0.5.0
What's changed
- Draft availability, snooze, installable dashboard, and Web Push notifications by @prom3theu5 in #9
Full changelog: 0.4.2...0.5.0
Highlights
Keryx 0.5.0 gives every draft one of three availability states and lets the server tell you when something happens to a plan.
- Snooze parks a draft until a wake time without touching its links:
keryx snooze <id> --for 2h(or--until <RFC 3339>),keryx unsnooze <id>. A snoozed draft keeps serving its public, raw, versioned, and PDF URLs; it just leaves the Active list. Wakes are derived from the clock, so nothing rewrites the row when a snooze expires. - Enable and disable complete the existing disable facility:
keryx disable <id> [--reason]stops serving,keryx enable <id>brings it back. One mutation,PUT /api/drafts/:id/availability, owns every transition;POST /api/drafts/:id/disableremains as a compatibility adapter. - Dashboard by availability: Active, Snoozed, and Disabled tabs replace the All view and its low-value filters. The selected pane offers Snooze (with presets or a custom wake time), Unsnooze, Disable, and Enable, and
/?draft=<id>&view=<state>deep-links to a tab and draft. - Installable app: Keryx serves a manifest, icons, and a service worker. On an HTTPS origin (for example a Tailscale Serve hostname) a supported browser offers Install Keryx; plain HTTP keeps the ordinary dashboard.
- Web Push notifications for Plan published, revised, woke, enabled, and disabled, delivered even while the dashboard is closed. Events are written in the same SQLite transaction as the draft change, sent by a background dispatcher with retries, and a wake is sent exactly once even across a restart. Each device chooses which event types it receives. PDF publication never notifies.
keryx listhides snoozed drafts by default;--include-snoozedand--snoozedopt in.- Dependencies:
web-push-nativehandles payload encryption and VAPID signing; ratatui moves to 0.30 (clearing thelruadvisory GHSA-rhfx-m35p-ff5j).
Upgrade
Replace the binary and restart keryx serve. The SQLite schema migrates itself to version 2 (a nullable snoozed_until column plus the notification tables) on first start; no manual step is needed. A VAPID key pair is created once at <data-dir>/vapid.json (owner-readable only) and reused thereafter; keep it, because replacing it invalidates every push subscription.
Push requires an HTTPS origin in the browser and an open (no API key) dashboard, since a protected dashboard is read-only. The new --push-contact / KERYX_PUSH_CONTACT flag sets the VAPID contact; it defaults to the HTTPS public base URL, otherwise mailto:keryx@localhost.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The release archives also include the README, licence, and ready-made Keryx agent skills.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.5.0-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.5.0-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download 0.5.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.5.0-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.5.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your PATH.
macOS (Apple Silicon)
gh release download 0.5.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.5.0-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.5.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.5.0-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.5.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser can attach a quarantine flag and cause Gatekeeper to refuse it. Clear the flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs do not have a native binary. Build from source, or run the Apple Silicon build under Rosetta 2. Rosetta 2 is unsupported and untested for this release.
Windows (x86-64)
Run these commands in PowerShell:
gh release download 0.5.0 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.5.0-x86_64-pc-windows-msvc.zip*'
# Compare the archive against the published checksum.
Get-FileHash keryx-0.5.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.5.0-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.5.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.5.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen can warn on first run. The installation does not require administrator rights.
Build from source (any platform)
Install the pinned Rust nightly toolchain, then run:
rustup toolchain install nightly-2026-08-20 --profile minimal
git clone --branch 0.5.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly-2026-08-20 build --release --locked
./target/release/keryx --versionTo install the tagged release into ~/.cargo/bin, run:
cargo +nightly-2026-08-20 install --git https://github.com/SimCubeLtd/keryx \
--tag 0.5.0 --locked keryx--locked uses the dependency versions in the committed Cargo.lock.