Releases: SimCubeLtd/keryx
Release list
0.7.1
What's Changed
- Fix dashboard tag filters so a draft must have every selected tag. Selecting a second tag now narrows the results. By @prom3theu5 in #16
- Bump the workspace and CLI version to 0.7.1. By @prom3theu5 in #17
Full Changelog: 0.7.0...0.7.1
Upgrade from 0.7.0
Replace the binary and restart the server. This patch has no database migration or configuration change.
Install
The release workflow builds and attaches binaries and checksums for three targets. Downloads become available as those builds finish. The archives include the README, licence, and Keryx agent skills. Released binaries include S3 storage and OCI sharing.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.7.1-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.7.1-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.7.1-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download 0.7.1 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.7.1-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.7.1-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.7.1-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.7.1-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install without sudo, install to ~/.local/bin and make sure it is on your PATH.
macOS (Apple Silicon)
gh release download 0.7.1 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.7.1-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.7.1-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.7.1-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.7.1-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. If Gatekeeper blocks a browser download, clear the quarantine flag with:
xattr -d com.apple.quarantine /usr/local/bin/keryx
Intel Macs do not have a prebuilt binary in this release. Build from source.
Windows (x86-64)
Run these commands in PowerShell:
gh release download 0.7.1 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.7.1-x86_64-pc-windows-msvc.zip*'
# Compare the archive against the published checksum.
Get-FileHash keryx-0.7.1-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.7.1-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.7.1-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.7.1-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Compare the hash values, then add the extracted bin directory to your user PATH and open a new terminal. Run keryx --version to check the install. The executable is unsigned, so SmartScreen can warn on first run. Administrator rights are not required.
Build from source (any platform)
Install the pinned Rust nightly toolchain, then run:
rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.7.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --versionTo install the tagged release into ~/.cargo/bin:
cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
--tag 0.7.0 --locked keryx--locked uses the dependency versions in the committed Cargo.lock. Add --no-default-features for a lean build with neither S3 storage nor OCI sharing. The build needs Python 3 on the PATH, as earlier releases did, for the PDF renderer's style engine.
Contributors
0.7.0
What's Changed
- feat(website): add landing page, docs and manual Pages deployment by @prom3theu5 in #13
- feat(dashboard): add shared draft tags by @prom3theu5 in #14
- docs(website): document dashboard tagging by @prom3theu5 in #15
Full Changelog: 0.6.0...0.7.0
Highlights
Shared dashboard tags
Organise drafts with pink tag chips and find related work without changing the documents themselves.
- Add an existing tag or create one in a compact modal with keyboard navigation and autocomplete. Remove assignments through the chips in the detail pane.
- Select multiple tags in the toolbar to match any selected tag, combined with repository, availability and text search. Use Untagged only to find drafts without labels, or Tag A–Z to sort by their first alphabetical tag.
- Filters are saved in the dashboard URL. Live updates preserve filtering and an open tagging modal.
- Tags are shared database metadata linked to draft IDs. They survive new uploads and availability changes without changing draft timestamps, versions, content or notifications.
- Tagging is dashboard-only. There are no CLI/TUI commands, upload flags or automatic tags, and tags do not appear in exported HTML or PDFs.
- Protected dashboards remain read-only and hide tag data when an API key is configured.
Tag names support lowercase ASCII letters, digits, spaces and hyphens, up to 32 characters. Each draft can have up to 20 tags.
Website and documentation
Adds the Keryx landing page and Starlight documentation, including a guide to dashboard tagging and filtering.
Upgrade from 0.6.0
Replace the binary and restart your server. An additive migration creates the tag catalogue and draft assignments on SQLite or Postgres, preserving existing records. Existing drafts start untagged. No database recreation or document re-upload is needed.
Install
The release workflow builds and attaches binaries and checksums for three targets. Downloads become available as those builds finish. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.
Released binaries include S3 storage and OCI sharing.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.7.0-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.7.0-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.7.0-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download 0.7.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.7.0-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.7.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.7.0-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.7.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.
macOS (Apple Silicon)
gh release download 0.7.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.7.0-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.7.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.7.0-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.7.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs do not have a prebuilt binary in this release. Build from source.
