Skip to content

Releases: fireflyframework/firefly-weave

Firefly Weave 0.1.0a15

Pre-release

Choose a tag to compare

@ancongui ancongui released this 09 Oct 04:35
b255983

Firefly Weave 0.1.0a15 is an alpha prerelease for evaluation. Upgrade the CLI and SDKs together with the server.

Installation · Upgrade notes

The macOS packages are ad-hoc signed and not notarized; Windows packages are unsigned. Checksums accompany the downloads.

Workflow language

  • Build text in expressions with concat, which joins one or more strings,
    numbers, or Booleans, and join, which joins a list of them with a separator.
    Numbers are written as JavaScript writes them (2.0 becomes 2). The compiler
    reports an operand that can never be text as WV-COMP-TYPE_MISMATCH and guards
    one that might not be at run time. Decision table rules cannot use either
    operator yet (WV-DECISION-OPERATOR), and Studio does not edit them yet.
  • Compile a workflow that uses concat or join to weave/ir-v1alpha4, with
    text.concat, text.join, or both in the executable's new features list.
    Every other workflow keeps its IR version and digest.
  • List the language features a platform runs in language_features in the
    capabilities response, and add weave/ir-v1alpha4 to ir_versions. An older
    platform omits language_features, which means none. Activating a workflow
    that needs a feature the platform does not list answers HTTP 422
    WV-IR-UNSUPPORTED with result.missing_features; artifact import and the
    compatibility report call it ir_unsupported.
  • Add the language manifest, which lists the step kinds, operators, workflow
    fields, language features, and limits a platform supports:
    GET /api/v1/tenants/{tenant}/projects/{project}/language (catalog.read),
    weave remote language, WeaveClient.language(), the Studio host, and
    language-manifest.schema.json from weave schema export. The capabilities
    response now lists all ten runnable step kinds in step_kinds.
  • Accept forEach, callWorkflow, and spec.callable in workflow definitions
    and the workflow schema, so documents can be prepared for loops and workflow
    calls. The compiler refuses forEach and callWorkflow with
    WV-COMP-UNSUPPORTED_FEATURE until a release runs them; callable only
    declares an interface and compiles. Existing documents and artifacts keep
    their bytes and digests.
  • Runs in progress whose workflow uses a language feature the server does not
    run, for example after rolling back to an earlier release that lists fewer
    language features, now wait for an upgrade instead of being blocked for good.
    The server offers none of their tasks to workers, leaves their deadlines and
    expired attempts pending, records nothing about them, and does not let them
    hold back other runs. After the upgrade they continue, and deadlines that
    passed in the meantime apply then. A server that predates language features,
    such as 0.1.0a14, still blocks such runs permanently, so finish or cancel them
    before rolling back that far.
  • Reading such a run, sending it a signal, or reporting a task result for it
    answers HTTP 422 WV-IR-UNSUPPORTED with result.missing_features instead of
    HTTP 409 WV-LEGACY-UNAVAILABLE. Reading a definition version the server does
    not run, or repeating the publish request that created it, answers the same
    way. Run and incident lists still show such runs as unavailable, and runs with
    unavailable legacy evidence still answer WV-LEGACY-UNAVAILABLE.
  • Catalog list pages can contain a new kind of item for a version the server
    does not run: unavailable: true, reason: ir_unsupported, and
    missing_features. SDKs and CLIs older than this release reject such a page;
    upgrade them together with the server.

Connections and private networks

  • Accept http:// base URLs in no-code HTTP connections, as HTTP connector
    actions already do, and never send plain text silently: weave connections create, read, and test and weave connector import-openapi --target builtin print a "Not encrypted" warning on standard error, and Studio's
    connection form shows a Not encrypted notice. Private, loopback, and CGNAT
    addresses still need an approved entry, and machine-token endpoints stay
    HTTPS-only.
  • Connection test answers carry a new encrypted field. CLIs and SDKs older
    than this release cannot read weave connections test answers for HTTP
    connections from an upgraded server; upgrade the CLI and SDK together with the
    server.
  • Add development-only private origins to the Docker development platform:
    weave platform up --allow-private-origin ORIGIN (repeatable) lets HTTP
    connector actions and signed webhooks reach a local http:// test service at
    that exact origin on the installation's own egress network. The API reads the
    approved entries from the read-only file named by WEAVE_PRIVATE_ORIGINS_FILE
    and refuses to start when that file is malformed, a symbolic link, or writable
    by other users. Requests to an approved origin never follow redirects, and
    Weave refuses the connection when it cannot tell whether the address belongs
    to the platform itself.
  • Map WEAVE_HTTP_PRIVATE_NETWORKS, WEAVE_MAIL_PRIVATE_NETWORKS, and
    WEAVE_POSTGRES_PRIVATE_NETWORKS at startup to "Legacy setting" entries of
    the same private-origin policy, with a private_origins.legacy warning and
    unchanged reach.
  • Parse WEAVE_HTTP_PRIVATE_NETWORKS, WEAVE_MAIL_PRIVATE_NETWORKS, and the
    PostgreSQL private and plaintext network settings strictly at startup: a CIDR
    with host bits set, or more than 128 networks, in any of them stops the API.
    Before, the HTTP and mail settings accepted a CIDR with host bits set and
    failed the requests that used it, and the HTTP and PostgreSQL settings had no
    limit. Reach is otherwise unchanged.

