Releases: The-40-Thieves/obsidian-tc
Release list
v1.32.0
What's Changed
- feat(admin): session_rerun MCP tool — sandbox-only replay, admin:rerun + confirmation, scopes never widened by @suavecito585 in #1023
- feat(m1): reset_vault_cache include.embeddings accepts "inactive" by @suavecito585 in #1025
- fix(deps): bump fast-uri and moment for GHSA-hrr3-gc8f-f4qj, GHSA-4p3w-j4w9-5jqw by @suavecito585 in #1029
- feat(capture): purge committed capture_queue rows by @suavecito585 in #1026
- feat(release): keyless cosign signatures for release artifacts by @suavecito585 in #1030
- feat(hitl): reject elicit confirmations replayed against drifted state (replay_drift) by @suavecito585 in #1031
- feat(throttle): pluggable rate-limit backends — memory, sqlite, redis by @suavecito585 in #1033
- fix(vault): linear-time link scanner closes a quadratic-regex DoS by @suavecito585 in #1028
- feat(auth): JTI registry, auth rotate-key/list/revoke, per-request revocation check by @suavecito585 in #1032
- fix: isolate server tests from the real HOME; name the file in an invalid-config error by @suavecito585 in #1034
- feat(server): continuation cursor for read_notes instead of an overflow error by @suavecito585 in #1036
- feat(hitl): bind the remaining gated tools' confirmations to target state by @suavecito585 in #1035
- feat(auth): rotation grace default, key reaper, ES256/EdDSA signing keys, JWKS by @suavecito585 in #1037
- test(perf): robust log-log slope gate for link-scan scaling by @suavecito585 in #1039
- feat(m1): read_resources, a batch resources/read with byte-budget paging by @suavecito585 in #1038
- feat(search): search_and_read returns the top-k full notes in one call by @suavecito585 in #1041
- feat(auth): oidc mode verifies tokens from an external OpenID Connect provider by @suavecito585 in #1040
- feat(memory): sweep orphan memory rows on a schedule by @suavecito585 in #1044
- feat(m4): show_file_in_obsidian opens a note in the running Obsidian app by @suavecito585 in #1043
- fix(deps): bump urllib3 to 2.8.0 in bge-m3-service lock by @suavecito585 in #1046
- feat(morgiana): prune the CloudEvents spool by age and size by @suavecito585 in #1045
- feat(otel): child-span hierarchy behind observability.otel.detail by @suavecito585 in #1047
- fix(acl): search and enumeration results honor a path's rule-scopes by @suavecito585 in #1042
- docs: a generated reference page per MCP tool (built at docs build time) by @suavecito585 in #1050
- feat(m4): get/update/append/patch/delete_active_file act on the note open in Obsidian by @suavecito585 in #1049
- chore: stop generated-file conflicts between PRs by @suavecito585 in #1051
- fix(db): serialize migration check-and-apply across processes (cold-boot race) by @suavecito585 in #1052
- feat(attachments): write_attachment tool for binary attachments by @suavecito585 in #1048
- ci: move CodeQL to advanced setup so it can run on merge_group by @suavecito585 in #1054
- feat(retrieval): stat-conditional retrieval defaults behind retrieval.derivedDefaults (off by default) by @suavecito585 in #1053
- feat(mcp): give every tool a tag set from one vocabulary by @suavecito585 in #1055
- fix(auth): close four auth residuals (hardened requireJti, JWKS cache bound, uniform algorithms, log text) by @suavecito585 in #1056
- fix(db): retry transient SQLITE_IOERR_TRUNCATE on the Windows WAL conversion by @suavecito585 in #1057
- feat(facade): toolFacade.explainAutoMode explains the auto-mode decision by @suavecito585 in #1059
- feat(tags): suggest_tags, the first consumer of MCP sampling by @suavecito585 in #1060
- fix(security): harden write tools against hostile names, planted symlinks and create races by @suavecito585 in #1058
- feat(reflect): citation_style and detail arguments, per-vault defaults by @suavecito585 in #1061
- docs: update stale preference-key blockers and capture defaults by @suavecito585 in #1062
- feat(hitl): record confirmation outcomes as codes; doctor reports them by @suavecito585 in #1063
- test: share one multi-size slope helper for the scaling assertions by @suavecito585 in #1064
- test(perf): size Windows budgets for the perf-harness tests against runner stalls by @suavecito585 in #1065
- feat(search): read preferred.search_mode in search_vault behind retrieval.useSearchModePreference (off) by @suavecito585 in #1066
- fix(perf): judge boot.tools_registered against registered-tools.txt, not the recorded baseline by @suavecito585 in #1067
- test: size every spawn test's budgets against a Windows runner stall by @suavecito585 in #1069
- feat(tools): shared response_format (concise|detailed) with a config default (part 1 of #1027) by @suavecito585 in #1068
- feat(provenance): signed, hash-chained write provenance (part A) by @suavecito585 in #1070
- test: spawn stall-budget guard reads the syntax tree, not lines by @suavecito585 in #1071