Windows (x86-64)
Run these commands in PowerShell:
gh release download 0.7.0 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.7.0-x86_64-pc-windows-msvc.zip*'
# Compare the archive against the published checksum.
Get-FileHash keryx-0.7.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.7.0-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.7.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.7.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.
Build from source (any platform)
Install the pinned Rust nightly toolchain, then run:
rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.7.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --versionTo install the tagged release into ~/.cargo/bin, run:
cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
--tag 0.7.0 --locked keryx--locked uses the dependency versions in the committed Cargo.lock. Add --no-default-features for a lean build with neither S3 storage nor OCI sharing. The build needs Python 3 on the PATH, as earlier releases did, for the PDF renderer's style engine.
0.6.0
What's changed
- Make Keryx deployable with pluggable storage, OCI sharing, Postgres and a config file by @prom3theu5 in #12
Full changelog: 0.5.1...0.6.0
Highlights
Keryx 0.6.0 removes the reasons Keryx needed a local disk, and adds a way to hand a plan to someone who has no Keryx at all. An existing installation upgrades in place: replace the binary and start it. Everything new is opt-in.
Share a plan through any OCI registry
keryx share <draft-id> --to ghcr.io/acme/plans
oras pull ghcr.io/acme/plans/<draft-id>:v3 # the recipient needs no Keryx- A draft version becomes a single
text/htmllayer, so a plainoraspull writes a usable HTML file, named from the draft's title. It works with GHCR, ECR, Harbor, zot, Artifactory and Docker Hub. - Pushes happen on your machine with your own Docker credentials. The Keryx server holds no registry secrets and makes no outbound connection.
- Versions are immutable and explicit. Keryx pushes
:v<n>and nothing else, never reads:latest, and refuses to overwrite a tag that holds something different unless you pass--force. keryx inspectreads a reference's metadata without downloading the document.keryx pullbrings one into your Keryx as a new draft or a new version, or writes it to a file with--output.- A pulled document is untrusted HTML. Its sha256 is checked against the artifact, then it passes the same HTML policy as an upload. There is no flag to skip that.
Draft HTML in S3
--storage s3stores drafts in AWS S3 or any S3-compatible store: RustFS, MinIO, Ceph RGW, Cloudflare R2, Backblaze B2. Credentials come from the standard AWS chain, never from Keryx flags.- The server writes and deletes a probe object at startup and refuses to boot if it cannot, so a wrong bucket or a read-only credential never shows up as a 500 on the first upload.
keryx storage migrate --from disk --to s3is a verified copy in either direction. Every object is read back and checked against the sha256 recorded at upload, an interrupted run resumes by re-running it, and any failure leaves the source untouched.keryx storage gclists stored objects that no version owns, and never touches anything younger than one hour.- Disk writes are safer too. They are now synced before being renamed into place, so a power loss can no longer leave an empty draft file.
Postgres
--database-url postgres://...runs Keryx on Postgres, for deployments with no persistent volume. SQLite on local disk stays the default and needs no new flags.- TLS is set in the URL with
sslmodeandsslrootcert, including a private cluster CA. Pooled connections are checked before use, so Keryx heals after a failover without a restart. - Two pods starting together are safe: migrations run under an advisory lock.
- Keryx never prints the URL's credentials. The banner and errors show only
postgres://host:port/database.
A config file
Every setting now resolves as flag > environment variable > config.toml > built-in default. The file is optional and lives at $XDG_CONFIG_HOME/keryx/config.toml, or ~/.config/keryx/config.toml on every platform. --config or KERYX_CONFIG names another.
[client]
api_url = "http://plans.internal:7812"
share_to = "ghcr.io/acme/plans"
[server]
port = 7812
public_base_url = "https://plans.example.com"
max_html_bytes = 10000000
allow_font_links = true- Every existing environment variable and flag keeps its name and meaning.
- The file is validated before any command runs. An unknown key or a wrong type stops Keryx with the file and the entry named, so a typo can never silently do nothing.
keryx serve --helpshows the values in effect, including those from the file, and never prints a secret.
