Current version: 0.1.5
Changelog
Every release, what changed in it, and the artifacts it produced. Entries are written when the release ships, not rewritten afterwards.
Filenames and checksums are not repeated here. They live with the artifacts on the releases page, which reads them from the register the publish pipeline writes, so a checksum on this site exists in exactly one place. An entry with no date is the version in the build rather than one you can download, and says so.
Semantic versioning · Added, Changed, Fixed, Security, in that order, with the empty ones omitted · Corrections are dated notes, never silent edits
Releases
0.1.3
The commit panel gains a real AI report you ask for, three measured theme presets, and actions that tell you what they did.
Not released No tag has been cut for this version and no artifact is published, so there is no file to download and no checksum to publish.
Added
- AI commit report. “Why is this commit here?” in the commit detail panel is now a real analysis you ask for. Open the card, press Generate AI Report, and approve the consent notice the first time. It comes back in five parts: the observed facts, then the inference drawn from them, a recommendation, the risk, and the unknowns, which is the list of what this data cannot tell you. Nothing is generated by browsing or selecting a commit; the button is the only trigger. It needs a signed-in GitAegis account, because the analysis runs through GitAegis Cloud. What is sent is the commit's metadata (hash, subject, author name, dates, ref names), how the commit relates to the branch you are on, and the changed file paths with their added and deleted line counts. File contents and commit message bodies are never sent, and known secret shapes are stripped before the request leaves your Mac, with the number of redactions shown on the report. Every report names its provider and its model and carries the line “AI-generated suggestion; verify against the repository”: the deterministic engine remains the authority, and the report has no path to a Git operation.
- Three theme presets. GitAegis Graphite (the default dark, a navy-graphite canvas), GitAegis Slate (a lighter dark with stronger separation between surfaces), GitAegis Light, and System. Chosen in Settings, applied immediately, and remembered. Every preset is measured against WCAG AA contrast on every surface, and the accessibility sweep covers all three before a release.
Changed
- Copy actions confirm what they copied. Copying a hash, a subject or a patch now says so, in a notice below the title bar, instead of leaving you to guess whether the click registered.
- The commit detail panel fits. It is more compact, and a long commit message scrolls inside its own region rather than pushing everything below it off the screen.
- The disk image opens with an Applications folder. So installing is the drag it always should have been.
Fixed
- The commit patch button copies a real patch. It assembles an applyable unified patch from the commit's own diffs, or refuses and says why. It previously copied a two-line header that only looked like a patch and would not apply.
Known limits in this version
- The AI report needs an account and a network. Everything else in the application does not.
- The report describes; it never acts. There is no path from it to a Git operation, and no other AI feature is wired into this build.
- Rebase state is not restored from a capsule. It is recorded, not replayed.
- Configuration is not restored from a capsule; it is captured as evidence only.
.gitattributescontent filters cannot be wholesale disabled.- Bisect and a conflicted
stash applyhave no generic resume. git gc,git pruneandgit reflog expireare not implemented, and will not be.- Billing, team workspaces and provider integrations are not available in this build.
Requires
Git 2.38.0 or newer, already installed. GitAegis does not bundle Git and never downloads one. On macOS 12, Apple's Command Line Tools ship Git 2.37.1 (below the floor) so install with
brew install git.0.1.2
The About dialog reads its licences instead of naming file paths.
Changed
- Licences are readable inside the application. About lists the GitAegis licence, the open-source notices, the verbatim licence texts and the bundled typeface licence as documents you open. They were repository paths, which meant something only to the people building GitAegis.
Requires
Git 2.38.0 or newer, already installed. GitAegis does not bundle Git and never downloads one.
0.1.1
The update flow is the change. This is the first build delivered through the in-app updater, and it carries what that round found.
Fixed
- A withdrawn update stops offering itself. When a release is withdrawn, the banner comes down instead of leaving a retry that cannot succeed.
- A manifest for another channel is refused. The updater checks that the release manifest names the channel this binary was built for, and ignores it otherwise.
- A failed install cleans up after itself. It restores the temporary-directory redirect it made rather than leaving it in place.
