Skip to content

Releases: bobofbuilding/idacc

IDACC 0.1.690-review.40 unsigned review

Pre-release

Choose a tag to compare

@github-actions github-actions released this 02 Aug 03:32
Immutable release. Only release title and notes can be modified.

IDACC review build — not a consumer release

This bundle contains native IDACC packages built from one exact source commit
for hands-on review across macOS, Windows, and Linux.

  • Each packaged application uses a review-only SemVer identity such as
    0.1.685-review.42; the source package version remains unchanged.
  • The macOS applications use a stable ad-hoc review requirement and are not
    Developer ID signed or notarized. Disk images are unsigned.
  • The Windows application and installer are unsigned.
  • Operating-system security warnings are expected.
  • Self-update is enabled only on the isolated review prerelease channel.
  • Updater descriptors bind every downloadable installer to its exact SHA-512.
  • No private signing or notarization credentials are used. The scoped automatic
    GitHub token may publish the verified packages as a GitHub prerelease.
  • The prerelease does not change the stable GitHub Latest route and is not an
    IDACC production update.

No user-supplied or private runtime-source credential is used. GitHub's scoped
automatic github.token reads the public IDACC and Manager repositories and
writes the pending/final review status and the isolated prerelease bound to the
exact IDACC commit. Checkout credential persistence is disabled. Brain is
supplied by the vendored runtime capsule committed with IDACC; the workflow
verifies the capsule before materializing or packaging it.

The capsule manifest binds its exact file inventory, modes, and content hashes
to the lock. It intentionally omits raw private Git tree objects because those
objects would disclose the names and hashes of excluded private siblings. The
private upstream commit/tree and recorded Git blob identities are publisher
assertions in this credential-free review; the capsule inventory and SHA-256
content tree are independently reproducible and tamper-evident. A maintainer
with private-source access can repeat the upstream comparison using the capsule
export tool.

Verify the files with SHA256SUMS before review. Use REVIEW-BUNDLE.json and
the records under platform-records/ to confirm the exact IDACC, Manager, and
Brain source identities.

The combined .tar.gz preserves the Linux AppImage's executable mode. If the
standalone Linux platform artifact is downloaded instead, run
chmod 0755 ID-Agents-Control-Center-*.AppImage before launching it.

The pinned AppImage launcher checks whether unprivileged user namespaces are
available and may conditionally request Electron's --no-sandbox fallback on a
host where they are unavailable. IDACC's review and production startup policy
rejects that request before bundled application modules load, writes clear
guidance, and exits; the application will not continue without its sandbox.
Enable unprivileged user namespaces or install the Debian package instead. The
Debian package is the preferred Linux review path because its installer can
configure the Chromium sandbox helper and AppArmor integration for the host.

The workflow's repository-owner and agent/** branch checks reduce accidental
execution and distribution of review artifacts. Branch protection, Actions
permissions, and repository or environment policy remain administrative
controls that repository maintainers must configure and review.

The first move from the legacy stable installation into this review channel is
a manual bridge install. Subsequent review versions can update in-app without
Apple notarization credentials while retaining the fixed GitHub repository,
prerelease channel, SHA-512 metadata, downgrade protection, and explicit
restart approval.

Do not redistribute these packages as consumer-ready software. A production
release still requires the normal signed-tag, code-signing, notarization,
verification, and publication gates.

IDACC 0.1.690-review.38 unsigned review

Pre-release

Choose a tag to compare

@github-actions github-actions released this 02 Aug 02:45
Immutable release. Only release title and notes can be modified.

IDACC review build — not a consumer release

This bundle contains native IDACC packages built from one exact source commit
for hands-on review across macOS, Windows, and Linux.

