Skip to content

Releases: noctcore/nightcore

Nightcore v0.5.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 12:09
2e979e4

Nightcore v0.5.0: maintenance mode. 19 commits since v0.4.0.

I have moved Nightcore to maintenance mode. From here it gets dependency and security updates and fixes to what already exists, not new features. This release does the first round of that: it lands the whole dependency backlog, updates the Claude SDK and model list, and removes Council.

Auto-update from v0.4.0 works as before. The updater signing key is unchanged.


Highlights

  • Council is removed. The multi-agent debate board, its presets, canvas and write-capable Build stage are gone, about 19,000 lines across the web app, Rust core, engine and contracts.
  • Current Claude models. The Claude Agent SDK moves from 0.3.190 to 0.3.282, and the built-in model list is now Opus 5.5 (default), Sonnet 5, Haiku 4.5 and Fable 5.1.
  • Dependencies are current and both audits are clean with no exceptions. TypeScript 6, vitest 4, vite 8, Storybook 10, Tauri 2.12.

Removed

Council

Council shipped in v0.4.0 and was never driven end to end by hand. Carrying a feature that size in a project I am only maintaining was not worth it, so it is removed rather than hidden.

  • The Council view and its nav entry are gone. Nothing else in the app changes.
  • No Council state was ever written to disk, so existing settings and projects load unchanged.
  • The wire contracts lose the debate events, the council commands and presets, the nc:debate channel, and the resolve-worktree-op / worktree-op-required pair that only the Council build driver used.

The two design documents under docs/research stay as a record.

What's New

Claude SDK 0.3.282 and the current model catalog

The model picker has always read its list live from the SDK, so the SDK bump alone brings in the current models. The built-in list, which supplies the default model and the fallback when the live list is unavailable, was a generation behind and is updated to match.

  • A new install defaults to Opus 5.5.
  • A model id already stored in your settings (for example claude-opus-4-8) is not rewritten. It is still sent to the SDK exactly as stored, so pick a current model in Settings if you want to move.
  • A task that ran on an older model is labelled with the current model of the same family in the UI.

Lint-meta: async rules and a generated rule catalog

Lint-meta rules can now be asynchronous, and the harness can generate a rule catalog document from a rule registry and check it for drift. The portable runner @noctcore/harness is at v0.3.0 on npm, now published with npm trusted publishing instead of a long-lived token.

Conductor-mediated human input (removed with Council)

Human input to Council seats landed after v0.4.0 and left again with Council in this release. Listed here only so the history adds up.

Bug Fixes

  • A lint run where a rule crashed no longer reads as clean. When a rule threw, the output still ended with "lint-meta: no violations". It now ends with an INCOMPLETE line naming how many rules threw, and any throwing rule fails the run.
  • ctx.glob returns files only. It also returned directories, and a directory named like a file (vitest names its image snapshot directories <name>.test.tsx) made rules that glob then read throw EISDIR.
  • Lint-meta can see dot-directories. The glob skipped every dot-directory, so a rule over .github/workflows matched nothing and passed forever.
  • Tests and local runs boot the sidecar built for this machine. The lookup took the first sidecar binary it found, so a stale binary for another architecture could be picked up.

Under the Hood

  • A CI gate now exercises the live contract between the sidecar and the Rust core.
  • Architecture seams in the contracts package were consolidated, and baseUrl was dropped from the web tsconfig.
  • The repo is down to zero open issues. Roadmap and feature tickets were closed as not planned.

Dependencies

  • TypeScript 5.9 to 6.0.3 (TypeScript 7 is still blocked on the declaration toolchain)
  • vitest 3 to 4.1.11, with the browser provider moved to @vitest/browser-playwright
  • vite 7 to 8 (Rolldown), with plugin-react 5.2
  • Storybook 9 to 10
  • Tauri 2.11 to 2.12
  • Claude Agent SDK 0.3.190 to 0.3.282
  • bun audit and cargo audit both pass with empty ignore lists. The vitest advisory GHSA-82fw-gwwq-j7x9 and the quick-xml advisories are resolved by real upgrades, not exceptions.

