Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,21 @@ Historical entries retain their original delivery coordinates.

## Unreleased

## 0.18.64

Supported global CLI installs update to the latest stable release before an
ordinary command, with at most one automatic check per day.

- Add `ghostget update`, `check`, `status`, `enable`, and `disable`.
- Keep updates out of SDK calls, source checkouts, project dependencies, CI,
nested clients, help, and gateway-only sessions. Exact pins need `update enable`.
- Verify the immutable release archive before the owning package manager runs,
and wait until other commands using that installation have finished.

## 0.18.63

Annotated tag rejected before publication; tag unchanged.

Present GhostGet with the shared studio design conventions.

- Group related studio tools by purpose, shorten the opening copy, and keep installation within reach.
Expand Down
29 changes: 24 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ Install [Bun 1.3.14](https://bun.sh/docs/installation) if needed, then install
GhostGet and read a public page:

```sh
bun add --global https://github.com/hraness/ghostget/releases/download/v0.18.63/hraness-ghostget-0.18.63.tgz
bun add --global https://github.com/hraness/ghostget/releases/download/v0.18.64/hraness-ghostget-0.18.64.tgz
ghostget read https://example.com
```

Expand All @@ -49,15 +49,34 @@ which always names the latest published release. Upgrading from Wrench? Read the
The optional Agent Skill teaches your agent when and how to use GhostGet:

```sh
npx skills add hraness/ghostget#v0.18.63
npx skills add hraness/ghostget#v0.18.64
# With Bun instead:
bunx skills add hraness/ghostget#v0.18.63
bunx skills add hraness/ghostget#v0.18.64
```

Start a new agent session, then ask: “Use GhostGet to read https://example.com
and summarize it.” The skill is instructions for your agent; the CLI install
above supplies the executable.

### Update the CLI

Supported global Bun and npm installs on macOS and Linux check for a stable
GhostGet release before ordinary commands, at most once a day. Install the
GitHub CLI (`gh`) and authenticate it with `gh auth login --hostname github.com`
to let the updater download verified release archives. If your installed CLI
does not have `update`, repeat this guide's global CLI install command once.
Run `ghostget update` to update now,
`ghostget update check --json` to inspect a release, or `ghostget update status`
to see the saved setting. Use `ghostget update disable` to turn automatic updates
off and `ghostget update enable` to turn them on. Exact version pins require
`enable` before following new releases.

Set `HRANESS_NO_UPDATE=1` for a command that must use the installed version.
CI, nested clients, help, and gateway-only mode skip automatic checks. Manage
source checkouts, project dependencies, and unsupported installations with their
package manager. Agent Skill copies are refreshed separately through the skill
installer. Updating the CLI preserves connected accounts and saved content.

## When to use something else

| Tool | Use it instead of GhostGet when |
Expand Down Expand Up @@ -164,7 +183,7 @@ firewall.

