1.52.1 - Keep memory learning off during settings failures

Releases / current 1.52.1

What changed, starting with the version you run

Read the current tagged changes first, then work backwards when a deployment or a behaviour needs older context. Ongoing main-branch work appears in the weekly development log until it is cut into a release.

1.52.1 - Keep memory learning off during settings failures

Released on September 8, 2026. If the memoryLearning setting cannot be read, memory injection and automatic storage are skipped for that turn while chat continues. A settings outage must not turn learning back on after a user disabled it.

Next1.52.0 - Four public-data MCP servers

1.52.0 - Four public-data MCP servers

Released on September 8, 2026. Added four data.go.kr public-data MCP servers to the connector catalog, giving Korean public-data integrations a discoverable installation entry.

Next1.51.2 - Readable role-assignment menus

1.51.2 - Readable role-assignment menus

Released on September 8, 2026. Replaced undefined color classes in the model-role selectors. The dropdown no longer opens with gray text on a white background that conflicts with the surrounding interface.

Next1.51.1 - External model-role assignments stay visible

1.51.1 - External model-role assignments stay visible

Released on September 8, 2026. Raised the minimum max_tokens for B.AI probes and made role assignments outside the current model list visible, so an existing external-model assignment is no longer hidden by the picker.

Next1.51.0 - OpenDART and clearer provider setup

1.51.0 - OpenDART and clearer provider setup

Released on September 8, 2026. Added the OpenDART financial-disclosure MCP server, environment-schema defaults, and deduplication of concurrent server spawns. API-key settings now show provider logos and links to key issuance or authentication pages.

Next1.50.3 - Default-model filtering and saved values

1.50.3 - Default-model filtering and saved values

Released on September 7, 2026. The composer and default-model settings now filter only for chat capability, without the 20B cutoff that had excluded smaller external models. Role assignments and custom agents retain the existing size filter. Saved models outside the list remain visible and are no longer displayed or reset as Automatic.

Next1.50.2 - Preserve the default model after login

1.50.2 - Preserve the default model after login

Released on September 7, 2026. Fixed two paths that reset the saved default model after signing in again: guest-list correction and missing restoration of the saved preference.

Next1.50.1 - Evidence for nightly evaluation failures

1.50.1 - Evidence for nightly evaluation failures

Released on September 7, 2026. Failed evaluation cases now retain the beginning of the model response in results and FAIL logs, making later failure analysis possible without rerunning the original response.

Next1.50.0 - Operational metrics and observable data export

1.50.0 - Operational metrics and observable data export

Released on September 7, 2026. Added ops_metrics as an administrator-only, read-only tool exposed by an intent gate. Fixed memory, skill-manifest, and custom-agent export queries; partial exports now identify failed categories, and automatic extraction and backfill gain audit records.

Next1.49.0 - Strict schemas for local tool calls

1.49.0 - Strict schemas for local tool calls

Released on September 6, 2026. Local tool definitions now include strict:true so vLLM can enforce argument schemas during decoding, bringing schema constraints into generation itself.

Next1.48.1 - Credential-guard follow-up

1.48.1 - Credential-guard follow-up

Released on September 6, 2026. Consolidated the credential exclusion list, aligned directory handling, and recorded how many entries the shell fallback skipped, closing review findings in the new sandbox guard.

Next1.48.0 - Credential files excluded from discovery

1.48.0 - Credential files excluded from discovery

Released on September 6, 2026. Code discovery excludes credential files and reports how many were skipped. Under the high-risk approval policy, writes to sensitive files now require approval. Explicit reads and shell commands retain their existing gates; the all and none policies are unchanged.

Next1.47.0 - Code navigation without repeated approvals

1.47.0 - Code navigation without repeated approvals

Released on September 6, 2026. Added the dedicated code_nav kind so grep_code and repo_map can run without approval dialogs. Name-based exclusions also prevent a worktree’s .git file from slipping into code-navigation results.

