Releases: dragoscv/vitals
Release list
Nightly 0.9.0-nightly.20260929.gd2e4c60
Nightly build. Built from
mainevery night something lands. Unreleased,
and it may be broken. The installed app does not update itself from nightlies.
Security
- The local API is read-only —
127.0.0.1:7330no longer lets a
program end or pause your processes without a token. Another Windows
account on the same PC could reach it; thevitalsCLI now acts on your
own machine through Windows directly, with your own rights. - The CLI pipe is locked to your account — an explicit access list
(you, SYSTEM, administrators) replaces the Windows default, which also let
everyone read it. - The phone page is harder to attack — every response from the LAN
server carries a content security policy and refuses to be framed; request
bodies and WebSocket messages are capped. - Releases wait for the owner — publishing needs approval, release tags
can only be created by the owner, and every build action is pinned to an
exact version.
Added
-
Vitals for Android and Wear OS — native phone and watch apps. The phone
opens on This phone: processor, graphics, memory, battery, temperatures,
storage with a folder map and cleanup, per-app time and data, sensors, a
week of history and alerts, all read through Android's public interfaces.
Pair a PC with a QR code to see it, its processes and sensors, wake it and,
with a control token, end or suspend processes. The watch monitors itself
and your PCs, with a tile and complications. Signed APKs ship with every
release, so Obtainium can follow them. -
Free Windows' own space with Windows' own tools — in Reclaimable space,
the Windows Update cache, system temporary files, the thumbnail cache, crash
dumps, the component store, the previous Windows installation, the Recycle
Bin and the hibernation file now have a button that runs the tool Windows
provides for each (Disk Cleanup, DISM or powercfg). Windows asks for
administrator approval once, for that action only; you see what it is doing
while it works, and afterwards how much space was actually freed, measured
before and after. Emptying the bin, removing the previous Windows and
turning hibernation off say what cannot be undone and need a tick first. -
Free space from a storage scan — put folders and files in review with
the + beside them (or right-click on the map), check the list and its
total, and send them to the Recycle Bin in one step, from where any of them
can be put back. Windows, installed programs and the folders your account
is made of are refused, and anything the bin could not hold is left where
it is rather than deleted for good. The sizes go down straight away,
without scanning again. -
Why can't I delete this — when something is in use, Vitals names the
program holding it, so you know what to close. -
Explore a storage scan — after a scan, a map shows every folder sized by
the space it takes, as layers or as blocks. Click a block to go inside, use
the breadcrumb or Up to come back, and hover for its size and share. A list
beside it can be driven with the keyboard, and every row can be opened,
shown in File Explorer or have its path copied. -
Largest files — the thousand biggest files on the scanned drive, each one
click away from File Explorer. -
Act on startup items and services — right-click a row, or use the
button at its end. Startup items switch off and on the way Task Manager
does it; services start, stop, restart, and can be set to start
automatically, manually or never. Both open the file location, its
properties, a web search, or copy their details. -
Hide Microsoft services — ticked by default on Startup and Services,
so the lists show what other software added; the hidden count is shown
and one click brings them back. -
Safe by default — anything Windows depends on asks before it is
switched off, what Windows forbids is not offered, and a change that
needs administrator rights asks once, for that change only. -
CPU temperature and package power — install the optional sensors
service from Devices & sensors (one administrator prompt) and Vitals shows
the CPU package temperature, the hottest core and the package power draw
on Devices, the Thermals chart, Prometheus (vitals_cpu_power_watts) and
Home Assistant. It uses the signed PawnIO driver, only reads, and can be
removed from the same screen. -
Hardware — Devices & sensors shows what the computer is made of:
processor, every memory module, graphics cards, drives (with temperature
and health) and the motherboard and BIOS. -
Device Manager — every device Windows lists, grouped the same way,
with its driver and any problem it reports. You can search, and show
devices that are not connected. -
Fan speeds — with the sensors service installed, the motherboard's fan
speeds appear on Devices, the Thermals chart, Prometheus
(vitals_fan_rpm) and the LAN API. -
Drive temperatures without administrator rights.
