Skip to content

Releases: SimCubeLtd/keryx

0.7.1

Choose a tag to compare

@prom3theu5 prom3theu5 released this 23 Sep 08:41
0f08a11

What's Changed

  • Fix dashboard tag filters so a draft must have every selected tag. Selecting a second tag now narrows the results. By @prom3theu5 in #16
  • Bump the workspace and CLI version to 0.7.1. By @prom3theu5 in #17

Full Changelog: 0.7.0...0.7.1

Upgrade from 0.7.0

Replace the binary and restart the server. This patch has no database migration or configuration change.

Install

The release workflow builds and attaches binaries and checksums for three targets. Downloads become available as those builds finish. The archives include the README, licence, and Keryx agent skills. Released binaries include S3 storage and OCI sharing.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.7.1-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.7.1-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.7.1-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download 0.7.1 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.7.1-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.7.1-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.7.1-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.7.1-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install without sudo, install to ~/.local/bin and make sure it is on your PATH.

macOS (Apple Silicon)

gh release download 0.7.1 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.7.1-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.7.1-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.7.1-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.7.1-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. If Gatekeeper blocks a browser download, clear the quarantine flag with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs do not have a prebuilt binary in this release. Build from source.

Windows (x86-64)

Run these commands in PowerShell:

gh release download 0.7.1 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.7.1-x86_64-pc-windows-msvc.zip*'

# Compare the archive against the published checksum.
Get-FileHash keryx-0.7.1-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.7.1-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.7.1-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.7.1-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Compare the hash values, then add the extracted bin directory to your user PATH and open a new terminal. Run keryx --version to check the install. The executable is unsigned, so SmartScreen can warn on first run. Administrator rights are not required.

Build from source (any platform)

Install the pinned Rust nightly toolchain, then run:

rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.7.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --version

To install the tagged release into ~/.cargo/bin:

cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
  --tag 0.7.0 --locked keryx

--locked uses the dependency versions in the committed Cargo.lock. Add --no-default-features for a lean build with neither S3 storage nor OCI sharing. The build needs Python 3 on the PATH, as earlier releases did, for the PDF renderer's style engine.

Contributors

0.7.0

Choose a tag to compare

@prom3theu5 prom3theu5 released this 22 Sep 22:28
f1cd5ec

What's Changed

  • feat(website): add landing page, docs and manual Pages deployment by @prom3theu5 in #13
  • feat(dashboard): add shared draft tags by @prom3theu5 in #14
  • docs(website): document dashboard tagging by @prom3theu5 in #15

Full Changelog: 0.6.0...0.7.0

Highlights

Shared dashboard tags

Organise drafts with pink tag chips and find related work without changing the documents themselves.

  • Add an existing tag or create one in a compact modal with keyboard navigation and autocomplete. Remove assignments through the chips in the detail pane.
  • Select multiple tags in the toolbar to match any selected tag, combined with repository, availability and text search. Use Untagged only to find drafts without labels, or Tag A–Z to sort by their first alphabetical tag.
  • Filters are saved in the dashboard URL. Live updates preserve filtering and an open tagging modal.
  • Tags are shared database metadata linked to draft IDs. They survive new uploads and availability changes without changing draft timestamps, versions, content or notifications.
  • Tagging is dashboard-only. There are no CLI/TUI commands, upload flags or automatic tags, and tags do not appear in exported HTML or PDFs.
  • Protected dashboards remain read-only and hide tag data when an API key is configured.

Tag names support lowercase ASCII letters, digits, spaces and hyphens, up to 32 characters. Each draft can have up to 20 tags.

Website and documentation

Adds the Keryx landing page and Starlight documentation, including a guide to dashboard tagging and filtering.

Upgrade from 0.6.0

Replace the binary and restart your server. An additive migration creates the tag catalogue and draft assignments on SQLite or Postgres, preserving existing records. Existing drafts start untagged. No database recreation or document re-upload is needed.

Install

The release workflow builds and attaches binaries and checksums for three targets. Downloads become available as those builds finish. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.

Released binaries include S3 storage and OCI sharing.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.7.0-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.7.0-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.7.0-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download 0.7.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.7.0-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.7.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.7.0-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.7.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.

macOS (Apple Silicon)

gh release download 0.7.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.7.0-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.7.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.7.0-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.7.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs do not have a prebuilt binary in this release. Build from source.