Known limitations

  • Usage cost figures are not re-verified for the new models. Rates are matched by model family and were not checked against Opus 5.5, Sonnet 5 or Fable 5.1. Fable has no price entry, so it reports tokens only.
  • macOS terminals still use the DOM renderer. GPU rendering stays off on macOS until the upstream xterm.js fix reaches a stable release.
  • The Windows terminal daemon still has no named-pipe parity. This is no longer planned.
  • marked stays on 15.x. The 18.x upgrade is a real migration in the sanitizer path and is not done.
  • The Codex SDK was not updated in this release.

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 31 Jul 13:39
49f3e51

Nightcore v0.4.0 — conformance and the platform play. 138 commits since v0.3.0.

This release is mostly about making the guardrails real: things that claimed to be enforced are now provably enforced, and several that turned out to be enforcing nothing were fixed.


⚠️ The project moved to the noctcore organization

Since v0.3.0 this repository moved from Shironex/nightcore to noctcore/nightcore.

If you are running v0.3.0, auto-update still works — no action needed. Verified for this release:

  • v0.3.0 shipped its updater endpoint as https://github.com/Shironex/nightcore/releases/latest/download/latest.json. GitHub's repository-transfer redirect still resolves that URL to the new location, and the updater follows it.
  • The updater signing key is unchanged from v0.3.0, so existing installs can verify this release's signature. (A rotated key would have silently bricked the update path for every existing client.)

If you contribute, update your remote:

git remote set-url origin https://github.com/noctcore/nightcore.git

Operational note for maintainers: the redirect from the old path survives only while nothing occupies it. Creating a repository named nightcore under the old personal account would break latest.json resolution for every v0.3.0 client still on the shipped endpoint. Don't.

The portable Structure-Lock runner is published under the same org as @noctcore/harness (now v0.2.0 on npm, with SLSA provenance).


Council — governed multi-agent debate

A full debate board: a Conductor stage/turn state machine, a moderated nc:debate bus with an append-only transcript, presets as data (Research, Coding, UI-bug), a React-Flow canvas with editable routing edges, broadcast collection with quorum/timeout, judge-agent + vote convergence, a no-progress stall detector, an adversarial Review stage, and an objective gate that acts as terminal judge — a failing gate overrides consensus.

Council now writes code: a single-writer Build stage on an isolated worktree, driven through a path-less RPC to the Rust worktree seam so it reuses the existing confinement rather than inventing a second path.

Governance and containment

  • Native OS sandbox adopted — the SDK's Options.sandbox replaces ~840 lines of custom Seatbelt writing, with the PreToolUse gate kept because the two cover disjoint surfaces. Staged default-on for macOS worktrees with a tri-state opt-out (Auto / Always / Never) that never flips an explicit "off". When the sandbox is unavailable the run is loud about it — a warning, a ledger marker, and a badge — rather than silently continuing unconfined.
  • Per-project governance journal — an append-only .nightcore/ledger/project.ndjson recording policy saves, quarantines, arm/disarm and ratchet snapshots, with a trust summary computed on demand (so it cannot drift from the journal) and a shields-compatible badge export.
  • Policy UX — edit-time regex/glob validation, a pattern tester wired to the same matcher that enforces, RepoProfile-keyed starter packs, and a live denial feed. A typo'd rule used to silently neither match nor error.
  • Review calibration — the reviewer's verdict is now clamped to a mechanical band derived from finding severities, with fuzzy cross-lens corroboration used for ranking only. Posting to GitHub always requires an explicit human confirmation.

Scans and conformance

  • Insight run-over-run delta — "apparent new / resolved / persisting" against the previous comparable run, gated on matching coverage and labelled apparent rather than asserted.
  • Drift v2 — an opt-in deep-audit pass with a visible cost ceiling, carry-forward for trends, and an ESLint-rule substrate that uses --stats as proof-of-execution so "no messages" can't be mistaken for "clean" when a rule never ran.
  • Scan run ceilings from Settings are honored and shown before you start a run.

Terminal

OSC 133 shell integration (exit-status decorations, prompt navigation, copy-last-output, long-run notification), focus-follows-pane with ⌘1–9, tab overflow, branch metadata on tabs, and governance markers that survive a daemon restart — previously they vanished exactly on the long-lived sessions where they matter.