Fixes
- Ctrl-C with a dashboard open. The server hung on shutdown while a dashboard tab held its live-update stream open. Shutdown now ends those streams, and the browser reconnects when the server is back. SIGTERM now shuts down gracefully too, so a
systemctl restartno longer waits out the stop timeout. A second Ctrl-C exits immediately. - A version whose HTML file is missing now serves a clean 404, and PDF publishing answers not found. It used to be a 500.
Under the hood
- The single crate is now a workspace of internal crates, so boundaries such as "the TUI cannot touch the database" are enforced by the compiler.
- The hand-written SQLite layer is replaced by SeaORM behind a
DraftStoretrait, and blob storage sits behind aBlobBackendtrait built on OpenDAL. The whole store test suite runs against both SQLite and Postgres in CI. - ring stays the only TLS and crypto backend.
aws-lc-rsand OpenSSL are kept out of the build, and CI fails if either appears. supply-chain/README.mdrecords how dependencies are vetted and which ones are knowingly unreviewed.cargo vetexemptions fell from 763 to 501 through imported audits, per-crate publisher trust and hand audits.
Upgrade
Replace the binary and restart keryx serve with the same flags and environment. No data is moved.
On its first start, 0.6.0 takes a consistent snapshot of your database next to it, keryx.db.backup-<timestamp>, then brings the database under managed migrations in place. The startup banner says exactly what it did:
database: ~/.keryx/keryx.db (adopted a legacy database at user_version 2; backup at ~/.keryx/keryx.db.backup-20260919T211828Z; schema already current)
blobs: file://~/.keryx (probe ok, 0 ms)
Later starts say schema up to date. --no-backup skips the snapshot, which is yours to delete once you are happy.
Rollback is supported. Stop 0.6.0, reinstall 0.5.1 and start it on the same files. This was tested in both directions with the released 0.5.1 binary: every version served at each step, including ones uploaded on the other release.
Things to know:
- Client API URL. The first client command moves the API URL from
~/.keryx/config.jsonintoconfig.tomland deletes the JSON. Your API key stays in~/.keryx/credentials.json. If you roll back, runkeryx auth set <key> --api-url <url>once, because 0.5.1 does not readconfig.toml. - Read-only data directory. 0.5.1 would start on one. 0.6.0 refuses at boot, because of the startup probe.
- A new
.stagingdirectory appears in the data directory and is emptied at every start. It must be on the same filesystem as the data directory. - The startup banner changed. The
database:andblobs:lines have a new shape. Adjust anything that parses them. - TLS trust. HTTPS connections now trust the operating system's certificate store instead of a bundled root list, so a private CA installed on the machine is honoured.
- Postgres starts empty. There is no SQLite to Postgres copy. Every draft is a complete HTML document, so re-upload what you want to keep.
- Still one server. Neither S3 nor Postgres makes Keryx multi-node. Run exactly one server per database.
- If you moved drafts to S3, run
keryx storage migrate --from s3 --to diskwith 0.6.0 before rolling back. 0.5.1 only reads local disk. - Agent skills. The release archives carry updated
keryx-readandhtml-communicationskills that know the sharing commands.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.
Released binaries include S3 storage and OCI sharing.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.6.0-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.6.0-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.6.0-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download 0.6.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.6.0-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.6.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.6.0-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.6.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.
macOS (Apple Silicon)
gh release download 0.6.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.6.0-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.6.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.6.0-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.6.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.
Windows (x86-64)
Run these commands in PowerShell:
gh release download 0.6.0 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.6.0-x86_64-pc-windows-msvc.zip*'
# Compare the archive against the published checksum.
Get-FileHash keryx-0.6.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.6.0-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.6.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.6.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.
Build from source (any platform)
Install the pinned ...
0.5.1
What's changed
- Realtime dashboard updates by @prom3theu5 in #10
Full changelog: 0.5.0...0.5.1
Highlights
Keryx 0.5.1 updates an open dashboard when draft activity occurs. You no longer need to reload the page after another client changes a draft.
- A Server-Sent Events connection tells the browser when its dashboard snapshot may be stale.
- The browser fetches server-rendered rows and draft details after each signal. Search, sorting, repository filters, availability counts, selection, and version history stay in sync without a page reload.
- Realtime updates cover uploads, revisions, availability changes, wake-ups, prune, and purge.
