Repository navigation
Releases: saifmukhtar/ultimatter
Release list
Ultimatter v1.1.3
v1.1.2 — Critical Security Update & Zero-Fork Engine
This is a major security and performance release. All users are strongly advised to update immediately.
🛡️ Security (CVE Patches)
This release addresses several critical vulnerabilities discovered during a comprehensive security audit:
- DNS Rebinding & Master Token Leak: Fixed an issue where the control server did not validate the
Hostheader, allowing malicious sites to extract theSECURE_TOKENvia DNS rebinding. - Control Server CSRF: Enforced
Originvalidation andX-Requested-Withpreflight checks for all state-changing POST requests (Tailscale toggles, shutdowns). - DOM XSS & Token TOCTOU: Implemented strict HTML entity encoding in the Mobile Hub, transitioned to a single-use exchange token system, and bounded the session cookie cache to prevent memory exhaustion (DoS).
- Cookie & API Hardening: Added strict
SecureandSameSite=Laxflags to auth cookies, removed master token web exposure, and injected strict HSTS andX-Frame-Optionsheaders.
⚡ Performance & Fixes
- Zero-Fork Agent Discovery (0.0% CPU): Completely eliminated CPU drain and battery spikes. The gateway no longer spawns heavy OS shells (
lsof/powershell) and now uses direct, in-memory kernel socket inspection (/proc/net/tcp) to find active agents. - AppImage Startup Fix: Fixed a blank-screen race condition on restart by implementing a double-probe supervisor check in Rust.
- IP Rotation Resilience: Fixed an issue where router IP changes broke Root CA trust. The gateway now dynamically regenerates Leaf Certificates on the fly if your IP changes, keeping your phone permanently trusted.
- UI Resiliency: Fixed a UI syntax error breaking the desktop dashboard and added a fallback mathematical JavaScript QR scanner (
jsQR) for browsers lacking nativeBarcodeDetectorsupport.
📦 Which file should I download?
Every platform has two types of downloads: Native Desktop Apps (with a full graphical window and dock icons) and Command Line Binaries (for terminal users or headless servers).
🍏 macOS (Apple Silicon)
Ultimatter-macos-arm64.zip👉 (Recommended) The native macOS.appbundle. Extract and drag to your Applications folder.ultimatter-macos-arm64.tar.gz👉 The raw CLI executable for terminal usage.
🪟 Windows (x64)
ultimatter-windows-x64.zip👉 (Recommended) Zipped archive containing the native Windows.exe.ultimatter-windows-x64.exe👉 The raw, unzipped executable.
🐧 Linux (x64)
Ultimatter-x86_64.AppImage👉 (Recommended) The portable Linux GUI app. Just mark as executable (chmod +x) and double-click to run.ultimatter-linux-x64.tar.gz👉 The raw CLI executable for headless servers or terminal usage.
Full Changelog: https://github.com/saifmukhtar/ultimatter/blob/main/CHANGELOG.md
Full Changelog: v1.1.0...v1.1.2
Ultimatter v1.1.0
v1.1.0: Universal Hub & Native Desktop Apps 🚀
🚀 New Features
- Universal Mobile Hub: A brand-new UI that automatically discovers and lists all active AI agents (Antigravity, OpenCode, and Claude Code) in a single dashboard.
- Native Desktop App: Replaced the web-based floating bubble with a fast, native desktop control panel (built in Rust/Wry) featuring official macOS Dock and Windows Taskbar icons.
- Node.js SDK: The core reverse-proxy engine is now decoupled. You can
require('ultimatter')and embed the secure gateway directly into your own Node apps (seeLIBRARY.md). - In-Browser Camera Scanner: Pair your phone instantly using a pure HTML5 QR scanner built right into the pairing page.
- 1-Tap Root CA Downloader: Download and install the SSL certificate directly from the Mobile Hub to fix Android/iOS trust warnings instantly.
🔄 Changes & Enhancements
- Hub as Global Default: The Mobile Hub is now the default landing page (
/) for all users, regardless of how many apps are running. - Granular Agent Control: Added 1-tap toggles to the desktop dashboard to temporarily enable or disable network access for specific agents.
- Ultra-Fast Network Probing: Upgraded the discovery engine to use 2ms zero-fork kernel socket fingerprinting (drastically reducing CPU usage).
- Multi-Platform CI/CD: The GitHub Actions pipeline now automatically builds 6 zero-dependency artifacts across all major operating systems.
🐛 Bug Fixes
- Fixed SPA Routing: Resolved an issue where React Router apps (like Antigravity) would throw 404 errors when reloaded on mobile.
- Fixed Archive Naming: Ensured executables are cleanly named
ultimatter(without the platform suffix) inside release.zipand.tar.gzfiles. - Fixed Android Cert Downloads: Enforced strict MIME types (
application/x-pem-file) so Android Chrome stops incorrectly appending.crtto downloaded certificates. - Fixed Upstream CSP Blocks: Properly stripped and sanitized upstream Content Security Policy headers that were breaking injected Mobile Hub elements.
📦 Which file should I download?
Every platform has two types of downloads: Native Desktop Apps (with a full graphical window and dock icons) and Command Line Binaries (for terminal users or headless servers).
🍏 macOS (Apple Silicon)
Ultimatter-macos-arm64.zip👉 (Recommended) The native macOS.appbundle. Extract and drag to your Applications folder.ultimatter-macos-arm64.tar.gz👉 The raw CLI executable for terminal usage.
🪟 Windows (x64)
ultimatter-windows-x64.zip👉 (Recommended) Zipped archive containing the native Windows.exe.ultimatter-windows-x64.exe👉 The raw, unzipped executable.
🐧 Linux (x64)
Ultimatter-x86_64.AppImage👉 (Recommended) The portable Linux GUI app. Just mark as executable (chmod +x) and double-click to run.ultimatter-linux-x64.tar.gz👉 The raw CLI executable for headless servers or terminal usage.
Ultimatter v1.0.0
Full Changelog: main...v1.0.0
Full Changelog: main...v1.0.0
Ultimatter main
Full Changelog: https://github.com/saifmukhtar/ultimate-antimatter/commits/main
Full Changelog: https://github.com/saifmukhtar/ultimatter/commits/main