Reliability under load

  • Keep a platform ready when a compatibility rescan confirms it. A burst of API
    requests no longer makes the periodic rescan restrict the platform until the
    next one, and changes are no longer refused for a moment while a confirming
    rescan cleans up. 503 WV-COMPATIBILITY answers carry Retry-After, the
    seconds until the next automatic rescan, and a rescan that withdraws readiness
    logs Compatibility rescan withdrew readiness with the finding kinds and codes.
  • Retry a Studio read, or a change that carries an idempotency key, after
    503 WV-COMPATIBILITY when Retry-After is 5 seconds or less, within the
    existing limit of four attempts.
  • Background work that starts when a compatibility check makes the platform
    ready, such as event delivery, native connectors, broker and provider inboxes,
    and recovery, no longer keeps failing with WV-OPERATION-CAPACITY after the
    check's response ends, and no longer carries that request's identity.
  • Give recovery, the provider and email inboxes, and Kafka consumers their own
    execution capacity, so a burst of API requests no longer refuses their work.
    Recovery and schedule scan failures now log the error class and code, for
    example Tenant recovery scan failed (CatalogError WV-OPERATION-CAPACITY).
  • Native connector calls no longer share the two execution work slots of API
    requests, so a burst of requests no longer refuses them. They run up to the
    capacity configured for each WEAVE_NATIVE_EXECUTORS entry.
  • Native connector tasks no longer fail with HANDLER_FAILED when Weave refuses
    one of their platform calls for capacity (WV-OPERATION-CAPACITY or
    WV-REQUEST-CAPACITY). The invocation check before the connector starts is
    sent again while the task's lease is valid; authority and credential checks
    made while the connector runs get up to three attempts within one second.
  • A schedule whose run start is refused for capacity stays enabled and fires the
    same occurrence, with the same key, on the next scan, instead of being blocked
    with WV-SCHEDULE-READINESS. An occurrence still refused when its minute ends
    is skipped like any other missed minute.
  • Provider receipts refused for capacity stay pending with the reason
    transient_failure and the usual cooldown instead of being blocked.
  • email_receipts.dispatch answers HTTP 429 (WV-OPERATION-CAPACITY or
    WV-REQUEST-CAPACITY) when Weave refuses the dispatch for capacity, where it
    used to answer HTTP 200 with state blocked. The receipt keeps its state, and
    the next pending scan dispatches it.
  • Keep an integration event delivery recoverable when Weave refuses one of its
    database transactions for capacity (WV-OPERATION-CAPACITY). The delivery
    stays leased instead of moving to retry with DELIVERY_FAILED or to an
    AUTHORITY_REVOKED incident. When the lease expires, the attempt is recorded
    as ACK_UNKNOWN and the same event ID is delivered again. The attempt still
    counts, so a delivery refused on every attempt ends in a DELIVERY_EXHAUSTED
    incident.

API

  • Publish the run summary, step, and log operations (run_summaries.list,
    runs.steps, and runs.logs) and their schemas so clients can build against
    them. They require run.read and validate their queries and cursors; this
    release answers an authorized, valid request with HTTP 501 WV-UNAVAILABLE.

