Skip to content

Releases: saifmukhtar/ultimatter

Ultimatter v1.1.3

Choose a tag to compare

@github-actions github-actions released this 28 Sep 11:14

What's Changed

New Contributors

Full Changelog: v1.1.2...v1.1.3

v1.1.2 — Critical Security Update & Zero-Fork Engine

Choose a tag to compare

@saifmukhtar saifmukhtar released this 20 Sep 22:08

This is a major security and performance release. All users are strongly advised to update immediately.

🛡️ Security (CVE Patches)

This release addresses several critical vulnerabilities discovered during a comprehensive security audit:

  • DNS Rebinding & Master Token Leak: Fixed an issue where the control server did not validate the Host header, allowing malicious sites to extract the SECURE_TOKEN via DNS rebinding.
  • Control Server CSRF: Enforced Origin validation and X-Requested-With preflight checks for all state-changing POST requests (Tailscale toggles, shutdowns).
  • DOM XSS & Token TOCTOU: Implemented strict HTML entity encoding in the Mobile Hub, transitioned to a single-use exchange token system, and bounded the session cookie cache to prevent memory exhaustion (DoS).
  • Cookie & API Hardening: Added strict Secure and SameSite=Lax flags to auth cookies, removed master token web exposure, and injected strict HSTS and X-Frame-Options headers.

⚡ Performance & Fixes

  • Zero-Fork Agent Discovery (0.0% CPU): Completely eliminated CPU drain and battery spikes. The gateway no longer spawns heavy OS shells (lsof/powershell) and now uses direct, in-memory kernel socket inspection (/proc/net/tcp) to find active agents.
  • AppImage Startup Fix: Fixed a blank-screen race condition on restart by implementing a double-probe supervisor check in Rust.
  • IP Rotation Resilience: Fixed an issue where router IP changes broke Root CA trust. The gateway now dynamically regenerates Leaf Certificates on the fly if your IP changes, keeping your phone permanently trusted.
  • UI Resiliency: Fixed a UI syntax error breaking the desktop dashboard and added a fallback mathematical JavaScript QR scanner (jsQR) for browsers lacking native BarcodeDetector support.

📦 Which file should I download?

Every platform has two types of downloads: Native Desktop Apps (with a full graphical window and dock icons) and Command Line Binaries (for terminal users or headless servers).

🍏 macOS (Apple Silicon)

  • Ultimatter-macos-arm64.zip 👉 (Recommended) The native macOS .app bundle. Extract and drag to your Applications folder.
  • ultimatter-macos-arm64.tar.gz 👉 The raw CLI executable for terminal usage.

🪟 Windows (x64)

  • ultimatter-windows-x64.zip 👉 (Recommended) Zipped archive containing the native Windows .exe.
  • ultimatter-windows-x64.exe 👉 The raw, unzipped executable.

🐧 Linux (x64)

  • Ultimatter-x86_64.AppImage 👉 (Recommended) The portable Linux GUI app. Just mark as executable (chmod +x) and double-click to run.
  • ultimatter-linux-x64.tar.gz 👉 The raw CLI executable for headless servers or terminal usage.

Full Changelog: https://github.com/saifmukhtar/ultimatter/blob/main/CHANGELOG.md

Full Changelog: v1.1.0...v1.1.2

Ultimatter v1.1.0

Choose a tag to compare

@github-actions github-actions released this 10 Sep 15:04

v1.1.0: Universal Hub & Native Desktop Apps 🚀

🚀 New Features

  • Universal Mobile Hub: A brand-new UI that automatically discovers and lists all active AI agents (Antigravity, OpenCode, and Claude Code) in a single dashboard.
  • Native Desktop App: Replaced the web-based floating bubble with a fast, native desktop control panel (built in Rust/Wry) featuring official macOS Dock and Windows Taskbar icons.
  • Node.js SDK: The core reverse-proxy engine is now decoupled. You can require('ultimatter') and embed the secure gateway directly into your own Node apps (see LIBRARY.md).
  • In-Browser Camera Scanner: Pair your phone instantly using a pure HTML5 QR scanner built right into the pairing page.
  • 1-Tap Root CA Downloader: Download and install the SSL certificate directly from the Mobile Hub to fix Android/iOS trust warnings instantly.

🔄 Changes & Enhancements

  • Hub as Global Default: The Mobile Hub is now the default landing page (/) for all users, regardless of how many apps are running.
  • Granular Agent Control: Added 1-tap toggles to the desktop dashboard to temporarily enable or disable network access for specific agents.
  • Ultra-Fast Network Probing: Upgraded the discovery engine to use 2ms zero-fork kernel socket fingerprinting (drastically reducing CPU usage).
  • Multi-Platform CI/CD: The GitHub Actions pipeline now automatically builds 6 zero-dependency artifacts across all major operating systems.

🐛 Bug Fixes

  • Fixed SPA Routing: Resolved an issue where React Router apps (like Antigravity) would throw 404 errors when reloaded on mobile.
  • Fixed Archive Naming: Ensured executables are cleanly named ultimatter (without the platform suffix) inside release .zip and .tar.gz files.
  • Fixed Android Cert Downloads: Enforced strict MIME types (application/x-pem-file) so Android Chrome stops incorrectly appending .crt to downloaded certificates.
  • Fixed Upstream CSP Blocks: Properly stripped and sanitized upstream Content Security Policy headers that were breaking injected Mobile Hub elements.

📦 Which file should I download?

Every platform has two types of downloads: Native Desktop Apps (with a full graphical window and dock icons) and Command Line Binaries (for terminal users or headless servers).

🍏 macOS (Apple Silicon)

  • Ultimatter-macos-arm64.zip 👉 (Recommended) The native macOS .app bundle. Extract and drag to your Applications folder.
  • ultimatter-macos-arm64.tar.gz 👉 The raw CLI executable for terminal usage.

🪟 Windows (x64)

  • ultimatter-windows-x64.zip 👉 (Recommended) Zipped archive containing the native Windows .exe.
  • ultimatter-windows-x64.exe 👉 The raw, unzipped executable.

🐧 Linux (x64)

  • Ultimatter-x86_64.AppImage 👉 (Recommended) The portable Linux GUI app. Just mark as executable (chmod +x) and double-click to run.
  • ultimatter-linux-x64.tar.gz 👉 The raw CLI executable for headless servers or terminal usage.

Ultimatter v1.0.0

Choose a tag to compare

@github-actions github-actions released this 19 Aug 11:10

Full Changelog: main...v1.0.0

Full Changelog: main...v1.0.0

Ultimatter main

Choose a tag to compare

@github-actions github-actions released this 18 Aug 19:39