Skip to content

Releases: jorphex/wren

0.1.6

Choose a tag to compare

@github-actions github-actions released this 03 Sep 09:14

Wren 0.1.6

Wren 0.1.6 makes transaction reviews clearer, restores direct unlock flows for
locked accounts, and gives the wallet a calmer, more consistent visual system.

Reviews and approvals

  • Transaction reviews now group the decoded action, fee and nonce controls,
    estimated asset changes, contract data, and signer actions more clearly.
  • Token approvals make requested, custom, unlimited, and revoke adjustments
    easier to find without hiding the resulting allowance.
  • Estimated sends and receipts share one compact ledger. Values remain estimates
    from the configured RPC and may be unavailable for some contracts.
  • Submitted transactions use three readable states—submitted, confirming, and
    confirmed—with compact hash, explorer, cancel, and speed-up actions when they
    apply.
  • A known app origin can move to another enabled chain without a redundant
    approval screen or account exposure. Unknown origins and unknown or disabled
    chains still fail closed.
  • Raw data shows transaction fields instead of internal Wren bookkeeping.

Activity evidence

  • Activity details recover supported methods and transfers from transaction data
    and confirmed receipts instead of relying only on the original review result.
  • Local calldata decoding provides a stable fallback when remote metadata is slow
    or unavailable.
  • Wrapped-native deposits and withdrawals show their relevant asset changes.

Wallet and accounts

  • Account settings restores reliable renaming for named and unnamed accounts.
    Local names remain separate from ENS names.
  • Connected apps now uses one eligibility rule for its badge and list, with
    clearer per-account guardrail and revoke actions.
  • Selecting a locked software or hardware account continues to its password,
    device PIN, passphrase, or reconnect flow. Ready software and watch-only
    accounts switch directly; hardware accounts open signer management.
  • Wallet, Control Center, and review screens share one top bar, content grid,
    translucent card treatment, and spacing rhythm.
  • Activity previews fit their content and use a shorter empty state.

Maintenance and compatibility

  • Patched the transitive fast-uri advisory, updated Electron from 42.8.0 to
    42.10.1, and refreshed other reviewed dependencies. Coordinated major upgrades
    remain deferred.
  • Expanded production-layout coverage across transaction, signing, approval,
    permit, batch, deployment, delegation, and lifecycle states.
  • Wren Companion 0.1.2
    remains the paired browser extension over authenticated protocol 3. Firefox
    store review remains pending.

Distribution

  • Linux x64: Wren-0.1.6.AppImage and wren_0.1.6_amd64.deb.
  • Windows x64 preview: Wren-Setup-0.1.6-unsigned-x64.exe.
  • macOS previews: Wren-0.1.6-macos-x64-unnotarized.dmg and
    Wren-0.1.6-macos-arm64-unnotarized.dmg.

Verify the selected file against SHA256SUMS and its GitHub attestation. Linux
x64 remains the qualified target. Windows is unsigned and unqualified. macOS is
ad-hoc signed, unnotarized, and unqualified pending checks on the exact physical
hardware. Wren has not had an independent security audit; please start with a
backup and a small test account.

0.1.5

Choose a tag to compare

@github-actions github-actions released this 31 Aug 18:59

Wren 0.1.5

Wren 0.1.5 improves everyday Control Center and wallet workflows, refreshes the
visual hierarchy, makes Activity rows useful detail views, and keeps privacy-safe
transaction references available for the same 90-day window as Activity history.

Richer Activity details

  • Every Activity row is clickable and keyboard accessible. Detail views show the
    applicable type, result, app, network, account, and exact timestamps without
    placing private request contents in Activity history.
  • Transaction, Wallet Calls, and EIP-7702 revocation entries can retrieve semantic
    transaction context on demand from the configured RPC. Wren verifies the retained
    hash, sending account, and optional canonical block before showing native value,
    recipient or contract, bounded method/argument context, Copy, or explorer actions.
  • Wallet Calls details distinguish submitted, confirmed, reverted, and unavailable
    actions. Partial recovery is labeled rather than reconstructed or guessed.
  • A compact main-process-only ledger retains Activity identity, account, origin,
    chain, submitted hashes, and optional canonical block references for 90 days.
    It never stores fetched transaction bodies, calldata, decoded opaque bytes,
    recipients, or amounts. Renderer state and profile backups exclude the ledger,
    and Clear Activity removes it.
  • On upgrade, Wren backfills references only from evidence that is still retained.
    Older entries without recoverable evidence show that on-chain evidence is
    unavailable.
  • Clear Activity establishes a durable history boundary. Repeated observations of
    an unchanged retained transaction, including a replacement, stay cleared; a
    newer lifecycle update may appear again.

