Release v0.7.0
Sharkfin v0.7.0
What's Changed
0.7.0 (2026-04-19)
Features
- web: switch to framework-agnostic mount/unmount contract (d9da99c)
- add /notifications/subscribe WebSocket endpoint (aa43411)
- add auth_id column, AuthID field, update UpsertIdentity signature (cc3a031)
- add bot role migration (Postgres) (e925ad4)
- add bot role migration (SQLite) (a17e649)
- add identity_webhooks table (Postgres) (1389f97)
- add identity_webhooks table (SQLite) (55320e9)
- add optional metadata column to messages (86b7f46)
- add register_webhook and unregister_webhook MCP tools (0385d0c)
- add REST-backed webhook and identity methods to Go client (9c1108b)
- add WebhookStore interface and SQLite/Postgres implementations (4a34bd3)
- auto-assign bot role for service identities (bb3d3bb)
- include service channel members in webhook recipients (f93de41)
- per-identity webhook dispatch in WebhookSubscriber (f6df47d)
- Postgres UpsertIdentity with auth_id resolution (aff231c)
- reorganize client dirs, license clients + web as Apache-2.0 (b7302ea)
- REST API endpoints for service-to-service communication (b721495)
- SQLite UpsertIdentity with auth_id resolution (6451afb)
- update daemon handlers and backup for new UpsertIdentity (676d26e)
- client: add HTTP status-mapped sentinel errors (df75cc0)
- client: add RESTClient command methods (8bdf4d4)
- client: add RESTClient type and constructor (a80b274)
- client: update package doc to reflect REST + WebSocket capabilities (a4afcd9)
- postgres: seed general channel on first boot for backend parity (9984351)
Bug Fixes
- add 1 MiB request body size limit to REST handlers (dd906f0)
- address code review findings (webhook dedup, N+1, list_webhooks tool) (e4d114e)
- align SQLite webhook upsert with Postgres semantics (598fdd7)
- auto-promote first user to admin role on fresh database (86d4f2c)
- await capabilities before rendering for correct initial permissions (b2e32f5)
- broadcast messages back to sender so they render immediately (5303880)
- fetch capabilities after connect, not during store creation (748d191)
- include identity_webhooks in WipeAll (fa6642f)
- move permission store outside createRoot for cross-tree reactivity (e705b5a)
- refetch capabilities on WebSocket reconnect (fb011bb)
- remove distracting sidebar background color (546d09e)
- replace all hardcoded styles with design tokens (ef169bb)
- revert () => wrapper, add channel seed + empty state (089b0bc)
- UI bug batch — input gating, banner debounce, cache headers, debug log (69c96b9)
- update test suite for seeded general channel and first-user auto-admin (43a0a7e)
- use createMemo for permission checks in SolidJS components (7165c48)
- use literal ellipsis in search placeholder instead of unicode escape (4227e44)
- use wf-input instead of deprecated wf-text-input (86b2162)
- wrap permission checks in Show when={() => ...} for SolidJS reactivity (12d3402)
- backup: handle pre-seeded channels gracefully during import (d65de78)
- e2e: export SHARKFIN_BINARY and include all packages in test glob (67cdd71)
- e2e: harden bridge harness; add SIGKILL fallback (4f5fe89)
- e2e: harden daemon harness against orphan-process leaks (494140e)
- migrations: use TRUE for built_in in bot role insert (Postgres) (2472976)
- test: make JWKS stub reject unknown API keys (e9d44a4)
Continuous Integration
- auto-tag client releases on path change (e386bdb)
Styles
Tests
- integration test for bot registration flow (6f1104a)
- client: add failing TestNewRESTClient_NoDial (f1121b1)
- client: add failing TestRESTClientRegister (69ad24d)
- client: cover RESTClient Channels, CreateChannel, and JoinChannel (65c07c3)
- e2e: add failing leak tests for daemon and bridge (b424133)
