A patch release. The capture daemon and the local server give memory back sooner after a burst of work, the background service starts with the same memory settings as the app, and the local investigation panels say which filters their evidence follows.
Highlights
✓The heap stops growing far past what it holds - The local server, the capture daemon and the nightly scripts now let the heap grow by 20 percent before collecting, instead of V8's default. Before this, the capture daemon held 96.5 MiB of heap with 33 MiB in use after reading its first transcript. (#4802)
✓Free memory goes back after a burst - The capture daemon returns the heap's free pages to the operating system after each cycle, and the local server does the same once it has been idle for 3 seconds and has grown 16 MiB since the last time. Every process also starts with a smaller young generation, and on Linux the daemon hands freed native memory back sooner. Set REPOOPS_HEAP_RELEASE=0 to turn the release off. (#4807)
✓The background service uses the same memory settings - The capture daemon installed as a Windows, macOS or Linux service started without the memory settings the app's own launchers use. It now starts with them, and so does the dashboard login service. (#4804)
✓Investigation panels name their scope - Remediation's summaries follow the environment, service and time range you picked, and machine logs and repository-wide settings say which filters they do not apply. Pages you are not looking at stop polling in the background and release their timers. (#4808, #4809, #4810)
Notes
Installed 0.3.4 asks the update store for one byte range at a time, so the update to 0.3.5 is the first that can download only the changed parts of the installer.
macOS builds are not signed with an Apple Developer ID or notarized. First launch may require right-clicking the app and selecting Open, and macOS may refuse to apply an update until the builds are signed.
Linux keeps your data across an update, and later updates download less
A patch release. On Linux the app reopens on your own data after it updates itself, the desktop app stops writing into its own install folder, and builds from this release can download only the changed parts of the next update.
Highlights
✓Linux reopens on your data after an update - After the AppImage updated itself, the new version added its data folder suffix a second time and opened an empty profile on the sign-in screen until the next launch. It now opens the folder you were using, and a rollback to 0.3.3 does too, because the app now starts the version it installs with the data folder setting it was itself started with. (#4797, #4801)
✓No writes into the install folder - Runtime health samples, the rollup watcher and the marketplace catalog now write to the app's data folder. On Linux the install folder is the AppImage's read-only mount, so each of them logged an error on every tick; on macOS it sits inside the app bundle, and on Windows each update replaces it. (#4800)
✓Smaller downloads from the next update on - The update store answers one byte range per request, and the updater asked for several at once, so every update downloaded the whole installer. Builds from this release ask for one range at a time and fetch only what changed. The updater that runs is the installed one, so the saving starts with the update after 0.3.4. (#4800)
✓Less server memory on Linux - The local server starts with one malloc arena and a thread pool of four, and two routes stop rescanning work the capture daemon has already done. (#4796)
Also in v0.3.4
✓The Tap reaches a restarted browser build - After the browser build's local service restarts, `repoops tap` reads its new launch value and sends the copy again, and a copy that wakes a sleeping server waits for it instead of being dropped. (#4798)
Notes
The smaller downloads apply to updates installed by 0.3.4 or later. Updating from 0.3.3 to 0.3.4 still downloads the whole installer.
macOS builds are not signed with an Apple Developer ID or notarized. First launch may require right-clicking the app and selecting Open, and macOS may refuse to apply an update until the builds are signed.
Six pages that open with data, cost you can check against the bill, and a desktop app that runs lighter
The app is now six primary pages under one scope bar, and each opens with data the capture daemon prepared. A case shows which evidence exists and can fetch what is missing, the cost pages put the provider's bill beside measured spend, and the desktop app stops its server when no window is open, restarts its daemon when it stops, and can roll back.
Highlights
✓Six pages under one scope bar - Today, Attribution, AI Security, Remediation, LLM Cost Metrics and Memory share one bar for repository, environment, service and a time range with a start and an end. The page address keeps it while you move between them, and a copied link opens on the same scope. Pages merged into one of the six are listed under Moved here on that page, grouped by what they do, and old links still open. (#4721, #4731, #4771, #4778, #4786)
✓Pages open with data after a restart - The capture daemon prepares the first reads of the six pages, and each page says how old its data is. On a synthetic 96,000-case store, Today finished loading in 1.1 s instead of 8.2 s. Prepared reads are answered while the server is still booting. (#4718, #4723, #4774)
✓See what evidence a case has, and fetch the rest - Every case lists its evidence (runtime payload, deployment, commits and pull requests, transcript, tool records and more) as captured, partial, unsupported, expired, restricted or not requested. On a managed repository an owner can ask the right installation for what is missing, or for one family such as the tool records alone. Transcripts open as a redacted preview with credentials, tokens, keys and emails masked; reading the original is a separate action that the audit trail records apart. (#4715, #4717, #4750, #4754)
✓Billed beside measured, and a monthly budget - LLM Cost Metrics, in the desktop app and on repoops.ai, shows what the provider billed and what case receipts measured side by side, never added together, and every figure opens the receipts behind it. A Monthly LLM budget in Settings holds Build it, validation runs, the unattended schedules and agent actions that would spend once the month's measured spend reaches it. It does not cap what the provider charges. (#4747, #4748, #4758, #4762)
✓The Brain library - Memory lists the repository's brain documents by kind, with the owner, when each was last verified, its sources and whether it is reviewed, in the desktop app and on repoops.ai. A case's Prevention section lists the documents that name it. (#4755, #4761)
✓A desktop app that runs lighter and recovers - The local server stops ten minutes after the last window closes and starts again when you open one, while the capture daemon keeps capturing and runs the background work your team relies on. The app starts the daemon whenever it is on in Settings and restarts it if it stops. Settings and the tray can roll back to the previous version, and a failed update says why. (#4734, #4738, #4742, #4751)
Also in v0.3.3
✓Security and privacy fixes - A machine bound to a team no longer names unrelated repositories in its health report, and cloud sync turned on by the team's default sends only the repositories whose team policy you accepted. On Windows, the data folder, daemon logs, prepared pages and update store are now limited to your own account; the earlier restriction passed your account to icacls in a form it refused, so it never applied. (#4730, #4737, #4791)
✓Retention you can read - Retention windows can be shortened and never lengthened, Settings shows what each sweep removed, kept and failed on, and a case evidence hold keeps a session's transcript past its window. Events that never reached the cloud are no longer archived where cloud sync cannot read them. (#4722, #4727)
✓Less memory and CPU at idle - A smaller V8 young generation, fewer git processes, a daemon that loads fewer modules and starts with two worker threads, and one malloc arena on Linux. On a ten-repository test set the first-sync memory peak fell from about 810 MiB to between 500 and 560 MiB. (#4725, #4735, #4757, #4768, #4772, #4784, #4787, #4792)
✓Mac updates get the file they need - The macOS builds ship a zip beside each dmg, and the update feed lists it. The updater installs an update or a rollback on a Mac only from a zip, and the feed used to list dmg files alone. (#4741)
✓A smaller installer - The desktop installer keeps one interface language, leaves out server code for retired pages, unused database drivers, source maps and image text recognition (OCR). (#4719, #4741)
✓A browser build, on its own update feed - A preview of RepoOps that runs in your default browser instead of its own window: a small local service starts the dashboard and the capture daemon, and the download is about 30 to 35 MB against about 106 MB for the desktop app. It is published at repoops.ai/updates/lean/ for Windows, macOS (Apple silicon and Intel) and Linux, and updates itself only from manifests signed with the RepoOps release key. Its local service answers only the browser its launcher opened, with a new random value each launch and a sign-in cookie bound to its port. The Download button still gives the desktop app. (#4767, #4770, #4775, #4777, #4779, #4791)
✓Panels say what state they are in - Each evidence panel on the six pages reads current, stale, measured and empty, failed, restricted, or not reported, instead of an empty table or $0.00. (#4740)
Notes
On Windows, the RepoOps data folder, daemon logs, prepared pages and update store now allow your own account only. SYSTEM and the Administrators group lose access, so a backup or security tool that runs as either can no longer read them.
Retention windows only get shorter. A saved 90-day or keep-forever transcript window now runs at 30 days, and the first sweep removes transcript text older than that.
The standard installer no longer includes image text recognition. Image secret scans and Brain image search treat each image as unknown, not clean.