Control Center and wallet workflows

  • Persistent Control Center navigation keeps Home, Accounts, Networks, App
    activity, and Settings close at hand, with account, active-network, and app
    counts where available.
  • Account management groups signing and watch-only accounts, shows disconnected
    hardware accounts, keeps account ordering stable, and offers direct create,
    import, and watch actions.
  • Network management adds Active and All views with an inline Add action.
  • The wallet adds a portfolio summary with a direct Send action, plus address Copy
    and QR actions. Chrome Companion now opens its Web Store listing directly.
  • The request summary identifies the next review, its app, and whether other
    requests are pending or confirming.

Clearer request reviews

  • Permit reviews state the action, account, token, amount, network, spender,
    expiry, and signature type, while keeping raw typed data available.
  • Token approvals place the token, spender, expiry, and spending-limit choices
    together. Unlimited approval has an explicit warning; custom values are
    validated; incomplete token details remain visible but cannot be edited.
  • Wallet Calls batch settings show the starting nonce, maximum batch fee, and
    per-transaction gas and fee controls. EIP-7702 revocation keeps configured-RPC
    delegation evidence available on demand.

Interface system

  • The dashboard, Control Center, wallet panel, request reviews, account selectors,
    navigation, and management surfaces now share one consistent visual hierarchy.
  • Send and Sweep have visible recipient and amount fields at rest, regular-weight
    values, clearer mode selection, and aligned positive-balance selection controls.
  • Portfolio, balances, requests, and Activity use corrected optical alignment,
    spacing, separators, footer actions, hover bounds, and empty-state treatment.
  • Account identity and portfolio balance presentation is lighter and more direct,
    while transaction and signing controls retain explicit review emphasis.

Profile migration reliability

  • Existing Frame profiles regain their canonical legacy color palette during
    migration instead of carrying incomplete theme values into Wren.
  • Mixed-case account keys are merged into their canonical lowercase identity while
    preserving account metadata and records.

Compatibility and security boundary

  • Wren 0.1.5 remains designed to pair with
    Wren Companion 0.1.2
    over authenticated protocol 3. Firefox review remains pending. Use the
    checksum-verified Companion archive where store distribution is unavailable.
  • Wren has not had an independent security audit. The Activity lookup is an explicit
    user action, uses only the configured RPC, returns a bounded semantic projection,
    and does not add telemetry or a Wren backend.

Platform boundary

Linux x64 AppImage and deb packages remain Wren's qualified release target.

The Windows x64 installer is an unsigned, unqualified preview. Windows will
show an unknown publisher and may display SmartScreen. Its filename includes
unsigned, and both the installer and packaged executable must report NotSigned.

The Intel and Apple Silicon macOS DMGs are unqualified previews. They are
ad-hoc signed and unnotarized, with no Apple Developer ID, Team ID, trusted
publisher, or notarization ticket. Neither architecture is described as physically
qualified until its exact artifact passes the physical Mac checklist. Automatic
macOS updates are not published.

Release artifacts:

  • Wren-0.1.5.AppImage
  • wren_0.1.5_amd64.deb
  • Wren-Setup-0.1.5-unsigned-x64.exe
  • Wren-0.1.5-macos-x64-unnotarized.dmg
  • Wren-0.1.5-macos-arm64-unnotarized.dmg
  • SHA256SUMS
  • wren.cdx.json

Verify the applicable SHA256SUMS entry and GitHub build and SBOM attestations
before installing. Checksums and attestations bind downloads to the public release
workflow; they do not create a trusted Windows or Apple publisher.

0.1.4

Choose a tag to compare

@github-actions github-actions released this 24 Aug 19:42

Wren 0.1.4

Wren 0.1.4 is an urgent transaction-reliability release. It restores Send on
Base, Base Sepolia, and other recognized OP Stack networks, improves recovery
from transient funding-check failures, and introduces clearly labeled macOS
previews.

Critical transaction fix

  • Wren 0.1.3 could retain every Base or Base Sepolia Send at Funding check
    unavailable
    , regardless of asset or amount. Refreshed OP Stack L1 data fees
    were stored as byte-formatted hexadecimal values, while the final safety
    boundary correctly requires minimal JSON-RPC quantities. Wren now stores
    canonical values such as 0x3e8 and 0x0; native and ERC-20 Sends share the
    corrected path.
  • Nothing was signed or sent when this failure occurred. Existing retained
    requests can be Rechecked after installing 0.1.4.
  • Initial approval now awaits a fresh OP Stack data-fee estimate instead of
    depending on periodic network-update timing. Recheck regenerates a failed zero
    gas estimate when possible, refreshes current fee evidence, and repeats the
    strict funding check. Missing or malformed balance, gas, or L1-fee evidence
    still fails closed.

