Up.computer v0.0.32 (open-source core)
This is the first release built entirely from the open-source repository (MIT).
Task orchestration, browser automation and computer use now live in the public core
and work with every supported agent harness (Claude, Codex, OpenCode, Cursor, Grok).
Highlights
Task orchestration is open source
- Tasks, task agents and automations are part of core: anyone can build and run the full local orchestration.
- Agents start on a task's status and tags. Combinations of tags let several agents work on one task.
- An agent runs again on a task only after a real change to its trigger fields (status, tags, title, description,
notBefore). There are no hidden retries. - Run-status triggers: an agent can start when another agent's run ends as
failed,interruptedorblocked. Use this for your own "doctor" agent. notBeforedelays a task until a given time.agent_run_stopstops a run.agent_run_messagesends a message to any run: an active run gets it as its next turn, and an ended run continues in its own thread with its context.- Closing a task stops its runs.
- The Tasks sidebar entry shows how many agents are working right now.
Instructions you can edit from chat
- Settings → Instructions has an "All chats" field and four task fields: task creation, agent creation, automation creation and task execution.
- Per-project additions are appended to the shared instructions for tasks in that project. Pick the scope with the switcher.
- Agents can read and edit the instructions with
instructions_get/instructions_update. Every change is kept in history and can be reverted (instructions_history/instructions_revert). - Task-agent runs cannot change the shared instructions unless their agent is explicitly allowed to.
- New defaults describe a delegation workflow, and a one-time onboarding offers to set up agents in your first chat.
Browser automation and computer use for every harness
- The
preview_*browser tools can use a managed Chrome when the built-in browser is unavailable, or always if you choose so. - Every harness gets the
computer_*tools through the built-in MCP server.- They are on by default, and Action approvals are off by default.
- Plan and Ask modes can only observe.
- Password managers, Keychain Access and system authentication prompts are blocked. The block matches app names and is best-effort.
- The allowed-apps list now applies only to tools that target an app, so listing apps works with an allowlist.
Other changes
- The Orchestrator composer mode was removed. Existing Orchestrator threads continue in the default mode.
- Settings: one back arrow and consistent titles. On phones the section list matches the desktop sidebar. In a narrow desktop window the header stays clear of the macOS window controls.
- The computer-use sidecar is packaged once (smaller download).
Downloads and validation
- macOS Apple Silicon and Intel: signed and notarized. For Apple Silicon, Gatekeeper acceptance and the stapled ticket were verified on the released build. The same code was tested in local builds: tasks, agent runs, instructions and computer use.
- macOS Intel, Windows x64 and Linux x64: CI builds succeeded; no manual runtime tests for this release.
- The Windows installer is unsigned; Windows SmartScreen may warn or block it.
Known limitations
- The instruction-write restriction for agent runs guards against accidental or injected edits. It is not a security boundary: agents with shell access can edit settings files.
- Blocking credential apps for computer use is best-effort.
- The default "queue" behavior relies on agent instructions. Two chats acting at the same moment can start two tasks for one agent.
Back up important application data before upgrading.