Board and onboarding

Dependency editor, multi-select with bulk verbs, run-order transparency derived from the coordinator's real execution order, an Auto-Mode arm preview, and an Issue chip. Plus a first-run stage diagram, a ? shortcut cheatsheet, nav stage explainers, and Settings scope badges derived from the real settings shape rather than a hand-maintained list.

Engineering integrity

  • The ts-rs drift guard was passing vacuously and is fixed: cargo reads .cargo/config.toml from the working directory, not --manifest-path, so three local entry points — including codegen:check itself — were regenerating bindings into a gitignored directory while the guard diffed a different one. A CI step now perturbs a type and requires the guard to trip.
  • Rust coverage floor via cargo-llvm-cov, the last tier without one.
  • E2E ladder rings 2–3 — a Linux tauri-driver ring driving the real window, and a deterministic replay provider so CI never needs a live account. Both rings prove they fail when the app is broken.
  • Transcript reads are paged (largest IPC hop 1.80 MB → 0.22 MB) and the Trust Report's unbounded whole-file read is gone.
  • Documentation site — a written guide that imports the app's real stage table and fails its own build on an unknown stage, so docs can't drift from the product.

Known limitations

  • macOS terminals still use the DOM renderer. The upstream WebGL corruption fix (xtermjs#5883) is merged but not in any stable @xterm/addon-webgl release, so GPU rendering stays off on macOS. Tracked in #430.
  • Windows named-pipe daemon parity is deferred to v0.5 (#169) — it needs interactive verification on a real Windows desktop, not just CI execution.
  • Council's write path and the deep-audit model pass are wired and tested, but have not been driven end-to-end by hand. Treat first live runs as such.

Full changelog: v0.3.0...v0.4.0

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 11 Jul 21:46

Nightcore v0.3.0 — Governed autonomy

v0.3 is the governance release: the loop now plans before it codes, proves what it enforces, and never posts or executes on your behalf without a reviewable receipt.

Plan before code

  • Plan-approval gate — Build tasks now produce a reviewable plan you approve / refine-with-feedback / reject before any code is written. On by default (a global setting + a per-task "Plan first" toggle let you flip it), scoped to interactive tasks and hooks-capable providers, and it never auto-approves or auto-rejects on timeout — a parked plan waits for you.

Prove what you enforce (Drift v1)

  • The Enforce stage now measures conformance, not just coverage: a checkable convention compiles into an armable check, and EnforceRun runs your armed checks and reports per-convention drift with method + site counts (clean / drifted / uncheckable / errored) — it never claims a convention is "followed" without showing how it was measured and at how many sites.
  • Checks manager on the Enforce stage — list / edit / enable / disable / remove armed checks, run them on demand, per-check timeouts, and a plugin-actually-wired arm gate so a check can't arm green and enforce nothing.

Trust at the VERIFY stage

  • Review posts survive — inline comments are validated against the live diff, un-anchorable findings demote into the review body (nothing is lost), and a moved PR head is caught instead of 422-ing the whole review.
  • Fail-visible reviews — degraded runs and $0 usage-limit runs are now flagged on PR-review, Insight, and Scorecard results, so an incomplete scan never reads as a clean bill.
  • Approve the real change, not the prose — pr_fix now shows the actual local fix-commit diff before the push gate.

Under the hood

  • Prompt-injection hardening — the foreign PR diff is wrapped in an untrusted block and size-capped before it reaches the review model; untrusted PR filenames and finding text are sanitized before they're posted.
  • Armed-check command safety — drift checks can only run vetted package-script / rg/grep count commands; arbitrary-code launchers and shell metacharacters are refused at the arm gate.
  • Security-critical checks are excluded from flaky-retry; a one-shot RuleTester runner validates that an armed lint rule actually fires.
  • An in-process end-to-end test harness over the real stores + orchestrator, plus CI wall-clock improvements.

Install

Unsigned build — on macOS run xattr -cr on the app if Gatekeeper blocks it; on Windows choose "Run anyway" past SmartScreen. Existing installs update in place via the built-in updater.

v0.2.1

Choose a tag to compare

@github-actions github-actions released this 11 Jul 13:50
ec463c7

A patch release fixing a critical regression in v0.2.0, a usage meter that now actually shows Claude's 5-hour window, and new attention/notification features. If you installed v0.2.0, updating restores scans.

