Skip to content

Releases: boggspa/TaskWraith

TaskWraith v1.9.0

Choose a tag to compare

@boggspa boggspa released this 27 Jul 04:57

If 1.8.9 gave every agent room to work, 1.9.0 connects those rooms into a
workshop with a front door. Parallel lanes can return work you choose to keep,
top-level threads can leave one another durable notes, and human collaborators
can enter a host-reviewed People space without becoming agent authority. The
dock holds the documents, canvases, mail, and calendar context around the code;
Pi opens a broad BYOK model bench; and Mistral Vibe adds a plan-backed door. The
same local authority still decides what each seat may touch—or which colours it
may change—while product observation remains a clear, optional choice.

Branches come back as candidates

Write-capable fan-out lanes can now ask for an isolated worktree instead of
sharing the checkout. Each lane forks from the committed workspace boundary,
returns a durable candidate, and appears in a Compare dock where its patch can
be inspected and promoted deliberately. The composer exposes that choice as an
Isolate toggle, while ensemble_await and ensemble_lane_result give agent-run
workflows a real join-and-read step rather than making a synthesizer scrape the
panel transcript.

Git work is easier to follow before and after the fan-out. Main owns a
per-thread workflow marker, the sidebar groups marked threads under Git with
their true repository name, and worktree patches have explicit capture/apply
contracts. Read-only postures can inspect git status, git diff, and
git log without an approval card, so review lanes can gather evidence without
borrowing mutation authority.

A panel stays a panel

Turning a normal thread into an Ensemble now creates at least two seats, so the
extra orchestration chrome always opens onto an actual panel. If a two-seat
panel loses one participant through the ordinary composer controls, the thread
returns to a solo chat on the remaining seat instead of persisting a one-agent
Ensemble. Explicit agent-authored or saved-preset one-seat rosters remain
untouched: TaskWraith does not rewrite a roster that was deliberately stated.

Threads can knock on another door

Top-level threads gain peer messages: a durable, permission-gated inbox for
passing a note to another task without pretending the two provider sessions
share context. A message enters the target's next turn exactly once, visibly
labelled as untrusted relayed content; an optional wake remains a separate,
more privileged choice. Exact ids and unambiguous titles resolve in main, the
startup sweep catches queued delivery, and user- plus agent-originated sends
converge on the same authority.

The Peers dock makes that path visible on desktop, and the paired iPhone/iPad
companion can read the inbox, send a reply, and show the same pending indicator.
Sub-thread return still flows child to parent; peer messaging is the deliberate
sideways path between independent top-level tasks.

People can enter without becoming an agent

Human collaboration now calls itself People instead of Shares and makes the
host boundary easier to read. Invite-issued, offline, and live states are
distinct; contribution-rule presets say what a collaborator may request;
participants can be removed individually; and an expandable activity log
explains admission, disconnect, duplicate/rejected contributions, and draft
insertion instead of making a dropped comment look like it vanished. Even the
strongest preset only prepares a host draft—the user still decides whether to
send it to an agent.

Unpackaged builds also gain a same-Mac rehearsal lane: separately named
instances receive separate app data, single-instance locks, identities, and
relay and Tailscale Serve ports. An explicit LAN-only or loopback invite appears
only after the corresponding remote-reachability guard refuses that invite, so
the rehearsal does not weaken the packaged remote boundary. Side-by-side boot,
data isolation, and port separation have been exercised; the collaboration
handshake and unrelated-network two-Mac flow have not, so this remains a test
path rather than a production-connectivity claim.

The dock becomes a desk

A new Office dock brings focused editors for Word documents, spreadsheets,
slide decks, calendars, and mail drafts into the workspace. TaskWraith can
round-trip DOCX, XLSX, PPTX, and ICS through bounded local codecs, preserve
deck speaker notes and document images, import dropped files, and open or reveal
grant-covered documents outside the workspace without turning a reference into
silent access.

An optional Outlook connector uses Microsoft's device-code sign-in to read
mail and calendar context, save email drafts, and create personal time blocks.
It deliberately has no send-mail permission, refuses invite-producing attendee
creation, bounds Graph responses, and treats message/event text as untrusted
third-party content. Canvas work also joins the right dock with sketch embeds
and chat-scoped list/close controls, so visual and document context can stay
beside the thread that owns it.

Agent-driven Canvas actions now fail closed when a target or human-input
snapshot is stale, serialize per surface, and stand down while a human is driving.
Credential fields remain human-only, in-progress sketch strokes survive agent
updates, and the audit receipt is persisted before a liveness check can fail.
Canvas drivers remain bound to their isolated surfaces and must never target
TaskWraith's own consent chrome; pausing for recent human input is courtesy,
not a substitute for that structural boundary.

Canvas consent follows the surface

Permission to let an agent interact with a preview now applies only to the
surface you approved
, not to every preview opened afterwards in the same run
— an agent can enumerate a chat's canvases, so an unscoped grant reached
windows you never saw a prompt for. Because a workspace-wide "interact with any
preview, in any chat, until revoked" grant is not a scope anyone can
meaningfully consent to, it can no longer authorize an interaction; a broader
grant persisted by an older build is inert rather than honoured.

