focused patch release for the first stable DS Agent 1.0 line. It
fixes an approval-surface regression found in the published v1.0.0 desktop
app and adds visible creator/maintainer attribution. The v1.0.0 commit, tag,
Release, notes, and installer remain immutable.

Package, desktop, Tauri and Cargo metadata are 1.0.1, and the updater identity
is v1.0.1.

Approval UI fix

  • Historical pending capability records are no longer inserted as one global
    approval block beneath an unrelated active conversation. An ordinary
    knowledge question therefore cannot inherit old browser, file, update, or
    other approval rows merely because they remain pending in local history.
  • Chat approval controls now belong to the assistant message and exact
    permission_request_id values that proposed the actions. A task with no
    action awaiting confirmation shows no approval controls.
  • When one task needs several permissions, DS Agent shows one explanatory
    sentence and one Confirm and run / Reject decision pair. One click
    resolves every permission record for that task before its actions resume in
    order. The Kernel still retains separate capability decisions and audit
    records underneath that single user decision.
  • Rejecting once blocks every action awaiting approval for that task. Partial
    failures refresh current permission state so a retry does not blindly repeat
    already completed decisions.
  • Legacy manual capability requests remain actionable only in their own
    capability card. Task-bound and exact-tool approvals are excluded from those
    generic cards, preventing duplicate approval surfaces.

The patch does not silently delete, approve, or reject historical local
records. Existing v1.0.0 app data remains under the user's control.

Attribution and release identity

  • Lee take is visible as the creator and maintainer in Settings.
  • Root, desktop, Rust package, and Windows application metadata consistently
    identify version 1.0.1 and the supported publisher attribution.
  • This attribution is not a digital signature. The Windows installer and
    application remain unsigned and may show an unknown-publisher warning.

Model and authority boundary

A valid DeepSeek API Key supplied by each user remains required. DS Agent does
not bundle a shared key or bypass DeepSeek access requirements. DeepSeek owns
open-ended understanding, planning, analysis, and synthesis; the DS Agent
Kernel owns deterministic validation, approval, execution, evidence, audit,
verification, and recovery.

Production Microsoft/Google account registration and live external-write
authority remain disabled. This patch does not sign in to real accounts, send
real email, or create, change, or cancel real calendar events.

Windows download and integrity

  • Asset: DS.Agent_1.0.1_x64-setup.exe
  • Size: 12,716,857 bytes
  • SHA-256: 469C4EFA54F4C94A6E37D28C9C88D331B26E1770C6792DC93D02B451640E2A6F
  • File and product version: 1.0.1
  • Architecture: Windows x64
  • Authenticode status: unsigned (NotSigned)

The installer embeds the Microsoft WebView2 bootstrapper. The release artifact
was built and inspected without launching the installer or changing the
installed DS Agent application or its data.

The offline release gate covers the source secret scan, TypeScript/Vite
production build, focused approval interaction checks, all Node/UI checks, and
852 Rust tests: 845 passed, seven permission-gated live/GUI tests were
intentionally ignored, and zero failed.

Deterministic briefing fixtures

For deterministic Operations Briefing checks,
docs/templates/operations-briefing-smoke-evidence contains the warning
SMOKE SAMPLE evidence for local verification only and every file says
Replace before operational use. The bundled smoke files are marked as
non-operational test data. Separately,
docs/templates/operations-briefing-evidence contains blank operator templates
that the desktop can seed into a user-selected evidence folder.

DS Agent v1.0.0

Choose a tag to compare

@Lee-take Lee-take released this 15 Jul 10:01

DS Agent v1.0.0

v1.0.0 is the first stable DS Agent 1.0 release. It evolves the published
v0.9.0 foundation without rewriting or moving any earlier commit, tag,
Release, or asset.

Package, desktop, Tauri and Cargo metadata are 1.0.0, and the updater identity
is v1.0.0.

