Release notes

Current release is 0.8.1, published 2026-09-30. Where a release needs something from you before you upgrade, it says so at the top of the entry.

0.8.1

current

2026-09-30

The site report is now a formal hand-over document, the wireless survey reports the customer's own access points with a channel plan, the survey reaches other private networks, and File Transfer handles whole folders.

  • ChangedSite Report is now a formal hand-over document. It opens with a cover: the site, who it was prepared for and by, and a count of what was found on the network by kind — routers and firewalls, switches, access points, cameras, recorders, door controllers, printers, servers, and the Wi-Fi networks in use. Then an agenda listing every section, a page saying which reports are included and why any was left out, and a sign-off for both sides. Every section opens with one plain sentence a customer can read before the tables an engineer reads, and it prints on A4 with the site and reference at the head of each page.
  • AddedThe report carries the technician's company name and logo — added once, remembered, and printed on the cover and the running header.
  • ChangedThe wireless survey now reports the customer's own access points rather than every network in range. The signals heard are grouped into radios and access points, each listed with the networks it broadcasts, and a channel plan is worked out for the site's radios together — 1, 6 or 11 on 2.4 GHz, quiet blocks on 5 GHz, DFS handled — so no two are sent to the same channel. Networks that belong to neighbours are counted per channel, not named. Recorders (NVR/DVR) and door controllers are now identified as their own kinds of device.
  • ChangedThe survey reaches beyond the subnet this machine is on. After sweeping the connected networks it makes a bounded attempt to find other private networks — the siblings of a connected subnet, the networks the routing table can reach, and the common private ranges — knocks on their likely gateways, and sweeps the ones that answer. The hosts that turn out to be servers, routers or firewalls then get a full scan of all 65,535 TCP ports, shown as an nmap-style summary, while everything else keeps the Common set.
  • AddedFile Transfer can download, copy and move whole folders, not only files. A folder downloads as a tree — recreated locally with every file under it — and copy and move carry folders too. Broken symlinks stay out, since there is nothing behind them to fetch.

0.8.0

2026-09-24

A new look and a new mark, a Site Report page that surveys the site on its own and keeps every customer's report, throughput testing that speaks iperf3, and SSH that reaches equipment behind a bastion.

  • ChangedA new identity. A new mark — two strands of a twisted pair crossing once to make the C — and a new look throughout: Bricolage Grotesque for titles, Instrument Sans for text, Martian Mono for readings; a warm off-white on a dark matte body, or bone with white panels in the light theme; one coral accent that marks the primary button, the active tool and the chosen segment. Colour otherwise stays with the data. Every page is laid out the same way: panels with a titled head, a grid that fills the window, tables that scroll inside their panel, and the shared fields, buttons and segmented controls.
  • AddedSite Report, a page of its own. Tick the sections, press Run survey, and the app runs the tools behind them in order — adapters, wireless, the six connectivity checks with the download speed test, an IP sweep of every connected subnet, a Common-ports scan of every host found, a listen for the switch port, and a throughput test when an iperf3 endpoint is given — while the report fills in beside the checklist. The report is the formal hand-over document, and now opens with how it was measured: who, when, from which adapter, each step with its target, duration and outcome. Every report is filed in the app under the customer's name with the technician's, and can be reopened, exported as HTML, printed to PDF, or deleted.
  • AddedThroughput. An iperf3-compatible client and server. Test against any iperf3 -s, or start the server and let any iperf3 -c test this machine. TCP or UDP; upload, download or both at once; parallel streams; jitter, loss and out-of-order counts for UDP. Presets for VoIP readiness, a link check, saturation and a Wi-Fi client. The command line is shown, editable and pasteable, and runs unchanged anywhere iperf3 is installed. Every run ends in a plain-language verdict read against the speed the local port negotiated, and is kept per endpoint for the next visit. iperf3's username-and-key authentication works on both sides. Verified against stock iperf3 3.21.
  • AddedSSH agent. A third way in alongside password and key file: the Windows OpenSSH agent holds the key, so the app never reads a key file, and hardware-backed keys work.
  • AddedJump hosts. A saved SSH or SFTP connection can be reached through another saved connection — one hop, the way ssh -J does it. Both host keys are pinned.
  • AddedContinuous ping on Diagnose, with a live chart of round-trip time.
  • AddedIP Scanner history. Sweeps are kept per subnet; the next visit shows what is new, no longer seen, or replaced.
  • AddedSaved connections export and import, so a connection list can move to another machine.
  • ChangedSignal grades use one set of thresholds everywhere (-55, -67, -80 dBm); the legend, the colours and the arc glyph used to disagree.
  • ChangedCopy throughout is shorter and says what a thing is rather than what it is not. The Speed Test verdict names packet loss, and no longer says Wi-Fi on a wire.
  • ChangedThe Overview no longer waits for the terminal and chart libraries to load; each page is its own chunk.
  • FixedCheckboxes and radios took the Windows blue accent. TFTP's empty state promised uploads while Read-only was ticked. Three defects on the Channels page. Sort state and scan progress are announced to screen readers. Password and label fields lost their labels once something was typed. The mock backend is no longer shipped to every user.