Relatedly, and worth stating plainly: when an agent asked to type into a field,
the approval record kept the text it was about to type, and that record reached
TaskWraith's durable history — even though the tool contract told agents the
typed value was never recorded. New runs no longer store it. Existing history
is not rewritten
, so if a previously typed value was sensitive, clear that
chat's history.

Pi opens the model bench

Pi joins as a first-class coding-agent seat with isolated runtime homes and
bring-your-own-key access to DeepSeek, Z.ai/GLM, Qwen, MiniMax, Mistral, Groq,
and Cerebras models. Each upstream has its own key boundary, model names,
pricing row, spend attribution, and brand hue; pickers show only configured
upstreams, transcript attribution keeps the actual upstream's hue, and desktop
plus iOS carry the same provider/model map. The New Additions card now leads
with that upstream lineup.

AntiGravity becomes steadier at the same time: conversations resume, successful
model discovery is cached, unservable catalogue rows are filtered, Gemini 3.x
thought signatures survive tool replay, and schema unions stay real unions.
Denied services remain denied, cache reads are disclosed, and throttling is
distinguished from a genuinely empty allowance.

Mistral gets its own door

Mistral Vibe joins as a first-class ACP seat for the user's Mistral plan,
separate from Pi's metered mistral/* API-key upstream. Devstral Small is the
fast, frugal default beside Mistral Medium 3.5; both carry their 262K context
map onto iOS, and a clearly heuristic plan-burn meter gives the otherwise
unmetered subscription a cautious early warning.

The distinction is authority, not just branding. Read-only and write-capable
seats select Vibe's gated plan and default session modes over ACP; its
auto-approve modes are unreachable, and inherited Mistral API credentials are
scrubbed so a plan-backed run cannot silently cross into Pi's pay-as-you-go
bill. Fresh sessions receive explicit host-composed context instead of
pretending provider history was retained. Provably read-only shell commands
remain useful in Plan, while short Vibe throttles surface as retryable warnings
instead of masquerading as a subscription quota wall.

The composer model picker and iOS first-launch sheet now carry that same
Mistral roster, and New Additions no longer promises an image-input capability
the seat does not expose. An opt-in live exercise against vibe-acp 2.22.0
also proves the normal lane can select Plan plus Devstral Small, use plan
credentials without inheriting an API key, return an answer, and close cleanly.
That source exercise is evidence for the ordinary ACP lane, not a substitute
for the scheduled-seat release seal.

The workshop can wear your colours

Agents on write-capable seats can read and set a small allowlist of typed
theme tokens through theme_tokens_get and theme_tokens_set. This is a
data channel, not arbitrary CSS: selectors, rules, URLs, calculations, provider
identity colours, focus rings, and approval-card geometry stay outside the
writable set, with validation repeated when the renderer applies persisted
values. Successful writes are pushed narrowly to every open window and applied
through the same validated appearance path, so the change appears without a
reload. Read-only review seats can inspect the palette but cannot restyle it.

Two properties of the appearance channel are deliberately not negotiable. A
restyle always asks: theme_tokens_set prompts on every call, and no standing
grant, trusted session, or session-wide auto-approve can quiet it — previously
a single "allow for this session" on any unrelated tool silenced every later
restyle. And the approval card's own controls no longer take their spacing
from values an agent can write, so a restyle cannot crowd Accept and Reject
together and turn a ...

Read more

TaskWraith 1.8.9

Choose a tag to compare

@boggspa boggspa released this 24 Jul 20:02

TaskWraith 1.8.9

Every release of TaskWraith has quietly been about the same question: how much
can you trust a panel of agents with, and how little do you have to babysit
them? 1.8.9 answers with elbow room. Agents get their own isolated checkouts.
Your merged work gets a watcher. The panel stops wasting turns on etiquette.
And you get to look away.

A room of their own

Runs that need one now claim an isolated worktree before dispatch
allocated during preflight, bound per-thread, persisted asynchronously, and
reused on later turns. Parallel threads stop editing the same checkout out
from under each other, and Diff Studio follows the allocated worktree, so
review shows the tree the agent actually edited rather than the base checkout.
The same instinct runs deeper: Codex's runtime home is now seat-local, and
main-owned chat state (worktree bindings included) survives stale renderer
saves.

Someone keeps watch

The GitHub popover gains Watch this PR — a per-chat opt-in that keeps
polling after the agent's work lands. The poller is main-owned and skeptical:
it revalidates the PR number and head before posting a change, deduplicates
repeated CI states, and reports auth or missing-PR failures instead of
silently dropping them. Close the laptop; TaskWraith watches the checks.

AntiGravity takes a full seat

Introduced in 1.8.8, AntiGravity now becomes a first-class Ensemble
participant
: lane-aware reachability, isolated seat prompting, serial and
fan-out routing, compaction, usage telemetry, grants, and every ordinary
participant affordance. Tool Grants close the same gap for Cursor — every
brokered live provider now shows the workspace-grant controls its broker
actually honors.

