Stable downloads: https://download.cmtraceopen.com/?source=github-release
CMTrace Open v1.6.2
Download shortlinks
Each shortlink always resolves to the current stable release, so it stays valid in
tickets, runbooks, and slides long after this page scrolls out of view.
| Platform | Shortlink |
|---|---|
| Windows x64, portable EXE | https://win.cmtrace.net |
| Windows ARM64, portable EXE | https://winarm.cmtrace.net |
| Windows x64, Lite portable EXE | https://lite.cmtrace.net |
| Windows x64, MSI installer | https://msi.cmtrace.net |
| macOS Apple silicon, DMG | https://mac.cmtrace.net |
| Linux x64, AppImage | https://linux.cmtrace.net |
Nightly channel: https://nightly.cmtrace.net
The MSI installs both the Full and Lite editions. Portable EXEs require no installation.
CycloneDX SBOMs (sbom-rust.cdx.json, sbom-npm.cdx.json) and build provenance
attestations are published alongside the binaries.
Changed
-
Parser and IPC source compatibility: The parser source version advances from 0.1.1 at v1.6.0 through 0.2.0 to 0.3.0. Changes include the required
ErrorCodeSpan.outcomefield, caller-supplied DsRegCmd evaluation time, canonical Intune/CCM module paths, the removal of environment expansion from the parser crate and of the timeline error variant, newParseResult.modified_unix_ms/AggregateParseResult.child_errorsfields for Rust struct constructors, and expanded event/provenance data contracts. Downstream source consumers must update; desktop version 1.6.2 does not publish the parser crate. -
Observed BGB source contract (#775): Record sanitized client-notification evidence and the Simple-framed
BgbServer.logformat for the observed site version. The card remains capture guidance: its keys are unvalidated and the SCCM evidence admission path does not admit this Simple-framed source as supported diagnostic evidence. -
Redaction architecture decision (#589): Record accepted ADR-004 revision 2 for context-bound publication. The ADR defines later implementation work; this release does not claim that all Intune lanes implement its future contract.
-
Canonical Intune parser ownership (#356): IME analysis now lives under
intune::apps::windows::ime, ESP underintune::enrollment::windows::esp, and shared logical CCM framing underparser::ccm::logical. The former public paths and ESP-only administrator-restart command are removed. Captured ESP bundles require a manifest; a missing manifest is reported as missing coverage without discovering undeclared evidence.
Added
-
Expanded Event Viewer (#583): Add provider-database import/export and packaged provider metadata, recovery and source-coverage reporting, event diagnosis, reusable filters, triage highlights, durable event markers, and a unified timeline. Event identities and source provenance survive merged and streamed loads; records without a placeable timestamp remain visible. Exact evidence keys drive correlation, and incomplete evidence stays explicit.
-
Live Event Log operations and portable evidence (#583): Add Windows live tail and an explicitly confirmed channel-clear operation, diagnostic ZIP intake, bounded capture/archive handling, and streamed exports that follow the visible filter and ordering. Provider handling retains coverage gaps; normalized event exports apply identity masking. Provider-database export preserves the validated database bytes. Live Windows operations remain Windows-only; offline evidence has separate supported paths.
-
Stop large explicit event loads (#639, #643): Stop a running channel load, retain the fetched records with cancelled/incomplete coverage, and allow a fresh load. Concurrent channel reads share the cancellation request; explicit loads remain frontend-owned under ADR-005 rather than gaining backend paging.
-
WIM metadata parser foundation (#597): Add pure byte-slice parsing for WIM headers, resource entries, and image XML metadata. Unsupported compression, split images, malformed XML, invalid versions and out-of-bounds resources produce coverage states. This is parser-library groundwork, not a new image-extraction or mounting UI.
