1Helm 0.0.22
1Helm 0.0.22
This release makes 1Helm's model policy explicit and durable, turns the mobile apps into secure lightweight gateways to the instance you select, and completes the eight requested product and interface changes.
What changed
- Log Out — the profile popover now contains a visible Log Out action. Native clients retain a separate Disconnect action that also clears the selected instance and secure session.
- Light default — first-ever browser profiles start in light mode while keeping the user-controlled dark-mode switch.
- Presentation PDF decks — each slide has a locked, visible, configurable printable area (1500 × 1000 by default). The Excalidraw menu exports the complete deck as one bounded multi-page PDF and excludes out-of-area content.
- Mobile instance gateways — Android and iOS package only a minimal HTTPS connection and recovery shell, then load the selected instance's live frontend. Exact-origin bridge checks preserve secure sessions, deep links, attachments, camera and microphone access, keyboard behavior, and safe-area handling without freezing a copy of the product frontend into the app.
- Model policy — effective precedence is thread → channel → personal → workspace → agent. Every composer displays and submits that policy; personal overrides are labeled and removable; stale submissions are rejected; admitted turns snapshot the model and provider; silent audits use explicit
system-*identities; requested models remain separate from Router fallback outcomes. - Selected answers — selected structured choices now expose
aria-pressedplus a strong ring, fill, inset accent, and checked indicator in both themes. - Cowork tabs — Cowork section tabs are centered at normal widths while remaining horizontally usable on narrow screens.
- Routes — the visualization is spacious and flows bottom-to-top: Requests → 1Helm Router → a stable eight-provider arc containing ChatGPT, Claude, Antigravity, xAI, OpenRouter, NVIDIA, Cloudflare, and GLM, with dotted live request paths.
Additional fixes
- HTTP browser WebSockets use
ws:; HTTPS and native instances usewss:. - Fast Cowork Yjs synchronization, detached Files-test interaction, and legacy presentation element ordering are deterministic.
- Version, native mobile build numbers, channel-machine pins, README, and changelog are synchronized at
0.0.22. - Windows artifacts are intentionally unsigned. Setup and the packaged app report
NotSigned, which is the accepted disclosed status until 1Helm adopts a trusted Windows signing identity; no self-signed certificate is used.
Downloads and integrity
| Artifact | SHA-256 |
|---|---|
1Helm-0.0.22-arm64.dmg |
01bff6b3d12a6c9a3b8dd5984aa5c576f96837eb115282c31de19ceae0c69356 |
1Helm-0.0.22-mac-arm64.zip |
c755120cee48548d39fcc93ab42eda65e50914f93cabff1b8a0124ae48e9adc7 |
1Helm-0.0.22-linux-node.tgz |
1cae09865cccc29a87bc5c9e86d3f65e8a8fe8278e64a0e46bc98c9d3fa2b844 |
1Helm-0.0.22-windows-x64-setup.exe |
ec8cf602727354bd277624533b6b7a7fbd4db0bae8974c1cbe38e3af8d0c6f1e |
1Helm-0.0.22-full.nupkg |
c3cab727c9773ed35c6e77c7e7777fb44c4e2d5ab7b98a5b21e65feb820448ca |
RELEASES |
a302e97d6646bf83f517b0702283722487cae7fe1f5fb8fd6ca15a3307ba880c |
1Helm-0.0.22-universal.apk |
34169de533d81ac31468ab6f45771d8a3f8564cf458fd97aee8a72e23939e8ea |
Exact source commit: 8a90acc4f4da12349805287faafc2f970cc172e0
Exact source archive SHA-256: d91ab630a207bc2fbedf141ca28d0883df1f9df1c9a1b613b7bf70aeb5fa7e4d
Verification
- Shared source verification passed TypeScript typechecking, the production build, onboarding 20/20, native-world 125/125, 106 broader contracts with two documented environment-only browser skips, brief browser 50/50, production browser 18/18, parsed multipage PDF export, thread audit 17/17, mobile, feedback, site, and Android build coverage. Required CI and CodeQL are green on the exact merged commit.
- macOS: the Apple Silicon app, updater ZIP app, DMG, and mounted app passed strict Developer ID verification, Apple notarization, stapling, and Gatekeeper. App notarization submission
978293de-b988-4ed2-9026-f6b823779a18and DMG submissione2bf3d6f-e334-412f-b1b1-2a60fe3240edwere accepted. A fresh public DMG download matched its SHA-256 and was installed on the retained Apple Silicon host; version0.0.22, bundlecom.gitcommit90.1helm, the arm64 process, configured loopback health, workspace/provider state, and Application Support inode34829724passed. The exact prior-app backup was removed only after acceptance. The public feed offers the updater ZIP to0.0.21and no update to0.0.22. - Linux: the exact digest-qualified archive passed a real retained systemd update to
0.0.22, loopback health, and an intentionally unhealthy release rollback. The exact healthy release root was restored after failure and/var/lib/1helmretained inode1179777throughout. A fresh public archive download again matched the canonical SHA-256; the service remains active on that exact release root, its loopback setup endpoint is healthy, the updater path is active, and the temporary acceptance override is absent. - Windows: native typecheck/build and focused desktop, updater, mobile, licensing, and release-governance contracts passed. The literal
RELEASESmanifest matches the full package SHA-1 and size. A retained Squirrel0.0.21 → 0.0.22update and a Setup reinstall both completed with exit code 0; installed version and configured loopback health passed at port52690. Database SHA-2563e3cb52205e069fe7c62138319e4fac96018e51be189027434aaaa9566e65ee8, its creation identity, installation IDaae9113be49de5f1, provider/channel/computer state, the WSL data-root identity, and distro1helm-aae9113be49de5f1-channel-2were retained. The channel still has/workspaceand no/mnt/c. Fresh public Setup, nupkg, andRELEASESdownloads matched their canonical hashes and manifest, and the public Setup reinstall again exited 0 with configured loopback health while preserving the current database identity/state, installation ID, provider/channel/computer state, WSL root/distro,/workspace, and host-mount isolation. Setup and the packaged/installed app report the acceptedNotSignedAuthenticode status. The public feed offers0.0.22to0.0.21and no update to0.0.22. The broad Windows test aggregator's 12-second server startup limit and cross-platform Apple/LXC fixtures remained environment-only failures under host load and are not represented as passes. - Android: the permanently signed universal APK contains arm64-v8a, armeabi-v7a, x86, and x86_64; v2/v3 signature verification passed. Certificate SHA-256 is
7b2d96ab21a242f9b17ddc7c65d133033bb9f0322158b6aab57bf8d46a7d27bf. A retained signed0.0.16 → 0.0.22in-place update and a separate clean0.0.22install both launched successfully; the retained update kept application-data inode377038and its marker. The fresh public APK is byte-identical to that accepted candidate and independently passed SHA-256, zip alignment, v2/v3 signature, certificate, package/version, and four-ABI checks. - iOS: App Store build
22(0.0.22, bundlecom.gitcommit90.onehelm.mobile) was archived and exported from the exact source with App Store distribution signing; strict code-sign verification passed. The exact IPA, App Store metadata, reviewer credentials, and a fail-closed validation/upload script are staged on the release Mac. The sanitized HTTPS review workspace and deterministic provider now run the same0.0.22source while preserving their retained data. App Store Connect validation/upload awaits account authentication and the installable IPA is intentionally not a GitHub release asset. - Live demo: the exact merged source is deployed; loopback setup status and
https://demo.1helm.comare healthy.
Licensing
1Helm remains licensed under AGPL-3.0-only.