Releases: m4ttstack/mattstack
Release list
v2.19.0
A team can now turn the worktree pool on for everyone who joins, and intercept shims stay installed without a manual step. Settings writes stop printing a warning-looking line when the daemon will sync them.
Worktree pool
- a team can set
rt.worktreeApp{"enabled":true}to turn the worktree pool on for its members; a member's user or machine setting still overrides it (#594, #596) rt.worktreeAppresolves through the normal settings resolver, sort settings get, the console and the daemon always agree; the pool is on only where a setting saysenabled: true(#596)- answering the Claude hook offer records only that answer, and no longer saves the pool as off (#594)
Setup and settings
- rerunning a single setup step that feeds intercept rules (such as
repos.clone) reinstalls the shims afterwards, and the daemon reinstalls them after a team pull that changes the rules (#595) - a settings write prints nothing when the daemon will sync it; a short note appears only when a change cannot sync (no remote, or sync turned off) (#594)
- a CI guard fails any new code that reads settings layer by layer or opens a settings file directly outside the resolver (#597)
Apps and build
- boxscore caps its page content at 1680px, centred (#593)
- a dev app rebuild writes the app-build and install output into its log, so a failure shows the real error (#598)
Bundled
- gh 2.102.0; the catalog's fast-browser plugin moves to fast-browser main (#599)
Full Changelog: v2.18.0...v2.19.0
v2.18.0
A teammate's first install surfaced a run of setup snags; this release fixes them. Setup finds tools installed off PATH, asks forge and Slack tokens for the scopes the board actually uses, clones big repos reliably, and a fresh install serves deck and opens View Logs on the first try. Boxscore also gets its redesign.
Setup and joining a team
- checklist row actions that run a setup step now answer the prompts that step asks for, so installing the proxy from its row no longer hangs (#579)
- the join note stays readable before Continue, and the Fast Browser row passes the marketplace source to its setup (#577)
- a mattstack marketplace added from the same repo counts as present, and the plugins row shows claude's own error (#578)
- plugins that are already enabled are no longer errors; verify lists accounts still to connect as "to connect" instead of failing; uninstall removes marketplaces by name (#580)
- the Slack account row shows wherever verify needs it (#583)
- team tools installed in
/opt/homebrew/bin,/usr/local/binor~/.local/binare found even under the app's minimal PATH (#584) - repo access rows probe with rt's stored forge token, and offer Connect when there is none (#584)
- a Slack redirect mismatch says exactly which Redirect URL to add to the Slack app (#584)
- the clone step survives big repos, names what failed, and reuses a clone that is already there (#581)
- member GitLab tokens ask for
api, so the board can post reviews (#589) - Slack connect asks for the user scopes the board reads and reacts with (#590)
- clones rt makes keep a remote they can fetch from: rt's token is offered to git only for that forge's host and only when git's own credentials fail, and a clone uses SSH when your key works (#591)
Apps
- boxscore is rebuilt on the app-kit chrome with five metric groups, a person page and evidence panels; its settings move to the console (#573)
- console and chat drop their own app switcher, and board gets the System/Light/Dark control (#573)
- board's default stale window follows each repo's rt sync window, so a fresh install no longer shows the "align configs" banner (#588)
- a bundled deck creates its own record and routes on boot, so
deck.mattstackanswers on a fresh install, and it finds portless, cloudflared and railway off PATH (#586) - View Logs bundles logdy, finds it off PATH, opens exactly one tab, and never opens a dead page (#576)
Release and build
rt release appsreplacesrt release app <name>and releases every served app that changed in one patch, kit changes included (RT-307, #575)- the clean-room walkthrough covers the proxy row and a
joinscenario for joining an existing team (#585)
Bundled
- fast-browser 0.1.9; the catalog's fast-browser plugin moves to match (#587)
- when the bundled fast-browser is in use, rt owns
~/.local/bin/fast-browserand repairs a launcher left pointing at a deleted copy (#582) - glab 1.120.0 (#592)
Full Changelog: v2.17.0...v2.18.0
v2.17.0
Browser runs can sign in to your local dev sites with a saved dev login, the console renders gate context as Markdown, and board's doctors can finally prove a branch has no stacked children.