-
Event detail resolves the error codes in an event's text (#665): A grid full of
0x8007…and HRESULTs from MDM, AppX, Windows Update or ConfigMgr events was readable only by opening the Error Lookup dialog and retyping the code. The detail pane now lists the codes it finds in the message and event data with their name and category, and marks a code the database cannot explain as not in the database rather than staying silent. Results stay associated with the selected event text, so a pending or failed lookup cannot show the previous event's codes. Detection stays in the parser crate, so the frontend never grows a second idea of what a code looks like (#665). -
Configuration Manager and Intune error code coverage (#614): The embedded table now resolves every
0x87D…code published withError source: Configuration Managerand every0x87D…code in the Intune app installation error reference: 54 new codes, plus published wording replacing paraphrased text on 9 existing entries (792 codes total).
Fixed
-
Standalone Windows Event Log exporter: Remove the live-query metadata limit's dependency on the separately gated Intune diagnostics module, preserving its 512 KiB bound. Linux and Windows CI now compile library tests and run the exporter CLI tests with only the release's
event-logfeature enabled, catching the feature combination that failed in the 1.6.1 draft build. -
Linux AppImage launcher permissions: The npm build commands prepare Tauri's x86_64 AppRun launcher with mode 0755 before AppImage bundling and signing. Debian/RPM-only and executable-only builds leave the launcher cache and network untouched. This addresses the launcher permission denial reported by AppImage catalog #8206; Linux library compatibility remains a separate requirement.
-
Moved environment-variable expansion out of the pure parser crate:
collector::env_expandread the host process environment, which is engine-side work under the crate's own boundary rule. It now lives in the shared nativesrc-tauri/src/env_expand.rsmodule, so collector and ESP diagnostics can each use it without enabling the other feature. CI checks the ESP-only and collector-only builds to protect that boundary. -
DsRegCmd capture freshness uses an explicit evaluation instant (item 3 of #738): Both public analysis entry points now require
evaluated_at: DateTime<Utc>, supplied once at the application boundary and passed through to the capture-confidence rules. Fixed-time public API regressions cover repeatability and the existing confidence thresholds. This removes the DsRegCmd freshness clock read; other parser clock and local-time behavior is outside this change.cmtraceopen-parsergoes to 0.3.0, and the native dependency requirement moves to0.3, because the required argument breaks the previous 0.2.0 source API. -
event-log-export --helpexits zero (#740): A help request took the usage-error path, so it printed its usage to stderr and exited 1 - a caller checking the interface, including the exporter's own CI smoke step, saw a failure.--helpand-hnow print the usage on stdout and exit 0, while a genuine usage error - no source, or an unknown argument - still exits 1 with its diagnostic. -
External diagnostic tools run under a deadline (#684): The bounded-command runner the ESP queries used was private to that module and compiled only on Windows, so the macOS diagnostic tools (
mdatp,pkgutil,profiles,system_profiler,sw_vers,log) and the SCCM CIM query ran with no deadline at all: a hanging tool could leave its diagnostic operation waiting indefinitely. The runner now lives inprocess_utilas one cross-platform primitive with a neutral error type, the ESP lane keeps its own vocabulary through a thin adapter, and the tools whose output is read are bounded by it. The non-waiting interactive launches and the elevated boot-script wrapper retain their existing execution behavior. -
A rotated-in log larger than the old offset is detected as a new file: Tail rotation was detected by size, so a replacement that had already grown past the offset held for the previous file was missed: the reader sought into the middle of the new file, never read its head, and could emit a partial first entry. Rotation is now detected by file identity (#687).
-
ReportingEvents.log parses as ReportingEvents again (#657): A real
ReportingEvents.logwas detected as plain text and every row fell through to a raw line: no timestamp, no provider, no severity, and hundreds of successful Windows Update transactions counted as Info. The record carries the writing machine's offset (-0500), writes the millisecond group with.or:inside one file, and orders its fields differently from the shape the parser expected. The parser now reads the real order, keeps the offset as provenance, normalises the display to the form every other log's Date/Time column already uses, maps the provider to the component, takes severity from the agent's own status, and turns the hexadecimal result code into the0xNNNNNNNNform the error database and message highlighting expect (240005becomes0x00240005). -
Native IME timestamps use the local offset at the record date (#738): Zoneless IME records on native targets now use the reading machine's offset at the recorded date, avoiding a one-hour epoch error across DST seasons. Explicit source offsets remain authoritative. Nonexistent or repeated local clocks retain the previous current-offset fallback. The browser WASM backend retains that fallback for all zoneless records because its timezone library cannot report ambiguous clocks; its seasonal-offset behavior is not fixed here. Servicing timestamp resolution is unchanged.