The local server stops ten minutes after the last window closes. Set REPOOPS_DESKTOP_SERVER_IDLE_MIN=0 to keep it running.
macOS builds are not signed with an Apple Developer ID or notarized. First launch may require right-clicking the app and selecting Open, and macOS may refuse to apply an update until the builds are signed.
A focused app that opens incidents where you find them, and keeps capturing when things go wrong
The first published build since 0.3.0. Version 0.3.1 was prepared but never shipped, so its fixes arrive here too. The app now centres on six investigation homes, capture survives stalls, pressure and a dead network, and a restart no longer reloads your whole history.
Highlights
✓Open a case where you find it - Today, AI security, Remediation and the other homes open a case in place with the same seven sections the team page shows: overview, evidence, attribution, security, cost, fix and prevention. (#4469, #4470, #4561)
✓Capture keeps going when something stalls - A wedged publish is stopped at its cap instead of running on, one refused record no longer holds up every event behind it, and under memory or disk pressure the daemon sheds work before it would exit. Today shows the daemon's own memory, lag and cycle numbers. (#4430, #4432, #4433, #4544)
✓The browser extension talks to the app, not to a port - The desktop app registers a signed native messaging host at startup, and the extension sends sessions and health through it. There is no localhost fallback. Its toolbar popup says what was captured, delivered and refused. (#4442, #4443, #4444, #4557)
✓Codex sessions are captured - A capture adapter reads Codex rollouts beside Claude Code transcripts, and each agent attempt keeps who ran it, on whose instruction, and how sure the record is. (#4548, #4596)
✓Team setup you can leave and resume - Six steps, one panel at a time, each read from what exists. A connect code names its team before the machine binds, and each direction of delivery has its own receipt. (#4447, #4546)
✓Less memory, a shorter first run - Route modules load when first used, a restart no longer re-reads all session history (about 190MB resident instead of 495MB on a large repo), and a new install's first trace sync uses about 100MB less. First run no longer asks for a launch plan, and background jobs for retired features stop. (#4696, #4697, #4699, #4702, #4707)
Also in v0.3.2
✓A smaller installer - The OCR builds Node never loads and type declarations are left out, about 37MB. (#4700)
✓The 0.3.1 fixes - The app stops going unresponsive while reading its own records, opening a trace reads only the days that hold it, and the logged memory limit is the real one. (#4398, #4399, #4401, #4402, #4404, #4406)
✓Managed repositories report their capture coverage - For a repository with a managed policy, the app tells your team which capture adapters it runs, which tool sessions it cannot read, and how long evidence has waited to upload, so the team's required GitHub check can say why a pull request falls short. (#4701, #4706)
✓Production sources read further and fail by name - Sentry, Vercel and PostHog reads walk past the first page, honor Retry-After, and name a revoked credential or a missing scope instead of a bare failure. (#4545)
Notes
0.3.1 was never published. Updating from 0.3.0 brings both versions' changes.
A repo whose journal predates 0.3.1 signs with the old per-install key. Run ledger-reanchor once per repo; it reads the previous key for you and reports what it did.
Browser capture stays experimental: its adapters are not yet verified against live sessions.
macOS builds are not notarized. First launch may require right-clicking the app and selecting Open.
The app stops going unresponsive, and reports the memory limit it actually has
Reading one repo's own records could take the bundled server past its memory limit, which a user saw as a dead app behind a wall of connection errors. Three reads were rewritten, the memory limit the app reports is now the one it has, and two RepoOps installs can share a repo without breaking its records.
Highlights
✓The app stops dying while reading its own records - A repo's integrity journal had stopped rotating in August and reached 319MB, and every dashboard load read the whole thing into memory. It streams now. On the repo that hit it, the same check went from 631MB of memory to 89MB, and finished in 1.5 seconds. (#4398)
✓Opening an agent trace is fast - Clicking one session used to read every day of telemetry to find it, about 650MB for a dozen turns. A small index means it reads only the days holding that session. Opening a second session went from 23 seconds to under one. (#4401)
✓Refreshing Attribution no longer kills the server - Refresh runs that same reader over every session in the window. Measured against a real corpus, the old path never returned and the server ran out of memory after seven minutes. It now answers in about six seconds. (#4401)
✓The memory limit in the log is the real one - The desktop asked its server for an 8GB heap and wrote that number into the log, while the runtime capped it at 4GB and ignored the request. It now reports the limit it has, and sizes the heap under it so a climbing server is restarted cleanly instead of crashing. (#4399, #4404)
✓Two installs can share one repo's records - The desktop app and a separately running dashboard each signed the same repo's journal with their own key, so the records could never verify and never rotate. The signing key now travels with the journal, and a lock stops two writers claiming the same entry. (#4402, #4406)
Also in v0.3.1
✓Recover a repo whose records stopped verifying - Run ledger-reanchor prints what it will do and what it gives up, and writes only when you say so. It is also the one-time step for a repo written before the signing key moved. (#4398, #4406)
✓Incident cases from more sources - Failed deployments, GitHub runs and scanning alerts, product exceptions and web-vital breaches, and your own production events all open cases on both apps. (#4390, #4393, #4396)
✓Investigation state that persists - Hypotheses, confirmed cause, contradictions, checkpoints and a security classification are stored on a case as versioned findings rather than placeholders. (#4392, #4400)
✓Cost and prevention on a case - Cost receipts with reconciliation and an exact-scope containment approval, plus reviewed lessons with delivery receipts and recurrence decisions. (#4395, #4403, #4405)
✓Where attribution came from - The attribution chain records how each hop was found and how confident it is, with a capture support matrix behind it. (#4388, #4391)
Notes
A repo whose journal predates this version signs with the old per-install key. Run ledger-reanchor once per repo; it reads the previous key for you and reports what it did.
After that migration, archived history keeps every content and linkage check on a deep verify, but its signatures can no longer be re-checked under the repo's key. Everything written afterward stays fully checkable.
The incident pipeline is still being built. These screens do not mean every production source or attribution link is connected.
macOS builds are not notarized. First launch may require right-clicking the app and selecting Open.
The new workspace, with the right server behind it
The desktop opens its bundled server by default, including after an upgrade. Settings shows which desktop and server builds are connected. This version also includes the merged workspace design and incident investigation sections.
Highlights
✓Your desktop starts its bundled server - An older localhost server cannot silently supply the upgraded desktop's pages. The bundled server uses its own port and data profile, leaving the old server running. (#4383)
✓Check the connection in Settings - See desktop and server versions, content-build fingerprints, port, connection mode, and verification state together. Optional shared attachment requires the same product, version, and build. (#4383)
✓Startup errors stop the connection - If isolated setup fails or a shared server cannot be verified, RepoOps stops instead of silently falling back. A mismatched shared server offers an explicit bundled restart or quit. (#4383)
✓A shared incident investigation layout - Today and case views use the reviewed workspace composition. Open a case through Overview, Evidence, Attribution, Security, Cost, Fix, and Prevention, with missing evidence kept explicit. (#4380)
✓Security investigation and coverage pages - The local workspace includes Security investigation and coverage subtabs alongside the existing data and permission boundaries. (#4380)
Also in v0.3.0
✓Website layout rules restored - Restored the marketing layout styles lost in an earlier merge, including the page composition and setup-form rules. (#4382)
✓Desktop setup guidance - The existing dashboard quickstart and walkthrough show where to compare desktop and server connection details. (#4383)
Notes
The first isolated startup imports the safe repository and settings subset. Historical records remain in the original profile; they are not copied into the isolated profile.
Changing the Desktop server setting takes effect after restarting RepoOps. Explicit shared mode requires an exact version and application-build match.
The incident pipeline is still being built. These screens do not mean every production source or attribution link is connected.
macOS builds are not notarized. First launch may require right-clicking the app and selecting Open.
A smaller first week, and screens that tell you it worked
The app showed 111 things in the sidebar before you had done anything. It now shows 46, and the ones you meet first say what you get from them and how you will know they worked. Nothing was deleted to get there: every page still answers at its own address. This release also fixes a first-run failure where a repository listed in your config could be dropped in silence, leaving an empty dashboard and no reason anywhere on screen.
