Nightly 0.9.0-nightly.20260929.gd2e4c60
Pre-releaseNightly build. Built from
mainevery night something lands. Unreleased,
and it may be broken. The installed app does not update itself from nightlies.
Security
- The local API is read-only —
127.0.0.1:7330no longer lets a
program end or pause your processes without a token. Another Windows
account on the same PC could reach it; thevitalsCLI now acts on your
own machine through Windows directly, with your own rights. - The CLI pipe is locked to your account — an explicit access list
(you, SYSTEM, administrators) replaces the Windows default, which also let
everyone read it. - The phone page is harder to attack — every response from the LAN
server carries a content security policy and refuses to be framed; request
bodies and WebSocket messages are capped. - Releases wait for the owner — publishing needs approval, release tags
can only be created by the owner, and every build action is pinned to an
exact version.
Added
-
Vitals for Android and Wear OS — native phone and watch apps. The phone
opens on This phone: processor, graphics, memory, battery, temperatures,
storage with a folder map and cleanup, per-app time and data, sensors, a
week of history and alerts, all read through Android's public interfaces.
Pair a PC with a QR code to see it, its processes and sensors, wake it and,
with a control token, end or suspend processes. The watch monitors itself
and your PCs, with a tile and complications. Signed APKs ship with every
release, so Obtainium can follow them. -
Free Windows' own space with Windows' own tools — in Reclaimable space,
the Windows Update cache, system temporary files, the thumbnail cache, crash
dumps, the component store, the previous Windows installation, the Recycle
Bin and the hibernation file now have a button that runs the tool Windows
provides for each (Disk Cleanup, DISM or powercfg). Windows asks for
administrator approval once, for that action only; you see what it is doing
while it works, and afterwards how much space was actually freed, measured
before and after. Emptying the bin, removing the previous Windows and
turning hibernation off say what cannot be undone and need a tick first. -
Free space from a storage scan — put folders and files in review with
the + beside them (or right-click on the map), check the list and its
total, and send them to the Recycle Bin in one step, from where any of them
can be put back. Windows, installed programs and the folders your account
is made of are refused, and anything the bin could not hold is left where
it is rather than deleted for good. The sizes go down straight away,
without scanning again. -
Why can't I delete this — when something is in use, Vitals names the
program holding it, so you know what to close. -
Explore a storage scan — after a scan, a map shows every folder sized by
the space it takes, as layers or as blocks. Click a block to go inside, use
the breadcrumb or Up to come back, and hover for its size and share. A list
beside it can be driven with the keyboard, and every row can be opened,
shown in File Explorer or have its path copied. -
Largest files — the thousand biggest files on the scanned drive, each one
click away from File Explorer. -
Act on startup items and services — right-click a row, or use the
button at its end. Startup items switch off and on the way Task Manager
does it; services start, stop, restart, and can be set to start
automatically, manually or never. Both open the file location, its
properties, a web search, or copy their details. -
Hide Microsoft services — ticked by default on Startup and Services,
so the lists show what other software added; the hidden count is shown
and one click brings them back. -
Safe by default — anything Windows depends on asks before it is
switched off, what Windows forbids is not offered, and a change that
needs administrator rights asks once, for that change only. -
CPU temperature and package power — install the optional sensors
service from Devices & sensors (one administrator prompt) and Vitals shows
the CPU package temperature, the hottest core and the package power draw
on Devices, the Thermals chart, Prometheus (vitals_cpu_power_watts) and
Home Assistant. It uses the signed PawnIO driver, only reads, and can be
removed from the same screen. -
Hardware — Devices & sensors shows what the computer is made of:
processor, every memory module, graphics cards, drives (with temperature
and health) and the motherboard and BIOS. -
Device Manager — every device Windows lists, grouped the same way,
with its driver and any problem it reports. You can search, and show
devices that are not connected. -
Fan speeds — with the sensors service installed, the motherboard's fan
speeds appear on Devices, the Thermals chart, Prometheus
(vitals_fan_rpm) and the LAN API. -
Drive temperatures without administrator rights.
-
Lag watchdog —
vitals-watchdognotices when a window you are using
stops answering, or programs cannot get the processor in time, names the
process behind it (never the shell or IDE it was started from), and offers
End, Lower its priority or Ignore from a notification. It never ends
anything on its own, and--diagnoseshows what it would decide. -
The watchdog ships with Vitals — it is part of the installer and turns
itself on at the first launch. Settings → Watchdog turns it off, chooses
the sensitivity (Relaxed, Normal or Sensitive) and the warning sound: any
of Windows' notification sounds, none, or your own audio file with a
volume, and a Test button.
Changed
-
Privacy policy covers the Android and Wear OS apps: the two kinds of
special access and what they stay on, the phone-to-watch link, and the
diagnostics Google ML Kit sends when the QR scanner opens. -
Storage scans are about 80 times faster and count everything — a whole
drive of eight million files is read in about seven minutes instead of
never finishing, andProgram Filesin six seconds instead of eight
minutes. There is no depth choice any more: every folder is counted, at
every depth, and the scan shows live progress and the folder it is reading. -
CI takes about 8 minutes instead of 49: the Windows checks run as three
parallel jobs with their own caches, and a push that only changes the
website or prose skips the Rust jobs. -
Scoop is available (
scoop bucket add vitals https://github.com/dragoscv/scoop-vitals);
winget and Chocolatey are submitted and awaiting their moderators.
Fixed
-
A debug build takes about 10 GB instead of growing without limit — the
desktop crate no longer builds two extra copies of itself for mobile targets
Vitals does not ship, andverify.ps1prunes abandoned incremental caches
and fails whentarget/goes over budget (contributors only). -
OneDrive folders are counted in storage scans; they used to be skipped.
-
Stopping a scan no longer stops a cleanup search (or the other way
round) — each has its own Stop button. -
Links are no longer reported as unreadable folders — a scan that only
passed over shortcuts to other places is complete, and says how many it did
not follow. -
A shortcut to a file no longer counts as the file's size.
-
Scanning a drive scans the drive — choosing C: could scan whichever
folder Vitals was started from instead. -
The board's thermal zones are labelled as such, so a 28 °C chipset
reading is no longer mistaken for the CPU temperature. -
The watchdog no longer warns during builds or while you are away from the
computer: a busy processor on its own is not a freeze. -
The macOS build compiles again: the desktop overlay is transparent on
Windows and Linux only, because on macOS a transparent window needs Tauri's
private-API feature. macOS is built on every release but not yet published.
Verifying this download
Windows may show a SmartScreen warning on first run (Windows protected your
PC) because the installer is not yet signed with a commercial certificate.
Choose More info → Run anyway. That is expected — see
docs/distribution.md.
You do not have to take our word for what is in the binary. With the
GitHub CLI:
gh attestation verify .\Vitals_x64-setup.exe --repo dragoscv/vitalsThis proves the file was built by this repository's release workflow from the
tagged commit, and nowhere else. Checksums for every file are in
SHA256SUMS.txt:
(Get-FileHash .\Vitals_x64-setup.exe -Algorithm SHA256).Hash.ToLower()Software bills of materials (CycloneDX) for the Rust and JavaScript
dependencies are attached as sbom-rust.cdx.json and sbom-js.cdx.json.