Next1.46.0 - Code search and workspace test gates

1.46.0 - Code search and workspace test gates

Released on September 6, 2026. Agent Tasks gained folded tool results, grep_code and repo_map for code exploration, and a workspace test gate as the first set of coding-workflow improvements.

Next1.45.3 - Compatible tool names and security follow-ups

1.45.3 - Compatible tool names and security follow-ups

Released on September 6, 2026. Applied the tool-name codec to OpenAI-compatible providers that rejected server::tool names with HTTP 400. Security follow-ups covered global MCP environment wrapping, REST history images, and dangling symbolic links.

Next1.45.2 - Memory deduplication tuned from live observations

1.45.2 - Memory deduplication tuned from live observations

Released on September 5, 2026. Expanded near-duplicate memory detection with repeated-ending removal and modifier stop words, following observations from live use.

Next1.45.1 - Recognize paraphrased memory duplicates

1.45.1 - Recognize paraphrased memory duplicates

Released on September 5, 2026. Added token similarity to automatic memory extraction so variations in Korean sentence endings can still be recognized as near-duplicate memories.

Next1.45.0 - Memory control and smaller prompts

1.45.0 - Memory control and smaller prompts

Released on September 5, 2026. Made the server authoritative for memory-learning preferences, added deletion tombstones and audit records, corrected source labels, and added extraction-source badges and an observation report. Boundary tags and format filters reduce answer leakage into extracted memories. Prompt work limits skill injection, gives system skills priority, and hides unreferenced MCP servers or low-frequency tools unless relevant. Contact email addresses were unified under openmake.cc.

Next1.44.0 - iOS design alignment and stream recovery

1.44.0 - iOS design alignment and stream recovery

Released on September 5, 2026. Applied the Instrument design system to iOS with web-aligned tokens and fonts. Streaming can detach and resume after a socket disconnect caused by tab switching or backgrounding, and local Agent Tasks now retain the explicitly selected approval policy.

Next1.43.1 - Refresh NVIDIA NIM fallback models

1.43.1 - Refresh NVIDIA NIM fallback models

Released on September 5, 2026. Replaced NVIDIA NIM fallback entries with currently served models after three of four older entries returned end-of-life responses or disappeared from the provider list.

Next1.43.0 - Instrument design system on the web

1.43.0 - Instrument design system on the web

Released on September 5, 2026. Introduced cobalt and cyan colors with Space Grotesk, Noto Sans KR, and IBM Plex Mono. Mobile inputs use 16px text to prevent iOS focus zoom, and touch-pointer icon buttons gained 36px hit targets.

Next1.42.0 - Keep answers in the requested language

1.42.0 - Keep answers in the requested language

Released on September 4, 2026. Added a language reminder after tool results and observations for answer-language drift. Language detection now strips code identifiers so a Korean question containing code is less likely to be misclassified as English.

Next1.41.0 - Research, connectors, and provider error clarity

1.41.0 - Research, connectors, and provider error clarity

Released on September 4, 2026. Added Tavily and Context7 MCP catalog entries, bench web SSO support, live model-list cache refresh, and OpenAI-compatible raw mode. Deep Research now includes the current date in decomposition, accepts valid subtopics more tolerantly, and fixes depth configuration, cancellation, and user isolation. Provider errors distinguish insufficient credit from access restrictions; model probes can recover from demotion, inferred capabilities survive caching, and deployment applies environment changes to PM2.

Next1.40.1 - Preserve reasoning across local tool turns

1.40.1 - Preserve reasoning across local tool turns

Released on September 3, 2026. The local tool loop now preserves assistant reasoning into the next turn and keeps vLLM tool-call IDs, maintaining continuity across tool execution.