0.7.1

2026-08-25

Equipment that refused to connect at all now connects, and SSH takes a private key.

  • FixedSSH and file transfer failed with “No common key exchange algorithm” against anything offering ecdh-sha2-nistp256 or the SHA-1 exchanges — most enterprise network hardware and all older kit. Both now negotiate what equipment actually offers, modern algorithms first.
  • AddedPrivate key authentication for SSH and file transfer. OpenSSH format — Ed25519, RSA, ECDSA — including encrypted keys, with any key already in ~/.ssh offered on the connection form. A saved key connection reconnects in one click.
  • AddedCopy and Paste buttons on the SSH and serial terminals. The clipboard already worked three ways; none of them were discoverable, and Ctrl+C in a terminal interrupts the running command rather than copying.
  • ChangedA PuTTY .ppk is now identified by content and reported with the PuTTYgen conversion steps, rather than failing as an unreadable file.
  • FixedA saved key connection with no passphrase could never reconnect in one click, because an entry with nothing stored was treated as incomplete.

0.7.0

2026-08-04

The app password, encrypted transcripts, and a port scanner that takes more than one host.

Read before upgrading

This release introduces the app password, and there is no way to recover it. It is not a lock on the front door — it is the key your saved SSH, SFTP and RDP passwords are encrypted with, so if you lose it those credentials are permanently unreadable. Put it somewhere safe before you set it. Passwords you already had are moved onto the new key as soon as you set it.
  • SecuritySaved credentials are now encrypted with ChaCha20-Poly1305 under a key derived from your app password with Argon2id. Previously they were protected by Windows DPAPI, which ties them to your Windows account — meaning anything running as you could read them back, which is exactly what credential-stealing malware does.
  • SecuritySession transcripts are encrypted and renamed .clog. They routinely contain running-config, SNMP communities and pre-shared keys, and were plain text on disk.
  • AddedA Security page: change the password, lock on demand, and optionally lock after a stretch with no keyboard or mouse activity — off by default.
  • AddedThe port scanner takes more than one host: a subnet, a range, a list or a mix. Multi-host targets are swept for live hosts first and only those are scanned. Results group by host with name, vendor and open-port count, and filter, sort and export to CSV, JSON or text.
  • ChangedScan parallelism, retries and timeout are adjustable, and a running scan can be stopped.

0.6.2

2026-07-28

Fixes the blank terminal that made SSH and serial unusable in 0.6.1.

  • FixedThe webview's content security policy was refusing the styles xterm applies to its own rows, so a connected session printed into a pane that never showed anything.
  • FixedA session that dies silently is now noticed and closed rather than sitting on “connected” indefinitely.
  • FixedThe public IP on the overview screen works for the first time.

0.6.1

2026-07-21

Fixes found by using 0.6.0 on real equipment.

  • FixedSSH full screen could trap you with no way back out.
  • FixedThe saved-connections list is reachable again when opening a new session.
  • FixedThe sidebar widens in place instead of covering the page.
  • AddedSession transcripts, off by default.
  • AddedPort Finder shows vendor marks for the manufacturers we hold.
  • FixedPacket capture says when it cannot open an adapter, and an IP sweep reports what it found.

0.6.0

2026-07-14

The dark instrument theme and the icon rail.

  • ChangedDark became the primary theme, with light as an opt-in that is remembered across launches.
  • ChangedThe sidebar became an icon rail that widens on hover.
  • AddedCtrl+K to jump between screens.
  • AddedSignal traces and heat bars on the networks view, and an oscilloscope-style trace on the signal view.

0.5.5

2026-07-07

The security work: host key verification, and the fixes around it.

  • SecuritySSH host keys are pinned on first connect and a change is refused, with a panel showing both fingerprints when a device has genuinely been rebuilt.
  • SecurityTFTP path limits, so a served folder cannot be escaped.
  • SecuritySystem binaries are invoked by absolute path, and the update helper runs in its own working directory.
  • SecurityRDP credentials are handed to the Windows client through the Credential Manager rather than on a command line.
  • FixedThe executable name is pinned. It had changed between builds, so the installer added the new binary alongside the old one instead of replacing it.

Releases before 0.5.5 are not listed here. Notes for them were not kept in a form worth reproducing, and writing them from memory would be guesswork rather than history.