-
Lag watchdog —
vitals-watchdognotices when a window you are using
stops answering, or programs cannot get the processor in time, names the
process behind it (never the shell or IDE it was started from), and offers
End, Lower its priority or Ignore from a notification. It never ends
anything on its own, and--diagnoseshows what it would decide. -
The watchdog ships with Vitals — it is part of the installer and turns
itself on at the first launch. Settings → Watchdog turns it off, chooses
the sensitivity (Relaxed, Normal or Sensitive) and the warning sound: any
of Windows' notification sounds, none, or your own audio file with a
volume, and a Test button.
Changed
-
Privacy policy covers the Android and Wear OS apps: the two kinds of
special access and what they stay on, the phone-to-watch link, and the
diagnostics Google ML Kit sends when the QR scanner opens. -
Storage scans are about 80 times faster and count everything — a whole
drive of eight million files is read in about seven minutes instead of
never finishing, andProgram Filesin six seconds instead of eight
minutes. There is no depth choice any more: every folder is counted, at
every depth, and the scan shows live progress and the folder it is reading. -
CI takes about 8 minutes instead of 49: the Windows checks run as three
parallel jobs with their own caches, and a push that only changes the
website or prose skips the Rust jobs. -
Scoop is available (
scoop bucket add vitals https://github.com/dragoscv/scoop-vitals);
winget and Chocolatey are submitted and awaiting their moderators.
Fixed
-
A debug build takes about 10 GB instead of growing without limit — the
desktop crate no longer builds two extra copies of itself for mobile targets
Vitals does not ship, andverify.ps1prunes abandoned incremental caches
and fails whentarget/goes over budget (contributors only). -
OneDrive folders are counted in storage scans; they used to be skipped.
-
Stopping a scan no longer stops a cleanup search (or the other way
round) — each has its own Stop button. -
Links are no longer reported as unreadable folders — a scan that only
passed over shortcuts to other places is complete, and says how many it did
not follow. -
A shortcut to a file no longer counts as the file's size.
-
Scanning a drive scans the drive — choosing C: could scan whichever
folder Vitals was started from instead. -
The board's thermal zones are labelled as such, so a 28 °C chipset
reading is no longer mistaken for the CPU temperature. -
The watchdog no longer warns during builds or while you are away from the
computer: a busy processor on its own is not a freeze. -
The macOS build compiles again: the desktop overlay is transparent on
Windows and Linux only, because on macOS a transparent window needs Tauri's
private-API feature. macOS is built on every release but not yet published.
Verifying this download
Windows may show a SmartScreen warning on first run (Windows protected your
PC) because the installer is not yet signed with a commercial certificate.
Choose More info → Run anyway. That is expected — see
docs/distribution.md.
You do not have to take our word for what is in the binary. With the
GitHub CLI:
gh attestation verify .\Vitals_x64-setup.exe --repo dragoscv/vitalsThis proves the file was built by this repository's release workflow from the
tagged commit, and nowhere else. Checksums for every file are in
SHA256SUMS.txt:
(Get-FileHash .\Vitals_x64-setup.exe -Algorithm SHA256).Hash.ToLower()Software bills of materials (CycloneDX) for the Rust and JavaScript
dependencies are attached as sbom-rust.cdx.json and sbom-js.cdx.json.
Vitals 0.9.0-beta.1 (public beta)
Public beta. Feature-complete for this release and tested, but still
collecting reports before 1.0. The installed app updates itself to newer
betas and to the final release.
The first public release. A beta: every screen works against live data on
Windows, and this is the first build to go through the release pipeline end
to end.
2026-09-28 — real temperatures on Devices & sensors
Features
- Temperatures without administrator rights — the machine's thermal
zones are read through Windows' performance counters when the usual query
is refused, and NVIDIA graphics cards report temperature, fan speed and
power through their own driver.