Next1.40.0 - External models under real rate limits

1.40.0 - External models under real rate limits

Released on September 3, 2026. Running Discussion and Deep Research on external models hit the per-minute limits of free and developer keys: five parallel expert calls ended in 5/5 429s on a B.AI free key and 3/5 on a hasa key. The external execution client is now wrapped with a per-provider semaphore and exponential 429 backoff that honors Retry-After, Deep Research fan-out concurrency and timeouts follow the provider hint, and the SDK's own blind retries were set to zero with a multiplier on its timeout so a long-reasoning model is no longer cut off every 360 seconds. An explicitly chosen external model that cannot run now surfaces an error instead of silently falling back to local, and the composer notice that claimed external models were ignored was corrected.

The three-step reasoning-effort control is forwarded as reasoning_effort to OpenAI-compatible external providers, where it had only applied to local and ChatGPT OAuth models. Local calls that specify no sampling get the official thinking ON/OFF presets, ten meta calls pass think:false explicitly, and the fallback for an unspecified level dropped from maximum to medium. The per-request prompt image total is capped at vLLM's limit of 8, {{env.KEY}} positional secrets reach MCP servers as sh variable references instead of argv, and three security follow-ups landed: REST image limits, a push endpoint host allowlist, and realpath-based symlink escape blocking in the user sandbox.

Next1.39.0 - B.AI provider and the security review's high findings

1.39.0 - B.AI provider and the security review's high findings

Released on September 2, 2026. B.AI joined as a BYOK provider; all 45 of its models were called with a zero-balance key and only the five free ones went into the catalog. A capability cache filled by model-name heuristics had been hiding measured config values, so a model that supports vision and thinking was rejected for both; inferred rows now defer to config.

The September 2 apps/api security review's first batch closed here. System skills could be overwritten by any authenticated user, which was stored prompt injection into every user's prompt; anyone could assign their own skill to a shared industry agent; and a push subscription could be registered under another userId to receive copies of that user's notifications. Pinning the owner to req.user also fixed web push never having been delivered at all. The batch further covered an IDOR on internal bundle installation, enforcement of the high-risk MCP tool role gate on the execution path, CSV formula injection in exports, an existence oracle on other users' MCP server status, ownership checks that passed on empty values, and an advisory lock around first-run administrator setup.

Next1.38.0 - qwen3.8-27b by default, local models discovered from the gateway

1.38.0 - qwen3.8-27b by default, local models discovered from the gateway

Released on September 2, 2026. The local default chat model is qwen3.8-27b. After the DGX swapped models, the app had stayed bound to the old qwen3.6-35b-a3b name because a single static catalog line was the only source of the model list. Boot and periodic probes now read LiteLLM /model/info to discover local models, and the static list remains only as a fallback. Open AI Service Hub (hasa) joined as a BYOK provider and was added to the LiteLLM gateway as a wildcard deployment.

Next1.37.2 - Nightly evaluation markers, second pass

1.37.2 - Nightly evaluation markers, second pass

Released on September 1, 2026. Two remaining nightly real-model failures were examined. A Korean-language refusal to an English injection had been missing English-only markers and now passes; a request for Klingon stays a failure on purpose, because the model was observed complying with fake Klingon and that is the quality signal the case exists to catch.

Next1.37.1 - Routing golden set at 100%

1.37.1 - Routing golden set at 100%

Released on September 1, 2026. The 27 routing failures left by the expanded golden set were diagnosed as 17 cases of missing vocabulary and 10 topic-boost misfires. Seventy keywords were added across 24 industry agents, the pattern that sent every "짜줘" to programming was narrowed, routing went from 77.5% to 100%, and the threshold was ratcheted to 0.9. A label defect that flagged a normal refusal as a violation and evaluator case-normalization were corrected alongside.

Next1.37.0 - Orphaned sandbox containers reaped at boot

1.37.0 - Orphaned sandbox containers reaped at boot

Released on September 1, 2026. An MCP sandbox container survived three app restarts for two days because the server ignored stdin EOF and only the docker CLI was killed. Containers now carry role, pid, and serverId labels, and boot reaps only those whose owning process is dead. Task sandboxes that must survive for resumption are out of scope by label.

