Repository navigation
Releases: tosin2013/local-knowledge-vault
Releases · tosin2013/local-knowledge-vault
Release list
v0.3.0 — Answer quality & robustness
v0.3.0 — Answer quality & robustness
Better answers, a real first-run experience, and bulk import of your existing notes.
Answer quality
- Citations you can trust. Citation markers for notes that weren't retrieved are stripped from the answer, and an answer that cites no note is labelled as possibly ungrounded. (#38)
- Numbered inline citations. Valid
[itm_…]markers render as clickable[1],[2]links that open the note, with matching numbered chips. (#129) - Better retrieval. Stopwords are dropped so off-topic questions get "I couldn't find that in your notes" instead of an answer built on irrelevant passages. Search now uses the trigram tokenizer, which adds substring and CJK matching. (#37)
- Strong matches are no longer dropped. A scoring filter introduced with the retrieval work removed the best-matching notes as a vault grew; it is gone, and repeated words across chat turns now count once. (#196)
- Ollama context sizing. The context window is sized from the prompt, history is capped, and reasoning tokens no longer leak into answers. (#36)
Import and onboarding
- Import Markdown / Obsidian notes from a folder: reads YAML frontmatter, infers title, group and project, and normalizes wiki-links. (#190)
- Vault guide. First run seeds a "Vault guide" project whose notes teach the app with its own concepts, and Ask starts scoped to it. Remove it in one click; it never comes back. (#139, #163)
- New project action in the notes rail, and a "Create your first note" prompt when the vault is empty. (#163, #189)
- Simple mode now shows URL import, Settings and Media chat. (#130)
Robustness
- A late reply can no longer overwrite a different chat you've switched to, and Send can't fire twice. (#39)
- Sending shows your message immediately with an "Answering from your notes…" placeholder; a failed send restores your question. Media ingest shows progress and can be cancelled. (#128)
- A render error shows a fallback instead of a blank window; save/delete failures surface a visible error; chat replies are announced to screen readers. (#40)
- Versioned database migrations. Deleting every sample note no longer brings them back on relaunch. (#41)
- MCP OAuth now goes through the MCP SDK's auth provider, following the MCP authorization spec. (#103)
Full changelog: v0.2.0...v0.3.0
What's Changed
- Add SECURITY.md with private vulnerability reporting (#172) by @tosin2013 in #173
- security: Add SSRF protection for Add from URL feature by @tosin2013 in #174
- security: bound zip decompression to stop zip bombs crashing main process by @tosin2013 in #175
- security: restrict MCP OAuth endpoints to http(s) schemes by @tosin2013 in #176
- security: stop trusting renderer-supplied filesystem paths by @tosin2013 in #177
- test: cover the renderer filesystem-path guards (patch coverage) by @tosin2013 in #178
- security: encrypt API keys and OAuth tokens with safeStorage by @tosin2013 in #179
- fix: answer quality — citations, Ollama context, and FTS retrieval (#36, #37, #38) by @tosin2013 in #180
- chore: bump version to 0.2.0 (#181) by @tosin2013 in #182
- Chat: guard late replies by session and add per-action send busy by @tosin2013 in #183
- Renderer error handling: ErrorBoundary, catches, aria-live by @tosin2013 in #184
- DB: versioned migrations and a sample-seed flag by @tosin2013 in #185
- Chat: render valid [itm_…] markers as numbered inline citations by @tosin2013 in #186
- Onboarding: seed samples into a Getting started project with Remove samples by @tosin2013 in #187
- UX: surface URL import, Settings, and Media chat in Simple mode by @tosin2013 in #188
- Ask & Media chat: answering feedback, restore input, ingest progress/cancel by @tosin2013 in #191
- MCP: use the SDK's authProvider for OAuth by @tosin2013 in #192
- Import Markdown / Obsidian notes from a folder (#190) by @tosin2013 in #193
- Notes rail: 'Create your first note' empty state (#189) by @tosin2013 in #194
- Search: remove the inverted BM25 floor and dedupe query terms (#196) by @tosin2013 in #197
- Onboarding: Vault guide, New project, and a default project (#163) by @tosin2013 in #195
- chore(release): v0.3.0 — Answer quality & robustness (#198) by @tosin2013 in #199
v0.2.0 — Security follow-ups
v0.2.0 — Security follow-ups
This release closes the security follow-ups found after v0.1.0. Upgrading is recommended.