Studio, desktop app, and CLI

  • Give Studio one dark theme built from design tokens, the self-hosted Manrope
    typeface, and Lucide icons. The sidebar and pairing pages show the Firefly
    Weave logo; the collapsed sidebar and narrow windows show the Firefly mark,
    and the browser tab the Firefly favicon.
  • Remove the Lumi mascot from Studio, the API explorer, exported workflow
    graphs, the README, and the documentation diagrams.
  • Say Weave AI throughout Studio: Ask Weave AI, Weave AI settings,
    Explain with Weave AI, the AI models settings card, and the role labels
    Weave AI user and Weave AI manager. Show the product name, Fi...
Read more

Firefly Weave 0.1.0a14 — Docker development platform

Choose a tag to compare

@ancongui ancongui released this 07 Oct 14:36
b4c0643

Firefly Weave alpha14 adds weave platform up for a local development platform that runs in Docker in the background. It brings together the API, PostgreSQL, Keycloak sign-in, a demo workspace, and optional account creation. Use the matching alpha14 checkout and CLI; the foreground API route remains available.

See the Docker development guide for setup, sign-in, Studio, and stopping/resuming the platform.

Validation used a real local Docker platform: CLI authentication and successful workflow execution; Studio sign-in and session recovery against Keycloak; and stop/resume retaining the saved run and account while leaving unrelated containers unchanged. These checks establish the local development journey, not production-cluster provisioning or interactive desktop coverage on every operating system.

Agentic and Files workers 0.1.6 pin core 0.1.0a14. Both worker updates are dependency-only; their execution behavior and the database schema are unchanged.

The release includes the core and worker packages, locked installation requirements, CLI installer, and matching optional Studio browser bundle. Verify downloads against SHA256SUMS. Native installers are separate assets and should only be used when attached with their matching manifests.

Ordinary macOS installers remain ad-hoc signed and are not notarized. A separate opt-in workflow now supports Developer ID signing and Apple notarization for reviewed release tags. It requires an Apple Developer account, certificate/private key, App Store Connect API credentials, and a protected GitHub environment. No actual Apple notarization has been verified for this release. Windows installers remain unsigned. See desktop signing and installation.

This release does not constitute an Azure upgrade; cloud rollout evidence remains separate.

Firefly Weave 0.1.0a13

Pre-release

Choose a tag to compare

@ancongui ancongui released this 07 Oct 10:43
2434ba5

Fix AI worker preparation under platform capacity pressure.

  • Context and credential requests retry only explicit, known pre-admission capacity rejections while the worker retains a valid lease. Expiry, cancellation, and renewal failure stop those retries.
  • A local preparation-budget timeout before model execution is reported as not started. Provider and ambiguous network failures retain conservative outcome handling.
  • Core/CLI/SDK/Studio: 0.1.0a13. Agentic and Files: 0.1.5; Files has a dependency update only. Desktop: 0.1.0-alpha.13.
  • API contracts and database schema remain unchanged from alpha12 (0030_worker_presence). Existing historical executions are not replayed automatically.

Installation, API/SDK guidance, and deployment acceptance are documented at https://fireflyframework.github.io/firefly-weave/.

The standard source, test, type, documentation and installed-artifact checks passed. Studio's source is unchanged from alpha12; this release packages it with the updated host. Real-provider acceptance is recorded separately from local test results.

macOS bundles are ad-hoc signed, not notarized. Windows installers are unsigned. Verify downloaded files using the included checksums.

Verified delivery on October 7, 2026:

  • All 32 release assets were downloaded and hash-checked after publication, including six desktop installers across four targets.
  • Main/tag checks, documentation publication, and desktop installer workflows passed for the tagged commit.
  • All 17 standard check stages passed, including 3,654 core unit/contract cases, 76 Agentic cases and 29 Files cases. Another 94 affected integration cases passed; this is not a fresh full integration/load campaign.
  • Azure preproduction uses the corrected alpha13 SDK / Agentic 0.1.5 worker against the unchanged alpha12 API and schema 0030. One new Azure OpenAI workflow succeeded with one model request and consistent replay. API, Lumi, Operations and historical runs were preserved. This verifies that specific deployment combination, not arbitrary mixed versions.

Azure scaling remains disabled in the verified Operations setup. Installer verification does not establish interactive sign-in on every operating system.

Firefly Weave 0.1.0a12

Pre-release

Choose a tag to compare

@ancongui ancongui released this 07 Oct 08:44
230a3ab

Firefly Weave alpha12 improves guided workflow authoring and adds reviewed deployment operations.