- Events carry only a revision. Draft data and HTML remain in the existing server-rendered snapshot path.
- A reconnect receives the latest revision immediately, so the dashboard recovers changes that occurred while the connection was down.
- Protected deployments use the same redacted rendering path for both the initial page and realtime snapshots.
Upgrade
Replace the binary and restart keryx serve. Version 0.5.1 adds no database migration and needs no new configuration.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.5.1-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.5.1-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.5.1-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download 0.5.1 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.5.1-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.5.1-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.5.1-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.5.1-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.
macOS (Apple Silicon)
gh release download 0.5.1 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.5.1-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.5.1-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.5.1-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.5.1-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.
Windows (x86-64)
Run these commands in PowerShell:
gh release download 0.5.1 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.5.1-x86_64-pc-windows-msvc.zip*'
# Compare the archive against the published checksum.
Get-FileHash keryx-0.5.1-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.5.1-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.5.1-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.5.1-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.
Build from source (any platform)
Install the pinned Rust nightly toolchain, then run:
rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.5.1 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --versionTo install the tagged release into ~/.cargo/bin, run:
cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
--tag 0.5.1 --locked keryx--locked uses the dependency versions in the committed Cargo.lock.
0.5.0
What's changed
- Draft availability, snooze, installable dashboard, and Web Push notifications by @prom3theu5 in #9
Full changelog: 0.4.2...0.5.0
Highlights
Keryx 0.5.0 gives every draft one of three availability states and lets the server tell you when something happens to a plan.
- Snooze parks a draft until a wake time without touching its links:
keryx snooze <id> --for 2h(or--until <RFC 3339>),keryx unsnooze <id>. A snoozed draft keeps serving its public, raw, versioned, and PDF URLs; it just leaves the Active list. Wakes are derived from the clock, so nothing rewrites the row when a snooze expires. - Enable and disable complete the existing disable facility:
keryx disable <id> [--reason]stops serving,keryx enable <id>brings it back. One mutation,PUT /api/drafts/:id/availability, owns every transition;POST /api/drafts/:id/disableremains as a compatibility adapter. - Dashboard by availability: Active, Snoozed, and Disabled tabs replace the All view and its low-value filters. The selected pane offers Snooze (with presets or a custom wake time), Unsnooze, Disable, and Enable, and
/?draft=<id>&view=<state>deep-links to a tab and draft. - Installable app: Keryx serves a manifest, icons, and a service worker. On an HTTPS origin (for example a Tailscale Serve hostname) a supported browser offers Install Keryx; plain HTTP keeps the ordinary dashboard.
- Web Push notifications for Plan published, revised, woke, enabled, and disabled, delivered even while the dashboard is closed. Events are written in the same SQLite transaction as the draft change, sent by a background dispatcher with retries, and a wake is sent exactly once even across a restart. Each device chooses which event types it receives. PDF publication never notifies.
keryx listhides snoozed drafts by default;--include-snoozedand--snoozedopt in.- Dependencies:
web-push-nativehandles payload encryption and VAPID signing; ratatui moves to 0.30 (clearing thelruadvisory GHSA-rhfx-m35p-ff5j).
Upgrade
Replace the binary and restart keryx serve. The SQLite schema migrates itself to version 2 (a nullable snoozed_until column plus the notification tables) on first start; no manual step is needed. A VAPID key pair is created once at <data-dir>/vapid.json (owner-readable only) and reused thereafter; keep it, because replacing it invalidates every push subscription.
Push requires an HTTPS origin in the browser and an open (no API key) dashboard, since a protected dashboard is read-only. The new --push-contact / KERYX_PUSH_CONTACT flag sets the VAPID contact; it defaults to the HTTPS public base URL, otherwise mailto:keryx@localhost.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.5.0-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.5.0-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download 0.5.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.5.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.
macOS (Apple Silicon)
gh release download 0.5.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.5.0-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.5.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.5.0-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.5.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.
Windows (x86-64)
Run these commands in PowerShell:
gh release download 0.5.0 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.5.0-x86_64-pc-windows-msvc.zip*'
# Compare the archive against the published checksum.
Get-FileHash keryx-0.5.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.5.0-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.5.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.5.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.
