ShellVibe 1.5.0
Added
- The vault has an Environment view beside Identities for the tokens and keys
a shell needs, so they no longer sit in a dotfile in the clear. Each value is
encrypted with the vault key, scoped to the workspace, and synced and backed
up with identities. Every new local tab and split pane starts with the
workspace's variables; a locked vault never holds the shell back — it starts
without them and says so. - Local shells start with
TERM_THEMEset tolightordark, following the
terminal palette rather than the app theme, so CLI tools can pick colors that
read on the terminal's background. - Settings → About → Report a problem opens a GitHub issue with the build and
the recent error log filled in. After a crash, the next launch offers the
same once. Home folders, IP addresses anduser@hostpairs are masked, the
report is shown before anything opens, and the app itself sends nothing.
Fixed
- Numpad digits and operators type as plain text in agent CLIs, such as
Cursor's, that ask for only the kitty keyboard protocol's disambiguate flag;
they inserted private-use characters before. Keypad Enter sends a carriage
return there too. (xterm3 6.3.4) - On a phone, a starred host's overflow menu no longer runs 20px past the
screen edge; the star sits beside the host name instead. - Setting up cloud backup while the server could not be reached stored the new
passphrase anyway. The next scheduled backup then sealed this device's data
under a passphrase no other device had and uploaded it over the account's
backup. Setup now stops and says the server could not be reached. - A cloud backup no longer lands on top of a newer one from another device
without asking. Each upload now names the revision it builds on, so a device
that has not restored another device's later backup gets the "restore first,
or overwrite" choice instead of silently becoming the newest backup. Devices
that have joined automatic sync are unaffected, since they already hold what
the others wrote.
Changed
PRIVACY.mdand the README describe the optional account: what
api.shellvibe.devstores, what it can and cannot read, how long it keeps
it, and how to export or delete it. Both still said there was no account and
no server.
Verifying your download
Every file is listed in SHA256SUMS:
sha256sum -c SHA256SUMS
These builds are not code-signed
There is no code-signing certificate behind this release yet. Your operating
system does not know who built these files, and it will say so. That warning is
accurate: verify the checksums above before you run anything here.
macOS refuses the app outright and reports that it cannot be checked for
malware. To open it anyway:
- Drag ShellVibe to Applications and try to open it once. It will be blocked.
- Open System Settings → Privacy & Security, scroll to Security, and press
Open Anyway next to the ShellVibe message. - Confirm with your password.
macOS 15 removed the old Control-click shortcut, so this is the only route, and
you will repeat it after every update.
Windows shows "Windows protected your PC" with an unknown publisher. Press
More info, then Run anyway. The warning will not fade with time:
reputation accumulates against a certificate, and there is none.
Linux needs nothing special. chmod +x the AppImage and run it.
Signed builds are planned. Until then — if turning off your operating system's
malware protection for an SSH client is not a trade you want to make, which is
a reasonable position — build it yourself instead:
git clone https://github.com/klc/shellvibe && cd shellvibe
flutter build macos --release # or: linux, windows