Highlights
✓The sidebar shows what a first week needs - 111 rows down to 46. The rest are behind the advanced switch, one click away, and every one of them still opens at the address it always had. The hosted dashboard got the same treatment, 58 rows down to 17. A test holds both halves, so a row leaving the navigation can never quietly mean a page was removed. (#4248, #4251)
✓A repository that fails to track now says so - If an entry in your config was malformed, it was dropped without a word: the dashboard booted with nothing in it and the reason appeared only in a log a desktop user never sees. Every dropped repository is now named on the Today screen with what to correct, in plain language rather than as a database error. (#4361)
✓The screens you meet first say what proves it worked - Seventeen screens now answer three questions in their own words: what you get here, what to do next, and how you will know it worked. That third answer did not exist anywhere in the product before, because the place the copy lives had no field for it. (#4349, #4357)
✓Attestation signing is on by default - Work records are signed without you turning anything on. This is the one control that ships armed; everything else still ships off and you arm it yourself. (#4306)
✓The install stops carrying this project's internal documents - The desktop payload included the documents describing how RepoOps itself is built. They are no longer packaged, and a check now fails the build if an internal directory reaches a customer's disk. (#4254)
Also in v0.2.21
✓First run stops asking for a production URL - It was asked before anything needed it, and most people had nothing to type. (#4353)
✓A fix can name who may approve it - Remediation approvals now record the person who made the decision rather than a typed name, carry a per-member ceiling on how severe a fix one person may wave through, and show a queue that says who may clear each item and which ones nobody can.
✓The marketing site says five things instead of thirty - Fourteen routes left the site navigation and the sitemap, folding into the five areas the product actually sells. Each one still serves at its address, so an old link still lands. (#4249)
✓The docs site stops publishing pages it stopped linking - Three earlier cuts removed pages from the documentation sidebar and left them advertised to search engines and to AI readers, including this project's own internal reference. Both indexes now publish exactly what the sidebar links. (#4333, #4345)
✓A merge regenerates what it makes stale - Merging the main branch used to leave a generated page out of date, and you found out from a failed check ten minutes later. It is regenerated at merge time now, with the files named for you to commit. (#4351)
Notes
Attestation signing is now armed on install. Every other enforcement control still ships off and you arm each one yourself.
macOS builds are unsigned. On first launch, right-click the app and choose Open.
Nothing was deleted in the navigation cuts. Every page removed from a sidebar still answers at its own address, and tests assert both halves.
The front door opens again, and the download is 180 MB smaller
The published npx repoops could not start. A module the installer imports was generated into the package and never added to its file list, so the command died before printing a line, and npm does not let a published version be replaced. This release is the fix. While it was being cut, the desktop app also stopped shipping 180 MB of tooling it never loads.
Highlights
✓npx repoops starts - The published package was missing a file that one of its own modules imports, so the command exited with a module-not-found error before it could print anything. Every install since 0.2.19 hit it. The packaging check could not catch it either, because a file absent from the file list is absent from both the tarball and the list of what the tarball should contain, so the two agreed about a package that does not run. That check now also confirms every import in a shipped module names a file that shipped beside it. (#4101)
✓The download is 180 MB smaller - The desktop app bundled the whole build tree, so every install carried the test runner, the linter and the migration tool: 123 MB of tooling that nothing in the app imports. Four code-parsing grammars shipped alongside them for a feature that was never finished, which the code says in its own comments. Measured the way the release job installs, the bundled dependencies went from 496 MB to 316 MB, and from 161 packages to 59. Nothing behaves differently. (#4232)
✓Three commands run without installing the app - adopt wires the RepoOps loop into the repository you are standing in, connect does the same scoped to one coding tool, and mcp-scan reads the MCP servers configured on your machine without running any of them. They download once after sign-in, then run offline, and they write only to your repository. readiness, which scores a repository's day-one posture out of 100, now runs the same way. (#4095, #4116)
✓Arming a detector installs what it needs - repoops arm <detector> turned a detector on and left the hook it depends on uninstalled, so the detector ran and saw nothing. Arming now installs the hook, and disarm is its opposite. Nothing is armed when you install RepoOps, and this release does not change that. (#4082, #4111)
✓A failed tab load no longer takes the toolbar with it - When a tab could not load its data, the error pane replaced everything inside the tab, including the buttons you would use to retry. The pane now replaces the content and leaves the controls around it alone. (#4212)
Also in v0.2.20
✓Files another tool writes into your project are attributed, not accused - A write into .claude/ by a tool you installed used to read as an unexplained change. Recognised tools are now named beside the strict verdict, so you can tell a tool you chose from a change nobody can account for. Attribution never marks anything verified and never clears a suspect verdict. (#4059)
✓A stale document arrives as a pull request - Nominate a document, and when the code it describes moves out from under it, the drift comes back as a pull request rather than a note nobody reads. (#4051, #4055)
✓GitHub Issues and Asana connectors - Two more places RepoOps can send an outbound record. (#4057)
✓One list of what is left - Work was tracked in six places at once, each stale somewhere the others were not. There is now one ledger, one row per item, and a check that fails a change when the page falls behind its sources. (#4118)
✓A published accuracy number for a detector - Measured against a fixture set, with a check that fails if the published figure and the measured one drift apart. (#4058)
Notes
Nothing is armed on install. Every enforcement control ships off and you arm each one yourself.
macOS builds are unsigned. On first launch, right-click the app and choose Open.
The remediation loop can run past sensing, and three things that stopped it
The last release made RepoOps open cases on a schedule. This one lets those cases move: a scheduled pass that writes a fix brief without anyone clicking, the build step reconnected after it turned out never to have been wired at all, and a daemon that stops reporting an update to itself. Every unattended step stays off until you switch it on.
Highlights
✓RepoOps can draft the fix brief on its own - Writing the brief that describes a fix was a button on the queue and nothing else. On a machine where nobody pressed it, no brief was ever written and everything downstream waited forever. It can now run on the hourly cycle, off by default because it spends your Anthropic key on one call per case, bounded to three cases a tick and then by your daily cap. It only ever scopes a case that has no brief yet, because a refusal it already paid for should not be bought again. (#4007)
✓The build step was connected to nothing - The step that turns an approved brief into a real pull request was handed to the daemon from the day it shipped, and the daemon read it nowhere. It had never run once, switch or no switch. Both unattended steps are now wired together in the right order, each one recording that it ran, so a step that did nothing can be told apart from a step that was never called. (#4007)
✓A fresh install no longer offers to update itself - The app read its version from the wrong file, one that always says the same number whatever you install. So a build you had just installed reported that an update was available, and would have gone on reporting it forever. With automatic updating switched on that is a loop. (#4010)
✓The background worker stops crying wolf every hour - Its stall alarm was set for a job that runs every five minutes, and applied to one that runs hourly and legitimately takes about six. So it fired on essentially every run and left a permanent error on the status, which is the surest way to make a real error invisible. The alarm now matches the job it is watching. (#4012)
Also in v0.2.19
✓The daemon says which build it is running - A version number describes a build, not a running process. If an update replaces the files underneath a process that is already running, the two disagree and nothing notices. Status now compares them and says so plainly. (#3974)
✓Diagnostics that reached no log now reach it - Thirty-seven of the background worker's own messages, including every failed publish, were written to a console a background service does not have. (#3974)
✓Live detection watches your repositories - It had been pointed at a folder nothing writes to, so it watched nothing at all, and every alert it did try to raise was rejected on its way to the store. (#3984)
Notes
Unattended scoping and unattended building are separate switches and both start off. Turning either on spends money, bounded by your daily cap.
Restart the app after updating. A running background worker keeps the code it started with, so an update that lands underneath it does nothing until it restarts.
macOS is unsigned. First launch needs right-click, then Open.
The loop runs on a schedule, and your install can see updates again
The last release shipped an auto-remediation loop that had never actually run. This one is mostly the work of finding out why and fixing it: a scheduled pass that opens cases without anyone clicking, a credential per repo instead of one shared login, and a daemon that can finally tell you which build it is running. Install this one by hand. It is the release that repairs automatic updating, so it cannot arrive automatically.