Highlights

  • Kernel-owned lifecycle projections cover Chat, Agent, Automation, Tool,
    Connector, Artifact, Computer Use, and Expert Team work without moving
    business state into Tauri commands or React components.
  • Review and Recovery use Kernel-issued opaque actions bound to exact revisions.
    Approved local file changes have durable before/after checkpoints, verified
    one-shot undo, stale-action rejection, and restart-safe no-replay behavior.
  • Recurring Automation and Microsoft/Google-shaped connected work share typed
    intent, health, read/sync, private local draft, mutation, reconciliation, and
    crash-repair contracts. Adversarial fake providers prove timeout/restart
    idempotency and a provider apply count of one.
  • Chinese and English chat can draft mail or propose a calendar event, present a
    human-readable review card, and approve the exact revision.
  • Connected-work approval/start and successful provider completion/private
    projection consumption are atomic. Startup repair handles interrupted work
    without replaying external effects.
  • Migration and privacy tests cover legacy schema upgrades, malformed-row
    starvation resistance, stale generations, late results, repeated approvals,
    dynamic secret markers, and private absolute paths.
  • Approval cards now appear at the bottom of the auto-scrolling DS Agent chat
    thread with visible Confirm and run and Reject actions. The right rail
    remains a read-only status surface.
  • Scenario Templates and Task Records and Work Packages remain implemented but
    are hidden from the ordinary Plugins sidebar to keep the main experience
    focused.

Model and authority boundary

DeepSeek owns open-ended understanding, planning, analysis, and synthesis. The
DS Agent Kernel owns deterministic validation, approval, execution, evidence,
audit, verification, and recovery. Credentials and provider-private content do
not become ordinary event, export, model-context, or UI data.

Production Microsoft/Google account registration and external-write authority
remain disabled in this release. Validation uses offline data and adversarial
fake providers; it does not use real accounts, activate a live provider, send
email, or create, modify, or cancel real calendar events.

Windows download and integrity

  • Asset: DS.Agent_1.0.0_x64-setup.exe
  • Size: 12,714,575 bytes
  • SHA-256: 3B944589C8443A677AF55F8748C06A4D6EBA4ACE86E63E302D5782D5A5E548E4
  • File and product version: 1.0.0
  • Architecture: Windows x64

The installer is currently unsigned, so Windows may show an unknown-publisher
warning. It embeds the Microsoft WebView2 bootstrapper. The final artifact was
built and inspected without launching the installer or changing installed app
data.

The offline release gate passed the 192-file secret scan, TypeScript/Vite
production build, all Node/UI checks, and 852 Rust tests: 845 passed, seven
permission-gated live/GUI tests were intentionally ignored, and zero failed.

Deterministic briefing fixtures

For deterministic Operations Briefing checks,
docs/templates/operations-briefing-smoke-evidence contains the warning
SMOKE SAMPLE evidence for local verification only and every file says
Replace before operational use. The bundled smoke files are marked as
non-operational test data. Separately,
docs/templates/operations-briefing-evidence contains blank operator templates
that the desktop can seed into a user-selected evidence folder.

DS Agent v0.9.0

Choose a tag to compare

@Lee-take Lee-take released this 15 Jul 04:16
5b89624

DS Agent v0.9.0 Release Notes / 正式版说明

Status: Windows-first stable release. Repository:
https://github.com/Lee-take/dsagent

状态:Windows 优先正式版本。项目地址:
https://github.com/Lee-take/dsagent

Release Identity / 发布身份

Package, desktop, Tauri and Cargo metadata are 0.9.0, and the updater
identity is v0.9.0. Installed v0.5.0, v0.8.0-rc.1 and v0.8.0 clients
can detect this stable release. A v0.9.0 client does not treat an equal or
lower version as an update.

package、desktop、Tauri 和 Cargo 元数据均为 0.9.0,updater 当前身份为
v0.9.0。已安装的 v0.5.0v0.8.0-rc.1v0.8.0 可以发现本正式版;
v0.9.0 不会把相同版本或更低版本当作更新。

Published historical tags and Releases remain immutable. v0.9.0 is a new
commit, annotated tag and installer asset rather than a moved release label.

既有公开 tag 与 Release 保持不可变。v0.9.0 使用新的 commit、annotated tag 与
安装包资产,不移动任何历史发布标签。

Expert Team / 专家团队

Complex tasks can now run as one bounded Expert Team while ordinary chat still
shows one parent task and one final answer.

复杂任务现在可以作为一个有界“专家团队”运行,同时普通对话仍只呈现一个父任务和一份
最终答案。

  • DeepSeek plans two to four distinct Research, Analysis, Production and Review
    roles when specialist collaboration materially helps the task.

  • Research and Analysis are read-only. Production writes only to isolated,
    run-scoped staging. Review is read-only and must accept or reject the exact
    Production revision.

  • DS Agent persists immutable attempt contracts, dependencies, evidence,
    budgets, retry lineage, conflicts, quality gates and merge receipts.

  • At most three dependency-ready experts run concurrently. Read/write resource
    conflicts are serialized and nested expert teams are rejected.

  • Failed work creates a bounded new attempt instead of rewriting history. The
    parent cannot synthesize success until every latest deterministic gate passes.

