LedgerPDF v0.1.1
LedgerPDF v0.1.1
Security and reliability update, released 2026-08-11.
This release makes LedgerPDF's agent-access controls match what the interface says: approved folders are authoritative, every window reads the real live-agent state, and concurrent work fails safely instead of silently replacing newer binder data.
Security and reliability
- Made the visible approved-folder list authoritative and removed shipped environment overrides.
- Added cross-process binder leases and live revision checks for user/agent and agent/agent races.
- Prevented standalone agents from silently overwriting unrelated binders, exports, or cover memos.
- Made new and reopened windows query authoritative live-agent state.
- Clarified the difference between the on-screen binder switch and persistent approved-folder access.
- Made long mark and shape notes wrap instead of clipping.
- Added a Tesseract fallback when macOS Vision OCR fails at runtime.
Downloads
- macOS Apple silicon:
LedgerPDF-0.1.1-mac-arm64.dmg(recommended) or.zip. The application and DMG are signed with Ledger Labs LLC's Developer ID, notarized by Apple, and stapled. - Windows x64:
LedgerPDF-0.1.1-win-x64.exe. This per-user installer does not require administrator access. It is not code-signed yet, so Windows SmartScreen may show an unrecognized-publisher warning. See the Windows installation guide. - Verification:
SHA256SUMScontains the SHA-256 digest of each distributable.
Release verification
- Source commit:
6e8e0b7c13784536b133f0d284882991a901e4bf - Windows run 31535513491 built the exact source commit and passed the complete application suite, native installer registration/uninstall test, and packaged-app verification.
- macOS was built from a clean checkout of the exact source commit. The application, DMG, and ZIP-extracted application independently passed strict signature, Gatekeeper, notarization-staple, packaged-renderer, frozen-engine, PDF export, recents, MCP, and approved-folder checks.
- Public Git history and release files passed secret scanning; npm, Python, and CodeQL vulnerability checks are clean.
This is alpha software. Keep independent copies of important documents and do not make LedgerPDF the only copy of anything.