Next1.36.0 - Korean government documents, exact token counts, sandbox defaults

1.36.0 - Korean government documents, exact token counts, sandbox defaults

Released on September 1, 2026. .hwp and .hwpx had been accepted for upload but never read. The pure-JS parser kordoc now extracts HWP 3.x/5.x, HWPX, and HWPML, .hml uploads are allowed, and kordoc is baked into the agent-task sandbox image. Right after deployment the composer's raw-upload list turned out to lack the hwp family, sending a 363KB document as garbled text past the context window; the list is now paired with the backend, and context overflow is reported as CONTEXT_TOO_LARGE with advice to reduce attachments instead of a transient error that retrying never fixed.

Character-based token estimation undercounts JSON logs, base64, and hex badly enough to bypass the context-fit safety net, so requests whose estimate exceeds half the effective context are recounted through vLLM /tokenize. Sandbox posture is checked at boot and enabled automatically during first-run setup when docker and the image are present, uvx tool venvs moved to a cache volume so a readonly rootfs no longer kills uvx-based servers, and the routing golden set grew from 50 to 150 cases with a nightly real-model evaluation script.

Next1.35.1 - Daily routing and TTFT aggregation finds its logs

1.35.1 - Daily routing and TTFT aggregation finds its logs

Released on August 30, 2026. The daily routing and TTFT aggregation job was still looking in the old fixed log location, so it found nothing to aggregate. It now reads OMK_LOG_DIR, the same setting that moved PM2 logs onto a persistent volume.

Next1.35.0 - Commits from a lost branch, recovered in full

1.35.0 - Commits from a lost branch, recovered in full

Released on August 30, 2026. Eight commits stranded on a lost branch were transplanted back. Ports now resolve from .env through a single source instead of the shell that happens to invoke PM2 or Next, which is what let the web fall back to port 3000 and bake the wrong WebSocket address into the build. MCP gained multiple named instances per template, restored at boot, with renaming and registration deletion from the connector list, and the administrator catalog form now sends the field names the API actually accepts. The task result view became readable through artifacts, outcome, and preview; deliverables are persisted to the artifact gallery as well; and a goal that asks for html now gets html instead of the hardcoded markdown default.

Two agent-task defects came back with them. The first task after a process restart ran with zero user MCP tools because the pool was only ever filled by a chat start, a login, or the tool picker, so the model gave up claiming nothing was installed; the pool is now awaited before tools are collected. A token quota was also being reported as "requests used", which read as an upstream provider limit rather than this application's own 429.

Next1.34.0 - Agent work you can resume, share, and inspect

1.34.0 - Agent work you can resume, share, and inspect

Released on August 30, 2026. A week of agent-task work landed in one release. openmake-code can list tasks, resume local work, and reprint a task's result, progress log, and diff, and a queued task no longer becomes a permanent orphan after a restart. Read-only sharing runs across the server, web, and CLI, with shared output opened through an isolated-origin viewer so the shared surface never becomes a second execution channel. Read-only tool calls within one turn now run in parallel across chat, Agent Tasks, and sub-agents, local-bridge writes come back with tsc or py_compile diagnostics attached, and sub-agent activity is recorded alongside a shadow metric for delegation adoption.

Extensions and MCP moved from drafts to a controlled installation path: external skills and plugins are adapted to OpenMake on install, plugin bundles publish into this deployment's own gallery instead of GitHub, draft skills are approved or rejected in groups, an MCP server can be disabled instead of deleted, and remote MCP login uses Authorization Code + PKCE with dynamic registration. Tool health became measurable - per-tool failure rate and cause over a real denominator, with an opt-in circuit breaker for tools that keep failing - approvals were consolidated at /approvals, and administrator pages lost the mock fallbacks that had always been fake and gained role guards.

Next1.33.1 - ChatGPT path corrections

1.33.1 - ChatGPT path corrections

Released on August 23, 2026. Two requests that worked everywhere else were being dropped on the ChatGPT route: a structured request now passes its json_schema in the Responses API shape instead of being ignored, and reasoning effort is forwarded as reasoning.effort rather than silently discarded.

