## bvisible/mcp-ssh-manager — v3.8.5…v4.0.0-beta.1

_92 commits._

### Features
- **feat(ssh): announce AI_AGENT on request, and never for a person (#84)** (93ad2e1)
- **feat(ssh): announce AI_AGENT=mcp-ssh-manager on every command channel** (c3b40c0)
- **feat(terminal): a shell on this machine, and tabs to keep several open** (0f25bd8)
- **feat(ui): the importer people can actually reach** (f4bd894)
- **feat(desktop): update itself from GitHub Releases** (efd732c)
- **feat(ui): an introduction on a first run, and a door out of the empty queue** (063d1e6)
- **feat(desktop): drop a file on the Dock icon and choose where it goes** (614a78e)
- **feat(files): wire three dead context-menu actions, and rule off Options** (80be872)
- **feat(ui): a Terminal screen, and Options in tabs** (30f22ba)
- **feat(ui): one design across the screens, Nora's orange, and a rail that starts out of the way** (53a501e)
- **feat: import servers from wherever they already are, and export them back** (12869e0)
- **feat: 4.0.0 — approval leaves the filesystem, and the app gets a menu bar** (bb9d00d)
- **feat(brand): an icon — the prompt, and the mark of what types into it** (c46c880)
- **feat: alert thresholds, a command log, and agent output rendered as a terminal** (8dc7d2b)
- **feat(ui): saved commands, Options at the bottom, and a terminal that follows the theme** (c2fcbf8)
- **feat(ui): the dark mode that was there all along** (b336f8a)
- **feat(desktop): a real application for macOS, Windows and Linux** (bfb155d)
- **feat(options): groups become editable, and can run a command across a tier** (0ee5b03)
- **feat(migration): offer the vault instead of waiting to be discovered** (da9eae5)
- **feat(vault): recovery files, and stop the vault lying about being readable** (9982da9)
- **feat(ui): move the last five screens over, and delete what they replaced** (704587e)
- **feat(ui): use TransHub's actual components, and put both filesystems side by side** (cd2cd9a)
- **feat(v4): the control plane gets TransHub's interface** (359697e)
- **feat(v4): interactive terminal — take the keyboard on any server** (cde68cd)
- **feat(v4): show open tunnels, via a published state file** (0538058)
- **feat(v4): ship three skills with the package** (81b225b)
- **feat(v4): options screen — groups and host keys; fix a shell injection found doing it** (52684d8)
- **feat(v4): server health screen, probed on demand** (ffa461c)
- **feat(v4): watch the agent work — live command streaming** (8b929f6)
- **feat(v4): native macOS desktop app around the control plane** (c0a3c1f)
- **feat(v4): manage servers from the control plane, not just the CLI** (9c7f63e)
- **feat(v4): Homebrew formula, kept current by the release workflow** (48a3dd9)
- **feat(v4): control plane — approval queue and agent timeline** (d3b9206)
- **feat(v4): human-in-the-loop approval broker** (94f30ed)
- **feat(v4): encrypted credential vault, with CLI and loader integration** (6adaad9)

### Fixes
- **fix(desktop): quitting no longer hangs while an agent is connected** (b78dd7e)
- **fix(deps): js-yaml 4.3.2 (dev), so a full npm audit is clean** (576e242)
- **fix(deps): hono 4.13.9, clearing three moderate advisories** (7ee14bb)
- **fix(cli): edit the server the menu actually selected (#83)** (0ec433a)
- **Fix cross-platform candidate builds and preserve SFTP navigation** (268e2c3)
- **Prepare isolated candidate testing and fix recovery edge cases** (92e801a)
- **fix(ui): finishing the introduction now finishes it** (cfa2eac)
- **fix(ui): one event stream for the page, not one per subscriber** (bb0ae68)
- **fix(desktop): a file dropped on a cold Dock icon is no longer lost** (ade8833)
- **fix(build): reach npm on Windows without spawning a .cmd** (2144770)
- **fix(build): the desktop build runs on Windows** (a4ded93)
- **fix(files): a file dropped on a folder now lands in it** (4a45b54)
- **fix: widen #localOp's kind so 'touch' typechecks** (d39877f)
- **fix(demo): the fake host refused every pseudo-terminal** (44977f3)
- **fix(desktop): the packaged app shipped without its dependencies** (12c2c0f)
- **fix(test): stop the command-log suite hanging forever on Linux** (8183c9c)
- **fix(ui): keep sessions mounted, or switching tabs kills the shell** (60f6faa)
- **fix: removing an absent host key is not an error** (bb256c9)
- **fix(v4): the control plane must not outlive whatever launched it** (a3c6fea)
- **fix(brew): drop the redundant 0 from shell_output** (3fa2c1b)

