Skip to content

Releases: The-40-Thieves/obsidian-tc

v1.32.0

Choose a tag to compare

@github-actions github-actions released this 03 Oct 21:19
v1.32.0
31a2b44

What's Changed

  • feat(admin): session_rerun MCP tool — sandbox-only replay, admin:rerun + confirmation, scopes never widened by @suavecito585 in #1023
  • feat(m1): reset_vault_cache include.embeddings accepts "inactive" by @suavecito585 in #1025
  • fix(deps): bump fast-uri and moment for GHSA-hrr3-gc8f-f4qj, GHSA-4p3w-j4w9-5jqw by @suavecito585 in #1029
  • feat(capture): purge committed capture_queue rows by @suavecito585 in #1026
  • feat(release): keyless cosign signatures for release artifacts by @suavecito585 in #1030
  • feat(hitl): reject elicit confirmations replayed against drifted state (replay_drift) by @suavecito585 in #1031
  • feat(throttle): pluggable rate-limit backends — memory, sqlite, redis by @suavecito585 in #1033
  • fix(vault): linear-time link scanner closes a quadratic-regex DoS by @suavecito585 in #1028
  • feat(auth): JTI registry, auth rotate-key/list/revoke, per-request revocation check by @suavecito585 in #1032
  • fix: isolate server tests from the real HOME; name the file in an invalid-config error by @suavecito585 in #1034
  • feat(server): continuation cursor for read_notes instead of an overflow error by @suavecito585 in #1036
  • feat(hitl): bind the remaining gated tools' confirmations to target state by @suavecito585 in #1035
  • feat(auth): rotation grace default, key reaper, ES256/EdDSA signing keys, JWKS by @suavecito585 in #1037
  • test(perf): robust log-log slope gate for link-scan scaling by @suavecito585 in #1039
  • feat(m1): read_resources, a batch resources/read with byte-budget paging by @suavecito585 in #1038
  • feat(search): search_and_read returns the top-k full notes in one call by @suavecito585 in #1041
  • feat(auth): oidc mode verifies tokens from an external OpenID Connect provider by @suavecito585 in #1040
  • feat(memory): sweep orphan memory rows on a schedule by @suavecito585 in #1044
  • feat(m4): show_file_in_obsidian opens a note in the running Obsidian app by @suavecito585 in #1043
  • fix(deps): bump urllib3 to 2.8.0 in bge-m3-service lock by @suavecito585 in #1046
  • feat(morgiana): prune the CloudEvents spool by age and size by @suavecito585 in #1045
  • feat(otel): child-span hierarchy behind observability.otel.detail by @suavecito585 in #1047
  • fix(acl): search and enumeration results honor a path's rule-scopes by @suavecito585 in #1042
  • docs: a generated reference page per MCP tool (built at docs build time) by @suavecito585 in #1050
  • feat(m4): get/update/append/patch/delete_active_file act on the note open in Obsidian by @suavecito585 in #1049
  • chore: stop generated-file conflicts between PRs by @suavecito585 in #1051
  • fix(db): serialize migration check-and-apply across processes (cold-boot race) by @suavecito585 in #1052
  • feat(attachments): write_attachment tool for binary attachments by @suavecito585 in #1048
  • ci: move CodeQL to advanced setup so it can run on merge_group by @suavecito585 in #1054
  • feat(retrieval): stat-conditional retrieval defaults behind retrieval.derivedDefaults (off by default) by @suavecito585 in #1053
  • feat(mcp): give every tool a tag set from one vocabulary by @suavecito585 in #1055
  • fix(auth): close four auth residuals (hardened requireJti, JWKS cache bound, uniform algorithms, log text) by @suavecito585 in #1056
  • fix(db): retry transient SQLITE_IOERR_TRUNCATE on the Windows WAL conversion by @suavecito585 in #1057
