Skip to content
CAI
Software that uses CAICheck a score

BloopAI/vibe-kanban

45.1

Weak · 27 September 2026

196.5k

lines of production code

TypeScript

with Rust

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Vibe Kanban is a desktop and web application that integrates AI coding agents with project management and remote development workflows. It enables users to manage issues via a Kanban board, execute code through various AI executors with human-in-the-loop approval, and connect to remote workspaces via a secure relay tunnel. The system supports multi-repository projects, file attachments, and automated code reviews, packaged as a cross-platform desktop app with native notifications and local execution capabilities.

How it got here

2025 — Vibe Kanban rebrand and infrastructure overhaul

40 changes.

The project rebranded from Bloop to Vibe Kanban, restructuring the codebase into a monorepo with a Rust backend and Tauri desktop client. This period focused on establishing core infrastructure, including a new SQLite database schema, automated type generation, and a unified executor framework for various coding agents. It also introduced remote services for authentication, billing, and GitHub App integration, alongside an npx-based launcher for the desktop application.

2026 — Desktop app and remote tunneling infrastructure

31 changes.

This period focused on establishing the Tauri desktop application with native features like notifications and auto-updates, while simultaneously building the core relay tunneling infrastructure to enable direct WebRTC connections and remote SSH access. Parallel efforts expanded the web application's capabilities through a new shared UI library, enhanced workspace chat interactions, and improved Kanban board functionality.

Features

Add Azure DevOps and GitHub CLI-based git hosting support

The \crates/git-host\ module now provides a unified interface for managing pull requests on GitHub and Azure DevOps repositories. It introduces \GitHubProvider\ and \AzureDevOpsProvider\ implementations that interact with the \gh\ and \az\ CLIs respectively, handling operations such as creating pull requests, fetching PR status, and retrieving comments. A new \detect\_provider\_from\_url\ function automatically routes requests to the correct provider based on the repository URL, and the \GitHostService\ enum dispatches calls to the appropriate implementation.

crates/git-host · high confidence

Added Android adaptive icon and splash screen assets

The application now includes specific assets for the Android platform: an adaptive icon configuration (defining foreground and background resources) and a splash screen HTML page featuring a loading spinner that respects the system's dark mode preference.

crates/tauri-app/icons, crates/tauri-app/splash · high confidence

Added DiffChangeKind type definition

A new TypeScript type \DiffChangeKind\ has been added to the bindings, defining the possible states for file changes as 'added', 'deleted', 'modified', 'renamed', 'copied', or 'permissionChange'. This type is generated by ts-rs and provides a structured representation of diff change kinds for consumers of the bindings.

crates/utils/bindings · high confidence

Added Tauri-specific hooks for notification navigation and update handling

This change introduces two new React hooks in the local-web application to support the Tauri desktop environment. The \useTauriNotificationNavigation\ hook listens for OS notification click events and navigates the user to the corresponding deep link path within the app. The \useTauriUpdateReady\ hook monitors for completed background updates, updates the application state to reflect the new version, and triggers an app restart when necessary. These hooks ensure that desktop-specific features like notification interaction and seamless auto-updates function correctly for users on Windows, macOS, and Linux.

packages/local-web/src/app/hooks · high confidence

Added Windows toast notification capability

A new PowerShell script (toast-notification.ps1) has been added to the assets, enabling the application to display native Windows toast notifications. This script accepts a title, message, and optional application name (defaulting to 'Vibe Kanban') to construct and show a system-level notification, providing a new channel for user alerts on Windows platforms.

assets · high confidence

Added dark and light mode icons for AI agents

The \packages/public/agents\ directory now includes SVG icon assets for Amp, Claude, Codex, Copilot, Cursor, Droid, Gemini, OpenCode, and Qwen. Each agent is represented by a pair of icons (dark and light variants) to ensure proper visibility across different theme settings.

packages/public · high confidence

Added default development configuration and empty database seed

A new configuration file (config.json) has been added to the dev\_assets\_seed directory, establishing default settings for the application environment. This includes a light theme, Claude as the executor type, enabled sound alerts and push notifications, VS Code as the default editor, and GitHub integration settings with an empty token and 'main' as the default PR base. Additionally, an empty SQLite database file (dev.db) has been included to provide a clean initial state for development.

_dev\_assets\seed · high confidence

Added local database preparation script for SQLx cache management

A new \prepare-db.sh\ script has been added to the remote crate to facilitate local development and CI checks. This script manages a temporary PostgreSQL instance to run migrations and generate SQLx offline data caches for the remote crate, the billing module, and the relay-tunnel crate. It supports a \--check\ mode for verifying SQLx data without a running database, ensuring type safety and migration consistency during development.

crates/remote/scripts · high confidence

Codex executor adopts App Server protocol with slash commands and review capabilities

The Codex executor now communicates with the Codex App Server via a new JSON-RPC client, enabling advanced features such as slash commands (including /init to generate repository guidelines, /compact to manage sessions, /status, /mcp, and /fast mode toggles) and session-level code reviews. This change introduces a dedicated approval service integration for command and file changes, normalizes execution logs into a structured format for better UI display, and supports plan mode and collaboration settings. Users benefit from a more interactive and structured Codex experience with explicit control over session management, review workflows, and execution modes.

crates/executors/src/executors/codex · high confidence

Desktop bridge for remote IDE integration

The new \desktop-bridge\ crate enables opening remote workspaces directly in local desktop editors (VS Code, Zed, Cursor, Windsurf, and Google Antigravity). It provisions Ed25519 SSH keys, updates the local SSH config to route through the established relay tunnel, and generates the correct deep-link URLs for the selected editor.