Dev logins (RT-329)
- save one email and password per dev site in Settings > Dev logins, or with
rt logins add <origin>; passwords are never shown again, and a new site's host must be typed before Save enables (#569) rt logins list,rt logins removeandrt logins open-addmanage them;rt logins addreads values from hidden prompts or--jsonstdin, never argv, echoes an asterisk per password keystroke, and asks for the email in plain text (#569)- Fast Browser fills a saved login on that site's login page through the rt daemon, so a browser run gets past a local login without a human step; the value never reaches the transcript, and fills are limited to one per login every 5 minutes and 5 a day (#569, #571)
- origins must be https, or http on localhost;
mattstack://dev-logins/add?origin=...opens the add sheet (#569) - a saved site's row in Settings > Dev logins reads Edit, and the pane says it can be edited or deleted there (#570)
Board and gates
- board doctors check for stacked children with a live, unscoped read of the open MRs targeting a branch, so an auto-dispatched doctor no longer dead-ends on that check (RT-363, #566)
- answering a review gate from board now dismisses the pane's question form even when herdr's status for the pane has gone stale (#568)
- the console renders gate context as Markdown, and the gate protocol asks agents to write prose context that also reads fine unrendered (#563)
Herds
- shepherdr's
resumestrategy splits intofrom-specandfrom-plan, and job form labels drop the fixed half (#564) herd-progressreads progress for every shepherdr method, pipeline runs included, instead of only SDD ledgers (#565)
Release and build
- the dev app's rebuild and every relaunch (the restart handoff,
rt release update-machine,rt-tray/build.shinstall) run with a clean environment, so a dev app first opened from a shell no longer fails its rebuilds (#570) - the clean-room walkthrough fails a dropped ssh session or an overlong phase with a named reason instead of hanging, and teardown always removes the guest and the throwaway team repo (RT-362, #567)
Bundled
- fast-browser 0.1.8 with runtime 0.1.2: the saved-login fill, the secrets channel, and redaction of every encoded form of a secret; the catalog's fast-browser plugin moves to match (#571)
Full Changelog: v2.16.0...v2.17.0
v2.16.0
The mattstack Claude plugin and herdr-chat now live in this repo, rt drops the commands it no longer needs, and the agents rt launches keep their prompts out of ps.
Monorepo
- the
mattstackClaude plugin moves into this repo (plugins/mattstack, now 0.28.4); the marketplace catalog serves it in-tree instead of pinningm4ttstack/skills(#538, #539) - the herdr chat plugin moves into this repo (
plugins/herdr-chat) (#537) - the Sparkle feed, release constants, scripts and docs name
m4ttstack/mattstack(#534) - mattstack.app ships gitq's five agent skills (absorb, publish, restructure, sync, track) alongside deck's and board's (#535, #536)
- CI certifies the plugin's skills, dry-runs its compile, and fails on process-digraph warnings (#542, #544, #547)
Commands
rt update,rt commit,rt git commitandrt mr mapare removedrt versionfolds intort --versionrt chatandrt uninstallare hidden by default, and the verbs the apps, skills and daemon run no longer appear in the picker or help; onert.picker.hiddensetting lists what is hidden and replacesrt.picker.showandrt.picker.hide(#545, #549)rt settingsshows only its store verbs in the picker- command descriptions use plain language
rt hooksshows one checklist where ticked means the hook runs, marks hooks that are off[disabled], and says when a hook is skippedrt ci lease(claim, heartbeat, release, show) and a CI watch loop give each MR one CI attendant at a time, run over MCP tools with no Bash call (RT-331, #525)rt skills expandpastes mattstack attachments into hand-written skills; board's skills now carry the gate protocol this way (RT-358, #546)rt glitterpulls with GitHub Desktop's divergent-branch default:--ffunlesspull.ffis set
Agents and herds
- rt keeps agent prompts out of process argv: pane launches read the prompt from an owner-only file, and headless launches take it on stdin (#528)
- herd briefs name the shepherd by its chat handle and id, and the watchdog's background-work exemption expires after 60 minutes (RT-356, RT-359, #556)
