{
  "entries": [
    {
      "version": "1.5.57",
      "date": "2026-10-03",
      "severity": "normal",
      "body": "### PAVONA 1.5.57: upgrade from 1.5.56 with Setup; skip in-app Apply\n## Clear names and work you can follow\n\n**Names on the screen.** The main app and chat are PAVONA. The coding workspace is CUADA, notes are TABLETS, the personal agent area is LOCKER, and the security console is VERIDITAS. Each ongoing responsibility in LOCKER is a Mark; DevAd keeps its name. The `/scribe` and `/veridian` routes retain their names. The Windows installer remains `PriestAI Setup.exe`, update packages keep `PriestAI` filenames, and the site address remains priest.locker. Desktop and Start menu shortcuts keep the name Priest AI.\n\n**Marks and BEASTS in LOCKER.** Give a Mark a responsibility and memory notes, set optional read-only checks, review its activity, talk in its chat, or pause, resume and finish it. Marks belong to the signed-in account. Choose from ten built-in BEASTS whose pixel art is labelled as candidate art, or create a named Beast with a plain badge. A Beast shows status from agent and task activity. From it you can start a new chat that carries its name, open your agent runs and the CUADA console, and send it a task through CUADA's existing permission gate; in a permission mode that asks before running an agent, start that task from chat.\n\n**TABLETS history.** Pages remain Markdown with links, comments and a graph. TABLETS keeps up to 60 prior versions of each page; saves in the same clock tick no longer overwrite one another.\n\n**Schedules.** The Schedules panel creates and manages recurring Windows tasks. Plan mode is read only by default; allowing file edits is a separate choice. Windows tasks proposed by the assistant wait for your approval before they are created. `/loop` and `/remind` work through an open conversation.\n\n**Controls and evidence.** Choose moving glass, still glass or a plain background in Settings; the choice is saved for your account. A computer set to reduce motion shows the moving choice as still glass. Failed reads in the Models, Runs and Your other computers panels give a plain explanation and a next action. The comparison view still names each metric and competitor, shows ties and missing measurements, and names a leader only when the results can be compared.\n\n**Updating from 1.5.56.** Close PAVONA and use the 1.5.57 `PriestAI Setup.exe` from the releases page for the same installation folder. Compare its SHA-256 with the release page first. Do not use **Apply** in the 1.5.56 app for this upgrade: its older updater can time out during the test run. Setup keeps conversations, settings and models when it can verify the earlier program files. If it cannot, Setup leaves the installation unchanged and names up to five files it could not verify; keep the old folder and its data, and restore the earlier program files and their installed manifest from a trusted backup before running Setup again."
    },
    {
      "version": "1.5.56",
      "date": "2026-09-23",
      "severity": "normal",
      "body": "### PriestAI 1.5.56\n## A calmer app, a Work pane, and every change yours to keep or put back\n\n**A calmer window.** The row of panel buttons down the side is out of view, and every panel is still one search away in the sidebar's Everything list and the command palette. The permission mode sits right under the message box, the typing hint is the box's placeholder, and the microphone, skill and tool notices share one line. Escape stops a running reply when nothing else is open, and Alt+N starts a new conversation. If you prefer the earlier arrangement, Settings > This build has a Previous layout switch that brings it back after a reload.\n\n**One run pill and the Work pane.** A pill in the top bar says whether anything is thinking, running, waiting on you, stopped or failed. It opens the Work pane beside the conversation (a sheet on a narrow screen) with Plan, Files, Runs, Permissions and Records tabs. Alt+W opens and closes it.\n\n**See each change, then Keep or Put back.** When the assistant edits or writes a file, its card shows the file, the lines added and removed, and the diff folded underneath. Keep marks the change as decided. Put back first lists the files that checkpoint would restore and asks you to confirm, then restores them with the same undo the command line uses. It only ever puts back a checkpoint this conversation made.\n\n**Plans and files at a glance.** A task's plan is a card with a tick, a running dot or an open circle for each step; it stays with the reply and is pinned in Work > Plan. Work > Files lets you browse the folder the conversation works in, without ever showing sign-in or key files.\n\n**Agents you can shape and talk to.** Settings > Agents sets how many levels of agents may start one another and how many run at once, shows where your own agents live, lets you trust a folder's agent as written, and lists recent runs and which of them can be continued. Agents are read from your own agents folder and from a project's .priestai\\agents folder; a project's agents are third-party until you trust them, and none can replace a built-in agent of the same name. You can send a message to a running agent, continue a finished one, and ask to be told when a task stops.\n\n**Install and launch.** A Setup that was stopped part-way picks up where it left off and says so. Setup checks the engine installer it downloads before running it (a pinned digest, or else a valid Windows signature from the engine's publisher) and deletes a file that fails. Uninstall lists what it keeps, and a later install says what it found from before. Closing the window while tasks are running tells you they keep going and where to stop them. Typing priestai in a terminal gives you the prompt back at once, and the heavier panels load after the first paint.