  • Final merge authority remains with DS Agent. Staged bytes and hashes are
    reverified immediately before one exact merge receipt is recorded.

  • 当专家协作确实有帮助时,DeepSeek 可以规划二到四个不同的研究、分析、制作与审核角色。

  • 研究与分析保持只读;制作只能写入每次运行隔离的暂存区;审核保持只读,并且必须针对
    准确的制作版本给出接受或拒绝结论。

  • DS Agent 持久记录不可变任务约定、依赖、证据、预算、重试谱系、冲突、质量闸门与
    合并回执。

  • 最多三个依赖已满足的专家并发运行;读写资源冲突会串行化,嵌套专家团队会被拒绝。

  • 失败工作通过有界的新 attempt 继续,不改写历史;所有最新确定性闸门通过前,父任务
    不能合成成功结论。

  • 最终合并权仍属于 DS Agent;合并前会重新校验暂存内容与摘要,只记录一次准确回执。

Durable Soul Across Conversations / 跨对话 Soul

Explicit identity and collaboration settings now persist in the same chat turn
and are reloaded for new conversations.

用户明确设定或确认的身份与协作信息现在会在同一轮对话中持久化,并在新对话中重新载入。

  • Defines exact roles for the user's own name, how DS Agent addresses the user,
    the user's name for DS Agent and DS Agent's self-reference.

  • Explicit definitions, changes and immediately bound short confirmations can
    write Soul without a second confirmation.

  • DS Agent requires exact current-message evidence, an allowed field, bounded
    content and sensitivity checks before writing.

  • A visible success receipt appears only after both memory/soul.md and its
    append-only audit event are durable. Audit failure rolls the file back.

  • Unknown, sensitive, unbound, read-only expert or storage-unavailable updates
    fail closed and explicitly report that nothing was saved.

  • New and already-created empty conversations refresh the latest Soul before
    their first message; chat-history compression cannot erase the profile.

  • 明确区分用户姓名、DS Agent 对用户的称呼、用户对 DS Agent 的称呼以及 DS Agent 自称。

  • 明确的设定、修改和与上一条助手提议准确绑定的短确认,可以直接写入 Soul,无需二次确认。

  • 写入前必须通过当前消息原文证据、字段白名单、内容长度与敏感信息校验。

  • 只有 memory/soul.md 与 append-only 审计事件都持久化后才显示成功回执;审计失败会
    回滚文件。

  • 未知、敏感、证据未绑定、只读专家或存储不可用的更新会 fail closed,并明确说明未写入。

  • 新建和已提前创建的空对话会在首次发送前刷新最新 Soul;对话压缩不会擦除该设定。

Preserved Safety Boundaries / 保持不变的安全边界

  • DeepSeek owns open-ended reasoning, role planning, drafting, review judgment
    and synthesis proposals. DS Agent owns schemas, persistence, permissions,
    isolation, budgets, evidence, deterministic gates, recovery and final merge.

  • Durable Verified Computer Use keeps the v0.8.0
    observe -> approve -> revalidate -> act once -> observe -> verify boundary.

  • High-risk computer control still requires exact one-shot approval and local
    unlock. Model output cannot silently authorize local effects.

  • Secrets, raw screenshots, typed text, window titles, accessibility text and
    sensitive local paths remain local and are excluded from public release data.

  • DeepSeek 负责开放式推理、角色规划、起草、审核判断与综合提议;DS Agent 负责 schema、
    持久化、权限、隔离、预算、证据、确定性闸门、恢复与最终合并。

  • 持久、可验证 Computer Use 延续 v0.8.0 的
    观察 -> 批准 -> 再校验 -> 只执行一次 -> 再观察 -> 验证 边界。

  • 高风险电脑控制仍要求准确的一次性批准与本地解锁,模型输出不能静默授权本地副作用。

  • 密钥、原始截图、输入文本、窗口标题、无障碍文本和敏感本地路径继续只留在本机,不进入
    公开发布数据。

Upgrade Guidance / 升级说明

  1. Use the built-in updater from an installed v0.5.0, v0.8.0-rc.1 or v0.8.0
    client, or download the v0.9.0 installer from the GitHub Release.

  2. Verify the filename, byte length and SHA-256 published on the Release before
    running the unsigned installer.

  3. Do not interrupt the NSIS update while installation is in progress.

  4. Workspace choices, settings, Soul and durable run state live under OS
    app-data and workspace locations rather than the program directory.

  5. After updating, confirm the installed version is 0.9.0 and start a new
    conversation to verify the expected Soul identity settings.