Rounds that get to the point

Every seat receives a concrete statement of what its posture permits, Boss
guidance favors one explicit-target fan-out and closes finished goals without
confirmation laps, audited ensemble_send participation stops masquerading as
a scary mutation approval, and background lanes run under their seat's own
posture. The separate Work Session mode retires in favor of the primitives
that outgrew it. And the Blackboard learns rich polls — put a question to
the panel, count the votes.

New minds on the roster

Claude Opus 5 arrives across desktop and iOS — default 1M context, the
full reasoning ladder through Ultracode, optional Fast mode. The New Additions
card leads with it beside the current Gemini 3.6/3.5 Flash lineup, identical
on both platforms.

Calm to read, quick to follow

Settled transcript activity folds instead of jumping — animated super-group
transitions on desktop and iOS, auto-follow that survives participant
boundaries, a jump pill that counts real messages. Approval requests float
above the composer. iOS converges all roster and side-chat creation on the
combined provider/model picker. And two long-standing irritations end: a
launch stall from unbucketed usage history, and phones buzzing with
intermediate task notifications.

See CHANGELOG.md in the tagged source for the complete notes.

Artifact record

  • Tag / commit: v1.8.90867c80c2 (macOS artifacts built from this
    commit; 63 commits ahead of v1.8.8; iOS follow-on fdb545d01).
  • macOS: notarized universal .dmg + .zip (Developer ID Application:
    Christopher Izatt, 8CZML8FK2D). DMG notarization submission
    1fb45460-7261-4572-9576-77281c34513b (Accepted); stapled and verified
    with spctl (source=Notarized Developer ID) + stapler.
    latest-mac.yml published for stable-channel auto-update.
    • SHA-256 .dmg: 735e90c0180713b94df2efe4c2788deeeee40f4e0929327a0f6cd096bcafce5f
    • SHA-256 .zip: aae1885afcb7b8debf8314b5168599aafe523ba924edbf99d0c9df4d811282d2
  • iOS/TestFlight: 0.1.0 (84) uploaded, delivery UUID
    c90d29e5-a38f-4d43-a4ee-0f765446e594 (processing).
  • Windows/Linux: attached after this release via the boolean-dispatch flow on
    --ref v1.8.9 (SHA-verified artifacts, feeds validated locally).
  • Source verification: gates green before bump (ci 14,244; validate:release
    all steps; Kit 462/61 solo; bridge 91); full matrix green on pre-bump tip
    2a8e11d4a (run 30120910920) and on the bump commit before tagging. Also
    carries the post-1.8.8 electron-updater credential-leak patch
    (GHSA-p2f4-r6v6-j797).

TaskWraith 1.8.8

Choose a tag to compare

@boggspa boggspa released this 24 Jul 09:38

TaskWraith 1.8.8

TaskWraith 1.8.8 introduces the opt-in AntiGravity provider, live estimated
token telemetry across the CLI providers, and a broad reliability pass over
Ensemble routing, the transcript, and startup.

Highlights

  • AntiGravity (opt-in). Bring your own Gemini API key and run Gemini
    models as a first-class provider — isolated per-turn execution,
    authenticated model discovery with product names, a prompt-cache setting,
    and an estimated-spend meter with a soft monthly budget in Model Usage. The
    API-key lane behaves like every other bring-your-own-key provider; the
    separate AntiGravity CLI integration stays behind its own informed-consent
    card with per-lane consent and honest dormant/rollback semantics.
  • Live token telemetry. Grok, Cursor, and Kimi stream estimated working
    telemetry (text, thinking, and tool output) from one shared token-estimate
    authority; the working indicator and composer tally mark estimates and
    prefer live provider totals for context tracking.
  • A ChatGPT composer shell. Codex's above-row paired with a flat capsule
    body, satellite actions, and a wider model control.
  • Boss full-roster fan-out. One action fans work out to the whole
    Ensemble roster, each participant under its own permission posture, with
    visible turn order.
  • Transcript super-groups. Adjacent one-line summaries condense into
    compact super-groups on desktop and iOS, and every message gains a
    message-only copy action.

Reliability

  • Closing the window no longer ends active runs.
  • Startup defers project-reference reconciliation, prewarms roster discovery
    after first paint, and bounds ensemble provider discovery.
  • Ensemble: explicit foreground yields honored, picker routing kept out of
    composer text, seat-change announcement noise removed, Cursor runs bounded
    against yield/transport zombies and missing terminal events, concurrent
    Cursor MCP broker routes isolated, Codex tolerant of structured app-server
    errors.
  • Transcript: stable attribution columns, short thought durations included,
    read-only-aware attachment modal, and less chrome noise.
  • Permissions: git status allowed in read-only plans, trusted external
    writes honored, unsupported provider grants rejected.

See CHANGELOG.md in the tagged source for the complete public notes.