\n\n**One taskbar button with the PriestAI mark.** The app window and its Desktop and Start menu shortcuts share one taskbar identity and the sharp PriestAI icon, so a pinned shortcut and the open window are one button. Minimising the window no longer loses the icon.\n\n**Safer by default.** A web fetch or web search now asks before it sends, because the address or the query leaves your computer; plan mode refuses it and says why. A tool server at a plain http address off this computer needs your explicit yes and is marked insecure; a model engine reached that way is flagged, and a public one is refused. A background command has a real deadline, an output limit and a Stop. Files named like keys are not readable by the assistant wherever they sit, search results pass the same guard as reading, a repository's own skills are third-party until you trust them, and what a tool brings back is labelled as data.\n\n**Honest status.** A status check that never answered is shown as not measured, instead of being drawn as a fact.\n\n**The site.** A new tour at /tour/ walks through the whole platform, quoting the controls the app ships. The install guide shows the \"More info, Run anyway\" steps and asks you to compare the file's SHA-256 with the release page. Screenshots name the build they were taken from, the PriestAI mark is redrawn as leaded glass, and every page reads at phone widths in every theme.\n\n**Command line.** priest decide asks a local model for a probability for each choice. priest task run --agent-json runs a one-off agent described on the command line, without writing a file. priest eval list-external lists external benchmarks, priest eval record-licence switches one on once you record its data licence, and priest eval run --benchmark runs it. Each stays off until its licence is recorded, and one whose toolchain is missing is reported as not run, never as a score of zero.\n\n**Fairer comparisons.** PriestAI is always measured on one declared model, each task set gets its own comparison page, a tool that could not run is recorded as not run rather than estimated, PriestAI's own errors are read by the same rules as every other tool's, and malformed and failed tool calls are counted on their own.\n"
    },
    {
      "version": "1.5.55",
      "date": "2026-09-22",
      "severity": "normal",
      "body": "### PriestAI 1.5.55\n## The app opens its own panel, and two doors close to the assistant\n\n**The app opens its own panel, never another copy's.** A copy installed on a computer that already ran a different PriestAI panel used to open that one, with someone else's sign-in and accounts. The app now checks the panel is its own install before opening the window, and starts its own on a free port if not.\n\n**Two doors closed to the assistant.** It can no longer change your permission mode, approve its own permission requests, trust third-party skills or agents, or add tool servers through its own API tool - you still can, in the app. Its command tool now refuses the account, sign-in and key files its file reader already refused.\n"
    },
    {
      "version": "1.5.54",
      "date": "2026-09-22",
      "severity": "normal",
      "body": "### PriestAI 1.5.54\n## Safer Scribe edits and cleaner releases\n\n**Your latest note stays with you.** Scribe waits for pending text to save before changing spaces, closing a note, renaming, moving, deleting or restoring it. Failed saves keep the draft visible. Late replies cannot replace a different note, and a stale save cannot silently recreate a note that was moved or deleted. If another editor changes a note, Scribe offers recovery without discarding your pending text.\n\n**Bulk changes report what happened.** Replace previews are tied to the reviewed text and page versions. A stale preview changes nothing. If a concurrent edit interrupts an operation already in progress, Scribe reports confirmed changes and points you to page history. Import failures, timeouts and incomplete move recovery are reported without claiming success.\n\n**Return to an exact note.** The conversation workspace links to Scribe notes, and `priest notes open --space team --page \"Guides/Setup\" --json` prepares an application link. Open it in your signed-in application; the command does not create a second note store or bypass access checks. Website help describes the same behavior.\n\n**Cleaner packages and test cleanup.** Release packages exclude local recovery records and operator-specific comparison commands. Comparison tools remain available with portable examples and require explicit configuration. The test runner closes its owned browser and helper processes after completion or timeout. Existing Scribe spaces, links, graph, comments, history, imports, exports and theme choices remain available.\n\n**Installing this release.** Use the 1.5.54 installer for a complete Windows upgrade from 1.5.53 or earlier. Older in-app updaters do not deliver every new command-line component. This release fixes that list for future updates and keeps your saved comparison settings.\n\n**Your notes stay when removing the program.** Program removal also leaves Scribe notes, attachments, history and core records in place on older installations without a file manifest.\n\n\nUpdate recovery now includes the CLI and newly added code in previews and rollback. Interrupted copies keep the installed file intact; code edited after an update is preserved and reported for review."