Security
- Secrets are now encrypted at rest with Electron
safeStorage(macOS Keychain, Windows DPAPI, Linux libsecret/kwallet). This covers API keys, MCP OAuth tokens and client secrets, and the bridge bearer token. Existing plaintext secrets are still read and are re-encrypted the next time they are written. Where OS encryption isn't available (for example headless Linux), the old owner-only plaintext files are still used. (#35, #179) - Add from URL blocks private and internal addresses (SSRF): loopback, RFC 1918, link-local, multicast and reserved ranges, IPv4 and IPv6. Redirect targets are checked too, and DNS-rebinding protection is included. (#31, #174)
- Plugin install bounds zip decompression, so a zip bomb can no longer crash the main process. (#32, #175)
- MCP OAuth only opens http(s) endpoints; server metadata can no longer launch arbitrary URL schemes. (#33, #176)
- The main process no longer trusts filesystem paths from the renderer (
plugins:installsource, citation-pack output directory); Plugins install only from a file the user picks in the native dialog, or from the bundled examples. Citation packs are saved through the native save dialog. (#34, #177, #178) - Added
SECURITY.mdand enabled private vulnerability reporting. (#172, #173)
Not in this release
The answer-quality fixes (#36–#38, #180) are on main and will ship with v0.3.0.
Full changelog: v0.1.0...v0.2.0
What's Changed
- Add SECURITY.md with private vulnerability reporting (#172) by @tosin2013 in #173
- security: Add SSRF protection for Add from URL feature by @tosin2013 in #174
- security: bound zip decompression to stop zip bombs crashing main process by @tosin2013 in #175
- security: restrict MCP OAuth endpoints to http(s) schemes by @tosin2013 in #176
- security: stop trusting renderer-supplied filesystem paths by @tosin2013 in #177
- test: cover the renderer filesystem-path guards (patch coverage) by @tosin2013 in #178
- security: encrypt API keys and OAuth tokens with safeStorage by @tosin2013 in #179
v0.1.0
What's Changed
- Bump typescript from 5.9.3 to 7.0.2 by @dependabot[bot] in #3
- Bump vite-plugin-electron-renderer from 0.14.7 to 1.0.0 by @dependabot[bot] in #7
- Linux .rpm/.snap packages and Dependabot auto-merge policy by @tosin2013 in #11
- Upgrade Electron 33 → 44.4.5 (better-sqlite3 13, electron-builder 26) by @tosin2013 in #46
- Media chat: fix YouTube subtitle 429s from the yt-dlp invocation by @tosin2013 in #47
- Bump the react group across 1 directory with 4 updates by @dependabot[bot] in #12
- Media chat: download the original English transcript (en-orig), not YouTube's translation by @tosin2013 in #50
- Fix blank dev-mode renderer: remove vite-plugin-electron-renderer by @tosin2013 in #51
- Media chat: run yt-dlp async so a slow download can't freeze the app by @tosin2013 in #52
- Docs: add CONTRIBUTING.md (branch policy, required checks, governance labels) by @tosin2013 in #55
- Docs: update stack versions (Electron 33 -> 44, React 18 -> 19) by @tosin2013 in #56
- Security: require bearer token on Vault Bridge (#15) by @tosin2013 in #58
- Fix local-first leak: exclude Ollama :cloud models from auto-pick (#16) by @tosin2013 in #59
- Startup: recover from DB init failure with a dialog (#20) by @tosin2013 in #60
- Security: serve media only via registered opaque ids (#18) by @tosin2013 in #61
- Hardening: navigation guards, sandbox, strict production CSP (#17) by @tosin2013 in #62
- Security: validate YouTube URLs before yt-dlp (no arg injection) (#22) by @tosin2013 in #63
- Security: don't send a stored key to a changed baseUrl (#21) by @tosin2013 in #64
- Deduplicate YouTube rolling cues in auto-captions (#29) by @tosin2013 in #66
- Fix YouTube embed error 153 in packaged builds (#24) by @tosin2013 in #65
- Fix re-ingest deleting another project's notes (#28) by @tosin2013 in #67
- Harden caption parsing and companion discovery (#30) by @tosin2013 in #68
- Wire the YouTube IFrame API: seek, playhead, throttled notesNear (#27) by @tosin2013 in #69