### Backend
- **release: the preview is 4.0.0-beta.1, and its update metadata is accepted** (d04d4e3)
- **release: 4.0.0-rc.1, a preview published on GitHub only** (2e307f7)
- **Merge remote-tracking branch 'origin/main' into codex/v4-release-readiness** (13c096e)
- **Exclude colliding desktop diagnostics from release artifacts** (e41b837)
- **Use portable ESM preload URLs in published upgrade tests** (8c79eda)
- **Validate installed Linux packages and cross-platform native terminals** (bf28747)
- **Merge main into V4 candidate preserving validated release pipeline** (659ad98)
- **Harden V4 upgrades, vault recovery, desktop releases and onboarding** (b9f49b7)

### Tests
- **test(profiles): read-then-handle instead of check-then-read** (2ccbd7e)

### Docs
- **docs: the local shell, where it lives and what it does not cost** (f2bff6b)
- **docs: regenerate every image and the video against the current interface** (328bbc4)
- **docs: write down what shipping the desktop app actually requires** (23edebc)
- **docs: drop the black stage — the hero now follows GitHub's theme** (043f020)
- **docs: put the demo inside a laptop** (ecce46f)
- **docs: describe the deploy example as deploy, not as rsync** (cbc0f58)
- **docs: rewrite the README around what the thing does, not what it has** (0d34fbd)
- **docs: record the control plane refusing a command, and put it in the README** (358035e)
- **docs: regenerate the screenshots from a reproducible demo, in both wrappers** (e0e4c90)
- **docs: the README leads with what the control plane looks like** (5015773)
- **docs: how to upgrade, and what the key not travelling means** (daa7590)
- **docs(v4): record the terminal, and correct the PTY claim** (98dbe10)
- **docs: document the v4 control plane in the README** (84344a6)

### Chore
- **chore: keep AGENT_NAME and announcesAgent private to ssh-manager.js** (a077c68)
- **build(ui): rebuild the bundled interface** (11bbe1b)
- **ci: lint the workflows, since three release runs died on what a linter finds** (97da411)
- **Fix CI workflow environment variable** — Fixed a GitHub Actions workflow error by replacing an unavailable `runner.temp` context variable in the job-level environment with the `$RUNNER_TEMP` environment variable that's available at runtime. The notarization key file path is now correctly resolved using the plain environment variable instead of a context expression that GitHub couldn't parse. (663bb88)
- **ci: $RUNNER_TEMP, because `runner` does not exist yet at job level** (935cee4)
- **Fixed macOS signing to actually run** — The macOS code signing and notarization steps were silently skipped due to environment variable conditions being checked at the wrong scope, and the notarization key was written to the wrong path. Both issues are now fixed by moving secrets to job-level environment variables and using the correct path resolver, and verification now checks all CPU architectures instead of just one. (0a49581)
- **ci: the macOS signing steps were skipping themselves** (0b79ed8)
- **Add desktop release workflow** — Added a new CI workflow that builds macOS and Windows desktop applications from tagged releases, signs and notarizes the macOS version, and attaches the built artifacts to GitHub Releases. The workflow runs manually on demand and includes a dry-run mode that builds and signs without creating a release. (3a8d2ac)
- **ci: let the desktop workflow rehearse without creating a release** (ddd6c8b)
- **chore: remove an extracted asar committed by mistake** (178ced7)
- **build: notarization works — and the DMG needed submitting on its own** (13fae04)
- **build: one command to answer "is this DMG shippable?"** (38f79c3)
- **ci: audit the formula through a throwaway local tap** (d3ba3aa)
- **ci: audit and install the Homebrew formula on a macOS runner** (0ddca25)
- **ci: run the pipeline on the v4 branch too** (df8f231)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/bvisible/mcp-ssh-manager?utm_source=github-action)._