    },
    {
      "version": "1.5.53",
      "date": "2026-09-19",
      "severity": "normal",
      "body": "### PriestAI 1.5.53\n## Scribe, seven themes in living glass, a \"/\" menu, and an app that says only what it measured\n\n**Scribe - your notes, in the app.** A vault of pages in spaces, written in Markdown with `[[links]]`, backlinks, an outline, labels, stars, daily pages, templates, attachments, comments, page history with restore, a trash, import and export, search with saved searches, and a graph of how pages connect. `[[wiki:Page]]` cites the product handbook, which now travels with the install. The agent can search, read and add to your notes through three tools; it never overwrites a page silently, and a page you restrict to the owner account is restricted for the agent too.\n\n**Seven themes, and the glass is alive.** The app now carries all seven of the site's themes: Night, Ember, Moss, Paper, Vigil, Reliquary and Sunward. Reliquary is the light theme a new copy starts in; Paper stays one click away. Top bars, page heads, cards, panels, drawers and menus are drawn in the theme's own moving glass at their borders only, so the text inside keeps the ground it always had. Scribe's toolbar is glass across the whole bar, and the page title and the save status sit on a plate of the theme's own ground so they stay readable. Settings has one \"Moving glass\" switch (on the site, the same choice is \"Moving fractals in the glass\" in the music dock): off freezes the pattern exactly where it is, and it stays frozen after a reload. Reduced-motion shows one still frame; forced colours shows no glass at all.\n\n**A \"/\" menu, and more ways to steer a turn.** Type \"/\" in the composer for commands and your skills, including /memory, /compact and /effort. /effort sets how hard the model thinks, for every conversation; the word \"ultrathink\" in a message asks for extended thinking for that one turn and changes nothing afterwards; a thinking switch is set per conversation and resets when the app restarts. Ask for a model by the words best, fast or default, or by \"hybrid\" - the strong model while you are in plan mode, the quick one otherwise, read fresh at the top of every turn. The engine every face shares understands those words, so the command line and a request sent straight to the panel both take them; the model picker in the app still lists only the models you actually have. Project instructions and memory now reach the live turn, and automatic memory is on by default. When folding an old conversation is not enough, it is summarised instead of cut. The model words, hybrid, \"ultrathink\", project instructions, memory and summarising live in the one engine behind the app, the browser and the terminal console; the \"/\" menu and the thinking switch are in the app and the browser.\n\n**998 skills, and a new catalogue.** Skill bundles go from 573 to 998, each under its own licence with credit. A new catalogue lists 71 MCP servers and 404 developer tools. An MCP server in it can be switched on only once its licence and pinned launch command have been confirmed, and none has been yet; a developer tool is used only if you already installed it yourself. For a skill somebody else wrote - including the ones that ship with PriestAI - what is held back is your decision: Settings > Skills has a \"Third-party skills\" section with \"See the held-back text\" and \"Trust this skill as written\", and a turn that used a skill with lines held back shows a card saying so. A skill you wrote yourself is always used exactly as written.\n\n**The app says only what it measured.** If LM Studio, llama-server, vLLM or SGLang is the engine answering on your computer, the Models screen names it and lists its models, and the status strip no longer says that no engine is running. A model size nobody reported is a dash, not \"0.0\"; a size worked out from the model's name is marked \"about\", so a guess never reads as a measurement. When a model service refuses a request, the message names the status it answered instead of an exception's name like \"HTTPError 500\". When part of a screen stops working, the app says so in a sentence and gives you a \"Reload the page\" button. The Models screen paints at once instead of waiting on every machine it knows. In a panel, Escape closes the innermost thing first, such as the record you are reading, before it closes the panel, and a permission countdown follows the server's clock. A file the document reader cannot open is refused with the full list of types it can.\n\n**Setup and the command line.** The setup wizard offers a known first model from the shipped list, and says plainly when a download size is a guess. `priestai --help` is written in sentences, names its exit codes and suggests what you probably meant when it does not understand you; `priestai --console --help` says what the console is and how to leave it. The update rail no longer calls a refusal an update, and uninstall names what it leaves behind.