Skip to content

Releases: skaft-software/octet

octet v0.8.1

Choose a tag to compare

@achuthanmukundan00 achuthanmukundan00 released this 27 Sep 21:24
21d5c13

octet 0.8.1

This release adds optional native computer use, polishes the terminal experience,
repairs provider and session edge cases, and includes the committed startup and
agent-turn performance fixes since 0.8.0.

Highlights

  • Add the version-matched octet-computer-use executable bundle to the official
    extension catalog. It uses a separately installed MIT-licensed Cua Driver for
    native desktop observation and actions. Driver setup and OS permission grants
    are explicit. On macOS, the signed CuaDriver app supplies a visible agent cursor;
    the default fails closed if that host or its grants are unavailable. In full
    access, effectful actions do not prompt by default; gated profiles or
    OCTET_CUA_CONFIRM=1 require confirmation. It is not a sandbox.
  • Keep octet-browse installable but deprecated. Its isolated Chromium profile
    and manual-authentication boundary remain safer for logged-in page work than
    computer use on the real desktop. The MCP bridge can also connect to a
    separately configured local Cua Driver server.
  • Add in-session /setup, built-in Cards and Still themes, improved theme
    surfaces and model-adaptive splashes, and responsive workspace @ completion.
  • Fix Shift+Tab thinking cycling, oversized-entry compaction boundaries, custom
    endpoint-asserted context limits, Kitty image cursor/row handling, and
    interactive exit under slow extension cleanup.
  • Skip rewriting an unchanged workspace marker while retaining no-follow and
    atomic-repair checks. Reduce model lookup/credential-pruning work at startup
    and avoid copying full conversation history on ordinary provider turns.
    An offline phase benchmark informed these changes; it does not establish a
    first-frame or all-extension startup speedup for the published binary.

Availability and limits

Native archives and the installer target macOS Apple silicon/Intel and GNU/Linux
x86-64. Serve and five executable bundles are separate, exact-version assets;
installation does not activate an extension or persist a trust grant. npm, Homebrew, crates.io,
and SDK registry publication remain separate and unpublished channels. The
version-pinned GitHub release records signed assets and public-install results.

A local macOS driver demo exercised a live Calculator action, but this is
not broad application qualification. Windows host compatibility and Linux/Omarchy
computer-use parity are not release-qualified and remain follow-up work.
The optional macOS Octet-owned host app is a source-only developer override, not
an installed release dependency. Live-provider coverage, physical-terminal
qualification across terminals, and long-duration use are not established by
source tests or package smoke.

The historical 0.8.1-rc.1 notes describe an unpublished local
dogfood snapshot, not a public RC package. See the changelog
for the detailed committed changes and installation for
version-matched commands.

octet v0.8.0

Choose a tag to compare

@achuthanmukundan00 achuthanmukundan00 released this 25 Sep 06:57
3366510

octet 0.8.0

This release focuses on responsive interaction, bounded recovery, and host-owned extension
contracts for a small, model-flexible coding agent.

Highlights

  • Keep startup silent and editable, restore the full /model picker, and keep
    inspection commands and /goal responsive during streaming.
  • Improve activity shimmer, tool disclosure, worker presentation, and usage
    visibility without replacing durable accounting with display estimates.
  • Accept owner-bound /subagents stop <name|all> during an active response,
    keep input responsive while stopping, and show compact token counts with the
    same continuation alignment as Thinking. A stop request is not terminal settlement.
  • Preserve native scrollback after an active subagent roster instead of clipping
    unrelated commands, results, and answers into a pending-tool preview.
  • Add /settings, /scoped-models, /session, hidden /debug, capability-gated
    /fast, and !command / !!command shell escapes. Withdraw /tree and
    /checkout; rename /quit to /exit.
  • Add ordered --models selection and opt-in Windows --powershell, plus bounded
    HTML session export, local-model evaluation profiles, and tool checkpoints.
  • Repair request headroom, provider size-rejection recovery, sparse discovery
    metadata, reasoning capability decoding, and host-budgeted transport retries.
  • Refresh reviewed models.dev names, pricing, and capabilities without adding
    build/runtime metadata fetches. Direct DeepSeek schedule pricing stays unknown;
    public catalog evidence is not live inference acceptance.
  • Keep interrupted-attempt partial text in RecoveredOutput, separate from the
    current answer, provider replay, and usage accounting.
  • Update rustls to 0.23.45 for RUSTSEC-2026-0285. Preserve an admitted Python
    shutdown hook and acknowledgement when stdin closes, within the EOF drain budget.
  • Keep manual-compaction provider retry state off the nested caller futures to
    prevent Serve /compact from overflowing a normal Tokio worker stack.
  • Retain Serve, Browse, MCP, host-owned subagents, web search, and protocol
    safety/conformance. API 0.4 is the current extension wire; the separately
    supported canonical API 0.3 includes a session-isolated process event bus.
  • Remove Pi extension execution and its CLI entrypoint; retain Pi dry-run
    inventory and portable import/restore. Remove obsolete internal planning,
    comparison, and task-handoff documentation.

