Fixed
- Memory leak when a browser closed on its own. If a browser exited outside the Stop button (a crash, or closing Chrome from inside the profile window), a helper process was left running and holding around 130 MB. These built up over time on a long-running manager. The manager now releases it on that path as well.
Added
- License and seat limits now surface in a banner. When a profile fails to launch because the plan's concurrent-session limit is reached or the license key is invalid, the Manager shows a dismissible top banner with an Upgrade link instead of failing silently.
- Automated multi-architecture Docker releases. Version tags now build Linux AMD64 and ARM64 images on native GitHub-hosted runners, combine them under one Docker tag, and publish both the release version and
latestalongside the Windows and macOS installers.
Changed
- Safer release validation. Docker architecture digests, provenance, and the combined manifest are validated before publication, and
latestis promoted only from a complete verified release. Release tags are validated as canonical semantic versions, and workflow dependencies are pinned to immutable revisions.
macOS (universal — Apple Silicon + Intel): not notarized yet, so macOS blocks the first launch. Run xattr -rc "/Applications/CloakBrowser Manager.app" once, or use System Settings → Privacy & Security → Open Anyway.
Windows: if SmartScreen warns, click More info → Run anyway.
The stealth Chromium engine downloads on first launch.
Verify your download against SHA256SUMS (attached): shasum -a 256 -c SHA256SUMS.