Build from source (any platform)
Install the pinned Rust nightly toolchain, then run:
rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.5.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --versionTo install the tagged release into ~/.cargo/bin, run:
cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
--tag 0.5.0 --locked keryx--locked uses the dependency versions in the committed Cargo.lock.
0.4.2
What's changed
- Replace the dashboard text mark with the Keryx Dispatch logo by @prom3theu5 in #7
- Bump the Keryx version to 0.4.2 by @prom3theu5 in #8
Full changelog: 0.4.1...0.4.2
Highlights
Keryx 0.4.2 replaces the dashboard's Greek letter placeholder with the new Dispatch logo. The generated SVG has a 24 mm square canvas and uses the existing dashboard blue palette.
Upgrade
No manual data migration is required. Replace the binary and restart keryx serve.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.4.2-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.4.2-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.4.2-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download 0.4.2 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.4.2-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.4.2-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.4.2-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.4.2-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.
macOS (Apple Silicon)
gh release download 0.4.2 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.4.2-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.4.2-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.4.2-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.4.2-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.
Windows (x86-64)
Run these commands in PowerShell:
gh release download 0.4.2 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.4.2-x86_64-pc-windows-msvc.zip*'
# Compare the archive against the published checksum.
Get-FileHash keryx-0.4.2-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.4.2-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.4.2-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.4.2-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.
Build from source (any platform)
Install the pinned Rust nightly toolchain, then run:
rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.4.2 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --versionTo install the tagged release into ~/.cargo/bin, run:
cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
--tag 0.4.2 --locked keryx--locked uses the dependency versions in the committed Cargo.lock.
0.4.1
What's changed
- Add direct version-history navigation, reusable release caches, and upload-provenance guidance by @prom3theu5 in #6
Full changelog: v0.4.0...0.4.1
Highlights
Keryx 0.4.1 makes dashboard navigation less disruptive and fixes release builds that recompiled every dependency for each tag.
Open drafts and stored versions in new tabs
- Open draft titles and Open document actions in a new browser tab, so the dashboard stays available.
- Open any immutable version directly from the version-history row.
- See the eight newest versions first.
- Use Load older versions to reveal the remaining history without infinite scrolling.
Reuse release build caches
GitHub scopes caches by branch or tag. The release event now dispatches the build from the default branch, where later releases can reuse the same cache. Each build still checks out the requested tag and verifies that the tag matches the version in Cargo.toml.
The release toolchain is pinned to nightly-2026-08-20. Compiler updates now happen deliberately instead of invalidating the cache whenever nightly changes.
The first build in the new default-branch scope seeds each platform cache. Later builds can restore those cached dependencies.
Preserve upload provenance
The bundled HTML communication skill now requires the keryx upload command to run from the repository checkout. The HTML source can still live under /tmp/keryx; Keryx records provenance from the directory where the command runs.
Upgrade
No manual data migration is required. Replace the binary and restart keryx serve.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.4.1-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.4.1-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.4.1-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download 0.4.1 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.4.1-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.4.1-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.4.1-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.4.1-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.
macOS (Apple Silicon)
gh release download 0.4.1 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.4.1-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.4.1-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.4.1-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.4.1-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.
Windows (x86-64)
Run these commands in PowerShell:
gh release download 0.4.1 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.4.1-x86_64-pc-windows-msvc.zip*'
# Compare the archive against the published checksum.
Get-FileHash keryx-0.4.1-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.4.1-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.4.1-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.4.1-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.
Build from source (any platform)
Install the pinned Rust nightly toolchain, then run:
rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.4.1 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --versionTo install the tagged release into ~/.cargo/bin, run:
cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
--tag 0.4.1 --locked keryx--locked uses the dependency versions in the committed Cargo.lock.
v0.4.0
What's changed
- Add the searchable dashboard and per-upload Git provenance by @prom3theu5 in #5
Full changelog: v0.3.1...v0.4.0
Highlights
Keryx 0.4.0 replaces the basic draft list with a responsive management dashboard and records the source checkout for every new upload.
Search and manage drafts in the browser
- Search titles, descriptions, draft IDs, repositories, and branches.
- Filter by update time, version count, disabled state, missing provenance, or repository.
