Skip to content

Releases: dragoscv/vitals

Nightly 0.9.0-nightly.20260929.gd2e4c60

Pre-release

Choose a tag to compare

@github-actions github-actions released this 29 Sep 23:21

Nightly build. Built from main every night something lands. Unreleased,
and it may be broken. The installed app does not update itself from nightlies.

Security

  • The local API is read-only — 127.0.0.1:7330 no longer lets a
    program end or pause your processes without a token. Another Windows
    account on the same PC could reach it; the vitals CLI now acts on your
    own machine through Windows directly, with your own rights.
  • The CLI pipe is locked to your account — an explicit access list
    (you, SYSTEM, administrators) replaces the Windows default, which also let
    everyone read it.
  • The phone page is harder to attack — every response from the LAN
    server carries a content security policy and refuses to be framed; request
    bodies and WebSocket messages are capped.
  • Releases wait for the owner — publishing needs approval, release tags
    can only be created by the owner, and every build action is pinned to an
    exact version.

Added

  • Vitals for Android and Wear OS — native phone and watch apps. The phone
    opens on This phone: processor, graphics, memory, battery, temperatures,
    storage with a folder map and cleanup, per-app time and data, sensors, a
    week of history and alerts, all read through Android's public interfaces.
    Pair a PC with a QR code to see it, its processes and sensors, wake it and,
    with a control token, end or suspend processes. The watch monitors itself
    and your PCs, with a tile and complications. Signed APKs ship with every
    release, so Obtainium can follow them.

  • Free Windows' own space with Windows' own tools — in Reclaimable space,
    the Windows Update cache, system temporary files, the thumbnail cache, crash
    dumps, the component store, the previous Windows installation, the Recycle
    Bin and the hibernation file now have a button that runs the tool Windows
    provides for each (Disk Cleanup, DISM or powercfg). Windows asks for
    administrator approval once, for that action only; you see what it is doing
    while it works, and afterwards how much space was actually freed, measured
    before and after. Emptying the bin, removing the previous Windows and
    turning hibernation off say what cannot be undone and need a tick first.

  • Free space from a storage scan — put folders and files in review with
    the + beside them (or right-click on the map), check the list and its
    total, and send them to the Recycle Bin in one step, from where any of them
    can be put back. Windows, installed programs and the folders your account
    is made of are refused, and anything the bin could not hold is left where
    it is rather than deleted for good. The sizes go down straight away,
    without scanning again.

  • Why can't I delete this — when something is in use, Vitals names the
    program holding it, so you know what to close.

  • Explore a storage scan — after a scan, a map shows every folder sized by
    the space it takes, as layers or as blocks. Click a block to go inside, use
    the breadcrumb or Up to come back, and hover for its size and share. A list
    beside it can be driven with the keyboard, and every row can be opened,
    shown in File Explorer or have its path copied.

  • Largest files — the thousand biggest files on the scanned drive, each one
    click away from File Explorer.

  • Act on startup items and services — right-click a row, or use the
    button at its end. Startup items switch off and on the way Task Manager
    does it; services start, stop, restart, and can be set to start
    automatically, manually or never. Both open the file location, its
    properties, a web search, or copy their details.

  • Hide Microsoft services — ticked by default on Startup and Services,
    so the lists show what other software added; the hidden count is shown
    and one click brings them back.

  • Safe by default — anything Windows depends on asks before it is
    switched off, what Windows forbids is not offered, and a change that
    needs administrator rights asks once, for that change only.

  • CPU temperature and package power — install the optional sensors
    service from Devices & sensors (one administrator prompt) and Vitals shows
    the CPU package temperature, the hottest core and the package power draw
    on Devices, the Thermals chart, Prometheus (vitals_cpu_power_watts) and
    Home Assistant. It uses the signed PawnIO driver, only reads, and can be
    removed from the same screen.

  • Hardware — Devices & sensors shows what the computer is made of:
    processor, every memory module, graphics cards, drives (with temperature
    and health) and the motherboard and BIOS.

  • Device Manager — every device Windows lists, grouped the same way,
    with its driver and any problem it reports. You can search, and show
    devices that are not connected.