  • feat(facade): toolFacade.explainAutoMode explains the auto-mode decision by @suavecito585 in #1059
  • feat(tags): suggest_tags, the first consumer of MCP sampling by @suavecito585 in #1060
  • fix(security): harden write tools against hostile names, planted symlinks and create races by @suavecito585 in #1058
  • feat(reflect): citation_style and detail arguments, per-vault defaults by @suavecito585 in #1061
  • docs: update stale preference-key blockers and capture defaults by @suavecito585 in #1062
  • feat(hitl): record confirmation outcomes as codes; doctor reports them by @suavecito585 in #1063
  • test: share one multi-size slope helper for the scaling assertions by @suavecito585 in #1064
  • test(perf): size Windows budgets for the perf-harness tests against runner stalls by @suavecito585 in #1065
  • feat(search): read preferred.search_mode in search_vault behind retrieval.useSearchModePreference (off) by @suavecito585 in #1066
  • fix(perf): judge boot.tools_registered against registered-tools.txt, not the recorded baseline by @suavecito585 in #1067
  • test: size every spawn test's budgets against a Windows runner stall by @suavecito585 in #1069
  • feat(tools): shared response_format (concise|detailed) with a config default (part 1 of #1027) by @suavecito585 in #1068
  • feat(provenance): signed, hash-chained write provenance (part A) by @suavecito585 in #1070
  • test: spawn stall-budget guard reads the syntax tree, not lines by @suavecito585 in #1071
  • test: pin tools/list and initialize instructions byte-stable across restarts by @suavecito585 in #1072
  • feat(tools): response_format on resource reads, links, frontmatter and listings (part 2 of #1027) by @suavecito585 in #1074
  • test: contain and gate temp-dir leaks in the vitest and scripts suites by @suavecito585 in #1073
  • feat(provenance): optional commit-trailer and frontmatter stamps (part C) by @suavecito585 in #1076
  • feat(tools): response_format on list tools, search_and_read, graph search, memory and episode reads (part 3 of #1027) by @suavecito585 in #1075
  • fix(vault-lock): compare lock file dev/inode exactly so Windows file ids survive by @suavecito585 in #1078
  • perf: measure retrieval.cache on a real vault; it stays off by @suavecito585 in #1079
  • chore: release fills each changes fragment's PR number from merge history by @suavecito585 in #1080
  • feat(provenance): get_provenance, a per-note signed write history query (part B) by @suavecito585 in #1077
  • feat(search): retrieval.searchAutoRoute fuses auto's text and semantic legs (off by default) by @suavecito585 in #1081
  • feat(tools): response_format on knowledge reads, bundles and the canvas reader; review 40 more tools (part 4a of #1027) by @suavecito585 in #1083
  • fix(memory): memory read tools honor the caller's folder read ACL by @suavecito585 in #1082
  • feat(response-format): part 4b closes the decision list, 10 more aware tools, 55 exempt by @suavecito585 in #1086
  • fix(capture): captures follow the folder read ACL of the notes they name by @suavecito585 in #1085
  • docs: cloud agent environment setup in AGENTS.md by @suavecito585 in #1087
  • fix(memory): memory writes require the projection path's write ACL in both modes by @suavecito585 in #1084
  • fix(metrics): require admin:metrics and an unbound token for remote /metrics by @suavecito585 in #1088
  • chore: bump @modelcontextprotocol/server to 2.2.0 by @suavecito585 in #10...
Read more