Artifact record

  • Tag / commit: v1.8.865213b23 (macOS artifacts built from this commit;
    115 commits ahead of v1.8.7; the iOS build-number bump follows on as
    6bac15af0).
  • macOS: notarized universal .dmg + .zip (Developer ID Application:
    Christopher Izatt, 8CZML8FK2D). DMG notarization submission
    1bb75c63-7080-4ac4-ba97-688a5254480f (Accepted); stapled and verified with
    spctl (source=Notarized Developer ID) + stapler. latest-mac.yml
    published for stable-channel auto-update.
    • SHA-256 .dmg: 83a39277770127dfa4e47580ecabb2e90105439c925aa68d2f087c6df89c5d54
    • SHA-256 .zip: b48fcff33d85f02b7331a1244b783c0847d3b3799aa1d0a70e2d3c235ad05672
  • iOS/TestFlight: 0.1.0 (83) uploaded to App Store Connect, delivery UUID
    ec30c133-6bdc-4541-888b-7b974e02503a (processing).
  • Windows/Linux: attached via CI workflow dispatch from --ref v1.8.8 after
    this release.
  • Source verification: local gates green before bump (npm run ci 14,066;
    validate:release all steps; iOS Kit 458/60 solo; bridge 91) AND the full
    GitHub matrix green on the pre-bump tip b1f19151a (run 30080947397) plus
    the bump commit's own matrix before tagging.

TaskWraith 1.8.7

Choose a tag to compare

@boggspa boggspa released this 22 Jul 20:57

Highlights

  • Choose the Blackboard section—Decisions, Facts, Risks, Do Not Repeat, or Notes—when posting from the Composer.
  • Settled transcript activity and system notices fold into expandable one-line summaries, with matching iOS companion treatment.
  • Welcome usage history can build a full 90-day heatmap in the background.

Fixes

  • Provider quota refreshes now time out rather than blocking the desktop.
  • Ensemble routing is more deterministic, Blackboard post handling fails closed, and file changes use official provider marks.

TaskWraith 1.8.6

Choose a tag to compare

@boggspa boggspa released this 22 Jul 11:57

TaskWraith 1.8.6

TaskWraith 1.8.6 is a desktop and iOS companion release focused on resilient
queued work, Path-B Cursor support, and a verified macOS distribution.

Highlights

  • Packaged macOS stability: hardened Electron fuses are re-signed in the
    final application bundle, preventing the startup crash caused by an invalid
    code-signature page.
  • Queue workflow restored: follow-up messages during an active run return
    to the durable RunQueue and classic Steer controls; routine busy sends no
    longer force the Execution Stack UI.
  • Managed Cursor (Path-B): Cursor is selectable through its contained
    native sandbox, with CLI login and sidebar usage meters restored.
  • iOS companion improvements: richer transcript formatting, message
    actions, mentions, Diff Studio inline hunks, liquid-glass sheets, and
    Blackboard bridge actions.
  • Permissions and recents: workspace-write posture handling, workspace
    grants, background usage loading, and recent-thread ordering are more
    reliable.

Distribution

  • macOS universal build is signed, notarized, and stapled.
  • The bundled macOS update feed includes the stapled DMG checksum and size.
  • iOS companion build 0.1.0 (81) was submitted to TestFlight for Apple
    processing.

See CHANGELOG.md
for the complete user-facing change list.

TaskWraith 1.8.5

Choose a tag to compare

@boggspa boggspa released this 20 Jul 18:18

1.8.5 - 2026-07-20

Added

  • Kimi ACP sessions can resume as durable, isolated seats. Native ACP
    continuity now survives TaskWraith run boundaries, with seat checkpoints,
    resumable provider sessions, and bounded prompt compaction for longer-lived
    work.
  • Kimi K3 exposes selectable thinking and plan-aware context. K3 offers
    Low, High, and Max reasoning controls, while the usable context limit follows
    the detected Moonshot plan from 256K through as much as 1M rather than
    advertising one fixed window to every account.
  • Needs your input surfaces pending agent questions. A global banner and
    Sidebar/Approvals attention markers call out chats that are waiting on a
    user answer, and the unfocused desktop window can bounce or flash so a
    parked question is harder to miss.
  • Node Graphs show project thread relationships. A Work-scoped sidebar
    section and thread-graph pane project user-drawn dependency edges between
    chats, with SVG connectors for the active project map.
  • Execution Graph, Stack, and Map inspect main-owned run structure. Main
    owns stack runtime, permission ceilings, terminal joins, and dispatch wiring
    so repository diagnostics and attention stacks stay coherent across
    multi-step work.
  • PDF text extraction and on-device OCR are brokered tools. Bundled
    pdfjs-dist text-layer extraction plus generalized Vision OCR let agents
    read PDF text and image contents through TaskWraith-hosted tools rather than
    opaque provider-side parsing.
  • Projects have a guarded reference library. A selected project now exposes
    a References section for cataloguing relevant files, folders, and links. Each
    row can be excluded from or restored to the library, removed, and—when it is
    a file or folder—checked for last-known availability. The main-owned Projects
    registry persists the metadata through main-renderer-only IPC and the
    renderer facade. Its file/folder picker remains deliberately separate from
    access-grant pickers, verification performs one main-side existence check
    without reading content, and URL verification is rejected rather than
    fetching the network. A reference grants no file or network access and is
    never indexed or injected into agent context.
  • Sub-thread status ticker and Ensemble mailbox delivery. Parent chats show
    a live sub-thread status ticker, and Ensemble parents can drain a durable
    sub-thread mailbox into the idle authority seat once so returned worker
    results reach Boss/Captain context without a manual paste.
  • Host-rerun continuation keeps Codex work on a fresh run identity. After a
    host rerun, TaskWraith mints an independent continuation run that resumes the
    existing provider session instead of double-joining history on the approval
    run or spawning a virgin seat.
  • The host sky follows local conditions. Weather, solar and lunar state,
    and the starfield can now shape the optional sky effects. When those effects
    are enabled, TaskWraith resolves the host's approximate location through
    ipapi.co with ipwho.is as fallback, rounds coordinates to 0.1 degrees
    (about 11 km) before requesting Open-Meteo data, and stores the result in the
    local host-weather-cache.json. No workspace or task content is sent as part
    of that lookup.

