Skip to content

Nightly 0.9.0-nightly.20260929.gd2e4c60

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 29 Sep 23:21

Nightly build. Built from main every night something lands. Unreleased,
and it may be broken. The installed app does not update itself from nightlies.

Security

  • The local API is read-only — 127.0.0.1:7330 no longer lets a
    program end or pause your processes without a token. Another Windows
    account on the same PC could reach it; the vitals CLI now acts on your
    own machine through Windows directly, with your own rights.
  • The CLI pipe is locked to your account — an explicit access list
    (you, SYSTEM, administrators) replaces the Windows default, which also let
    everyone read it.
  • The phone page is harder to attack — every response from the LAN
    server carries a content security policy and refuses to be framed; request
    bodies and WebSocket messages are capped.
  • Releases wait for the owner — publishing needs approval, release tags
    can only be created by the owner, and every build action is pinned to an
    exact version.

Added

  • Vitals for Android and Wear OS — native phone and watch apps. The phone
    opens on This phone: processor, graphics, memory, battery, temperatures,
    storage with a folder map and cleanup, per-app time and data, sensors, a
    week of history and alerts, all read through Android's public interfaces.
    Pair a PC with a QR code to see it, its processes and sensors, wake it and,
    with a control token, end or suspend processes. The watch monitors itself
    and your PCs, with a tile and complications. Signed APKs ship with every
    release, so Obtainium can follow them.

  • Free Windows' own space with Windows' own tools — in Reclaimable space,
    the Windows Update cache, system temporary files, the thumbnail cache, crash
    dumps, the component store, the previous Windows installation, the Recycle
    Bin and the hibernation file now have a button that runs the tool Windows
    provides for each (Disk Cleanup, DISM or powercfg). Windows asks for
    administrator approval once, for that action only; you see what it is doing
    while it works, and afterwards how much space was actually freed, measured
    before and after. Emptying the bin, removing the previous Windows and
    turning hibernation off say what cannot be undone and need a tick first.

  • Free space from a storage scan — put folders and files in review with
    the + beside them (or right-click on the map), check the list and its
    total, and send them to the Recycle Bin in one step, from where any of them
    can be put back. Windows, installed programs and the folders your account
    is made of are refused, and anything the bin could not hold is left where
    it is rather than deleted for good. The sizes go down straight away,
    without scanning again.

  • Why can't I delete this — when something is in use, Vitals names the
    program holding it, so you know what to close.

  • Explore a storage scan — after a scan, a map shows every folder sized by
    the space it takes, as layers or as blocks. Click a block to go inside, use
    the breadcrumb or Up to come back, and hover for its size and share. A list
    beside it can be driven with the keyboard, and every row can be opened,
    shown in File Explorer or have its path copied.

  • Largest files — the thousand biggest files on the scanned drive, each one
    click away from File Explorer.

  • Act on startup items and services — right-click a row, or use the
    button at its end. Startup items switch off and on the way Task Manager
    does it; services start, stop, restart, and can be set to start
    automatically, manually or never. Both open the file location, its
    properties, a web search, or copy their details.

  • Hide Microsoft services — ticked by default on Startup and Services,
    so the lists show what other software added; the hidden count is shown
    and one click brings them back.

  • Safe by default — anything Windows depends on asks before it is
    switched off, what Windows forbids is not offered, and a change that
    needs administrator rights asks once, for that change only.

  • CPU temperature and package power — install the optional sensors
    service from Devices & sensors (one administrator prompt) and Vitals shows
    the CPU package temperature, the hottest core and the package power draw
    on Devices, the Thermals chart, Prometheus (vitals_cpu_power_watts) and
    Home Assistant. It uses the signed PawnIO driver, only reads, and can be
    removed from the same screen.

  • Hardware — Devices & sensors shows what the computer is made of:
    processor, every memory module, graphics cards, drives (with temperature
    and health) and the motherboard and BIOS.

  • Device Manager — every device Windows lists, grouped the same way,
    with its driver and any problem it reports. You can search, and show
    devices that are not connected.

  • Fan speeds — with the sensors service installed, the motherboard's fan
    speeds appear on Devices, the Thermals chart, Prometheus
    (vitals_fan_rpm) and the LAN API.

  • Drive temperatures without administrator rights.

  • Lag watchdog — vitals-watchdog notices when a window you are using
    stops answering, or programs cannot get the processor in time, names the
    process behind it (never the shell or IDE it was started from), and offers
    End, Lower its priority or Ignore from a notification. It never ends
    anything on its own, and --diagnose shows what it would decide.

  • The watchdog ships with Vitals — it is part of the installer and turns
    itself on at the first launch. Settings → Watchdog turns it off, chooses
    the sensitivity (Relaxed, Normal or Sensitive) and the warning sound: any
    of Windows' notification sounds, none, or your own audio file with a
    volume, and a Test button.

Changed

  • Privacy policy covers the Android and Wear OS apps: the two kinds of
    special access and what they stay on, the phone-to-watch link, and the
    diagnostics Google ML Kit sends when the QR scanner opens.

  • Storage scans are about 80 times faster and count everything — a whole
    drive of eight million files is read in about seven minutes instead of
    never finishing, and Program Files in six seconds instead of eight
    minutes. There is no depth choice any more: every folder is counted, at
    every depth, and the scan shows live progress and the folder it is reading.

  • CI takes about 8 minutes instead of 49: the Windows checks run as three
    parallel jobs with their own caches, and a push that only changes the
    website or prose skips the Rust jobs.

  • Scoop is available (scoop bucket add vitals https://github.com/dragoscv/scoop-vitals);
    winget and Chocolatey are submitted and awaiting their moderators.

Fixed

  • A debug build takes about 10 GB instead of growing without limit — the
    desktop crate no longer builds two extra copies of itself for mobile targets
    Vitals does not ship, and verify.ps1 prunes abandoned incremental caches
    and fails when target/ goes over budget (contributors only).

  • OneDrive folders are counted in storage scans; they used to be skipped.

  • Stopping a scan no longer stops a cleanup search (or the other way
    round) — each has its own Stop button.

  • Links are no longer reported as unreadable folders — a scan that only
    passed over shortcuts to other places is complete, and says how many it did
    not follow.

  • A shortcut to a file no longer counts as the file's size.

  • Scanning a drive scans the drive — choosing C: could scan whichever
    folder Vitals was started from instead.

  • The board's thermal zones are labelled as such, so a 28 °C chipset
    reading is no longer mistaken for the CPU temperature.

  • The watchdog no longer warns during builds or while you are away from the
    computer: a busy processor on its own is not a freeze.

  • The macOS build compiles again: the desktop overlay is transparent on
    Windows and Linux only, because on macOS a transparent window needs Tauri's
    private-API feature. macOS is built on every release but not yet published.


Verifying this download

Windows may show a SmartScreen warning on first run (Windows protected your
PC
) because the installer is not yet signed with a commercial certificate.
Choose More info → Run anyway. That is expected — see
docs/distribution.md.

You do not have to take our word for what is in the binary. With the
GitHub CLI:

gh attestation verify .\Vitals_x64-setup.exe --repo dragoscv/vitals

This proves the file was built by this repository's release workflow from the
tagged commit, and nowhere else. Checksums for every file are in
SHA256SUMS.txt:

(Get-FileHash .\Vitals_x64-setup.exe -Algorithm SHA256).Hash.ToLower()

Software bills of materials (CycloneDX) for the Rust and JavaScript
dependencies are attached as sbom-rust.cdx.json and sbom-js.cdx.json.