Repository navigation
GitPulse v1.0.0
First major GitPulse release. The v0.1.0 tag was cut the day before, but
GitHub never published it: installer uploads rewrote the draft's tag_name
to untagged-<hex> and finalize aborted with every installer already on the
draft. That desktop work — native menus, the macOS status popover, repository
hygiene, the rebuilt command palette, and the workbench — ships here together
with core Git workflow improvements, DevMap / code-intel hardening, and a
release pipeline that can finish after GitHub detaches a draft tag.
Added
- Expand the native application menu with Go submenus for all 16 view sections,
zoom controls, and Help entries for documentation, shortcuts, diagnostics,
optional-tool setup, release notes and issue reporting. Section navigation
reveals the repository pane from Fleet. Repository commands disable when unavailable. - Add live menu checkmarks and progress labels, an open-repository switcher,
clear-recents, staging and branch actions, parked-operation controls,
copy/reveal/remote utilities and manual update checks. - Add an optional icon-only macOS status item opening a compact light/dark
popover: repository switching, changed/staged/conflict/stash cards, last-fetch
sync counts, parked-operation and busy-work chips, History/Pulse/Fleet/Terminal
shortcuts, copy/reveal/remote/appearance utilities, expandable details and
contextual review/recovery actions. Refresh and appearance stay in the panel.
Open GitPulse restores the main window; closing the main window while enabled
preserves its session. Copy, refresh and appearance stay in the popover; Reveal
and Remote dismiss it without bringing GitPulse forward. Right-click retains
native app controls and adds the current primary action and Refresh when
available. Escape collapses the switcher or details first;Rrefreshes and
1–4open a nonzero metric. The status window still cannot mutate Git. - Menu bar status enhancements: attention-dot glyph, optional tray title counts,
per-repo switcher badges, realFETCH_HEADage, hide-Dock-while-closed, and
Launch at login (LaunchAgent with--background). - Add a global build cleaner to Fleet and Settings, with selected roots,
exclusions, retention and run budgets, opt-in native scheduling, closed-repo
discovery, durable history and an optional macOS headless LaunchAgent. - Reuse DevCouncil's Rust hygiene policy and generated agent guidance. Harden
traversal, case-insensitive preservation, partial scans, revision revocation,
lock release, registration failures and Git filesystem-monitor suppression. - Add Repository hygiene to Storage: stale-output previews across supported
language ecosystems, shared-cache inspection and tool-owned maintenance,
saved retention/weekly-review preferences, cancellation and explicit outcomes. - Drag task cards across Kanban columns with a movement threshold, mid-card
insertion, and neighbor-column keyboard moves. Positions stay strictly between
neighbors instead of appendingDate.now()in the middle of a column. - Add currently open GitPulse tabs as workspace or task members from the board
and workspace editor, registering a path only when it is not already linked. - Keep selected task title and description locked while automatic enhancements
run. - Add task board/list layouts, priority/type/owner/label/due filters over loaded
cards, multi-selection and keyboard-accessible context menus. Actions include
duplication, status/priority changes, agent copying and confirmed deletion with
per-task outcomes and bounded delete passes. - Add notes-to-draft editing, inline Manvi title/description suggestions and a
Quick Enhance sheet for saved tasks. Proposals respect field locks and require
explicit acceptance against the saved revision. - Add agent copy for new unsaved drafts and saved task briefs. Saved copies name
their revision and exclude unsaved edits; board copying reports its eight-task
limit and partial results. - Modular DevCouncil install in Setup: DevMap only (default), analysis suite, or
full host. Copy the documented command or run it in Terminal → Console.
Settings can disable or uninstall a GitPulse-owned binary without going
throughcargo uninstall. There is no uv / Python install path. - Save named stashes from the existing repository panel, with controls for
including untracked files and keeping staged changes. Preview entries inline
in the read-only code viewer before applying, popping, or dropping them. - Stage or unstage a selection in one native request. Bound path counts, bytes,
and argument chunks; evaluate every planned command before the first write,
hold one repository mutation lock, and report partial Git failures explicitly. - Scan GitHub Dependabot and code scanning alerts when a repository opens, and
warn when critical or high findings are open. Turn off under Settings →
Analysis. Failures stay in Health and diagnostics, not as an all-clear toast.
