NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #3482 most downloaded on pub.dev
Cross-platform AI agent harness for Dart and Flutter: streaming provider adapters, agent loop with tools, session persistence, context compaction.
Last release today
06 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
2 months old
252 releases · first in 2026
One column per month.
ci: repin factory workflows — review-threads-resolved re-review by @IstiN in #733
Full Changelog: v0.1.433...v0.1.434
repin: factory 358eb3e — develop-done source fix by @IstiN in #728
Full Changelog: v0.1.432...v0.1.433
repin: factory a0e3a47 — machine-loop dead-end fixes by @IstiN in #725
Full Changelog: v0.1.430...v0.1.432
fix(sm): contents:write — update-branch pushes onto the head branch by @IstiN in #715
Full Changelog: v0.1.429...v0.1.430
chore: repin factory 3cae1d2 (REST mergeable_state + direct silent token) by @IstiN in #708
Full Changelog: v0.1.428...v0.1.429
fix( #687 ): repin factory 40dd6f0 (dup-guard) + pr-aware stub run-name by @IstiN in #698
Full Changelog: v0.1.427...v0.1.428
feat(agent): automatic tool-result spilling with symmetric previews by @vabhzw17eg2qu4m9-bit in #684
Full Changelog: v0.1.426...v0.1.427
fix(cli): hermetic resolveEffectiveCliArgs env + skip missing browser-ext artifact by @vabhzw17eg2qu4m9-bit in #681
Full Changelog: v0.1.425...v0.1.426
fix(agent): survive starved hidden ranges on the auto-compact continuation by @vabhzw17eg2qu4m9-bit in #677
Full Changelog: v0.1.424...v0.1.425
fix(release): annotated tag identity — empty-ident exit 128 killed mobile release assembly (run 35426119831) by @ai-teammate in #669
Full Changelog: v0.1.423...v0.1.424
ci(nightly): fix four deterministic nightly-red failures by @vabhzw17eg2qu4m9-bit in #662
Full Changelog: v0.1.422...v0.1.423
feat(622): on-device automation — mobile.* tools, store/god flavors, consent UX by @vabhzw17eg2qu4m9-bit in #659
Full Changelog: v0.1.421...v0.1.422
mobile.* automation ships as two release flavors —
store (applicationId dev.fa1.app, the Play pipeline) and god
(dev.fa1.app.god, sideload only, same release key) — with ONE CI
variable driving both the gradle flavor and the FA_FLAVOR
dart-define so the pair cannot drift. build-mobile.yml grows a
store|god APK matrix (both APKs attach to the GitHub release; the Play
AAB job is unchanged) plus a store-APK size-delta report against the
previous release artifact (UT-CI-1, +10% fail threshold) and a
disabled (if: false) emulator job pinning the shape for the six
channel ITs (IT-flavor-1, IT-floor-1, IT-observe-1, IT-gesture-1,
IT-shell-1, IT-consent-1). Tool tiers: store exposes
mobile.launch/mobile.logs (own-app deep links + launcher); god
adds mobile.hierarchy/mobile.tap/mobile.swipe/mobile.text/
mobile.screenshot (AccessibilityService + MediaProjection);
mobile.shell rides an opt-in Shizuku bridge and fails with the named
error Shizuku not running when absent. Everything is gated through
the issue #19 availability floor with the honest reason "requires the
god tier (sideload build) — get it at https://fa1.dev/android".
