Skip to content

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agentic-ai ide wysiwyg-editor

Affected surfaces

auth

Summary

AI summary

Claude Opus 4.7 with a 1M‑token context window becomes the default model.

Full changelog

April 17 Release

Highlights

  • Claude Opus 4.7 is now the default model, with the full 1M-token context window natively supported. Opus and Sonnet 4.6 remain selectable.
  • Automations — run scheduled, AI-powered tasks inside your workspace, with execution history, tracker integration, and commit-linking automations you can toggle per project
  • Mobile Control — Improved layout on iOS/iPad, improved initial-sync and reconnection, and auto-open of workspaces when mobile sends prompts

Major Features

AI & Agents

  • Claude Opus 4.7 with 1M-token context window as default Claude model
  • Session phase badges in agent mode history panel
  • Interrupt a running Claude Code session and push another session onto the stack
  • Queued prompts now bundle into a single prompt instead of running sequentially
  • Running tool calls show elapsed time indicator
  • Renamed Nimbalyst version of /plan extension command to /design to avoid conflict
  • Lowered tool-search threshold to 2% for reduced context usage
  • ExitPlanMode confirmation widget no longer auto-accepted

Automations

  • Scheduled AI-powered tasks run against your workspace on a cron-style schedule
  • Automations are stored in nimbalyst-local/automations and are just markdown files
  • Automation execution history with per-run status and output
  • Tracker integration: automations can create, update, and comment on tracker items

Mobile Session

  • Unified iPad and iPhone session list with desktop
  • Auto-open workspace when mobile sends prompts to a closed project
  • iOS initial sync no longer deletes server files on first connect
  • Stale draft sync echoes on iOS rejected to prevent text jumbling
  • iOS transcript loading deadlock resolved
  • Aligned desktop and iOS notification opt-in flow

Web Clipper Extension

  • Chrome extension for clipping websites into project markdown files

Fixed

MCP

  • Hardened OAuth MCP server flows to prevent unauthorized remote servers from triggering login on startup
  • Remote MCP OAuth no longer prompts on startup

Editor & Files

  • Cursor hijacking and sibling editor sync fixes in DocumentModel
  • Editor overflow menu no longer clipped by diff header
  • Tool call file edit FK violation
  • Files scope dropdown stays above transcript actions
  • EditorScreenshotWidget displays images correctly
  • Excalidraw MCP tools no longer fail when no file is active
  • Dotfiles like .env visible in file tree
  • Local images inlined as base64 in shared file links

UX Polish

  • Unified shift/cmd-click selection across all session group types
  • Session list shift-select range and bulk archive from context menu
  • Kanban context menu archive acts on multiselected sessions
  • Session input placeholder includes navigation and session mention syntax
  • Account and sync settings page reflects current working state
  • Persisted hidden gutter buttons; removed dead projectState blob
  • Improved Figma MCP OAuth error messaging
  • Improved web clipper content extraction for JS-heavy sites
  • Aligned desktop and iOS notification opt-in flow

Security Fixes

  • Hardened OAuth MCP server flows to prevent unauthorized remote servers from triggering login on startup

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Nimbalyst open source Obsidian, Codex app, and Linear for coding agents

Get notified when new releases ship.

Sign up free

About Nimbalyst open source Obsidian, Codex app, and Linear for coding agents

All releases →

Related context

Beta — feedback welcome: [email protected]