  6. 在已安装的 v0.5.0、v0.8.0-rc.1 或 v0.8.0 中使用内置 updater,也可以从 GitHub
    Release 下载 v0.9.0 安装包。

  7. 运行未签名安装包前,按 Release 公布值核对文件名、字节数与 SHA-256。

  8. NSIS 升级过程中不要中断安装。

  9. 工作区、设置、Soul 与持久运行状态位于 OS app-data 和工作区,而不是程序安装目录。

  10. 升级后确认安装版本为 0.9.0,并新建对话核验预期 Soul 身份设置。

Validation Evidence / 验证证据

  • Test-first regression coverage reproduces the cross-conversation Soul failure
    and verifies exact field repair, persistence, receipt ordering and restart.

  • Expert Team tests cover hostile staging paths, symlink or junction rejection,
    content tampering, evidence conflicts, resource scheduling, restart recovery,
    bounded retries and exact-revision review/merge.

  • The complete local release gate includes secret scanning, TypeScript checking,
    the production frontend build, all Node suites, Rust tests, formatting, diff
    checks and the source-only release guard.

  • A fresh Windows installer is built without installation and independently
    checked before publication. Exact final byte length and SHA-256 are published
    with the GitHub Release asset.

  • Publication is gated on GitHub Actions for the exact release commit, an
    immutable annotated tag and a post-publication asset re-download.

  • 测试优先回归覆盖复现了跨对话 Soul 故障,并验证字段纠错、持久化、回执顺序与重启恢复。

  • 专家团队测试覆盖恶意暂存路径、符号链接或 junction 拒绝、内容篡改、证据冲突、资源调度、
    重启恢复、有限重试与准确版本审核/合并。

  • 完整本地发布闸门包括秘密扫描、TypeScript 检查、前端 production build、全部 Node
    套件、Rust 测试、格式检查、diff 检查与 source-only 发布检查。

  • 全新 Windows 安装包会在不安装的情况下构建并独立核验;最终字节数与 SHA-256 随
    GitHub Release 资产发布。

  • 发布必须等待准确 release commit 的 GitHub Actions、不可变 annotated tag 与发布后
    资产回下载核验。

Known Limits / 已知限制

Operations Briefing live smoke tests use
docs/templates/operations-briefing-smoke-evidence by default. The bundled
smoke files are marked as SMOKE SAMPLE evidence for local verification only
and Replace before operational use. The desktop seed action continues to use
blank operator templates under
docs/templates/operations-briefing-evidence, not smoke or business data.

  • The Windows installer is unsigned and may show an unknown-publisher warning.

  • Expert Team is intentionally one level deep, has bounded attempts and does
    not grant experts arbitrary destination writes or desktop control.

  • Soul chat writes require explicit user definition, change or confirmation;
    inferred general memories remain separately reviewable.

  • No live DeepSeek call or installed-app migration is part of the deterministic
    source test suite.

  • macOS packaging still requires verification on a macOS host.

  • Live email delivery and cloud-drive connectors remain deferred.

  • PDF v1 remains ASCII-safe; use Markdown or HTML for full-fidelity CJK output.

  • Windows 安装包未签名,可能显示“未知发布者”警告。

  • 专家团队刻意限制为一层并采用有限 attempt,不允许专家任意写入最终目标或控制桌面。

  • Soul 对话写入要求用户明确设定、修改或确认;一般推断记忆仍保持单独可审核。

  • 确定性源码测试不包含真实 DeepSeek 调用或已安装应用迁移。

  • macOS 安装包仍需在 macOS 主机验证。

  • 真实邮件投递与云盘连接器继续延期。

  • PDF v1 保持 ASCII-safe;完整中日韩文本输出请使用 Markdown 或 HTML。

Installer Integrity / 安装包完整性

  • Filename: DS.Agent_0.9.0_x64-setup.exe
  • Size: 12,473,860 bytes
  • SHA-256: F9A822E267E7591C5AC2B7D5F5A67C89DCE6834221F30DD0B30AD7D4C999ADA4
  • Windows signature: unsigned (NotSigned)

The values above come from the fresh, uninstalled release candidate and are
repeated on GitHub Release for download verification.