- the herd watchdog stops nagging "done, not closed" while a follow-up round is live, and gate pushes no longer interrupt herd workers with an Escape (RT-355, RT-357, #543)
- a
herd-progressskill renders a shepherd's/progressas one table (#553) - shepherdr's fence check counts a job's committed work (#557)
- ship and stage-ship budget every loop, stage-ship's rebase aborts, and receive-review executes a handed plan (#552)
- the rt, gitq, deck and board skills gain process digraphs with bounded loops and gates (RT-341, #531, #532, #533, #541, #548)
mr_uploadaccepts a run's own evidence folder (#550)
Board
- MR cards link their
!iid(GitLab) or#iid(GitHub) to the forge page - review findings cap body and fix lines at 100 characters, set their folders back, and lead each fix with an arrow
- review and respond escalations park and resume like doctor's, a resumed review never posts twice, and a resumed doctor waits out its own old CI lease (#554)
- answering a herd-owned gate from board or the console goes through as a recorded human override instead of failing (#561)
Deck and console
- in mattstack-dev, a row's deploy button becomes an amber Redeploy pill when its checkout has new code for that app (#559)
- deck's command runs use your own bun ahead of the bundle's, so dev builds and Redeploy work inside mattstack.app (RT-352, #530)
- every expanded setting in the console switches between its editor and JSON with one Form | JSON toggle (#555)
- the console shows long string lists as wrapping tags, and its JSON editor resizes by dragging (#551)
Setup, worktrees and chat
repos.clonerecognizes an existing clone by its normalized origin, not a substring (RT-360, #558)- worktree pool names are handed out in order, so a freed name waits its turn (RT-345, #526)
- a new chat session's sign-in releases its pane from earlier sessions' rows (#529)
- a solo install's Done screen stays solo after the Full Disk Access relaunch, instead of offering Open the board and Invite teammates (RT-328, #527)
Release and build
rt release update-machineretries its #rt announce while the relaunched daemon comes back (#540)- the dev-app rebuild's turbo cache works outside a git checkout, which clears mattstack-dev's "build failed" badge (#560)
- the clean-room VM gains a solo leg (RT-328, #527)
Bundled
- fast-browser 0.1.7: browser-driver fills flow arg placeholders, and the flow runner treats an in-flight mutating step as possibly landed; the catalog's fast-browser plugin moves to match (#562)
Full Changelog: v2.15.0...v2.16.0
v2.15.0
mattstack.app can now be set up for one person with no team, rt can move a repo's stored state to a new name ahead of the repo's rename to mattstack, and every chat session gets a hidden identity behind its handle.
Just me setup (RT-328)
- a Just me card on the Team screen installs mattstack.app for one person: no team repo, no access rows, and team-only apps such as board stay off (#523, #520)
- Settings > Apps lists every app with a toggle and a "Needs a team" caption on a solo install;
rt apps list,rt apps enableandrt apps disableare the same switches from the CLI (#523, #520) - Settings > Team on a solo install offers Create a team and Join a team, which re-enter setup at the Team step and turn team apps back on (#523)
rt team statusreportsmode: "solo"when no team clone exists (#520)- deck reads
requiresTeamfrom each app's manifest and can idle any app: a disabled app leaves the launcher and its launch agent is uninstalled until it is re-enabled (#517)
Repo rename groundwork
rt repos reidentify <old> <new>moves every store rt keys by repo identity (the repo index, worktree registry and data dir, tracking, the events cursor, state.db tables, herds, editor prefs andrepos.<id>settings sections) from one remote identity to another. Each store reports moved, already, none or refused; a refusal in one store never stops the others;--dry-runshows the counts first (#524)- the daemon runs the same move on its own when a tracked repo's remote now derives a new GitHub identity and GitHub confirms the old name redirects to it (#524)
- the shared checkout resolves
~/Documents/GitHub/mattstackfirst and falls back to~/Documents/GitHub/repo-tools, so a machine keeps working before and after the folder moves (#524)
Chat
- every session gets a hidden identity id behind its display name, so a recycled name never inherits another agent's rooms, DMs, unread or history; existing handles keep their rows (#521)
