Skip to content

Flowlight 0.9.3

Choose a tag to compare

@github-actions github-actions released this 28 Sep 02:53
· 38 commits to main since this release

What's new in 0.9.3

  • A budget for HTTPS inspection. Recorded bodies are the most sensitive thing Flowlight holds, and what protected them was a guess at which headers carry credentials. A guess is the wrong shape for this: it can only know the headers somebody thought of, and when it is wrong it writes a secret to disk under a promise that it wouldn't. Headers are now kept because they are on a list, not discarded because they looked dangerous. The old behaviour is still offered — reading an unfamiliar API means seeing headers nobody has allowed yet — and a third option keeps no header values at all. Whatever you choose, header names and value lengths survive. Hiding the header altogether would be the quieter lie: it would show a shorter request than the one that actually happened, and nothing on screen would say so.
  • Limits you set, rather than limits you hope for. Words of your own mark a header as a credential whatever a vendor calls it. A daily per-app ceiling caps recorded bodies, and past it the exchange is still recorded — time, host, path, status, headers — with only the bodies dropped and a note saying why. Retention is a setting. And inspection now ends by itself after eight hours, because "until somebody remembers" left the most sensitive mode in the app running long after the reason for it had passed.
  • Two sentences that were not true. The Advanced panel said recorded requests were kept for three days and credential headers were never stored. The period had become a setting, and what happens to a credential is that its length is stored instead. That line is now generated from the settings, so it cannot drift from them again.
  • An agent is no longer renamed by its own updates. Claude Code was appearing as 2.1.260, 2.1.267, 2.1.283 — a new identity on every release, each with its own allowlist, baselines and history. The executable's path names it correctly, but that path cannot be read once a process has exited, and the fallback was the filename — which, for an installer that keeps one file per release, is the version. A version is never accepted as an identity now, the real name is remembered from the times the path was readable, and a one-time repair merges the identities already recorded, adding their traffic together rather than letting one overwrite another.
  • Inspecting one app shows that app. "Inspect …'s Traffic" put the name in the search field, and that search reads response bodies too — so asking for one agent's traffic returned every page whose HTML happened to mention it. It scopes now, with a chip you can remove.

Install

Signed with Developer ID and notarized by Apple.

  • brew install --cask xinbetween/tap/flowlight
  • Flowlight.dmg — drag to Applications.
  • Flowlight-0.9.3.pkg — installs to /Applications; offers to quit a running copy first.

macOS 15 or later, Apple silicon and Intel.

Full changelog: https://github.com/xinbetween/flowlight/releases

Checksums

eb1f8dbcaf1084c1b13cfdb9eb58154349c485cb8c96bb380e01c20fb584a4af  Flowlight.dmg
9874ebce3ba2bd85d73aeede2eb42db9f6a2ee280337ef32918e488071be080f  Flowlight-0.9.3.pkg