Changelog

What's new in NeverWrite

Linux AppImages & Secure Provider Keys

  • Added Added Linux AppImage releases for x64 and ARM64, including Linux update feed support and AppImage updater integration
  • Added Added Kilo API key setup in AI provider settings, with secure local persistence, logout cleanup, and setup-state validation alongside the existing Kilo CLI login flow
  • Added Added an in-app HTML viewer for vault .html and .htm files, including sandboxed script execution, relative asset loading, and restrictive network protections
  • Added Added .html and .htm files to the default file tree so HTML documents appear without enabling the global all-files view
  • Changed Updated the embedded Claude ACP runtime to upstream 0.33.1 and the embedded Codex agent runtime to 0.14.0
  • Changed Polished Linux-specific desktop packaging behavior, window chrome, updater handling, and cross-platform shortcut behavior for the AppImage release path
  • Fixed Fixed chat Markdown rendering so slash-prefixed text is no longer converted into a clickable vault pill unless it resolves to a valid vault reference
  • Fixed Fixed dragging agent chats from the collapsed sidebar so the sidebar overlay stays active while the drag starts
  • Fixed Fixed inline file-review Accept and Reject buttons so decisions run on click release instead of immediately on press
  • Fixed Fixed provider quota, rate-limit, and usage-limit failures so chat shows a clear provider-limit message instead of treating the error like setup or authentication failure
  • Fixed Fixed oversized saved AI session transcripts by compacting new saves and repairing previously inflated saved chats on load
  • Fixed Fixed vault scans, text-file reads, and watcher hashing for Markdown and text files that contain invalid UTF-8 bytes by decoding them lossily instead of failing the vault operation
  • Fixed Fixed Linux updater handling when a release feed is missing so the app can continue gracefully across Linux release variants
  • Security Secured persisted AI provider secrets for Codex/OpenAI, Claude/Anthropic, Gemini/Google, and Kilo API keys through OS credential storage instead of runtime setup JSON
  • Security Audited NeverWrite for the May 2026 Mini Shai-Hulud npm supply-chain attack and found no exposure to the known malware indicators, affected package sets, or risky workflow pattern