rt chat sign-in --as <name or id>continues an identity and--name <name>starts a fresh one; the agent name pool grows to 1,000 (#521)
Settings
- eleven per-repo keys (
rt.roles,rt.worktrees,rt.hooks,rt.syncand others) refuse a global value instead of applying it to every repo;rt settings checkreports a stray one (#518) - the VS Code extension now reads repo sections for the open repo, and console's effective-inputs panel reads the run's own repo (#518)
Glance and gitq
- the group dashboard rides one shared cable instead of a watcher per MR, a late MR joins the group's push, and a single MR dashboard follows the cable's connection state (#519)
GitHubEventsPollercommits its tick state only after a full tick (#519)gitq undomoves refs by compare-and-swap, never by checkout, checks for holding worktrees first, and resumes a partial undo (#519)
Also
- MCP git tools accept a hand-made git worktree of a registered repo, such as
<checkout>/.worktrees/<name>, and still refuse its subdirectories (#522) - the VS Code extension bundle is load-checked in the release (#519)
- glitter's hovered tab button has symmetric padding (#514)
@mattstack/glance-reactis private; it no longer publishes to npm (#516)- the marketplace catalog ships the current
mattstackplugin (RT-338 wave 1, 0.26.1) and fast-browser plugin
Full Changelog: v2.14.0...v2.15.0
v2.14.0
One repo now builds the whole suite: the apps, glance and gitq were folded into rt with their history, so mattstack.app ships board, console, chat, boxscore, deck and gitq from the tagged commit. Agents reach rt through MCP tools instead of Bash for MRs, runs, worktrees, herds and chat, with credentials redacted from every result.
Monorepo
- m4ttstack/apps, m4ttstack/glance and m4ttstack/gitq live in this repo as
apps/*,packages/*andapps/gitq, imported as merge commits with full history; the old repos are read-only from here on (#489, #499, #502) - rt-client, settings-kit and tui-kit are private workspace packages built by the root install; nothing publishes them anymore
- the release builds every bundled app from the tagged commit (
scripts/build-apps.ts), so an app change merged to main is in the next release by construction; only fast-browser stays a pinned download @mattstack/glance,@mattstack/glance-reactand@mattstack/gitqstill publish to npm on demand from their directories; gitq's release tagsgitq-v<version>and refuses a workspace dependency whose version is not on npmrt release app <name>cuts a patch release for one bundled app when the diff stays inside that app, the notes and the website (#464, #469)
MCP tools (RT-326)
- MR tools cover reads and writes on GitLab:
mr_view,mr_list,mr_threads,mr_pipeline,mr_job_trace,mr_for_branch,mr_create,mr_update,mr_upload,mr_comment,mr_comment_inline,mr_reply_thread,mr_resolve_thread,mr_approve,mr_ready,mr_rebase,mr_retry,mr_mapandmr_merge, so board posting no longer waits on the Bash classifier (#472, #478, #485, #491) run_*tools start, stage, snapshot and answer decision runs (#488);worktree_provision,worktree_disposeandworktree_stop_holdersplus theherd_*tools drive worktrees and herds, andrt_verbexposes a wider curated verb set (#497)- guarded git tools
git_push,git_pull,git_rebaseandbranch_sync; a push whose upstream targets main, master or the remote default is refused (#492) chat_*tools mirror every rt chat verb, and a daemon-signed-in session gets a chat session file so its tools answer with its own handle (#501, #504)- every tool result passes through credential redaction, so a token in an avatar URL or remote never reaches a transcript; enrich also strips userinfo from https remotes (#500, #482)
- the daemon auto-accepts Claude Code's relocation prompt for announced attended panes (#490)
- the mattstack skills for chat, worktrees and herdr-inject run on these tools instead of Bash;
rt skillslists a pack's MCP tools,check --strictlints them with derived rules and a pack script scan, and an advisory audit flags Bash where a tool exists (#493, #505, #507, #513) - base Claude permissions drop the glab and
rt runsrules and add the Monitor waits; the gate rule stays (#487)
Settings
- every key has a schema, writes are validated,
rt settings checkverifies the real stores, and a schema lock guards breaking changes between releases (#474) - versioned store names with migrations and drift detection, so a key can change shape without stranding an older app (#484)