  • 文件名:DS.Agent_0.9.0_x64-setup.exe
  • 大小:12,473,860 字节
  • SHA-256:F9A822E267E7591C5AC2B7D5F5A67C89DCE6834221F30DD0B30AD7D4C999ADA4
  • Windows 签名:未签名(NotSigned

以上数值来自全新构建且未安装的 release candidate,并会在 GitHub Release 中重复公布,
供下载后核验。

DS Agent v0.8.0

Choose a tag to compare

@Lee-take Lee-take released this 15 Jul 02:08

DS Agent v0.8.0 Release Notes / 正式版说明

Status: Windows-first stable release. Repository:
https://github.com/Lee-take/dsagent

状态:Windows 优先正式版本。项目地址:
https://github.com/Lee-take/dsagent

Release Identity / 发布身份

Package, desktop, Tauri and Cargo metadata remain 0.8.0, and the updater
identity is v0.8.0. Installed v0.5.0 and v0.8.0-rc.1 clients can detect
this stable release. A stable v0.8.0 client does not treat the historical RC,
an equal version or a lower version as an update.

package、desktop、Tauri 和 Cargo 元数据继续保持 0.8.0,updater 当前身份为
v0.8.0。已安装的 v0.5.0v0.8.0-rc.1 可以发现本正式版;v0.8.0
正式版不会把历史 RC、相同版本或更低版本当作可用更新。

The v0.6 Automation connector and v0.7 Artifact Engine names were internal
roadmap milestones already consolidated into the public v0.5.0 release. No
retroactive v0.6 or v0.7 tags are created. The published v0.8.0-rc.1 tag,
Release and notes remain immutable historical update-test evidence.

v0.6 Automation connector 与 v0.7 Artifact Engine 是内部路线图里程碑,相关能力
已合并进入公开的 v0.5.0,因此不会补建 v0.6 或 v0.7 tag。已经发布的
v0.8.0-rc.1 tag、Release 和说明保持不可变,作为升级测试历史证据。

Durable Verified Computer Use / 持久、可验证的 Computer Use

v0.8.0 delivers the first complete Windows-first Durable Verified Computer Use
step through one evidence-driven loop:

observe -> approve -> revalidate -> record ActionStarted -> act once -> observe -> verify

v0.8.0 交付首个 Windows 优先的持久、可验证 Computer Use 完整步骤,采用同一条
证据驱动闭环:

观察 -> 批准 -> 再校验 -> 持久记录 ActionStarted -> 只执行一次 -> 再观察 -> 验证

  • Sessions and steps persist in SQLite with revision compare-and-swap, bounded
    recovery and malformed-row quarantine.

  • The exact action, one-shot approval, stable window identity, title hash,
    accessibility target, semantic state and checkpoint are bound together.

  • DS Agent persists ActionStarted before the external input effect. A restart
    across that boundary becomes EffectUnknown and is never replayed
    automatically.

  • The foreground window and target are revalidated immediately before acting;
    stale or changed bindings fail closed with zero control calls.

  • Post-action screenshot and UI Automation evidence are captured automatically.
    Screenshot-only evidence cannot claim semantic success; the deterministic
    postcondition must pass.

  • User takeover stops later control, records durable state and requires a fresh
    observation before work can continue.

  • The right rail exposes bounded create, bind, approve, run, takeover,
    re-observe and cancel controls without exposing raw private evidence.

  • Local loopback bridge requests bypass system proxies so local capability calls
    are not diverted through unrelated proxy configuration.

  • Session 与 step 使用 SQLite 持久化,并通过 revision compare-and-swap、有限恢复和
    畸形记录隔离保护状态一致性。

  • 准确动作、一次性批准、稳定窗口身份、标题摘要、无障碍目标、语义状态和 checkpoint
    被绑定为同一份执行证据。

  • DS Agent 在产生外部输入副作用前先持久记录 ActionStarted;如果跨越该边界重启,
    状态转为 EffectUnknown,绝不自动重放。

  • 执行前立即重新校验前台窗口和目标;陈旧或变化的绑定会 fail closed,控制调用为零。

  • 动作后自动采集截图与 UI Automation 证据;只有截图不能证明语义成功,必须通过确定性
    后置条件。

  • 用户接管会停止后续控制、持久记录状态,继续前必须重新观察。

  • 右侧状态栏提供有界的创建、绑定、批准、运行、接管、重新观察和取消入口,不暴露原始
    私密证据。

  • 本地 loopback bridge 请求绕过系统代理,避免本地能力调用被无关代理配置转发。

Safety And Privacy Boundaries / 安全与隐私边界

  • The verified Computer Use scenario is an isolated, low-risk Notepad-like
    Windows application.

  • Secure/UAC desktops, privileged targets, managed browser login-state reuse,
    broad cross-application coverage and general undo are not claimed.