-
The log list no longer names an unmounted row as active: Rows come from the virtualizer, so scrolling the selection out of the window unmounted its element while
aria-activedescendantstill pointed at it — a reference to nothing. The attribute is now set only when the selected row is among the mounted virtual items, matching what the registry tree already does (#711). -
Insufficient evidence no longer reads as "No issues detected": The event diagnosis panel mapped five outcomes onto four labels, collapsing
insufficientEvidence— a coverage gap — onto the same wording asnoFindings, a clean result. Both the badge and the producer's headline now distinguish incomplete evidence from a result with no findings. The panel tests render serialized summaries verified against the producer, so a mock headline cannot hide contradictory wording (#714). -
Second launch opens in the running window (#565): A second launch, whether a file-association double-click or a path on the command line, hands its files to the window that is already open, which raises itself and opens them like any other path, instead of leaving a second window behind. An elevated restart is a replacement rather than a second launch, so it never routes itself.
-
A failing workspace no longer takes the whole window: The active workspace, including Log Explorer, renders inside an error boundary, so a workspace that throws shows a panel naming it and its error while every other workspace stays reachable. Log Explorer also recovers when another file loads, the failed file is closed, or a comparison is created again or closed. A separate application boundary shows a reload action if the shell or theme fails before a workspace mounts. Startup failures also clear the splash, which previously could remain indefinitely (#698).
-
README and CONTRIBUTING linked documents that no longer exist:
219536ffremovedDSREGCMD_TROUBLESHOOTING.md(moved to the wiki) andFEATURE_IMPROVEMENTS.md(stale roadmap) but left the links behind, so the README sent every visitor to a guide that is not in the tree. The README now points at the wiki page that holds the guide, and CONTRIBUTING lists the wiki instead of two dead entries. -
The decisions index lists ADR-005 (#539): The table of architecture decisions in
docs/architecture/decisions/README.mdstopped at ADR-004, so the decision governing a very large explicit event load was not reachable from the index that exists to list it. The row records the ADR’s accepted status following #679. -
Process-launch comments distinguish launches from waits (#684): The file-manager and System Settings comments now explain that
spawnreturns a child handle without waiting for the launcher to exit, and the handle is discarded. The Secure Boot wrapper comment describes its existing wait through elevation consent, script execution, and descendant processes. Execution behavior is unchanged. -
Updater manifest publisher: The
publish-updater-manifestjob in both release workflows called its local action without checking the repository out first, so it died at load time withCan't find 'action.yml'andlatest.jsonwas never published by that path — the job had never once succeeded. Both callers now check out, and a workflow-contract test fails naming any job that runs a local action without doing so. -
The macOS diagnostics tab row is a real tab list: The strip rendered raw buttons whose active state was a CSS class alone, so a screen reader heard buttons with no indication of which tab was current. It now uses the same tab component as the JAMF workspace, which supplies the tab list and tab roles,
aria-selected, and arrow-key navigation (#713). -
Epoch-zero file modification times display as dates: The source sidebar now distinguishes a genuine modification time of zero from an unavailable timestamp (
null). This relies on the multi-file loader carrying real file metadata (#662). -
Package-manager manifests caught up to 1.6.0 (#625, #690): Updated the repository Scoop manifests and Homebrew cask to the existing 1.6.0 artifacts. The Homebrew DMG hash was verified from the downloaded artifact. The 1.6.2 manifest updates need hashes from the final release artifacts.