Binding threat model: consent screen before accessibility activation,
one-tap disable in Settings, redaction on extracted screen text,
exec-tier approval + critical patterns on mobile.shell, god never
ships to Play. Tier table, sideload + Shizuku steps, consent notes and
the manual E2E checklist: docs/android-automation.md.fix(653): stale auto-compacted marker on the busy row after the fold finishes by @vabhzw17eg2qu4m9-bit in #658
Full Changelog: v0.1.420...v0.1.421
feat: resume-timing caller attribution for full opens by @ai-teammate in #649
Full Changelog: v0.1.419...v0.1.420
fix(machine): dev runners carry targetRepository so the timer auto-save works by @IstiN in #644
Full Changelog: v0.1.418...v0.1.419
chore(factory): repin to c85468de — timer, excludes, flutter, 120-min timeout by @IstiN in #635
Full Changelog: v0.1.417...v0.1.418
fix(machine): runner path overrides — factory-agents/ layout for fa by @IstiN in #631
Full Changelog: v0.1.416...v0.1.417
feat(machine): assignment-driven trigger — assign to ai-teammate starts the loop by @IstiN in #625
Full Changelog: v0.1.415...v0.1.416
fix(620): raise password prompt PTY test waits 30s to 60s by @vabhzw17eg2qu4m9-bit in #621
Full Changelog: v0.1.414...v0.1.415
feat(machine): dmtools-agents factory rollout — ai-teammate-author gated by @IstiN in #614
Full Changelog: v0.1.413...v0.1.414
fix(611): poll pub.dev post-upload verify up to 11 min instead of failing at ~16s by @vabhzw17eg2qu4m9-bit in #612
Full Changelog: v0.1.411...v0.1.413
fix(608): sync firebase_options template public API (optionsFor) with tracked file
fix(cli): TUI scheduled countdown ticks on the minute boundary while idle ( #213 ) by @ai-teammate in #264
Full Changelog: v0.1.368...v0.1.369
fix(147): default CPU shards to Modal — the self-hosted runner has no docker by @vabhzw17eg2qu4m9-bit in #258
Full Changelog: v0.1.367...v0.1.368
fix(app): web IndexedDB session persistence — per-record keys, migration, quota isolation ( #237 ) by @vabhzw17eg2qu4m9-bit in #249
Full Changelog: v0.1.365...v0.1.366
fix(234): latch the web boot signal; e2e waits on it, not the transient splash class by @vabhzw17eg2qu4m9-bit in #242
Full Changelog: v0.1.364...v0.1.365
fix(ctx): footer meter, over-window guard and compaction share one request-size basis by @ai-teammate in #217
Full Changelog: v0.1.363...v0.1.364
fix(catalog): single-slash URL join for all release-asset fetches by @ai-teammate in #219
Full Changelog: v0.1.362...v0.1.363
fix(195): images follow-up - stale citation renumbering guard + F3/F4/F5 + config tests by @vabhzw17eg2qu4m9-bit in #205
Full Changelog: v0.1.359...v0.1.361
feat(169): declarative-only secured theme API by @vabhzw17eg2qu4m9-bit in #188
Full Changelog: v0.1.357...v0.1.358
fix(327): provider connections can no longer assemble a model from
one provider row and auth from another — the app-level guard
(restorableBootConfig + AgentService) refuses mismatched
model/auth entries up front with a ProviderConnectionException
naming the entry, and 401-style auth failures surface the entry name
([<entry>] decoration) instead of a bare provider error. The
Settings Providers section marks each saved row with a provenance
badge — [local] for entries added on this surface, [synced] for
seeds synced from the CLI (pre-provenance rows read as local) — and
the office-host-bound outlook.* family now renders as a gated
Tools row with the "available in the Outlook add-in host only"
reason on every other surface (app, relay/SW registry, CLI tools
listing) instead of staying silent. The drawer session selection
debug line prints on CHANGE only (issue #327 AC6: the 3 s idle poll
no longer spams 20 identical lines per minute).
docs/tool-availability.md documents the outlook family row.
fix(259): sleep-resilient scheduled wake-ups for schedule_message.
All due-time math in ScheduledMessageQueue now rides an injectable
wall clock (clock:), long waits are split into ≤60s timer legs that
recompute the remaining delay from the wall clock on every fire (no
duration-drift accumulation across OS sleep), and both hosts run a
wall-clock catch-up sweep at every turn start (CLI _beginUserPrompt,
app sendText) on top of the existing idle inbox-tick sweeps — the
first post-sleep turn delivers every overdue record immediately.