Additional reconciled changes

  • Keep model/thinking/subagent and consent surfaces inside the active run loop;
    renderer layout and terminal writes no longer hold the semantic input lock.
  • Bound Bash spill storage and editor history, move optional telemetry writes
    off the agent path, and advance session/replay projections incrementally.
  • Expose qualified native Responses steering and asynchronous tools with durable
    intent, settlement and fail-closed accounting; unsupported routes retain queued
    steering. Host model selection for workers remains owner-bound.
  • Keep worker activity in a bounded, mutable transcript roster, with full
    details in /subagents; raw orchestration calls and state transitions add
    no transcript notices. Full-access MCP mutations use host-owned policy
    checks; controlled policies still refuse them.
  • Offer first-run API-key, supported OAuth, and local-model setup in that order.

Reload

Interactive resource/extension reload is enabled silently by default and applies
at idle boundaries. /reload --dry-run previews changes. Host replacement
requires /reload --force or explicit reload_host = true, and a replaced
binary requires confirmation before its first probe execution. Resource rebuilds
refuse while host worker tasks remain attached, including retained idle receivers;
force/watch passes cannot bypass that refusal. Finish or stop work, then exit and
resume the session to replace that owning host. In-flight provider calls are not
silently replayed. A separate running octet serve process needs its own restart
to use a new binary.

Limits and availability

Native iOS/macOS companions remain source-only, not supported live connection
paths or signed installable releases. Product open-all remains fail-closed
without atomic writer handover. /fast is session/process scoped and does not
promise provider acceptance or clear historical cost uncertainty. Optional
protocol services do not imply a product UI or broader host authority.

This release does not claim every review finding resolved. Terminal layout,
Mermaid, notification wording, native-app delivery, live-provider acceptance,
and physical-terminal qualification remain separate from this release-gate scope.
Deterministic tests do not establish all-provider, physical-terminal, or
long-duration acceptance.

The version-pinned GitHub release
records validation, signed native assets, exact-version Serve and executable
bundles, and public-install results. See installation for
version-matched commands and CHANGELOG.md for detailed changes. The
RC qualification record retains its
historical, bounded evidence; source checks alone do not establish publication.

npm, Homebrew, crates.io and SDK registries remain separate, unpublished channels.
Live-provider/audio and physical-terminal acceptance were not run as release gates.

Verified publication

  • Signed native binaries and exact-version Serve packages are published for macOS arm64, macOS x86_64, and Linux x86_64. All 28 required installer, metadata, checksum, archive, and Sigstore-bundle assets are present.
  • Exact-head PR CI, main CI, and CodeQL passed.
  • Native publication and public install verification on all three platforms passed. Serve/bundle publication and official install/update/removal verification passed.
  • Additional isolated macOS arm64 public smoke passed: signed installer without Cargo or shell-profile changes, both executables, native-host hello, and all 343 packaged documentation assets compared with the exact release source.
  • The published binary officially installed and updated Browse, MCP, Subagents, and Web Search; all 16 checks passed, including default-disabled behavior, explicit runtime activation of all four commands, listing, and removal. No user extension configuration was changed.
  • Published Serve passed install/update, loopback launch/authentication, security-header and exact web-asset checks, listing, and removal while preserving its data sentinel.
  • No live-provider inference, physical-terminal acceptance, or registry publication is claimed by these checks.