  • Configure step inputs with type-aware choices and accessible help. The editor keeps invalid changes visible, organizes its toolbar and sidebars, and separates existing project actions from creating API actions.
  • Configure workflow AI profiles and Lumi independently. Standard OpenAI and Anthropic connections use their normal endpoints; advanced settings remain available, with explicit Azure configuration.
  • Register container destinations, inspect workers and capacity, drain workers, and review deployment plans before applying them through a destination-side runner. Compose uses trusted templates; Kubernetes and Azure Container Apps support bounded changes to existing resources. Cloud cluster provisioning remains external.
  • Ask Lumi about explicitly selected Operations records. It cannot approve or apply infrastructure changes.
  • Recover temporary Studio session capacity rejections without blocking page assets. Reviewed Compose plans can restart stopped workers and verify readiness afterward.
  • Keep worker heartbeats active through explicit capacity rejections while the lease remains valid, including while completion waits for acknowledgment. The worker never repeats the handler to recover a lost response.

Upgrade the database through 0029_deployments and 0030_worker_presence before starting the new server. Follow the singleton API maintenance procedure; do not overlap old and new schedulers. Existing workflow roles do not gain deployment permissions automatically.

Installation and quickstart · Source changes

Core/CLI/Studio: 0.1.0a12; Agentic and Files workers: 0.1.4; desktop: 0.1.0-alpha.12.

Desktop installers are unsigned prerelease builds; macOS bundles use verified ad-hoc signatures and are not notarized. Verify the accompanying target-specific checksum manifests. Installing a release does not configure identity providers, admit workers, or deploy a remote platform automatically.

Firefly Weave 0.1.0a9

Firefly Weave 0.1.0a9 Pre-release
Pre-release

Choose a tag to compare

@ancongui ancongui released this 03 Oct 17:20

Studio now guides administrators through AI provider connections and named Lumi connections. Workflow model profiles remain independent, and incomplete profiles stay editable. Agentic workers can renew dedicated OAuth2 client credentials.

The illustrated AI and Lumi guides cover setup, roles, execution, and proposal review. Core 0.1.0a9 pairs with Agentic and Files workers 0.1.1; database schema remains 0028_files.

Validation: 17 offline stages passed, including 3,488 core unit/contract tests, 56 Agentic tests, 29 Files tests, lint, types, strict documentation builds, and installed artifacts. Studio passed 608 unit tests and 31 affected browser tests with zero retries.

Azure live-provider acceptance is a separate deployment step. Verified native installers are available for macOS (Apple silicon and Intel), Windows x64, and Linux x64. All six installers and their build metadata were checked against the successful tagged desktop workflow; macOS bundle seals were also verified. macOS bundles use ad-hoc signatures and are not Apple-notarized; Windows installers are unsigned.

Verify downloads using SHA256SUMS. See the installation guide and documentation.

Firefly Weave 0.1.0a8

Firefly Weave 0.1.0a8 Pre-release
Pre-release

Choose a tag to compare

@ancongui ancongui released this 03 Oct 11:41

Firefly Weave alpha8

Alpha8 adds file transfers, decision tables, workflow AI steps, and a separately configured Lumi assistant. Studio now shows decisions and parallel branches as separate lanes, applies valid property changes immediately with Undo, and provides guided data mapping, human-task forms, connection slots, and accessible menus.

New capabilities

  • Pass verified file references through workflows, worker tasks, and human approvals. Upload and download through the API, Python SDK, CLI, and Studio forms; file bytes stay separate from execution history.
  • Deploy the independent Files worker for FTP, FTPS, SFTP, SharePoint/OneDrive, and Google Drive. It provides list, metadata, download, write, move, and delete Actions with explicit connection and worker policies.
  • Author contains, not-contains, in-list, and not-in-list conditions and versioned decision tables using first, unique, or collect matching.
  • Configure workflow model profiles and run AI Actions through an independent Firefly Agentic worker. Lumi uses a separate environment configuration and private gateway. Review and validate its workflow proposals before applying them with Undo; save other proposed definition types as reviewed draft files.
  • Worker completion retries now follow the active task deadline after explicit server capacity rejections; the SDK retries the acknowledgment without rerunning the business handler.
  • Configure and inspect processes through the improved Studio, including human-task attachments, input/output mapping, branch results, task details, and workflow execution.

Upgrade and configure

The server requires schema 0028_files. Stop writers and follow the upgrade procedure before starting the new runtime. Migrations are explicit; installing the CLI or Studio does not migrate a server. Grant file and Lumi roles explicitly where needed.

The server supports Python 3.12. The independent Agentic worker requires Python 3.13 and ships as a separate package; the Files worker has its own package and dependency lock. Publish the worker's exported contracts, admit its immutable image, configure credentials and grants, and activate a workflow before starting work.

Start with files, file connectors, AI workers, Lumi, or the Studio guide.