rt.mcp.uploadRootswidens wheremr_uploadmay read from (#479)- test runs refuse to write the account's real stores (#468)
Glitter
- opens any repo without registering it (#509)
- the mouse wheel scrolls the view, not the selection (#510)
- a diff line taller than the pane scrolls row by row, and a file-to-symlink typechange parses both diff blocks (#459, #454)
- the master row hides its glyph when there are no changes, and the sidebar's tab pad and gap rows collapse
Herd
- worker trees are pre-trusted for every account, and rendered briefs drop author-note blocks (#511, #512)
- herd ask option labels are capped at 60 characters so a gate never waits on an overlong form (#495)
- panes keep a real title:
rt agentno longer passes--name, and pane rename drops the--herdr keeps in the label (#471) - a gate can supply its own notification headline and summary (#465)
Tray
- Discard New Build keeps the build cached instead of wasting it (#483)
- each badged gate counts once in the dock, and badge fetches use their own connection per app host (#467, #466)
- review changes opens in its own window, and rows stay busy until the list refresh lands (#458)
Worktrees and MRs
- one containment rule for triage and dispose checks every tip, and the panel stops polling when closed (#470)
- dispose accepts a HEAD already in main over a stale
origin/<branch>(#460) - an unsynced MR's discussions are stored instead of throwing (#486)
Docs
- rt.cool, install, onboarding and teams follow the mattstack.app setup flow and state current behaviour only (#461)
- skills tell sessions to run
/reload-pluginsafter a sync or init instead of restarting (#496)
CI
- the unit suite runs as three balanced shards and a PR runs only its changed tests plus the guard tests; a go job runs beside static with runner-measured timings; superseded PR runs are cancelled (#475, #480, #457)
- test hygiene: a test that leaves
process.exitCodeset fails on its own, HOME stays valid across files, daemon-logger and shutdown tests are order-independent, and leftover Go module caches are swept (#473, #462, #463, #453) - the dev app stage always reconciles the copied deps against deps.lock (#455)
Board 0.1.8
- approved means GitLab says approved (#160)
- a respond gate's row counts its threads and the status word clamps; an answered gate leaves the decision queue right away (#162)
- notifications link to the MR's row and read in plain words (#163)
- badges report the gate ids they count, so a run gate is never double-counted against console, and a gate settled during a relay gap stops counting (#164)
- board and deck share one decision-gate helper, and deck's own row shows its service (#165)
- doctor's retry and rebase go through rt's MR tools instead of
glab ci retry(#167)
Console 0.1.4
- JSON editors for every settings row and explain layer, a per-repo view with a repo picker, and a Needs fixing flow for diverged or unregistered keys, now working across repos with diverged scalars handled (#169, #494, #498)
- the installed-caches chip says to run
/reload-pluginsin running sessions instead of restarting them (#496) - the gate-count endpoint returns the counted gate ids so the tray can dedupe against board (#164)
Deck 1.1.2
- removing a route-only row clears its routes, and board shows remove failures (#161)
gitq
- the bundled CLI moves from the 0.2.1 binary to the tree: cascades record and use a per-node fork point,
continuekeeps the resumed branch's store update and records the fork point against the final target, preflight warns when a child's fork point is unrecoverable, and the rebase engine refuses a doomed sweep instead of conflicting through it - transient watchman cookies no longer count as a dirty tree
gitq abortfalls back to the leased slot when no pause file survives and only aborts a rebase that is in progress there; the board's action endpoint refuses a non-local Origin, a non-JSON body and an untracked stack (#502)- repos.json keys are forwarded unchanged as identities, matching rt-client's identity-keyed lookups
Boxscore and chat ship unchanged apart from boxscore's settings page taking its composite editors from the schema (#169).
Full Changelog: v2.13.1...v2.14.0
v2.13.1
A follow-up to 2.13.0: Sparkle updates install on the first click, and deck's Add app registers an app from its manifest.