-
Deployment folder scan is bounded, and says when it was: The recursive scan behind "analyze deployment folder" now stops at a depth bound, caps collected paths at 5,000 and enumerated entries at 50,000 across the tree, and does not descend a directory symlink, in a synchronous command that previously followed links and had no limit at all. A directory exceeding the remaining entry budget is skipped without selecting an arbitrary prefix; unreadable directories and failures to inspect traversal paths are reported as coverage gaps. Selected logs that cannot be read remain Unknown records. Limitation details retain at most 20 distinct messages and an omission notice, with bounded hash deduplication. Empty incomplete scans are labeled as incomplete in the status bar, counts describe discovered logs, and intake rejects outcome totals that contradict the file records. It also reports which bound it hit, so a partial scan is not presented as the folder's contents: the workspace states "Scan incomplete" with the bounds named, and the status bar marks the count (#702).
-
DsRegCmd export boundary (#556): The analysis the workspace receives is now a redacted projection, so the JSON summary, rendered summary and copied status text use the parser's identity masking. This does not resolve the separately held short-identity narrative or raw live-capture bundle issues. The unprojected form is reachable only from
analyze_text_preserving_local_values, which the rules evaluate against inside the crate. -
CBS.log and dism.log zoneless timestamps use the viewer's local zone (#657): The servicing prefix is the servicing host's local wall clock with no offset, and both parsers promoted it to UTC. Every epoch consumer — the Time Range header, sorting, and elapsed time — was therefore shifted from the Date/Time column by the machine's offset, and a merged CBS + DISM view could not claim a shared window. The prefix is now resolved through the viewing machine's local zone. A bounded spring-forward gap is clamped to the transition instant to preserve chronological order; a repeated fall-back clock or a gap that cannot be bounded keeps its text without an epoch. A zoneless source does not establish the original machine's timezone. Timezone stance recorded in
references/log-format-reference.md. -
Removed the reserved timeline source-read error variant (#721): Removed
TimelineError::SourceReadand the TypeScriptkind: "sourceRead"union member. No checked-in producer emitted it; per-source failures remain inTimelineBundle.errors. This removes a public Rust variant and narrows the exported TypeScript type, so external code that names the obsolete variant must be updated. -
Removed an unused timeline hook:
useTimelineBundlehad no consumers - the modules that import that file all use the exportedbuildTimelineFromSourcesinstead. The hook is gone and the module is renamed to match what it exports. -
Merged folder view reports the parsers that read it (#657): The aggregate stream dropped its format and parser provenance, so a folder whose files were all read by their dedicated parser reported
Unknown formatwith noDedicated/ quality labels. The merged status line now reports the composition — the shared format, provenance, and quality, or an explicitMixed— from the per-file parser selections the folder load already had. -
Error Codes table no longer counts completed operations (#657): CBS.log writes
[HRESULT = 0x00000000]on successful steps, and the table counted every recognized code in a message regardless of outcome, so a healthy log appeared to fail withS_OK. Error codes now carry a failure / success / success-requires-action outcome, and the table counts failures plus codes that still require action (a pending reboot) only. -
Multi-file open reports each file’s modification time (#662): Multi-file source entries now carry the file system’s modification time when available. Cached parse results do not retain file metadata and report an unavailable time instead of inventing one.
-
MAC profile payloads stop dropping settings after a brace (#706):
extractBracedBlockandcollectBalancedBlockcounted{and}without regard for quoted values, so a brace inside one — a quoted value ("a}b"), a filter expression, a regex, a format placeholder — ended the block early and every setting after it was dropped with no error and no warning. A viewer that shows a partial profile that looks complete is worse than one that reports a parse error. The scan now tracks quoted regions and backslash escapes, and both callers share it; the array-of-dicts path had also been passing an index one character past the opening brace, so its dicts were read from the wrong offset. -
Source panel follows a second known log source (#657): Switching to a known file source (CBS.log, DISM.log) restored the sidebar through the folder lane, whose listing call refuses a file source; the refusal was swallowed, so the panel kept the previous source's header and path while the main view showed the new file. File-shaped sources now set the panel directly, and the restore is one code path for both shapes.