Transaction queue reliability

  • Queued transactions can now be inspected read-only without changing fees,
    nonces, or token approvals. Once the current transaction is submitted, Wren
    advances review to the next request while continuing confirmation and
    reorganization monitoring in the background. Repeated confirmation updates no
    longer restart completion timing or duplicate activity.

Interface fixes

  • Funding failures show the specific retained reason while keeping the warning,
    message, and Recheck controls in stable positions as feedback changes.
  • The Send screen and Review Send action area now use one continuous Wren panel
    background instead of placing the action in a black section.

Security and release reliability

  • Compiler-version validation is bounded against excessive regular-expression
    work on malformed source-verification input.
  • Release SBOM generation now produces the same source identity on Linux,
    Windows, and macOS.
  • Qualified dependency and GitHub Actions updates are consolidated; incompatible
    standalone major upgrades remain deferred.

Platform boundary

Linux x64 AppImage and deb packages remain Wren's qualified release target.

The Windows x64 installer is an unsigned, unqualified preview. Windows will
show an unknown publisher and may display SmartScreen. Its filename includes
unsigned, and the release workflow requires both the installer and packaged
executable to report NotSigned.

The Intel and Apple Silicon macOS DMGs are unqualified previews. They have
valid ad-hoc code seals but no Apple Developer ID, Team ID, trusted publisher, or
notarization ticket. Gatekeeper should reject the initial launch until the user
explicitly chooses Open Anyway. Neither architecture has been installed or
qualified on a physical Mac by this project. Automatic macOS updates are not
published.

Wren 0.1.4 is designed to pair with Wren Companion 0.1.2 over authenticated
protocol 3.

Release artifacts:

  • Wren-0.1.4.AppImage
  • wren_0.1.4_amd64.deb
  • Wren-Setup-0.1.4-unsigned-x64.exe
  • Wren-0.1.4-macos-x64-unnotarized.dmg
  • Wren-0.1.4-macos-arm64-unnotarized.dmg
  • SHA256SUMS
  • wren.cdx.json

Verify the applicable SHA256SUMS entry and GitHub build and SBOM attestations
before installing. Checksums and attestations bind the downloads to this public
release workflow; they do not create a trusted Windows or Apple publisher.

0.1.3

Choose a tag to compare

@jorphex jorphex released this 22 Aug 16:43

Wren 0.1.3

Wren 0.1.3 adds local wallet creation and contract tools. It also makes
transactions, browser connections, permissions, and restart recovery clearer and
more reliable.

Linux x64 remains the qualified desktop target. This release also includes an
unsigned Windows x64 preview for local testing. The Windows installer uses a
one-click current-user setup and may be shown as an unknown publisher.

New

  • Create an encrypted local wallet with a new 12-word recovery phrase or Ethereum
    private key. Wren uses the operating system's secure random generator, confirms
    the password and backup, shows the secret only during setup, and removes
    unfinished setup data. If you copy the secret, Wren clears it from the clipboard
    after one minute when it is still unchanged.
  • Prepare a contract deployment from complete creation data. Wren simulates the
    deployment, shows it for review, signs it, and sends it once.
  • Publish Solidity or Vyper source for an existing contract or a confirmed Wren
    deployment. Wren accepts common compiler, Foundry, and Hardhat build files and
    checks them against the selected contract. Sourcify is the primary service.
    Etherscan V2 is an optional fallback on supported networks. Published source is
    public and cannot be withdrawn through Wren.

Improved

  • Send now presents assets, contacts, search, networks, token icons, balances,
    addresses, and copy actions consistently. Closing, retrying, queueing,
    replacement, submission, and monitoring states are more predictable.
  • Transaction review stays attached to a submitted transaction instead of
    immediately returning to Requests. If the network does not confirm a
    submission, Wren keeps it visible for checking and does not send it again.
  • Connected Apps now distinguishes current account access from global app
    activity. Per-account revocation uses an explicit consequence review, reliable
    focus recovery, and transient status feedback.
  • Removing a signer now also removes accounts that depend on it. New local-wallet
    and profile-backup passwords use an eight-character minimum. Wren warns about
    easy-to-guess local-wallet passwords and lets you continue after explicit
    confirmation.
  • Network editing has clearer endpoint status, failover information, and
    short-window layouts. Upgraded profiles repair Wren's recognized Companion
    connection so its network list remains available.
  • Earn loads progressively, preserves public product context during partial
    failures, and applies the wallet privacy setting to every account-derived
    balance, amount, position, workflow, and receipt value.
  • Generated-wallet, account-access, deployment, verification, network, Send, and
    signing surfaces have stronger keyboard, screen-reader, focus, scaling, and
    short-height behavior.