  • Fan speeds — with the sensors service installed, the motherboard's fan
    speeds appear on Devices, the Thermals chart, Prometheus
    (vitals_fan_rpm) and the LAN API.

  • Drive temperatures without administrator rights.

  • Lag watchdog — vitals-watchdog notices when a window you are using
    stops answering, or programs cannot get the processor in time, names the
    process behind it (never the shell or IDE it was started from), and offers
    End, Lower its priority or Ignore from a notification. It never ends
    anything on its own, and --diagnose shows what it would decide.

  • The watchdog ships with Vitals — it is part of the installer and turns
    itself on at the first launch. Settings → Watchdog turns it off, chooses
    the sensitivity (Relaxed, Normal or Sensitive) and the warning sound: any
    of Windows' notification sounds, none, or your own audio file with a
    volume, and a Test button.

Changed

  • Privacy policy covers the Android and Wear OS apps: the two kinds of
    special access and what they stay on, the phone-to-watch link, and the
    diagnostics Google ML Kit sends when the QR scanner opens.

  • Storage scans are about 80 times faster and count everything — a whole
    drive of eight million files is read in about seven minutes instead of
    never finishing, and Program Files in six seconds instead of eight
    minutes. There is no depth choice any more: every folder is counted, at
    every depth, and the scan shows live progress and the folder it is reading.

  • CI takes about 8 minutes instead of 49: the Windows checks run as three
    parallel jobs with their own caches, and a push that only changes the
    website or prose skips the Rust jobs.

  • Scoop is available (scoop bucket add vitals https://github.com/dragoscv/scoop-vitals);
    winget and Chocolatey are submitted and awaiting their moderators.

Fixed

  • A debug build takes about 10 GB instead of growing without limit — the
    desktop crate no longer builds two extra copies of itself for mobile targets
    Vitals does not ship, and verify.ps1 prunes abandoned incremental caches
    and fails when target/ goes over budget (contributors only).

  • OneDrive folders are counted in storage scans; they used to be skipped.

  • Stopping a scan no longer stops a cleanup search (or the other way
    round) — each has its own Stop button.

  • Links are no longer reported as unreadable folders — a scan that only
    passed over shortcuts to other places is complete, and says how many it did
    not follow.

  • A shortcut to a file no longer counts as the file's size.

  • Scanning a drive scans the drive — choosing C: could scan whichever
    folder Vitals was started from instead.

  • The board's thermal zones are labelled as such, so a 28 °C chipset
    reading is no longer mistaken for the CPU temperature.

  • The watchdog no longer warns during builds or while you are away from the
    computer: a busy processor on its own is not a freeze.

  • The macOS build compiles again: the desktop overlay is transparent on
    Windows and Linux only, because on macOS a transparent window needs Tauri's
    private-API feature. macOS is built on every release but not yet published.


Verifying this download

Windows may show a SmartScreen warning on first run (Windows protected your
PC
) because the installer is not yet signed with a commercial certificate.
Choose More info → Run anyway. That is expected — see
docs/distribution.md.

You do not have to take our word for what is in the binary. With the
GitHub CLI:

gh attestation verify .\Vitals_x64-setup.exe --repo dragoscv/vitals

This proves the file was built by this repository's release workflow from the
tagged commit, and nowhere else. Checksums for every file are in
SHA256SUMS.txt:

(Get-FileHash .\Vitals_x64-setup.exe -Algorithm SHA256).Hash.ToLower()

Software bills of materials (CycloneDX) for the Rust and JavaScript
dependencies are attached as sbom-rust.cdx.json and sbom-js.cdx.json.

Vitals 0.9.0-beta.1 (public beta)

Choose a tag to compare

@github-actions github-actions released this 28 Sep 14:09

Public beta. Feature-complete for this release and tested, but still
collecting reports before 1.0. The installed app updates itself to newer
betas and to the final release.

The first public release. A beta: every screen works against live data on
Windows, and this is the first build to go through the release pipeline end
to end.

2026-09-28 — real temperatures on Devices & sensors

Features

  • Temperatures without administrator rights — the machine's thermal
    zones are read through Windows' performance counters when the usual query
    is refused, and NVIDIA graphics cards report temperature, fan speed and
    power through their own driver.