-
Removed two capability flags nothing read, and used the live-acquisition helper that already existed:
WorkspaceCapabilities.liveAcquisitionand.multiFileDropwere declared, typed, documented, and never read by application code. ESP acquisition checks were first centralized in a helper (#717); the later backend-capability change (#734), described above, determines the final behavior. -
ESP live acquisition asks the backend instead of guessing the platform (#718): Whether live acquisition is possible was answered twice — the Rust probe sets
live_acquisition_supportedfrom the target the binary was built for and explains itself inlive_acquisition_detail, while the workspace comparedcurrentPlatformand carried its own copy of the sentence. The workspace now reads the capability the backend publishes and shows its explanation, falling back to the platform comparison only when the probe does not answer, so changing what a build supports changes what the UI says. -
Removed a stubbed WhatIf filter and an unproduced source status:
WhatIfFilterand its store field, setter, default and reset had no reader;SourceStatusKindcarried"auto-selected-file", which nothing constructs or compares. -
Design-system repository path and duplicate-file cleanup (#694): Point the design-system guide at this repository's source tree, remove an unused theme copy, and ignore common Finder duplicate filenames so accidental copies stay out of future changes.
-
ESP export no longer publishes a short identifier in narrative (#752): Every classified value carried the six-byte floor that exists to keep junk firmware serials ("0", "N/A") from mangling readable narrative, so a value read from a field that declares an identity was held to a bar meant for arbitrary content. A tenant domain four bytes long was masked in its typed field and left verbatim in the narrative naming the same value — one export contradicting itself about one value. The floor is now stated per field: a serial keeps the existing bar, while a tenant id, tenant domain or user principal name is scrubbed from four bytes, which is short because the identity is short. Values below four bytes still escape, and that remainder is unchanged and stated in the constant's documentation.
-
Registry keys differing only in case no longer split the tree: The registry tree keyed its nodes on the raw path, so
HKLM\SOFTWAREandhklm\SOFTWARE— the same key on Windows — built two independent subtrees. Keys are now matched case-insensitively while the tree still displays the casing the file used: a key that merges into an existing subtree takes that subtree's casing for its own path, so a node always prefix-matches the parent it hangs from, and collapsing a subtree moves the selection back to it instead of leaving the selection on a row that just disappeared. Selecting or searching a merged key displays values from every case-equivalent source section, retaining repeated value records (#708). -
DsRegCmd evidence and findings (#590, #642): Move bundle loading and analysis off the Tauri main thread. Distinguish failed SCP queries from missing configuration, avoid inventing PRT/certificate timing without capture time, match Win32 and AADSTS codes as complete codes, and remove unsupported replication/migration conclusions. Sort Top Findings by severity; handle malformed endpoints, registry values and event timestamps conservatively; log malformed evidence by its bundle-relative name.
-
JAMF and Intune workspace behavior (#631, #725): Keep the JAMF workspace active when opening its own log and give it a clear label. Rename the generic Intune analysis workspace to identify its purpose.
-
SCCM client and site versions (#772): Read client version from
SMS\Mobile Clientand site-server version fromSMS\Setup, show them separately, and use the site version for server-scoped capture authorization. Missing versions remain coverage gaps. -
Event, timeline, marker and registry interactions (#583): Reject stale source transitions, preserve lossless event-record IDs and source identity, serialize marker persistence, retain dirty markers after I/O errors, and keep source failures visible. Improve registry keyboard/focus behavior, dialog ownership and focus restoration, and native Always on Top state/listener handling.
-
Windows file-association ownership (#583): Verify the selected handler, scope prompts to the installed edition, and clean up stable/nightly and Full/Lite runtime registrations during uninstall without treating an ordinary NSIS uninstall as a different channel.
-
Evidence collection and shared text matching (#583, #632, #644): Make collection bundle timestamps and identifiers culture-independent. Consolidate caseless matching and group Autopilot distinct values using that shared normalization; retain the existing workload-specific masking rules.
Build & CI
-
Windows release signature verification: Require successful native Windows signature and timestamp verification for each Full/Lite portable EXE, NSIS installer and MSI before attestation and upload. Check the expected publisher and timestamp authority, record source/run/target, SHA-256 and certificate evidence, and reject missing or changed files. Recheck receipt coverage and hashes before both artifact and release uploads. Certificate leaf and timestamp-device rotation remain supported.