  • Each packaged application uses a review-only SemVer identity such as
    0.1.685-review.42; the source package version remains unchanged.
  • The macOS applications use a stable ad-hoc review requirement and are not
    Developer ID signed or notarized. Disk images are unsigned.
  • The Windows application and installer are unsigned.
  • Operating-system security warnings are expected.
  • Self-update is enabled only on the isolated review prerelease channel.
  • Updater descriptors bind every downloadable installer to its exact SHA-512.
  • No private signing or notarization credentials are used. The scoped automatic
    GitHub token may publish the verified packages as a GitHub prerelease.
  • The prerelease does not change the stable GitHub Latest route and is not an
    IDACC production update.

No user-supplied or private runtime-source credential is used. GitHub's scoped
automatic github.token reads the public IDACC and Manager repositories and
writes the pending/final review status and the isolated prerelease bound to the
exact IDACC commit. Checkout credential persistence is disabled. Brain is
supplied by the vendored runtime capsule committed with IDACC; the workflow
verifies the capsule before materializing or packaging it.

The capsule manifest binds its exact file inventory, modes, and content hashes
to the lock. It intentionally omits raw private Git tree objects because those
objects would disclose the names and hashes of excluded private siblings. The
private upstream commit/tree and recorded Git blob identities are publisher
assertions in this credential-free review; the capsule inventory and SHA-256
content tree are independently reproducible and tamper-evident. A maintainer
with private-source access can repeat the upstream comparison using the capsule
export tool.

Verify the files with SHA256SUMS before review. Use REVIEW-BUNDLE.json and
the records under platform-records/ to confirm the exact IDACC, Manager, and
Brain source identities.

The combined .tar.gz preserves the Linux AppImage's executable mode. If the
standalone Linux platform artifact is downloaded instead, run
chmod 0755 ID-Agents-Control-Center-*.AppImage before launching it.

The pinned AppImage launcher checks whether unprivileged user namespaces are
available and may conditionally request Electron's --no-sandbox fallback on a
host where they are unavailable. IDACC's review and production startup policy
rejects that request before bundled application modules load, writes clear
guidance, and exits; the application will not continue without its sandbox.
Enable unprivileged user namespaces or install the Debian package instead. The
Debian package is the preferred Linux review path because its installer can
configure the Chromium sandbox helper and AppArmor integration for the host.

The workflow's repository-owner and agent/** branch checks reduce accidental
execution and distribution of review artifacts. Branch protection, Actions
permissions, and repository or environment policy remain administrative
controls that repository maintainers must configure and review.

The first move from the legacy stable installation into this review channel is
a manual bridge install. Subsequent review versions can update in-app without
Apple notarization credentials while retaining the fixed GitHub repository,
prerelease channel, SHA-512 metadata, downgrade protection, and explicit
restart approval.

Do not redistribute these packages as consumer-ready software. A production
release still requires the normal signed-tag, code-signing, notarization,
verification, and publication gates.

IDACC 0.1.690-review.37 unsigned review

Pre-release

Choose a tag to compare

@github-actions github-actions released this 02 Aug 01:50
Immutable release. Only release title and notes can be modified.

IDACC review build — not a consumer release

This bundle contains native IDACC packages built from one exact source commit
for hands-on review across macOS, Windows, and Linux.

  • Each packaged application uses a review-only SemVer identity such as
    0.1.685-review.42; the source package version remains unchanged.
  • The macOS applications use a stable ad-hoc review requirement and are not
    Developer ID signed or notarized. Disk images are unsigned.
  • The Windows application and installer are unsigned.
  • Operating-system security warnings are expected.
  • Self-update is enabled only on the isolated review prerelease channel.
  • Updater descriptors bind every downloadable installer to its exact SHA-512.
  • No private signing or notarization credentials are used. The scoped automatic
    GitHub token may publish the verified packages as a GitHub prerelease.
  • The prerelease does not change the stable GitHub Latest route and is not an
    IDACC production update.

