This release includes 1 security fix for security teams reviewing exposed deployments.
Published 25d
Developer Productivity
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai-coding
claude-code
codex
gemini-cli
macos
menu-bar
+5 more
menubar-app
pokemon
swift
swiftui
token-usage
Affected surfaces
rce_ssrf
Summary
AI summaryUpdates What's new, Lighter, and Hardening across a mixed release.
Full changelog
What's new
- Settings footer links — quick links to GitHub and the website next to the version number.
Fixes
- "Disable Keychain access" now sticks — the toggle wasn't persisted and silently reset after an app restart.
Lighter
- App is ~43% smaller (stripped release binary; download ~13% smaller).
- Usage cache on disk shrunk ~72% (compressed, old caches load seamlessly).
- Log file no longer grows forever — capped with rotation.
Hardening
- External URLs from API responses (PokéAPI evolution chain, GitHub release page) are now scheme/host-validated before use.
Security Fixes
- External URLs from API responses are now scheme/host-validated before use
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About PokeTokenBar
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]