Changed
- Devices & sensors — Power and Thermal zones are separate cards that
never scroll; the readings table and the list of what cannot be measured
scroll on their own.
Added
- Updates install themselves. About twenty seconds after launch Vitals
checks GitHub for a newer version, downloads it in the background, checks
its signature, and installs it when you quit — never while you are using
it. Settings → About has the switch to turn it off, and shows a version
that is downloaded and waiting. - A log file and a crash file. Vitals now writes
vitals.log(capped, so
it cannot fill a disk) and, if it ever crashes,crash.txtin
%LOCALAPPDATA%\Vitals\logs. Nothing is sent anywhere; attach them to a
bug report if you want to. - Legal and community documents: privacy policy, terms of use, third-party
licence notices, contributors, support, governance, and a Contributor
Covenant 3.0 code of conduct. The Privacy and About panels link to them. - A website at vitals.dragoscatalin.ro,
in English and Romanian, with the download, guides and reference. - The installer speaks Romanian as well as English.
Changed
- The Privacy panel tells the whole truth. It used to say Vitals "sends
nothing anywhere"; it now names the update check and the local-only
connection on127.0.0.1that thevitalscommand-line tool uses. - Running benchmarks no longer freezes the window. The run moved off the
main thread.
Security
- Pairing tokens are stored as hashes.
lan-tokens.jsonused to hold
every paired phone's secret in plain text; it now holds a SHA-256 hash and
the eight-character prefix you see in Settings. An existing file is
converted the first time this version starts, and existing pairings keep
working. - The flight recorder no longer writes who is signed in or your network
adapters' hardware addresses. It still records process names and
resource use for bug reports.
2026-09-28 — "show hidden devices" at the top of the list
Changed
- The "Show hidden devices" switch is at the top of the device list on
the Performance page, so it is in reach however long the list gets. Its
explanation opens from the (i) beside it.
2026-09-28 — the network chart shows the adapter you chose
Fixed
- The network chart shows the adapter you chose — on the Performance
page every adapter drew the same total for the whole machine, so picking
another one seemed to do nothing. Each adapter now has its own chart. - The scrollbar no longer covers the device list on the Performance
page.
2026-09-28 — hide the devices you do not need
Added
- Hide devices on the Performance page — right-click any disk, GPU or
network adapter and choose Hide; "Show hidden devices" brings them all
back, dimmed, and the same menu shows one again. The choice is
remembered across restarts.
Fixed
- Virtual network adapters are recognised as virtual — Hyper-V
switches, WAN miniports and Wi-Fi Direct reported themselves as Ethernet
or Wi-Fi, so they could not be filtered out. They now start hidden, with
unused tunnels and displays that report nothing.
2026-09-28 — no page scroll on any screen
Changed
- Every screen fits the window — titles, toolbars and selections stay
put, and only the part that needs it scrolls: a table, a list, a card's
contents. In a very short window a screen's body scrolls as one, so
nothing gets squeezed unreadably small.
2026-09-28 — a dashboard that fits the window
Changed
- The dashboard fits the window — cards share the window's height and
width instead of growing with their content, so the page never scrolls;
a card that is short on room scrolls inside itself. Each card leads with
its key number in the header, and charts grow into the space left.
2026-09-28 — every tab is ready before you open it
Changed
- Every tab is ready before its first visit — after the window paints,
each section's code and data are loaded in the background while the app
is idle, so opening a tab for the first time shows its content at once
instead of a loading skeleton. Disk scans and benchmarks still only run
when you start them.
Fixes
- Processes opened for the first time could list only the processes that
had changed recently (116 of 780) for up to thirty seconds. - Reading startup items, installed apps, sensors and connections no longer
freezes the window while it runs.
2026-09-28 — one window background
Changed
- One window background — the title bar, sidebar and content share one
canvas with no borders between them; the window no longer reads as three
panels. - Removed the Surface setting (solid / mica / acrylic). It only tinted
the title bar and sidebar, which now have no fill of their own; a saved
value is ignored.