(repo-wide) · high confidence

Embedded SSH server with SFTP and loopback forwarding

The \embedded-ssh\ crate introduces an embedded SSH server that authenticates users via Ed25519 public keys derived from the relay signing service. It supports interactive shell sessions over stdio and the SFTP subsystem, enabling file browsing and editing in tools like VS Code Remote SSH. The server also implements TCP/IP forwarding for loopback addresses (localhost, 127.0.0.1, ::1), allowing clients to forward local ports through the relay. This functionality is supported by new types in \relay-types\ for managing relay hosts and sessions, and \remote-info\ for storing API endpoint configurations.

crates/embedded-ssh, crates/relay-types, crates/remote-info · high confidence

Initial setup of local web router, virtual executor schemas, and inspect mode store

This change introduces the foundational structure for the local web application and its core state management. It adds a TanStack Router configuration to handle routing via a generated tree, defines TypeScript declarations for virtual executor schemas to support coding agent interfaces, and implements a Zustand store for managing inspect mode state and pending component markdown within the workspace chat feature.

packages/local-web/src/app/router, packages/local-web/src/shared, packages/web-core/src/features/workspace-chat/model/store · high confidence

Initialize local-web app entry point with Tauri-specific features and error handling

The local-web application now has a dedicated entry point that bootstraps the React app with Tauri desktop integrations, including custom font-size-based zoom controls (Cmd/Ctrl + +/-/0) and system notification navigation. It wraps the application in providers for runtime configuration, local authentication, hotkeys, and analytics (PostHog), while integrating Sentry for error boundary monitoring with a dedicated crash screen fallback.

packages/local-web/src/app/entry · high confidence

Introduce Amp coding agent executor

The Amp executor is now available as a coding agent, allowing users to run the @sourcegraph/amp CLI. It supports a 'dangerously\_allow\_all' configuration option to bypass safety checks, uses the Claude log processor for its JSON stream output, and discovers its MCP configuration from \~/.config/amp/settings.json.

crates/executors/src/executors · high confidence

Introduce GitHub App integration for webhook-triggered PR reviews

Added a new GitHub App service in the remote crate that enables webhook-triggered code reviews. This includes JWT generation for GitHub App authentication, webhook signature verification, and a PR review service that clones repositories, calculates merge-bases for accurate diffs, creates non-blocking tar archives, uploads them to R2, and starts review workers.

_crates/remote/src/github\app · high confidence

Introduce Vibe Kanban MCP server with orchestrator mode and issue management tools

The \crates/mcp\ crate now includes a new \vibe-kanban-mcp\ binary that launches an MCP server in either 'global' or 'orchestrator' mode, determined by the \--mode\ argument. In orchestrator mode, the server automatically discovers its session context and restricts available tools to the configured workspace and session. This release adds new tools for managing issue assignees (\assign\_issue\, \unassign\_issue\), issue relationships (\create\_issue\_relationship\, \delete\_issue\_relationship\), and issue tags (\add\_issue\_tag\, \remove\_issue\_tag\), alongside existing capabilities for listing issues, managing workspaces, and handling repository scripts.

crates/mcp · high confidence

Introduce local deployment crate with integrated terminal and workspace management

The new \crates/local-deployment\ crate provides the local runtime environment, introducing an integrated terminal with a PTY backend (using \portable\_pty\) that supports interactive shells like bash, zsh, and PowerShell. It also includes a \WorkspaceManager\ for handling worktree creation and repository attachment, a \LocalContainerService\ for executing coding agents, and a \copy\ utility for glob-based file copying. Additionally, a \build.rs\ script ensures the \VK\_SHARED\_API\_BASE\ environment variable is correctly propagated to the application at compile time.

crates/local-deployment · high confidence

Introduce npx-based launcher for Vibe Kanban desktop app

Users can now run Vibe Kanban instantly via \npx vibe-kanban\ without prior installation. This new CLI entry point automatically detects the user's operating system (Linux, Windows, or macOS) and processor architecture (x64 or ARM64), downloads the corresponding Tauri desktop bundle from the release server, caches it locally, and launches the application. The launcher supports subcommands like \--help\, \--version\, \review\, and \mcp\, and handles platform-specific installation details such as macOS App Bundle placement and Linux AppImage execution.

npx-cli · high confidence

Introduce preview proxy with developer tooling and security hardening

A new preview proxy service has been added to isolate preview content from the main application. The proxy forwards HTTP and WebSocket requests to local upstream servers while stripping hop-by-hop and relay-specific signing headers (x-vk-relayed, x-vk-sig-\*) to prevent the preview target from rejecting requests. It also injects developer tooling scripts—including a React DevTools hook (bippy), a click-to-component inspector, navigation state tracking, and an Eruda console—into previewed HTML responses to aid debugging.

crates/preview-proxy · high confidence

Introduce relay-tunnel server for host-based remote access

The relay-tunnel crate now includes a new server binary that enables remote access to local hosts via a relay proxy. The server authenticates users using JWT access tokens and validates access to specific hosts using database-backed session and identity checks. It manages host registration and online status, maintains an in-memory registry of active relay connections, and proxies browser traffic over WebSocket control channels to local machines.