Changed

  • Cursor runs again under Path-B contained native sandbox (+ write).
    Managed Cursor is always-enabled (no brittle per-build fingerprint gate) and
    re-admitted through the shared CLI transport. Production argv always comes
    from the contained builders that hard-pin --sandbox enabled, with separate
    read-only and write-capable argv shapes routed by seat permission—never a
    bare uncontained cursor-agent spawn, never sandbox-disabled / force /
    yolo / resume-token argv from the production entry.
  • Fresh Ensemble panels start small and role-shaped. New Ensemble chats now
    seed at most four active seats (Boss, Captain, Specialist, and an independent
    Outsider), while new saved roster presets begin with the first three roles
    and room for at most five. The twenty-seat limit remains a capacity ceiling
    rather than the default panel size.
  • Primary navigation is organized as Chat, Code, and Work. The surface
    split makes conversation, workspace activity, and projects/workflows easier
    to distinguish. Switching or choosing a workspace from a pristine draft now
    preserves its selected provider, model, reasoning, permission posture, and
    unsent composer text.
  • Provider brand marks appear on the transcript filter rail. Official
    provider logos replace ad-hoc colour-only chips so multi-provider transcripts
    are easier to scan.
  • Solo tool grants stay editable while a run is live. Permission grants for
    solo seats can be adjusted during an active turn without waiting for the run
    to finish.
  • Projects now use a main-backed optimistic registry. Shared pure registry
    operations, a main-owned projects.json, snapshot/apply/import IPC, change
    broadcasts, one-shot legacy import, and explicit main-renderer channel
    classification establish the durable boundary. The renderer store now uses
    that boundary through an optimistic facade. Main-owned Project Work profiles
    also establish an atomic home-chat claim for each project, with Work-surface
    controls to set, clear, and open the claimed home. View-only preferences such
    as the active surface and expanded state remain in renderer storage, while
    per-surface search queries stay session-only. An unhomed project can also
    Start Project Home: TaskWraith opens an ordinary pristine General draft
    and claims it for that project on the first committed message or run, while
    an abandoned draft remains reusable/reapable like any other pristine draft.
  • The right dock remembers the surface for the current context. Chat and
    Code keep the last-selected dock destination per chat for the current app
    session. In Work, a chat that belongs unambiguously to one project uses that
    project's dock memory, so moving among the project's member threads retains
    the same destination; ambiguous membership safely falls back to the chat.

Fixed

  • Provider and orchestration edges are more resilient. Fixes cover Kimi
    transport and usage hardening, Ensemble roster imports, stale broker sockets,
    and related run-lifecycle cleanup.
  • Grok broker tools advertise under the TaskWraith MCP namespace. The
    progressive gateway presents Grok-facing broker tools as TaskWraith rather
    than a legacy unqualified surface, and parent-provider binding prefers the
    live run session so approval modals name the correct seat.
  • External activity includes Grok and keeps paired-device rollups honest.
    The activity scan reads Grok usage instead of reporting zero, and the paired
    device rollup agrees with the header totals.
  • Universal Mac builds ship both @napi-rs/canvas architectures. The
    notarized macOS package includes the canvas native binaries required on both
    Apple Silicon and Intel so Canvas/PDF paths do not miss one arch.
  • iOS reconnect wakes coalesce instead of flap. APNs, foreground, and path
    reconnect signals single-flight through one coordinator so the companion no
    longer races competing reconnects after push or resume.

Security

  • Managed Kimi authentication and admission stay fail-closed where it
    matters.
    Rotating Kimi OAuth credentials use a source-home-keyed durable
    authority across isolated ACP seats and crash recovery. The brittle per-build
    fingerprint gate is dropped for always-enabled development admission, but
    packaged builds still require an exact reviewed runtime tuple and the
    embedded qualification roster remains intentionally empty—so packaged Kimi
    and sealed scheduled Kimi execution stay unavailable until their respective
    admission/authority evidence is commissioned. A successful kimi login or a
    Settings usage key does not qualify a managed run.
  • Manual unsigned builds cannot write GitHub Release assets. Windows and
    Linux testing builds now upload only immutable SHA/run-labelled Actions
    artifacts under read-only repository permission. The credentialed provider
    canary also stays fail-closed until its protected environment has been
    explicitly commissioned, and signed publication requires a fresh successful
    exact-commit canary attestation plus commissioned immutable v* tag/release
    controls. Both signed publishers re-resolve the remote tag and reject
    auto-created or moved tags before uploading.
  • Deleting chat history now clears the adjoining TaskWraith audit state. The
    Settings action removes chats, run/run-queue and execution-graph history,
    approval/feedback ledgers, sub-thread mailboxes, Canvas workspaces/artifacts,
    Kimi seat state, and the bridge subprocess log. Provider-native history and
    provider credentials remain separate and are not removed by that control.
  • canvas_eval receipts retain correlation metadata instead of executable
    content.
    Human-approved execution and Canvas-audit receipts retain the
    joined approval id, unkeyed SHA-256 digest, lengths, and outcome rather than
    script/result content. Auto-denial and compatibility/tool rows are
    content-redacted but may omit that full receipt. The digest is integrity and
    correlation metadata, not encryption; provider-authored transcript prose,
    provider-native history, and opt-in debug capture remain outside the
    guarantee.