Source commit: 3366510eb78faf45fb65cbbd8740deeee704c0f8; tree d96dd24dd9d1ec5a5cfac530e2d4f218355fcbbe. PR #431 was squash-merged without changing the qualified tree. Both full pre-squash histories remain on archive/v0.8.0-full-history at 0e8d3cc1c4758bb737487e3f220d4c2b54dd6279.

octet 0.7.6

Choose a tag to compare

@achuthanmukundan00 achuthanmukundan00 released this 12 Sep 06:18
44fba05

octet 0.7.6

Fixed

  • Repair stale models.dev integration so discovered models receive reviewed display names, context/output limits and advertised thinking metadata where the provider API leaves them unspecified. Explicit API assertions remain authoritative; metadata does not select a wire protocol or enable unsupported thinking controls.
  • Recognize DeepSeek V4.1 Flash correctly instead of falling back to stale model-family defaults.
  • Remove the duplicate working-directory line from the TUI splash. The working directory remains in the footer, including its narrow-terminal fallbacks.

Changed

  • Refresh the checked-in rich models.dev snapshot before release and review its source identity, names, pricing and capabilities together. Compilation consumes checked-in metadata without a network refresh.
  • Align product, SDK, Serve and the four executable-bundle distribution versions to 0.7.6. Extension API and native-host protocol versions, independent examples and historical releases remain unchanged.

Known limitation

Direct DeepSeek scheduled pricing is not represented by the static price table. Cost remains unknown unless explicit pricing is configured; rates are not borrowed from another provider or presented as zero-cost.

Verification and availability

The version-pinned GitHub release records validation, signed native assets, exact-version Serve and executable bundles, and public-install results. Source changes alone do not establish availability. See installation for version-matched commands.

npm, Homebrew, crates.io and SDK registries are separate, unpublished channels. This hotfix does not claim all-provider or live-inference qualification; those checks are independent of package publication.

Publication verification

Immutable source: 44fba05c00d7d99bca1c8c0366dce37e79e5a94a. PR423 passed all14 hosted checks; merged-main CI and CodeQL passed.

  • Serve release: all three platform build/install/launch checks and Linux official public install/update/removal passed.
  • Native release: Cargo-free public installs passed on Linux x86-64, macOS Intel and Apple silicon, including exact version, native-host handshake and Serve package integration.
  • Independently downloaded all28 public assets, verified all14 source/ref/workflow-bound Sigstore signatures, sizes, GitHub digests and signed checksum manifests. All316 packaged documentation files match immutable source bytes/modes in every native archive. Published installer and metadata regenerate byte-for-byte from the source/workflow bindings.
  • Additional isolated Apple-silicon public installation passed exact version/host/documentation checks and install/update/removal of Serve plus all four executable bundles. The existing user installation was not replaced.
  • Local Rust1.86 offline/locked qualification: coding library1353 passed/1 ignored, AI302 passed, agent522 passed/1 ignored; workspace/all-target/all-feature Clippy with warnings denied and formatting passed. Web280 tests and associated build/checks passed. Five actual-CLI DeepSeek loopback cases verified native Off/low/high/max and historical-selector behavior without live inference.
  • v0.7.4/v0.7.5 tags, release bodies and all historical asset identities remain unchanged. Existing publication protections were preserved.

Live-provider, physical-terminal, graphical/audio and endurance acceptance were not run; synthetic fixtures are not universal-provider or zero-bug qualification. npm/Homebrew/crates.io/SDK registries and website deployment are separate from this publication.

octet 0.7.5

Choose a tag to compare

@achuthanmukundan00 achuthanmukundan00 released this 12 Sep 00:02
ac721cb

octet 0.7.5

Published and verified. Native binaries for macOS arm64, macOS Intel and Linux x86-64, matching Serve runtimes, and four executable-extension bundles are available below. All 28 assets (14 payloads plus their Sigstore bundles) were downloaded and verified against exact workflow identities and the immutable source before Latest promotion.

Immutable source: ac721cbffca836ab1a76f39297adbb471056e282 (protected PR #421).

