Skip to content

Releases: tosin2013/local-knowledge-vault

v0.3.0 — Answer quality & robustness

Choose a tag to compare

@github-actions github-actions released this 01 Oct 16:46
096ed1b

v0.3.0 — Answer quality & robustness

Better answers, a real first-run experience, and bulk import of your existing notes.

Answer quality

  • Citations you can trust. Citation markers for notes that weren't retrieved are stripped from the answer, and an answer that cites no note is labelled as possibly ungrounded. (#38)
  • Numbered inline citations. Valid [itm_…] markers render as clickable [1], [2] links that open the note, with matching numbered chips. (#129)
  • Better retrieval. Stopwords are dropped so off-topic questions get "I couldn't find that in your notes" instead of an answer built on irrelevant passages. Search now uses the trigram tokenizer, which adds substring and CJK matching. (#37)
  • Strong matches are no longer dropped. A scoring filter introduced with the retrieval work removed the best-matching notes as a vault grew; it is gone, and repeated words across chat turns now count once. (#196)
  • Ollama context sizing. The context window is sized from the prompt, history is capped, and reasoning tokens no longer leak into answers. (#36)

Import and onboarding

  • Import Markdown / Obsidian notes from a folder: reads YAML frontmatter, infers title, group and project, and normalizes wiki-links. (#190)
  • Vault guide. First run seeds a "Vault guide" project whose notes teach the app with its own concepts, and Ask starts scoped to it. Remove it in one click; it never comes back. (#139, #163)
  • New project action in the notes rail, and a "Create your first note" prompt when the vault is empty. (#163, #189)
  • Simple mode now shows URL import, Settings and Media chat. (#130)

Robustness

  • A late reply can no longer overwrite a different chat you've switched to, and Send can't fire twice. (#39)
  • Sending shows your message immediately with an "Answering from your notes…" placeholder; a failed send restores your question. Media ingest shows progress and can be cancelled. (#128)
  • A render error shows a fallback instead of a blank window; save/delete failures surface a visible error; chat replies are announced to screen readers. (#40)
  • Versioned database migrations. Deleting every sample note no longer brings them back on relaunch. (#41)
  • MCP OAuth now goes through the MCP SDK's auth provider, following the MCP authorization spec. (#103)

Full changelog: v0.2.0...v0.3.0


What's Changed

  • Add SECURITY.md with private vulnerability reporting (#172) by @tosin2013 in #173
  • security: Add SSRF protection for Add from URL feature by @tosin2013 in #174
  • security: bound zip decompression to stop zip bombs crashing main process by @tosin2013 in #175
  • security: restrict MCP OAuth endpoints to http(s) schemes by @tosin2013 in #176
  • security: stop trusting renderer-supplied filesystem paths by @tosin2013 in #177
  • test: cover the renderer filesystem-path guards (patch coverage) by @tosin2013 in #178
  • security: encrypt API keys and OAuth tokens with safeStorage by @tosin2013 in #179
  • fix: answer quality — citations, Ollama context, and FTS retrieval (#36, #37, #38) by @tosin2013 in #180
  • chore: bump version to 0.2.0 (#181) by @tosin2013 in #182
  • Chat: guard late replies by session and add per-action send busy by @tosin2013 in #183
  • Renderer error handling: ErrorBoundary, catches, aria-live by @tosin2013 in #184
  • DB: versioned migrations and a sample-seed flag by @tosin2013 in #185
  • Chat: render valid [itm_…] markers as numbered inline citations by @tosin2013 in #186
  • Onboarding: seed samples into a Getting started project with Remove samples by @tosin2013 in #187
  • UX: surface URL import, Settings, and Media chat in Simple mode by @tosin2013 in #188
  • Ask & Media chat: answering feedback, restore input, ingest progress/cancel by @tosin2013 in #191
  • MCP: use the SDK's authProvider for OAuth by @tosin2013 in #192
  • Import Markdown / Obsidian notes from a folder (#190) by @tosin2013 in #193
  • Notes rail: 'Create your first note' empty state (#189) by @tosin2013 in #194
  • Search: remove the inverted BM25 floor and dedupe query terms (#196) by @tosin2013 in #197
  • Onboarding: Vault guide, New project, and a default project (#163) by @tosin2013 in #195
  • chore(release): v0.3.0 — Answer quality & robustness (#198) by @tosin2013 in #199

v0.2.0 — Security follow-ups

Choose a tag to compare

@github-actions github-actions released this 30 Sep 16:58

v0.2.0 — Security follow-ups

This release closes the security follow-ups found after v0.1.0. Upgrading is recommended.