Windows (x86-64)

Run these commands in PowerShell:

gh release download 0.7.0 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.7.0-x86_64-pc-windows-msvc.zip*'

# Compare the archive against the published checksum.
Get-FileHash keryx-0.7.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.7.0-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.7.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.7.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.

Build from source (any platform)

Install the pinned Rust nightly toolchain, then run:

rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.7.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --version

To install the tagged release into ~/.cargo/bin, run:

cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
  --tag 0.7.0 --locked keryx

--locked uses the dependency versions in the committed Cargo.lock. Add --no-default-features for a lean build with neither S3 storage nor OCI sharing. The build needs Python 3 on the PATH, as earlier releases did, for the PDF renderer's style engine.

0.6.0

Choose a tag to compare

@prom3theu5 prom3theu5 released this 19 Sep 22:31
dd8d1ac

What's changed

  • Make Keryx deployable with pluggable storage, OCI sharing, Postgres and a config file by @prom3theu5 in #12

Full changelog: 0.5.1...0.6.0


Highlights

Keryx 0.6.0 removes the reasons Keryx needed a local disk, and adds a way to hand a plan to someone who has no Keryx at all. An existing installation upgrades in place: replace the binary and start it. Everything new is opt-in.

Share a plan through any OCI registry

keryx share <draft-id> --to ghcr.io/acme/plans
oras pull ghcr.io/acme/plans/<draft-id>:v3     # the recipient needs no Keryx
  • A draft version becomes a single text/html layer, so a plain oras pull writes a usable HTML file, named from the draft's title. It works with GHCR, ECR, Harbor, zot, Artifactory and Docker Hub.
  • Pushes happen on your machine with your own Docker credentials. The Keryx server holds no registry secrets and makes no outbound connection.
  • Versions are immutable and explicit. Keryx pushes :v<n> and nothing else, never reads :latest, and refuses to overwrite a tag that holds something different unless you pass --force.
  • keryx inspect reads a reference's metadata without downloading the document. keryx pull brings one into your Keryx as a new draft or a new version, or writes it to a file with --output.
  • A pulled document is untrusted HTML. Its sha256 is checked against the artifact, then it passes the same HTML policy as an upload. There is no flag to skip that.

Draft HTML in S3

  • --storage s3 stores drafts in AWS S3 or any S3-compatible store: RustFS, MinIO, Ceph RGW, Cloudflare R2, Backblaze B2. Credentials come from the standard AWS chain, never from Keryx flags.
  • The server writes and deletes a probe object at startup and refuses to boot if it cannot, so a wrong bucket or a read-only credential never shows up as a 500 on the first upload.
  • keryx storage migrate --from disk --to s3 is a verified copy in either direction. Every object is read back and checked against the sha256 recorded at upload, an interrupted run resumes by re-running it, and any failure leaves the source untouched.
  • keryx storage gc lists stored objects that no version owns, and never touches anything younger than one hour.
  • Disk writes are safer too. They are now synced before being renamed into place, so a power loss can no longer leave an empty draft file.

Postgres

  • --database-url postgres://... runs Keryx on Postgres, for deployments with no persistent volume. SQLite on local disk stays the default and needs no new flags.
  • TLS is set in the URL with sslmode and sslrootcert, including a private cluster CA. Pooled connections are checked before use, so Keryx heals after a failover without a restart.
  • Two pods starting together are safe: migrations run under an advisory lock.
  • Keryx never prints the URL's credentials. The banner and errors show only postgres://host:port/database.

A config file

Every setting now resolves as flag > environment variable > config.toml > built-in default. The file is optional and lives at $XDG_CONFIG_HOME/keryx/config.toml, or ~/.config/keryx/config.toml on every platform. --config or KERYX_CONFIG names another.

[client]
api_url  = "http://plans.internal:7812"
share_to = "ghcr.io/acme/plans"

[server]
port = 7812
public_base_url = "https://plans.example.com"
max_html_bytes = 10000000
allow_font_links = true
  • Every existing environment variable and flag keeps its name and meaning.
  • The file is validated before any command runs. An unknown key or a wrong type stops Keryx with the file and the entry named, so a typo can never silently do nothing.
  • keryx serve --help shows the values in effect, including those from the file, and never prints a secret.