Highlights
✓RepoOps opens cases on its own now - The pass that turns findings into reviewable cases only ever ran when someone pressed a button on a local tab, so on a machine where nobody pressed it the queue stayed empty for ever. It now runs on the daemon's hourly cycle, opt-in with REPOOPS_AIR_OPEN_SCHEDULE=1, and every case records whether a person or the schedule opened it. On the first machine it ran on, it opened thirteen cases against findings that had been sitting there for weeks. (#3834, #3971, #3974)
✓Every install was blind to updates, including this one - The daemon's update reader asked the apex domain and refused redirects, and the site sends the apex to www with a 307. So every install recorded 'no update available' for its whole life, against a feed that was serving correctly the entire time. It now follows the hop. Because the fix ships inside the thing that was broken, an install older than this release has to be updated by hand once; after that, updates arrive on their own again. (#3828)
✓One GitHub credential per repo, not one for all of them - Until now a repo could name a credential but there was no way to get one, so every tracked repo pointed at a single shared login that could merge into all of them. You can now mint a token per repo: the token goes to your data directory, the repo entry stores only the variable's name, and nothing reaches your config file or the database. The loop also strips that whole namespace from any command it runs inside a repo, so one repo's test script cannot read another repo's token. (#3873)
✓The same defect in four repos is shown as one problem - A defect that comes from a shared dependency opens a case in every repo it touches. Those cases now carry a shared identity, so when you open one you can see the others exist. They are linked and never merged: each repo keeps its own fix, its own checks and its own approval, because a fix belongs to the repo it lands in. (#3875)
✓Cargo, Go and Python projects are understood without configuration - Verification used to need either a package.json or a hand-written verify block, which left Rust, Go and Python repos unable to prove a fix. RepoOps now reads Cargo.toml, go.mod and pyproject.toml. It will only offer a test command when it can see test files, because cargo test and go test pass on a project with no tests, and a manufactured pass is worse than an honest refusal. (#3840)
✓The daemon tells you which build it is actually running - A version number describes a build, not a process. When an update replaces the files under a daemon that is already running, the two disagree and nothing notices: that is how one install ran eighteen hours of stale code while correctly reporting its version. Status now compares the running process against the code on disk and says plainly when they differ, and what to do about it. (#3974)
Also in v0.2.18
✓Fixes you can only approve, never widen - The per-repo remediation policy has an editor, and it only offers controls that narrow what your account already allows. The server refuses a widening change regardless of what the page sends. (#3839)
✓A build that says nothing is no longer indistinguishable from one that is not running - Thirty-seven of the daemon's own diagnostics, including every failed publish, were written to a console that a background service does not have. They now reach the log file. (#3974)
✓Incident reporting, end to end - An owner and a developer can hold a conversation on a single incident, transcripts can be requested and granted with a recorded reason, and a team can set its own floor for those requests. (#3866, #3874, #3855)
✓Legal and marketing pages matched to the code - The pages describing what happens to customer data were checked against what the software actually does, and corrected where they disagreed. (#3951)
Notes
Install this build by hand. It contains the repair for automatic updating, so an install older than 0.2.18 cannot receive it automatically. After installing once, updates resume on their own.
Restart the app after updating. A running daemon keeps the code it loaded at start, so an update that lands under it does nothing until the process restarts. This build tells you when that has happened.
Unattended building stays off unless you turn it on. Case opening and unattended fix-building are separate switches, and the second one spends money.
macOS is unsigned. First launch needs right-click, then Open.
RepoOps writes the fix, verifies it, and waits for your approval
The auto-remediation loop is this release. RepoOps drafts a fix for a defect it found, builds and tests it in a throwaway worktree, replays the guard against the commit that caused the defect, and merges nothing without you. It runs across every repo you track, with a policy per repo that can only narrow what you allowed account-wide.
Highlights
✓RepoOps writes the fix, and says when it will not - A bounded set of recipes covers the defect classes whose cure is mechanical. A credential hardcoded into source becomes a value read from the environment, with a loud failure when it is absent. A tracked .env becomes an ignore rule plus the command that takes it out of the index. When a line is not the shape a recipe understands, the recipe declines and states why, so an empty diff never reads as a bug. (#3635)
✓Five checks before a fix reaches you - The fix builds and tests on its own branch in a throwaway worktree. A new regression test has to pass on the fix and fail when grafted onto the commit that introduced the defect. The guard replays against that commit and blocks it. The pull request's own CI is read from GitHub. A check that did not run is recorded as failed, with that as its stated reason, never as passed, and a project with no test script fails that check rather than skipping it. Your working tree is never touched. (#3637, #3705)
✓Approving is one act, and rejecting says why - Approving re-runs the whole bar on the server before anything is applied, then writes the lesson, arms the guard and lands the change as one act, rolling the local writes back if the last step fails. Auto-merge stays off on a fix RepoOps wrote, so nothing merges without you. Rejecting needs a reason, closes the pull request, and discards the diff, the guard and the lesson together, so a recipe that keeps missing can be removed. (#3637, #3649, #3710)
✓The loop runs across every repo you track - One build tick now walks every tracked repo. A fix builds in its own checkout, pushes to its own remote, and opens its pull request there. Each repo can carry its own build and test commands for a toolchain that is not npm, and its own policy: watch only, a higher severity floor, or a share of the daily build cap. A per-repo setting can narrow what you allowed account-wide, never widen it. A repo whose loop is blocked holds its cases and names the blocking fact instead of spending the retry budget. (#3755, #3758, #3761)
✓One work queue at the top of Today - Four producers that used to emit work separately are now one ranked list, where every item carries an owner, a state and a clock. Two producers naming the same thing merge into one row that says what folded in. The queue leads with the fix pipeline: built and waiting on you, building now with the spend so far, and held below your build floor. The panel says how many of the four producers answered, so a short queue because everything is fine cannot be mistaken for a short queue because two readers failed. (#3628, #3719)
✓Your brain runs on your own model key - Hosted Ask, the entity pass and photo capture read a shared server-side key, so a paying customer's question and the retrieved contents of their own brain reached the model provider on our key, while the privacy page promised that never happens. The key is now yours, from Anthropic, OpenAI or OpenRouter, stored per user and encrypted. No key is a refusal rather than a quiet downgrade. Set it in My Brain. (#3526)
Also in v0.2.17
✓You set how much runs unattended, and what it may spend - High and critical findings build without waiting for you; medium and low sit until you click Scope only or Build it. A daily cap of $10.00 of measured build spend bounds the whole thing, counted from what build sessions actually cost, failed runs included, and estimated never. A case held below the floor or at the cap records why it was held instead of vanishing. Both numbers are yours to edit on Settings. (#3711)
✓A fresh install stopped carrying the build machine's repo paths - The installer shipped with the author's own tracked repo paths and vendor ids baked in, and the first-run wizard dead-ended anyone whose code lives outside C:/Projects. Both are fixed. (#3642)
✓Closing the window during startup no longer quits the app - The guard that drops a closed sign-in window into local-only mode stood down before the tray existed, so closing the window during first-run startup lost the product. The sign-in screen also stopped saying it was waiting on the browser while it was actually starting the local server. (#3587)
✓A link could open an attacker's site inside the app's own window - The navigation allowlist compared strings, and a URL can start with a string it does not belong to: http://127.0.0.1:4000@evil.com/x starts with the trusted prefix while its origin is evil.com. A link of that shape, arriving from a Sentry issue or tracked-repo content, opened a window on the attacker's origin with the preload attached and no address bar. Both guards now parse and compare origins, and refuse userinfo outright. (#3527)
✓Production errors pull for real - Connecting Sentry backfills 30 days straight away instead of waiting on the next cron tick, and every later pull stays incremental. Duplicate production events fold into one case. (#3670)
✓A public API you can build against - An OpenAPI 3.1 spec at /openapi.json, API version 1 pinned with a request header, rate-limit headers, and a promise that a breaking change carries deprecation and sunset headers for at least 180 days before it lands. (#3478, #3494)
✓Team access got stricter - Connect codes are stored hashed and no longer travel in the URL. A read-only member could mint a write-capable device token. A member who is removed or demoted has their devices signed out, and rotating a device token re-checks team membership. (#3503, #3508, #3613)
✓Connect a service by OAuth - A connector can be connected with OAuth from the Connectors tab, rather than by pasting a token. (#3736)
Notes
Windows installers are signed. macOS is not notarized yet, so first launch needs right-click then Open.