Security

  • Secrets are now encrypted at rest with Electron safeStorage (macOS Keychain, Windows DPAPI, Linux libsecret/kwallet). This covers API keys, MCP OAuth tokens and client secrets, and the bridge bearer token. Existing plaintext secrets are still read and are re-encrypted the next time they are written. Where OS encryption isn't available (for example headless Linux), the old owner-only plaintext files are still used. (#35, #179)
  • Add from URL blocks private and internal addresses (SSRF): loopback, RFC 1918, link-local, multicast and reserved ranges, IPv4 and IPv6. Redirect targets are checked too, and DNS-rebinding protection is included. (#31, #174)
  • Plugin install bounds zip decompression, so a zip bomb can no longer crash the main process. (#32, #175)
  • MCP OAuth only opens http(s) endpoints; server metadata can no longer launch arbitrary URL schemes. (#33, #176)
  • The main process no longer trusts filesystem paths from the renderer (plugins:install source, citation-pack output directory); Plugins install only from a file the user picks in the native dialog, or from the bundled examples. Citation packs are saved through the native save dialog. (#34, #177, #178)
  • Added SECURITY.md and enabled private vulnerability reporting. (#172, #173)

Not in this release

The answer-quality fixes (#36–#38, #180) are on main and will ship with v0.3.0.

Full changelog: v0.1.0...v0.2.0


What's Changed

  • Add SECURITY.md with private vulnerability reporting (#172) by @tosin2013 in #173
  • security: Add SSRF protection for Add from URL feature by @tosin2013 in #174
  • security: bound zip decompression to stop zip bombs crashing main process by @tosin2013 in #175
  • security: restrict MCP OAuth endpoints to http(s) schemes by @tosin2013 in #176
  • security: stop trusting renderer-supplied filesystem paths by @tosin2013 in #177
  • test: cover the renderer filesystem-path guards (patch coverage) by @tosin2013 in #178
  • security: encrypt API keys and OAuth tokens with safeStorage by @tosin2013 in #179