Fixed

  • Keep the context-compaction and activity shimmer on a monotonic clock rather than letting render cost or event traffic change its speed. Missed animation frames are skipped, not replayed; busy render notifications cannot indefinitely postpone painting.
  • Route terminal diagnostics through the TUI instead of writing over its cursor. Model switches no longer leave stale splash headings or old logo colours, including sessions over SSH.
  • Avoid a misleading untrusted-project warning when starting in your home directory: a skill directory already loaded as a user root is not loaded again as a project root. Actual project skills still require workspace trust.
  • Correct stale publication-status documentation bundled with 0.7.4. The 0.7.4 release was published; its original tag and signed assets are unchanged.
  • Preserve linked public documentation and reference source in native, embedded-text and container packaging, with the same files retained by npm packaging. Reference files do not enable extensions.
  • Bound installer-script downloads independently of curl's version, and bound pre- and post-install version checks by time and output size.
  • Remove misleading per-session Serve authority choices. Sessions expose the immutable host policy, and the server rejects unsupported profile changes rather than acknowledging labels without enforcement. Configure restrictions before launch; this is not an OS sandbox.

Changed

  • The default footer now groups model, reasoning, context percentage/limit and cumulative cost on the left, with the working directory right-aligned. Narrow terminals shorten or omit the path first; estimated context and unknown-cost markers are preserved.

Added

  • A monochrome octet mark, target version and honest progress for the installer and octet update: measured download bars, named verification stages, and indeterminate activity for work without a known total. Success requires the installed version to match; redirected output remains plain.
  • A quiet startup notice when a newer stable octet release is available. Run octet update to update; the check never installs software automatically or blocks the composer. Offline startup does not check for updates.
  • /changelog opens the current version's bundled release notes as scrollable rich Markdown inside the TUI. The splash includes a reminder of the command. Reading release notes requires neither network access nor a model request.

Unchanged

  • ANSI256 and ANSI16 terminals retain the uniform model-colour logo introduced in 0.7.4. True-colour terminals retain their gradient.
  • Existing session data, provider recovery, tool permissions, and extension trust behavior are unchanged.

Installation and availability

The version-pinned GitHub release records signed native assets, exact-version Serve and executable bundles, and their public-install verification. See installation for the matching commands.

npm, Homebrew, crates.io and SDK registries are separate, unpublished channels. Website deployment and live-provider, physical-terminal and endurance qualification are independent of package publication.

Publication verification

  • Protected main CI, CodeQL and dependency graph passed for the exact release source.
  • Serve/bundle release passed, including official public installation and update.
  • Native release passed, including Cargo-free installation from public assets on all three platforms.
  • Independently checked all 14 payload signatures, GitHub asset digests, both checksum manifests, source/workflow-bound metadata and all 315 inventoried documentation files in each native archive. The installer matches the reviewed source with only the workflow’s exact commit-binding transformation.
  • v0.7.4 release identity, notes and all 28 asset records remain unchanged.

These checks are not a claim of zero bugs, live-provider acceptance, physical-terminal or endurance qualification. The Skaft documentation source corrections are merged; live-site deployment remains blocked by its separate owner configuration, Hlid/font and full-site bootstrap requirements.

octet 0.7.4

Choose a tag to compare

@achuthanmukundan00 achuthanmukundan00 released this 11 Sep 16:53
fdb44e6

octet 0.7.4

Published and verified: signed native binaries/installer for macOS Apple silicon, macOS Intel and GNU/Linux x86-64; matching Serve packages and all four official executable bundles.

curl --proto '=https' --tlsv1.2 -LsSf \
  https://github.com/skaft-software/octet/releases/download/v0.7.4/install-octet.sh | sh
octet --version   # octet 0.7.4

The installer changes your installed binary. Existing running processes need a restart to use the new version.

Highlights

  • Recover eligible interrupted Codex inference without restarting tasks or replaying committed tools. Preserve steering, cancellation and compaction behavior, with finite replacement budgets and separately paced pre-send outage waiting.
  • Retain uncertain provider usage durably, including deadline-cancelled request opening; distinguish known cost/token subtotals across CLI, RPC, delegation and experimental Serve.
  • Keep API-wait presentation responsive, sweep the entire compaction label, and use one model-accent colour across the logo on ANSI256/ANSI16 terminals. True-colour gradients remain available.
  • Improve ANSI256 Light diff readability, overlap bounded provider discovery, and reduce usage-reconciliation overhead.
  • Align the product, SDK sources, Serve and four official executable bundles to 0.7.4; include reviewed maintenance/security fixes.

Verification

  • Native release workflow: all three builds, checksum/Sigstore signing verification and public binary installation checks passed.
  • Serve and executable-bundle workflow: all builds, reproducible packaging, checksum/Sigstore verification and official installation/update checks passed.
  • 28 release assets are attached. Hosted asset digests match both published checksum manifests; the downloaded native metadata identifies the exact release source and tooling tags.