Next1.33.0 - Reasoning effort, answer verification, sturdier structured output

1.33.0 - Reasoning effort, answer verification, sturdier structured output

Released on August 23, 2026. Reasoning effort became a user choice: a three-step control in the composer, normalised per model, with a pass-through hint so a LiteLLM gateway stops rejecting it. Answer verification arrived next to it - a judge model reads the reply once and surfaces what it would question, never rewriting the answer. Structured answers were hardened along the whole path: the schema is emitted in OpenAI strict form so external models stop omitting fields, an unsupported json_schema or a schema mismatch degrades instead of failing with a 422, and output that hits the length ceiling retries at a smaller size.

Model handling stopped trusting configuration over the model itself. Capability interpretation moved to a single source of truth with a boot-time tool-call probe, so swapping a model can no longer quietly disarm tools, thinking is gated on the declared capability instead of misreading a stream, and context length is measured at boot rather than pinned to a fixed 262K threshold. A repeat_penalty mapping bug that never sent the parameter was corrected to the vLLM name.

Next1.32.1 - Bridge file listing no longer blocks

1.32.1 - Bridge file listing no longer blocks

Released on August 23, 2026. Filesystem calls behind the bridge file kind moved to async with a timeout guard, so one blocking call can no longer take down every connected root.

Next1.32.0 - Local execution consolidated, native companion

1.32.0 - Local execution consolidated, native companion

Released on August 23, 2026. The local execution track closed its first axis and opened its second: creating a local agent task is now written to the audit trail, and the bridge device code was consolidated into a single packages/local-bridge-core so every client runs one implementation. A first SwiftUI native companion landed alongside it - helper bridge, approval dialog, notification deep links, and its own native update channel - and several roots can be connected at once, each with an independent bridge connection under a derived device id. The Electron shell is frozen to security fixes from here; desktop-native is its successor.

Routing now skips the LLM for URL-only queries and uses a domain hint instead, while a gate-decision observability loop aggregates routing gates into a weekly report. Installation gained an update subcommand behind a two-stage installer CI gate, the chat composer folded its attachment buttons into a single + menu covering files and folder selection, and connecting an untracked subfolder no longer fails with a worktree cwd ENOENT.

Next1.31.1 - External-provider guard split

1.31.1 - External-provider guard split

Released on August 22, 2026. The external-provider path in chat was split under the 600-line guard, taking one module from 594 lines to 353 without changing behaviour.

Next1.31.0 - Camera and voice input on the phone

1.31.0 - Camera and voice input on the phone

Released on August 21, 2026. Stage three of the phone feature line adds camera capture and voice input on iOS.

Next1.30.0 · Location context on the phone

1.30.0 · Location context on the phone

Released on August 21, 2026. Stage two of the phone feature line adds GPS location context to requests and applies the web logo as the app icon.

Next1.29.0 · Bridge folder selection

1.29.0 · Bridge folder selection

Released on August 21, 2026. A bridge folder-selection protocol lets the web choose the folder a local run executes in without restarting the CLI, and the readiness log records the selected folder alongside it.

Web search now caps query length, so a long prompt no longer comes back as a provider 414.

Next1.28.0 · API key scope hardening

1.28.0 · API key scope hardening

Released on August 20, 2026. API keys now carry explicit bridge and chat scopes, so a key issued for one surface cannot be replayed against the other.

Next1.27.0 · OpenMake Code and workflow observability

1.27.0 · OpenMake Code and workflow observability

Released on August 20, 2026. OpenMake Code is a local CLI agent task: tools run on your own machine instead of the server's Docker sandbox, while turn orchestration stays on the server. It speaks the same bridge protocol as the Desktop app and adds no agent loop of its own.

The administrator surface gains four agent-task workflow observability metrics, and OpenAI-compatible clients now merge a system message into the leading system prompt instead of dropping it.