Updates
- "Install and Relaunch" now installs on the first click even with the mattstack window open. The window-close quit interception used to cancel Sparkle's quit, so the app only closed its window and the install waited for another click; Sparkle's own installer is now let through while an install is running (RT-296, #451). Updating to 2.13.1 from 2.13.0 or earlier still goes through the old app's code, so if the window only closes, click Install and Relaunch again.
Deck 1.1.1
- Add app asks for the app's directory and registers it from its
mattstack.deck.json, the same asdeck register --dir(port, start command, env, action commands, name and icon); a directory without a manifest falls back to name, command and working directory (RT-297, #452) - Add app never changes an app that is already registered: it reports "already registered" instead of relinking or restarting it
- the route-only "I run this myself" option is gone from Add app
- a relative or missing directory is refused before anything registers,
deck register --dirresolves a relative path, and typing in the form no longer jumps focus back to the Name field
Glitter
- the diff pane tints added and removed rows, highlights whole files so multi-line comments and markdown headings color correctly, and soft-wraps long lines (#443)
Full Changelog: v2.13.0...v2.13.1
v2.13.0
The prod-readiness release. Opening mattstack.app on a Mac that had been running mattstack-dev now serves every bundled app on the first launch, a daemon launchd refuses to start heals itself, boxscore ships in the bundle, the window waits for deck instead of showing a 502, and setup stops registering apps one by one.
Bundled apps
- deck 1.1.0 serves exactly the apps the bundle ships: on every start its sweep creates, adopts or fixes the rows for board, chat, console and boxscore, creates each app's data directory, and stops serving (without deleting) anything else, so switching between mattstack and mattstack-dev never destroys the other flavor's registrations (RT-280, RT-281, RT-284, #448)
- the gitq CLI still ships and stays on your PATH; the gitq web app is no longer served by mattstack.app (RT-281, #448)
- boxscore 0.1.0 is bundled for the first time (RT-282, #448)
- board, chat 0.1.3 and console 0.1.3 carry their name and icon inside the bundle, so tabs are labelled on a clean install (#445, #448)
- board 0.1.7 shows a "Board isn't set up yet" page until your team's board settings exist, instead of restarting in a loop, and switches to the real board on its own once they do (#450)
rt-tray/deps.lockrows can declareserve: { port, args }; a row with it is a bundled app, a row without it is a tool (#442)
Tray
- the window holds its splash until deck answers and the app list has loaded, up to 90 seconds, then shows "Can't reach deck" with the reason and a Retry button (RT-283, #446)
- a tab whose app answers a server error shows the failure overlay with a working Retry instead of a blank 502 page (RT-283, #446)
- a daemon or deck that launchd refuses to start ("alive but not serving", exit 78) is healed once at launch with a clean unregister and register (RT-279, #449)
- re-registering a launch agent waits for launchd to drop the old job before registering again, and the app records an agent as set up only after it answers (RT-279, #449)
- a version change no longer force-restarts agents registered on the same launch, which removes the ~30 second gap before deck answered; served apps restart once, after deck is up (RT-283, #449)
Setup and uninstall
rt setupno longer registers board, chat, console or gitq itself; deck's sweep does it on both flavors (RT-281, RT-284, #444)rt uninstallrejects arguments it does not recognise instead of running a full uninstall, and removes mattstack's apps from deck in one call (#444)
Developer tooling
- the clean-room VM check now fails unless deck serves exactly the bundle's apps, each healthy with its icon, and checks every
.mattstackroute (RT-284, #447) - the dev app's build cache drops builds whose worktree is gone (#437)
rt release update-machineaccepts a daemon running a later main that contains the release (#438)- the repo purity gate judges only commit messages a push would publish, with tests for the new range (#439, #441)
@mattstack/glance0.27.0 (#440)- glitter's guarded branch header reads "checked out in another worktree" with a padlock glyph
Full Changelog: v2.12.0...v2.13.0
v2.12.0
The worktree triage and updater release. A new tray panel handles the worktrees left behind after a merge, connecting a forge links you straight to a token with the right scopes, and the app's updater moves to Sparkle 2.10.0.