\n\n**The site reads properly on a phone.** The stained-glass window stands behind every page, but only the home page's sections had a surface of their own: the docs, the Measured page and the terms put body text straight onto moving glass. Every page other than the home page now reads from one leaded panel with the window framing it, and the home page's two bare sections get the same panel, in all seven themes. Glass buttons carry their labels on a plate of the theme's own ground. Docs tables are lists on a phone instead of a word to a line; inner folds have padding; wide tables scroll inside their box; tapping a field no longer zooms the page; opening support no longer raises the keyboard over the greeting; the resting music dock is one small round button and loads the player only when you press it; the \"press T\" hint is shown only where there is a keyboard; the docs preview renders an article's headings and stops repeating itself.\n\n**Two phone-only faults, fixed at the cause.** On a slow load the glass script ran before the stylesheets had arrived. It read the support button as unpositioned and pinned it in the page's flow, so the button fell to the foot of the page; and it built the window from fallback colours, so a pale theme got a dark window. The script no longer pins a host before the stylesheets have arrived, and it rebuilds the glass when the page's colours arrive late or a page returns from the back/forward cache.\n\n**New pages, and a site that finds its way.** A privacy page that says what the code does, an accessibility page, a page for the collection box - PriestAI is free, with a collection box - and a 404 page in the site's own dress; the status page now takes its release and date from the release list. Every page of the site names its publisher and a contact address in its footer; the ad and social stills carry the site's address alone. Search engines get a sitemap, a robots file and one address per page; files are cached for as long as they are good for. The wording across the site was rewritten to be plain and direct.\n\n**Every page has its own link preview.** The picture a shared link unfurls into is drawn for each page from that page's own title and description, and its address carries the picture's hash so messengers fetch the new one. The ad pages name the release the manifest names instead of a version typed by hand.\n\n**The handbook matches the code.** The install page now says what uninstall really does - it removes the shortcuts, the `priestai` command and its PATH entry, and leaves the program folder and your conversations where they are unless you tick the boxes that move them aside - and lists the Start menu entry the installer makes. The permissions page no longer contradicts itself about manual mode, where every action asks first.\n\n**Corrected at the moment it errs.** When you ask for a rename by name and an edit changes more than the name, or leaves a function whose whole body is a call to itself, the edit's own result now says so - and, when the edit is short, with the exact text the rename should have produced - so the next step is the repair. The end-of-turn check is unchanged and keeps the last word. Its two re-asks now start again when the problems found are different ones, never past four in a turn; a turn that still fails is marked unverified with the real count. A failing test stays a finding until the folder changes - and a turn has two minutes of test running in all, so once those are spent the finding stands as it is. A test run that never started still counts. A test the agent has just repaired is run fresh, never from an old compiled copy of itself, so a correct fix is no longer reported as still failing.\n\n**Steadier under the hood.** A pinned model that has failed three times now hands the turn to its runner-up instead of stopping with an error. Both stream clocks leave room for a tool call the engine writes in silence, sized by the turn's own measured speed; the newest tool result is folded last, and only when the request would not fit otherwise. A rescue turn no longer spends the model's one step on a window the caller already named.\n\n**Integrations, with credit.** One licence policy decides what may ship: permissive licences ship with their authors' licence text beside each skill; anything else is driven as a separate program or learned from, never copied in. `priestai --cli toolchain list` and `priestai --cli toolchain doctor` say which developer tools are on this computer. A second, larger evaluation corpus (25 tasks) joins the first.\n\n**Background tasks.** A release's card now reads as a release - \"Release\" and its step count, with no agents or tokens line."