Catch-up is exactly-once per record (no replay of missed cycles);
recurring self-re-arming cycles resume from "now" after a clock jump.
Docs (AGENTS.md messaging section) describe an optional external
cron/launchd pinger for delivery during lid sleep.
feat(287): compaction 2.0 is the DEFAULT — every resolution point now
falls back to the structured engine (judge-hide → checkpoint + expand,
#148) instead of the classic lossy prefix summary: the core resolver
(resolveCompactionEngine), the AutoCompactorFactory default, the
CLI compaction host (config.compactionEngine ?? structured), the
/settings summary line, and the app's per-compaction resolution.
Classic 1.0 stays fully supported as the in-settings rollback — an
explicit compaction.engine: classic (user or project yaml) or
--compaction-engine classic is always honored, never rewritten.
Migration: users without a compaction: section get structured on
upgrade; nothing is rewritten on read. The app's Settings gained a
Compaction section (issue #287): an engine picker — Structured
(recommended) / Classic (legacy 1.0) — with honest one-line tradeoffs
(structured: hidden-in-place + expandable, requires a configured
model for the judge pass; classic: lossy summary, zero extra calls),
the effective engine plus its source layer (project .fah/config.yaml
user
~/.fah/config.yaml> structured default), a docs link, and writes that go through the core config service (surgical line edits validated before persisting — unrelated comments survive byte-for-byte). The choice applies at the next compaction (the per-compaction re-resolution, no restart needed). On the web there is no config yaml: the picker renders disabled with a note and the structured default applies. The CLI/settingssummary mirrors the default in itscompaction:line.
fix(hub): boot online from the persisted DAP credential — with no
DAP_MASTER_SECRET/DAP_CLIENT_SECRET in the environment, the CLI now
seeds the hub kill switch from ~/.dap/config.json clientSecret
(the explicit prior opt-in from /dap start), restoring the documented
"the next boot is online by itself" behavior: hub mail delivery and
hub peers in agent_directory (the browser extension, embedded hosts)
work on a fresh boot. The fabric gate also reads the mutable
environment overlay the plugin actually uses, not the read-only
process environment.
fix(195): images follow-up from the #190 review. F2: a stale
[Image N] citation in history no longer silently rebinds to the
WRONG image after compaction renumbering — once a renumbering boundary
(compaction summary, structured marker, local-trim note) exists in the
window, authored history citations degrade to the
(image no longer available) note while generated content-keyed refs,
carrier labels and the current message stay intact. F3: the current
message's in-place images now carry their [Image N] label so the
model can cite what it sees. F4: the app logs per-request cap drops
through AppLog (logs/app.log) instead of silently dropping. F5:
estimateContextTokens charges repeated images at the wire-replacement
cost (first occurrence full, repeats ~32 chars), fixing the
transcript-vs-wire estimation asymmetry; per-message estimateTokens
is unchanged. F1: the images: config section gained the previously
claimed tests — CLI parse/round-trip/strictness (bad bools, unknown
keys, non-positive ints, malformed sections) and the config-service
validator dispatch pin.
feat(169): declarative-only secured theme API — theme packs
(theme.json + optional wallpaper image in a .zip; strict schema
validation with unknown-key rejection, path-traversal/symlink/size
screens, WCAG contrast warnings), a Settings section to import, switch
and remove packs (a colors-only apply keeps the current wallpaper;
removing the active pack reverts atomically), wallpaper layers in the
chat, apps grid and launcher screens, and the jsr.fa.theme bridge —
list/current/apply behind the theme permission with a consent
dialog per apply. Apps can never install or delete packs (no such API
exists; pinned by a byte-scan test).