Reliability and safety

  • Profiles from Wren 0.1.2 upgrade without resetting encrypted signers,
    permissions, connected apps, networks, contacts, tokens, or activity.
  • Wren saves generated accounts and transaction intent before making them active
    or broadcasting. After a restart, it can distinguish work that never started
    from a submission whose result is still unknown, without sending twice.
  • Access revocation and local-history clearing confirm that profile changes were
    saved before reporting success. If saving fails, Wren clearly says whether the
    change is temporary or uncertain.
  • Account and signer removal is saved before protected signer data is erased. If
    shutdown interrupts cleanup, Wren finishes the confirmed removal after restart.
  • Before source publication, Wren saves the destination and request. After a
    restart, it resumes status checks without publishing the same request again or
    saving source files and API keys in the profile.
  • Dapp chain switching can be approved before account access without silently
    widening account permission. Denial, revocation, expiry, and events remain
    limited to the requesting site and selected account.

Wren 0.1.3 is designed to pair with Wren Companion 0.1.2. Companion 0.1.2 adds
Chrome and Firefox identity switching, BaseScan and Etherscan connection fixes,
tab status, and network-list recovery. The authenticated local protocol remains
version 3.

Release artifacts:

  • Wren-0.1.3.AppImage
  • wren_0.1.3_amd64.deb
  • Wren-Setup-0.1.3-unsigned-x64.exe
  • SHA256SUMS
  • wren.cdx.json

Verify the applicable SHA256SUMS entry and GitHub artifact attestation before
installing. The Windows filename and notes state its unsigned status explicitly;
checksums verify the downloaded bytes but do not create a trusted publisher.

Wren 0.1.2 — Security and reliability update

Choose a tag to compare

@github-actions github-actions released this 19 Aug 14:14

Wren 0.1.2

Wren 0.1.2 is a security, reliability, and wallet-safety update.

Highlights

  • Fails closed if Chromium sandboxing is unavailable or disabled.
  • Tracks canonical transaction receipts and handles chain reorganisations,
    replacements, speed-up transactions, and cancel transactions more safely.
  • Recovers review requests when a transaction or EIP-5792 batch does not have
    enough funding.
  • Adds ERC-7811 asset discovery and a read-only inspector for transactions,
    calldata, EIP-712 data, and supported JSON-RPC requests.
  • Adds optional local dapp guardrails, stronger recipient review, safer native
    Max, and reviewed token/native Sweep calls.
  • Adds optional confirmed-recipient history and stronger OS or hardware signer
    protection.
  • Minimises browser transport identity retained during Companion authentication.

Downloads

This release publishes unsigned Linux x64 packages only:

  • Wren-0.1.2.AppImage
  • wren_0.1.2_amd64.deb
  • SHA256SUMS
  • wren.cdx.json

Verify SHA256SUMS and the GitHub build attestations before installation.

Companion compatibility

Install Wren 0.1.2 before Wren Companion 0.1.1. The pair uses mutually
authenticated protocol 3. Older Wren builds reject the Companion 0.1.1
authentication message.

Release boundary

Wren has not received an independent security audit. Use a backed-up disposable
profile and test accounts before you trust it with valuable assets. Linux
packages are unsigned. macOS, Windows, Linux arm64, native Wayland Glide, and
unlisted hardware combinations are not release-qualified. Simulation, decoded
labels, and guardrails are review evidence. They do not guarantee transaction
safety.

See the repository README, signer and platform support reference, and
qualification checklist for supported behavior and known limitations.

0.1.0

Choose a tag to compare

@github-actions github-actions released this 17 Aug 16:44

Wren 0.1.0

Wren 0.1.0 is the first Wren-branded release: a desktop EVM wallet and
signing firewall for browser dapps and native applications.

Highlights

  • Native transaction and signature review with decoded calldata, configured-RPC
    simulation evidence, typed-data and permit handling, and explicit dangerous
    signing consent.
  • Hardware, encrypted software, and watch-only accounts behind account, method,
    chain, and origin permissions.
  • Per-application chain routing, EIP-6963 browser discovery through Wren
    Companion, and authenticated protocol-3 connections for originless clients.
  • Local contacts, configurable EVM RPC and IPFS endpoints, Frame profile import,
    and a curated Yearn Earn integration.

Downloads

This release publishes unsigned Linux x64 packages only:

  • Wren-0.1.0.AppImage
  • wren_0.1.0_amd64.deb
  • SHA256SUMS
  • wren.cdx.json

Verify SHA256SUMS and the GitHub build attestations before installing. Browser
dapps also require the separately released Wren Companion 0.1.0 extension.

Release boundary

Wren has not received an independent security audit. Use a backed-up disposable
profile and test accounts before trusting it with valuable assets. Linux packages
are unsigned. macOS, Windows, Linux arm64, native Wayland Glide, and unlisted
hardware combinations are not release-qualified. Simulation and decoded labels
are review evidence, not guarantees of transaction safety.

See the repository README, signer/platform support reference, and qualification
checklist for the exact supported boundary and known limitations.