Security update — please upgrade from 1.3.0.
- Next.js 16.3.0 → 16.3.5: fixes two critical remote-code-execution advisories (the image optimizer with AVIF files, and servers running on Windows, which the Windows launcher is).
- sharp 0.35.3 → 0.35.4: fixes the libheif vulnerabilities it bundles.
No other changes. Your data folder (datos/) carries over: copy it into the new folder.
Try it first without installing: cvforge.korven.dev (sample data, no key).
Install
- Download
cvforge-v1.3.1.zipbelow and check it:shasum -a 256 -c checksums.txt - Unzip it, then double-click CVForge (macOS) or CVForge (Windows). On Linux:
./programa/start.sh(Node.js 20+). - It opens at
http://localhost:3000and asks for your Anthropic API key.
One zip for every system: the macOS (Apple Silicon and Intel) and Windows Node runtimes ship inside, so nothing gets installed on your system.
macOS: the app isn't notarized yet. If macOS blocks it, open System Settings → Privacy & Security and click Open Anyway (macOS 15+), or right-click → Open (macOS 14 and earlier).
Windows: the launcher hasn't been tested on a physical Windows machine yet. Reports welcome.
Full notes: CHANGELOG.md.