Next1.26.0 · Mobile rendering and iOS foundations

1.26.0 · Mobile rendering and iOS foundations

Released on August 19, 2026. The three iOS tracks land together: OpenAPI contracts as the source of truth with contract tests and a CI drift gate, mobile authentication with refresh-body mode and OAuth exchange codes, and a SwiftUI MVP covering OpenMakeKit, chat, OAuth, and iOS CI.

Answers were reshaped for phone screens - tables become cards, long answers collapse into sections, and Kakao map blocks render as native map cards backed by a server embed with a MapKit fallback. The release also raises the default agent-task turn limit from 10 to 32, limits trigger-declared skills to relevant turns, adds a least-privilege host:port form to the SSRF allowlist, records the MCP instance pid so health checks can detect dead processes, and redraws the brand mark for the favicon, logo, and iOS/PWA icons.

Next1.25.0 · Extensions and mobile foundations

1.25.0 · Extensions and mobile foundations

Released on August 16, 2026. OpenMake adds an Agent Plugins v1-compatible extension bundle layer with .zip sources, version checks, updates and reinstall, workspace sharing and galleries, an administrator-curated catalog, and marketplace.json installation.

Settings now includes extension management for installed bundles, component status, and removal. Large-repository skill ingestion now generates skill_manifests, while installation identity and manifest handling, agent-task verification-file cleanup, and Korean IME Enter double-submit handling were hardened.

Next1.24.1 · Citation and agent-task recovery hardening

1.24.1 · Citation and agent-task recovery hardening

Released on August 15, 2026 as a follow-up bug-fix release. Tool-result evidence now reaches the goal judge, zero-complete plans cannot be misread as finished, and dead citation markers are removed while responses are constrained to real source numbers.

The release also strengthens expired-token session restoration, OAuth account binding, search quotas, and the desktop execution path.

Next1.24.0 · Operational settings and isolated execution

1.24.0 · Operational settings and isolated execution

Released on August 14, 2026. Operational settings now live in system_settings and an administrator UI. A first-run setup wizard and automatic boot-secret generation reduce environment editing, while installation gains a curl bootstrap, OS detection, port-conflict avoidance, Windows-to-WSL2 guidance, and an uninstall path.

Local agents run in isolated Git worktrees with a creation commit fixed as the diff baseline. Completion judgment is consolidated and persisted, alongside parallel image generation, stronger task-sandbox packages, automatic ChatGPT OAuth verification, GA4 measurement, and WebSocket port-migration fixes.

Next1.23.0 · Operator visibility and usage cost

1.23.0 · Operator visibility and usage cost

Released on August 9, 2026. An administrator can now switch history, Deep Research, and agent tasks to an all-users view with an owner badge on each entry, and the full-conversation view paginates on the server instead of stopping at a cap. Conversations are searchable by body text, not just title, with the matching excerpt shown alongside the result.

Token usage is converted into an indicative cost by day, month, and year - not actual billing - with the coverage start date stated and the default unit price taken from published Qwen3.8-Max rates. Failed and cancelled agent tasks can be retried from the beginning, messages gained copy and regenerate controls, model-role assignment changes are written to an audit log that captures the previous value atomically with the write, and HTML responses now send HSTS with X-Powered-By removed.

Next1.22.2 · Large-PDF workflow fixes

1.22.2 · Large-PDF workflow fixes

Released on August 8, 2026. Three defects in the large-PDF workflow were fixed together: Korean filenames, the turn budget, and visibility while a task waits for approval. Documents whose extraction failed are now also eligible for the raised turn budget, so a hard document no longer runs out of turns before it can report why.

Next1.22.1 · Instrumentation blind spot

1.22.1 · Instrumentation blind spot

Released on August 7, 2026. Tool instrumentation no longer has a blind spot for task-side calls, and version lookups on task artifacts stopped emitting 404 noise.

Next1.22.0 · Execution graph and one-shot install

1.22.0 · Execution graph and one-shot install

Released on August 7, 2026. Execution steps are attributed to the plan node that produced them through plan_step_index, the next step is deterministically promoted to in_progress once the previous one completes or blocks, and task detail shows a plan-node badge so the graph is readable from the UI.