The complete candidate passed protected PR CI, including macOS, Ubuntu, MSRV, web, security/dependency checks and extension conformance. The merged release source is fdb44e65d1f4d2bb5b5f95b54c7ad8b92bc11b34; its tree is identical to tested candidate 28f5fbc24cfeb633ccf121a41a06607e0f284a52.

Physical and Wi-Fi observations are user-reported evidence, not controlled endurance certification. Weeks-long uninterrupted operation and exhaustive Codex parity are not claimed. The source qualification document preserves earlier unpublished-candidate checkpoints; this release page records the subsequent publication status.

Native archives/installer, Serve and the four executable bundles use separate signed release workflows. Serve remains experimental. Installation never automatically enables or trusts extensions. npm, Homebrew, crates.io and Python/TypeScript SDK registry publication remain separate, unpublished channels.

octet 0.7.3

Choose a tag to compare

@achuthanmukundan00 achuthanmukundan00 released this 09 Sep 18:49
207dccc

octet 0.7.3

A focused release of the streaming, rendering, and colour fixes since 0.7.2.

Included changes

  • Full-TUI 256-colour fallback uses the fixed xterm palette with a lightness
    constraint to preserve contrast. True-colour, ANSI16, explicit palette colours,
    and no-colour behavior are preserved.
  • Streaming retains completed work and stabilizes incremental Markdown output.
    Subagent presentation, picker navigation, and composer chip editing are improved.
  • Safe tool ordering, OpenRouter batch handling, and Luna model support.
  • Browse setup tests now wait for delivery of the readiness notification and join
    the worker before temporary-directory cleanup.

Changes are integrated from #398, #399, #400, and #401; release preparation is #404.

Compatibility and distribution

Product, SDK, Serve, and official executable bundles are version 0.7.3. Bundles
require exactly octet 0.7.3; extension API and native-host protocol versions are
unchanged. Installation does not enable extensions. Serve remains experimental.

The release targets signed native and Serve packages for macOS Apple silicon,
macOS Intel, and GNU/Linux x86-64, plus Browse, MCP, Subagents, and Web Search
bundles. npm, Homebrew, crates.io, and SDK registries remain separate unpublished
channels. Publication and public-install results are recorded on the
GitHub release.

Evidence and remaining limits

The implementation passed deterministic renderer, coding-agent, startup PTY,
colour-mode matrix, and Browse tests; the palette received independent code
review. The user reported smoother thinking streaming and stable scroll-up while
the model worked on the pre-version-bump candidate. This is observational evidence,
not a measured performance comparison or complete terminal acceptance.

Resize and genuine updates to historical rows can still clear/replay native
scrollback (#392). Selection, copy, and completion across the complete Terminal.app,
Ghostty, and Ghostty-to-Ubuntu SSH width matrix remain unqualified. Independent
physical visual review of the 256-colour fallback is incomplete (#382); streamed
Markdown and umbrella acceptance remain open (#393, #351). Live-provider and native
audio acceptance are not run for this release.

Changelog · Documentation

Verified publication

  • Candidate 3e2475ac94ad487e3b427abeae333660ac81e97b; merge and canonical tag
    207dccc6dcd8999db9cc6b41f87e4e86448d02aa. Their source trees match exactly.
  • Local workspace check, strict Clippy, formatting, four extension suites,
    installer tests, reproducible native/four-bundle packaging, and binary/host smoke passed.
  • All 14 release PR checks,
    exact-main CI,
    and CodeQL passed.
  • Signed Native
    and Serve
    workflows and hosted public-install checks passed. Native signing required a
    failed-job retry after adding the exact new tooling tag to the deployment
    allowlist; existing reviewer protections were preserved.
  • Independently downloaded all 28 public files and verified 14 keyless signatures,
    11 checksums, exact source/workflow identities, and byte-identical regenerated
    native metadata.
  • Fresh macOS Apple-silicon installation with Cargo disabled passed CLI version/help,
    host handshake, all five package install/list/remove checks, and Serve launch smoke.

Install the signed release:

curl --proto '=https' --tlsv1.2 -LsSf \
  https://github.com/skaft-software/octet/releases/download/v0.7.3/install-octet.sh | sh

octet 0.7.2

Choose a tag to compare

@achuthanmukundan00 achuthanmukundan00 released this 08 Sep 00:32
ddc997f

octet 0.7.2

Published with signed Native/Serve assets and independently verified public installation.