crates/relay-tunnel/src · high confidence

Introduce relay-tunnel-core for WebSocket-based relay tunneling

This change adds the \relay-tunnel-core\ crate, which implements the core logic for a relay tunneling feature. It provides a client that establishes a WebSocket control channel to proxy HTTP requests to a local address, and a server component that accepts WebSocket connections and proxies requests over Yamux streams. The implementation includes a Yamux configuration that increases the stream window size to 1 MB and the write timeout to 30 seconds to prevent failures on slow connections. Additionally, it adds a TLS connector that accepts all certificates in debug builds to support development environments while maintaining standard validation in release builds.

crates/relay-tunnel-core · high confidence

Introduce remote code review feature

The review crate now provides a CLI tool that allows users to submit a GitHub pull request URL for remote analysis. The tool clones the repository, optionally attaches context from local Claude Code sessions, and uploads the code to the Vibe-Kanban API (api.vibekanban.com) for AI-driven review. It handles GitHub CLI integration with fallbacks for older versions, manages user configuration (such as saved email addresses), and displays progress via a terminal spinner.

crates/review · high confidence

Introduce structured normalized log entry types and streaming processors

The executor logs module now defines a comprehensive set of data structures for normalizing conversation history and tool interactions, including \NormalizedConversation\, \NormalizedEntry\, and specific entry types like \ToolUse\, \UserMessage\, \AssistantMessage\, \ErrorMessage\, and \NextAction\. This enables the UI to display richer context, such as tool call arguments, results, and manual approval statuses. Additionally, new streaming processors (\PlainTextLogProcessor\ and \stderr\_processor\) have been added to handle mixed-format log streams, cluster messages by time or size, and emit structured JSON patches for real-time UI updates.

crates/executors/src/logs · high confidence

Introduction of SQLite database service with platform-specific migration handling

The \crates/db/src/lib.rs\ module introduces a new \DBService\ for managing SQLite connections and migrations. It configures the database pool to use the \Delete\ journal mode and automatically handles migration checksum mismatches on Windows by updating stored checksums, while strictly failing on other platforms to ensure data integrity.

crates/db/src · high confidence

Introduction of the Deployment trait and error types

The \crates/deployment\ crate now provides a central \Deployment\ trait that aggregates access to core services such as container management, Git operations, file handling, event streaming, and relay control. This trait also includes utility methods for updating Sentry scopes, tracking analytics events, and managing user authentication context, establishing a unified interface for deployment-related operations.

crates/deployment · high confidence

Kanban board gains multi-select bulk actions and a 'Hide blocked' filter

The Kanban board now supports multi-selecting issues to perform bulk operations, including changing status, priority, assignees, or deleting them via the new BulkActionBar. Additionally, a 'Hide blocked' toggle has been added to the filter bar, allowing users to exclude issues that are blocked by unresolved parent issues from the view. The underlying filtering logic also now supports searching by issue short ID and number alongside the title.

packages/web-core/src/features/kanban · high confidence

Native system notifications for Vibe Kanban on desktop

Users on desktop platforms (Windows, macOS, Linux) now receive native operating system notifications for new Vibe Kanban updates. This change introduces a new \AppSystemNotifications\ component that monitors notification groups and, when running within the Tauri desktop app, invokes the native \show\_system\_notification\ command to display alerts with titles, bodies, and deep links to the relevant content.

packages/local-web/src/app/notifications · high confidence

New API type definitions for attachments, notifications, and issue relationships

The \crates/api-types\ crate now defines the core data structures for the application's API, introducing support for new capabilities. Users can now attach files to issues and comments via the new \Attachment\ and \Blob\ types, which include presigned URL generation for secure file access. The system now supports in-app notifications, with types for \Notification\ and \NotificationPayload\ covering events like status changes, comments, and reactions. Additionally, issues can now be linked through explicit relationships (e.g., Blocking, Related) via the \IssueRelationship\ type, and authentication sessions have been enhanced with refresh token grace windows in the \AuthSession\ type.

crates/api-types · high confidence

New Claude Code executor with approval and slash command support

This change introduces a new executor for Claude Code located in \crates/executors/src/executors/claude\. It implements a bidirectional control protocol (\protocol.rs\) to manage tool usage permissions and hook callbacks, allowing the application to approve, deny, or interrupt tool actions via an approval service (\client.rs\). The executor also supports discovering and executing slash commands and skills from project, global, and plugin directories (\slash\_commands.rs\), and defines the necessary type structures for the control protocol and permissions (\types.rs\).

crates/executors/src/executors/claude · high confidence

New application context providers for theming, configuration, and element interaction

The application now includes three new provider components in the local web package to manage core state. The ThemeProvider allows users to switch between light, dark, and system-default color schemes, applying the selection to the document root. The ConfigProvider handles user system configuration, including syncing the application language and managing authentication recovery states. Additionally, the ClickedElementsProvider introduces a context for tracking and deduplicating clicked UI elements, supporting features like opening files in an editor with path normalization for different operating systems.