- Sort by update time, title, or version count.
- Select a draft without leaving the list. The detail pane shows its metadata and version history.
- Download the current HTML or PDF from the row menu.
- Prune a draft, or force prune every version after a destructive-action confirmation.
- Follow the system color scheme by default, with persistent light and dark overrides.
- Use the wider, more spacious layout on large displays. The list and detail pane still collapse for laptop, tablet, and mobile widths.
Record provenance for every upload
keryx upload now reads Git metadata from the directory where you run the command. The uploaded HTML can live elsewhere, including /tmp/keryx.
Each immutable version can store:
- The repository host, owner, and name.
- The current branch.
- The commit SHA and subject.
- The dirty state of the checkout.
The SQLite migration copies existing draft-level repository metadata onto the version that is current during the upgrade. Keryx cannot recover branch or commit data for historic uploads that never recorded it. Upload a new version to add current provenance.
Keep API-key dashboards public without exposing management data
The dashboard remains public when KERYX_API_KEY is set. In that mode, Keryx redacts Git provenance and removes PDF, history, prune, and force-prune controls. Use the authenticated CLI for those operations. Public draft and raw HTML links continue to work.
Upgrade
No manual data migration is required. Replace the binary and restart keryx serve. Keryx updates the SQLite schema when it opens the database.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.4.0-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.4.0-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.4.0-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download v0.4.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.4.0-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.4.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.4.0-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.4.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.
macOS (Apple Silicon)
gh release download v0.4.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.4.0-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.4.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.4.0-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.4.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.
Windows (x86-64)
Run these commands in PowerShell:
gh release download v0.4.0 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.4.0-x86_64-pc-windows-msvc.zip*'
# Compare the archive against the published checksum.
Get-FileHash keryx-0.4.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.4.0-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.4.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.4.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.
Build from source (any platform)
Install the Rust nightly toolchain, then run:
rustup toolchain install nightly --profile minimal
git clone --branch v0.4.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly build --release --locked
./target/release/keryx --versionTo install the tagged release into ~/.cargo/bin, run:
cargo +nightly install --git https://github.com/SimCubeLtd/keryx \
--tag v0.4.0 --locked keryx--locked uses the dependency versions in the committed Cargo.lock.
v0.3.1: Merge pull request #4 from SimCubeLtd/fix/inline-script-csp
What's Changed
- fix: let accepted inline scripts actually run by @prom3theu5 in #4
Full Changelog: v0.3.0...v0.3.1
Highlights
A fix for 0.3.0. --allow-safe-handlers accepted an inline on* handler at upload while the
served CSP still said script-src 'none', so the handler was stored and never ran.
That made the flag ineffective for the case it exists to support. In the async-CSS idiom
<link rel="stylesheet" media="print" onload="this.media='all'"> the handler is the media swap,
so with it blocked the stylesheet stayed print-only and --allow-font-links rendered no font
either, despite its CSP being correct. <noscript> does not cover it: that only renders when
scripting is disabled, and CSP-blocked scripting still counts as enabled.
--allow-inline-scripts/KERYX_ALLOW_INLINE_SCRIPTSserves drafts with
script-src 'unsafe-inline'. One keyword covers inline<script>,on*handlers and
javascript:URLs alike; upload validation is what keeps the last two in check.connect-src
stays'none'either way, since a draft is a document rather than a client for something else.
Off by default, so the strict posture is unchanged unless asked for.keryx uploadnow warns when a document carries inline scripts but the target server will not
execute them, instead of leaving it to be found in the browser console.
Note on what the flag costs: 'unsafe-inline' means any script in an uploaded document executes
when someone opens that draft, including anything that got past upload validation. That suits the
single-machine and trusted-LAN deployment Keryx targets. For a wider audience, hash-pinning the
stored scripts is the tighter option and the immutable-version model makes it straightforward.
Upgrading from 0.3.0 needs no data migration. Restart keryx serve with the flag to let existing
drafts run their scripts.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The
release archives also include the README, licence, and ready-made Keryx agent skills.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.3.1-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.3.1-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download v0.3.1 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.3.1-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your
PATH.
macOS (Apple Silicon)
gh release download v0.3.1 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.3.1-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.3.1-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.3.1-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.3.1-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser may attach a
quarantine flag and cause Gatekeeper to refuse it; clear that flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs: no binary is published. Build from source, or run the Apple Silicon build under
Rosetta 2. Rosetta is unsupported for this release and untested.