A focused hotfix for coherent terminal startup, late terminal replies, composer
completion, extension trust defaults, and compact tool presentation.

Included fixes

  • Startup readiness: the first branded frame waits for resolved model (or
    model-less setup), workspace, and appearance. Startup animation begins at
    readiness rather than during asynchronous configuration.
  • Terminal replies: the shared input owner consumes late OSC 11 background
    replies, including slowly fragmented bodies after header recognition. Explicit
    appearance overrides skip the query; SSH alone does not imply reduced color
    support. An opening header fragmented beyond the 250 ms Escape-key ambiguity
    timeout can still pass through; see terminal reply limits.
  • File completion: Up/Down selects path and @ mention suggestions; Tab
    inserts the selected result. The popup follows the selection beyond its first
    visible rows. Directory descent, attachment handling, and normal editor
    navigation without a visible menu remain intact.
  • Extension trust: installed executable bundles stay disabled by default.
    Full access implicitly trusts explicitly enabled extensions without persisting
    a trust grant. Safe mode removes implicit trust and retains its permission and
    execution boundaries; artifact integrity checks remain mandatory. Policy or
    process downgrades also retire retained services even when trust remains valid.
  • Subagent events: worker rows sit further beneath the transcript heading
    and omit per-worker call counts. The complete roster, state, token usage, cost,
    and retained telemetry remain available.
  • Bash command previews: terse tool events show the first three visual lines
    of a command and a hidden-line count. Ctrl+O expands the full retained command;
    command execution and existing output truncation are unchanged.

See terminal behavior, commands and keys, and
extension policy.

Compatibility and publication

Product, SDK, Serve, and first-party executable distribution versions are
0.7.2; matching bundles require exactly octet 0.7.2. Extension API versions
and native-host protocol 1 are unchanged. Installing a bundle does not enable
it. Safe mode is not an OS sandbox.

The published signed assets cover macOS Apple silicon/Intel and GNU/Linux x86-64,
plus Serve and octet-browse, octet-mcp, octet-subagents, and
octet-web-search. v0.7.2
is the latest stable release. Published 0.7.0/0.7.1 tags and assets remain unchanged.

npm, Homebrew, crates.io, and SDK registries remain separate and unpublished.
The website installer redirect is separate work and is not part of this hotfix.

Verification status

  • Source PR #373 and policy
    repair PR #374 passed all 14
    checks each; final merge ddc997f9d11bf6d281b8eca09c6271ba2e452f23 exactly matches the validated candidate tree.
  • 36 local gates passed: 1,183 coding-library, 499 agent, 142 TUI, all 9
    startup PTY and 6 terminal-reply PTY tests; API conformance, extension suites,
    Clippy/workspace checks, deterministic packaging and installer/Serve smoke.
  • Exact-main CI
    and CodeQL passed. Signed Native
    and Serve
    publication and their hosted install checks passed.
  • Independently downloaded all 28 public files, verified 14 keyless
    signatures
    against exact source/workflow identities and 11 checksums,
    and regenerated byte-identical signed native metadata.
  • Fresh no-Cargo native install/version/help/host handshake and public
    Serve/four-bundle install/update/remove checks passed. Existing config,
    sessions and Serve data were preserved; install did not enable extensions.
  • Five simulated public-binary PTY checks passed for delayed/fragmented replies,
    genuine typing, and explicit appearance. These are not actual SSH acceptance.
  • The unchanged web timing gate required failed-job-only retries before the final
    main pass. No web code or performance thresholds were changed.

Manual Ghostty/Ubuntu 26.04 SSH, Apple Terminal, live-provider, and native-audio
acceptance are NOT RUN. Deterministic terminal fixtures are not a substitute
for those manual checks. No benchmarks or performance comparisons are claimed.

Changelog · Documentation

octet 0.7.1

Choose a tag to compare

@achuthanmukundan00 achuthanmukundan00 released this 07 Sep 19:18
d264a81

octet 0.7.1

2026-09-07

A focused patch release for prompt presentation, trusted release downloads,
terminal appearance and scrolling, and model-supported auxiliary reasoning.