Tray and setup
- Worktrees… panel: every worktree left behind after its merge request merged, why it is stuck, whether its work is safe elsewhere, and one guarded action per row (dispose, keep, push the branch, review the diff, stop holders, or remove to the 14-day trash); the menu item carries a count and a daily summary notification opens the panel (#429)
rt worktree triage [--repo] [--json]prints the same rows in the terminal (#429)- dispose now accepts a branch that was rebased into its merged MR (RT-271, #429)
- the Connect sheet links to the forge's new-token page with rt's scopes pre-checked; GitLab owners are now asked for
api, and a stored token missing a scope reads invalid and names it (RT-276, #433)
Updates
- Sparkle 2.10.0: fixes temp-file leaks when a delta update fails and re-applies filesystem compression after delta updates on macOS 27; tested both ways in the VM, from 2.11.0's Sparkle 2.9.6 and from the new updater itself (#434)
Developer tooling
- the dev app caches builds per worktree, so switching back to a tree you already built is instant (#435)
rt cd's background branch-cache refresh runs in its own session, so a pane reads idle 10 to 15 seconds sooner afterrt cd(#436)rt release update-machinereadsdeck list's real table through the serving bundle's own deck, and fails closed when deck lists no managed apps (RT-274, #430)- the release workflow caches its dependency downloads, so an upstream outage no longer fails a release that has built before (#432)
- the VM walkthrough dismisses Setup Assistant after boot, and its update leg accepts the
v-prefixed version CI stamps into rt (#428, #434)
Documentation
- a Glitter guide on rt.cool covering the board, the checkbox staging model, stash, history, menus, and every key (#431)
- the tray guide covers the Worktrees panel, and the install page lists the token scopes each forge and role needs
Full Changelog: v2.11.0...v2.12.0
v2.11.0
the onboarding and agent-tools release. A new teammate reaches Install without a terminal, picks a writing style, and gets a checklist that re-checks in about 3 seconds. Agents get a curated MCP door into rt, and rt glitter grows into a GitHub Desktop style git client.
Setup and onboarding
- onboarding UI pass over every wizard screen: team cards, checklist rows, install progress that scrolls to the running step, Done, and the connect sheet (#377)
- writing style: a
skills.writingStylesetting,rt skills writing-style show | list | use | new, and a setup row that Finish requires and that cannot be skipped, with a picker of the mattstack plugin's presets (#387) - Install now installs and enables the superpowers plugin; existing installs pick it up from the plugins row's one-click install (#373)
rt team joinpoints a joiner's board at the team's switchboard, and a joiner reaches Install without a terminal when the team declares one (#373, #393)rt home remote set <url>gives the home repo a remote from setup; the inviter is notified when an invitee replies; the Slack connect error names the real cause (#417)- Install seeds Claude Code's
permissions.defaultMode: autowhen a config dir has none, so Enterprise and Console-key sessions stop prompting for routine git (#396) - the baseline Claude permissions allow
rt runsandrt gate, so pipeline skills stop prompting in unattended panes (#395) - checklist refresh drops from about 14s to about 3s: the Fast Browser rows ask
fast-browser doctorfor only the four checks they read (#407) - a Chrome Web Store install of the Fast Browser extension now reads ready, and a failing extension row shows doctor's own fix (#407)
- Settings > Fast Browser joins a checklist load already running instead of starting a second one (#406)
- the team screen's restore card is hidden until
rt restoreexists (#414)
Agents, gates and MCP
rt_verb: a new MCP tool in the mattstack plugin that runs a curated set of agent-safe rt verbs (#378)- security: compiled rt no longer loads a
bunfig.tomlpreload or a.envfrom the caller's working directory (#378) - the AskUserQuestion hook asks the daemon via
rt gate fork-check, so a pane's own run gate can be asked as a form (#391) - unattended panes accept Claude Code's worktree relocation prompt in its current drawing instead of stalling (#394)
- injecting into a Claude pane sets aside anything already typed and restores it afterwards (#408)