  • Raw screenshots, typed text, window titles, accessibility text and sensitive
    local paths stay local. Public DTOs and UI surfaces carry only bounded labels,
    summaries, evidence handles and fingerprints.

  • DeepSeek may propose content and one exact action. DS Agent owns schema and
    policy validation, authorization, execution, evidence, verification,
    recovery, takeover and replay prevention.

  • Computer control remains high risk, requires an exact one-shot approval and
    local unlock, and cannot be silently authorized by model output.

  • 已验证的 Computer Use 场景是隔离、低风险、类似记事本的 Windows 应用。

  • 本版本不宣称支持安全/UAC 桌面、特权目标、受管浏览器登录态复用、广泛跨应用覆盖或
    通用撤销。

  • 原始截图、输入文本、窗口标题、无障碍文本和敏感本地路径只留在本机;公开 DTO 与 UI
    仅显示有界标签、摘要、证据句柄和指纹。

  • DeepSeek 可以提议内容与一个准确动作;DS Agent 负责 schema/policy 校验、授权、执行、
    证据、验证、恢复、接管和防重放。

  • Computer control 始终属于高风险能力,需要准确的一次性批准和本地解锁,模型输出不能
    静默自我授权。

Upgrade Guidance / 升级说明

  1. In DS Agent, check for updates from an installed v0.5.0 or
    v0.8.0-rc.1 client, or download the stable installer from the GitHub
    Release.

  2. Verify the installer filename, byte length and SHA-256 against the values in
    the published Release before running an unsigned binary.

  3. The built-in updater downloads the installer, runs the NSIS silent update
    and restarts DS Agent. Do not interrupt the process while installation is in
    progress.

  4. Workspace choices, settings and durable run state live under OS app-data and
    workspace locations rather than the program installation directory.

  5. After updating, confirm the installed version is 0.8.0 and that the
    expected workspace/settings remain available.

  6. 在已安装的 v0.5.0v0.8.0-rc.1 中使用 DS Agent 检查更新,也可以从
    GitHub 正式 Release 下载稳定版安装包。

  7. 运行未签名安装包前,按 Release 公布值核对文件名、字节数和 SHA-256。

  8. 内置 updater 会下载安装包、执行 NSIS 静默升级并重启 DS Agent;安装过程中不要
    中断进程。

  9. 工作区选择、设置和持久运行状态位于 OS app-data 与工作区,而不是程序安装目录。

  10. 升级后确认安装版本为 0.8.0,并检查原有工作区和设置仍可使用。

Exact Stable Checkpoint / 正式版精确检查点

  • Source commit / 源码提交: 2ea78c5fa285df22359f5ef4f1174224f764a58d
  • GitHub Actions: CI run 29382864044 completed successfully for that exact commit.
  • Remote evidence / 远程证据: 1,600-module frontend build; Rust 779 passed, 0 failed, 7 ignored; secret scan and 167-file source-only release guard passed.
  • Installer / 安装包: DS.Agent_0.8.0_x64-setup.exe, 12,354,607 bytes, SHA-256 AF22E6D28C20BF8C61967421AAEB9DFDAAA9E2729CED18AE0D43A68E331E49BF.

Validation Evidence / 验证证据

  • The published RC commit completed GitHub Actions with the production frontend
    build, secret scan, source-only release guard and 778 passing Rust tests, zero
    failures and seven environment-only ignored tests.
  • The public RC installer was downloaded again and matched its published byte
    length and SHA-256.
  • The maintainer completed the built-in updater transition from installed
    v0.5.0 to v0.8.0-rc.1; registry, executable and embedded updater identity
    were independently rechecked before stable promotion.
  • Stable updater fixtures passed, including old-stable discovery and
    RC/equal/downgrade fail-closed coverage. The complete offline local release
    gate passed with a 1,600-module frontend production build, 779 passing Rust
    tests, zero failures, seven environment-only ignored tests, secret scan,
    source-only guard, formatting and diff checks.
  • A fresh stable installer candidate was built without installation. Its
    ProductVersion and FileVersion are 0.8.0; the binary contains the stable
    updater identity and no v0.8.0-rc.1 updater identity.
  • Publication remains gated on exact-commit remote CI, an immutable annotated
    tag and a post-publication asset re-download.

Operations Briefing live smoke tests use
docs/templates/operations-briefing-smoke-evidence by default. The bundled
smoke files are marked as SMOKE SAMPLE evidence for local verification only
and Replace before operational use. The desktop seed action continues to use
blank operator templates under
docs/templates/operations-briefing-evidence, not smoke or business data.

