A reliability, privacy, and performance overhaul — every subsystem reviewed, fixed, and now covered by a 112-test suite that runs in CI.
Reliability
- The microphone picker in Settings now actually selects your mic (previously it silently used the system default)
- Transcription failures, download failures, and mic disconnects surface as menu bar alerts instead of failing silently
- Model downloads are verified against pinned SHA256 hashes, with per-model progress and cancel
- Recordings cap at 5 minutes (memory-bounded) and still transcribe what was captured
- Cancel a stuck transcription with the hotkey (tap in push-to-talk, hold in toggle mode)
Privacy
- Dictated text is never logged in release builds — verify yourself:
stringsthe binary and find no transcript output - Docs and audit commands on the website corrected to match the source layout
Performance
- ~3.4× faster text correction (one compiled regex instead of ~230 recompiled per dictation)
- Typing no longer delays decoding; inference no longer blocks the app's thread pool
New
- First-launch onboarding: permissions walkthrough + recommended 181 MB Q5 model (existing users never see it)
- Emoji and other astral characters are no longer mangled mid-typing (surrogate-pair chunking fix)
- whisper.cpp upgraded to v1.9.1
- Supply-chain hardening: GitHub Actions SHA-pinned, least-privilege CI token
Install
Download the DMG, drag to /Applications, right-click → Open on first launch (ad-hoc signed).
SHA256 WhisperDictation.dmg:
76de1835922e2f6f4031483b0fa52a8e5c7e576dd0c3edf4a371dc31f39aaeaa