A one-shot install script for Linux and macOS landed alongside a fix for a boot failure on a fresh clone. History coverage widened to structured storage, administrator task and research tabs, and OpenAI-compatible session continuity. The release also adds a scrape cache, URL normalization, an external-content boundary guard, search-source labels on web_search results, clipboard paste attachments in the composer, an opendataloader 2.5.0 upgrade with multilingual sandbox baking, and fixes for the five main causes of sandbox tool errors.

Next1.21.0 · Agent-task resilience and unified history

1.21.0 · Agent-task resilience and unified history

A retrospective of twenty failed agent tasks set this release's direction. Transient LLM errors — 5xx, 408, 429, and connection-class failures — now retry with exponential backoff instead of killing the whole task, while user cancellation and exhausted budgets still stop immediately. A task left waiting on approvals is demoted after two unanswered timeouts: approval-gated tools are removed and the task is nudged to close with the information it already has, while an explicit rejection keeps its old meaning. Every retry and demotion persists as a step, so their frequency reads straight from the database, and each turn now records which tools it intended to call.

The history list now shows agent tasks alongside conversations, newest first in the same date groups. Task entries are read-only — a badge and status label identify them, clicking one deep-links into the task detail, and deleting history still only touches conversations.

Next1.20.0 · Scanned-document OCR and chunked upload

1.20.0 · Scanned-document OCR and chunked upload

Scanned PDFs without a text layer are now readable. An agent task narrows the document to the chapters it needs from the table of contents and runs OCR on those pages inside the sandbox, while attachments under 30MB are OCR'd across pages in parallel at upload time. Files upload in chunks, so the 100MB per-request ceiling no longer stops a large document — a 66MB scanned PDF now runs from upload through to a finished report artifact.

Agent task termination was corrected as well. A task that exhausted its turn limit used to be reported as completed; it now fails and can be resumed, and reaching a resource limit forces a closing turn so the output is not cut off mid-artifact. Goal input accepts 20,000 characters and keeps code blocks intact. The release also cleans up tool-call leakage and language mixing in responses, fixes missing images on non-streaming replies, adds external key validation and usage screens, and hardens SSRF IPv6 ranges with a rate limiter dedicated to agent tasks.

Next1.19.0 · Dispatch tuning and shadow previews

1.19.0 · Dispatch tuning and shadow previews

Orchestration auto-dispatch was tuned against a benchmark, so the decision to open a discussion or hand work to a background task follows a measured pattern rather than a first draft. Shadow instrumentation now stores a preview of the query behind each decision, which is what makes a dispatch record readable after the fact.

Next1.18.0 · Auto-dispatch and gateway routing

1.18.0 · Auto-dispatch and gateway routing

The model can now assign discussion and background task delegation as tools of its own, exposed only on the turns an intent prefilter matches. It ships behind ORCHESTRATION_AUTO_DISPATCH and does nothing until you enable it, while shadow instrumentation records what it would have decided.

LLM_GATEWAY_PROVIDERS routes external provider inference through the LiteLLM gateway instead of calling each provider directly. Leave it unset and every provider keeps its direct path; Ollama Local and ChatGPT OAuth stay direct either way, and a single provider is rolled back by removing it from the list. Router vocabulary work in the same release moved routing accuracy to 93.3%.

Next1.17.0 · Report pipeline

1.17.0 · Report pipeline

Report-intent requests now produce structured report data that the server renders through a fixed HTML template. Report artifacts can be exported to PDF or DOCX, and report work can be delegated to an agent task when the request needs more research turns.

Next1.16.1 · Desktop stability

1.16.1 · Desktop stability

Desktop 1.7.1 fixes a packaged-build defect that could omit agent-browser.js and leave the app window missing. The release also adds a post-package ASAR require check to prevent the same omission from shipping again.