  • 已发布 RC commit 的 GitHub Actions 已通过 production frontend build、secret
    scan、source-only release guard,以及 778 个 Rust 通过测试、0 失败、7 个仅环境原因
    ignored 测试。
  • 公开 RC 安装包已重新下载,字节数与 SHA-256 均与发布值一致。
  • 维护者已完成从已安装 v0.5.0v0.8.0-rc.1 的内置 updater 升级;正式版
    提升前又独立复核了注册表、可执行文件和内嵌 updater 身份。
  • 正式版 updater fixture 已通过,覆盖旧稳定版发现更新以及 RC/相同版本/降级全部
    fail closed。完整离线本地 release gate 已通过:前端 production build 为 1,600 modules,
    Rust 为 779 passed、0 failed、7 个仅环境原因 ignored,并通过 secret scan、source-only
    guard、format 与 diff 检查。
  • 已构建但未安装全新稳定版 candidate;ProductVersion 与 FileVersion 都是 0.8.0
    二进制包含 stable updater 身份且不含 v0.8.0-rc.1 updater 身份。
  • 发布仍需等待精确 commit 的远程 CI、不可变 annotated tag 与发布后资产回下载核验。

Known Limits / 已知限制

  • The Windows installer is unsigned and may show an unknown-publisher warning.

  • Durable Verified Computer Use remains a bounded Windows-first capability, not
    a claim of safe arbitrary desktop automation.

  • macOS packaging configuration exists but still requires verification on a
    macOS host.

  • Email read/draft/send remains an approval and audit surface without live mail
    delivery; cloud-drive connectors remain deferred.

  • PDF v1 is ASCII-safe; use Markdown or HTML for full-fidelity Chinese and other
    Unicode report output.

  • Windows 安装包未签名,可能出现“未知发布者”提示。

  • 持久、可验证 Computer Use 仍是有界的 Windows 优先能力,不代表可以安全地自动化任意
    桌面应用。

  • macOS 打包配置已经存在,但仍需在 macOS 主机上验证。

  • 邮件读取/草稿/发送目前仍是批准与审计表面,不会真实投递邮件;云盘连接器继续延期。

  • PDF v1 保持 ASCII-safe;需要完整中文或其他 Unicode 报告时请使用 Markdown 或 HTML。

Installer Integrity / 安装包完整性

  • Filename / 文件名: DS.Agent_0.8.0_x64-setup.exe
  • Byte length / 字节数: 12,354,607
  • SHA-256: AF22E6D28C20BF8C61967421AAEB9DFDAAA9E2729CED18AE0D43A68E331E49BF

DS Agent v0.8.0-rc.1

DS Agent v0.8.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@Lee-take Lee-take released this 15 Jul 01:17

DS Agent v0.8.0-rc.1 Release Notes

Status: Windows-first release candidate for update testing. The public stable
release remains v0.5.0 until this candidate has passed real installed-app
update verification.

Repository: https://github.com/Lee-take/dsagent

Versioning Note

The v0.6 Automation connector and v0.7 Artifact Engine names were internal
roadmap milestones. Their completed capabilities were already consolidated into
the public v0.5.0 release, so this project does not create retroactive v0.6 or
v0.7 tags. v0.8.0-rc.1 is the next public prerelease.

Durable Verified Computer Use

This candidate adds the first complete Windows-first Durable Verified Computer
Use step. It implements one evidence-driven vertical loop:

observe -> approve -> revalidate -> record ActionStarted -> act once -> observe -> verify

  • Sessions and steps are persisted in SQLite with revision compare-and-swap,
    bounded recovery and malformed-row quarantine.
  • The exact action, one-shot approval, stable window identity, title hash,
    accessibility target, semantic state and checkpoint are bound together.
  • DS Agent persists ActionStarted before the external input effect. If the app
    restarts across that boundary, the step becomes EffectUnknown and is never
    replayed automatically.
  • The foreground window and target are revalidated immediately before acting.
    A changed or stale binding blocks the input with zero control calls.
  • Post-action screenshot and UI Automation evidence are captured automatically.
    Screenshot-only evidence cannot claim semantic verification; the declared
    deterministic postcondition must pass.
  • User takeover stops subsequent control, records durable state and releases the
    shared desktop resource. Re-observation is required before continuing.
  • The right rail exposes safe controls for create, bind, approve and run,
    takeover, re-observe and cancel without exposing raw private evidence.
  • Local loopback bridge requests bypass system proxies so local capability calls
    cannot be diverted through an unrelated proxy configuration.