    },
    {
      "version": "1.5.52",
      "date": "2026-09-18",
      "severity": "normal",
      "body": "### PriestAI 1.5.52\n## An agent that checks its own work, and a loop that does not wait\n\n**The agent is checked before it says done - by the folder, not by its word.** When you ask for a rename by name, the edit must change the name and nothing else: if it changed more, the agent is told exactly what, told to keep the new name, and given the exact text the edit should have produced. A function whose whole body is a call to itself is flagged as one that can never return. A test file the turn created that `python -m unittest discover` would never find (its name does not start with `test`) is said, with a name every runner finds. When you ask for tests to pass, or the turn touched a test file, the project's tests are run once before the turn is accepted. Each finding is a fact about the files with a file and line; the agent is asked again at most twice, and a turn that still fails is marked unverified, never passed off as finished.\n\n**It acts instead of announcing.** A reply that says \"I'll use read_file\" and makes no tool call is asked once to make the call. Tool calls a small model writes as JSON in its prose are taken up as calls when they fit exactly one tool. Several calls in one step are accepted, and consecutive read-only calls run together.\n\n**Edits that land.** edit_file now finds its text when only line endings, trailing spaces or indentation differ - each looser rung is accepted only for a unique match, and the reply says which rung matched. A missed edit shows the two nearest lines with their numbers. The file's own line endings and byte-order mark are kept, and the write is atomic with the original restored on any failure.\n\n**A loop that does not wait in silence.** The local loop streams: words arrive as the model writes them, Stop closes the socket mid-answer, and a stalled model is said after 180 seconds with no first token or 60 seconds of silence instead of a quiet wait of up to fifteen minutes. A model runner that dies mid-step is asked once more. A stopped engine is said in about a second again. Long tool results keep their end as well as their start, with a marker saying how much was cut. The conversation folds in one batch down to a low-water mark, keeping the first turn and the latest turns whole.\n\n**The window fits the graphics card.** After a model loads, the app checks that it is fully on the GPU; if it spilled, the window steps down one size, once, says so in the transcript, and remembers it for that model.\n\n**Cloud seats fail over honestly.** A pinned cloud model that fails with a retryable error gets one attempt on its declared runner-up, announced, never silently; rate limits and server errors honour the provider's Retry-After up to thirty seconds.\n\n**Forethought.** `priest forethought triage` reads a refused release's own log and lays out the work: one reader per failing test, one fixer per cause in its own worktree, the neighbouring tests, a review, and the relaunch - sized to a budget that is known before it starts, with a stop line, a handoff it writes itself, and a one-time wake-up to resume. It never edits a gate, an assertion or the baseline to pass.\n\n**Background tasks show everything that is running.** A workflow, and now a release, appears as a card with its steps: a box per stage with done out of total, a row per step with its time, and the release's own sentence when a gate says no. A release has no stop button. The docked Task panel adds a place for plugins; the music player is the first. `priest usage --by-key` prints what Settings says about each API key.\n\n**Every moving part is the same glass.** The band, the buttons, the dock and the window are drawn one way now: jewel panes with the set as light, in each theme's own colours. A visit keeps one view and breathes slowly instead of touring the whole set, and the crackle is calmer.\n\n**Housekeeping that matters.** Forty-three bundled skills from three authors shipped without their licence text; each now carries its author's own MIT licence. A pattern that detects vision models held a stray control character since early September and could never match a model named \"-vl\"; it does now. The status mirror is republished after every release. The measured comparison on the site is unchanged: it was taken on 1.5.49 and will be re-measured, with every rival in the same session, before any new number is published."
    },
    {
      "version": "1.5.51",
      "date": "2026-09-18",
      "severity": "normal",
      "body": "### PriestAI 1.5.51\n## The window, an agent that checks its own work, and workflows\n\n**The site stands in front of a window.** Behind every page there is now a gothic stained-glass window: pointed lancets and round oculi for tracery, a crackle mosaic of small panes coloured by lancet, and the Mandelbrot set moving through all of it. The light follows the pointer. It is drawn from each theme's own colours, so every theme has its own window. It moves on the display's own frame clock, where 1.5.50's glass waited 33 ms between frames and its background wash was a still refreshed every 2.4 seconds; that wash is gone, and the page stands in front of real panes. The pointer's light is now the theme's own accent and brightens each pane in its own colour instead of washing it pale. One fractal frame is rendered per tick and everything else is three cached layers, so it stays cheap; reduced-motion shows one still frame and high-contrast modes show none.\n\n**A short front page.** The long sections now fold: five cards under the hero instead of a wall to scroll. About 370 words are visible on arrival where there were 1,300, and a phone reaches the footer in a few swipes. Nothing was removed; a menu link into a folded section opens it.\n\n**A menu in groups.** Start, Product and Proof, then the six pages, in place of seventeen stacked rows.\n\n**Feast Your Eyes, and a smaller dock.** The dock opens with Mastodon's Feast Your Eyes. On a phone it arrives as a small pill with the track already loaded and opens to a compact player when tapped. The fractals in the glass move by default; the dock's switch holds them still, the choice is remembered, and reduced motion still means still. Signed in to Spotify in the same browser, the player plays the whole song from the start; signed out, Spotify plays its own 30-second preview.\n\n**API keys in Settings.** Settings > Connect > API keys takes a key for any provider by name - featherless, groq, gemini, openrouter, or an OpenAI-compatible address of your own, which becomes a seat the router can use. The field empties the moment you press Save and the panel only ever shows the last four characters. Keys are entered on the computer that runs PriestAI, so one never crosses a network on its way in.\n\n**Two live sessions, side by side.