This release adds 5 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+8 more
ReleasePort's take
Light signalAgent FM v0.1.1 improves macOS integration with explicit error messages for secure storage failures and signed/notarized distribution. Provider keys now encrypt via macOS secure storage with fail-closed error handling.
Why it matters: macOS users get clear error messages instead of silent failures when secure storage is unavailable. Notarized app improves installation trust. Treat as FYI; upgrade when convenient.
Summary
AI summaryFirst‑run macOS secure storage now shows clear error messages and uses the Agent FM name.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Notarizes and staples app and DMG in signed release workflow. Notarizes and staples app and DMG in signed release workflow. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Security | Medium |
Provider keys encrypted via macOS secure storage, fails closed when unavailable. Provider keys encrypted via macOS secure storage, fails closed when unavailable. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Feature | Medium |
Explains Agent FM Safe Storage before macOS Keychain prompt appears. Explains Agent FM Safe Storage before macOS Keychain prompt appears. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Feature | Medium |
Updates packaged executable name to Agent FM for polished macOS prompts. Updates packaged executable name to Agent FM for polished macOS prompts. Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Bugfix | Medium |
Shows clear error when macOS denies secure storage instead of silent failure. Shows clear error when macOS denies secure storage instead of silent failure. Source: llm_adapter@2026-05-21 Confidence: high |
— |
Full changelog
What's changed
This patch improves the first-run macOS secure-storage experience.
- Explains Agent FM Safe Storage before macOS may show a Keychain prompt.
- Shows a clear setup error if macOS denies secure storage access instead of silently failing.
- Keeps provider keys encrypted through macOS-backed secure storage and fails closed when encryption is unavailable.
- Updates the packaged executable name to
Agent FM, so future macOS prompts use the polished app name. - Notarizes and staples both the app and DMG in the signed release workflow.
Verification
- CI passed on
main. - DMG and mounted app pass
codesign,spctl, andxcrun stapler validate. - SHA-256:
a4263f5da0bc5a8c84858d17387e58b609f41c5a6211837f8f1129ba44aa009d
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Agent FM
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]