No user-supplied or private runtime-source credential is used. GitHub's scoped
automatic github.token reads the public IDACC and Manager repositories and
writes the pending/final review status and the isolated prerelease bound to the
exact IDACC commit. Checkout credential persistence is disabled. Brain is
supplied by the vendored runtime capsule committed with IDACC; the workflow
verifies the capsule before materializing or packaging it.

The capsule manifest binds its exact file inventory, modes, and content hashes
to the lock. It intentionally omits raw private Git tree objects because those
objects would disclose the names and hashes of excluded private siblings. The
private upstream commit/tree and recorded Git blob identities are publisher
assertions in this credential-free review; the capsule inventory and SHA-256
content tree are independently reproducible and tamper-evident. A maintainer
with private-source access can repeat the upstream comparison using the capsule
export tool.

Verify the files with SHA256SUMS before review. Use REVIEW-BUNDLE.json and
the records under platform-records/ to confirm the exact IDACC, Manager, and
Brain source identities.

The combined .tar.gz preserves the Linux AppImage's executable mode. If the
standalone Linux platform artifact is downloaded instead, run
chmod 0755 ID-Agents-Control-Center-*.AppImage before launching it.

The pinned AppImage launcher checks whether unprivileged user namespaces are
available and may conditionally request Electron's --no-sandbox fallback on a
host where they are unavailable. IDACC's review and production startup policy
rejects that request before bundled application modules load, writes clear
guidance, and exits; the application will not continue without its sandbox.
Enable unprivileged user namespaces or install the Debian package instead. The
Debian package is the preferred Linux review path because its installer can
configure the Chromium sandbox helper and AppArmor integration for the host.

The workflow's repository-owner and agent/** branch checks reduce accidental
execution and distribution of review artifacts. Branch protection, Actions
permissions, and repository or environment policy remain administrative
controls that repository maintainers must configure and review.

The first move from the legacy stable installation into this review channel is
a manual bridge install. Subsequent review versions can update in-app without
Apple notarization credentials while retaining the fixed GitHub repository,
prerelease channel, SHA-512 metadata, downgrade protection, and explicit
restart approval.

Do not redistribute these packages as consumer-ready software. A production
release still requires the normal signed-tag, code-signing, notarization,
verification, and publication gates.

IDACC 0.1.690-review.35 unsigned review

Pre-release

Choose a tag to compare

@github-actions github-actions released this 02 Aug 01:02
Immutable release. Only release title and notes can be modified.

IDACC review build — not a consumer release

This bundle contains native IDACC packages built from one exact source commit
for hands-on review across macOS, Windows, and Linux.

  • Each packaged application uses a review-only SemVer identity such as
    0.1.685-review.42; the source package version remains unchanged.
  • The macOS applications use a stable ad-hoc review requirement and are not
    Developer ID signed or notarized. Disk images are unsigned.
  • The Windows application and installer are unsigned.
  • Operating-system security warnings are expected.
  • Self-update is enabled only on the isolated review prerelease channel.
  • Updater descriptors bind every downloadable installer to its exact SHA-512.
  • No private signing or notarization credentials are used. The scoped automatic
    GitHub token may publish the verified packages as a GitHub prerelease.
  • The prerelease does not change the stable GitHub Latest route and is not an
    IDACC production update.

No user-supplied or private runtime-source credential is used. GitHub's scoped
automatic github.token reads the public IDACC and Manager repositories and
writes the pending/final review status and the isolated prerelease bound to the
exact IDACC commit. Checkout credential persistence is disabled. Brain is
supplied by the vendored runtime capsule committed with IDACC; the workflow
verifies the capsule before materializing or packaging it.

The capsule manifest binds its exact file inventory, modes, and content hashes
to the lock. It intentionally omits raw private Git tree objects because those
objects would disclose the names and hashes of excluded private siblings. The
private upstream commit/tree and recorded Git blob identities are publisher
assertions in this credential-free review; the capsule inventory and SHA-256
content tree are independently reproducible and tamper-evident. A maintainer
with private-source access can repeat the upstream comparison using the capsule
export tool.