chore(flutter): raise the Flutter floor to 3.47 (>=3.47.0) across
flutter_app, packages/fa_ui, packages/fa_llm_flutter and
yoclip; drop the meta: 1.18.0 dependency overrides (the 3.47 SDK
declares meta ^1.18.3, so 1.19.0 resolves for dart_tui without an
override); regenerate the flutter_app goldens for the 3.47.4
rendering (text/geometry drift only); clean up new-SDK lints in two
config tests; ios Podfile now forces the iOS 16 deployment floor on
pod TARGET-level build configs too (podspec-declared 15.0 targets
broke the build against 16.0-only Promises under the newer toolchain).
chore(deps): js_widget_runtime ^0.4.121 — typed fallback hardening
for legacy manifest keys, widget manifest i18n compatibility, and the
JSR video onError bridge.
feat(155): backend agent mode — fah as a server-side agent engine for a Go supervisor. --output events[=full] switches stdout to a HEP v1 JSONL stream
fah as a server-side agent engine
for a Go supervisor. --output events[=full] switches stdout to a HEP
v1 JSONL stream (header + agent_start/turn lifecycle frames, message
and tool deltas, usage passthrough in turn_done; events=full also
caps tool args at 4000 chars instead of the 100-char summary);
prose mode is untouched. --attach <path> (repeatable) reads image
files, sniffs the type from magic bytes, and rides them as base64
data-URI image blocks on the first user message. SIGTERM (and SIGINT)
in headless mode now abort the run gracefully — partial transcript
persists (persistAbortedPartials), a cancelled frame closes the
HEP stream, stdout is flushed, exit code 130; a second SIGTERM forces
exit 143. An unknown --session key on a clean root starts a fresh
session instead of failing. --version --output json prints
{"version":…,"hep":"v1"}. (Per-request [Image N] image dedup was
also prototyped here and is superseded by the session image registry
from #190, which this change adopts instead.)ci(177): PR-level CI speed restructure — a pull request now pays only for what it touched. Path-aware gating (changes job), the sequential "Quality ga
changes job), the sequential
"Quality gates" monolith split into parallel jobs (static, test-core
×3 duration-balanced shards with merged coverage, coverage-gate,
guards, flutter-tests on ubuntu), pub/flutter caching everywhere,
concurrency cancel-in-progress on all PR workflows, and one aggregate
Quality gate required check. PRs ratchet coverage on CHANGED lines
(scripts/diff_coverage.py); main/tags/nightly keep the full 80%
ratchet. The pre-commit hook is now a thin wrapper over the SAME
scripts/ci_fast_gate.sh CI runs, with the same path filters.nightly.yml) — the original
monolith gates + the PTY/CLI integration suites (never gated on PRs
before; live-provider tests self-skip without keys) + the terminal-visual
screenshot suite (never ran in CI at all) — with a deduped nightly-red
auto-issue. packages/fa_ui non-golden tests join CI for the first time.coverage-gardener.yml re-measures PTY-suite coverage of
lib/src/cli/** and commits the higher baseline;
scripts/check_cli_coverage.py enforces it nightly (ratchet only up).scripts/test_shards.json +
scripts/rebalance_shards.py (junit timing or file-count fallback),
rebalanced weekly by shard-rebalance.yml.docs(144): KB — real Outlook add-in installation guide
feat(148): structured compaction engine — context hiding that is structured, addressable, and expandable. New branch records hidden_range / compact_ch
hidden_range / compact_checkpoint store hide/cover state keyed by
stable record ids (append-only; classic compaction's lossy summary is
untouched); the context projection replaces hidden records with one-line
markers (≤12 tokens each) at their original positions, hides tool pairs
atomically so the wire stays valid for both provider shapes, and keeps a
stable numeric alias per record (1-based JSONL line number — the
zero-tool fallback resolves to the same bytes). The two-pass engine
(lib/src/compaction/structured/) hides first via a cheap judge over
the context ledger and checkpoints only when hiding is insufficient
(nested checkpoints flatten at depth cap). The compact_expand tool
restores any id/range on demand under a per-turn token budget with
paging; the agent loop resets the budget per user turn. Engine choice:
compaction.engine: classic|structured in config (strict parse),
resolved session < project < global, default classic; CLI host flag and
settings entry included, the Flutter app honors the same chain through
loadAppCompactionEngine (config parity, no new settings screen).
