Highlights: Reliable Chrome recovery and cleanup, faster file bundles, and the source-map-js security fix (CVE-2026-93749).
- Browser: release Chrome launched by session recovery according to
keepBrowser, preserve borrowed browsers and concurrent leases, and show manual-login guidance with hidden-window recovery; fixes #548 and #547, thanks @HidakaKoyo. - Browser: use fresh cold-launch ports and live attach endpoints, wait for HTTP 404 approval responses, exclude volatile copied-profile session state while preserving auth storage, and report partial cookie transfers safely; fixes #535, #537, #538, and #540, improves #541; thanks @webkitvn and @Sogl.
- Browser: capture generated images from current-prompt ChatGPT blob galleries and download their bytes inside the page, preventing image-generation timeouts on the new layout; fixes #549, thanks @HidakaKoyo.
- Files: look for
.gitignorefiles only in the directories and glob bases passed to--fileand their parents under the working directory, instead of walking the whole working directory, so a small bundle no longer takes seconds to minutes when oracle runs from a home directory, and stop a.gitignoreinfoo/from applying to files in a siblingfoobar/; fixes #532, thanks @postoso. - Files: apply default-ignored directory names only below the directory or glob base passed to
--file, so a bundle under/tmpor abuild/folder is no longer dropped when oracle runs from elsewhere; fixes #531, thanks @postoso. - Browser: dismiss blocking UI only inside visible dialogs, so a sidebar conversation whose title contains a word like "close" is no longer clicked after opening a ChatGPT project URL; fixes #534, thanks @tlq5l and @webkitvn.
- Browser: recognize GPT-6 picker labels, preserve the latest CLI alias and legacy localized radios, and verify model and Pro effort separately; fixes #553, thanks @felipekrgb.
- Browser: recognize Japanese Chat/Work effort controls and assistant completion/copy signals while preserving current-turn verification; thanks @kiyo-e.
- Browser: tolerate macOS openrsync vanished-file transfers when copying live Chrome profiles, while rejecting real read errors and missing authentication storage; fixes #550, thanks @Sogl.
- Dependencies: refresh provider and MCP SDKs, Chrome tooling, terminal dependencies, Vitest/coverage, Hono, Vite, and the source-map-js security fix (CVE-2026-93749) within the two-day cooldown; retain Node >=24 and Undici 7 compatibility; thanks @dependabot.
- Dependencies: refresh OpenAI and Gemini SDKs, Puppeteer, and the pinned Chrome DevTools protocol within the two-day cooldown, retaining Node >=24 and Undici 7.