TC Bridge 1.32.0 (companion plugin)

Choose a tag to compare

@suavecito585 suavecito585 released this 03 Oct 21:20
31a2b44

TC Bridge (Obsidian companion plugin) build for manifest version 1.32.0, mirrored automatically from the signed release v1.32.0.

This tag ("1.32.0", no "v" prefix) exists only to satisfy Obsidian's community-directory rule that a plugin release's tag equal manifest.json's version — every other obsidian-tc release stays tagged v1.32.0. It carries the identical three plugin assets (main.js, manifest.json, styles.css) already attached to that release, each with its keyless cosign bundle (.sigstore.json; see SECURITY.md, "Verifying release artifacts").

Unlike v1.32.0, this tag is UNSIGNED: CI holds no maintainer signing key (see docs/RELEASE-SIGNING.md), so it cannot carry a verify-tag signature the way an annotated v* tag can once a key is configured. Treat v1.32.0 as the authoritative, signed release.

v1.31.8

Choose a tag to compare

@github-actions github-actions released this 29 Sep 09:34
v1.31.8
467a023

What's Changed

Full Changelog: 1.31.7...v1.31.8

TC Bridge 1.31.8 (companion plugin)

Choose a tag to compare

@github-actions github-actions released this 29 Sep 09:34
467a023

TC Bridge (Obsidian companion plugin) build for manifest version 1.31.8, mirrored automatically from the signed release v1.31.8.

This tag ("1.31.8", no "v" prefix) exists only to satisfy Obsidian's community-directory rule that a plugin release's tag equal manifest.json's version — every other obsidian-tc release stays tagged v1.31.8. It carries the identical three plugin assets (main.js, manifest.json, styles.css) already attached to that release.

Unlike v1.31.8, this tag is UNSIGNED: CI holds no maintainer signing key (see docs/RELEASE-SIGNING.md), so it cannot carry a verify-tag signature the way an annotated v* tag can once a key is configured. Treat v1.31.8 as the authoritative, signed release.

v1.31.7

Choose a tag to compare

@github-actions github-actions released this 29 Sep 08:11
v1.31.7
1f554e5

What's Changed

  • fix(cli): setup hardening — re-validate existing vaults, atomic Windows force-write, marker-path test coverage by @suavecito585 in #1013
  • fix(index): stable vault identity — rename-safe index rows, no cross-vault sharing by @suavecito585 in #1014
  • fix(memory): extend memoryDefense to note writers, sessions and importers (#994 follow-up) by @suavecito585 in #1015
  • fix(index): fence index writes at commit time — no stale overwrite or resurrection across processes by @suavecito585 in #1016
  • fix(security): memoryDefense covers every note writer via the shared write primitive by @suavecito585 in #1017
  • fix(security): memoryDefense closes split, partial-rewrite and invisible-codepoint gaps by @suavecito585 in #1018
  • chore(release): 1.31.7 by @suavecito585 in #1019

Full Changelog: 1.31.6...v1.31.7

TC Bridge 1.31.7 (companion plugin)

Choose a tag to compare

@github-actions github-actions released this 29 Sep 08:11
1f554e5

TC Bridge (Obsidian companion plugin) build for manifest version 1.31.7, mirrored automatically from the signed release v1.31.7.

This tag ("1.31.7", no "v" prefix) exists only to satisfy Obsidian's community-directory rule that a plugin release's tag equal manifest.json's version — every other obsidian-tc release stays tagged v1.31.7. It carries the identical three plugin assets (main.js, manifest.json, styles.css) already attached to that release.

Unlike v1.31.7, this tag is UNSIGNED: CI holds no maintainer signing key (see docs/RELEASE-SIGNING.md), so it cannot carry a verify-tag signature the way an annotated v* tag can once a key is configured. Treat v1.31.7 as the authoritative, signed release.

