Skip to content

0.5.0

Choose a tag to compare

@prom3theu5 prom3theu5 released this 28 Aug 00:35
5ede367

What's changed

  • Draft availability, snooze, installable dashboard, and Web Push notifications by @prom3theu5 in #9

Full changelog: 0.4.2...0.5.0


Highlights

Keryx 0.5.0 gives every draft one of three availability states and lets the server tell you when something happens to a plan.

  • Snooze parks a draft until a wake time without touching its links: keryx snooze <id> --for 2h (or --until <RFC 3339>), keryx unsnooze <id>. A snoozed draft keeps serving its public, raw, versioned, and PDF URLs; it just leaves the Active list. Wakes are derived from the clock, so nothing rewrites the row when a snooze expires.
  • Enable and disable complete the existing disable facility: keryx disable <id> [--reason] stops serving, keryx enable <id> brings it back. One mutation, PUT /api/drafts/:id/availability, owns every transition; POST /api/drafts/:id/disable remains as a compatibility adapter.
  • Dashboard by availability: Active, Snoozed, and Disabled tabs replace the All view and its low-value filters. The selected pane offers Snooze (with presets or a custom wake time), Unsnooze, Disable, and Enable, and /?draft=<id>&view=<state> deep-links to a tab and draft.
  • Installable app: Keryx serves a manifest, icons, and a service worker. On an HTTPS origin (for example a Tailscale Serve hostname) a supported browser offers Install Keryx; plain HTTP keeps the ordinary dashboard.
  • Web Push notifications for Plan published, revised, woke, enabled, and disabled, delivered even while the dashboard is closed. Events are written in the same SQLite transaction as the draft change, sent by a background dispatcher with retries, and a wake is sent exactly once even across a restart. Each device chooses which event types it receives. PDF publication never notifies.
  • keryx list hides snoozed drafts by default; --include-snoozed and --snoozed opt in.
  • Dependencies: web-push-native handles payload encryption and VAPID signing; ratatui moves to 0.30 (clearing the lru advisory GHSA-rhfx-m35p-ff5j).

Upgrade

Replace the binary and restart keryx serve. The SQLite schema migrates itself to version 2 (a nullable snoozed_until column plus the notification tables) on first start; no manual step is needed. A VAPID key pair is created once at <data-dir>/vapid.json (owner-readable only) and reused thereafter; keep it, because replacing it invalidates every push subscription.

Push requires an HTTPS origin in the browser and an open (no API key) dashboard, since a protected dashboard is read-only. The new --push-contact / KERYX_PUSH_CONTACT flag sets the VAPID contact; it defaults to the HTTPS public base URL, otherwise mailto:keryx@localhost.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.5.0-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.5.0-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download 0.5.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.5.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.

macOS (Apple Silicon)

gh release download 0.5.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.5.0-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.5.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.5.0-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.5.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.

Windows (x86-64)

Run these commands in PowerShell:

gh release download 0.5.0 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.5.0-x86_64-pc-windows-msvc.zip*'

# Compare the archive against the published checksum.
Get-FileHash keryx-0.5.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.5.0-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.5.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.5.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.

Build from source (any platform)

Install the pinned Rust nightly toolchain, then run:

rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.5.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --version

To install the tagged release into ~/.cargo/bin, run:

cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
  --tag 0.5.0 --locked keryx

--locked uses the dependency versions in the committed Cargo.lock.