packages/local-web/src/app/providers · high confidence

New build, CI, and migration tooling scripts

This change introduces a suite of new scripts to support the project's evolving build and development workflows. It adds build automation for the Tauri desktop app, including MSI packaging for Windows and manifest generation for auto-updates across macOS, Linux, and Windows. A new script bundles the 'bippy' library for injection into proxied HTML pages. To support a frontend structure migration, it includes scripts to check for legacy path violations, rewrite import paths, and migrate the remote-web package layout. Additionally, it adds CI and developer tooling for i18n consistency checks, unused key detection, SQLx database preparation, and a wrapper for the 'ring' crate's build process.

scripts · high confidence

New database models for execution processes, agent turns, and attachments

The database layer now includes new models to support detailed tracking of coding agent interactions and file attachments. \ExecutionProcess\ and \ExecutionProcessRepoState\ track the lifecycle, status, and repository context of background tasks (such as setup scripts, coding agents, and dev servers), including commit state changes. \CodingAgentTurn\ records individual agent prompts, summaries, and session IDs to enable follow-up conversations and session resumption. \File\ and \WorkspaceAttachment\ models manage uploaded files and their association with workspaces, supporting deduplication via SHA256 hashes. Additionally, \Merge\ and \PullRequest\ models provide unified tracking of direct merges and PR merges, while \Project\ and \Repo\ models expose configuration options like default working directories and custom scripts.

crates/db/src/models · high confidence

New database repositories for attachments, blobs, auth sessions, and organization management

The remote service now includes a comprehensive set of new database repositories in \crates/remote/src/db\ to support core product features. This adds persistent storage and retrieval for file attachments and blobs (including thumbnails and metadata), secure authentication session management with refresh token rotation and reuse detection, and full lifecycle management for organizations, including invitations, member roles, and GitHub App installations. Additionally, it introduces repositories for issue assignees, comment reactions, notification digests, and data export, enabling users to manage project content, collaborate via comments and reactions, receive digest notifications, and export project data.

crates/remote/src/db · high confidence

New executor configuration, approval, and environment management modules

The executors crate now includes dedicated modules for managing executor profiles, command building, environment injection, and approval workflows. Users can now configure executors with model, agent, and reasoning overrides via the new ExecutorConfig and CmdOverrides structures, while environment variables and repository context are handled through ExecutionEnv and RepoContext. Command execution is now built via a robust CommandBuilder that supports base command overrides, parameter extension, and cross-platform shell parsing. Approval workflows for tools and questions are abstracted through the ExecutorApprovalService trait, allowing for supervised or automated execution modes. Additionally, MCP configuration reading and writing now supports JSONC with comment preservation, and executor discovery exposes model selectors, slash commands, and loading states.

crates/executors/src · high confidence

New project export feature and workspace creation mode

Users can now export project data (including optional attachments) via a new dedicated page that lets them select organizations and projects and download a zip file. Additionally, a new 'create mode' has been introduced to streamline workspace creation, allowing users to pre-select repositories, target branches, linked issues, and executor configurations, with state persisted in scratch storage and bootstrapped from drafts or seeds.

packages/web-core · high confidence

New remote API routes for attachments, billing, GitHub App integration, and data export

The remote service now exposes a comprehensive set of new HTTP endpoints for managing attachments (init, confirm, and commit uploads with Azure Blob storage and thumbnail generation), billing (Stripe webhook handling, portal sessions, and checkout), GitHub App integration (installation, status, repository review toggling, and PR review triggering), and data export (generating zipped CSVs of issues, users, and statuses). It also introduces routes for listing relay hosts, fetching user identity, and proxying Electric shape queries, alongside standard CRUD routes for issue assignees, comments, and comment reactions.

crates/remote/src/routes · high confidence

New remote authentication service with OAuth handoffs and local login

The remote crate now includes a complete authentication module (\crates/remote/src/auth\) that supports both local credential login and OAuth provider handoffs (GitHub, Google). This introduces a new \OAuthHandoffService\ for managing secure, time-limited authorization flows, a \JwtService\ for generating short-lived access tokens and long-lived refresh tokens, and a \require\_session\ middleware to validate requests and enforce session inactivity timeouts. The implementation also features an \OAuthTokenValidator\ that periodically checks provider token validity and automatically revokes all user sessions if a provider token is found to be invalid or revoked.

crates/remote/src/auth · high confidence

New remote server infrastructure with analytics, audit logging, and background tasks

The remote server crate now includes a new analytics service that sends events to PostHog when configured via environment variables, a structured audit logging system that emits security-relevant events (auth, member management) to the tracing log, and background tasks for periodic cleanup of expired attachments and pending uploads. Additionally, a notification digest system has been added to send periodic email summaries of user activity, configurable via environment variables, and the server startup now conditionally initializes email, storage, and GitHub App services based on available configuration.

crates/remote/src · high confidence

New services crate for backend logic and config migrations

The new \crates/services\ crate introduces core backend services including analytics tracking, an approval system for tool execution, authentication context management, and a comprehensive configuration system with versioned migrations (v1 through v8). Users benefit from improved editor support (adding Xcode and Google Antigravity), structured config upgrades, and backend telemetry capabilities.

crates/services/src · high confidence

New shared UI component library and linting configuration

The \packages/ui\ directory now contains a new shared UI package scaffold, including an ESLint configuration that enforces unused-import rules and TypeScript strictness. This package introduces a suite of reusable React components for the application, such as Accordion, Alert, Badge, Button, and a complex AppBar with support for project/host navigation and user popovers. It also includes specialized UI elements for the Kanban board (BulkActionBar, AskUserQuestionBanner) and a performance-optimized ChangesPanel utilizing TanStack Virtual for rendering large diff lists.