Fixes

  • Ctrl-C with a dashboard open. The server hung on shutdown while a dashboard tab held its live-update stream open. Shutdown now ends those streams, and the browser reconnects when the server is back. SIGTERM now shuts down gracefully too, so a systemctl restart no longer waits out the stop timeout. A second Ctrl-C exits immediately.
  • A version whose HTML file is missing now serves a clean 404, and PDF publishing answers not found. It used to be a 500.

Under the hood

  • The single crate is now a workspace of internal crates, so boundaries such as "the TUI cannot touch the database" are enforced by the compiler.
  • The hand-written SQLite layer is replaced by SeaORM behind a DraftStore trait, and blob storage sits behind a BlobBackend trait built on OpenDAL. The whole store test suite runs against both SQLite and Postgres in CI.
  • ring stays the only TLS and crypto backend. aws-lc-rs and OpenSSL are kept out of the build, and CI fails if either appears.
  • supply-chain/README.md records how dependencies are vetted and which ones are knowingly unreviewed. cargo vet exemptions fell from 763 to 501 through imported audits, per-crate publisher trust and hand audits.

Upgrade

Replace the binary and restart keryx serve with the same flags and environment. No data is moved.

On its first start, 0.6.0 takes a consistent snapshot of your database next to it, keryx.db.backup-<timestamp>, then brings the database under managed migrations in place. The startup banner says exactly what it did:

database: ~/.keryx/keryx.db (adopted a legacy database at user_version 2; backup at ~/.keryx/keryx.db.backup-20260919T211828Z; schema already current)
blobs: file://~/.keryx (probe ok, 0 ms)

Later starts say schema up to date. --no-backup skips the snapshot, which is yours to delete once you are happy.

Rollback is supported. Stop 0.6.0, reinstall 0.5.1 and start it on the same files. This was tested in both directions with the released 0.5.1 binary: every version served at each step, including ones uploaded on the other release.

Things to know:

  • Client API URL. The first client command moves the API URL from ~/.keryx/config.json into config.toml and deletes the JSON. Your API key stays in ~/.keryx/credentials.json. If you roll back, run keryx auth set <key> --api-url <url> once, because 0.5.1 does not read config.toml.
  • Read-only data directory. 0.5.1 would start on one. 0.6.0 refuses at boot, because of the startup probe.
  • A new .staging directory appears in the data directory and is emptied at every start. It must be on the same filesystem as the data directory.
  • The startup banner changed. The database: and blobs: lines have a new shape. Adjust anything that parses them.
  • TLS trust. HTTPS connections now trust the operating system's certificate store instead of a bundled root list, so a private CA installed on the machine is honoured.
  • Postgres starts empty. There is no SQLite to Postgres copy. Every draft is a complete HTML document, so re-upload what you want to keep.
  • Still one server. Neither S3 nor Postgres makes Keryx multi-node. Run exactly one server per database.
  • If you moved drafts to S3, run keryx storage migrate --from s3 --to disk with 0.6.0 before rolling back. 0.5.1 only reads local disk.
  • Agent skills. The release archives carry updated keryx-read and html-communication skills that know the sharing commands.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.

Released binaries include S3 storage and OCI sharing.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.6.0-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.6.0-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.6.0-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download 0.6.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.6.0-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.6.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.6.0-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.6.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.

macOS (Apple Silicon)

gh release download 0.6.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.6.0-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.6.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.6.0-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.6.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.

Windows (x86-64)

Run these commands in PowerShell:

gh release download 0.6.0 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.6.0-x86_64-pc-windows-msvc.zip*'

# Compare the archive against the published checksum.
Get-FileHash keryx-0.6.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.6.0-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.6.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.6.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.

Build from source (any platform)

Install the pinned ...

Read more

0.5.1

Choose a tag to compare

@prom3theu5 prom3theu5 released this 28 Aug 02:50
4604435

What's changed

Full changelog: 0.5.0...0.5.1


Highlights

Keryx 0.5.1 updates an open dashboard when draft activity occurs. You no longer need to reload the page after another client changes a draft.

  • A Server-Sent Events connection tells the browser when its dashboard snapshot may be stale.
  • The browser fetches server-rendered rows and draft details after each signal. Search, sorting, repository filters, availability counts, selection, and version history stay in sync without a page reload.
  • Realtime updates cover uploads, revisions, availability changes, wake-ups, prune, and purge.
  • Events carry only a revision. Draft data and HTML remain in the existing server-rendered snapshot path.
  • A reconnect receives the latest revision immediately, so the dashboard recovers changes that occurred while the connection was down.
  • Protected deployments use the same redacted rendering path for both the initial page and realtime snapshots.