- test: pin tools/list and initialize instructions byte-stable across restarts by @suavecito585 in #1072
- feat(tools): response_format on resource reads, links, frontmatter and listings (part 2 of #1027) by @suavecito585 in #1074
- test: contain and gate temp-dir leaks in the vitest and scripts suites by @suavecito585 in #1073
- feat(provenance): optional commit-trailer and frontmatter stamps (part C) by @suavecito585 in #1076
- feat(tools): response_format on list tools, search_and_read, graph search, memory and episode reads (part 3 of #1027) by @suavecito585 in #1075
- fix(vault-lock): compare lock file dev/inode exactly so Windows file ids survive by @suavecito585 in #1078
- perf: measure retrieval.cache on a real vault; it stays off by @suavecito585 in #1079
- chore: release fills each changes fragment's PR number from merge history by @suavecito585 in #1080
- feat(provenance): get_provenance, a per-note signed write history query (part B) by @suavecito585 in #1077
- feat(search): retrieval.searchAutoRoute fuses auto's text and semantic legs (off by default) by @suavecito585 in #1081
- feat(tools): response_format on knowledge reads, bundles and the canvas reader; review 40 more tools (part 4a of #1027) by @suavecito585 in #1083
- fix(memory): memory read tools honor the caller's folder read ACL by @suavecito585 in #1082
- feat(response-format): part 4b closes the decision list, 10 more aware tools, 55 exempt by @suavecito585 in #1086
- fix(capture): captures follow the folder read ACL of the notes they name by @suavecito585 in #1085
- docs: cloud agent environment setup in AGENTS.md by @suavecito585 in #1087
- fix(memory): memory writes require the projection path's write ACL in both modes by @suavecito585 in #1084
- fix(metrics): require admin:metrics and an unbound token for remote /metrics by @suavecito585 in #1088
- chore: bump @modelcontextprotocol/server to 2.2.0 by @suavecito585 in #10...
TC Bridge 1.32.0 (companion plugin)
TC Bridge (Obsidian companion plugin) build for manifest version 1.32.0, mirrored automatically from the signed release v1.32.0.
This tag ("1.32.0", no "v" prefix) exists only to satisfy Obsidian's community-directory rule that a plugin release's tag equal manifest.json's version — every other obsidian-tc release stays tagged v1.32.0. It carries the identical three plugin assets (main.js, manifest.json, styles.css) already attached to that release, each with its keyless cosign bundle (.sigstore.json; see SECURITY.md, "Verifying release artifacts").
Unlike v1.32.0, this tag is UNSIGNED: CI holds no maintainer signing key (see docs/RELEASE-SIGNING.md), so it cannot carry a verify-tag signature the way an annotated v* tag can once a key is configured. Treat v1.32.0 as the authoritative, signed release.
v1.31.8
What's Changed
- feat(setup): --install-client grok, verified end-to-end against the Grok CLI by @suavecito585 in #1021
- fix(runtime): stdin EOF no longer stops an HTTP-serving process by @suavecito585 in #1020
- chore(release): 1.31.8 by @suavecito585 in #1022
Full Changelog: 1.31.7...v1.31.8
TC Bridge 1.31.8 (companion plugin)
TC Bridge (Obsidian companion plugin) build for manifest version 1.31.8, mirrored automatically from the signed release v1.31.8.
This tag ("1.31.8", no "v" prefix) exists only to satisfy Obsidian's community-directory rule that a plugin release's tag equal manifest.json's version — every other obsidian-tc release stays tagged v1.31.8. It carries the identical three plugin assets (main.js, manifest.json, styles.css) already attached to that release.
Unlike v1.31.8, this tag is UNSIGNED: CI holds no maintainer signing key (see docs/RELEASE-SIGNING.md), so it cannot carry a verify-tag signature the way an annotated v* tag can once a key is configured. Treat v1.31.8 as the authoritative, signed release.
v1.31.7
What's Changed
- fix(cli): setup hardening — re-validate existing vaults, atomic Windows force-write, marker-path test coverage by @suavecito585 in #1013
- fix(index): stable vault identity — rename-safe index rows, no cross-vault sharing by @suavecito585 in #1014
- fix(memory): extend memoryDefense to note writers, sessions and importers (#994 follow-up) by @suavecito585 in #1015
- fix(index): fence index writes at commit time — no stale overwrite or resurrection across processes by @suavecito585 in #1016
- fix(security): memoryDefense covers every note writer via the shared write primitive by @suavecito585 in #1017
- fix(security): memoryDefense closes split, partial-rewrite and invisible-codepoint gaps by @suavecito585 in #1018
- chore(release): 1.31.7 by @suavecito585 in #1019
Full Changelog: 1.31.6...v1.31.7
TC Bridge 1.31.7 (companion plugin)
TC Bridge (Obsidian companion plugin) build for manifest version 1.31.7, mirrored automatically from the signed release v1.31.7.