packages/ui · high confidence

New standalone Relay Test Client for debugging relay path routing

A new standalone browser-based test client has been added to the repository, allowing developers to test relay path routing and proxied local backend API calls without modifying the main Remote frontend UX. The client provides a UI for authenticating via GitHub or Google, entering host pairing codes, and manually overriding tokens, then executes a sequence of API calls (including session creation, auth-code exchange, and SPAKE2 authentication) to verify the relay infrastructure.

scripts/relay-test-client · high confidence

New unified executor action framework for coding agents, reviews, and scripts

The executor subsystem now uses a unified \ExecutorAction\ enum to dispatch coding agent tasks (initial and follow-up), code reviews, and shell scripts through a single \Executable\ trait. This change introduces a \working\_dir\ option to all action types, allowing users to specify a relative path for execution instead of being limited to the container root. It also standardizes how executor profiles and overrides are applied via \ExecutorConfig\ and supports QA-mode mocking for testing. Users benefit from consistent behavior across agent interactions, review workflows, and script execution, with clearer control over where commands run.

crates/executors/src/actions · high confidence

New utility crate for core application infrastructure

The \crates/utils\ module has been introduced to centralize shared application logic. This includes a new approval system with a 10-hour timeout for tool execution, a robust diff engine for generating and parsing unified diffs, and a memory-bounded message store (100 MB limit) for streaming and replaying execution logs. Path handling is improved with WSL2 detection, macOS private alias normalization, and executable resolution that refreshes the system PATH. Platform-specific behaviors are standardized, such as suppressing console windows on Windows and opening URLs in browsers with WSL2 support. Additionally, the crate provides JWT claim extraction, Sentry error reporting integration, and asset management for embedded sounds and scripts.

crates/utils/src · high confidence

New workspace chat hooks for session management, approvals, and attachments

This change introduces a suite of new React hooks in the workspace chat feature to handle core user interactions. \useSessionSend\ and \useCreateSession\ manage sending messages and creating new sessions, while \useSessionAttachments\ enables uploading files and inserting them into chat. \useApprovalMutation\ provides the ability to approve, deny, or answer agent requests. Additionally, \useSessionMessageEditor\ handles draft persistence for messages, \useSessionQueueInteraction\ manages queuing and canceling messages, \useResetProcess\ and \useMessageEditRetry\ allow users to reset or retry specific agent processes, and \useConversationHistory\ and \useTodos\ handle the display of chat history and task lists.

packages/web-core/src/features/workspace-chat/model/hooks · high confidence

OpenCode executor now tracks and displays token usage and context window information

The OpenCode executor now monitors and reports token consumption during AI interactions. A new \models.rs\ module implements a cache for model context windows, while \sdk.rs\ emits \TokenUsage\ events containing total tokens and the model's context limit. These events are processed by \normalize\_logs.rs\ to display token usage details directly in the conversation log, giving users visibility into their API consumption and context window utilization.

crates/executors/src/executors/opencode · high confidence

WebRTC direct tunneling with relay fallback

This change introduces a new WebRTC transport layer that allows direct peer-to-peer connections as a faster alternative to the standard relay, with automatic fallback to the relay if the direct path fails. The \relay-webrtc\ crate implements the client and host logic for establishing WebRTC data channels, including SDP signaling and ICE candidate exchange. The \relay-protocol\ crate defines a shared transport-agnostic frame format (\RelayWsFrame\) and conversion traits (\RelayTransportMessage\) that allow both the existing Axum and tungstenite WebSocket implementations to be reused over the new WebRTC data channel. The \ws-bridge\ crate provides the bidirectional bridging logic to connect the WebRTC data channel to upstream WebSocket endpoints, preserving message types across the bridge.

crates/relay-protocol, crates/relay-webrtc, crates/ws-bridge · high confidence

Windows installer and macOS app configuration for Tauri v2

The Tauri application bundle now includes native installer support for Windows and proper configuration for macOS. A new MSI template (msi-template.wxs) defines the Windows installation structure, including per-user installation, desktop/start-menu shortcuts, and major upgrade handling. A build script (build.rs) resolves a Windows-specific linker conflict involving duplicate version resources. On macOS, the Info.plist sets the application display name to "Vibe Kanban" and configures the App Transport Security to allow local HTTP/WS connections for development. The tauri.conf.json is updated to version 0.1.45, enabling the auto-updater plugin and defining the app's security content policy.

crates/tauri-app · high confidence

Removals

Removal of legacy Button component

The legacy Button component located in the UI library has been removed from the codebase. This change eliminates the specific implementation that previously handled button variants (such as default, destructive, outline, secondary, ghost, and link) and sizes (default, small, large, icon) using class-variance-authority, requiring consumers to adopt the replacement UI primitives.

frontend/src/components · high confidence

Removal of legacy backend entry point and health check route

The legacy \main.rs\ entry point and the associated \health\ route module have been removed from the backend. This deletes the previous implementation of the \/health\ endpoint and the root \/hello\ and \/echo\ handlers, indicating a structural shift in how the application is initialized or served.

