v0.5.1
Fixes that writing the documentation site turned up, and pitboard's facts about Claude Code
read again, from 2.1.284.
Added
- In
pitboard-core,assumptions::read_onsays which systems' builds a fact is read from,
as the newassumptions::Platform.
Changed
- pitboard's facts about Claude Code are read from 2.1.284, and from its macOS build as well
as its Linux one. The weekly check reported three facts moved from 2.1.281; all three were
read from the Linux build, which has no keychain code, or from the runtime Claude Code
ships in. The one real change is that Claude Code no longer moves its login to the
plaintext file when the keychain is locked, and nothing in pitboard depends on the old
behaviour. - The README introduces pitboard and links to
docs.usepitboard.com, where the guides and reference are. SECURITY.mdis only the security policy: which versions get fixes, how to report a
vulnerability, and what pitboard does and does not protect against. Where parked logins
are kept and what leaves your machine are on
Security and privacy.- How to make a release, how to replace the update key, and the Sparkle and Homebrew
measurements a release rests on, moved fromCONTRIBUTING.mdtoRELEASING.md. - How the code is laid out, and the measurements of macOS, Claude Code and Codex it rests
on, moved toARCHITECTURE.md.
Fixed
pitboard status --fresh, and Refresh in the app, asked Anthropic or OpenAI again during
a wait the service had asked for. The 0.3.0 notes andpitboard doctorsaid they did not.
They keep that wait now, and still ask a service again after it could not be reached.
When a service had never answered for an account and then could not be reached, pitboard
said the account was rate limited.- With
PITBOARD_NO_ARGV=1, renewing a parked login too large forsecurity's standard
input spent its refresh token and then could not store the new one. The parked login was
lost. pitboard refuses before asking the service now, and the parked login stays as it was. - A switch whose login could not be read back said to run
pitboardagain, which only
reads. It names thepitboard usethat finishes or undoes the switch. - With Codex's
auth.jsonmissing,pitboard doctorsuggestedpitboard use codex/<label>,
which refuses while nothing is signed in. It says to sign in withcodex login. - The man page listed a page per command, such as
pitboard-status(1), and none of them is
installed. It sets out every command, with its arguments and options, on its one page. - The app never said that Claude Code is not installed: it waited for a read to fail in a
way no read does. It says so when it finds neitherclaudenorcodex, and neither tool
has a login or an enrolled account.
Security
- The menu bar app ignored
PITBOARD_NO_ARGV, and so did daily renewal unless its
scheduler set it. Either could pass a large login tosecurityas an argument, which
another process running as you could read while the call lasts. The app reads
PITBOARD_NO_ARGVfrom its own environment, and a schedule installed while it is set
keeps it.