- Install failures are visible in two places. The About dialog reports them as well as the banner, so a failure is not invisible to somebody who dismissed the banner.
- Escape from Settings returns focus where it started. Closing the Settings dialog with
Escputs keyboard focus back on the control that opened it.
Requires
Git 2.38.0 or newer, already installed. GitAegis does not bundle Git and never downloads one.
0.1.0
The recovery layer and the everyday Git toolkit, for macOS. GitAegis takes a full recovery capsule before any risky operation, and refuses to run the operation if the capsule cannot be written.
Added
- Recovery capsules. A capsule captures six domains before a risky operation runs: refs, index, staged changes, working changes, untracked files, and operation state. Restore any single domain or all of them. If the capsule cannot be written, the operation is blocked and never runs.
- Operation model. Every mutation is a transaction carrying an intent, a risk level, its preconditions, the exact commands it will execute, a checkpoint, a rehearsal pass, and a rollback plan. Dangerous actions open the Operation Preview drawer rather than a confirmation dialog.
- Operation Journal. Every mutating operation is recorded with its plan, its commands, its checkpoint, and its outcome.
recover_incompletereconciles unfinished transactions torequires-interventionon the first launch after a crash. - Flight Recorder. A timeline of what happened to a repository (refs created, deleted and moved, HEAD moves and retargets, index and stash changes, worktree registrations, and operation markers appearing and clearing) including the ones GitAegis did not cause. Events that captured a state hash can be rolled back to. Content edits inside the working tree are visible in status and do not produce timeline events.
- Lost Work. Finds commits nothing points at any more, scanning the HEAD reflog, the stash reflog, Flight Recorder “before” oids,
refs/aegis/recovery refs, capsule bundles, sibling worktree HEADs, and a boundedgit fsck --unreachable --dangling. Offers to put a branch back on what it finds. - Safe Mode. When the index or
HEADcannot be trusted, mutating controls lock out instead of letting you make it worse. Safe Mode additionally pinscore.hooksPath=/dev/null. - Doctor. Scans for real damage, shows the evidence behind each finding, and proposes repairs that take a capsule first. Eight repair recipes ship: index rebuild, stale-lock quarantine, interrupted merge recovery, interrupted rebase recovery, deleted-branch recovery, detached-HEAD preservation, moved-worktree repair, and invalid-upstream repair.
- Everyday Git. Repository catalogue and discovery across a folder tree; status with staged, unstaged, untracked and conflicts; hunk- and line-level staging; commit with amend safety and signing pass-through; branches, tags, remotes, refs, reflog, file history, blame; fetch, pull, push, force-push-with-lease, publish, prune; merge, rebase, cherry-pick, revert, reset, restore, clean; conflict detection with stage-1/2/3 read, resolution, and sequencer continue / skip / abort; worktrees; stashes; submodules; Git LFS status, missing-object accounting, read-only locks and fetch; commit graph, compare, search and bisect; clone with streamed cancellable progress; init with optional README,
.gitignoreand licence. - Five modes. Home
⌘1, Work⌘2, History⌘3, Review⌘4, Doctor⌘5. - Command palette.
⌘Kover real intents rather than a fuzzy list of menu labels. - Semantic Composer. Proposes commit groupings from your working changes and applies them through the operation orchestrator, so a grouping is planned, checkpointed and reversible like anything else.
- In-app updates. GitAegis reads one fixed release manifest, 30 seconds after launch and then once a day. The request carries no identifier, no version parameter and no query string: your version is compared on your machine. Nothing installs on its own. When a newer build is offered you press Restart to update, and the downloaded archive's signature is verified against a key built into the application before anything is installed.
- Accessibility and display. UI scale 80–200%, light, dark and system themes, and full keyboard navigation.
- Support bundles. Generated locally, scanned for secrets, and path-redactable before you send them.
- Platform. macOS 12 Monterey and later, as a signed universal binary for Apple Silicon and Intel.