backend · high confidence

Removed legacy Bloop frontend entry point and styles

The legacy frontend entry point (\main.tsx\), root component (\App.tsx\), and global styles (\index.css\) have been removed from the \frontend/src\ directory. This cleanup eliminates the initial 'Welcome to Bloop' demo page and its associated Tailwind CSS configuration, indicating that the application's entry logic and UI structure have been migrated to a different location or implementation.

frontend/src · high confidence

Architecture

Server binary restructured with new build script and middleware layer

The server crate has been reorganized into a new binary structure. A new build script (\build.rs\) now injects environment variables (PostHog, Sentry, shared API bases) into the binary at compile time and ensures the frontend web assets directory exists. The application entry point (\main.rs\) has been rewritten to initialize the deployment, configure logging with specific module filters, bind both a main server and a preview proxy listener, and handle graceful shutdowns. A new middleware layer has been added, including origin validation to restrict cross-origin requests, relay request signature verification for secure relay communication, and signed WebSocket support. Additionally, a type generation tool (\generate\_types.rs\) has been introduced to export Rust database and API models to TypeScript definitions, and a centralized error handling module (\error.rs\) now maps internal service errors to standardized API responses.

crates/server · high confidence

Behavioural changes

ACP-based executors now support user approval workflows

The ACP executor implementation in \crates/executors/src/executors/acp\ has been updated to integrate with the executor approval service. When an agent requests permission to perform an action, the system now pauses execution to await user approval or denial via the \ExecutorApprovalService\. If no approval service is configured, the system automatically selects the most permissive available option (AllowAlways, then AllowOnce, then the first option) to maintain backward compatibility. Denied actions can include user-provided feedback, which is queued and sent after the denial. Additionally, session management now persists conversation history to JSONL files in the user's home directory, supporting session forking and resume prompts.

crates/executors/src/executors/acp · high confidence

Automated type generation and new JWT token refresh logic

The shared types module has been migrated to an automated generation pipeline: \shared/types.ts\ is now auto-generated from the Rust backend (via \generate\_types.rs\), introducing comprehensive types for repositories, workspaces, sessions, and scratch storage, while the legacy \shared/remote-types.ts\ is added as a separate auto-generated file for remote-specific schemas. Additionally, a new \shared/jwt.ts\ module provides a \shouldRefreshAccessToken\ utility that proactively triggers token refresh when the access token is within 20 seconds of expiry, improving authentication reliability.

shared · high confidence

Cursor executor auto-approves MCP servers

The Cursor executor now automatically configures trust for Model Context Protocol (MCP) servers. When running in a Cursor project, it reads the project's MCP configuration and writes the necessary approval entries to the local Cursor approvals file, eliminating the need for manual user interaction to authorize these servers.

crates/executors/src/executors/cursor · high confidence

Database schema overhaul for issues, attachments, and relay infrastructure

The remote database schema has been significantly restructured to support new product capabilities. Issues are now the primary task entity, replacing the previous shared tasks model, and feature org-scoped simple IDs (e.g., BLO-5), custom statuses, tags, comments, and relationships. File support is introduced via a deduplicated blob and attachment system, allowing files to be linked to issues or comments. Authentication has been hardened with separate refresh tokens and a grace window for token rotation. The platform also adds support for GitHub App installations with per-repository review toggles, a new in-app review table, and a relay infrastructure for remote host tunneling, including host identity and browser sessions. Finally, billing records for Stripe subscriptions and notification digests are now persisted.

crates/remote/migrations · high confidence

Database schema refactored to support multi-repo projects and granular execution tracking

The database schema has been significantly restructured to support multi-repository projects and more detailed execution state tracking. Projects are now linked to repositories via a new \repos\ registry and \project\_repos\ junction table, allowing multiple repositories per project with distinct setup, cleanup, and copy-file configurations. Task attempts now track specific repositories via \attempt\_repos\, and execution processes are linked to specific repository states through \execution\_process\_repo\_states\. The previous \task\_attempts\ columns for merge commits and pull requests have been consolidated into a new \merges\ table that supports both direct and PR merge types. Additionally, the schema introduces \shared\_tasks\ for cross-project collaboration, \scratch\ for transient data, and \tags\ to replace the previous task templates system. Execution logging has been refined with \execution\_process\_logs\ for append-only JSONL logs, and draft handling has been unified into a \drafts\ table before being dropped in favor of a new follow-up mechanism.

crates/db/migrations · high confidence

Droid executor introduces structured log normalization

The Droid executor now parses raw stdout into structured JSON events, mapping them to distinct UI entries for system messages, user/assistant chat, and tool calls (such as file reads, greps, and globs). This change enables the interface to display a cleaner, categorized conversation history and tool status rather than unstructured text output.

crates/executors/src/executors/droid · high confidence

Generated route tree and Vite environment types for local web

The local web package now includes an auto-generated TanStack Router route tree (\routeTree.gen.ts\) that defines the application's navigation structure, including paths for onboarding, app sections (export, notifications, workspaces, projects, hosts), and specific workspace/issue contexts. Additionally, a Vite environment declaration file (\vite-env.d.ts\) has been added to expose the \\_\_APP\VERSION\\_\ global constant to the TypeScript compiler.