Fixes

Scans work again (critical)

v0.2.0 — the first release built in CI rather than locally — baked the build machine's path into the binary, so the analysis sidecar tried to start in a directory that doesn't exist on your machine and failed to launch. Every scan (Insight, Harness, Scorecard, PR review) and the model list were broken; the terminal was unaffected. The sidecar now resolves its working directory at runtime, so a CI-built release runs the same as a local build.

Usage meter — Claude's 5-hour window (for real this time)

Claude now shows its 5-hour session window next to the weekly window. The earlier attempt matched the window by its length, but Claude's API returns that field empty, so the 5-hour window stayed hidden. The meter now classifies windows by kind (session / weekly / per-model weekly), which is what the API actually sends.

  • Fixed the sidebar overlap — the usage widget no longer draws over the nav rows at small heights; the nav list scrolls and the usage footer stays pinned.
  • Collapsed-sidebar tooltips — hovering a usage icon in the collapsed rail shows the numbers immediately.

New — attention & notifications

  • Desktop notifications when a terminal command finishes, and when a run parks awaiting your input (on by default).
  • Terminal tab auto-naming from the running process, plus a 3-state attention badge with jump-to-waiting so you can find the tab that needs you.
  • One-click installer for the Claude notify hook (copies the snippet to your clipboard).
  • A ready update now surfaces as a pill in the sidebar footer.

Update

Existing v0.2.0 installs update in place via the in-app updater. Fresh installers for macOS (Apple Silicon / Intel) and Windows are attached below.

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 11 Jul 11:52

Nightcore v0.2.0 is a large release — 201 commits since v0.1.0 — that fills in the governed autonomy story end to end: a five-stage lifecycle, a terminal cockpit, per-task trust receipts, live usage metering, and two-way GitHub issue sync. Everything an agent does now leaves an auditable trail, and the gates that keep it on-rails are visible where the work happens.

Prerequisite: the claude CLI must be installed and on your PATH — Nightcore drives it, it does not bundle it. Codex is an optional second provider.

Highlights

Terminal cockpit

A full integrated terminal, built as a first-class governed surface:

  • Tabs + grid view with drag-to-reorder, zoom-a-pane, and a session cap of 12.
  • Task injection — pick a task and its title, description, and on-disk JSON path are typed into your shell (you press Enter); the task links to the terminal with a chip on the board card.
  • One-click Claude launch/resume with an ungoverned-session marker (a terminal claude runs as you, outside the gates) and an opt-in, default-off skip-permissions flag.
  • Worktree create from the new-tab picker (in an isolated term/ namespace) and open-terminal-here on task worktrees.
  • Live-PTY survival across app restarts via an opt-in detached daemon (macOS/Linux; Windows keeps read-only restore).
  • Confined tabs — an opt-in macOS Seatbelt sandbox that blocks writes outside the working tree while still letting Claude Code run.
  • Ergonomics: shortcuts, smart copy/paste, in-scrollback search, clickable links, live font/scrollback settings, unread-output badges, manual + opt-in AI tab naming, broadcast-input to a grid, and drag-a-file-in to type its path.

Trust Report

A per-task governance receipt — gauntlet results, guardrail activity, and cost, computed on demand — rendered in the task drawer, exportable as Markdown, and attachable to a PR as a comment.

Provider usage meter

An opt-in sidebar meter showing your live Claude and Codex rate-limit windows (5h / weekly / model-scoped) with reset countdowns, plus a cost-from-transcripts detail view.

Usage-aware governance

Auto Mode now pauses new run pickups when a rate-limit window gets hot (default 90%, adjustable), finishes in-flight runs untouched, and auto-resumes when the window cools — so unattended runs don't burn your cap.

GitHub two-way issue sync

Task status changes write back to the linked GitHub issue (labels + a status comment), PRs from issue-linked tasks get Closes #N, and issues closed upstream surface a chip on the task. Findings can also be exported as a GitHub issue map with native sub-issues.

Five-stage lifecycle + History

The app is now organized as Intake → Understand → Harden → Enforce → Verify, with convention-coverage badges in Enforce, convert-all parity across findings, and a global History view of every scan run across projects.

Security

  • Execution-sink ask gate — agent writes to .github/workflows/, .claude/, git hooks, package.json, and similar now require your approval even under bypass permissions (covers file tools and Bash redirects). This closes a one-shot-RCE hole in the default posture.
  • Confined terminal tabs allow Claude Code's own state dirs under ~/.claude while keeping settings/hooks write-protected.