Ship commit: 314c2338a6cb250940f4889f53a1f8957ec270ff
CI matrix: run 29765225079 (success)
Notary (DMG): 0fa4889c-19ab-49e0-a099-a99ea1674bf9 Accepted
iOS companion: build 80 VALID on App Store Connect / TestFlight

TaskWraith 1.8.4

Choose a tag to compare

@boggspa boggspa released this 16 Jul 21:03

TaskWraith 1.8.4

TaskWraith 1.8.4 is a focused reliability release for transcript reading,
multi-provider dispatch, and Sidebar update chrome.

Highlights

  • Transcript scrolling stays under the reader's control. Scrolling away
    from the live edge now remains authoritative while new messages, thinking,
    and tool activity arrive — including when a pristine chat replaces its
    welcome surface with the first real transcript. Jump to latest counts
    unseen activity until you deliberately return.
  • Concurrent Ensemble seats launch reliably. Ordinary dispatches into one
    chat keep independent reservations, so overlapping fan-out lanes no longer
    fail with a false live-owner conflict. Scheduled work remains excluded while
    any ordinary dispatch is live.
  • Sidebar update progress stays visually seamless. The update pill now
    shares the fixed-opacity chrome band with the masthead, workspace counters,
    tabs, and search instead of opening a mismatched strip above them.

See CHANGELOG.md in the tagged source for the complete public notes.

Artifact record

  • Tag / commit: v1.8.4f67f5f058 (4 implementation commits ahead of
    v1.8.3, plus the release commit).
  • macOS: notarized universal .dmg + .zip (Developer ID Application:
    Christopher Izatt, 8CZML8FK2D). App notarization submission
    e76f88c5-30c2-41ec-becd-84338a84cf95; DMG notarization submission
    3829ea7e-5edc-4961-ad32-28d81a4b42a7 (both Accepted). App + DMG stapling,
    Gatekeeper, packaged launch smoke, and latest-mac.yml feed validation all
    passed.
    • SHA-256 .dmg: f6f27029ee245a9b5e9aa4534614fac062f04d7cc757def4298e5b2af7094e31
    • SHA-256 .zip: 765bdc3fbed465a10d67abbfa7880cfd4e9f6f78c920895e010c9ded170a8453
  • iOS/TestFlight: 0.1.0 (79) uploaded successfully, delivery UUID
    d2fef9f6-7681-46af-89e7-ceaf8f480561 (processing).
  • Windows: exact-tag CI attachment run 29534607603 succeeded, including the
    full five-gate matrix and the unsigned x64 + arm64 installer build/upload.
  • Linux: exact-tag CI attachment run 29534615907 succeeded, including the
    full five-gate matrix and the AppImage + deb build/upload. The published
    Windows and Linux update feeds were downloaded back from the release and
    verified at version 1.8.4 against their uploaded artifact names and sizes.
  • GitHub release inventory: 15 uploaded assets across macOS, Windows, and
    Linux (plus feeds, blockmaps, checksums, and SBOM).
  • Source verification: local gates green before bump (11,760 tests; iOS Kit
    416/55; bridge suite; validate:release all steps). Source-tip matrix
    29532725344 and exact ship-commit matrix 29533547714 both green on all
    five required legs before tagging.

TaskWraith 1.8.3

Choose a tag to compare

@boggspa boggspa released this 16 Jul 15:22

TaskWraith 1.8.3

TaskWraith 1.8.3 is a fast-follow to 1.8.2: it adds Moonshot's new Kimi K3
flagship and restores Windows and Linux as shipping platforms.

Note for Windows and Linux users: 1.8.2's Windows/Linux artifacts were
never published — 1.8.3 is your first update since 1.8.1 and includes
everything from both releases.

Highlights

  • Kimi K3. Moonshot's new flagship model joins the Kimi provider — 256K
    context, always-on Max-effort thinking, built for long-horizon agentic
    coding. Selectable alongside Kimi K2.7 Code (which stays the default and
    keeps its Standard/HighSpeed Fast toggle) across solo, Ensemble, queued,
    scheduled, and remote runs.
  • Windows is a first-class platform again. Four Windows-fatal defects from
    the recent hardening work are repaired: scheduled-workflow persistence no
    longer fails on directory-fsync, media persistence no longer rejects every
    asset (platform-aware permission and identity checks), and hardened Git
    invocations no longer fatal before running.
  • Linux + concurrency hardening. Staged media cleanup is safe against
    ext4 inode reuse, and concurrent identical media ingests always deduplicate
    to the canonical asset.