Installed apps update themselves within four hours. Nothing to do.
This release folds 391 changelog entries. The full engineering record is in CHANGELOG.md.
A fresh install works, and an incident now names who and what caused it
Two defects meant a brand new install could not track your code at all unless it happened to live in the same folder as the author's. Both are fixed. The rest of this release is a security audit of 193 findings, a reliability audit of 34, and a new way to work an AI incident: from the error, back to the session and the prompt and the person, forward to a fix and a check that catches the next one.
Highlights
✓A new install can track your repo - The app shipped with a repo entry from the build machine baked in. On your machine that path does not exist, so first launch skipped the setup wizard and opened a dashboard tracking a repo that was not there, with every panel drawing a placeholder. Adding your own repo then failed, because the folder check only accepted paths under C:/Projects. A config entry whose path is not on this machine is now skipped, and your home directory is an accepted location. (#3353, #3355)
✓A tracked repo could run a command on your machine - A standing goal file in a tracked repo had its predicate handed to a shell, nightly, with no gate. Someone pushing that file needed you to do one thing: git pull. Running a predicate now takes an explicit setting plus your approval of that exact file, granted in a terminal, and editing the file lapses the approval. Two more paths that could reach a shell were closed the same week, along with an empty request body that returned every tracked repo's substituted secrets. (#3246, #3251, #3248)
✓One queue for AI incidents, with the person and the prompt attached - The Agent incidents tab was an explainer with nothing behind it. It is now a queue across security, performance and operations. Each case carries a severity, an owner, a status, a deadline, and where the problem came from: which session, which prompt, which person, with the confidence stated rather than implied. A production error and a runtime hold open a case by rule, not by guess, and both thresholds are yours to set. The tab is called AI incidents now, local and hosted. (#3315, #3313, #3347, #3349)
✓A worked incident becomes a check that catches the next one - Resolving a case can write a lesson, and a lesson can now carry a pattern that runs at the gate every change passes through. RepoOps drafts the pattern from the line that caused the incident so you are not writing a regular expression by hand. A new check starts in warn, which prints and passes, and is promoted to blocking only by a person. You can also tell a check it was wrong, and say a lesson turned out to be false. (#3259, #3261, #3262, #3263, #3316)
✓It looks for 32 kinds of agent, not 5, and it says which ones it cannot see - Agent discovery knew about five tools. It now knows about 32, found by their extension folder rather than a guessed config path. Ten of them have no confirmed layout on disk and are reported as undetectable rather than given a guessed path, because a scan that can never fire reads exactly like a clean machine. Enforcement also runs on Codex CLI and GitHub Copilot CLI now, not only Claude Code. (#3287, #3290, #3297)
✓The spend ceiling fires - The cost ceiling rule had existed for months and had never once fired, because the number it reads was never supplied by anything. RepoOps now sums the session's cost from telemetry it already writes and hands it to the gate before the decision. If you set the figure yourself it still wins. (#3288)
Also in v0.2.16
✓Commands that did not do what their name said - Several tabs, two of them behind Copy buttons, handed you an npx command that only prints a redirect and downloads the installer. Each now points at the surface that already does the job. (#3391)
✓The app reports its own crashes, and survives a busy port - Crashes in the dashboard now arrive as production errors instead of disappearing. A port already in use took the app down through the crash path, restarting five times before giving up and logging itself as five separate production errors. (#3270, #3361)
✓Accepting brain proposals no longer freezes the app - Accepting a proposal froze the server once per proposal, and Accept all high confidence froze it for minutes. A path filter on the events read parsed the whole corpus to throw nearly all of it away. (#3385, #3386)
✓The Settings tab's Save buttons work - They were gated behind a confirmation the tab itself could not produce. (#3377)
✓Seven hosted pages stopped reporting a failed read as a clean result - Plus five ROI tiles that graded a team which had measured nothing. (#3359)
✓Your team sets its own incident deadlines, and closing the ticket closes the case - How long a case of each severity has is now yours to configure, and a case that opened a Jira or Linear ticket follows it. (#3326, #3330)
✓A benchmark result did not replicate, and is published as a failure - A preregistered replication of the August 16 result failed. The run is on the site with the negative control beside it. (#3392)
✓A Microsoft Defender for Endpoint comparison - The 27th tab on the comparison page, with the audit behind it. Local-first is no longer presented as the thing that sets RepoOps apart, because Defender ships local agent discovery too. (#3304, #3307)
Notes
Windows installers are signed. macOS is not notarized yet, so first launch needs right-click then Open.
Installed apps update themselves within four hours. Nothing to do.
This release folds 155 changelog entries. The full engineering record is in CHANGELOG.md.
Four changes to what your hosted dashboard shows and exports
These shipped to repoops.ai, not to the desktop app, so there is nothing to install. Each one changes a number or a document you may already have looked at, and three of them make something smaller than it was, so they are worth a minute of your time.
Highlights
✓Your Coverage score drops, and it is a measurement fix - Brain health read your activity over the same 30 days it used to judge whether a file had gone stale, so every file it could see had been touched inside the window and Coverage sat at 100 no matter what you did. It now looks back far enough to see a file nobody has touched for over a month. Nothing about your brain got worse on this deploy; the old number was not measuring anything. Scores from before this release cannot be compared with scores after it, and the page says so where you read it.
✓Turning off a share scope now stops the export - The four Share scope switches on Awareness settings were labelled as controlling what leaves your account, and they only ever controlled what came in. Pattern exports now honour them, so if you turned one off at any point, your exports get smaller from here. Only a switch you explicitly turned off closes a scope: an account that never touched them exports exactly as before.
✓A strict invoice export now means only granted consent - Strict mode held back contractors who had revoked consent, and shipped everyone still marked pending, which is the default for anyone nobody has asked. It now includes granted consent only, so a strict export can come out shorter than the last one. Every invoice states what strict held back and how many people were in each state, so a short document is never a silent one. Full mode is unchanged.
✓Public brain pages you published earlier now have an owner - A page published before the hosted store recorded ownership carried no owner, which left it editable and removable by anyone holding a publish credential. Ownership binds when a page is republished. If a page of yours is genuinely ambiguous about who owns it, it is listed for a person to resolve rather than assigned by a guess.
Notes
Nothing to install. These are live on repoops.ai now.
If your Coverage score fell today, that is this change. Compare against scores recorded after August 16, not before.
The week we made the product tell the truth about itself
Six days of audits found the same defect over and over: a tab that rendered an empty state while the data sat in the store, a control that saved a setting nothing read, a detector that could never fire. This release closes 78 of them, plus the surfaces they hid. If a panel looked broken to you and you assumed it was empty, it probably was not.
Highlights
✓Take a published page down - You could publish a Builder Profile or a brain lineage card and never unpublish it. Both now have a working remove, and a failed removal says so instead of claiming the page is gone while it is still being served. (#3176)
✓Open an incident and see what happened - The hosted incident queue showed a detector name, a reason and a date. The full record was already stored: the session it came from, the call that was held, the containment taken. Every row now opens. It will not draw a containment you only requested as one that completed. (#3010)
✓Say a lesson turned out to be wrong - RepoOps had no way to record that a memory became false. You can now retract a lesson, and the retraction is part of the record rather than a deletion that hides it ever existed. (#3058)
✓Check whether a benchmark can work before you pay for it - A Check corpus fit button on the Evals tab probes your brain with the paper's own language and tells you whether there is anything there to retrieve, before a run spends anything. No model call, no key. You can also pick which arm to score against. (#3135)
✓Controls that now control something - The fleet kill-switch and policy rules are editable from FleetView instead of read-only, and the audit signing key has an operator control. Without that key the Awareness audit tab could never show a row while telling you rows appear as pipelines fire. (#3134, #3176)
✓Guards that can catch what they were built to catch - Thirty-three checks shipped or repaired, several of which could never have fired against their own defect. Automated PR review that skipped silently under a green tick now says so on the checks page. (#3204)
Also in v0.2.15
✓Missions stops inventing a run - A repo with no captured sessions used to get a fabricated three-agent mission written into its real log, which then blocked the genuine one from ever seeding. Nothing is written now, and installs already carrying the invented row stop being shown it. (#2996)
✓The PR drafter reads the branch you asked for - The Branch field selected which sessions to match but the commits and changed files came from whatever the checkout had open, so you could get the wrong code under the right branch name. A branch the repo does not have is now refused by name instead of quietly falling back. (#2997)
✓The activity ledger names which AI tool produced each session - Sessions from different tools were pooled into one number.