packages/local-web/src · high confidence

Git operations now use the Git CLI for safer working-tree management

The \crates/git\ module has been restructured to delegate destructive and working-tree-touching operations (such as rebase, merge, checkout, and add/commit) to the Git CLI instead of the libgit2 library. This change improves safety by preventing accidental data loss from uncommitted changes, ensures correct sparse-checkout behavior, and provides better cross-platform stability (particularly between WSL and Windows). The new \GitCli\ wrapper handles these CLI interactions, while \GitService\ continues to manage the overall workflow, including read-only graph queries and network operations.

crates/git · high confidence

Improved scroll anchoring in the diff viewer for large PRs

The diff viewer now uses a patched version of the @pierre/diffs virtualizer (v1.1.4) to handle scrolling more robustly when viewing pull requests with 300+ files. This patch introduces a pending scroll request mechanism that ensures the view stays anchored to the correct file or line during re-renders, preventing the viewport from jumping unexpectedly. It also updates the React Virtualizer component to support external refs, allowing parent components to programmatically control the scroll position.

patches · high confidence

Introduce WebRTC direct tunneling for remote API communication

The remote web application now establishes a direct connection to the local host using WebRTC, bypassing the previous relay-only architecture. This change is implemented in the remote-web bootstrap and entry points, which initialize the WebRTC transport layer and configure the shared API client to route requests and WebSocket connections through this new direct tunnel.

packages/remote-web · high confidence

Migrate local web routing to TanStack Router with structured layout providers

The local web application has migrated its routing infrastructure to TanStack Router, replacing the previous implementation with a new file-based route structure. This change introduces a root route (\\_\_root.tsx\) that initializes core application context providers, including internationalization, theming, and user analytics (PostHog). A new \\_app\ layout route now wraps the main application shell, managing the provider hierarchy for workspaces, execution processes, and terminal sessions, while also handling keyboard shortcuts and release notes. The migration establishes distinct route paths for the workspace landing, project kanban views, issue details, and VS Code workspace integrations, ensuring consistent provider injection across these views.

packages/local-web/src/routes · high confidence

Native notification click handling on Windows, macOS, and Linux

The Tauri desktop app now supports clicking system notifications to navigate to specific content. Instead of relying on the generic \tauri-plugin-notification\ (which lacks click handling), the app uses platform-native APIs: \notify-rust\ on Linux, the native \UNUserNotificationCenter\ on macOS, and WinRT toast notifications on Windows. When a user clicks a notification, the app brings the window to focus and emits a \notification-clicked\ event with a deeplink path, allowing the frontend to navigate to the relevant page. This applies to both user-initiated notifications and backend push notifications.

crates/tauri-app/src · high confidence

New local navigation abstraction for resolving app destinations

The local web application now includes a dedicated navigation module (AppNavigation.ts) that maps internal application destinations to specific URL paths. This component handles the resolution of complex routes involving hosts, workspaces, projects, and issues, ensuring that local navigation correctly targets the appropriate URLs based on the current context and parameters.

packages/local-web/src/app/navigation · high confidence

Project rebrand to Vibe Kanban and sunsetting announcement

The product has been rebranded from 'Bloop' to 'Vibe Kanban', updating the README, project structure documentation (AGENTS.md), and configuration files to reflect the new identity. The README now prominently displays a sunsetting banner with a link to the shutdown announcement. Additionally, the repository structure has been reorganized from a simple backend/frontend split to a monorepo with distinct \packages/local-web\ and \packages/remote-web\ frontends, alongside a comprehensive set of new developer guidelines, security policies, and contribution standards.

(repo-wide) · high confidence

Removal of frontend Tailwind and Vite configuration files

The frontend's \tailwind.config.js\ and \vite.config.ts\ files have been deleted. This removes the local configuration for Tailwind CSS (including theme extensions, color palettes, and animation plugins) and the Vite build setup (including the React plugin, path aliases, and the API proxy to localhost:3001). Users relying on these specific local build settings or CSS utilities defined in the Tailwind config will need to adjust to the new build environment or configuration structure.

frontend · high confidence

Removal of utility class merging function

The \cn\ utility function, previously located in \frontend/src/lib/utils.ts\ and responsible for merging CSS class names using \clsx\ and \tailwind-merge\, has been removed from the codebase. This change eliminates the centralized helper for conditional class name composition, requiring consumers of this library to either implement their own class merging logic or rely on alternative patterns.

frontend/src/lib · high confidence

Structured log indexing and shell command categorization

The executor's log processing now uses a thread-safe monotonic index provider to assign unique IDs to conversation entries, ensuring consistent ordering and deduplication of normalized logs. Additionally, shell commands executed by the agent are automatically categorized (Read, Search, Edit, Fetch) to enable better visual aggregation in the UI, with specific logic to correctly classify file modifications while ignoring redirects to /dev/null.

crates/executors/src/logs/utils · high confidence

Workspace chat UI rewritten with virtualized rendering and new interaction controls

The workspace chat interface has been rebuilt to use TanStack Virtual for efficient rendering of long conversation histories, replacing the previous implementation. This change introduces a new conversation list container and entry display components that handle aggregated groups (tools, diffs, thinking) and individual messages. Users will now experience smoother scrolling and reduced memory usage in active sessions. Additionally, the chat box now supports arbitrary file attachments (including images during agent execution), session renaming, and a new turn navigation popover to jump between user messages. Forced scroll-to-bottom after sending a message has been removed, and scroll stability during streaming has been improved.