See CHANGELOG.md in the tagged source for the complete public notes
(including the full 1.8.2 entry this release carries to Windows/Linux users).

Artifact record

  • Tag / commit: v1.8.343547d87 (macOS artifacts built from this commit;
    13 commits ahead of v1.8.2).
  • macOS: notarized universal .dmg + .zip (Developer ID Application:
    Christopher Izatt, 8CZML8FK2D). DMG notarization submission
    d15b299e-b09e-45b4-83a6-b319274b3d12 (Accepted); stapled and verified with
    spctl (source=Notarized Developer ID) + stapler. latest-mac.yml
    published for stable-channel auto-update.
    • SHA-256 .dmg: c9a69eea30277e43c117f3352c8cb45cac45062772631f797bbad297c91e7aae
    • SHA-256 .zip: 469aaea5f392e0024cdd57f314c331f4aeaea8b779ae1cdebf25993949cb1b02
  • iOS/TestFlight: 0.1.0 (78) uploaded to App Store Connect, delivery UUID
    e6be9771-2e49-4cd5-8171-6d8f8a767d29 (processing).
  • Windows/Linux: attached via CI workflow dispatch from --ref v1.8.3 — all
    platform fixes are in-tag this cycle.
  • Source verification: local gates green before bump (11,749 tests; iOS Kit
    416/55; bridge 88; validate:release all steps) AND the ship commit's full
    GitHub matrix green on all five legs (run 29509434288) before tagging.

TaskWraith 1.8.2

Choose a tag to compare

@boggspa boggspa released this 16 Jul 12:46

TaskWraith 1.8.2

TaskWraith 1.8.2 hardens the workbench's execution core: Kimi Code moves to a
contained ACP transport by default, scheduled workflows gain end-to-end
occurrence authority, and the iPhone/iPad companion can now operate workflows
directly.

Highlights

  • Kimi Code runs through a contained ACP transport — now the default.
    Sessions run in an isolated provider home while TaskWraith holds workspace
    file authority through its brokered read/write/edit tools, with per-tool
    approvals matching the stdio providers and the TaskWraith gateway MCP served
    over HTTP. Setup copy is transport-aware, per-run thinking flows through ACP
    configuration, and the usage meter reads the Kimi Code OAuth credential —
    refresh-token rotation persists back to the CLI home so later logins stay
    valid.
  • Kimi Code HighSpeed. Kimi K2.7 Code offers Standard and HighSpeed tiers
    through the familiar Fast control across solo, Ensemble, queued, and remote
    runs.
  • Workflow controls from the iPhone/iPad companion. Scheduled workflows can
    be paused, resumed, or run immediately from iOS, with every write action
    authorized against the host's native consent and authority checks.
  • Scheduled workflow occurrences dispatch exactly once. Occurrence
    lifecycles are transacted with single-owner claims, journaled transitions,
    and bounded retries; launches fail closed when preflight, admission, lease,
    or provider authority cannot be established.
  • Usage and presentation. Usage surfaces show the provider's detected
    account plan, the sidebar usage card gets a calmer bounded-glass treatment,
    and provider colours are contrast-balanced across light and dark on desktop
    and iOS — including upstream-brand overrides for Ollama-hosted models.

Reliability and safety

  • Transcript navigation keeps the reader's place across chat switches, popouts,
    and remounts; expanded Ensemble rounds stay expanded per chat; explicit input
    owns scroll-away while live follow survives layout clamps. Fan-out activity
    stays in one first-anchored viewport and directed steers stay
    single-recipient.
  • Multiview lifecycle state stays with its pane and chat; concurrent chat saves
    are serialized and revision-aware; queued chat updates survive hydration;
    only persisted due tasks dispatch; scheduled Ensemble rounds reserve fresh
    state; workspace execution targets stay pinned from startup.
  • Transcript media and attachments keep durable ownership — atomic grant
    batches (forks and AV outputs included), fail-safe ledger locking, file-based
    large-asset ingestion, and asynchronous staging.
  • iOS: the type-out reveal drains fully on stream exit, scoped to its run; the
    composer diff pill avoids a first-frame layout livelock; app notices stay in
    First Launch.
  • Provider edge cases: Grok recovers denied tools without weakening Read-Only,
    Kimi speed tiers resolve through CLI aliases, Codex reasoning controls stay
    pinned to the dispatched run, and Codex session/weekly quota windows keep the
    right labels. Sandboxed packaged builds keep their capability handoff and
    boot cleanly.
  • Security: run authority is reconstructed from canonical state rather than
    renderer payloads; built-in Git actions treat repository configuration as
    untrusted; native provider file/shell tools stay brokered; remote favicon
    fetches are pinned and bounded; the Kimi Code contained transport is
    deny-walled (no network tools, no server-side filesystem/exec tools,
    fail-closed generation gate, no project-config code execution at session
    start); scheduled and unattended workflow authority is native-owned with an
    authenticated occurrence WAL, persisted elevation revocations, and
    whitelisted runnable template fields.

See CHANGELOG.md in the tagged source for the complete public notes.