Fixes
- The active sidebar item's label now meets WCAG AA contrast for every
accent (it measured 4.12:1 in light mode).
2026-09-27 — redesign and the truths it exposed
Features
- Fluent depth — cards are lit from above with a gradient surface, an
edge highlight and a layered shadow; the accent is used as light on the
active nav item, the primary button and the selected rail entry; two
static pools of the accent hue sit behind the content. Tokens in
theme.css, both modes (ADR 0030). - Navigation morphs — section changes run as a View Transition: the old
screen blurs out, the new one rises, the page title morphs between its
boxes, and the chrome stays put. A single sidebar indicator springs
between items. Skipped entirely under reduced motion. - Numbers roll — every meter's reading tweens to its new value inside
the formatter's own string; dashboard cards stagger in; skeletons
shimmer; charts fade their fill and mark the live edge with a glowing dot. - GPU memory — dedicated VRAM per adapter from DXGI, shown where a
dash used to be.
Fixes
- Disk read/write throughput, active time and response time were
0on
every volume: the rate arithmetic had no caller. Counters are now read
per volume every tick, without administrator rights. - Drive kind read "Unknown type" for every fixed disk; now NVMe / SSD / HDD
/ Removable from the device itself, on the Storage screen and the
dashboard alike. - A GPU the driver would not name showed as
Display adapter 0x00033f83;
DXGI names it, and an indirect display that borrows its render card's
name is marked(virtual display). - The Processes User column was empty on every row; it now shows the
account for every process the current user may open. - Eleven CSS tokens (
--color-accent-solid,--color-chart-1, …) were
referenced but never defined, leaving per-core bars, alert icons and HUD
sparklines colourless. AnimatedValueand the sidebar indicator honour the app's own
reduce-motion setting, not only the operating system's.
Build and tooling
- Size budget raised to the measured 188 880 B initial / 382 460 B shipped
(gzip) for the above; HUD and mobile unchanged. prove_devicesandcost_probeexamples invitals-win.
Since the S1 upgrade commit (7d9128c)
The session of 2026-09-10 turned a single-window monitor into a set of
clients over one sampler. Grouped by Conventional Commit type; the hashes
are the commits in git log --oneline 7d9128c..HEAD.
Features
- LAN server (
vitals-server) — REST, SSE, WebSocket and Prometheus
/metricsover axum, hosted by the desktop app and off by default
(76e2c4f,201fe3d). Advertised as_vitals._tcpover mDNS only while
running (cac19cd). A loopback listener on:7330lets the CLI attach
without a token (9570564). - Remote access UI — pairing with a QR code rendered in Rust so the
secret reaches the webview once; read and control token scopes
(201fe3d). - The phone app —
mobile.html, a lean PWA: machines, processes,
control with two-tap confirm, several PCs side by side (2861e6f), and an
alerts feed per machine card polled from/api/v1/alerts(7c9fc20). @vitals/client— a typed TypeScript SDK over REST, SSE and WebSocket
(9b69325).- CLI —
vitals ps / top / info / report / serve, attached to the app
over loopback or sampling directly when it is closed (c214938). - History for real —
vitals-storegains SQLite, retention and a flight
recorder (89f189a). - Alerts engine in Rust with sustain, hysteresis and cooldown
(6a4b4f6), run on the sampler thread and fanned out to the dashboard,
tray, toasts and LAN (3c5f946). - "Why is my PC slow?" — a verdict, the culprits and a minute of chart
(8e293b7). - Tray icon showing CPU; the close button can mean hide (
f1d1112). - HUD — an always-on-top transparent overlay,
Ctrl+Shift+H
(f8505d5). - Updater — a real minisign key, a published
latest.json, an honest UI
state (c0486da). - Command palette, keyboard shortcuts, route transitions and a motion
config onmotion/react-m(45371d1). - CSV/JSON export and URL-backed search on every table (
50c1d01). - Shared
StatListandToasterprimitives, ultr...