Trajectory ledger folds both record kinds as collapsible compacted
rows. Fixes #148.ci(159): content=none dispatch of build-mobile.yml ends green (clean release no-op) by @vabhzw17eg2qu4m9-bit in #162
Full Changelog: v0.1.352...v0.1.353
DAP slash-flow + CodeMie SSO expiry detection & auto re-auth (extension/app/CLI) by @ai-teammate in #145
Full Changelog: v0.1.350...v0.1.352
docs(144): real Outlook add-in installation guide by @vabhzw17eg2qu4m9-bit in #149
Full Changelog: v0.1.348...v0.1.349
ci(browser-ext): placeholder .env for the dispatch-only panel-app build by @ai-teammate in #136
Full Changelog: v0.1.344...v0.1.346
fix(compaction): the summarizer-down local-trim valve no longer wedges the session — a token-boundary cut could land between an assistant tool call an
fix(messaging): scheduled self-reminders actually arrive — 'self' was never resolved to the agent's mailbox, so schedule_message fired on time and the
<root>/self inbox; start() now migrates
the stranded legacy mail into the real mailbox. Cross-mailbox from
attribution fixed; parseDelay ms/fractional units fixed ('90ms' was 90 s).refactor(cli): move trajectory view additions out of agent_cli (file size guard)
fix(cli): skill autocomplete for partial skill names — typing /goal or /skill:goal in the TUI composer now offers /create-goal (the raw-prefix match b
/skill:<name> form.fix(roles): provider watchdog timeouts ("TimeoutException after 0:03:00: Future not completed", "request timed out") classify as transient transport f
fix(widgets): unique router instanceId per engine — frozen tiles and dead buttons
ci: workflow_dispatch for ci.yml — manual gates when pull_request can't fire
Full Changelog : v0.1.304...v0.1.305
Full Changelog: v0.1.304...v0.1.305
Full Changelog : v0.1.303...v0.1.304
Full Changelog: v0.1.303...v0.1.304
test/integration/redaction_e2e_test.dart;
the file now builds the same byte-identical string from chunks.agent_message to an asleep target launches a detached headless run of
that session so pending mail is processed immediately (wake: false opts
out).Full Changelog : v0.1.300...v0.1.301
Full Changelog: v0.1.300...v0.1.301
Full Changelog : v0.1.299...v0.1.300
Full Changelog: v0.1.299...v0.1.300
feat(browser): fa in the browser — Chrome MV3 extension with full site control, loopback bridge, DAP, CDP (issue #23 ) by @vabhzw17eg2qu4m9-bit in #26
Full Changelog: v0.1.298...v0.1.299
browser_ext/ (Chrome
MV3) pairs a local fa with the browser over a loopback WebSocket bridge
(fa serve --bridge [--port N] [--token T], /browser connect|status):
wire protocol v1 client (hello/welcome, 1s→30s reconnect backoff,
offline outbox, msgId dedupe, ping keepalive), one-time 32-byte pairing
tokens (.fah/bridge/token, mode 0600, rotated by every connect,
constant-time compare, non-chrome-extension:// origins refused, AC15),
two-way mail relay over the file messaging fabric
(browser-ext/<agentId> mailboxes). Eleven browser_* tools over the
bridge (navigate/tabs/switch_tab/click/type/press_key/select/read_dom/
eval/screenshot/wait_for, exec tier, availability-gated under the
browser + browser_eval ids — hidden until an extension pairs,
docs/tool-availability.md). Two control planes: quiet content-script DOM
ops by default, per-call trusted: true chrome.debugger path (E23
denied when DevTools owns the tab, any-tab screenshots via