packages/web-core/src/features/workspace-chat/ui · high confidence

Test coverage

Added tests for filesystem git repository discovery

Added a new test module for the FilesystemService that verifies the list\_git\_repos function correctly discovers git repositories, respects skip directories (such as node\_modules and target), handles empty or non-existent paths, and enforces maximum depth limits.

crates/services/tests · high confidence

Dependencies

Initial dependency lockfiles and manifest definitions for Rust crates and CLI

The repository now includes the initial \Cargo.lock\ and \Cargo.toml\ manifests for the Rust workspace (including \server\, \remote\, \relay-tunnel\, \executors\, and various relay/bridge crates) as well as the \package-lock.json\ for the \npx-cli\. This establishes the baseline dependency graph, pinning versions for key libraries such as \axum\ 0.8, \sqlx\ 0.8.6, \reqwest\ 0.13, \tauri\ 2, and \russh\ 0.48, and sets the Rust edition to 2024 across the workspace.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 31 → 45 (+13.6)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 79 → 72 (-7.4)
  • Architecture 81 (new)
  • Maturity 58 → 63 (+5.4)
  • Readiness 11 → 28 (+16.9)
  • Security 40 → 62 (+21.9)
  • Event Sourcing 100 (new)
  • Accessibility 51 (new)

Resolved (109)

  • (anonymous) (cognitive 21) (crates/preview-proxy/src/click_to_component_script.js)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 89 more

New (1072)

  • (anonymous) (cyclomatic 232) (crates/preview-proxy/src/click_to_component_script.js)
  • (anonymous) (cyclomatic 48) (crates/preview-proxy/src/devtools_script.js)
  • (anonymous)::buildStackEntries (cognitive 17) (crates/preview-proxy/src/click_to_component_script.js)
  • (anonymous)::ensureCurrentInStack (cognitive 19) (crates/preview-proxy/src/devtools_script.js)
  • AcpAgentHarness::bootstrap_acp_connection (cognitive 53) (crates/executors/src/executors/acp/harness.rs)
  • AcpAgentHarness::bootstrap_acp_connection (cyclomatic 31) (crates/executors/src/executors/acp/harness.rs)
  • ActionsProvider.ActionsProvider (cognitive 19) (packages/web-core/src/shared/providers/ActionsProvider.tsx)
  • ActionsProvider.ActionsProvider (cyclomatic 20) (packages/web-core/src/shared/providers/ActionsProvider.tsx)
  • AgentsSettingsSection.AgentsSettingsSection (cognitive 56) (packages/web-core/src/shared/dialogs/settings/settings/AgentsSettingsSection.tsx)
  • AgentsSettingsSection.AgentsSettingsSection (cyclomatic 58) (packages/web-core/src/shared/dialogs/settings/settings/AgentsSettingsSection.tsx)
  • AppBar.AppBar (cognitive 25) (packages/ui/src/components/AppBar.tsx)
  • AppBar.AppBar (cyclomatic 27) (packages/ui/src/components/AppBar.tsx)
  • AppNavigation.destinationToLocalTarget (cognitive 16) (packages/local-web/src/app/navigation/AppNavigation.ts)
  • AppNavigation.destinationToLocalTarget (cyclomatic 22) (packages/local-web/src/app/navigation/AppNavigation.ts)
  • AppNavigation.destinationToRemoteTarget (cyclomatic 19) (packages/remote-web/src/app/navigation/AppNavigation.ts)
  • AppNavigation.resolveLocalDestinationFromPath (cognitive 39) (packages/local-web/src/app/navigation/AppNavigation.ts)
  • AppNavigation.resolveLocalDestinationFromPath (cyclomatic 52) (packages/local-web/src/app/navigation/AppNavigation.ts)
  • AppNavigation.resolveRemoteDestinationFromPath (cognitive 26) (packages/remote-web/src/app/navigation/AppNavigation.ts)
  • AppNavigation.resolveRemoteDestinationFromPath (cyclomatic 33) (packages/remote-web/src/app/navigation/AppNavigation.ts)
  • AppServerClient::on_notification (cognitive 17) (crates/executors/src/executors/codex/client.rs)
  • …and 1052 more

Changes since last survey

  • 10 commits — 5 feature/other, 5 fixes

By area

  • (root) — 4 commits
  • crates/executors — 1 commit
  • crates/git — 1 commit
  • crates/server — 1 commit
  • crates/tauri-app — 1 commit
  • crates/utils — 1 commit
  • packages/ui — 1 commit

Notable commits

  • fix: fix: Tanstack router api fix (#3464)
  • fix: fix: an Enter that confirms an IME candidate is not an Enter (#3459)
  • fix: fix: correct swapped stderr/stdout labels in git CLI error output (#3447)
  • fix: fix: route server startup through startup::initialize_deployment (#3449)
  • fix: pnpm audit fixes (#3460)
  • change: Coalesce replayed stderr chunks so stored sessions load in linear time (#3456)
  • change: add script to bump version locally (#3457)
  • change: bump copilot version to 1.0.83 (#3454)
  • change: chore: bump version to 0.1.45 (#3462)
  • change: docs: add SECURITY.md (#3448)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

BloopAI/vibe-kanban was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d5cbb5380fa0b32e98ef9b8d987f63decce4be3a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.