This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Summary
AI summaryFirst public Developer ID‑signed, Apple‑notarized Velora release with improved first‑run onboarding.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
App and DMG use Developer ID signing with hardened runtime. App and DMG use Developer ID signing with hardened runtime. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Apple notarization is stapled to the DMG and verified before publication. Apple notarization is stapled to the DMG and verified before publication. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Gatekeeper accepts both the DMG and bundled app as Notarized Developer ID. Gatekeeper accepts both the DMG and bundled app as Notarized Developer ID. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Try It field stays locked during one‑time speech and writing model setup. Try It field stays locked during one‑time speech and writing model setup. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Feature | Low |
Onboarding displays current setup phase and download percentage. Onboarding displays current setup phase and download percentage. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Medium |
Prevents first dictation failure when models are still initializing. Prevents first dictation failure when models are still initializing. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Medium |
Ensures progress and completion remain correct across engine reconnects. Ensures progress and completion remain correct across engine reconnects. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Falls back to raw dictation if the optional writing model cannot load. Falls back to raw dictation if the optional writing model cannot load. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
Full changelog
Velora 0.4.3 is the first public Developer ID-signed and Apple-notarized release. Drag it to Applications and open it normally; no Gatekeeper bypass is needed.
First-run setup
- The Try It field stays locked while the speech and writing models complete their one-time setup.
- Onboarding shows the current setup phase and download percentage instead of letting a first dictation fail mysteriously.
- Progress and completion remain correct across engine reconnects.
- If the optional writing model cannot load, Velora falls back to raw dictation instead of trapping onboarding.
Distribution
- The app and DMG use Developer ID signing and hardened runtime.
- Apple notarization is stapled to the DMG and verified before publication.
- Gatekeeper accepts both the disk image and bundled app as Notarized Developer ID.
Verified with 55 Swift self-checks and 198 Python tests.
SHA-256: 2cf998df0d728cfe4ceae9b6f88196ed90794b0a451b14683ac3087350fe0de8
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Velora
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]