- gate notifications: a click opens the surface first (#362), pane-started work returns to its pane (#366), and pane-bound clicks no longer flash the shell window (#369)
- herd escalations collapse into one summary per herd that focuses the shepherd (#388)
rt herd spawnandrt agent startdefault--accountto the caller's cswap account (#367)rt skills initscaffolds a team's first skills pack, andrt skills bindwrites the pack's own fragment (#401)
Git client (rt glitter)
- a GitHub Desktop style board: changes, commit, branches, worktrees and the action segment, built to the design boards (#346, #353, #354)
- History tab (#383), stash with GitHub Desktop's own markers (#399), right-click and ctrl-k context menu (#389)
- live status for the current worktree and animated spinners (#400), hover on every interactive region (#360)
- create branches and provision worktrees from the foldouts, and list worktrees git knows about beyond rt's registry (#357, #365, #368)
- publish a repository with no remote through
gh(#420) - polish and follow-ups (#363, #405), plus a whole-binary pty test gate (#356, #392)
Worktrees
- on-deck worktrees build by cloning a golden donor's installed artifacts instead of a cold install, on replenish and on provision (#359, #364, #370, #371)
- merged worktrees stranded by herds and orphans are disposed (#410)
- missing GitHub tokens and untracked repos no longer silently disable PR state and merge cleanup; rt falls back to the
ghsession (#382) - the
rt cdpicker groups worktrees by recency and hides disposable trees
Daemon and project sync
- daemon restarts are pid-verified end to end instead of reporting success early (#361)
- project sync failures are reported to the board (#374), merged and closed MRs come from the index (#375), and
rt.ignoredMrskeeps deploy-branch MRs out of sync (#381)
mattstack.app and the dev app
- tab and dock badges for decisions waiting on you (#398)
- dev mode is retired: whoever launches a process sets its flavor, and the app you opened last is the active one (#418); launch agents re-register when their shipped plist changes (#419)
- a hand-installed deck agent is retired on flavor handoff and cleared before the prod deck helper registers (#380, #384)
- the board's scrollbar gutter no longer renders as a black strip (#355)
- the dev app runs deck from a linked checkout (#402) and can rebuild and restart itself from the tray (#411, #403, #404, #421)
- the tray asks flock to focus a pane when flock is running
rt run's queued launches open a seeded runner board (#390), and the runner board claims the mouse (#412)
Bundled apps
- board 0.1.5: every gate opens the two-column gate sheet, structured review gates with a full-screen decision queue, edit a drafted reply before it posts, merge refusal reasons, the freshness banner names rt's sync failure, and BOARD-48, BOARD-47 and SKILLS-76 fixes (#427)
- console 0.1.2: one grouped, filterable settings page with explain as a modal, the member-joined notification toggle, and unset notification toggles read on, matching what the daemon sends (#426, #427)
- chat 0.1.2: the Radix colour system and one type ladder (#427)
- deck 1.0.7 (was 1.0.5): the bundle helper owns deck, deploy restarts a source-run deck in the dev app, and app badges reach the shell (#385, #413)
- fast-browser 0.1.5 (was 0.1.3):
doctor --checks, and Web Store installs passextension-installed(#407) - every app artifact is now signed with the Developer ID certificate under a stable identifier, so TCC grants survive updates (#347)
Plugins and tools
- plugin catalog: mattstack 0.20.0 (pack authoring, writing-style presets, Hold at Gate 2 posts nothing) and fast-browser at 0.1.5 (#425)
- bundled tools: age 1.3.2, gh 2.101.0, glab 1.119.0, node 24.21.0, cloudflared 2026.9.3 (#425); Sparkle stays at 2.9.6 for its own release
- release and VM scripts' existence guards no longer invert under pipefail (#425)
@mattstack/rt-client0.31.1 and@mattstack/settings-kit0.3.0 (#374, #376, #379, #422, #424, #426)
Release tooling
rt release preflight,rt release verifyandrt release update-machineturn the release checklist's mechanical steps into verbs (#350, #351, #352)rt-tray/vm/run/gatekeeper-check.sh: a clean-room Gatekeeper assessment for any signed app (#358)
Full Changelog: v2.10.2...v2.11.0