✓The public brain page publishes, and unpublishing removes it - Plus a last-published receipt showing when, to what URL, and the error if there was one. (#3139)
✓One nightly failure no longer costs a repo its whole night - The nightly brain pass ran 33 steps inside a single error boundary, so one failure skipped every later step until the next night. Each step is now isolated and the pass reports which one failed. (#3192)
✓Benchmark retrieval can use vectors at all - Every retrieval number this program produced was keyword-only, because the vector warm had nowhere to persist and discarded its work every call. Runs now report which ranker they actually used, and what share of calls fused vectors. Still open and stated on the run: only about 11 percent fuse, so the hybrid comparison is not settled. (#3231)
Notes
Windows installers are signed. macOS is not notarized yet, so first launch needs right-click then Open.
Installed apps update themselves within four hours. Nothing to do.
This release folds 240 changelog entries. The full engineering record is in CHANGELOG.md.
The biggest release so far. RepoOps can now gate what an agent is allowed to do, inventory the secrets it can reach, sign its memory and its skills, and reconstruct any single run after the fact. The Evals tab also learned to score a research paper's claim against your own repo.
Highlights
✓Allow, block, or ask before an agent acts - The detectors RepoOps already ships now feed a live enforcement gate, with a per-detector ramp so you can watch a rule's false-positive rate before you let it block anything. Runtime containment adds a human-gated tail for the calls you want a person to see first. (#2670, #2677, #2693, #2737)
✓See what one agent run actually did - Run Forensics reconstructs a single run from the records it left: what it read, what it changed, what it called, and which subagent did which part. It is on the desktop app and on a team page for the whole org. (#2676, #2742)
✓Know which secrets your agent can reach - An inventory of the non-human identities in play, plus an optional local broker that hands an agent a scoped, short-lived credential instead of your raw API key. (#2679, #2690)
✓Signed memory and signed skills - Every sanctioned write to an agent's memory is signed, so a poisoned entry stands out instead of blending in, and each skill or subagent carries a signature you can check before it loads. Drift gets flagged rather than silently accepted. (#2681, #2685)
✓Secrets hidden in screenshots - Every secret detector reads text, so a screenshot of a terminal or a .env file used to slip past all of them. Images are now read and run through the same detectors, and a hit gets the same type and the same masking as one found in text.
✓Score a paper's claim against your own repo - Give the Evals tab a research paper URL and it runs the benchmark end to end, then reports what it measured and how far that is from the paper's own scoring. A run exports as a bundle another machine can replay and get the same numbers. (#2721, #2728, #2910)
Also in v0.2.14
✓A day-one security score and the evidence behind it - A 0-to-100 readiness score before you author a single policy, an export that maps your coverage to the four control frameworks auditors ask about, and a per-repo sandbox egress allowlist. (#2687, #2688, #2689)
✓Cost numbers you can trust - Claude Opus 4.5 was priced as Opus 4, a silent 3x overestimate on every run that used it, and three dated model snapshots could not be priced at all. Both are fixed. (#2921, #2923)
✓A faster dashboard - The read-through cache was unreachable, so every tab recomputed from scratch on every load. Also fixed: a hung call that could freeze a background loop for the life of the process, a failed stream connect that could take the server down for everyone, and a daemon status that reported a dead capture as running. (#2826, #2830, #2832, #2834)
✓Getting in and getting started - A team invite now accepts any sign-in method you have configured, not Google alone, and on a brand-new install the first-run card's button works. (#2837, #2839)
✓Hardening on the hosted side - Per-tenant rate limits on nine authenticated routes, a check that stops a connector pointing at a private or metadata address, and OAuth callbacks pinned to a trusted origin. (#2724, #2735)
✓Model choice as a security decision - Providers can be scored on whether they train on your data, how long they retain prompts, whether you control the processing region, and whether they publish an audit. A model with no data on it reads as not assessed, never as a low score.
Notes
Installed desktop apps auto-update to this build on next launch; no action needed.
Windows is code-signed. macOS and Linux builds are available too; on macOS the first launch needs a right-click, then Open.
Deploy the Sensor across a fleet, and meet the Tap
This release makes the headless Sensor easy to stand up on many machines and CI runners, keeps it capturing on an interval, and adds the Tap in beta: an optional, fail-open local tee for AI request metadata.
Highlights
✓Headless Sensor deploy - Bind an install with `repoops connect <code>`, or mint a reusable fleet enrollment secret with `repoops enroll-secret mint`, so you can stand up capture across many machines and CI runners without a manual setup on each. (#2656)
✓Guards over your captured sessions - `repoops sensor --guards` runs the session-signal and billing checks over what your agents already did, and `--verify` checks a captured attestation offline. Advisory only: it reports, it never blocks a merge. (#2657)
✓The Tap (beta) - An optional, fail-open local tee: it copies each AI request's metadata to your Sensor and passes the request through untouched. It never routes, blocks, caps, or stores keys, and it fails open on any error. Opt-in, loopback only. (#2658, #2659, #2660)
✓Always-on Sensor - `repoops sensor --watch` keeps capturing and pushing on an interval, rotating its device token and renewing its license as it runs; add `--otlp-receive` to accept OTLP traffic on localhost. (#2661, #2663)
✓Fleet secret controls - A per-team cap on live enrollment secrets plus an alert when enrollments spike, and a FleetView admin page to mint, list, and revoke fleet secrets. (#2662, #2664)
Also in v0.2.13
✓Security hardening on the fleet-secret mint path - Fleet-enrolled devices cannot mint further secrets, a rotated or grace-window token cannot mint, and the Tap refuses any non-loopback bind or sensor URL. (#2656, #2660)
Notes
Installed desktop apps auto-update to this build on next launch; no action needed.
Bulk actions for Session Signals, and alerts that actually fire
Session Signals gains bulk mute/unmute and fewer false alarms, alerts you configure now actually reach Slack, Discord, or Teams, and a sweep of dead-end links across the dashboard now go somewhere.
Highlights
✓Bulk actions and fewer false alarms in Session Signals - Select multiple signals and mute, unmute, or clear them in one action instead of one at a time. New repo and rule filters, a Rescan now button, and an Active/Muted view make the list easier to work through. A smarter ignore layer also cuts down on findings that were already redacted or came from test fixtures.
✓Alerts now actually reach Slack, Discord, or Teams - An alert step configured to notify an external channel previously only logged the alert locally. It now posts to the Slack, Discord, or Teams webhook you configured, so a raised alert reaches the place you set it up to reach.
✓Build now, right from the Requests tab - A queued request can be turned into a pull request on the spot with a Build now button, and anyone who submitted a request can see its full status: rejected with a reason, or delivered with a link to the PR that shipped it.
✓Every tool on the map, scored - The /compare positioning map now plots RepoOps against 23 competing tools on two axes: whether a shipped defect can be traced back to the AI session and prompt that wrote it, and whether your data stays on your machine. Hover a dot for the score, click to jump to that tool's full comparison.
✓Connect an OpenAI Admin key for Billing Guard - Billing Guard now accepts an OpenAI Admin key alongside Anthropic, so a live OpenAI account can be reconciled without setting an environment variable by hand.
Also in v0.2.12
✓A round of dead-end links now go somewhere - The desktop-only Labs cards, the Brain society empty-state link, the My Brain panels on Continuity, and four bootstrap-prompt cards on the hosted site all pointed nowhere or required manual setup. Each now works or explains plainly what it needs.
✓Signed-in team members can reach team routes again - Team API routes only recognized the desktop app's session cookie, so a browser sign-in got rejected. They now accept either.
✓Register a brain from the empty state - The Brain society tab's "register a brain" prompt now has a real form and route behind it, instead of pointing to a Settings page with no matching control.
Your Session Signals alert settings now sync across your machines and can be set from the hosted dashboard, and a team can share one set of alert sinks that every member's machine reaches.