** The split view's second pane can now be worked in: press Work here too and the pane becomes a second live session on that conversation, with its own composer and its own permission prompts. Each side adopts what the other saved before it saves, so neither can erase the other's words, and a conversation deleted on one side is not brought back by the other.\n\n**What each key has been used for.** Under every key in Settings > Connect > API keys there is now one sentence: calls this month, tokens in and out, the cost where the provider bills it in its reply, and how much of the provider's own rate limit is left and when it resets. The figures come from the provider's reply and headers only; a reply that reports no usage is shown as tokens not reported, never as zero. The key itself is never read for this.\n\n**A mark for every theme.** The logo and the tab icon now change with the theme, drawn from that theme's own colours.\n\n**The agent finishes what it starts.** Before a turn is accepted as done, the app now checks the folder instead of taking the model's word: a request that asked for a change and produced no write, a changed Python file that no longer compiles, or a renamed name still in use somewhere is sent back to the model with the file and line, at most twice, and a turn that still fails is marked unverified rather than passed off as finished. A write that was refused no longer counts as having acted, and an empty reply is asked again once.\n\n**Edits that take fewer steps.** edit_file can replace every occurrence (replace_all) or apply a list of edits to one file, all or nothing: if any edit in the list cannot be made, the file is left byte for byte as it was. A refused edit now says how many times the text appears and on which lines.\n\n**Tool calls that nearly worked now work.** A model that sends file_path for path, old_string for find or cmd for command is understood; a call with a missing or wrong-typed argument is refused before it runs with the argument's name, its type and what was sent; an unknown tool name is answered with the nearest real one. None of this adds a word to what the model is offered.\n\n**The window fits the turn.** The context window a local model is asked for is now the smallest standard size that holds the conversation (8,192, 16,384, 32,768 or 65,536), chosen once per turn and never above what the computer can hold, because a model reloads whenever the size changes. A model is warmed at that exact size when a workspace is bound or the model is changed.\n\n**Workflows.** `priest workflow run` runs a script that fans work out to many agents at once - in parallel, in pipelines, in named phases - with typed results, one guided retry when a reply does not fit, a journal so a stopped run resumes where it left off, and a queue per engine so a fan-out of twenty becomes work the hardware can actually serve. Every run records, per agent, the model that served it, tokens as reported, tool uses and time. A running workflow shows in Background tasks like everything else that is running: a card with its name, how many agents, the tokens they reported and its description, a box per phase with done out of total and one square per agent, the Agent / Model / Tokens / Time table, and a stop button that ends the run cleanly. `priest workflow show` prints the same facts in a terminal.\n\n**Measurement that can be checked.** Every benchmark row now carries per-step timing and token counts; the invalid-call rate is published beside two new figures that separate malformed calls from honest failed runs; a rival that exits without changing anything is recorded as not run rather than scored zero; a pinned benchmark warms its model first, publishes the load time as its own figure, and never scores the pinned model on another model's answer. No published number changed with this release: the next measured run will use these instruments.\n\n**One moving banner.** The tools, records and sign-in pages now carry the same Mandelbrot glass as the chat, from the one renderer.\n\n**DevAd runs again.** A custody guard added on 16 September refused every round and every campaign tick because it could only be satisfied by a worker running under a second OS identity, which does not exist yet. It can now be satisfied one other way: the machine's owner accepts, in an exact written sentence kept in local state, that workers run under their own account. Without that sentence the answer is still no, release admission is never waived by it, and every use is written to the ledger.\n\n**PulseStatus is live.** The status mirror reads the published manifest every time it opens, checks that the download answers at its published size, and is republished after each release."
    },
    {
      "version": "1.5.50",
      "date": "2026-09-17",
      "severity": "normal",
      "body": "### PriestAI 1.5.50\n## The glass is real, the room is docked, the app and the site are one theme\n\n**A live Mandelbrot in the stained glass.** The fractal is rendered on the graphics card every frame and drawn through each leaded pane: the hero's edges, the header band, the Download button, the DevAd support widget and the listening room's head. It breathes between six points of the set, cycles the theme's own three glass colours, and moves faster while the song plays. Reduced-motion draws one still frame; forced colours draw nothing. (1.5.48's fractal was a 160x112 texture at 1-4% opacity: technically present, invisible.)\n\n**Tread Lightly, up when you arrive.** The listening room is a dock in the corner with Mastodon's Tread Lightly loaded; press play. Close it and it stays closed on that browser; Menu > Music brings it back. Playback state comes from Spotify's embed API, which is why the site's script policy now names open.spotify.com.\n\n**One theme, every surface.** The dashboard shows the site's seven palettes (night, ember, moss, paper, vigil, reliquary, sunward) generated from the site's own stylesheet, with text nudged to WCAG AA; older \"dark\" and \"light\" choices map to night and paper. The dashboard's type is the site's: monospace body and headings, Priest Leadlight for the wordmark.\n\n**A shorter home page.** 1,810 words to 1,087: the guide finder, the pilot path and every folded paragraph went to the pages that own them. Menu labels are one word where one word says it.\n\n**385 more skills, licensed item by item.** ECC (292), SkillSpector (26), Comp AI's CRM (34), open-seo (22), ponytail (6), video-use (2), humanizer, i-have-adhd and phone-harness, each carried unchanged under its own MIT, Apache-2.0 or BSD licence inside the product's plugin wrapper, validated by the same checker as 1.5.49's 188.\n\n**DevAd carries the rest.** Scrapling, archify, openshorts, presenton, context-mode and dify are queued as campaigns with their licence verdicts as acceptance criteria; the queue runs on the owner's standing order."