Changed

  • Devices & sensors — Power and Thermal zones are separate cards that
    never scroll; the readings table and the list of what cannot be measured
    scroll on their own.

Added

  • Updates install themselves. About twenty seconds after launch Vitals
    checks GitHub for a newer version, downloads it in the background, checks
    its signature, and installs it when you quit — never while you are using
    it. Settings → About has the switch to turn it off, and shows a version
    that is downloaded and waiting.
  • A log file and a crash file. Vitals now writes vitals.log (capped, so
    it cannot fill a disk) and, if it ever crashes, crash.txt in
    %LOCALAPPDATA%\Vitals\logs. Nothing is sent anywhere; attach them to a
    bug report if you want to.
  • Legal and community documents: privacy policy, terms of use, third-party
    licence notices, contributors, support, governance, and a Contributor
    Covenant 3.0 code of conduct. The Privacy and About panels link to them.
  • A website at vitals.dragoscatalin.ro,
    in English and Romanian, with the download, guides and reference.
  • The installer speaks Romanian as well as English.

Changed

  • The Privacy panel tells the whole truth. It used to say Vitals "sends
    nothing anywhere"; it now names the update check and the local-only
    connection on 127.0.0.1 that the vitals command-line tool uses.
  • Running benchmarks no longer freezes the window. The run moved off the
    main thread.

Security

  • Pairing tokens are stored as hashes. lan-tokens.json used to hold
    every paired phone's secret in plain text; it now holds a SHA-256 hash and
    the eight-character prefix you see in Settings. An existing file is
    converted the first time this version starts, and existing pairings keep
    working.
  • The flight recorder no longer writes who is signed in or your network
    adapters' hardware addresses.
    It still records process names and
    resource use for bug reports.

2026-09-28 — "show hidden devices" at the top of the list

Changed

  • The "Show hidden devices" switch is at the top of the device list on
    the Performance page, so it is in reach however long the list gets. Its
    explanation opens from the (i) beside it.

2026-09-28 — the network chart shows the adapter you chose

Fixed

  • The network chart shows the adapter you chose — on the Performance
    page every adapter drew the same total for the whole machine, so picking
    another one seemed to do nothing. Each adapter now has its own chart.
  • The scrollbar no longer covers the device list on the Performance
    page.

2026-09-28 — hide the devices you do not need

Added

  • Hide devices on the Performance page — right-click any disk, GPU or
    network adapter and choose Hide; "Show hidden devices" brings them all
    back, dimmed, and the same menu shows one again. The choice is
    remembered across restarts.

Fixed

  • Virtual network adapters are recognised as virtual — Hyper-V
    switches, WAN miniports and Wi-Fi Direct reported themselves as Ethernet
    or Wi-Fi, so they could not be filtered out. They now start hidden, with
    unused tunnels and displays that report nothing.

2026-09-28 — no page scroll on any screen

Changed

  • Every screen fits the window — titles, toolbars and selections stay
    put, and only the part that needs it scrolls: a table, a list, a card's
    contents. In a very short window a screen's body scrolls as one, so
    nothing gets squeezed unreadably small.

2026-09-28 — a dashboard that fits the window

Changed

  • The dashboard fits the window — cards share the window's height and
    width instead of growing with their content, so the page never scrolls;
    a card that is short on room scrolls inside itself. Each card leads with
    its key number in the header, and charts grow into the space left.

2026-09-28 — every tab is ready before you open it

Changed

  • Every tab is ready before its first visit — after the window paints,
    each section's code and data are loaded in the background while the app
    is idle, so opening a tab for the first time shows its content at once
    instead of a loading skeleton. Disk scans and benchmarks still only run
    when you start them.

Fixes

  • Processes opened for the first time could list only the processes that
    had changed recently (116 of 780) for up to thirty seconds.
  • Reading startup items, installed apps, sensors and connections no longer
    freezes the window while it runs.

2026-09-28 — one window background

Changed

  • One window background — the title bar, sidebar and content share one
    canvas with no borders between them; the window no longer reads as three
    panels.
  • Removed the Surface setting (solid / mica / acrylic). It only tinted
    the title bar and sidebar, which now have no fill of their own; a saved
    value is ignored.