Upgrade

Replace the binary and restart keryx serve. Version 0.5.1 adds no database migration and needs no new configuration.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.5.1-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.5.1-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.5.1-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download 0.5.1 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.5.1-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.5.1-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.5.1-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.5.1-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.

macOS (Apple Silicon)

gh release download 0.5.1 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.5.1-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.5.1-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.5.1-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.5.1-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.

Windows (x86-64)

Run these commands in PowerShell:

gh release download 0.5.1 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.5.1-x86_64-pc-windows-msvc.zip*'

# Compare the archive against the published checksum.
Get-FileHash keryx-0.5.1-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.5.1-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.5.1-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.5.1-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.

Build from source (any platform)

Install the pinned Rust nightly toolchain, then run:

rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.5.1 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --version

To install the tagged release into ~/.cargo/bin, run:

cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
  --tag 0.5.1 --locked keryx

--locked uses the dependency versions in the committed Cargo.lock.

0.5.0

Choose a tag to compare

@prom3theu5 prom3theu5 released this 28 Aug 00:35
5ede367

What's changed

  • Draft availability, snooze, installable dashboard, and Web Push notifications by @prom3theu5 in #9

Full changelog: 0.4.2...0.5.0


Highlights

Keryx 0.5.0 gives every draft one of three availability states and lets the server tell you when something happens to a plan.

  • Snooze parks a draft until a wake time without touching its links: keryx snooze <id> --for 2h (or --until <RFC 3339>), keryx unsnooze <id>. A snoozed draft keeps serving its public, raw, versioned, and PDF URLs; it just leaves the Active list. Wakes are derived from the clock, so nothing rewrites the row when a snooze expires.
  • Enable and disable complete the existing disable facility: keryx disable <id> [--reason] stops serving, keryx enable <id> brings it back. One mutation, PUT /api/drafts/:id/availability, owns every transition; POST /api/drafts/:id/disable remains as a compatibility adapter.
  • Dashboard by availability: Active, Snoozed, and Disabled tabs replace the All view and its low-value filters. The selected pane offers Snooze (with presets or a custom wake time), Unsnooze, Disable, and Enable, and /?draft=<id>&view=<state> deep-links to a tab and draft.
  • Installable app: Keryx serves a manifest, icons, and a service worker. On an HTTPS origin (for example a Tailscale Serve hostname) a supported browser offers Install Keryx; plain HTTP keeps the ordinary dashboard.
  • Web Push notifications for Plan published, revised, woke, enabled, and disabled, delivered even while the dashboard is closed. Events are written in the same SQLite transaction as the draft change, sent by a background dispatcher with retries, and a wake is sent exactly once even across a restart. Each device chooses which event types it receives. PDF publication never notifies.
  • keryx list hides snoozed drafts by default; --include-snoozed and --snoozed opt in.
  • Dependencies: web-push-native handles payload encryption and VAPID signing; ratatui moves to 0.30 (clearing the lru advisory GHSA-rhfx-m35p-ff5j).

Upgrade

Replace the binary and restart keryx serve. The SQLite schema migrates itself to version 2 (a nullable snoozed_until column plus the notification tables) on first start; no manual step is needed. A VAPID key pair is created once at <data-dir>/vapid.json (owner-readable only) and reused thereafter; keep it, because replacing it invalidates every push subscription.

Push requires an HTTPS origin in the browser and an open (no API key) dashboard, since a protected dashboard is read-only. The new --push-contact / KERYX_PUSH_CONTACT flag sets the VAPID contact; it defaults to the HTTPS public base URL, otherwise mailto:keryx@localhost.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.5.0-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.5.0-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download 0.5.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.5.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.

macOS (Apple Silicon)

gh release download 0.5.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.5.0-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.5.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.5.0-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.5.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.

Windows (x86-64)

Run these commands in PowerShell:

gh release download 0.5.0 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.5.0-x86_64-pc-windows-msvc.zip*'

# Compare the archive against the published checksum.
Get-FileHash keryx-0.5.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.5.0-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.5.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.5.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.

Build from source (any platform)

Install the pinned Rust nightly toolchain, then run:

rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.5.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --version

To install the tagged release into ~/.cargo/bin, run:

cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
  --tag 0.5.0 --locked keryx

--locked uses the dependency versions in the committed Cargo.lock.

