Repository navigation
Releases: kavisara-samarakoon/ghost
Release list
GHOST v0.5.0-alpha — Controlled AI, Voice & Safe Orchestration
GHOST v0.5.0-alpha — Controlled AI, Voice & Safe Orchestration
GHOST v0.5.0-alpha is an alpha prerelease for controlled local dogfooding and testing on Apple Silicon macOS.
This release expands GHOST's human-controlled workflow model with confirmed local actions, advisory AI review, finite orchestration, reviewed voice transcription, and proposal-only intent interpretation.
AI NEVER OWNS EXECUTION AUTHORITY.
USER INTENT → INTERPRET → PREVIEW → EXPLICIT CONFIRMATION → ALLOWLISTED ACTION → AUDIT
Highlights
- Review pending desktop Action Requests with
ghost request list/show. - Explicitly apply an Action Request only after exact
APPLY <request-id>confirmation. - Run finite version-1 local orchestration plans only after full SHA-bound confirmation.
- Request one controlled advisory OpenAI review through the CLI.
- Capture short voice recordings, review them locally, and explicitly consent before transcription.
- Interpret typed text or explicitly selected transcript text as strict AI proposals.
- Save inert M34-compatible plan drafts for later independent CLI review.
- Shared cross-language contracts protect desktop/CLI request and plan compatibility.
- Production CSP, filesystem identity checks, private storage, and audit boundaries were hardened.
Execution authority
The desktop does not execute the GHOST CLI, shell commands, arbitrary processes, Git/GitHub operations, orchestration plans, Action Requests, deployments, merges, tags, or releases.
M32 and M34 are separate CLI execution boundaries and both require fresh exact human confirmation.
AI responses, transcripts, and intent proposals remain untrusted advisory/proposal data.
Network and privacy
Desktop OpenAI access is limited to separately confirmed voice transcription and controlled intent interpretation paths.
CLI M33 separately supports a confirmed advisory Responses API review.
OPENAI_API_KEY comes from process environment and is not stored by GHOST. Native credentials do not reach the React frontend.
Redaction is heuristic. Local workflow records and drafts are plaintext and should not contain secrets.
Validation
Release preparation and exact-tag validation include:
- CLI: 1,145 tests passed
- Ruff passed
- Python wheel and source distribution built
- fresh installed-wheel smoke passed
- Desktop frontend: 137 tests passed
- frontend production build passed
- Native Rust: 133 tests passed
- cargo fmt passed
- cargo check passed
- release-helper suite: 59 tests + 184 subtests passed
- shared contracts: 11 CLI cases + 2 native tests covering all 11 fixtures
- PR CI: 6/6 successful
- post-merge main CI: 6/6 successful
- exact-tag Tauri app and DMG rebuild succeeded
Post-merge main CI run: 37359361492
Release commit:
a70834eb993efc4294f4be65ec0ff5fcc509b7b8
Release asset
Apple Silicon macOS:
GHOST_0.5.0-alpha_aarch64.dmg
Size: 8,882,911 bytes
SHA-256:
b59f1eee64f4046ee69ee717d44464b1a303389f0877ec19b278d4173bd2a624
Checksum sidecar:
GHOST_0.5.0-alpha_aarch64.dmg.sha256
Verify after download with:
shasum -a 256 -c GHOST_0.5.0-alpha_aarch64.dmg.sha256
Known limitations
This remains an alpha prerelease.
- Apple Silicon/current-machine packaging was validated.
- The app is not Developer ID signed.
- The app is not notarized.
- Normal trusted Gatekeeper distribution is therefore not supported.
- Live OpenAI account/provider behavior was not exercised during release preparation.
- Real microphone-to-provider end-to-end behavior was not exercised.
- Normally launched macOS apps may not inherit
OPENAI_API_KEYfrom a shell. - GHOST has no Keychain credential integration.
- Redaction is heuristic.
- Local multi-file workflow operations are not database transactions and interruption may require manual reconciliation.
- There is no automatic GitHub, deployment, merge, tag, or release execution inside the GHOST product.
Do not disable macOS security controls as a normal installation procedure.
This prerelease is intended for owner-controlled/local dogfooding and testing, not production deployment.
GHOST v0.4.0-alpha — Safe Desktop Action Requests
GHOST v0.4.0-alpha — Safe Desktop Action Requests
Published prerelease tag: v0.4.0-alpha.
- Desktop package / Tauri / Cargo:
0.4.0-alpha - CLI package /
ghost version:0.4.0a0 - Target: macOS Apple Silicon (
aarch64)
Summary
This alpha adds a request-only desktop workflow for preparing, reviewing, and explicitly saving pending local Action Requests while preserving the human-controlled GHOST safety boundary.
Saving a request does not execute the GHOST CLI or mutate sessions, notes, outputs, next-step drafts, handoffs, or other workflow records.
Highlights
- Prepare → Review → explicit Save Request workflow.
- Request types:
start_session,add_session_note,generate_next_steps, andcreate_handoff. - Handoff providers: Codex, ChatGPT, Gemini, and Antigravity.
- Recent pending-request metadata is shown in the desktop.
- Request and desktop-audit files use private local permissions.
- Snapshot and search remain read-only.
- Open/Reveal remain explicit allowlisted actions for approved generated artifacts.
- Desktop safety wording now reflects the narrow pending-request write path.
Safety boundaries
- No shell or CLI execution from the desktop.
- No AI or network calls from the desktop.
- Saved Action Requests are pending drafts only.
- No automatic request consumer or executor exists.
- No workflow mutation occurs when a request is saved.
- No automatic GitHub publishing, merging, deployment, tagging, or release operations.
- Any future request consumer must require fresh human confirmation before workflow mutation.
