Release history

Changelog

Every release of Verscout, with the features, improvements, and fixes that shipped.

3.0.0.14

2026-09-26

Changes

  • Homebrew checksum mismatches stop the update; rejected downloads are never accepted by rewriting the trusted checksum.
  • App replacements preserve the installed bundle identity and signing team. Publisher changes and unverifiable identity require a manual vendor update.
  • Downloaded app versions are checked before replacement and after installation; stale archives cannot be reported as successful updates.
  • Updates stop safely when an app cannot quit or its destination cannot be restored reliably. Failed replacement retains the prior app and recovery copy.
  • Vendor update handoffs check that the app opened successfully and leave the installed version unchanged until a scan confirms the update.
  • Security previews report unavailable tools and partial results accurately; discovery retries failed catalog requests instead of caching an empty result.
  • Brewfile installations require an active license and explicit confirmation.
  • Labs navigation opens the current preview settings. Mobile download and FAQ controls have larger touch targets.
  • Expected packaged-runtime conditions no longer produce misleading warnings; genuine failures remain visible in the app log and verification checks.

3.0.0.13

2026-09-26

Changes

  • Homebrew cask updates now use the installed cask identity for receipt checks, repair and verification, including apps whose displayed names differ from their tokens.
  • Recovery snapshots handle app bundles containing administrator-owned files and macOS-managed provenance attributes while preserving portable metadata checks.
  • Launching a vendor updater or App Store page is recorded as a manual handoff; installed versions remain unchanged until a scan confirms the update.
  • Original app icons take precedence over package-manager icons throughout the list, details and history, including cards reached by scrolling.
  • Expected missing optional update feeds no longer produce error tracebacks. Network failures and incomplete compatibility checks remain visible.
  • Query-bearing Electron update endpoints can also supply Sparkle XML, including older vendor namespaces, so available DRmare releases are detected correctly.

3.0.0.12

2026-09-26

Changes

  • One annual subscription costs US$6.99 for up to three Macs, with the existing 21-day no-card trial and free scanning after expiry.
  • Active subscribers can preview and opt in to sharing software names and public update-source links to improve the shared catalog. Sharing is off by default; older sharing preferences do not enable this new flow.
  • Contributions exclude installed versions, usage history and local file paths. You can stop sharing and request deletion, including after license expiry. Offline deletion requests remain visible and can be retried.
  • Unverified submissions are isolated from trusted update sources. Subscription, privacy and refund terms now explain the actual behavior and retention periods.

3.0.0.11

2026-09-25

Changes

  • Update counts now match the visible list when updates are suppressed or ignored. Suppressed items remain available in their own category.

3.0.0.10

2026-09-25

Changes

  • Customer licenses are checked against the Verscout product catalog before activation.
  • License validation and deactivation now use the exact activation assigned to this Mac.
  • Repeated activation reuses the existing seat. Interrupted activation and offline deactivation preserve recovery information instead of silently consuming or releasing seats.
  • Release verification now exercises real disposable install, update, uninstall, cancellation, and failure recovery workflows.
  • The license screen now shows working activation controls and clear recovery guidance. Retired account forms and obsolete billing prices have been removed.
  • Clearing update notes and marking apps updated now preserve concurrent scan results.
  • External links open outside the native dashboard, keeping the app available.

3.0.0.9

2026-09-24

Changes

  • Check for Updates now offers a verified download and clear installation steps. Offline checks no longer report that the app is up to date.
  • Update downloads verify the DMG, its contained app, signing identity and exact version before opening. Installation remains an explicit quit, replace and reopen operation that preserves settings.
  • The app carries its own TLS trust roots, so secure update checks work on Macs without Homebrew. Certificate and hostname verification remain required.
  • The DMG includes an Applications shortcut and installation instructions.

3.0.0.7

2026-09-24

Changes

  • The downloadable DMG is now signed before notarization. Both the app and DMG must pass signature, stapling and Gatekeeper checks before release metadata is generated.
  • Release packaging rejects mismatched app versions and missing update-signing keys, and hashes the exact DMG selected for distribution.

3.0.0.6

2026-09-24

Changes

  • Vendor TAR and TGZ updates now extract correctly, including macOS resource forks and framework links. Archives are validated and bounded before extraction.
  • Permission repair stays inside the app bundle and rejects executable paths that escape it. Signed vendor bundles still require strict verification.