## Built-in provider catalog

This v0.18.63 source tree supports executable actions for 21 services: Beeper,
This v0.18.64 source tree supports executable actions for 21 services: Beeper,
Bluesky, ClasificadosOnline, Facebook, Facebook Groups, Facebook Marketplace,
GitHub, Gmail, Hacker News, Instagram, iMessage, LinkedIn, Reddit, Substack,
Threads, TikTok, Twitch, WebMCP Registry, WhatsApp, X, and YouTube. LinkedIn
Expand Down Expand Up @@ -248,7 +267,7 @@ For that same released coordinate, install GhostGet in an agent or application
that owns its own model, planning, tool loop, approvals, and interface:

```sh
bun add https://github.com/hraness/ghostget/releases/download/v0.18.63/hraness-ghostget-0.18.63.tgz
bun add https://github.com/hraness/ghostget/releases/download/v0.18.64/hraness-ghostget-0.18.64.tgz
```

```ts
Expand Down
3 changes: 3 additions & 0 deletions bun.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

21 changes: 21 additions & 0 deletions costs.json
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,27 @@
"maxCalendarDays": 90
},
"status": "capture-required; public execution rejects before credentials or network"
},
"local:cli-update-policy": {
"kind": "authoritative",
"retention": "persistent",
"owner": "src/update.ts",
"deletion": "src/update.ts",
"budget": {
"maxBytesPerStateFile": 16384,
"maxCoordinationEntries": 4096
},
"source": "Explicit update policy and verified installed release receipts; no account or captured content"
},
"local:cli-update-archives": {
"kind": "derived",
"retention": "persistent",
"owner": "src/update.ts",
"source": "Verified immutable release archives retained for global package-manager replay",
"budget": {
"maxBytesPerArchive": 536870912
},
"expiry": "Retain manager-referenced archives; cleanup requires proving no installation or running manager references them"
}
},
"exempt": []
Expand Down
2 changes: 1 addition & 1 deletion dist/apple-photos-client.js
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
// @bun
import {
GHOSTGET_VERSION
} from "./index-adtr3kqc.js";
} from "./index-rayqxqrk.js";
import {
canonicalJson,
sha256
Expand Down
2 changes: 1 addition & 1 deletion dist/beeper-client.js
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ import {
} from "./index-26yq8q16.js";
import {
GHOSTGET_VERSION
} from "./index-adtr3kqc.js";
} from "./index-rayqxqrk.js";
import {
canonicalJson,
canonicalJsonSha256Matches,
Expand Down
2 changes: 1 addition & 1 deletion dist/index-adtr3kqc.js → dist/index-rayqxqrk.js
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
// @bun
// src/version.ts
var GHOSTGET_VERSION = "0.18.63";
var GHOSTGET_VERSION = "0.18.64";

export { GHOSTGET_VERSION };
6 changes: 3 additions & 3 deletions docs/assurance.md
Original file line number Diff line number Diff line change
Expand Up @@ -2014,12 +2014,12 @@ Release admits source only with the exact commit's successful default-branch CI
- Assumptions: `github-api`, `github-enforcement`
- Not verified: Only the enumerated example cases are checked.

#### `release-source-codeql-exact-two-languages`
#### `release-source-codeql-exact-four-languages`

Source admission requires exactly the Actions and JavaScript/TypeScript CodeQL jobs and analyses on the exact source and current main; missing or extra languages, or two exact-source CodeQL runs, are rejected.
Source admission requires exactly the Actions, JavaScript/TypeScript, Python, and Rust CodeQL jobs and analyses on the exact source and current main; missing or extra languages, or two exact-source CodeQL runs, are rejected.

- Evidenced by example test.
- Source: `docs/publishing.md`: “Admission requires exactly those two jobs and analyses, with missing or extra languages rejected.”
- Source: `docs/publishing.md`: “Admission requires exactly those four jobs and analyses, with missing or extra languages rejected.”
- Evidence: `scripts/github-release-artifact.test.ts`
- Assumptions: `github-api`, `github-enforcement`
- Not verified: Only the enumerated example cases are checked.
Expand Down
4 changes: 2 additions & 2 deletions docs/contracts.md
Original file line number Diff line number Diff line change
Expand Up @@ -128,7 +128,7 @@ matches some IDs lists the installed ones and exits 0.
{
"ok": true,
"contract": "ghostget.contract-catalog.v1",
"ghostget": { "version": "0.18.63" },
"ghostget": { "version": "0.18.64" },
"generatedAt": "2026-09-21T20:00:00.000Z",
"vocabulary": {
"risks": ["R1", "R2", "R3", "R4"],
Expand Down Expand Up @@ -186,7 +186,7 @@ does not parse is an error (exit 3) and no catalog is read.
{
"ok": false,
"contract": "ghostget.contract-check.v1",
"ghostget": { "version": "0.18.63" },
"ghostget": { "version": "0.18.64" },
"plan": { "collectionKey": "hraness-social-profile-statistics", "reads": 15 },
"reads": [
{ "index": 0, "accountKey": "x-hraness", "adapter": "x-web", "operation": "profiles.read",
Expand Down
21 changes: 11 additions & 10 deletions docs/publishing.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,11 +32,11 @@ Explicit focused local/native and coupled reproductions still apply under

`scripts/release-source-ci.ts` reads GitHub's current run attempt directly. It
requires the exact repository, active workflow ID/path, main-push source and tree,
all eleven successful jobs, and ten actual checkout logs. Each source job records
its exact workflow/lock hashes, Node/npm/Bun versions and GitHub-hosted platform
before its frozen install. Admission also requires both successful
exact-source CodeQL jobs and current main analyses for Actions
and JavaScript/TypeScript, plus the successful
all nineteen successful jobs, and eighteen actual checkout logs. Each source job
records its exact workflow/lock hashes, Node/npm/Bun versions and GitHub-hosted platform
before its frozen install. Admission also requires all four successful
exact-source CodeQL jobs and current main analyses for Actions,
JavaScript/TypeScript, Python, and Rust, plus the successful
security comparison on the merged PR's identical tree. Any present main comparison must succeed;
analysis result counts are recorded without asserting that no alerts exist.
The CodeQL app's check must identify that exact PR through its returned PR
Expand All @@ -59,9 +59,10 @@ permissions for these API reads. Publication and attestation permissions stay
unchanged.

PR #272 moved the repository-owned Swift menu into the pinned shared desktop
foundation. The current repository has no tracked Swift source; GitHub's
default setup scans Actions and JavaScript/TypeScript. Admission requires
exactly those two jobs and analyses, with missing or extra languages rejected.
foundation. The current repository has no tracked Swift source; its verification
oracles added in PRs #357 and #358 include Python and Rust. GitHub's default setup
scans Actions, JavaScript/TypeScript, Python, and Rust. Admission requires exactly
those four jobs and analyses, with missing or extra languages rejected.
The shared foundation owns its native source checks and published artifacts.
Reintroducing another source language requires a reviewed coverage update.

Expand Down Expand Up @@ -242,12 +243,12 @@ delivery proceeds through a new source-qualified version.

## Install the canonical release

These commands require the matching published immutable v0.18.63 release.
These commands require the matching published immutable v0.18.64 release.

For the CLI:

```sh
bun add --global https://github.com/hraness/ghostget/releases/download/v0.18.63/hraness-ghostget-0.18.63.tgz
bun add --global https://github.com/hraness/ghostget/releases/download/v0.18.64/hraness-ghostget-0.18.64.tgz
ghostget --version
ghostget doctor --json
```
Expand Down
14 changes: 7 additions & 7 deletions kb/launch/social-kit.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ The plan is for GhostGet to stay small. Your agent does the thinking, and GhostG
Post 9 of 9, 192 characters

```text
GhostGet is free, MIT licensed, and runs on macOS and Linux. The first step reads a public page and needs no account. Latest release: v0.18.63.
GhostGet is free, MIT licensed, and runs on macOS and Linux. The first step reads a public page and needs no account. Latest release: v0.18.64.

https://ghostget.com/blog/introducing-ghostget/
```
Expand Down Expand Up @@ -115,7 +115,7 @@ The plan is for GhostGet to stay small. Your agent does the thinking, and GhostG
Post 9 of 9, 192 characters

```text
GhostGet is free, MIT licensed, and runs on macOS and Linux. The first step reads a public page and needs no account. Latest release: v0.18.63.
GhostGet is free, MIT licensed, and runs on macOS and Linux. The first step reads a public page and needs no account. Latest release: v0.18.64.

https://ghostget.com/blog/introducing-ghostget/
```
Expand Down Expand Up @@ -173,7 +173,7 @@ The plan is for GhostGet to stay small. Your agent does the thinking, and GhostG
Post 9 of 9, 192 characters