Fixes

  • Auto Mode's toggle now reflects armed-vs-drained truth with a real disarm path.
  • Onboarding no longer blocks Claude-only users on Codex/gh.
  • A failed session keeps its transcript visible beside the error.
  • Assorted issue-sync hardening (project guard, degrade-cache recovery, comment coalescing) and a CI test-flake fix.

Install & update

Grab an installer for macOS (Apple Silicon / Intel) or Windows from the assets below. Existing v0.1.0 installs update in place via the signed in-app updater.

What's next

Development is public and roadmap-driven — see the Roadmap board, the planning map, and docs/research/2026-07-11-roadmap-v0.3-v0.5.md. v0.3 focuses on making trust visible (a plan-approval gate, evidence bundles, richer gauntlet controls) and table-stakes polish.

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 09 Jul 15:42

Nightcore v0.1.0 — First Alpha

Stop typing code. Start directing AI agents.

The first installable alpha of Nightcore — a local-first desktop studio that orchestrates Claude agents on a Kanban board, with verification gates, git worktree isolation, and minisign-verified auto-updates.


✨ What's New

📦 Installable desktop app

  • macOS (Apple Silicon + Intel — separate downloads) and Windows NSIS installer
  • Bundled Bun sidecar — no need to install Bun/Node; the Claude Agent SDK runtime ships inside the app
  • Auto-update — Settings → About → Check for updates (minisign-verified; updates download from GitHub Releases)

🎯 Core studio

  • Kanban board — drag-and-drop tasks across Backlog → Ready → In Progress → Verifying → Done
  • Task kinds — Build, TDD, Research, Decompose
  • Auto Mode — parallel agents with concurrency cap, dependency ordering, and failure circuit-breaker
  • Worktree isolation — per-task git branches so main stays safe
  • Live streaming — transcripts, tool use, cost & token usage per run
  • Verification gauntlet — build → lint/typecheck → Structure-Lock → independent AI reviewer before merge

🔍 Codebase scans

View What it does
Insight (I) 9-category codebase analysis — convert findings to tasks
Harness (H) Convention auditor across 8 lenses — apply artifacts to disk
Scorecard (R) A–F production-readiness grades — harden weak areas into tasks

🔀 Git & PR workflow

  • Worktrees (W) — browse branches, preview merges, view diffs
  • PR Review (P) — AI-grounded review of open PRs; post comments, fix CI, resolve conflicts
  • Issue Triage (T) — validate GitHub issues against the codebase; convert to tasks

⚙️ Settings

  • Global + per-project defaults (model, effort, concurrency, permissions)
  • External MCP servers, constitution editor, desktop notifications
  • Provider config inspector on the board toolbar

📥 Install

Platform Download
macOS Apple Silicon Nightcore_aarch64.app.tar.gz or .dmg
macOS Intel Nightcore_x64.app.tar.gz or .dmg
Windows Nightcore_0.1.0_x64-setup.exe

Prerequisites (not bundled)

  • Claude Code CLI — installed and logged in (claude in terminal)
  • Git
  • GitHub CLI (gh) — optional at onboarding; required for PR Review & Issue Triage

⚠️ Alpha caveats

This is pre-1.0 software. APIs, UI, and on-disk formats may change between releases.

  • Codex provider is not ready — the Codex routing layer landed in this build but will fail if selected. Use Claude as your provider until the next update fixes this.
  • macOS & Windows only — Linux is best-effort, not officially supported.
  • Separate macOS builds per CPU — no universal binary (Apple Silicon and Intel are distinct downloads).
  • Agents have filesystem + shell access — use only on trusted projects. See SECURITY.md.

🔄 Updating

  1. Open Settings → About
  2. Click Check for updates (or wait ~30s after launch for the background probe)
  3. Finish any active agent runs first — install is blocked while tasks are running
  4. Click Install & restart

🗺️ What's next

  • Fix Codex provider end-to-end
  • Continued polish on onboarding, docs, and harness hardening catalog

Built with Tauri 2 · Rust · Bun · React 19 · Claude Agent SDK
Report issues → github.com/Shironex/nightcore/issues