Highlights
✓Team-wide Session Signals alerts - A team owner or admin sets one set of alert sinks (Slack, PagerDuty, incident.io) for the whole team. Every member's machine then alerts to the team sinks in addition to their own personal sinks, never instead of them, and an identical sink is hit once.
✓Set your alerts from the hosted dashboard - The alert sinks and capture toggles you could only set in the local app now have a card on repoops.ai Settings. It writes straight to your account, and every machine you have connected pulls it. Secrets are shown back only as a masked tail.
✓More of your config follows you across machines - On top of the alert sinks and capture toggles, the sync now carries your brain-wiki model choice, the nightly flag, and the briefing tuners. Set them once, on any connected machine, and the rest pick them up.
✓Per-PR labor cost attribution - See the developer-hours and dollar cost attributed to each pull request, so you can read what a change actually cost to ship.
✓Run the accountability metrics on your own repo - `repoops bench` runs the real accountability benchmark against your repository, and the accountability pages read honestly about who can run what.
Also in v0.2.11
✓Request intake, end to end - Requests you file now travel up to the platform owner and back down to a bound desktop with their full record and status, including a reject reason.
✓Deeper founder metrics - The Telemetry time-and-cost view gains owner/admin founder metrics, and a local rate preview shows developer hours and cost.
✓Billing and recurrence fixes - Re-enabled the live Stripe webhook and completed its event set; recurrence rules and lessons now populate for tracked repos even without Claude Code sessions.
The alert and capture settings you set on one machine now sync to your other machines, and the connect flows that used to fail in silence tell you what happened.
Highlights
✓Alert and capture settings sync across your machines - Set the Session Signals alert sinks (Slack, PagerDuty, incident.io) and the deep-capture toggle once, on any machine connected to a team, and your other machines pick them up on their own. No more copying settings between .env files by hand. A new Settings card holds them, and secrets are only ever shown back as a masked tail.
✓The Repos page tells you what happened - Connecting your organization on the team Repos page used to save nothing and look identical to "no repos yet" when you had not connected your GitHub account first. It now shows the outcome and leads you to the missing step.
✓Team connector sync works again - The team connector vault stopped syncing to connected apps because the list it reads rejected the app's own credential. It now accepts it, so connected-service credentials reach your machines again.
✓A cleaner empty state for app LLM calls - When an app has no LLM-call telemetry yet, that tab no longer shows internal setup notes or blanks the page. It keeps the layout and points to the setup guide.
✓Rejected requests tell you why - When the platform owner rejects or updates a request you filed, the note they leave now travels back to you, so a rejection shows its reason.
Also in v0.2.10
✓Why RepoOps, re-checked - Every comparison row on the Why RepoOps page was re-verified against current public sources (pricing, docs, changelogs) and re-dated.
The requests you file from the dashboard now travel. They flow up to your team and to the platform owner, who can triage them and drop the good ones straight into a build session, and each request's status flows back to you so you can see where it stands.
Highlights
✓Your requests flow up, and their status flows back - A request you file now reaches your team's roll-up and the platform owner's console. You can follow where each one stands: accepted, in queue, being built, delivered, or rejected.
✓Send your existing requests up with one button - A new Sync to cloud button on the Requests tab pushes the requests already on your machine up to the hosted store, so ones you filed earlier or on another machine show up in the roll-up and the console.
✓An owner console to triage every request - On repoops.ai, the platform owner gets a console that lists every request across every team, sets its status, and copies the ones worth building into a build session. Your team's own hosted Requests roll-up sits alongside it.
✓An Organization field on your repos - Tracked repos now take a GitHub organization on the add form and on each repo card. The value saves and reads back on reload.
Also in v0.2.9
✓A steadier Submit request button - The Submit request button is now rate limited, so a stuck click or a runaway script cannot flood the queue.
Notes
Existing installs update themselves: the app checks repoops.ai on launch and every four hours, downloads in the background, and installs on quit.
Windows is code-signed. macOS and Linux builds are available too; on macOS the first launch needs a right-click, then Open.
A polish release that fixes the parts you check first. The App updates card now tells the truth, the Windows installer shows its icon, and the Requests tab starts on your own submissions. On repoops.ai, a hosted Requests tab gathers what your team asked for.
Highlights
✓App updates read true - The App updates card now shows your installed version, detects the live update feed instead of saying it is not hosted yet, and the Re-check button reports a real verdict.
✓The Windows installer shows its icon - The setup file no longer installs with a blank icon. Windows now shows the RepoOps icon in Explorer and in the install dialog.
✓Requests you can find, and a team roll-up - The Requests tab shows your own submissions by default, with a source filter to bring in the ones pulled from hosted. On repoops.ai, a hosted Requests tab and team roll-up gather what your team asked for, and each member's submission is attributed to their team.
✓Clearer desktop settings - Start-at-login and the isolated-server option now read as desktop-app controls, not half-built features, because they manage an OS-level setting a browser tab cannot.
✓More install and feature docs - Install steps for macOS and Linux, plus new pages for requesting a change, the bring-your-own-key chat, and desktop isolated mode.
Also in v0.2.8
✓Ask the brain: the key link works again - The 'set a key' link in Ask the brain opens the right docs page instead of a dead one.
Notes
Existing installs update themselves: the app checks repoops.ai on launch and every four hours, downloads in the background, and installs on quit.
Windows is code-signed. macOS and Linux builds are available too; on macOS the first launch needs a right-click, then Open.
Request changes from the dashboard, and see what they cost
This release turns the dashboard into a place you act from, not just one you watch. Ask for a change and it builds itself, measure evals and developer cost where the work happens, and pull tool usage from the vendors your team already uses. Windows stays the code-signed path; macOS and Linux ship alongside it.
Highlights
✓Ask for a change from the dashboard, and watch it build itself - Submit a feature request, a fix, or a cleanup item straight from the dashboard. Each one captures the page you were on and lands in a queue you triage, and the items you promote build into pull requests on their own.
✓Eval engineering, end to end - New judges score answers for faithfulness and for correct tool parameters. Per-case eval bars carry their own instructions and answer keys, you can turn a recorded trace into an eval, and judge-hygiene checks keep the graders honest. A merge-confidence score advises on each change, and you can import and export evals in Harbor's format.
✓See developer hours and cost - Enter developer rates and keep their history. A founder view on the hosted Telemetry tab puts time and cost side by side, the combined activity view breaks hours down per repo, and a labor-cost line now shows on the invoice.
✓Ask your tools a question with your own key - A new chat runs on your own model key and works through a tool loop to answer. It records the model calls it makes, so the spend stays on the books.
✓Vendor tool usage, per developer - Pull per-developer tool usage straight from the Cursor and Copilot admin APIs, so attribution reflects what each person actually used.
✓Desktop: isolated mode and a steadier autostart - An opt-in isolated server mode runs on its own port with its own data profile, Windows autostart is more reliable, and several update issues are fixed.
Also in v0.2.7
✓Session signals and spend - A marketplace feed of rule-packs powers session signals. Spend now breaks down by topic, marks bring-your-own-key usage, and maps to the initiative behind it.
✓Review analytics - Track the time from request to review, score review depth by meaning rather than line count, and compare each developer's adoption against outcomes.
✓Team fleet visibility - A team tool catalog flags shadow tools, an inventory lists your hosted MCP servers, and an optional process scan (off unless you turn it on) shows what is running.
✓Honesty passes and copy cleanup - Another round of accuracy fixes across the hosted tabs, plus copy cleanups so every surface says what the product actually does.
Notes
Existing installs update themselves: the app checks repoops.ai on launch and every four hours, downloads in the background, and installs on quit.
Windows is code-signed. macOS and Linux builds are available too; on macOS the first launch needs a right-click, then Open.
Steadier on its feet, and a memory that answers straight
This release hardens the parts you feel every day: a first run that never dead-ends, an app that keeps its own server alive, and a project memory that returns an exact count instead of a confident guess. Windows stays the code-signed path; macOS and Linux builds ship alongside it.
Highlights
✓A first run that never dead-ends - Missing Git no longer closes the app. If setup cannot finish, you can explore with sample data or continue offline and sign in later, so you always land on a working dashboard.
✓The app keeps itself running - If the background server crashes it now relaunches itself, a crash leaves a diagnostic report you can hand us, and a single failing tab shows a small error instead of blanking the whole window.