Changed
- Rebuild the command palette with eight discoverable search modes, fuzzy ranked
commands, file and repository search, complete view/section navigation, Clone and
Rebase dialog entry points, contextual availability, result paging and accessible
keyboard/focus behavior. Successful-use history is validated and bounded. - Keep palette searches current across query/mode/repository changes; show loading,
deadlines, failures, retry and partial coverage. Resolve cross-repository symbols
through the workspace registry before opening files, preserve help-mode transitions,
and make the status-bar palette entry work before its first lazy load. - Compact the Work inbox to open-and-read, fold notification settings, and give
automatic suggestions a board-sized control. Fold task enhancement locks and
repository membership into editor details. - Give the macOS status popover the app's native background blur, translucent
surfaces and rounded material bounds. Preserve the compact layout and provide
opaque accessibility fallbacks. Match the native window to the panel on resize
and reopen; the browser fixture includes a labeled glass simulation. Select
the tray display using physical bounds so Retina coordinates can open the panel. - Refine the macOS status popover around three large Changed, Staged and Conflicts
cards, a monochrome repository header, last-fetch counts and one blue primary
action. Keep stashes, workspace insights, the command palette and secondary
shortcuts inside Details, with Open GitPulse, Settings and Quit in the footer. - Named GitPulse as the successor to the deprecated LiquiTask workbench in the
README, wiki home, and Tasks documentation. - Document DevCouncil as independently selectable components and modules, Manvi
as the wrap around them, and GitPulse as the host that uses each for its
respective job. - Refresh README, feature, architecture, contributor and wiki guidance for Tasks,
schema-20 DevMap, current shortcuts, module ownership and verification limits.
Add a Tasks and workspaces guide; preserve older implementation plans as plans. - Resolve repository maps per worktree in both agent guides and document
devmap build --manifestfor missing generated state. - Re-vendor DevCouncil analysis crates at v0.2.0 (
devcouncil@a31918e2) from
rust/after that workspace flattened out ofrust-port/crates. Include
dc-evidencesodc-verifycan link. Re-vendordc-verifyso ledger writes
keep usingrigor::redact_secrets. - Add a CodeQL config that excludes
src-tauri/framework/**. Bindgen
offsetof tests and WRY cookie conversion in those ports are not GitPulse
sinks. Attach the file to default setup in GitHub Settings. - Refresh
@lucide/svelte1.44.0, Vite 8.3.0, and@types/node26.5.1.
Fixed
- Resume a GitHub draft whose
tag_namebecameuntagged-<hex>after
installer uploads, instead of posting a second draft./releases/tags/{tag}
does not return drafts, even while the tag is still attached; prepare lists
drafts by that tag or by the name it POSTs, and refuses a truncated page
rather than treating it as "no draft". Identify a draft by its tag and
release ID. GitHub often rewritestarget_commitishto a branch name after
associating an existing tag; a SHA intarget_commitishmust still match the
pinned commit, and a ref name is not a second pin. Anuntagged-placeholder
is accepted only in GitHub's hex form, and finalize writes the intended tag
name back with the notes. Platform builds upload by release ID only so
tauri-action cannot retarget the draft. Prepare now also deletes leftover
draft installers before the matrix rebuilds: GitHub 422s a second Windows
NSIS/MSI upload of the same name, and tauri-action retries that as a
flaky upload until the Windows leg fails. A draft still pinned to the
previous tagged SHA is retargeted onto this commit after that wipe, never
mutated until it is proven a mutable unpublished draft. - Sign every nested helper in the macOS universal bundle before the main
binary. Tauri copies every[[bin]]intoContents/MacOSand signs them in
manifest order — main first. OnceInfo.plistis in the bundle, codesign
treats that file as the bundle executable and every other Mach-O as nested
code that must already be signed.lipoproduces unsigned helpers, so the
sign ofgitpulsefailed withcode object is not signed at all / In subcomponent: gitpulse-hook.scripts/bin/codesignpiggy-backs on the main
binary's sign the same wayscripts/bin/lipostitches the helpers. - Quiet Linux GTK framework ports that drowned the release clippy log:
explicitextern "C"on libappindicator-sys, gir builder visibility and
TypedArrayData<'_>in javascriptcore-rs, crate-levelunexpected_cfgs
on webkit2gtk, and wryv2_42/macos_12_unavailablecheck-cfg plus
allow(deprecated)on webkitgtkrun_javascript. Path patches are
lint-capped, so those warnings never failed the job. - Name an in-flight CI or coverage run instead of treating it as "no
successful run".release-state readychecks that locally before thev*
tag is moved, so a tag pushed with main cannot burn preflight and then die
in the 5-minute prepare job. The release workflow still must not override
tauri-action'stauriScript; the npmtauriscript is what puts the
lipo and codesign shims on PATH. - Keep unmerged index entries in conflict review instead of reporting them
as staged and ready to commit. - Keep partially staged files visible on both sides in the sidebar and diff
rail, with separate churn counts. Stage-all, native menu enablement, explorer
actions, filters and previews include their remaining working edits. - Unstage files before the first commit without losing working content. Include
both sides when unstaging a rename so its old path is not left staged for deletion. - Commit selected files without including unrelated staged changes. Treat glob
characters as literal filenames, and allow amend with the existing message. - Refuse a missing branch without checking out a same-named working file.
- Clone into a private staging directory, then publish without replacing any
existing destination. Concurrent attempts cannot delete another clone's data;
failed cleanup identifies the retained staging directory. - Preserve stash-list and diff truncation across IPC and show limits in the UI.