Windows (x86-64)
In PowerShell:
gh release download v0.3.1 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.3.1-x86_64-pc-windows-msvc.zip*'
# Compare against the published checksum
Get-FileHash keryx-0.3.1-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.3.1-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.3.1-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.3.1-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen may warn on first run. Nothing here needs
administrator rights.
Build from source (any platform)
Install the Rust nightly toolchain, then:
rustup toolchain install nightly --profile minimal
git clone --branch v0.3.1 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly build --release --locked
./target/release/keryx --versionOr install the tagged release straight into ~/.cargo/bin:
cargo +nightly install --git https://github.com/SimCubeLtd/keryx \
--tag v0.3.1 --locked keryx--locked uses the exact dependency versions in the committed Cargo.lock.
v0.3.0: Merge pull request #3 from SimCubeLtd/feat/google_fonts
What's Changed
- feat: relax link and styling so archify can work by @prom3theu5 in #3
Full Changelog: v0.2.0...v0.3.0
Highlights
Two upload rules become configurable per-server, both off by default. Documents that were rejected
outright can now be accepted deliberately, without loosening the policy for everyone.
--allow-font-links/KERYX_ALLOW_FONT_LINKSaccepts a<link>whoserelis only
stylesheet,preconnect,dns-prefetchorpreloadand whosehrefhost is
fonts.googleapis.comorfonts.gstatic.com.<base>and every other host stay blocked. The
flag also widens the CSP on served drafts withstyle-src https://fonts.googleapis.comand
font-src https://fonts.gstatic.com, without which an accepted font link would still be blocked
in the browser.--allow-safe-handlers/KERYX_ALLOW_SAFE_HANDLERSaccepts an inlineon*handler whose body
is nothing but;-separated assignments of literals or dotted property paths, the async-CSS
idiomonload="this.media='all'". Anything containing(,[,<, a template literal, or a
blocked scheme is still rejected, so a permitted handler can set properties but cannot call
anything.
Also in this release:
keryx uploadreads the server's effective policy fromGET /api/mebefore validating locally.
--max-html-bytesexisted in 0.2.0 but had no effect on CLI uploads, which always validated
against the hardcoded 512 KB default. Raising the server cap now works end to end.<script type="application/json">andapplication/ld+jsonare accepted with no flag. The HTML
spec classifies these as data blocks that no browser executes, so rejecting them was a bug in the
type allowlist rather than a safety control.module,importmapandspeculationrulesstay
blocked.- URL attributes block a dangerous scheme only at the start of the value, so a URL such as
https://example.com/?q=javascript:1is no longer a false positive.
PDF publication keeps its own stricter policy and is unchanged: keryx publish still rejects
scripts and external assets.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The
release archives also include the README, licence, and ready-made Keryx agent skills.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.3.0-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.3.0-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download v0.3.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.3.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your
PATH.
macOS (Apple Silicon)
gh release download v0.3.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.3.0-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.3.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.3.0-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.3.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser may attach a
quarantine flag and cause Gatekeeper to refuse it; clear that flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs: no binary is published. Build from source, or run the Apple Silicon build under
Rosetta 2. Rosetta is unsupported for this release and untested.
Windows (x86-64)
In PowerShell:
gh release download v0.3.0 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.3.0-x86_64-pc-windows-msvc.zip*'
# Compare against the published checksum
Get-FileHash keryx-0.3.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.3.0-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.3.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.3.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen may warn on first run. Nothing here needs
administrator rights.
Build from source (any platform)
Install the Rust nightly toolchain, then:
rustup toolchain install nightly --profile minimal
git clone --branch v0.3.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly build --release --locked
./target/release/keryx --versionOr install the tagged release straight into ~/.cargo/bin:
cargo +nightly install --git https://github.com/SimCubeLtd/keryx \
--tag v0.3.0 --locked keryx--locked uses the exact dependency versions in the committed Cargo.lock.