v0.1.0
·
27 commits
to develop
since this release
Immutable
release. Only release title and notes can be modified.
What's Changed
- Add project instructions for Claude Code by @maneja81 in #1
- Add OpenOrbit implementation: Electron app with AI agent orchestration by @maneja81 in #2
- Bump tmp, fast-csv, exceljs (security) by @maneja81 in #5
- Update README for current project state by @maneja81 in #7
- X2: guard settings JSON parsing so one bad row can't wipe the config by @maneja81 in #8
- updated images in readme by @maneja81 in #9
- X8: ignore generated directories in eslint config by @maneja81 in #10
- X6: guard agent_data JSON parsing, sharing the helper with settingsStore by @maneja81 in #11
- X7: stop a corrupt API key row from making migration 27 fail the app's start by @maneja81 in #12
- adding images by @maneja81 in #14
- fixing gitignore by @maneja81 in #15
- X1: validate every settings write against one shared schema by @maneja81 in #16
- X3: validate the numeric settings on read, not just on write by @maneja81 in #17
- S11: stop an agent disabling the approval gate that governs it by @maneja81 in #18
- Add a run-openorbit skill for driving the app, and track skills in git by @maneja81 in #19
- Add a sql command to the run driver by @maneja81 in #20
- S1: give the main process one source of truth for settings defaults (finishes X3) by @maneja81 in #21
- S8: validate the provider URLs, and stop an agent redirecting them by @maneja81 in #22
- Log TTS synthesis failures instead of silently going native by @maneja81 in #23
- S9: stop sending the API keys to the renderer by @maneja81 in #24
- X4: validate settings per key when merging onto defaults (closes S6, S19) by @maneja81 in #25
- S7: leave one declaration of the orchestrator model default per project by @maneja81 in #26
- S16: recover the Danger Zone button when a reset fails by @maneja81 in #27
- Fix tool_output log truncation by @maneja81 in #28
- S22: unwrap IPC errors before deciding what to tell the user by @maneja81 in #29
- Surface real errors on silent TTS playback failures by @maneja81 in #30
- S13: show the orchestrator prompt template, not a rendered snapshot of it by @maneja81 in #31
- S12: bound the settings that get interpolated into system prompts by @maneja81 in #32
- Fix CSP blocking TTS audio playback by @maneja81 in #33
- S10: gather the safety controls into their own Settings section by @maneja81 in #34
- X10: validate the tasks IPC input by @maneja81 in #35
- S3/S4/S5/S2: make the numeric settings enforce the range they advertise by @maneja81 in #36
- X9: guard the remaining JSON column reads by @maneja81 in #37
- S14: detach the orchestrator when a tool it uses is deleted by @maneja81 in #38
- S15: remove the orchestrator's dead enabled-toggle handler by @maneja81 in #39
- S17: let onboarding be run again without wiping the database by @maneja81 in #40
- S18: apply the system-stats interval without a restart by @maneja81 in #41
- S21: warn when a provider URL would send the API key in the clear by @maneja81 in #42
- X5: save the text settings on blur rather than on every keystroke by @maneja81 in #43
- Show the logo at the top of the README by @maneja81 in #44
- Give modals a name, a focus trap, and focus restoration (U1–U4) by @maneja81 in #45
- Stop a mis-aimed click from declining a tool call (U5) by @maneja81 in #47
- Take down an approval prompt that main already answered by @maneja81 in #48
- Fix Browse Registry returning no results for every query by @maneja81 in #49
- Record the worktree base rule and the verify-gate baseline by @maneja81 in #50
- Show how long an approval has before it declines itself (U6) by @maneja81 in #51
- Stop saying good night to someone who's still working by @maneja81 in #52
- Stop a second click queueing a duplicate knowledge operation (U10) by @maneja81 in #53
- Choose an AI provider per slot and per agent by @maneja81 in #54
- Create SECURITY.md for security policy by @maneja81 in #46
- Confirm a delete with Enter in DeleteConfirmModal (U11) by @maneja81 in #55
- Stop agent create, update and delete failing silently (U7, U8, U9) by @maneja81 in #56
- Make the orbit's orbs keyboard reachable (U14) by @maneja81 in #57
- Keep a chat render failure from taking the whole app down (U12) by @maneja81 in #58
- Give the click-to-open chat image a keyboard path (U15) by @maneja81 in #59
- Name args when testTool is given the wrong key (U20) by @maneja81 in #60
- Say so when the onboarding answers didn't save (U13) by @maneja81 in #61
- Re-encode background video and music, cutting 51 MB from the bundle by @maneja81 in #62
- Drop the unused
nodedependency by @maneja81 in #63 - Add GitHub Actions CI workflow by @maneja81 in #64
- Add the app icon source electron-builder needs by @maneja81 in #65
- Add electron-builder packaging config by @maneja81 in #66
- Resolve a blank agent model against that agent's own provider by @maneja81 in #67
- Stop a partial Chat-provider write from resetting the fields it didn't mention by @maneja81 in #68
- Add release workflow for macOS, Windows and Linux by @maneja81 in #69
- Split AI Models into "API keys" and "Default models" by @maneja81 in #70
- Make an agent's model field honest about its provider by @maneja81 in #71
- Fix six defects found by an independent review of this branch by @maneja81 in #72
- Add CHANGELOG.md covering everything before the first release by @maneja81 in #73
- Fix SSRF guard bypassed by redirect (KI-1) by @maneja81 in #74
- Gate agent prompt/connector mutation behind approval (KI-2) by @maneja81 in #75
- Fix getDb() caching a half-migrated handle when migrations throw (KI-3) by @maneja81 in #76
- Gate create_task/update_task behind approval for prompt tasks (KI-4) by @maneja81 in #77
- Handle interruptions in the scheduled task runner (KI-5) by @maneja81 in #78
- Fix unreachable SIGKILL escalation for the search daemon (KI-6) by @maneja81 in #79
- Add error listener to the spawned search daemon (KI-7) by @maneja81 in #80
- Fix daemon start leaking child and poisoning daemonReady (KI-8) by @maneja81 in #81
- Handle daemon startup rejection at the call site (KI-9) by @maneja81 in #82
- Fix OAuth credentials with no expires_in treated as never-expiring (KI-10) by @maneja81 in #83
- Restrict HTTP tool param names to a safe identifier pattern (KI-11) by @maneja81 in #84
- Run the protocol check in testTool even when private hosts are allowed (KI-12) by @maneja81 in #85
- Restrict renderer permission handler to an allowlist (KI-13) by @maneja81 in #86
- Check res.ok before parsing the daemon response body (KI-14) by @maneja81 in #87
- Await an in-flight scheduled task before quitting (KI-15) by @maneja81 in #88
- Remove unused preload IPC channels (KI-16) by @maneja81 in #89
- Add test coverage and a failure path to secretStorage.ts (KI-17, KI-18) by @maneja81 in #90
- Harden the OAuth callback response and token-endpoint errors (KI-20, KI-21) by @maneja81 in #91
- Batch of minor audit cleanups (KI-19, KI-22, KI-23) by @maneja81 in #92
- Document the KI-1..23 audit fixes, and fill in two doc gaps by @maneja81 in #93
- Prepare v0.1.0: dated changelog, release-accurate README, branching rules by @maneja81 in #94
- Release v0.1.0: sync main to develop by @maneja81 in #95
New Contributors
Full Changelog: https://github.com/maneja81/OpenOrbit/commits/v0.1.0