✓Ask your brain a counting question, get a real number - Questions like "how many sessions mention this error" or "how many PRs shipped last month" now return an exact count, with the query that produced it, instead of a ranked guess. When it cannot answer with a real number, it says so rather than inventing one.
✓Work fully offline - A local-only mode runs the whole dashboard with no account and no network. Your code and telemetry stay on your machine, the same as every other mode.
✓Knowledge Graph - A new view maps how your repos, sessions, decisions, and the people behind them connect, so you can see the shape of a project at a glance.
✓Connect Anthropic billing without environment variables - Paste your Anthropic admin key right on the Billing Guard tab, now its own item in the nav. The key is checked against the live account before it is saved, never returned to the browser, and never logged.
Also in v0.2.6
✓Team and org rollups - Owners can group the teams they manage into an org and see capture coverage, cost, and prevented incidents rolled up across them. Device tokens now expire, rotate without a capture gap, and can be revoked.
✓Always-on capture, now container-ready - Run the background capture agent as a server-side container so a team keeps capture on with no desktop left online.
✓Hundreds of smaller fixes - Reliability, packaging, billing accuracy, and a long tail of polish across the dashboard.
Notes
Existing installs update themselves: the app checks repoops.ai on launch and every four hours, downloads in the background, and installs on quit.
Windows is code-signed. macOS and Linux builds are available too; on macOS the first launch needs a right-click, then Open.
RepoOps has run on Windows for a while; now macOS and Linux builds are downloadable too. These are early and meant for testing, so we want your feedback before we call them final. Windows stays the polished, code-signed path.
Highlights
✓macOS downloads: Apple Silicon and Intel - Two macOS builds, so you grab the one that matches your Mac: Apple Silicon for M-series, Intel for older Macs (the Apple menu's "About This Mac" tells you which). They are not notarized yet, so the first launch needs a right-click, then Open.
✓Linux downloads: AppImage and .deb - Run the portable AppImage or install the .deb. It is the same local-first dashboard as every other platform.
Notes
macOS and Linux are testing builds, so please send feedback. Windows remains code-signed and is the recommended path for now.
On some machines the app's built-in health monitor used a memory limit smaller than the memory a healthy app actually needs, so it kept restarting its own server every half minute - pages loaded, but data calls randomly failed. The limit now sizes itself to your machine.
Highlights
✓Fixed: constant background restarts - The health monitor's memory limit now scales with your machine's RAM instead of a fixed number smaller than normal usage, so a healthy app is never killed mid-request.
Notes
Installs update themselves automatically. If you previously set REPOOPS_DESKTOP_MEMORY_CEILING_MB as a workaround, you can remove it - explicit settings still win if kept.
v0.2.1 could show a blank window at the sign-in step on a fresh device - two of the app's gate screens were left out of the packaged bundle. v0.2.2 completes the fix; activation now carries you from the app through Google sign-in and back.
Highlights
✓Fixed: blank window at sign-in on a new device - The activation gate and recovery screens were missing from the app bundle, and the sign-in flow's server callback could fail after choosing a Google account. Both are fixed; packaging now bundles every app screen automatically.
Notes
If the app showed a blank window, download and run the installer again from the download page - it replaces the install in place. Existing working installs update themselves.
v0.2.0's installer left four startup modules out of the packaged app, so the desktop app could fail to launch after a fresh install. v0.2.1 repackages the same release with the fix. Everything listed under v0.2.0 applies.
Highlights
✓Fixed: app failed to start after install - A packaging gap dropped the app's health-watchdog and recovery modules from the bundle; launching showed a JavaScript error instead of the dashboard. The bundle is fixed and a regression test now guards it.
Notes
If v0.2.0 showed you the startup error, just download and run the installer again from the download page - it replaces the broken install in place.
Your brain learns overnight, and your AI bill gets an auditor
Two months and more than 800 changes since v0.1.0. The theme: RepoOps stopped being a dashboard you read and became a loop that works while you don't - it consolidates what your agents learned every night, hands you a 90-second triage in the morning, and audits what your AI vendors charge you.
Highlights
✓Billing Guard - Reconciles what your Claude, OpenAI, Bedrock, or Azure usage should have cost (from your local telemetry and a versioned rate card) against what the vendor actually billed, flags the gap, and drafts the dispute email for you.
✓The nightly brain - A background pass consolidates your project memory every night - a full AI distillation with your own key, or a zero-cost local distiller without one. The Today view greets you with "what your brain learned last night" and the real overnight cost.
✓90-second morning triage - At most three cards a day, each a proposed lesson with replayed evidence ("would have fired in 4 of your last 20 sessions"). One click promotes it to a durable rule and rewrites your CLAUDE.md or AGENTS.md in the same motion.
✓My Brain - A personal brain that follows you across projects and tools: your lessons, decisions, and preferences as local files you own, with capture on-ramps, nightly consolidation, and an "Ask my brain" search that actually cites its sources.
✓Brain Wiki - Every repo gets an auto-written, plain-language explainer of what the code is and how it works. Every claim carries an inline citation that is re-verified on each commit - stale claims turn red instead of quietly lying to you.
✓Marketplace - Browse installable brains and skills at repoops.ai/marketplace. Packs carry prevention receipts: an outcome-measured count of how often their lessons actually fired after install - a rating that can't be faked.
Also in v0.2.0
✓Spend Efficiency grade - One composite grade across six levers (model right-sizing, routing, caching, context, visibility, ROI) with the concrete actions to raise it.
✓Always-on capture - A real OS background service watches your tracked repos and survives reboots - no dashboard window to keep open.
✓Commitments - Promised-but-not-done work gets an owner, a deadline, and a slip alert.
✓Loop contracts - Turn a correction you keep making into a contract with a done-check and a give-up rule, and see whether your automation actually pays for itself.
✓Hundreds of fixes - Faster tabs, lower memory, sturdier background jobs, and a long tail of polish across the dashboard.
Notes
Existing installs update themselves: the app checks repoops.ai on launch and every four hours, downloads in the background, and installs on quit.
Fresh installs: grab RepoOps-Setup.exe from the download page. At the time of this release the build was not code-signed, so Windows SmartScreen asked once (More info, then Run anyway). Later builds are code-signed, so newer installers no longer trigger that prompt.
Platforms at this release: Windows, with macOS and Linux in progress. Both are available now (see the latest release).
Point RepoOps at a local git repo and it remembers what your AI coding agent did, what it cost, and whether anything's unsafe to ship - all on your machine. Nothing is uploaded; your code and telemetry never leave your computer. The local single-developer desktop app is free, forever.
Highlights
✓Project memory (the brain) - Aggregates each repo's accumulated knowledge - decisions, mistakes-not-to-repeat, architecture - into one browsable view.
✓Today view - The home surface: next-best-action, spend and budget, security, ship-readiness, config/env health, and a brain pulse - each deep-linking to its detail tab.
✓Claude Code telemetry & cost - Session usage, spend trends, and model-upgrade recommendations, with LLM-routing guidance.
✓Security guardrails - Plain-language footgun checks (.env in git, committed secrets, open CORS, all-interfaces bind) - each with the exact fix.
Also in v0.1.0
✓Config & env doctor - Catches referenced-but-unset env vars and won't-run-in-prod issues before you deploy.
✓Ship assistant - A go-live preflight verdict plus stack-aware deploy and domain runbooks.
✓Explain my codebase - On-demand plain-language summaries of routes, files, and modules (AI-assisted with your own key; structural fallback otherwise).
✓Vulnerabilities & Dependencies - Live npm audit plus per-dependency risk.
✓File integrity - Sensitive-path change monitoring against origin/main.
✓Auto-update - The Windows desktop app updates itself from repoops.ai - no reinstall.
Notes
Install: download the build for your OS from the download page. The Windows installer (RepoOps-Setup.exe) is code-signed; SmartScreen may still note it isn't commonly downloaded yet, so click More info then Run anyway. The macOS and Linux builds are not signed yet: on macOS, right-click then Open on the first launch. See the install guide.
Privacy: runs entirely on your machine; no account required for the free app.
Optional: add your ANTHROPIC_API_KEY in Settings (bring your own key) to enable spend rollups and AI codebase summaries.