Known limitations
- Browser/static preview mode cannot save requests; native local mode is required.
- Alias validation does not prove that a project or active session exists.
- Goal/note text is limited to 8000 UTF-8 bytes.
- Secret detection is heuristic; secrets should not be entered.
- Recent pending-request display is intentionally bounded.
- A custom
GHOST_HOMEparent must already exist. - Request saving and audit appending are not transactional.
- No execution approval system or request processor is included.
- This macOS alpha is not Apple Developer-signed or notarized.
Validation
- CLI: 331 tests passed.
- Ruff: passed.
- Desktop frontend: 64 tests passed.
- Desktop production build: passed.
- Rust native tests: 49 passed.
cargo check --locked: passed.- Release-helper tests: 27 passed.
- Pull-request CI: 6/6 successful.
- Post-merge main CI: 6/6 successful.
- Tauri release build completed from the exact tagged commit.
- DMG structural verification passed.
- Bundled app identifier and version verified.
- Bundled executable verified as arm64.
- Isolated native dogfood confirmed a pending
generate_next_stepsrequest and audit record without workflow mutation.
Release verification
- Release commit:
fe5380595da50abe88e80314d88dea601dd9e7a9 - Main CI run:
37050115190— successful - Asset:
GHOST_0.4.0-alpha_aarch64.dmg - Size:
7,961,360bytes - SHA256:
fc691e3b24fd70501704134a1e91d470d8e902f3bacce5739ec4535bddc7648c - Checksum sidecar:
GHOST_0.4.0-alpha_aarch64.dmg.sha256
Verify after download:
shasum -a 256 -c GHOST_0.4.0-alpha_aarch64.dmg.sha256This remains an alpha release intended for local dogfooding and is not production-ready.
GHOST v0.3.0-alpha — Local MVP Desktop Checkpoint
GHOST v0.3.0-alpha — Local MVP Desktop Checkpoint
Published prerelease tag: v0.3.0-alpha.
- Desktop package, Tauri config, and Cargo package:
0.3.0-alpha. - CLI package and
ghost version:0.3.0a0(Python's normalized alpha version). - Product name: GHOST. CLI workflow and desktop safety behavior are unchanged.
Summary
This alpha release turns the desktop app into a usable local-first workflow cockpit for
reviewing projects, sessions, memory, and artifacts while preserving strict safety boundaries.
Highlights
- Command Space now acts as a local MVP cockpit.
- Projects Page v1 for reviewing and selecting loaded workspaces.
- Sessions Page v1 for active goals, notes, status, and related work.
- Artifacts Page v1 for reviewing generated drafts and reports.
- Memory Page v1 with explicit-submit local search.
- Read-only desktop snapshots of approved GHOST workflow metadata.
- Safe Open/Reveal actions for approved generated artifacts.
- Improved desktop CI and native safety validation.
- Official branding and a polished dark/cyan GHOST interface.
Safety boundaries
- Desktop remains intentionally read-only for workflow writes.
- No shell execution from desktop.
- No CLI execution from desktop.
- No AI or network calls from desktop.
- No automatic publishing, deployment, merge, or release actions.
- Memory search requires an explicit submit.
- CLI remains the controlled path for creating sessions, outputs, context packs, handoffs,
and update packs.
Known limitations
- Creating or editing workflow data still requires the CLI.
- Desktop refresh may require reopening the app.
- Search results are limited to approved local GHOST memory locations.
- This alpha is intended for local dogfooding, not public production use.
- The macOS app and DMG are not Apple-signed or notarized.
Validation checklist
- CLI tests and Ruff checks.
- Frontend production build and tests.
- Rust native tests and checks.
- Tauri macOS app and DMG package build.
- Main CI after merge.
- Manual native dogfood validation.
Release verification
- Release commit:
80f9a33 - Main CI run:
34708499791completed successfully. - DMG SHA256:
3ae94ed728819d0d5e1c96da6aa309365692624352a2e27f0227ae546083b783
GHOST v0.2.0-alpha
GHOST v0.2.0-alpha
GHOST v0.2.0-alpha is the first runnable desktop alpha checkpoint.
Highlights
- CLI v0.2.0a0 with existing local-first workflow behavior.
- Runnable macOS Tauri desktop app.
- Premium Command Space interface.
- Read-only local GHOST project snapshot.
- Active session and artifact snapshot.
- Safe click-only Open/Reveal actions for allowlisted GHOST artifacts.
- Local bounded .ghost memory search.
- Frontend safety tests in CI.
- Native macOS Tauri/Rust safety tests in CI.
- Desktop build artifact rejection in repository hygiene checks.
Safety status
- No AI API calls.
- No network calls from desktop runtime.
- No shell execution.
- No GHOST CLI execution from desktop.
- No .env reads.
- No source-code search.
- No broad opener permission.
- Snapshot/search/action code remains bounded, allowlisted, and fail-closed.
Build
Included asset:
- GHOST_0.2.0-alpha_aarch64.dmg
This is an unsigned local macOS alpha build for personal testing.
GHOST CLI v0.1.0
GHOST CLI v0.1.0 is the first local-first workflow coordinator MVP.
Highlights:
- Project registry and audit foundation
- Session manager
- Context pack generation
- AI handoff draft generation for Codex, ChatGPT, Gemini, and Antigravity
- Sanitized output logging
- Deterministic next-step drafts
- Review-only update packs
- Read-only doctor readiness checks
- Isolated NEXORA demo workflow
- Version command and release-candidate documentation
- GitHub Actions CI for CLI, release scripts, and repository hygiene
Safety boundaries:
- Local-first and draft-first
- Human approval required
- No AI API calls
- No terminal execution from GHOST CLI
- No GitHub automation inside GHOST CLI
- No .env reads
- Not production automation software yet