Artifact record

  • Tag / commit: v1.8.26820393a (macOS artifacts built from this commit;
    169 commits of work ahead of v1.8.1; the iOS build-number bump follows on
    as c7bc0f0a7).
  • macOS: notarized universal .dmg + .zip (Developer ID Application:
    Christopher Izatt, 8CZML8FK2D). DMG notarization submission
    fe916a93-4a6b-4a0c-aacd-bc8b43558e0e (Accepted); stapled and verified with
    spctl (source=Notarized Developer ID) + stapler. latest-mac.yml
    published for stable-channel auto-update.
    • SHA-256 .dmg: 84ec7e88cb2a5cdfb7f898ee76f493ffb703decb8b707194db69032fc0229a00
    • SHA-256 .zip: 8e29cdd8f2c1d484ec2e5e6bf2b5664037763c55117df9f22d95ccc4edd58cff
  • iOS/TestFlight: 0.1.0 (77) uploaded to App Store Connect, delivery UUID
    f386601b-8e6a-4d49-8e47-e1cc1faab965 (processing).
  • Windows/Linux: attached via CI workflow dispatch after this release
    (unsigned x64/arm64 setup.exe; Linux AppImage + .deb).
  • Source verification: whole suite green before bump — 945 files / 11,743
    tests; iOS Kit swift test 414; swift bridge 88; validate:release all
    steps.

TaskWraith 1.8.1

Choose a tag to compare

@boggspa boggspa released this 12 Jul 18:24

TaskWraith 1.8.1

TaskWraith 1.8.1 is a focused reliability and orchestration release for the
local-first macOS workbench and its iPhone/iPad companion.

Highlights

  • Ensemble now has a BG stage for detached background work. BG seats stay
    out of ordinary rotation, start only when explicitly mentioned or delegated,
    and cannot take Boss, Captain, or synthesizer authority.
  • The composer now shows provider-backed live token and projected-cost usage for
    solo and Ensemble work when available, with a clear estimate when it is not.
  • Teams can close a genuinely complete active goal through a binding quorum poll
    when the Boss or Captain is unreachable; review gates stay attached to the
    goal they were created for.
  • Agents can propose a validated Ensemble roster for user confirmation; Settings
    can selectively import or export saved rosters and keeps participant cards
    compact until you need their detailed controls. The Blackboard popover can
    post or remove notes without opening the right dock.
  • Desktop and iOS receive a shared motion and feedback pass that respects Reduce
    Motion.

Reliability and safety

  • Ensemble routing now preserves event order and directed scope, favors an
    explicit mention over a yield return, closes terminal yields cleanly, and
    keeps foreground fan-out results with their source before the next serial
    speaker begins. A reader fan-out also shows one contextual Skip control.
  • Continuous mode returns control when a no-work, all-yielded panel cannot
    complete on its own, rather than spending another hop. Queued provider/model
    seat changes take effect only after the current pass closes.
  • Goal-complete proposal responses retain their own tool identity, and a poll
    resolution cannot create a duplicate audit status line. Activity collapse no
    longer risks a nested renderer update loop.
  • Settings and provider capability catalogues consistently surface the
    goal-complete proposal tool, including Cursor's gateway.
  • Solo Codex terminal state is persisted reliably. Kimi and Grok MCP handling,
    Kimi weekly quota reporting, late Kimi Wire failure handling, and unsupported
    Codex reasoning-level handling are corrected.
  • Before an iPhone/iPad action is sent, TaskWraith verifies the paired Mac is
    alive and makes a bounded reconnect/wake attempt if it has slept. The action
    is not sent until the host is proven reachable; synced threads remain
    readable meanwhile.
  • The reviewer-verdict exception is exact and gate-scoped. Agent-created roster
    imports require confirmation and remain capped to Read-Only, Plan, or Default
    permissions without custom overrides.

See CHANGELOG.md in the tagged source for the complete public notes.

Artifact record

  • Tag / commit: v1.8.1eac99767 (macOS artifacts built from this commit;
    the iOS build-number bump follows on as 08ed731c4).
  • macOS: notarized universal .dmg + .zip (Developer ID Application:
    Christopher Izatt, 8CZML8FK2D). DMG notarization submission
    5c237109-2a37-4746-b017-b6214b6bd255 (Accepted); stapled and verified with
    spctl (source=Notarized Developer ID) + stapler. latest-mac.yml
    published for stable-channel auto-update.
    • SHA-256 .dmg: 384f0e44a61a53ae7cfe9afd9ceb02f8b415bef7bfb8cd2eb988496b4d36454b
    • SHA-256 .zip: 37a3cab37718284ffd27e757922885a406c6aceb45986854140c50ae4c89c790
  • iOS/TestFlight: 0.1.0 (76) uploaded to App Store Connect, delivery UUID
    5a88bdc6-38ea-4f66-a393-1248741592ac (processing).
  • Windows/Linux: attached via CI workflow dispatch after this release
    (unsigned x64/arm64 setup.exe; Linux AppImage + .deb).
  • Source verification: whole suite green before bump — 858 files / 10,238 tests;
    iOS Kit swift test 403; swift bridge 88; validate:release all steps.