Fixes

  • The active sidebar item's label now meets WCAG AA contrast for every
    accent (it measured 4.12:1 in light mode).

2026-09-27 — redesign and the truths it exposed

Features

  • Fluent depth — cards are lit from above with a gradient surface, an
    edge highlight and a layered shadow; the accent is used as light on the
    active nav item, the primary button and the selected rail entry; two
    static pools of the accent hue sit behind the content. Tokens in
    theme.css, both modes (ADR 0030).
  • Navigation morphs — section changes run as a View Transition: the old
    screen blurs out, the new one rises, the page title morphs between its
    boxes, and the chrome stays put. A single sidebar indicator springs
    between items. Skipped entirely under reduced motion.
  • Numbers roll — every meter's reading tweens to its new value inside
    the formatter's own string; dashboard cards stagger in; skeletons
    shimmer; charts fade their fill and mark the live edge with a glowing dot.
  • GPU memory — dedicated VRAM per adapter from DXGI, shown where a
    dash used to be.

Fixes

  • Disk read/write throughput, active time and response time were 0 on
    every volume: the rate arithmetic had no caller. Counters are now read
    per volume every tick, without administrator rights.
  • Drive kind read "Unknown type" for every fixed disk; now NVMe / SSD / HDD
    / Removable from the device itself, on the Storage screen and the
    dashboard alike.
  • A GPU the driver would not name showed as Display adapter 0x00033f83;
    DXGI names it, and an indirect display that borrows its render card's
    name is marked (virtual display).
  • The Processes User column was empty on every row; it now shows the
    account for every process the current user may open.
  • Eleven CSS tokens (--color-accent-solid, --color-chart-1, …) were
    referenced but never defined, leaving per-core bars, alert icons and HUD
    sparklines colourless.
  • AnimatedValue and the sidebar indicator honour the app's own
    reduce-motion setting, not only the operating system's.

Build and tooling

  • Size budget raised to the measured 188 880 B initial / 382 460 B shipped
    (gzip) for the above; HUD and mobile unchanged.
  • prove_devices and cost_probe examples in vitals-win.

Since the S1 upgrade commit (7d9128c)

The session of 2026-09-10 turned a single-window monitor into a set of
clients over one sampler. Grouped by Conventional Commit type; the hashes
are the commits in git log --oneline 7d9128c..HEAD.

Features

  • LAN server (vitals-server) — REST, SSE, WebSocket and Prometheus
    /metrics over axum, hosted by the desktop app and off by default
    (76e2c4f, 201fe3d). Advertised as _vitals._tcp over mDNS only while
    running (cac19cd). A loopback listener on :7330 lets the CLI attach
    without a token (9570564).
  • Remote access UI — pairing with a QR code rendered in Rust so the
    secret reaches the webview once; read and control token scopes
    (201fe3d).
  • The phone app — mobile.html, a lean PWA: machines, processes,
    control with two-tap confirm, several PCs side by side (2861e6f), and an
    alerts feed per machine card polled from /api/v1/alerts (7c9fc20).
  • @vitals/client — a typed TypeScript SDK over REST, SSE and WebSocket
    (9b69325).
  • CLI — vitals ps / top / info / report / serve, attached to the app
    over loopback or sampling directly when it is closed (c214938).
  • History for real — vitals-store gains SQLite, retention and a flight
    recorder (89f189a).
  • Alerts engine in Rust with sustain, hysteresis and cooldown
    (6a4b4f6), run on the sampler thread and fanned out to the dashboard,
    tray, toasts and LAN (3c5f946).
  • "Why is my PC slow?" — a verdict, the culprits and a minute of chart
    (8e293b7).
  • Tray icon showing CPU; the close button can mean hide (f1d1112).
  • HUD — an always-on-top transparent overlay, Ctrl+Shift+H
    (f8505d5).
  • Updater — a real minisign key, a published latest.json, an honest UI
    state (c0486da).
  • Command palette, keyboard shortcuts, route transitions and a motion
    config on motion/react-m (45371d1).
  • CSV/JSON export and URL-backed search on every table (50c1d01).
  • Shared StatList and Toaster primitives, ultr...
Read more