v1.31.6

Choose a tag to compare

@github-actions github-actions released this 29 Sep 01:18
v1.31.6
c466176

What's Changed

  • Fix repository.url shape in embedder-local/reranker-local package.json by @suavecito585 in #990
  • ci(publish): widen registry propagation wait with backoff by @suavecito585 in #992
  • fix(sessions): break started_at ties in the active-session resolver by @suavecito585 in #993
  • fix(scripts): name offending files on comment-style ratchet failure by @suavecito585 in #991
  • fix(runtime): bounded shutdown — abort the boot embed on SIGTERM and stdin EOF (#995) by @suavecito585 in #997
  • fix(embedder,reranker): cap ONNX threads and disable spinning by default (#995) by @suavecito585 in #996
  • fix(embeddings): keep an existing index's provider on upgrade; explicit opt-in to local (#995) by @suavecito585 in #999
  • feat(memory): opt-in memoryDefense secret scan on memory writers (#994) by @suavecito585 in #1000
  • fix(runtime): one indexing leader per vault across stdio processes (#995) by @suavecito585 in #998
  • chore: trim comment prose back under the comment-style threshold (baseline 37 → 34) by @suavecito585 in #1002
  • feat(indexing): defer the boot re-embed while tool calls are in flight (#995) by @suavecito585 in #1003
  • docs: run one shared obsidian-tc for several MCP clients by @suavecito585 in #1004
  • feat(cli): obsidian-tc setup — detect the environment once and write an explicit config by @suavecito585 in #1001
  • fix(deps): bump ip-address to >=10.5.1 (two medium advisories) by @suavecito585 in #1006
  • feat(cli): first-run setup fallback and opt-in MCP client install by @suavecito585 in #1005
  • fix(cli): first-run setup follow-ups — help flag, provenance, PowerShell quoting, race hardening by @suavecito585 in #1007
  • feat(cli): setup --install-client for Codex, ChatGPT, Antigravity and Hermes Agent by @suavecito585 in #1008
  • feat(cli): setup --install-client for VS Code, opencode, Windsurf, Zed, Gemini CLI and more by @suavecito585 in #1009
  • feat(cli): setup --install-client for Cline, Roo Code, Continue, Goose, Amazon Q, Kiro and more by @suavecito585 in #1010
  • fix(runtime): deterministic vault-lock keepalive tests on Windows by @suavecito585 in #1012
  • chore(release): 1.31.6 by @suavecito585 in #1011

Full Changelog: 1.31.5...v1.31.6

TC Bridge 1.31.6 (companion plugin)

Choose a tag to compare

@github-actions github-actions released this 29 Sep 01:18
c466176

TC Bridge (Obsidian companion plugin) build for manifest version 1.31.6, mirrored automatically from the signed release v1.31.6.

This tag ("1.31.6", no "v" prefix) exists only to satisfy Obsidian's community-directory rule that a plugin release's tag equal manifest.json's version — every other obsidian-tc release stays tagged v1.31.6. It carries the identical three plugin assets (main.js, manifest.json, styles.css) already attached to that release.

Unlike v1.31.6, this tag is UNSIGNED: CI holds no maintainer signing key (see docs/RELEASE-SIGNING.md), so it cannot carry a verify-tag signature the way an annotated v* tag can once a key is configured. Treat v1.31.6 as the authoritative, signed release.

v1.31.5

Choose a tag to compare

@github-actions github-actions released this 26 Sep 17:54
v1.31.5
6f100f3

What's Changed

  • fix(sessions): bound explicit sessions — resolver bound, absolute lifetime, stale-session visibility (THE-1108) by @suavecito585 in #988
  • chore(release): 1.31.5 by @suavecito585 in #989

Full Changelog: 1.31.4...v1.31.5

TC Bridge 1.31.5 (companion plugin)

Choose a tag to compare

@github-actions github-actions released this 26 Sep 17:54
6f100f3

TC Bridge (Obsidian companion plugin) build for manifest version 1.31.5, mirrored automatically from the signed release v1.31.5.

This tag ("1.31.5", no "v" prefix) exists only to satisfy Obsidian's community-directory rule that a plugin release's tag equal manifest.json's version — every other obsidian-tc release stays tagged v1.31.5. It carries the identical three plugin assets (main.js, manifest.json, styles.css) already attached to that release.

Unlike v1.31.5, this tag is UNSIGNED: CI holds no maintainer signing key (see docs/RELEASE-SIGNING.md), so it cannot carry a verify-tag signature the way an annotated v* tag can once a key is configured. Treat v1.31.5 as the authoritative, signed release.