Next1.16.0 · Local agent browser and artifact guards

1.16.0 · Local agent browser and artifact guards

The Desktop app can run an agent browser tool in local Electron Chromium (Cowork D3). Artifact actions now verify whether generated code is executable before exposing a Run control.

Next1.15.1 · Fail-closed credential handling

1.15.1 · Fail-closed credential handling

MCP environment credentials and external-provider keys or OAuth tokens now fail closed when decryption fails, instead of allowing a broken decryption path to continue.

Next1.15.0 · Scheduled reports and MCP credential rotation

1.15.0 · Scheduled reports and MCP credential rotation

Scheduled agent reports can publish artifacts automatically, and registered MCP server credentials can be replaced. The release also fixes several credential-handling issues in the MCP execution path.

Next1.14.0 · Connected-folder visibility

1.14.0 · Connected-folder visibility

Agent tasks gained better subfolder awareness, and Desktop makes the connected local folder visible so users can tell which workspace a local task can access.

Next1.13.0 · Usage clarity

1.13.0 · Usage clarity

External BYOK provider usage is explicitly exempt from the local token quota, so a user who brings their own key is not billed twice against the workspace limit. The ChatGPT OAuth role path also records usage, which closes a gap where an operator could not tell which route had been taken.

Next1.12.0 · Research evidence

1.12.0 · Research evidence

Deep Research now connects configured skill knowledge and MCP tool evidence into the research pipeline, so a report can draw on your own connected sources instead of web search alone.

Next1.11.0 · Model list accuracy

1.11.0 · Model list accuracy

External models that cannot actually be used are excluded from the list, an over-eager vision block on external models was corrected, and a failed external vision call now falls back to the local model instead of erroring out.

Next1.10.0 · Skills for agent tasks

1.10.0 · Skills for agent tasks

Automatic skill selection reaches agent tasks, not just chat, when it is enabled. A role-assigned ChatGPT model that returned 403 and silently fell back to the local model was also fixed.

Next1.9.0 · ChatGPT subscription OAuth

1.9.0 · ChatGPT subscription OAuth

A ChatGPT subscription OAuth provider was added and external models were opened to the /v1 API surface. The flow is unofficial and depends on the provider's policy, so treat it as an opt-in convenience rather than a supported integration.

Next1.8.0 · Desktop sandbox completes the three-layer defense

1.8.0 · Desktop sandbox completes the three-layer defense

An OS-level sandbox (sandbox-exec) was added to desktop command execution, completing the three-layer defense: an immediate denylist, non-bypassable confirmation, and OS-enforced isolation. The mcp-runtime image also bakes in its Chromium system dependencies.

Next1.7.1 · Security hardening

1.7.1 · Security hardening

Desktop security hardening and the local bridge execution trust model landed alongside thirteen fixes from a source security audit covering IDOR, RCE, SSRF, authentication, CSRF, and general hardening. Personal identifiers and fixed credentials were removed from the public repository.

Next1.7.0 · Verified self-updater

1.7.0 · Verified self-updater

The desktop app gained a self-updater driven by a server manifest, which is the mechanism behind today's SHA-256 verified update path.

NextDesktop 1.10.0 · Local work boundary

Desktop 1.10.0 · Local work boundary

The desktop menu shows which local folder is connected without sending its full path to the server. The local bridge keeps realpath-scoped access, per-command confirmation, and sandbox protection, so an agent task can work on your machine without becoming a remote shell.

The 1.6.0 line began with the local bridge executor itself: agent tasks can run tools on the user's machine once a folder is connected, with a composer toggle and a badge in the task list showing when that is happening.

That line ends at 1.10.0. Its bridge became a shared core, and local work moved to the Companion — the Electron build stays downloadable for anyone already running it.

OpenMake Desktop 1.10.0 connects to an existing OpenMake service; it does not bundle the backend. Captured with the Korean interface.
NextArchive

Archive

1.5.7 fixed version and git tag reporting in the /health response. Earlier releases remain useful for upgrade context — compare the changelog in the repository when a change affects your deployment.