Page.captureScreenshot, AC16) with the debugging infobar as the honesty
signal; task tab groups (fa — <task>) close agent-opened tabs on
task_end or bridge disconnect (AC17). Self-contained mode: dart2js build
of browser_ext/dart/ (scripts/build_browser_ext.sh → sw/agent.js +
build/fa-extension.zip) runs the agent core inside the service worker —
panel provider form (OpenAI-compatible endpoints; deterministic fake:
provider for tests), approval banner (30s timeout = deny), JSONL session
shellUnavailable), keys read
only inside the SW (AC8). The embedded agent joins the DAP hub with an
E2E-encrypted CLI-compatible identity (faDapKey): dap_peers/dap_dm
tools, one mail deduper across bridge + hub links (AC18). Headless CI:
test/browser_ext/ (real Chrome via --load-extension,
--headless=new; integration-tagged) in .github/workflows/ browser-ext.yml; unit layers dart test test/browser/,
browser_ext/dart dart test, node --test browser_ext/test/. Docs:
docs/browser-extension.md.Full Changelog : v0.1.297...v0.1.298
Full Changelog: v0.1.297...v0.1.298
Full Changelog : v0.1.296...v0.1.297
Full Changelog: v0.1.296...v0.1.297
AnsiMarkdown.inlineFormatMaxChars) —
degenerate spans render verbatim, fences/rules/tables unchanged.
Regression-tested by the new tool/thinking_lag_probe.dart PTY probe
(burst streams: keypress echo p95 stays under budget) and a markdown
unit test.Full Changelog : v0.1.295...v0.1.296
Full Changelog: v0.1.295...v0.1.296
gh API call) are retried up to 2 times (3 attempts
total) with a 1s backoff before the error surfaces. Retries are visible
as [bash attempt N/3 ... — retrying] notices in the tool output, and
the final error carries them too. Aborts and real command failures
(non-zero exit, exec errors, shell unavailable) are never retried.Firebase.initializeApp threw an unhandled [core/duplicate-app] that
killed main() before the first frame. The duplicate-app case now reuses
the natively configured app.docs: fa1.dev is now referenced from the README (website + live web demo + iOS beta + installer) and from homepage in pubspec.yaml, so the link render
homepage in pubspec.yaml, so
the link renders on pub.dev next to the package name.feat(redact): layered secret redaction pipeline (issue #24) — ten pure layers (registered/path/vendor/prefix/pem/asn1/connection/context/ entropy/pii)
RedactionPipeline.scan/redact
with idempotent [REDACTED:<kind>] markers, allowlist + data-URL
pass-through, live RedactionConfig, and per-layer/per-tool stats.
Agent hooks mask tool results BEFORE session persist, mask the outgoing
context, deny credential-file read/bash in blockMode, and mask user
prompts; write-side tools (write/edit/checkpoint/MCP write-ish) are
never filtered. redact: config section, /redact command, app wiring,
docs/redaction.md.integration — the real-PTY +
dart run cold start intermittently exceeded the gate timeouts on CI,
which had been silently blocking every tag publish since ~0.1.214.Full Changelog : v0.1.212...v0.1.213
Full Changelog: v0.1.212...v0.1.213
Full Changelog : v0.1.211...v0.1.212
Full Changelog: v0.1.211...v0.1.212
Full Changelog : v0.1.210...v0.1.211
Full Changelog: v0.1.210...v0.1.211
Full Changelog : v0.1.208...v0.1.210
Full Changelog: v0.1.208...v0.1.210
Full Changelog : v0.1.207...v0.1.208
Full Changelog: v0.1.207...v0.1.208
Your coding agent can read these notes before it upgrades. Set up the MCP server →