0.4.2

Choose a tag to compare

@prom3theu5 prom3theu5 released this 27 Aug 13:30
88d9a5d

What's changed

  • Replace the dashboard text mark with the Keryx Dispatch logo by @prom3theu5 in #7
  • Bump the Keryx version to 0.4.2 by @prom3theu5 in #8

Full changelog: 0.4.1...0.4.2


Highlights

Keryx 0.4.2 replaces the dashboard's Greek letter placeholder with the new Dispatch logo. The generated SVG has a 24 mm square canvas and uses the existing dashboard blue palette.

Upgrade

No manual data migration is required. Replace the binary and restart keryx serve.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.4.2-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.4.2-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.4.2-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download 0.4.2 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.4.2-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.4.2-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.4.2-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.4.2-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.

macOS (Apple Silicon)

gh release download 0.4.2 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.4.2-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.4.2-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.4.2-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.4.2-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.

Windows (x86-64)

Run these commands in PowerShell:

gh release download 0.4.2 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.4.2-x86_64-pc-windows-msvc.zip*'

# Compare the archive against the published checksum.
Get-FileHash keryx-0.4.2-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.4.2-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.4.2-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.4.2-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.

Build from source (any platform)

Install the pinned Rust nightly toolchain, then run:

rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.4.2 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --version

To install the tagged release into ~/.cargo/bin, run:

cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
  --tag 0.4.2 --locked keryx

--locked uses the dependency versions in the committed Cargo.lock.

0.4.1

Choose a tag to compare

@prom3theu5 prom3theu5 released this 27 Aug 12:41
ac8cf55

What's changed

  • Add direct version-history navigation, reusable release caches, and upload-provenance guidance by @prom3theu5 in #6

Full changelog: v0.4.0...0.4.1


Highlights

Keryx 0.4.1 makes dashboard navigation less disruptive and fixes release builds that recompiled every dependency for each tag.

Open drafts and stored versions in new tabs

  • Open draft titles and Open document actions in a new browser tab, so the dashboard stays available.
  • Open any immutable version directly from the version-history row.
  • See the eight newest versions first.
  • Use Load older versions to reveal the remaining history without infinite scrolling.

Reuse release build caches

GitHub scopes caches by branch or tag. The release event now dispatches the build from the default branch, where later releases can reuse the same cache. Each build still checks out the requested tag and verifies that the tag matches the version in Cargo.toml.

The release toolchain is pinned to nightly-2026-08-20. Compiler updates now happen deliberately instead of invalidating the cache whenever nightly changes.

The first build in the new default-branch scope seeds each platform cache. Later builds can restore those cached dependencies.

Preserve upload provenance

The bundled HTML communication skill now requires the keryx upload command to run from the repository checkout. The HTML source can still live under /tmp/keryx; Keryx records provenance from the directory where the command runs.

Upgrade

No manual data migration is required. Replace the binary and restart keryx serve.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.4.1-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.4.1-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.4.1-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download 0.4.1 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.4.1-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.4.1-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.4.1-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.4.1-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.

macOS (Apple Silicon)

gh release download 0.4.1 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.4.1-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.4.1-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.4.1-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.4.1-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.

Windows (x86-64)

Run these commands in PowerShell:

gh release download 0.4.1 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.4.1-x86_64-pc-windows-msvc.zip*'

# Compare the archive against the published checksum.
Get-FileHash keryx-0.4.1-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.4.1-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.4.1-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.4.1-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.

Build from source (any platform)

Install the pinned Rust nightly toolchain, then run:

rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.4.1 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --version

To install the tagged release into ~/.cargo/bin, run:

cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
  --tag 0.4.1 --locked keryx

--locked uses the dependency versions in the committed Cargo.lock.

v0.4.0

Choose a tag to compare

@prom3theu5 prom3theu5 released this 27 Aug 01:03
f895d84

What's changed

  • Add the searchable dashboard and per-upload Git provenance by @prom3theu5 in #5

Full changelog: v0.3.1...v0.4.0


Highlights

Keryx 0.4.0 replaces the basic draft list with a responsive management dashboard and records the source checkout for every new upload.