3.0.0.5

2026-09-24

Changes

  • Signed apps must pass strict signature verification. A damaged signed app can no longer be accepted as an unsigned app.
  • PKG updates verify the installed bundle, signing identity and actual version before reporting success. Failed verification restores a checked copy of the previous app where safe, preserving recovery files and clear outcomes.
  • ZIP and DMG recovery preserves verified backups and failed bundles. An unsafe restore cannot be reported as successful or lose its only backup during cleanup.
  • Cancellation before installation prevents a queued installer from starting. An uncertain installer timeout retains both its package and recovery files.
  • Recovery lists installer snapshots and provides a Show files action. These snapshots cover the app bundle; package receipts and other installer changes are outside their scope. Recovery data is never purged automatically.

3.0.0.4

2026-09-24

Changes

  • A taller scan panel shows all sources clearly. Browser scans retain accessible extensions when a folder is blocked, with clear access warnings.
  • Scan progress and failed-start recovery are more accurate.

3.0.0.3

2026-09-23

Changes

  • Saved integration switches now reload faithfully, removals persist, and failed saves no longer display success. Opted-in Slack, Discord and custom webhook notifications use real scan/update outcomes with bounded delivery and sanitized activity results. Custom webhooks support signed payloads.
  • Recovery controls open the archive review flow; package rollback sends the required saved version.
  • Package-manager ownership checks respect the scan deadline. When ownership is unavailable, local inventory remains visible and automatic updates stay disabled until a successful scan.
  • Scheduler notifications compare the previous scan counts correctly. Automation setup now explains authentication for every API request.

3.0.0.2

2026-09-23

Reliable scans

  • Optional migration, feed, App Store, vendor, Python, JDK, website and disk-size lookups share bounded work queues and deadlines. A disconnected service cannot make timed-out batches wait for every queued lookup before returning results.
  • Unavailable checks preserve installed inventory and show unverified versions. Cross-manager migration requires verified dependency information; store versions must match the installed bundle identity. Successful later metadata clears only verification warnings and preserves real compatibility restrictions.

New dashboard and management tools

  • A simpler dashboard puts Overview, Updates and Apps first, with advanced tools organized into four collapsible groups. Original process artwork animates during scans, updates and recovery, pauses in the background and respects Reduce Motion.
  • Scans no longer execute discovered app launchers or command wrappers. This fixes unwanted launches of IINA, comparison tools, GitHub Desktop and other GUI apps.
  • Ownership keeps license records, receipts and attachments in an encrypted local vault, with macOS owner authentication, masked keys, local receipt recognition, reviewed CSV imports, spending summaries, renewals and encrypted vault exports.
  • Recovery adds verified app/data archives, snapshots of selected fonts and plugins, exact-version restore, reversible removal and optional archives before updates. Encrypted portable snapshots import into a reviewed catalog before any restore. Explicit disk-space release checks file activity at the kernel boundary and refuses unsupported systems or changed originals.
  • Reviewed vendor-order imports can install selected supported catalog apps without executing links or commands from the imported file. Interrupted jobs remain visible and never restart automatically.
  • Native file dialogs support imports and exports. The local dashboard now requires a private native session, and self-update cache decisions are checked against the running version to prevent stale downgrade offers.
  • App details show known information immediately, retain completed lookups and provide a bounded retry when optional metadata cannot be loaded.
  • Optional update checks have a shared time budget and bounded background work. Failed network or compatibility checks preserve installed apps and show an unavailable state instead of claiming they are current or safe to update.

[2026-08-03]

Fixed

  • A PM run that measured no stages no longer reports grade A. The debt score is always computed and carries weight, so a zero-stage run scored 100 on debt alone; it now reports no grade. A failing stage also caps the grade below A.