Verify the files with SHA256SUMS before review. Use REVIEW-BUNDLE.json and
the records under platform-records/ to confirm the exact IDACC, Manager, and
Brain source identities.

The combined .tar.gz preserves the Linux AppImage's executable mode. If the
standalone Linux platform artifact is downloaded instead, run
chmod 0755 ID-Agents-Control-Center-*.AppImage before launching it.

The pinned AppImage launcher checks whether unprivileged user namespaces are
available and may conditionally request Electron's --no-sandbox fallback on a
host where they are unavailable. IDACC's review and production startup policy
rejects that request before bundled application modules load, writes clear
guidance, and exits; the application will not continue without its sandbox.
Enable unprivileged user namespaces or install the Debian package instead. The
Debian package is the preferred Linux review path because its installer can
configure the Chromium sandbox helper and AppArmor integration for the host.

The workflow's repository-owner and agent/** branch checks reduce accidental
execution and distribution of review artifacts. Branch protection, Actions
permissions, and repository or environment policy remain administrative
controls that repository maintainers must configure and review.

The first move from the legacy stable installation into this review channel is
a manual bridge install. Subsequent review versions can update in-app without
Apple notarization credentials while retaining the fixed GitHub repository,
prerelease channel, SHA-512 metadata, downgrade protection, and explicit
restart approval.

Do not redistribute these packages as consumer-ready software. A production
release still requires the normal signed-tag, code-signing, notarization,
verification, and publication gates.

IDACC 0.1.690-review.34 unsigned review

Pre-release

Choose a tag to compare

@github-actions github-actions released this 02 Aug 00:11
Immutable release. Only release title and notes can be modified.

IDACC review build — not a consumer release

This bundle contains native IDACC packages built from one exact source commit
for hands-on review across macOS, Windows, and Linux.

  • Each packaged application uses a review-only SemVer identity such as
    0.1.685-review.42; the source package version remains unchanged.
  • The macOS applications use a stable ad-hoc review requirement and are not
    Developer ID signed or notarized. Disk images are unsigned.
  • The Windows application and installer are unsigned.
  • Operating-system security warnings are expected.
  • Self-update is enabled only on the isolated review prerelease channel.
  • Updater descriptors bind every downloadable installer to its exact SHA-512.
  • No private signing or notarization credentials are used. The scoped automatic
    GitHub token may publish the verified packages as a GitHub prerelease.
  • The prerelease does not change the stable GitHub Latest route and is not an
    IDACC production update.

No user-supplied or private runtime-source credential is used. GitHub's scoped
automatic github.token reads the public IDACC and Manager repositories and
writes the pending/final review status and the isolated prerelease bound to the
exact IDACC commit. Checkout credential persistence is disabled. Brain is
supplied by the vendored runtime capsule committed with IDACC; the workflow
verifies the capsule before materializing or packaging it.

The capsule manifest binds its exact file inventory, modes, and content hashes
to the lock. It intentionally omits raw private Git tree objects because those
objects would disclose the names and hashes of excluded private siblings. The
private upstream commit/tree and recorded Git blob identities are publisher
assertions in this credential-free review; the capsule inventory and SHA-256
content tree are independently reproducible and tamper-evident. A maintainer
with private-source access can repeat the upstream comparison using the capsule
export tool.

Verify the files with SHA256SUMS before review. Use REVIEW-BUNDLE.json and
the records under platform-records/ to confirm the exact IDACC, Manager, and
Brain source identities.

The combined .tar.gz preserves the Linux AppImage's executable mode. If the
standalone Linux platform artifact is downloaded instead, run
chmod 0755 ID-Agents-Control-Center-*.AppImage before launching it.