Search and manage drafts in the browser

  • Search titles, descriptions, draft IDs, repositories, and branches.
  • Filter by update time, version count, disabled state, missing provenance, or repository.
  • Sort by update time, title, or version count.
  • Select a draft without leaving the list. The detail pane shows its metadata and version history.
  • Download the current HTML or PDF from the row menu.
  • Prune a draft, or force prune every version after a destructive-action confirmation.
  • Follow the system color scheme by default, with persistent light and dark overrides.
  • Use the wider, more spacious layout on large displays. The list and detail pane still collapse for laptop, tablet, and mobile widths.

Record provenance for every upload

keryx upload now reads Git metadata from the directory where you run the command. The uploaded HTML can live elsewhere, including /tmp/keryx.

Each immutable version can store:

  • The repository host, owner, and name.
  • The current branch.
  • The commit SHA and subject.
  • The dirty state of the checkout.

The SQLite migration copies existing draft-level repository metadata onto the version that is current during the upgrade. Keryx cannot recover branch or commit data for historic uploads that never recorded it. Upload a new version to add current provenance.

Keep API-key dashboards public without exposing management data

The dashboard remains public when KERYX_API_KEY is set. In that mode, Keryx redacts Git provenance and removes PDF, history, prune, and force-prune controls. Use the authenticated CLI for those operations. Public draft and raw HTML links continue to work.

Upgrade

No manual data migration is required. Replace the binary and restart keryx serve. Keryx updates the SQLite schema when it opens the database.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.4.0-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.4.0-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.4.0-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download v0.4.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.4.0-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.4.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.4.0-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.4.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.

macOS (Apple Silicon)

gh release download v0.4.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.4.0-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.4.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.4.0-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.4.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.

Windows (x86-64)

Run these commands in PowerShell:

gh release download v0.4.0 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.4.0-x86_64-pc-windows-msvc.zip*'

# Compare the archive against the published checksum.
Get-FileHash keryx-0.4.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.4.0-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.4.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.4.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.

Build from source (any platform)

Install the Rust nightly toolchain, then run:

rustup toolchain install nightly --profile minimal
git clone --branch v0.4.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly build --release --locked
./target/release/keryx --version

To install the tagged release into ~/.cargo/bin, run:

cargo +nightly install --git https://github.com/SimCubeLtd/keryx \
  --tag v0.4.0 --locked keryx

--locked uses the dependency versions in the committed Cargo.lock.

v0.3.1: Merge pull request #4 from SimCubeLtd/fix/inline-script-csp

Choose a tag to compare

@prom3theu5 prom3theu5 released this 26 Aug 13:22
724a1e1

What's Changed

  • fix: let accepted inline scripts actually run by @prom3theu5 in #4

Full Changelog: v0.3.0...v0.3.1


Highlights

A fix for 0.3.0. --allow-safe-handlers accepted an inline on* handler at upload while the
served CSP still said script-src 'none', so the handler was stored and never ran.

That made the flag ineffective for the case it exists to support. In the async-CSS idiom
<link rel="stylesheet" media="print" onload="this.media='all'"> the handler is the media swap,
so with it blocked the stylesheet stayed print-only and --allow-font-links rendered no font
either, despite its CSP being correct. <noscript> does not cover it: that only renders when
scripting is disabled, and CSP-blocked scripting still counts as enabled.

  • --allow-inline-scripts / KERYX_ALLOW_INLINE_SCRIPTS serves drafts with
    script-src 'unsafe-inline'. One keyword covers inline <script>, on* handlers and
    javascript: URLs alike; upload validation is what keeps the last two in check. connect-src
    stays 'none' either way, since a draft is a document rather than a client for something else.
    Off by default, so the strict posture is unchanged unless asked for.
  • keryx upload now warns when a document carries inline scripts but the target server will not
    execute them, instead of leaving it to be found in the browser console.

Note on what the flag costs: 'unsafe-inline' means any script in an uploaded document executes
when someone opens that draft, including anything that got past upload validation. That suits the
single-machine and trusted-LAN deployment Keryx targets. For a wider audience, hash-pinning the
stored scripts is the tighter option and the immutable-version model makes it straightforward.