Changed

  • During a bulk update the app being updated is now kept in the middle of the window with its progress log visible, and the next app glides up into place when one finishes — no more scrolling down to watch progress. The motion uses an ease-out glide; scrolling by hand stops the auto-follow for the rest of that run, and it respects the system "reduce motion" setting

Fixed

  • An interrupted cask update no longer leaves the app broken. A cask upgrade moves the app out of /Applications before installing the replacement, so a timeout, a Cancel, or a Skip could leave an empty shell behind and the app would simply not open — silently, until you happened to try it. The update now checks for that immediately after the interruption and restores the app from the staging copy, reporting what it did in the update log. If the staged copy is unusable it says a re-download is needed rather than reporting a false success. A partially-populated app is never replaced automatically, since it may be the only copy you have (AP-214)
  • Cask updates whose post-upgrade version check fails (timeout/error) are no longer reported as verified successes — the result now shows "could not verify installed version; re-scan to confirm" (audit SIL-1)
  • Post-install verification timeouts no longer abort an update with a generic "Internal error" — the original result is kept and pip verify degrades to success-but-unverified (audit SIL-2)
  • Failed writes of update history, scan cache, or settings are now surfaced ("history entry could not be saved") instead of silently lost (audit SIL-3); notification dedup failures are now logged (audit SIL-4)

Changed

  • Faster scans: proxy/settings environment computed once per scan instead of per subprocess (18×), per-cask `brew info` lookups replaced by the cached batch data, and app-card rendering no longer quadratic (audit PERF-1/2/3)
  • Removed 700+ lines of dead shadowed update-handler code and the unreachable auto-update-cask branch; behavior unchanged, static analysis now clean (audit COR-1/COR-2)

2.2.15.0

2026-07-03

Changed

  • Desktop UI/data consistency pass: settings merge fix, canonical `update_bucket`/`note_kind`, pins UI, view-mode persistence, dead filter/sort cleanup, action-button alignment, cask display names, bundle_id suppression keys, and frontend/backend dead-code cleanup (18-task audit remediation).

Fixed

  • Test: 4 live-browser xfail decorators now carry `# owner=eiman until=2026-09-01` comment for QuarantineWatch QW-001 compliance (metadata was previously invalid kwargs that broke pyright)
  • Test: admin impersonation E2E test re-enabled — root cause was missing `setupSession(AUTH_STATES.SUPER_ADMIN)` in the Impersonation describe block; all selectors were correct

2.2.13.0

2026-06-06

Changed

  • (auto-generated from commits; edit for release notes before shipping)
  • pm: auto-fix Verscout Desktop (grade A, score 98)
  • docs(verscout): add first two ADRs — Keychain ACL and WKWebView state
  • pm: auto-fix Verscout Desktop (grade A, score 98)
  • fix(test): make resolved-app-path launch test environment-independent
  • chore(verscout): close stale P1 git-hygiene TODO, log session end
  • pm: auto-fix Verscout Desktop (grade A, score 100)
  • pm: auto-fix Verscout Desktop (grade A, score 100)
  • pm: auto-fix Verscout Desktop (grade A, score 100)
  • pm: auto-fix Verscout Desktop (grade B, score 81)
  • pm: auto-fix Verscout Desktop (grade A, score 100)

2.2.12.0

2026-06-05

Changed

  • (auto-generated from commits; edit for release notes before shipping)
  • pm: auto-fix Verscout Desktop (grade A, score 96)
  • fix: write visual screenshot to baseline_dir to avoid temp-dir race
  • pm: auto-fix Verscout Desktop (grade B, score 85)
  • pm: auto-fix Verscout Desktop (grade B, score 81)
  • chore: gitignore .build-fingerprint to stop git_hygiene failures
  • chore: update build fingerprint after PM auto-fix runs
  • fix: write visual diff current screenshot to temp dir, not visual_baselines/
  • pm: auto-fix Verscout Desktop (grade B, score 81)
  • pm: auto-fix Verscout Desktop (grade B, score 81)
  • pm: auto-fix Verscout Desktop (grade A, score 100)

2.2.11.0

2026-06-03

Changed

  • (auto-generated from commits; edit for release notes before shipping)
  • pm: auto-fix Verscout Desktop (grade A, score 98)
  • pm: auto-fix Verscout Desktop (grade A, score 98)
  • pm: auto-fix Verscout Desktop (grade A, score 98)
  • pm: auto-fix Verscout Desktop (grade A, score 98)
  • pm: auto-fix Verscout Desktop (grade A, score 98)
  • fix(pm): add lint/codewatch to --quick pipeline (UNIVERSAL_PATTERNS compliance)
  • pm: auto-fix Verscout Desktop (grade A, score 99)
  • pm: auto-fix Verscout Desktop (grade A, score 99)
  • fix(ci): fix isort import order in capabilities_resolve.py
  • pm: auto-fix Verscout Desktop (grade A, score 99)