Fixes

  • Terminal appearance: fresh capable interactive installations offer
    Auto/Light/Dark with preview and persistence. /theme changes the selection
    later; existing configured installations and non-TUI modes do not open
    onboarding. See themes for detection and override behavior.
  • Startup presentation (#367): narrow, ASCII and no-color terminals retain a
    bounded startup surface. Welcome-card prefix invalidation handles animation,
    overlays, appearance/model changes and redraws without stale startup rows;
    no-color startup stays static.
  • Plain prompts (#368): interactive terminal input is no longer printed a
    second time after terminal echo. Explicit one-shot and piped prompt output
    remain visible.
  • Release GET retries (#369): trusted release downloads retry transient
    timeouts and HTTP 408/429/5xx with bounded backoff across headers and streamed
    bodies. Retries discard partial bytes and reset only the already-owned file;
    validation failures, including untrusted URLs/redirects, are never retried.
    This does not change model-inference retry policy.
  • Application scrolling: PageUp and application-owned mouse scrolling retain
    their history anchors through coalesced tool updates, worker-roster insertion
    and reflow. Explicit return-to-live controls remain unchanged.
  • Auxiliary reasoning (#370): local compaction and other host-generated
    auxiliary requests use Off only when the selected model accepts it; otherwise
    they use its valid advertised default or first supported choice. Explicit
    user reasoning selections and strict validation remain unchanged.

Installation and channels

Install signed native assets from
v0.7.1
for macOS Apple silicon/Intel or GNU/Linux x86-64:

curl --proto '=https' --tlsv1.2 -LsSf \
  https://github.com/skaft-software/octet/releases/download/v0.7.1/install-octet.sh | sh
octet --version   # octet 0.7.1

The release includes the separate Serve application and four executable
bundles: octet-browse, octet-mcp, octet-subagents, and octet-web-search.
Installation does not enable or trust executable bundles. npm, Homebrew,
crates.io and SDK registries remain separate and unpublished; Bun is unqualified.
See installation and distribution channels
for source builds, exact-version packages and publication boundaries.

Compatibility

  • Product, SDK and first-party extension distribution versions are 0.7.1;
    installed first-party packages require exactly octet 0.7.1. Extension APIs
    0.1/0.2/0.3 and native-host protocol 1 are unchanged. The four executable
    bundles still declare API 0.2; generated 0.3 types do not establish a complete
    Python 0.3 runtime.
  • The canonical repository is skaft-software/octet following #366. The
    immutable v0.7.0 assets and signing identity are unchanged;
    v0.7.1 uses the new repository identity.
  • Ygg installations and data remain separate. Install octet afresh when moving
    from Ygg; there is no automatic migration or supported ygg update transition.

Release verification

The canonical v0.7.1 and native tooling octet-binaries-v0.7.1 tags both
point to d264a81c1bda8325aad1a9b91b6e88fbb4be5216, merged through
PR #371.

  • PR CI and
    exact-commit main CI
    passed, with successful CodeQL checks on both source revisions.
  • Native publication
    and Serve/bundle publication
    passed. Public native installer checks passed on macOS Apple silicon/Intel
    and GNU/Linux x86-64.
  • All 28 public assets were downloaded. Archive/installer SHA-256 checksums and
    14 keyless signatures passed verification against the exact source/workflow
    identities; signed native metadata matched independent regeneration.
  • A fresh isolated public installation without Cargo reported octet 0.7.1
    and passed help, native-host handshake and installed Serve web-bundle checks.
    Public Serve and all four executable bundles passed install/update/remove
    checks while preserving configuration and session/Serve data sentinels.

Uncaptured native mouse/trackpad scrollback remains terminal-owned; the
application-viewport fix does not prevent native saved-line resets when the
retained-frame renderer must replay older changed rows. Terminal appearance
and startup coverage use simulated PTY/capability fixtures; manual Apple
Terminal and SSH acceptance are NOT RUN.

Optional live-provider checks: NOT RUN. Optional native-audio checks:
NOT RUN. No benchmarks were run for this release, and no benchmark or
performance-comparison claim is made.

Changelog · Documentation

octet v0.7.0

Choose a tag to compare

@achuthanmukundan00 achuthanmukundan00 released this 06 Sep 17:59
6dcde06

octet v0.7.0

Released: signed native binaries for macOS Apple silicon/Intel and GNU/Linux x86-64, Serve, and the four official executable-extension bundles.