Security
- Git subprocesses pin
GIT_CONFIG_*andGIT_TERMINAL_PROMPT=0, so a hostilecore.fsmonitororcore.pagerin a cloned.git/configcannot execute and Git can never block on a hidden credential prompt. Safe Mode additionally pinscore.hooksPath=/dev/null. - External diff and merge tools are never launched, in any mode.
- Credentials are read from the system keychain, and SSH uses your own keys through your own agent. GitAegis stores neither.
- Local Git work never requires an account. If you choose to sign in, GitAegis contacts only its configured account gateway for the account features you choose.
- An update archive must carry a valid signature against the key compiled into the application before it is installed; one that fails verification is refused. The manifest that advertises a release is plain JSON over TLS and is not itself signed, so a host compromise cannot inject code but could misdescribe a genuinely signed artifact. The updater answers that in part by requiring the manifest to name this binary's own channel.
- Support bundles are scanned for secrets before they are written.
Known limits in this version
- Rebase state is not restored from a capsule. It is recorded, not replayed.
- Configuration is not restored from a capsule; it is captured as evidence only.
.gitattributescontent filters cannot be wholesale disabled.- Bisect and a conflicted
stash applyhave no generic resume. git gc,git pruneandgit reflog expireare not implemented, and will not be.- Staged and working changes are captured as binary patches rather than as loose objects. On a repository damaged badly enough that the patch cannot be computed, those two domains are present but empty, and the capsule manifest records it.
- Optional account sign-in is available. Billing, team workspaces, provider integrations and AI assist are not available in this build.
- The scheduled update check is on by default and has no rendered off switch in this build. The setting exists and the Settings group that would carry it is not shown, so the honest description is that you cannot currently turn the daily check off from the interface. Nothing installs without you pressing Restart to update.
Requires
Git 2.38.0 or newer, already installed. GitAegis does not bundle Git and never downloads one. On macOS 12, Apple's Command Line Tools ship Git 2.37.1 (below the floor) so install with
brew install git.
How these entries are written
Stated in advance, so an entry you cannot independently verify still tells you something.
The editorial contract
- Four categories, always in this order: Added, Changed, Fixed, Security. A category with nothing in it is omitted rather than left empty. Added is a capability that did not exist before. Changed is behaviour that is different now, in plain words, whether or not the change was an improvement. Fixed is the symptom you would have seen, then the cause, not the internal ticket title, and not “various stability improvements”. Security is what was wrong, what it exposed, which version fixes it, and the advisory ID.
- Versioning is semantic. MAJOR.MINOR.PATCH. A major version means an on-disk format change or a behaviour change you must know about before you upgrade, and those entries lead with a “Before you upgrade” paragraph. Beta builds carry a -beta.N suffix.
- Every release stays published. Version numbers are immutable: a version will always be the bytes it was on the day it shipped. If a release is withdrawn, the entry stays on this page, gains a Withdrawn marker and the reason, and the artifacts stay downloadable.
- Entries are not rewritten. A mistake in an entry is corrected with a dated note beneath it, not by editing history out of it.
- What never appears in an entry. A capability described before it ships, a date for something that has not shipped, or a metric we cannot show you. Work that has not shipped lives on the roadmap.
Work that has not shipped lives on the roadmap, and never in an entry here.
How you find out about a release
Honestly: by looking. There is no feed and no mailing list, because there is nothing yet to syndicate.
This page
Every version, in full, newest first. Versions are immutable: a number always means the bytes it meant on the day it shipped, and a withdrawn release keeps its entry and gains the reason it was withdrawn.
From the application
GitAegis reads one fixed release manifest 30 seconds after launch and then once a day, and tells you when a newer build exists. The request carries no identifier and no version parameter. Nothing installs on its own: you press Restart to update, and the archive’s signature is checked against a key built into the application before it is installed.
Free edition · No account required
A recovery capsule before every risky Git operation.
You see the exact commands before they run, and the operation is refused if the capsule cannot be written.
Requires Git 2.38.0 or newer, already installed.
Every risky operation, in this order
- Previewthe exact commands, shown before anything runs
- Capsulerefs, index, staged and working changes, untracked files, operation state: written to disk first
- Executethe commands as shown, or not at all
- Journalplan, commands, capsule id, outcome