This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Topics
agentic-ai
ide
wysiwyg-editor
Affected surfaces
auth
Summary
AI summaryClaude Opus 4.7 with a 1M‑token context window becomes the default model.
Full changelog
April 17 Release
Highlights
- Claude Opus 4.7 is now the default model, with the full 1M-token context window natively supported. Opus and Sonnet 4.6 remain selectable.
- Automations — run scheduled, AI-powered tasks inside your workspace, with execution history, tracker integration, and commit-linking automations you can toggle per project
- Mobile Control — Improved layout on iOS/iPad, improved initial-sync and reconnection, and auto-open of workspaces when mobile sends prompts
Major Features
AI & Agents
- Claude Opus 4.7 with 1M-token context window as default Claude model
- Session phase badges in agent mode history panel
- Interrupt a running Claude Code session and push another session onto the stack
- Queued prompts now bundle into a single prompt instead of running sequentially
- Running tool calls show elapsed time indicator
- Renamed Nimbalyst version of
/planextension command to/designto avoid conflict - Lowered tool-search threshold to 2% for reduced context usage
- ExitPlanMode confirmation widget no longer auto-accepted
Automations
- Scheduled AI-powered tasks run against your workspace on a cron-style schedule
- Automations are stored in nimbalyst-local/automations and are just markdown files
- Automation execution history with per-run status and output
- Tracker integration: automations can create, update, and comment on tracker items
Mobile Session
- Unified iPad and iPhone session list with desktop
- Auto-open workspace when mobile sends prompts to a closed project
- iOS initial sync no longer deletes server files on first connect
- Stale draft sync echoes on iOS rejected to prevent text jumbling
- iOS transcript loading deadlock resolved
- Aligned desktop and iOS notification opt-in flow
Web Clipper Extension
- Chrome extension for clipping websites into project markdown files
Fixed
MCP
- Hardened OAuth MCP server flows to prevent unauthorized remote servers from triggering login on startup
- Remote MCP OAuth no longer prompts on startup
Editor & Files
- Cursor hijacking and sibling editor sync fixes in DocumentModel
- Editor overflow menu no longer clipped by diff header
- Tool call file edit FK violation
- Files scope dropdown stays above transcript actions
- EditorScreenshotWidget displays images correctly
- Excalidraw MCP tools no longer fail when no file is active
- Dotfiles like
.envvisible in file tree - Local images inlined as base64 in shared file links
UX Polish
- Unified shift/cmd-click selection across all session group types
- Session list shift-select range and bulk archive from context menu
- Kanban context menu archive acts on multiselected sessions
- Session input placeholder includes navigation and session mention syntax
- Account and sync settings page reflects current working state
- Persisted hidden gutter buttons; removed dead
projectStateblob - Improved Figma MCP OAuth error messaging
- Improved web clipper content extraction for JS-heavy sites
- Aligned desktop and iOS notification opt-in flow
Security Fixes
- Hardened OAuth MCP server flows to prevent unauthorized remote servers from triggering login on startup
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Track Nimbalyst open source Obsidian, Codex app, and Linear for coding agents
Get notified when new releases ship.
Sign up freeAbout Nimbalyst open source Obsidian, Codex app, and Linear for coding agents
All releases →Related context
Related tools
Featured in
Beta — feedback welcome: [email protected]