Install

curl -fsSL https://github.com/skaft-software/octet/releases/download/v0.7.0/install-octet.sh | sh

The installer verifies signed artifacts and installs octet and octet-host. Install afresh: older installations and data remain separate; this release does not perform automatic migration.

octet --version
octet extension install octet-serve
octet serve

What changed

The first lowercase octet release includes the renamed native agent and host, provider/media/cancellation/recovery fixes, endpoint-specific thinking controls, bounded Pi setup import and compatibility, and reorganized documentation.

Verification and boundaries

  • PR/main CI and CodeQL passed. Both protected release workflows passed, including public native installs on all three platforms and official extension install/update/remove checks.
  • All 28 public assets and 14 signatures independently verified against the exact repository, workflow identity, OIDC issuer and source SHA. Fresh macOS arm64 native/host/Serve checks passed.
  • Genuine pinned Pi loader qualification: 78/78 on the identical release tree. This is not universal Pi behavioral, provider or UX parity.
  • Live-provider/native-audio acceptance: NOT RUN (optional; not required for release). No paid provider calls were required.
  • npm @skaft/octet is not published: its first-package/trusted-publisher bootstrap and provenance are separate. Use the native installer above. Bun and other native targets remain unqualified.
  • Serve remains experimental. Source/signing identity remains skaft-software/ygg; historical notices are retained.

Source: 6dcde0620314c554b11719b0bc97835b104f0e47; tree: 542f539118cbf8618239504348604f1b9f89c660.

Ygg v0.6.7

Choose a tag to compare

@achuthanmukundan00 achuthanmukundan00 released this 02 Sep 14:11
93a771c

ygg v0.6.7

GitHub-only follow-up hardening from pre-user dogfood validation of v0.6.6.
These releases preceded external user adoption. npm, Homebrew, and crates.io
publication remained deferred while the product/package name was unresolved.

Fixed

  • Serve repository refresh now enumerates Git clean/process filters from the
    effective repository, worktree, and included configuration before running
    status commands.
  • Filter names that cannot be represented safely as Git command overrides,
    including delimiter-bearing or non-UTF-8 names, fail closed without running
    repository status.
  • Marker-based regressions cover ordinary local config, config.worktree, and
    the unsafe-name cases with real positive controls.

Installation and updates

Install the signed binary for GNU/Linux x86-64, macOS Intel, or macOS Apple
silicon:

curl --proto '=https' --tlsv1.2 -LsSf \
  https://github.com/skaft-software/ygg/releases/download/v0.6.7/install-ygg.sh | sh

Existing GitHub-binary users can update in place:

ygg update
ygg --version
ygg doctor

Managed first-party packages update separately from the core binary. Run the
ygg extension update ... commands reported by ygg update; an incompatible
older package is rejected rather than executed.

Cargo users can install the immutable tag with Rust 1.86 or newer:

cargo install --locked \
  --git https://github.com/skaft-software/ygg \
  --tag v0.6.7 \
  --bins \
  ygg-coding-agent

Compatibility and known limits

  • Core crates and first-party extension manifests target Ygg 0.6.7 exactly.
  • Executable-extension API 0.2 remains unchanged.
  • Existing configuration, credentials, sessions, goals, and extension-owned
    data remain in place across installer upgrades. Managed package binaries
    follow the separate exact-version update described above.
  • npm, Homebrew, and crates.io remain unpublished by maintainer decision.
  • The incremental production unwrap/expect audit tracked in #111 remains
    deferred to v0.7.0.

Immutable release evidence

  • Source: 93a771cc789d8b21e4d279831c941910c4cfd857
  • Release PR: #234
  • Security fix PR: #233
  • Protected post-merge CI: 33639465987
  • Post-merge CodeQL: 33639464121
  • Binary publication and install verification: 33640448510, attempt 2
  • Serve publication and official install/update verification: 33640447716
  • Published inventory: 28 GitHub assets; both checksum manifests and all 14
    Sigstore bundles independently verified with exact workflow identity,
    repository, ref, trigger, issuer, and source-SHA constraints.

The first binary post-publish attempt reached extension installation before the
parallel Serve workflow had attached SHA256SUMS; rerunning only the failed
post-publish jobs after Serve publication passed on all three supported targets.
No npm, Homebrew, or crates.io publication job ran.