2.2.10.0

2026-06-02

Changed

  • (auto-generated from commits; edit for release notes before shipping)
  • test: add TestWatch gap tests for ChangelogEntry, ChangelogSection, stage_capabilitywatch, stage_issuewatch
  • fix: detect iOS apps with incompatible version schemes as outdated
  • fix: Open App Store button now works — WKWebView swallows macappstore:// URLs
  • fix: cold-read audit — 2 bugs + 2 stale tests + 2 PM invariants
  • docs: mark update-system-overhaul spec as Shipped
  • refactor: Phase 6 — deduplicate shared constants into server_update_constants.py
  • refactor: Phase 5 — collapse exec() shard architecture in update worker
  • fix: Phase 4 — Sparkle apps without a download URL no longer show as auto-updatable
  • fix: Phase 3 — version-db/scraped strategy routes to Visit Website not Search Online
  • fix: Phase 2 — remove source guard from OPEN_APP_ONLY_APPS

2.2.9.0

2026-06-01

Changed

  • (auto-generated from commits; edit for release notes before shipping)
  • pm: auto-fix Verscout Desktop (grade A, score 100)
  • audit(9-dim): cold-read fixes — DMG recursive search, path sanitizer, coverage gaps
  • chore(todo): close Codex-injected CEO-AUDIT items from stale May-5 audit
  • fix: Open App Store / Open App buttons for manual section + post-install rollback
  • pm: auto-fix Verscout Desktop (grade A, score 92)
  • fix(ui): block scan result refresh from resetting dashboard during active update
  • fix(electron): exclude componments/components URLs from app download selection
  • fix: Warp stable_ version mismatch + Sidify nested .app discovery
  • fix(pm): raise CPU threshold to 150% for Verscout runtime monitor
  • docs: add missing changelog entries 2.2.2-2.2.5 + auto-generate CHANGELOG in release pipeline

2.2.8.0

2026-05-31

Changed

  • (auto-generated from commits; edit for release notes before shipping)
  • pm: auto-fix Verscout Desktop (grade A, score 100)
  • audit(9-dim): cold-read fixes — DMG recursive search, path sanitizer, coverage gaps
  • chore(todo): close Codex-injected CEO-AUDIT items from stale May-5 audit
  • fix: Open App Store / Open App buttons for manual section + post-install rollback
  • pm: auto-fix Verscout Desktop (grade A, score 92)
  • fix(ui): block scan result refresh from resetting dashboard during active update
  • fix(electron): exclude componments/components URLs from app download selection
  • fix: Warp stable_ version mismatch + Sidify nested .app discovery
  • fix(pm): raise CPU threshold to 150% for Verscout runtime monitor
  • docs: add missing changelog entries 2.2.2-2.2.5 + auto-generate CHANGELOG in release pipeline

2.2.7.0

2026-05-31

Changed

  • (auto-generated from commits; edit for release notes before shipping)
  • chore(todo): close Codex-injected CEO-AUDIT items from stale May-5 audit
  • fix: Open App Store / Open App buttons for manual section + post-install rollback
  • pm: auto-fix Verscout Desktop (grade A, score 92)
  • fix(ui): block scan result refresh from resetting dashboard during active update
  • fix(electron): exclude componments/components URLs from app download selection
  • fix: Warp stable_ version mismatch + Sidify nested .app discovery
  • fix(pm): raise CPU threshold to 150% for Verscout runtime monitor
  • docs: add missing changelog entries 2.2.2-2.2.5 + auto-generate CHANGELOG in release pipeline
  • pm: auto-fix Verscout Desktop (grade A, score 100)
  • fleet-audit 2026-05-30: fix verscout PM risk telemetry and theme persistence