Current boundaries

  • Files are limited to 25 MiB each and stored as bounded PostgreSQL chunks. The worker SDK supports content processing; document extraction and OCR are not built-in transfer operations.
  • FTP/FTPS/SFTP require server-isolated accounts. FTP/FTPS write and move are disabled by default; explicitly enabling their non-atomic destination policy accepts the protocol's concurrent replacement limitation.
  • Dedicated cloud-drive change-feed triggers and Google Workspace document export are not included. Cloud credentials and live-provider acceptance are deployment-specific.
  • Lumi and workflow AI require configured providers and credentials. The release does not automatically enable paid model calls.
  • Native desktop installers are unsigned or ad-hoc sealed as identified in their target-specific provenance. macOS ad-hoc sealing is not Apple notarization.

Firefly Weave 0.1.0a7 — saved platforms, REST actions without code, redesigned Studio

Choose a tag to compare

@ancongui ancongui released this 03 Oct 03:09

Connect by address, call REST APIs without code, and a redesigned Studio

Alpha7 lets people connect the CLI, Studio, and desktop app to a platform by its address, sign in through their identity provider, and pick a workspace, without hand-written connection files. It adds REST actions built without writing a connector, and a redesigned Studio editor and shell.

Highlights

  • Saved platforms and guided sign-in. weave auth setup SERVER checks the server, shows its published sign-in settings for review, signs in through the system browser (PKCE) or a device code, and saves the chosen workspace. Studio and the desktop app share the same saved platforms; tokens stay in the system credential store.
  • Published sign-in settings. GET /api/v1/client-configuration, configured with WEAVE_CLIENT_SIGN_IN and WEAVE_DISPLAY_NAME. Clients pin what was reviewed and refuse silent changes.
  • REST actions without code. weave connector http-action, weave connector import-openapi --target builtin, guided weave connections create, and the Studio New API action builder, on the built-in weave-http@2.0.0 connector.
  • Redesigned Studio. A usable Call an action step, Decision rule rows with Otherwise, one lifecycle command, readable zoom, an inspector with Apply changes, a docked simulation, Build and Operate navigation, toasts with Undo, and local drafts.
  • Runtime fixes found end to end. Port-free Keycloak loopback callbacks, supervised in-process native workers that replay capacity rejections, Studio retries for capacity rejections, and JWKS keys without alg (Microsoft Entra ID) accepted by key type.

See the changelog for the full list.

Download and install

  • CLI: curl --fail --location https://github.com/fireflyframework/firefly-weave/releases/download/v0.1.0a7/install.sh | sh -s -- --version v0.1.0a7
  • Browser Studio: the matching firefly-weave-studio-0.1.0a7.zip and its .sha256.
  • Desktop: installers are attached below only for targets whose build succeeded; no filename in the documentation implies an installer was published. macOS bundles are ad-hoc signed, not Developer ID signed and not notarized; Windows publisher signing is not provided.
  • Guides: installation, connect the CLI, Studio, desktop.

Verification

Unit and contract tests (3,100+), lint, types, strict documentation build, release preparation, and installed artifact closures passed, together with the Studio unit and browser suites on macOS and Linux and the desktop native tests on all four targets. Against a real local platform with Keycloak 26.7.4 on macOS: CLI sign-in and workspace selection, a no-code HTTP action run, the Studio sign-in journeys with the macOS Keychain, and device-code sign-in, reconnection, and export in a locally built desktop app.

Not verified: Microsoft Entra ID and other identity providers (Entra-shaped keys are covered by unit tests only), Windows and Linux credential stores, browser sign-in inside the desktop app, and the owned release-runner gates.

The database schema remains 0025_run_lifecycle; this release adds no migration. Existing --auth-config connection files keep working.

Firefly Weave 0.1.0a11

Pre-release

Choose a tag to compare

@ancongui ancongui released this 03 Oct 19:49
39b214b

Studio now guides AI provider connections, Lumi settings, and workflow AI profiles through focused setup steps and a final review. Back preserves draft values; configuration is saved only at the final action. Shared workflow profiles show the affected steps before applying changes, while Lumi remains independently configured.

Later AI steps can explicitly include earlier results from the same workflow execution. This uses existing scoped expressions and durable step outputs, with a documented YAML/Python example and a visual walkthrough. It does not introduce implicit cross-run memory or arbitrary provider tools.

Core 0.1.0a11 pairs with Agentic and Files workers 0.1.3. Database schema remains 0028_files; no migration is introduced. Existing Azure acceptance is recorded against alpha10; this Studio-focused release does not require an Azure backend upgrade.