The pinned AppImage launcher checks whether unprivileged user namespaces are
available and may conditionally request Electron's --no-sandbox fallback on a
host where they are unavailable. IDACC's review and production startup policy
rejects that request before bundled application modules load, writes clear
guidance, and exits; the application will not continue without its sandbox.
Enable unprivileged user namespaces or install the Debian package instead. The
Debian package is the preferred Linux review path because its installer can
configure the Chromium sandbox helper and AppArmor integration for the host.

The workflow's repository-owner and agent/** branch checks reduce accidental
execution and distribution of review artifacts. Branch protection, Actions
permissions, and repository or environment policy remain administrative
controls that repository maintainers must configure and review.

The first move from the legacy stable installation into this review channel is
a manual bridge install. Subsequent review versions can update in-app without
Apple notarization credentials while retaining the fixed GitHub repository,
prerelease channel, SHA-512 metadata, downgrade protection, and explicit
restart approval.

Do not redistribute these packages as consumer-ready software. A production
release still requires the normal signed-tag, code-signing, notarization,
verification, and publication gates.

UNSIGNED REVIEW — IDACC v0.1.686 review.24

Choose a tag to compare

@bobofbuilding bobofbuilding released this 29 Jul 17:17
Immutable release. Only release title and notes can be modified.
unsigned-review-v0.1.686-review.24

UNSIGNED REVIEW BUILD — NOT CONSUMER-READY

This public prerelease contains the seven native IDACC review installers built
from exact signed-source commit e3f02a15d470510db2138a331fef2e601c184b1d.

It is provided for hands-on review only:

  • macOS applications and disk images are unsigned and not notarized.
  • The Windows application and installer are unsigned.
  • Operating-system security warnings are expected.
  • Self-update is disabled and updater descriptors are intentionally excluded.
  • This prerelease is not GitHub Latest and is not a production update.

The packaged application includes the pinned ID Agents Manager 0.1.155 at
fcc6ad4fb357d21d34cb9622181e5bbbd874a502 and the verified Brain runtime
capsule 0.1.6 at upstream assertion
ad57302512cb526065260a3e88b137d5adcb145f.

Review workflow:
https://github.com/bobofbuilding/idacc/actions/runs/30470864055

Verify downloaded files against SHA256SUMS. The attached full review archive
also contains platform provenance, SBOMs, runtime manifests, the complete
review notice, and per-platform checksum records.

Do not redistribute these packages as consumer-ready software. The canonical
v0.1.686 release remains unpublished and can still be resumed when Apple and
Windows platform signing credentials are available.

v0.1.684

Choose a tag to compare

@bobofbuilding bobofbuilding released this 25 Jul 22:00

What changed

  • Bundle and supervise the ID Agents manager and Brain inside IDACC, isolate and migrate user state into app-owned profiles, add guided first-run readiness, and enforce clean-profile release verification.

v0.1.683

Choose a tag to compare

@bobofbuilding bobofbuilding released this 24 Jul 19:20

What changed

  • Automate evidence-based Brain proposal review through manager agents while preserving human review for unresolved or high-risk changes.
  • Harden Learn processing and recursive goal comparison with idempotent task creation, source-level perspective tracking, and bounded retries.
  • Unify goal cadence state between IDACC and the manager, deduplicate active-goal instructions, and expose clear cadence and fan-out controls.
  • Discover Claude CLI models from live local configuration and caches, preserve exact canonical model choices, and improve subscription and runtime catalog refresh behavior.

v0.1.682

Choose a tag to compare

@bobofbuilding bobofbuilding released this 24 Jul 13:49

What changed

  • Work now reports Under Review and Holding Pattern as one manager-supervised waiting flow.
  • Reconcile displays how many waiting tasks were actually routed, alongside validation recovery, stalled-owner triage, and assignment results.
  • The UI explains that both waiting lanes are recovered automatically by the manager, while the button provides an immediate bounded pass.

v0.1.681

Choose a tag to compare

@bobofbuilding bobofbuilding released this 24 Jul 01:55

What changed

  • Work: keep completed failures out of Holding and report all reconciled validation routes