Upgrading from 0.3.0 needs no data migration. Restart keryx serve with the flag to let existing
drafts run their scripts.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The
release archives also include the README, licence, and ready-made Keryx agent skills.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.3.1-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.3.1-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download v0.3.1 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.3.1-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your
PATH.

macOS (Apple Silicon)

gh release download v0.3.1 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.3.1-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.3.1-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.3.1-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.3.1-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser may attach a
quarantine flag and cause Gatekeeper to refuse it; clear that flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs: no binary is published. Build from source, or run the Apple Silicon build under
Rosetta 2. Rosetta is unsupported for this release and untested.

Windows (x86-64)

In PowerShell:

gh release download v0.3.1 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.3.1-x86_64-pc-windows-msvc.zip*'

# Compare against the published checksum
Get-FileHash keryx-0.3.1-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.3.1-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.3.1-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.3.1-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen may warn on first run. Nothing here needs
administrator rights.

Build from source (any platform)

Install the Rust nightly toolchain, then:

rustup toolchain install nightly --profile minimal
git clone --branch v0.3.1 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly build --release --locked
./target/release/keryx --version

Or install the tagged release straight into ~/.cargo/bin:

cargo +nightly install --git https://github.com/SimCubeLtd/keryx \
  --tag v0.3.1 --locked keryx

--locked uses the exact dependency versions in the committed Cargo.lock.

v0.3.0: Merge pull request #3 from SimCubeLtd/feat/google_fonts

Choose a tag to compare

@prom3theu5 prom3theu5 released this 26 Aug 13:00
b47acd4

What's Changed

  • feat: relax link and styling so archify can work by @prom3theu5 in #3

Full Changelog: v0.2.0...v0.3.0


Highlights

Two upload rules become configurable per-server, both off by default. Documents that were rejected
outright can now be accepted deliberately, without loosening the policy for everyone.

  • --allow-font-links / KERYX_ALLOW_FONT_LINKS accepts a <link> whose rel is only
    stylesheet, preconnect, dns-prefetch or preload and whose href host is
    fonts.googleapis.com or fonts.gstatic.com. <base> and every other host stay blocked. The
    flag also widens the CSP on served drafts with style-src https://fonts.googleapis.com and
    font-src https://fonts.gstatic.com, without which an accepted font link would still be blocked
    in the browser.
  • --allow-safe-handlers / KERYX_ALLOW_SAFE_HANDLERS accepts an inline on* handler whose body
    is nothing but ;-separated assignments of literals or dotted property paths, the async-CSS
    idiom onload="this.media='all'". Anything containing (, [, <, a template literal, or a
    blocked scheme is still rejected, so a permitted handler can set properties but cannot call
    anything.

Also in this release:

  • keryx upload reads the server's effective policy from GET /api/me before validating locally.
    --max-html-bytes existed in 0.2.0 but had no effect on CLI uploads, which always validated
    against the hardcoded 512 KB default. Raising the server cap now works end to end.
  • <script type="application/json"> and application/ld+json are accepted with no flag. The HTML
    spec classifies these as data blocks that no browser executes, so rejecting them was a bug in the
    type allowlist rather than a safety control. module, importmap and speculationrules stay
    blocked.
  • URL attributes block a dangerous scheme only at the start of the value, so a URL such as
    https://example.com/?q=javascript:1 is no longer a false positive.

PDF publication keeps its own stricter policy and is unchanged: keryx publish still rejects
scripts and external assets.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The
release archives also include the README, licence, and ready-made Keryx agent skills.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.3.0-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.3.0-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download v0.3.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.3.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your
PATH.

macOS (Apple Silicon)

gh release download v0.3.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.3.0-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.3.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.3.0-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.3.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser may attach a
quarantine flag and cause Gatekeeper to refuse it; clear that flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs: no binary is published. Build from source, or run the Apple Silicon build under
Rosetta 2. Rosetta is unsupported for this release and untested.

Windows (x86-64)

In PowerShell:

gh release download v0.3.0 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.3.0-x86_64-pc-windows-msvc.zip*'

# Compare against the published checksum
Get-FileHash keryx-0.3.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.3.0-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.3.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.3.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen may warn on first run. Nothing here needs
administrator rights.

Build from source (any platform)

Install the Rust nightly toolchain, then:

rustup toolchain install nightly --profile minimal
git clone --branch v0.3.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly build --release --locked
./target/release/keryx --version

Or install the tagged release straight into ~/.cargo/bin:

cargo +nightly install --git https://github.com/SimCubeLtd/keryx \
  --tag v0.3.0 --locked keryx

--locked uses the exact dependency versions in the committed Cargo.lock.