Distinguish repeated stash OIDs by stack position and discard late previews
after repository switches or panel disposal. - Keep bulk staging and Quick Commit attached to their original repository
across tab changes and dialogs. Track interactive rebase through the same
guarded mutation owner and reject stale plans. - Keep bulk mutation activity visible through recovery refresh after failure.
- Reload task assistance when the shared model selection changes; ignore stale
responses and recover without reopening the editor. - Harden Manvi task drafting and review: preserve and consume extracted notes,
expose task model configuration, and retain mutation identities after lost
replies. Refuse stale or foreign proposal confirmations and unsaved-edit
acceptance. Keep task fields, enhancement history and runs stacked in one
scroller, with an opaque save bar that prevents text bleeding through controls. - Preserve the latest native menu update through transient bridge failures.
- Keep native menu shortcuts from also executing in the webview. Match the
platform's Command/Control binding so alternate webview shortcuts still work. - Fix macOS status-icon left click: do not keep an
NSMenuattached at rest so
clicks open the popover instead of the native menu (verified on macOS 27). - Stop labeling untracked environments, agent state, dependency stores, logs
and scratch directories as automatically safe to reclaim. Cleanup previews
validate ignored paths, tracked content, activity and file identities, and
refuse stale, repeated or incomplete plans. - Ignore in-app HTML5 and pointer drags on the native window drop path, so
moving a Kanban card or tab no longer paints "Drop a Git repository to open". - Treat an unborn HEAD (empty or orphan branch) as a graph notice, not a
diagnostics fault. - Keep Swift coverage
--package-pathinside the repository. Plan Go coverage
from a rootgo.workor each nested module, and prefer a JavaScript project's
declared coverage script or runner instead of inventingnpxcommands. - Parse code-intel query envelopes with the
SourceFreshnessobject the
native side actually sends. A leftover boolean would have made an unverified
tree look like a completed freshness check, and the IPC scanner now sees the
six codeintel commands that a helper had been hiding. - Treat
fresh: nullon advertised MCP output as an unverified check, not as
a missing required field. Count the live-echo cooldown storm instead of a
wall-clock window so coverage instrumentation cannot starve the bound.
Isolate spawn-limit fan-out onto a private gate, and give a command its full
timeout after it acquires a process slot so queue wait cannot report a
timeout for work that never started. Run instrumented Rust coverage on one
test thread so pipe and shebang fixtures are not starved. Cap uninstrumented
CI and releasecargo testat one thread so sidecar hello fixtures stay
inside their 20s window. Coverage detail and working-tree reads for an
outbound source symlink annotate the entry without following the target. - Look up commit blobs named
0:foo.pyorfoo*.pyon Windows without
trusting Git-for-Windows pathspec: match those names against
ls-tree --full-treeand read them withcat-file. Git for Windows
read-treestill refuses drive-shaped names (invalid path '0:foo.py')
even withcore.protectNTFS=false, so tests seed those commits with
mktreeand never install them into the index. Other glob and colon
names still enter the index throughupdate-index --index-info. Pin
core.autocrlf=falseon stash fixtures so checkout does not rewrite LF.
Classify relative.devcouncil/watcher events against an absolute
worktree. Clippy-D warningsno longer fails the Windows job on an unused
mutDirBuilder or a unix-only live-echo cooldown helper. - Keep Windows
--lib, hygiene, clippy, llvm-cov, and CI cache prefixes
completing: volume-root canonicalize, comctl32 v6 manifest, writable fixture
mtimes, ImageOS cache keys, coverage-relaxed sidecar deadlines, and
filesystem-monitor / shared-cache slash normalization. Detail remains under
[0.1.0]. - Seal macOS app bundles with an ad-hoc signature by default, avoiding invalid
linker-only signatures. A configured Apple signing identity can override this;
trusted distribution and notarization remain separate checks. - Cap layered-impact and preview fan-out at 16 seeds and report the omitted
remainder. A truncated walk is never presented as complete coverage. - Parse Dependabot, code-scanning, and dependency-health payloads as typed
reports instead of trusting raw JSON shape. - Plan a first push of an unpublished branch against a configured remote
(checkout.defaultRemote, thenorigin, then a lone remote). Refuse when
none of those exist rather than inventingorigin.
Security
- Complete gitignore-literal escaping for copied hygiene ignore rules so a
backslash cannot undo a later meta escape. Paths that still contain\are
refused for copy-ignore and need manual review. - Launch at login writes a per-user LaunchAgent only. It starts GitPulse with
--backgroundand does not add network access or broaden filesystem rights.
Autostart IPC is limited to the main window capability.
Verification
- Add real Git regressions, Tauri IPC round trips, clone races, bounded batch
stress, and stash overflow tests. Gate the expanded Git-client browser harness
in local CI and the Chrome/WebKit workflow. - See the release audit for measured
results, inherited work, security impact, evidence limits, and remaining
release gates.