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 02:24
d25ae71

What's Changed

  • Bump typescript from 5.9.3 to 7.0.2 by @dependabot[bot] in #3
  • Bump vite-plugin-electron-renderer from 0.14.7 to 1.0.0 by @dependabot[bot] in #7
  • Linux .rpm/.snap packages and Dependabot auto-merge policy by @tosin2013 in #11
  • Upgrade Electron 33 → 44.4.5 (better-sqlite3 13, electron-builder 26) by @tosin2013 in #46
  • Media chat: fix YouTube subtitle 429s from the yt-dlp invocation by @tosin2013 in #47
  • Bump the react group across 1 directory with 4 updates by @dependabot[bot] in #12
  • Media chat: download the original English transcript (en-orig), not YouTube's translation by @tosin2013 in #50
  • Fix blank dev-mode renderer: remove vite-plugin-electron-renderer by @tosin2013 in #51
  • Media chat: run yt-dlp async so a slow download can't freeze the app by @tosin2013 in #52
  • Docs: add CONTRIBUTING.md (branch policy, required checks, governance labels) by @tosin2013 in #55
  • Docs: update stack versions (Electron 33 -> 44, React 18 -> 19) by @tosin2013 in #56
  • Security: require bearer token on Vault Bridge (#15) by @tosin2013 in #58
  • Fix local-first leak: exclude Ollama :cloud models from auto-pick (#16) by @tosin2013 in #59
  • Startup: recover from DB init failure with a dialog (#20) by @tosin2013 in #60
  • Security: serve media only via registered opaque ids (#18) by @tosin2013 in #61
  • Hardening: navigation guards, sandbox, strict production CSP (#17) by @tosin2013 in #62
  • Security: validate YouTube URLs before yt-dlp (no arg injection) (#22) by @tosin2013 in #63
  • Security: don't send a stored key to a changed baseUrl (#21) by @tosin2013 in #64
  • Deduplicate YouTube rolling cues in auto-captions (#29) by @tosin2013 in #66
  • Fix YouTube embed error 153 in packaged builds (#24) by @tosin2013 in #65
  • Fix re-ingest deleting another project's notes (#28) by @tosin2013 in #67
  • Harden caption parsing and companion discovery (#30) by @tosin2013 in #68
  • Wire the YouTube IFrame API: seek, playhead, throttled notesNear (#27) by @tosin2013 in #69
  • Governance: #30 bar now covers the notesNear throttle by @tosin2013 in #70
  • CI: coverage reporting with Codecov by @tosin2013 in #72
  • Bump @types/better-sqlite3 from 7.6.13 to 9.6.0 by @dependabot[bot] in #57
  • Upgrade Vite 5 → 8: security advisories + coordinated plugin upgrades by @tosin2013 in #73
  • Renderer: split App.tsx into feature components and hooks by @tosin2013 in #90
  • Tests: end-to-end App flows (Ask, notes rail, note peek, Simple/Advanced) by @tosin2013 in #92
  • Tests: speed up App flow tests and raise integration timeout by @tosin2013 in #93
  • Tests: AI settings components (ProviderDialog, ProvidersPanel, FirstRunLocalCard, BridgeSettings) by @tosin2013 in #94
  • ADR 0001: renderer test harness (#84) by @tosin2013 in #99
  • Upgrade Vitest 2 → 4.1.11: removes nested Vite 5, clears Dependabot #54 and #27 (#97) by @tosin2013 in #100
  • Renderer coverage: count src/plugins/** instead of excluding it (#96) by @tosin2013 in #101
  • Codecov: make the renderer component status blocking (#85) by @tosin2013 in #102
  • Tests: MCP client against a mock Streamable-HTTP + OAuth server by @tosin2013 in #104
  • Tests: built-in plugin views (MediaChat, McpConnections, MediaPersonas, ManagePlugins, contrib) by @tosin2013 in #105
  • Tests: run bridge server smoke in CI and cover ask/error paths by @tosin2013 in #106
  • Tests: media personas + persona definitions smoke tests by @tosin2013 in #107
  • Tests: IPC handlers (main.ts) and preload surface smoke by @tosin2013 in #108
  • Tests: grounding & routing gaps (askGrounded, sendChatTurn, pickModel, stripThinking, FTS) by @tosin2013 in #109
  • Tests: URL import against local HTTP fixture server by @tosin2013 in #110
  • Tests: media ingest remaining paths (stubbed yt-dlp, re-ingest transaction) by @tosin2013 in #111
  • Tests: store and loader edge cases (provider-store, plugin-loader, zip-read, db, user-data) by @tosin2013 in #112
  • Tests: provider adapter error paths (anthropic, openai-compatible, http, llm) by @tosin2013 in #113
  • Coverage gate: main process ≥ 80% (Codecov component + c8 check) by @tosin2013 in #114
  • Coverage gate: whole project ≥ 80%, renderer ≥ 70% (Codecov floors) by @tosin2013 in #115
  • Fix YouTube embed in production builds (#116, #117) by @tosin2013 in #118
  • Tests: close #43 gaps — stripThinking, tricky FTS, DB init failure; drop stale bundles by @tosin2013 in #140
  • Terminology: one user-facing term per concept + glossary by @tosin2013 in #141
  • Accessibility & keyboard: labels, F2 edit, live regions, shortcut menu by @tosin2013 in #142
  • Projects as first-class entities: list, picker, rename/merge/delete by @tosin2013 in #143
  • Personality editor: guidance, starter templates, copyable helper prompt by @tosin2013 in #144
  • Reframe Manage plugins as user-facing Add-ons by @tosin2013 in #145
  • ADR 0002: layered knowledge model (Sources → Notes → Answers) by @tosin2013 in #148
  • Notes-first retrieval: rank user notes above transcript chunks in Ask by @tosin2013 in #149
  • Save an answer or video moment as a note (AI draft until confirmed) by @tosin2013 in #150
  • Media transcript notes carry the source title by @tosin2013 in #151
  • Surface Delete and inline title editing outside Edit mode by @tosin2013 in #152
  • Notes rail: hide transcript chunks, filter/sort, Find show-more by @tosin2013 in #153
  • Bulk actions + soft-delete Trash for notes by @tosin2013 in #154
  • Project filter matches exact project name by @tosin2013 in #155
  • Media projects: rename/delete + confirm before re-ingest by @tosin2013 in #156
  • Citations to deleted/re-ingested notes show a clear message by @tosin2013 in #157
  • Gorgias chat profile only ships when its prompt exists by @tosin2013 in #158
  • Decouple the notes-rail project filter from the Ask scope by @tosin2013 in #159
  • Ad-hoc sign the macOS build so downloads open (#23) by @tosin2013 in #171

New Contributors

Full Changelog: https://github.com/tosin2013/local-knowledge-vault/commits/v0.1.0