    },
    {
      "version": "1.5.49",
      "date": "2026-09-17",
      "severity": "normal",
      "body": "### PriestAI 1.5.49\n## 188 skills from the wider ecosystem, each on its own licence\n\n- **188 skills, carried in the product's own wrapper.** Skill collections published as `SKILL.md` install as ordinary plugin bundles: the markdown travels unchanged so it stays updatable from upstream, and the manifest around it declares the narrowest surface the format allows - no commands, no tools, no network destinations, no filesystem scopes, no secret references - with file digests and attribution. Every bundle passes the same checker any other plugin passes.\n- **Licensed item by item, not repository by repository.** The OpenAI collections carry no top-level licence; each skill carries its own. So each was taken only where its own licence permits (MIT, Apache-2.0 or BSD) and that licence text ships inside the bundle. 36 of 44 OpenAI skills and 110 OpenAI plugin skills qualified; the 8 Figma skills are under Figma's Developer Terms and 413 plugin items carry no licence at all, so they were not taken. The others are humanlayer/skills, mattpocock/skills and petergyang/no-ai-slop, all MIT.\n- **The benchmark named a wrapper, not a command.** The published comparison disclosed Claude Code's route as a one-line script that only cleared two environment variables. It now names the command that was measured.\n- **DevAd can carry a campaign to publication on a standing order.** Campaigns paused at merge and publish for a per-campaign approval. The owner may now record a standing approval; every use of it is written to the ledger by name and date, and it can be withdrawn by deleting the file.\n\n**Rehearsals declare their world.** A local account created on the development copy, and a machine-specific marker beside the code, made nine tests and the palette smoke run measure the machine instead of the product. Tests now redirect the account store, and a rehearsal can say it is a customer copy (`PRIESTAI_CUSTOMER_COPY=1`, `PRIESTAI_ACCOUNTS_FILE`); nothing on a real install sets either."
    },
    {
      "version": "1.5.48",
      "date": "2026-09-16",
      "severity": "normal",
      "body": "### PriestAI 1.5.48\n## Stained glass everywhere, a faster local model, and Featherless\n\n- **The whole theme is one piece of glass now.** The home page's edge panels were twelve flat shapes; they are 158 irregular panes cut along the same Mandelbrot the site already renders, held in thin lead, so the pointer light sweeps across them individually. The rainbow strip under the header and the border on the support card were the same six colours in different shapes, and are now cut from that fractal too.\n- **Sunward, repainted.** The seventh theme was a violet sunset. It is now taken from the reference artwork: a near-black ground, cream text, and glass in scarlet, indigo and gold.\n- **The link preview was showing an older product.** Sharing the site in Messages produced a card with a headline and tagline the site had stopped using. It now carries the same wordmark, the current tagline and the fractal glass.\n- **The installer's band** used twenty-four identical chevrons on a nine-pixel strip, which at that height is mostly outline. It draws the leaded fractal, and falls back to the old strip where an image cannot be built.\n- **Your graphics card is no longer invisible.** On Windows the product read the card's memory from a field that reports 8 GB as 4, so it planned as though there were no GPU and asked for a 65,536-token window. On an 8 GB card that window's cache alone claimed the whole card and pushed 19 of the model's 33 layers onto the processor. The card is now measured properly and the window sized to fit it.\n- **Featherless is a first-class seat.** Models are addressed as `featherless/<model>`, usable anywhere a model is, measured by the same benchmark as everything else, and gated by the Money panel's budget like any other paid door.\n- **The menu was a document.** Sixteen entries each carried a sentence explaining a label that already said it. The descriptions moved to hover.\n"
    },
    {
      "version": "1.5.47",
      "date": "2026-09-16",
      "severity": "normal",
      "body": "### PriestAI 1.5.47\n## Security fixes, task controls and desktop improvements\n\n- **Owner protection.** Invited accounts cannot replace the owner through sign-in consent. First-time setup requires direct access on the computer, including when an HTTPS proxy is present.\n- **Encrypted remote access.** Network access requires HTTPS. Existing plaintext network settings fall back to local access. Configure a trusted certificate or a local HTTPS reverse proxy using the included secure-panel guide; local-only access continues to work.\n- **Bounded sign-in work.** Oversized credentials are rejected before password hashing. Expiring attempt records, request limits and hashing concurrency limits protect panel availability.\n- **Safer web reading.