Safety And Privacy Boundaries

  • The supported RC scenario is an isolated, low-risk Notepad-like Windows app.
  • Secure/UAC desktops, privileged targets, managed browser login state,
    cross-application coverage and general undo are not claimed.
  • Raw screenshots, typed text, window titles, accessibility text and sensitive
    local paths stay local. Public UI data contains bounded summaries and
    fingerprints only.
  • DeepSeek may propose content and one exact action. DS Agent owns schema and
    policy validation, authorization, execution, evidence, verification, recovery
    and replay prevention.

Update Test Notes

  • The intended test path is an installed public v0.5.0 client updating to
    v0.8.0-rc.1 through DS Agent's built-in updater.
  • The Windows asset is DS.Agent_0.8.0_x64-setup.exe.
  • Existing workspace configuration and durable local state should remain in the
    OS app-data and workspace locations rather than the install directory.
  • The installer is unsigned, so Windows may display an unknown-publisher
    warning.
  • Testers should confirm update detection, download, silent install, restart,
    displayed version and preservation of existing settings/state before this RC
    is promoted to v0.8.0.

Validation

The implementation completed the production frontend build, the full desktop
test suite, secret scan, source-only release guard, Rust formatting and diff
checks. The pre-release implementation baseline recorded 778 passing Rust
tests, zero failures and seven environment-only ignored tests. Focused Computer
Use tests, repeated Windows screenshot capture and an isolated Notepad-like
act-once/verify smoke also passed. The release candidate is published only after
the versioned release gate, remote CI and installer build complete successfully.

Operations Briefing live smoke tests use
docs/templates/operations-briefing-smoke-evidence by default. The bundled
smoke files are marked as SMOKE SAMPLE evidence for local verification only
and Replace before operational use. The desktop seed action continues to use
blank operator templates under docs/templates/operations-briefing-evidence,
not smoke or business data.

Bumps the package, desktop, Tauri and Cargo metadata to 0.8.0, while the
updater identity is v0.8.0-rc.1, so installed Windows clients can detect and
test this release candidate as newer than v0.5.0.

Installer Integrity

SHA-256: FBC08E49CCACEBFF725AFC4B2994C64B8AEAD051099B7EF1AE7A6DE132659139

DS Agent v0.5.0

Choose a tag to compare

@Lee-take Lee-take released this 14 Jul 13:32

DS Agent v0.5.0 Release Notes

Status: Windows-first feature release. The v0.5.0 release supersedes
v0.4.1 for ordinary downloads.

Repository: https://github.com/Lee-take/dsagent

DS Agent v0.5.0 adds a durable Automation and Artifact Engine foundation for
local office work. Automation definitions and runs now keep revision-bound
source receipts, restart-safe execution state, review queues, evidence and
recovery without depending on a live connected-account provider.

Word, Excel, PowerPoint and PDF outputs now move through a durable lifecycle:
generation, structure checks, actual Office/PDF rendering, bounded automatic
revision and delivery. Rendered pages can be reviewed in the app. Preview pages
are bound to validation evidence, and missing or changed completed files return
to a needs-attention state instead of continuing to appear complete.

The release also includes the provider-neutral connected-account foundation:
typed Mail and Calendar reads, bounded sync state, attachment landing,
revocation and recovery boundaries, and redacted public status views. Production
provider execution remains disabled until a provider is explicitly configured;
this release does not silently connect Microsoft or Google accounts.

Permissions remain local and explicit. DeepSeek handles understanding,
reasoning and content generation, while DS Agent owns tool authorization,
paths, execution, templates, validation, evidence, recovery and delivery state.
Office writes require exact approved paths. Validation revisions are limited to
three named sibling files and never overwrite the approved original.

The release was validated with the full Rust and desktop test suites, source
hygiene checks, real Microsoft Office rendering for DOCX/XLSX/PPTX, PDF
rendering, and a restart test covering actual preview persistence.

Operations Briefing live smoke tests use
docs/templates/operations-briefing-smoke-evidence by default. The bundled
smoke files are marked as SMOKE SAMPLE evidence for local verification only
and Replace before operational use.
The desktop seed action uses blank operator templates under
docs/templates/operations-briefing-evidence, not smoke or business data.

Bumps the package, desktop, Tauri, Cargo, and updater metadata to 0.5.0 /
v0.5.0 so installed Windows clients can detect this release as newer than
v0.4.1.

The Windows installer remains unsigned, so Windows may show an
unknown-publisher warning.

Installer Integrity

SHA-256: B4618BD8D40160B97981393DE0DA2FDB8CEC4D2D4E3980C314AB343645343E6D