2.2.6.0

2026-05-31

Changed

  • (auto-generated from commits; edit for release notes before shipping)
  • fix(ui): block scan result refresh from resetting dashboard during active update
  • fix(electron): exclude componments/components URLs from app download selection
  • fix: Warp stable_ version mismatch + Sidify nested .app discovery
  • fix(pm): raise CPU threshold to 150% for Verscout runtime monitor
  • docs: add missing changelog entries 2.2.2-2.2.5 + auto-generate CHANGELOG in release pipeline
  • pm: auto-fix Verscout Desktop (grade A, score 100)
  • fleet-audit 2026-05-30: fix verscout PM risk telemetry and theme persistence
  • pm: auto-fix Verscout Desktop (grade A, score 100)
  • pm: auto-fix Verscout Desktop (grade A, score 100)
  • pm: auto-fix Verscout Desktop (grade A, score 100)

2.2.5.0

2026-05-30

2.2.4.0

2026-05-30

Fixed

  • Release pipeline: published DMG files now correctly upload to remote CDN (previously uploaded to local development R2 bucket — some "released" versions may not have been reachable)
  • Keychain ACL checks scoped to Verscout-owned entries only

2.2.3.0

2026-05-26

2.2.2.0

2026-05-25

Fixed

  • Electron app updates: ZIP extraction now preserves symlinks (fixes apps that failed to launch after update)
  • Homebrew Cask recovery: handles stale caskroom directories gracefully (prevents "App source not found" errors)
  • Security: updated qs to ≥6.15.2 (GHSA-q8mj-m7cp-5q26)

2.2.0

2026-04-23

New

  • **Onboarding Wizard** — 4-step first-run experience: welcome, source selection, permissions/scheduling, and "Start Scanning" completion
  • **Multi-Select & Bulk Actions** — checkbox selection on individual packages, Select All toggle, floating action bar with "Update Selected" and clear
  • **Open at Login** — LaunchAgent-based toggle in Settings to start Verscout automatically on macOS login
  • **Custom App Discovery Locations** — add folders beyond /Applications for scanning (Settings > Locations)
  • **Beta/Pre-release Toggle** — opt in to beta versions from GitHub releases and Sparkle appcast beta channels (Settings > Updates)
  • **Proxy Support** — system, manual (HTTP/HTTPS/SOCKS5), or no-proxy modes with per-field configuration (Settings > Proxy)
  • **Bundle ID Collision Registry** — detects apps sharing bundle IDs (e.g., Electron forks) and resolves aliases for apps that change identifiers across versions
  • **Team ID Verification on Downloads** — extracts and compares Apple Team IDs between installed and downloaded app versions; warns on mismatch (possible supply-chain attack)
  • **Malware/Adware Blocklist** — integrates Apple XProtect definitions and a cloud-synced blocklist; blocked apps flagged with red badges and excluded from Update All
  • **Acknowledgements Page** — credits Homebrew, Sparkle, MAS CLI, and other open-source dependencies

Improved

  • macOS compatibility filtering now walks Sparkle feeds and Cask `depends_on.macos` to find the newest version that runs on your macOS — incompatible updates shown with amber badges instead of offered for install
  • Sparkle pre-release items (beta channels and version-string patterns) are now filtered unless the pre-release toggle is on
  • Network pre-flight check uses 3 DNS hosts instead of 1 — transient DNS failure no longer blocks all updates
  • Menu bar "Scan Now" uses `evaluateJavaScript` instead of reloading WKWebView, preserving dashboard state
  • Update All timeout scales by package count (10–90 min) instead of fixed 5 minutes
  • Dashboard asset cache-busting uses startup timestamp — no more stale WKWebView JS after source edits
  • Gzip response middleware reads the body once instead of three times, halving memory allocation for large scan results
  • Process info endpoint caches `ps aux` output for 2 seconds, eliminating redundant syscalls when viewing multiple package details
  • Activity log endpoint now holds the shared file lock, preventing TOCTOU with concurrent log writes
  • Scan cache write/load errors now log at WARNING for disk-full or permission failures instead of silent DEBUG
  • CLI casks (e.g., claude-code) no longer falsely flagged as orphaned — caskroom directory check added
  • Badge and skip-button overlap resolved — switched from absolute to inline flex layout
  • Suppress/ignore/skip actions use CSRF-aware `postAction()` instead of raw fetch
  • Source validation hardened with `_SAFE_SOURCE_RE` regex whitelist
  • Command whitelist in update worker prevents cache-poisoning vector
  • AppleScript path sanitization guard now runs before escaping and blocks backtick characters
  • Rate limiting enforced on `/api/launch-app` and `/api/open-folder` endpoints
  • Duplicate `json` import removed from export route handler
  • 14 `console.debug` statements removed from production JS
  • Stale `.pyc` files for deleted modules cleaned up
  • 120+ additional code quality fixes: null guards, empty-catch handlers, f-string logger arguments, plistlib performance, request.json standardization, CSS variable usage, and WCAG labels