- Governance: #30 bar now covers the notesNear throttle by @tosin2013 in #70
- CI: coverage reporting with Codecov by @tosin2013 in #72
- Bump @types/better-sqlite3 from 7.6.13 to 9.6.0 by @dependabot[bot] in #57
- Upgrade Vite 5 → 8: security advisories + coordinated plugin upgrades by @tosin2013 in #73
- Renderer: split App.tsx into feature components and hooks by @tosin2013 in #90
- Tests: end-to-end App flows (Ask, notes rail, note peek, Simple/Advanced) by @tosin2013 in #92
- Tests: speed up App flow tests and raise integration timeout by @tosin2013 in #93
- Tests: AI settings components (ProviderDialog, ProvidersPanel, FirstRunLocalCard, BridgeSettings) by @tosin2013 in #94
- ADR 0001: renderer test harness (#84) by @tosin2013 in #99
- Upgrade Vitest 2 → 4.1.11: removes nested Vite 5, clears Dependabot #54 and #27 (#97) by @tosin2013 in #100
- Renderer coverage: count src/plugins/** instead of excluding it (#96) by @tosin2013 in #101
- Codecov: make the renderer component status blocking (#85) by @tosin2013 in #102
- Tests: MCP client against a mock Streamable-HTTP + OAuth server by @tosin2013 in #104
- Tests: built-in plugin views (MediaChat, McpConnections, MediaPersonas, ManagePlugins, contrib) by @tosin2013 in #105
- Tests: run bridge server smoke in CI and cover ask/error paths by @tosin2013 in #106
- Tests: media personas + persona definitions smoke tests by @tosin2013 in #107
- Tests: IPC handlers (main.ts) and preload surface smoke by @tosin2013 in #108
- Tests: grounding & routing gaps (askGrounded, sendChatTurn, pickModel, stripThinking, FTS) by @tosin2013 in #109
- Tests: URL import against local HTTP fixture server by @tosin2013 in #110
- Tests: media ingest remaining paths (stubbed yt-dlp, re-ingest transaction) by @tosin2013 in #111
- Tests: store and loader edge cases (provider-store, plugin-loader, zip-read, db, user-data) by @tosin2013 in #112
- Tests: provider adapter error paths (anthropic, openai-compatible, http, llm) by @tosin2013 in #113
- Coverage gate: main process ≥ 80% (Codecov component + c8 check) by @tosin2013 in #114
- Coverage gate: whole project ≥ 80%, renderer ≥ 70% (Codecov floors) by @tosin2013 in #115
- Fix YouTube embed in production builds (#116, #117) by @tosin2013 in #118
- Tests: close #43 gaps — stripThinking, tricky FTS, DB init failure; drop stale bundles by @tosin2013 in #140
- Terminology: one user-facing term per concept + glossary by @tosin2013 in #141
- Accessibility & keyboard: labels, F2 edit, live regions, shortcut menu by @tosin2013 in #142
- Projects as first-class entities: list, picker, rename/merge/delete by @tosin2013 in #143
- Personality editor: guidance, starter templates, copyable helper prompt by @tosin2013 in #144
- Reframe Manage plugins as user-facing Add-ons by @tosin2013 in #145
- ADR 0002: layered knowledge model (Sources → Notes → Answers) by @tosin2013 in #148
- Notes-first retrieval: rank user notes above transcript chunks in Ask by @tosin2013 in #149
- Save an answer or video moment as a note (AI draft until confirmed) by @tosin2013 in #150
- Media transcript notes carry the source title by @tosin2013 in #151
- Surface Delete and inline title editing outside Edit mode by @tosin2013 in #152
- Notes rail: hide transcript chunks, filter/sort, Find show-more by @tosin2013 in #153
- Bulk actions + soft-delete Trash for notes by @tosin2013 in #154
- Project filter matches exact project name by @tosin2013 in #155
- Media projects: rename/delete + confirm before re-ingest by @tosin2013 in #156
- Citations to deleted/re-ingested notes show a clear message by @tosin2013 in #157
- Gorgias chat profile only ships when its prompt exists by @tosin2013 in #158
- Decouple the notes-rail project filter from the Ask scope by @tosin2013 in #159
- Ad-hoc sign the macOS build so downloads open (#23) by @tosin2013 in #171
New Contributors
- @dependabot[bot] made their first contribution in #3
Full Changelog: https://github.com/tosin2013/local-knowledge-vault/commits/v0.1.0