This tag ("1.31.7", no "v" prefix) exists only to satisfy Obsidian's community-directory rule that a plugin release's tag equal manifest.json's version — every other obsidian-tc release stays tagged v1.31.7. It carries the identical three plugin assets (main.js, manifest.json, styles.css) already attached to that release.
Unlike v1.31.7, this tag is UNSIGNED: CI holds no maintainer signing key (see docs/RELEASE-SIGNING.md), so it cannot carry a verify-tag signature the way an annotated v* tag can once a key is configured. Treat v1.31.7 as the authoritative, signed release.
v1.31.6
What's Changed
- Fix repository.url shape in embedder-local/reranker-local package.json by @suavecito585 in #990
- ci(publish): widen registry propagation wait with backoff by @suavecito585 in #992
- fix(sessions): break started_at ties in the active-session resolver by @suavecito585 in #993
- fix(scripts): name offending files on comment-style ratchet failure by @suavecito585 in #991
- fix(runtime): bounded shutdown — abort the boot embed on SIGTERM and stdin EOF (#995) by @suavecito585 in #997
- fix(embedder,reranker): cap ONNX threads and disable spinning by default (#995) by @suavecito585 in #996
- fix(embeddings): keep an existing index's provider on upgrade; explicit opt-in to local (#995) by @suavecito585 in #999
- feat(memory): opt-in memoryDefense secret scan on memory writers (#994) by @suavecito585 in #1000
- fix(runtime): one indexing leader per vault across stdio processes (#995) by @suavecito585 in #998
- chore: trim comment prose back under the comment-style threshold (baseline 37 → 34) by @suavecito585 in #1002
- feat(indexing): defer the boot re-embed while tool calls are in flight (#995) by @suavecito585 in #1003
- docs: run one shared obsidian-tc for several MCP clients by @suavecito585 in #1004
- feat(cli): obsidian-tc setup — detect the environment once and write an explicit config by @suavecito585 in #1001
- fix(deps): bump ip-address to >=10.5.1 (two medium advisories) by @suavecito585 in #1006
- feat(cli): first-run setup fallback and opt-in MCP client install by @suavecito585 in #1005
- fix(cli): first-run setup follow-ups — help flag, provenance, PowerShell quoting, race hardening by @suavecito585 in #1007
- feat(cli): setup --install-client for Codex, ChatGPT, Antigravity and Hermes Agent by @suavecito585 in #1008
- feat(cli): setup --install-client for VS Code, opencode, Windsurf, Zed, Gemini CLI and more by @suavecito585 in #1009
- feat(cli): setup --install-client for Cline, Roo Code, Continue, Goose, Amazon Q, Kiro and more by @suavecito585 in #1010
- fix(runtime): deterministic vault-lock keepalive tests on Windows by @suavecito585 in #1012
- chore(release): 1.31.6 by @suavecito585 in #1011
Full Changelog: 1.31.5...v1.31.6
TC Bridge 1.31.6 (companion plugin)
TC Bridge (Obsidian companion plugin) build for manifest version 1.31.6, mirrored automatically from the signed release v1.31.6.
This tag ("1.31.6", no "v" prefix) exists only to satisfy Obsidian's community-directory rule that a plugin release's tag equal manifest.json's version — every other obsidian-tc release stays tagged v1.31.6. It carries the identical three plugin assets (main.js, manifest.json, styles.css) already attached to that release.
Unlike v1.31.6, this tag is UNSIGNED: CI holds no maintainer signing key (see docs/RELEASE-SIGNING.md), so it cannot carry a verify-tag signature the way an annotated v* tag can once a key is configured. Treat v1.31.6 as the authoritative, signed release.
v1.31.5
What's Changed
- fix(sessions): bound explicit sessions — resolver bound, absolute lifetime, stale-session visibility (THE-1108) by @suavecito585 in #988
- chore(release): 1.31.5 by @suavecito585 in #989
Full Changelog: 1.31.4...v1.31.5
TC Bridge 1.31.5 (companion plugin)
TC Bridge (Obsidian companion plugin) build for manifest version 1.31.5, mirrored automatically from the signed release v1.31.5.
This tag ("1.31.5", no "v" prefix) exists only to satisfy Obsidian's community-directory rule that a plugin release's tag equal manifest.json's version — every other obsidian-tc release stays tagged v1.31.5. It carries the identical three plugin assets (main.js, manifest.json, styles.css) already attached to that release.
Unlike v1.31.5, this tag is UNSIGNED: CI holds no maintainer signing key (see docs/RELEASE-SIGNING.md), so it cannot carry a verify-tag signature the way an annotated v* tag can once a key is configured. Treat v1.31.5 as the authoritative, signed release.