Fixed

  • "Update All" button showed stale count — fingerprint-based polling now detects enrichment completion
  • Sidify download URL double-encoding — absolute URLs in Electron feeds no longer re-encoded
  • Multi-source download fallback — all sources (Sparkle, Electron, GitHub) tried in sequence instead of stopping at first failure
  • Lasso false positive — Repology blocklist check added to web scraping path
  • Onboarding "Scan Now" called a non-existent `runScan()` — fixed to `startScan()`
  • Double window open on activation — debounce added to AppKit observer
  • Stats disk usage empty — `compute_disk_usage()` now includes pre-enriched `size_bytes`
  • Constrained text overflow — name column truncates with ellipsis
  • Marketing download button empty href — `release-content.ts` fallback added
  • Web SaaS webhook_events missing GRANT — dedup was broken

2.1.0

2026-04-01

New

  • **macOS Notifications** — scan completion, security alerts, and auto-update results now post native notifications
  • **Security Vulnerability Alerts** — immediate notification when packages have known CVEs
  • **Auto-Update Notifications** — confirmation when packages are updated automatically

Improved

  • Scheduler passes settings context to auto-update flow for notification preferences
  • Notification text includes correct singular/plural grammar

2.0.0

2026-03-31

New

  • **Trust & Safety Checks** — code signing verification, revoked certificate detection, XProtect blocklist matching
  • **Compatibility Warnings** — flags updates that drop Intel support or require newer macOS
  • **Duplicate Resolution** — finds apps installed via multiple sources and recommends which to keep
  • **Deep Find Scanner** — discovers JDKs, CLI tools, pref panes, frameworks, drivers, launch items, kernel/system extensions, and browser add-ons
  • **Tool Registry** — browse and search the full Homebrew Cask + Formulae catalog from within the app
  • **App Catalog** — discover new apps with curated categories and one-click install
  • **Version Database** — cloud-backed version intelligence for 5,500+ apps
  • **Analytics Dashboard** — update trends, staleness metrics, and disk usage analysis
  • **iCloud Sync** — sync settings, pins, and schedules across Macs
  • **Menu Bar Packaging** — new sidebar for cleaner navigation and more screen real estate

Improved

  • Scan engine rewritten: 12 sources (Brew, Cask, pip, npm, App Store, Setapp, Adobe, Microsoft, JetBrains, iOS App, System, Standalone)
  • Conflict resolution for packages available from multiple managers
  • Brew-to-pip and pip-to-brew migration suggestions
  • Enhanced error messages with actionable troubleshooting steps
  • CSRF protection on all mutation endpoints
  • CSP, X-Frame-Options, and other security headers on responses

1.5.0

2026-02-15

New

  • **Standalone Update Engine** — direct downloads for apps not managed by any package manager
  • **Sparkle Feed Support** — read update info from in-app Sparkle/Squirrel feeds
  • **GitHub Release Tracking** — version checks against GitHub releases for open-source apps
  • **Web Scraping Fallback** — homepage and changelog page scraping for version detection

Improved

  • Scan speed improved 3x with parallel source checks
  • Better handling of apps with non-standard bundle IDs
  • Reduced false positives for App Store apps with pending updates

1.0.0

2026-01-10

New

  • Initial release
  • Homebrew Brew + Cask scanning
  • pip and npm package scanning
  • App Store update detection
  • One-click update for Brew/Cask/pip/npm packages
  • Batch update with progress tracking
  • Pin versions to skip specific updates
  • Schedule automatic scans (hourly, daily, weekly)
  • Light and dark theme support
  • Local-first architecture — no data collection, no accounts required