-
AppImage build baseline and evidence (#786): Build the Linux desktop packages on Ubuntu 22.04 and inspect the AppImage launcher modes, strong GLIBC imports and static versioned dependency closure. Record the final image hash and source/build inputs in an ABI report. Release builds archive the signed AppImage and report after the draft upload so runtime acceptance can use the same bytes; these static checks do not establish runtime compatibility. Native check jobs and the separate Linux exporter retain their existing runner baselines.
-
Source and regression gates (#589, #626, #637, #704, #705, #749): Pin the build toolchain to Rust 1.98.1 while retaining Rust 1.88 MSRV checks; enforce formatting, changed-range whitespace and parser WASM compilation. Explicitly requested EVTX fixtures now fail when absent. Add provider-database manifest, filtered Quick Stats, and timezone/DST regression coverage.
-
Review and package automation (#623, #660, #784): Publish Scoop updates as pull requests, constrain incompatible dependency proposals, and preserve CodeRabbit approval across later discussion-only reviews. The Windows dependency family stays pinned; these changes do not relax merge or release approval policy.
-
Repository and contributor maintenance (#630, #633, #678, #680, #685, #693, #722, #735, #767, #771, #773, #774): Correct historical changelog citations, module maps, documentation routes and gate guidance; share the checked-in agent workflow; add a feedback issue form; stop review noise about Markdown punctuation; remove an accidentally tracked endpoint capture. Removing the tracked capture does not rewrite repository history.
-
Windows SDK provenance test (#648): The test asked which spelling of the SDK tool path came back rather than which file was selected, so a second name for one directory (an 8.3 alias, a junction, a differently-cased profile path) failed it on a workstation while the selection was correct on a runner. Both assertions now compare
realpathSync.nativeon each side, and the fixtures reach the resolver through an alias so the condition is exercised rather than assumed. -
DsRegCmd responsiveness test (#669): Earlier assertions ran inside the current-thread runtime and could not observe a synchronous analysis blocking that thread. The runtime now runs on a separate OS thread: the test waits for a held simulated I/O stage, then verifies the runtime can schedule an unrelated task before releasing the stage. Stage-entry, gate, and worker-completion waits are bounded so setup failures fail the test instead of hanging it. The hook remains available in debug builds and test builds, including release-profile tests; shipped release builds ignore the delay environment variable.
-
Headless event-log exporter distribution (#697): CI smoke-tests
event-log-exportwith only theevent-logfeature enabled. The release workflow is configured to attach Windows x64, macOS arm64 and Linux x64 binaries; these separate CLI assets are not signed by the current workflow. The Linux CLI still requires GTK and WebKitGTK runtime libraries despite having no GUI. The README documents usage and source builds. Default full-feature Cargo checks and tests already cover the exporter; the new steps verify the release feature selection and publish the separate CLI asset. -
The CI workflow declares a
merge_grouptrigger (#756): A merge queue tests a temporary merge commit and reports the same required checks that gatemain. Without this trigger a queued pull request waits for checks that never start, so the queue stalls instead of merging - and the failure looks like a hung queue rather than a missing line, which is why a test now asserts the trigger is present. The changed-range whitespace check also selects its base frommerge_group.base_shaand takes the merge-base range there, instead of falling back to the empty tree and re-checking the whole repository. -
Supply chain (RUSTSEC-2026-0285): Raise
rustlsto 0.23.45. The advisory published against 0.23.38 turned thecargo denygate red on every push and pull request, without any code change being responsible. -
Linux Rust CI job:
Check & Test (Rust)failed while linking withldterminated by signal 7 (SIGBUS) in runs 36013586498, 36015082250, attempt 1, and 36013918180, recorded in #676. The incident blocked a required merge gate and prevented the parser-crate and audit steps from running. Disk exhaustion is an unconfirmed hypothesis: the runner disk was not measured at failure time. The job now reclaims unused preinstalled SDKs and toolchains before building and printsdf -h /as a pre-build disk baseline. -
Evidence collector tests now run in CI: The collector's 29 Pester tests now run in the Windows PowerShell 5.1 job. The culture regression test uses a fixed UTC clock and asserts the exact Gregorian timestamp under
fa-IR, preserving the bundle ID shape and nonce checks. Its path setup uses Windows PowerShell 5.1-compatibleJoin-Pathcalls. -
QA tracker citation check (#743): Correct the
LOG-018reference tosrc/stores/ui-store.test.tsand check the tracker's TypeScript source and test paths in CI. The check preserves.tsxextensions and reports references to missing files; it does not claim that the cited tests cover each user story. -
JAMF workspace e2e coverage (#314): Added
e2e/jamf.spec.ts, which switches into the macOS JAMF workspace, loads a log into it, and walks every tab (Overview, Logs, Policies, Profiles, Self Service, JAMF Connect) against fixtures taken from the committed JAMF corpus. The workspace is platform-gated twice, byplatforms: ["macos"]and by themacos-diagbackend feature, so the spec emulates a macOS host for the OS-plugin platform and the build's workspace allowlist, the same way the other specs compensate for not running under Tauri. -
The four downloaded CI tools are verified, and two are pinned: every Action in this repository was SHA-pinned while the executables the pipeline downloads and runs were not, and the Master Packager MSI was installed in the job that holds the update-signing key. Each download now has its SHA-256 recorded and checked before anything is executed,
komacis pinned to a version and the digest that release publishes instead of followingreleases/latest, and the Scoop installer is fetched from a pinned commit rather than a URL that redirects tomaster(#691).
Dependencies
- Runtime frontend (locked versions): React / React DOM 19.2.8 → 19.3.0; Fluent UI charts 9.3.23 → 9.3.27, components 9.74.5 → 9.74.9 and icons 2.0.339 → 2.0.343; TanStack React Virtual 3.14.10 → 3.14.13. Tauri clipboard, dialog, filesystem and updater plugins advance to 2.3.3, 2.7.3, 2.5.2 and 2.12.0 respectively.
- Rust (locked versions): Tauri 2.11.5 → 2.11.6; add single-instance 2.4.5; update log plugin 2.9.0 → 2.9.2 and align clipboard/dialog/filesystem/updater plugins with the frontend. Update
encoding_rs0.8.35 → 0.8.42,evtx0.12.2 → 0.12.3, directquick-xml0.41.0 → 0.42.0,flate21.1.9 → 1.1.10,log0.4.33 → 0.4.34,thiserror2.0.20 → 2.0.21 anduuid1.24.1 → 1.26.1.rustlsmoves 0.23.38 → 0.23.45 andrustls-webpki0.103.13 → 0.103.15. The attemptedwindows-future0.100.0 update was reverted; the final version remains 0.3.2. - Development tooling (locked versions): Playwright 1.62.1 → 1.63.0, Tauri CLI 2.11.4 → 2.11.5, Testing Library React 16.3.2 → 16.3.3, React type packages → 19.3.0, Vite 8.2.2 → 8.3.1, Vite React plugin 6.1.0 → 6.1.1, Vitest and coverage 4.1.11 → 5.0.2, and jsdom 30.0.1 → 30.1.1. Download-metrics Vitest moves 4.1.10 → 4.1.11;
taiki-e/install-actionadvances 2.87.2 → 2.87.20. Release and CI Node setup uses Node 22.
Platform and release notes
- Expected desktop artifacts remain Windows x64 and ARM64 Full/Lite portable EXEs, NSIS installers and MSIs; macOS Apple silicon DMG and app updater archive; and Linux x64 AppImage, DEB and RPM. The exporter adds Windows x64, macOS arm64 and Linux x64 CLI assets; there is no Windows ARM64 exporter asset in the configured matrix.
- Linux desktop packages use an Ubuntu 22.04 build baseline. Static ABI checks alone do not establish runtime compatibility. Release acceptance requires testing the exact signed AppImage on Ubuntu 22.04 and 24.04.
- The signed desktop updater requires all eight target entries in
latest.json. Package-manager catalogs remain on their existing artifacts until verified 1.6.2 hashes are available.