```text
GhostGet is free, MIT licensed, and runs on macOS and Linux. The first step reads a public page and needs no account. Latest release: v0.18.63.
GhostGet is free, MIT licensed, and runs on macOS and Linux. The first step reads a public page and needs no account. Latest release: v0.18.64.

https://ghostget.com/blog/introducing-ghostget/
```
Expand All @@ -197,7 +197,7 @@ GhostGet is for Claude Code, Codex, Cursor, and other agents that run commands o

The plan is for GhostGet to stay small. Your agent does the thinking, and GhostGet runs only actions someone has reviewed. Each new service arrives as reviewed actions with their own previews.

GhostGet is free, MIT licensed, and runs on macOS and Linux. The first step reads a public page and needs no account. Latest release: v0.18.63.
GhostGet is free, MIT licensed, and runs on macOS and Linux. The first step reads a public page and needs no account. Latest release: v0.18.64.

https://ghostget.com/blog/introducing-ghostget/
```
Expand All @@ -224,8 +224,8 @@ Topics: Developer Tools, Artificial Intelligence, Open Source
- Sometimes a post goes through but the answer gets lost on the way back. GhostGet writes down every send before it leaves and never sends it again on its own until it knows what happened.
- Anything beyond a read starts as a preview that shows the service, the account, and exactly what will be sent. Your agent can prepare it. Nothing is sent until someone confirms that exact preview.
- GhostGet is for Claude Code, Codex, Cursor, and other agents that run commands on your Mac or Linux machine and need to read the web and use the accounts you already have.
- GhostGet is free, MIT licensed, and runs on macOS and Linux. The first step reads a public page and needs no account. Latest release: v0.18.63.
- Latest release: v0.18.63. https://ghostget.com/blog/introducing-ghostget/
- GhostGet is free, MIT licensed, and runs on macOS and Linux. The first step reads a public page and needs no account. Latest release: v0.18.64.
- Latest release: v0.18.64. https://ghostget.com/blog/introducing-ghostget/

## Beats

Expand All @@ -251,4 +251,4 @@ Topics: Developer Tools, Artificial Intelligence, Open Source
- claimsTotal: 247. verification/claims.json, every claim
- claimsEvidenced: 228. verification/claims.json, status evidenced
- claimsConfigReadback: 15. verification/claims.json, layer configuration-readback
- status: Latest release: v0.18.63. package.json version
- status: Latest release: v0.18.64. package.json version
8 changes: 5 additions & 3 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@hraness/ghostget",
"version": "0.18.63",
"version": "0.18.64",
"description": "GhostGet gives your AI agent named web actions: read a page, archive one media item, or use a connected account, without credentials or a browser to steer.",
"license": "MIT",
"type": "module",
Expand Down Expand Up @@ -649,7 +649,8 @@
"src/control/registry.ts",
"src/control/registry-words.ts",
"src/control/retire-tray.ts",
"src/control/status-view.ts"
"src/control/status-view.ts",
"src/update.ts"
],
"scripts": {
"check:theme": "bun scripts/check-paper-theme.mjs",
Expand Down Expand Up @@ -705,7 +706,8 @@
"typescript": "6.0.3",
"@1password/sdk": "0.5.0",
"@hraness/desktop-foundation": "https://github.com/hraness/desktop-foundation/releases/download/v0.9.0/hraness-desktop-foundation-0.9.0.tgz",
"@steipete/sweet-cookie": "0.4.3"
"@steipete/sweet-cookie": "0.4.3",
"@hraness/cli-update": "https://github.com/hraness/cli-update/releases/download/v0.1.0/hraness-cli-update-0.1.0.tgz"
},
"devDependencies": {
"@hraness/design-kit": "github:hraness/design-kit#v0.35.0",
Expand Down
Loading
Loading