- e2e: fix stale tool list, channel-name collisions, and auto-admin assumptions (039dced)
Code Refactoring
- remove secret field from identity_webhooks (06c46e7)
- replace DM/Invite dialogs with wf-user-picker (6105836)
- replace InputBar with wf-compose-input wrapper (ee9f4f9)
- replace local permission store with @workfort/ui-solid usePermissions (892a160)
- replace local useIdleDetection with @workfort/ui-solid hook (41c1fcb)
- replace local utilities with @workfort/ui imports (079ccb3)
- use wf-avatar and wf-divider label in sharkfin (48acc45)
- use wf-nav-sidebar and wf-nav-section in sharkfin sidebar (7deb9e7)
- client: extract restTransport shared helper (b7ef605)
Documentation
- add bot/service identity implementation plan (960e382)
- add complexity ratings to remaining bugs (85d06d7)
- add Flow adapter REST API plan, requirements, rename tracking doc (1bb2d7f)
- add fort trust model to scope-core design (f507b1b)
- add login form flash bug to remaining work (ed4fa7e)
- add message input disable and rendering bugs to remaining work (3cff49b)
- add Passport admin UI design and update integration issues (04c3fa0)
- add Passport admin UI implementation plan (ace9d25)
- add Plans A/B/C, update remaining-ui-work tracking (4627cb7)
- add read_public permission design and update remaining work (0efecef)
- add remaining UI work tracking document (f767606)
- add scope-core Rust migration design (f667b9e)
- add scope-core Rust migration implementation plan (6944353)
- add stable identity ID implementation plan (e20cc10)
- consolidate tracking into single remaining-work.md (ef5ebbe)
- file HTTP server missing timeouts bug (ed18caa)
- mark message rendering bug as fixed (8527e20)
- move scope-core design to docs/, update remaining work tracker (a7fbbb5)
- Plan 8 — Sharkfin refactor to extracted components (202f604)
- UI extraction + shell chrome redesign design (0b67b27)
- update remaining work — permissions working, auto-join + message rendering next (f20261c)
- visual testing issues — 4 issues found, core flow verified working (2f1bd2d)
- client: add REST-variants implementation plan (0e76f79)
- client: approve REST-variants plan (79da872)
- client: document RESTClient usage in package doc (2667cb5)
- plans: add e2e harness orphan-leak hardening plan (946d14f)
- plans: approve e2e harness orphan-leak hardening plan (daa4b5d)
- remaining-work: file release-task missing -tags ui (c8797ed)
- remaining-work: file three sharkfin bugs surfaced in CI (0bacb4e)
Installation
Linux (x86_64)
wget https://github.com/Work-Fort/Sharkfin/releases/download/v0.7.0/sharkfin-linux-amd64.xz
xz -d sharkfin-linux-amd64.xz
chmod +x sharkfin-linux-amd64
sudo mv sharkfin-linux-amd64 /usr/local/bin/sharkfinLinux (ARM64)
wget https://github.com/Work-Fort/Sharkfin/releases/download/v0.7.0/sharkfin-linux-arm64.xz
xz -d sharkfin-linux-arm64.xz
chmod +x sharkfin-linux-arm64
sudo mv sharkfin-linux-arm64 /usr/local/bin/sharkfinmacOS (Apple Silicon)
wget https://github.com/Work-Fort/Sharkfin/releases/download/v0.7.0/sharkfin-darwin-arm64.xz
xz -d sharkfin-darwin-arm64.xz
chmod +x sharkfin-darwin-arm64
sudo mv sharkfin-darwin-arm64 /usr/local/bin/sharkfinmacOS (Intel)
wget https://github.com/Work-Fort/Sharkfin/releases/download/v0.7.0/sharkfin-darwin-amd64.xz
xz -d sharkfin-darwin-amd64.xz
chmod +x sharkfin-darwin-amd64
sudo mv sharkfin-darwin-amd64 /usr/local/bin/sharkfinWindows (x86_64)
Download sharkfin-windows-amd64.zip and extract.
Arch Linux (AUR)
yay -S sharkfinVerification
wget https://github.com/Work-Fort/Sharkfin/releases/download/v0.7.0/SHA256SUMS
sha256sum -c SHA256SUMS --ignore-missingBuilt automatically by Sharkfin CI