Validation: all 17 configured offline stages passed, including 3,496 core unit/contract tests, 56 Agentic tests, 29 Files tests, and clean installed core/CLI/worker artifacts. Final Studio checks passed 615 unit tests, TypeScript, formatting, the production build, and the full browser suite: 819 passed, with six live-platform tests skipped. Eight PostgreSQL AI execution tests verified run isolation, durable continuation, completion retry, and replay. The scope-parity oracle now reuses a per-process contract snapshot while preserving every compiler check and unchanged production limits.

The core, worker packages, optional Studio bundle, and verified native installers are available below. All six installers for macOS Apple silicon and Intel, Windows x64, and Linux x64 passed exact-tag provenance and checksum verification; both macOS bundle seals were also verified. macOS installers are ad-hoc signed, not Developer ID signed or Apple-notarized; Windows installers are unsigned.

Verify core and Studio bundle downloads with SHA256SUMS, and native installers with the matching target-specific weave-studio-*-SHA256SUMS file. Follow the installation guide, AI setup guide, and shared AI context walkthrough.

Firefly Weave 0.1.0a10

Pre-release

Choose a tag to compare

@ancongui ancongui released this 03 Oct 18:25
1ece929

Studio now forwards Lumi status, configuration, and chat through its authenticated local host. This fixes the 404 responses in alpha9 while preserving pairing, CSRF, environment scope, and upstream permission checks.

Workflow editing preserves canvas keyboard focus and prevents a delayed initial fit from clipping a newly revealed branch. Compiler scope-parity checks now reject inconclusive validation results; production compiler limits are unchanged. The new transparent Lumi illustration appears in Studio and the documentation.

Core 0.1.0a10 pairs with Agentic and Files workers 0.1.2. Database schema remains 0028_files; no new migration is introduced.

Validation: all 17 final-tree offline stages passed, including 3,496 core unit/contract tests, Agentic and Files worker tests, lint, types, strict documentation builds, and clean installed core/CLI/worker artifacts. Studio passed 610 unit tests and 42 affected browser tests plus 30 repeated race cases with zero retries. Another 26 provider integration tests passed against PostgreSQL. The installed alpha10 Studio connected to Azure successfully at desktop and narrow widths, including independent Lumi and workflow model settings.

Verified native installers are available for macOS (Apple silicon and Intel), Windows x64, and Linux x64. All six installers and their build metadata were checked against the successful workflow for this exact tag; macOS bundle seals were also verified. macOS bundles are ad-hoc signed, not Developer ID signed or Apple-notarized. Windows installers are unsigned.

Verify downloads with SHA256SUMS. Follow the installation guide, Studio setup, and AI configuration guide.

Firefly Weave 0.1.0a6 — macOS packaging repair

Choose a tag to compare

@ancongui ancongui released this 02 Oct 03:10

macOS packaging repair

Alpha6 repairs the missing macOS application resource seal in the alpha5 Apple Silicon installer. It also fixes the signed Python host startup by supplying the PyInstaller library-validation entitlement while keeping hardened runtime enabled.

macOS trust status: these preview bundles are ad-hoc signed, not Developer ID signed or notarized. Signature integrity and local startup have been verified; Gatekeeper still rejects the unnotarized publisher. This release does not promise that macOS will open a downloaded app without policy-approved manual approval. Use browser Studio if your installation policy requires a trusted publisher. Do not use the alpha5 Mac installer or remove quarantine as a workaround.

Download and install

  • Apple Silicon: download the alpha6 aarch64-apple-darwin.dmg and its target checksum inventory below.
  • CLI and browser Studio: use the matching 0.1.0a6 wheel/installer and optional Studio ZIP.
  • Other native targets are available only when attached below; no filename in the documentation implies an installer has already been published.
  • Follow the desktop installation guide or browser Studio guide.

Verification

Release packaging now verifies the outer application, both nested executables, and the application mounted read-only from its DMG. It smoke-tests the host again after signing, including readiness, matching version, assets, pairing, connection assistance, compiler, and owned shutdown. The alpha6 unit/contract suite passed 2,146 tests; packaging and source-attribution checks passed separately. Lint, types, strict documentation build, and independent installed artifact closures were checked.

The database schema remains 0025_run_lifecycle; this packaging repair adds no migration. This is an alpha preview, not certification of the full production recovery, live CIAM, mail, or cloud acceptance matrix. Checksums are supplied for the exact attached bytes. No signing credentials are included.