** Automatic page reads reject local, private and metadata addresses, validate redirects, and connect only to checked public addresses.\n- **Task and tool controls.** The combined update includes task permission inheritance, workspace and tool-approval improvements, and expanded agent and integration controls.\n- **Desktop and credentials.** Includes the prepared launcher, native credential-dialog, credential-cleanup and import-safety improvements, plus Linux launcher and portability updates.\n- **Accessible conversation controls.** Attachment and send controls remain reachable on narrow, zoomed screens. New conversations wait for confirmed storage before requesting their task activity.\n- **Apple builds and installation.** Corrected native iOS build configuration and macOS service startup so the model server stays managed after setup.\n- **Work visibility.** Employee activity and task views expose available status without claiming that unmeasured work has completed.\n- **Clearer product information.** Updated layouts, documentation and status pages distinguish measured behavior from work still being developed.\n\nThe new DevAd production-commissioning requirements are deferred until after this release. This manual release uses the existing test, packaging, installer and public-download verification process. It does not claim production authority commissioning or an external security certification.\n"
    },
    {
      "version": "1.5.46",
      "date": "2026-09-15",
      "severity": "normal",
      "body": "### PriestAI 1.5.46\n## A clearer interface, support tools and stronger request checks\n\n- **Website support.** Ask DevAd Support a question and check its source links. To contact a person, review the recipient and confirm an email to DevAd Support. Sharing your transcript is optional.\n- **Searchable handbook.** Find and preview articles, ask about selected sources, and copy or download their text for app chat or a plan-only CLI task.\n- **Updated appearance.** The website, app, shortcuts and installer use the stained-glass peacock mark. The terminal keeps its Leviathan cross. Shared themes, visible keyboard focus and layouts for phones make the controls easier to use.\n- **Adjust the homepage preview.** Change daylight, light angle and palette with a mouse or keyboard. Reduced motion is supported, and the download button stays visible on compact desktop screens.\n- **Find a page quickly.** Open page search or press Ctrl/Cmd+K to find documentation, downloads, support, measured results and console setup.\n- **Compare recorded results.** Charts on the homepage, results page and DevAd desk show measurements by category. Select a bar to inspect its evidence. Advantage bars appear only for comparable results; missing and old measurements are labeled. These task results are not an overall market ranking.\n- **Separate local comparisons.** The rival runners use the same configured local Qwen model, five tasks, one trial per task and a 75-second limit with file tools. Failed setup and unobserved metrics stay unmeasured. These results are kept separate from the older cloud comparison.\n- **Ongoing local measurements.** The DevAd loop can compare PriestAI with the configured local model in bounded runs. New local results stay in their own comparison group. This checkout enables the schedule; other installations can opt in.\n- **Broader maintenance coverage.** DevAd can propose improvements when tied competitors both outperform PriestAI. New Viriditas modules join the existing review and test process automatically.\n- **Stronger request checks.** Foreign browser origins and ambiguous HTTP requests are rejected before sensitive actions. Viriditas distinguishes unavailable or stale protection evidence and includes both high and critical findings.\n- **Open the installed console.** Menu > Open PriestAI offers a fixed link to the Windows console. Setup registers it; links cannot submit tasks or commands. Existing users can rerun Setup or use the console shortcut.\n- **Clearer terminal controls.** Search /menu, choose a numbered command and switch among six shared themes. An activity indicator supports reduced motion. Streamed answers cannot issue terminal escape commands.\n- **Defined security scope.** Engagements require a named authority and an expiry within seven days. Domains are exact unless subdomains are explicitly included. Exclusions and revocation are checked before scoped commands start. These command-text checks are not an OS or network sandbox.\n- **Restricted public assistants and scripts.** Public assistants use the reviewed support model. Website scripts must come from the same origin or match an approved inline-script hash.\n- Includes reviewed maintenance fixes since 1.5.45.\n\nBefore publication, the release process checks the repository tests, packaged files and installer startup. Download hashes are verified after deployment. These checks are not a completed Codex Security repository scan.\n"
    }
  ]
}