Getting started

Changelog

What each Neuralis release changed — the release notes of every published version, newest first.

Every Neuralis release is one version across the host, the @neuralis/* packages, create-neuralis and the neuralisapp/neuralis image. Its notes list what an operator notices first, what was added, changed and fixed, the security fixes, how to upgrade and what limits to know before upgrading.

A running installation tells its platform admins when a newer release is published: the Admin dashboard shows the installed and the latest version, and the Inbox carries one notice per new version. The check reads the published release manifest once a day and installs nothing — moving an installation to a new release is the operator's update procedure. Turn it off with the updateCheck platform setting, or point updateManifestUrl at a mirror of the manifest on a publicly reachable host.

Neuralis 0.2.0

Released: 2026-10-10 · Image: neuralisapp/neuralis:0.2.0 · npm: npm create neuralis@0.2.0

Highlights

  • One release is now one version everywhere: the host, the @neuralis/* packages, the image and its companion images move together, through one neuralis command line, and stored data is only ever raised by an explicit offline upgrade on a stopped app.
  • A running installation tells its platform admins when a new release is published (Admin dashboard and Inbox, on by default, switchable off).
  • Security fix: skill activation never hands a reserved platform secret to a skill. Update to 0.2.0.

Changes

Added

  • neuralis command line — every operator command is one verb of one tool: npx neuralis <command> in an install folder, node bin/neuralis.mjs <command> inside the image (setup, update, upgrade, checkpoint, backup, mount, pkg, user, host-broker and the rest).
  • neuralis upgrade — raises stored data formats on a stopped app: a dry run lists what would change and what blocks it; --apply takes one checkpoint, runs every pending upgrade, resumes an interrupted run and writes nothing when there is nothing to do.
  • neuralis update reads the release manifest attached to the published GitHub release, so the host, its packages, the image tag and the default companion images move as one tested line, and in an install folder --apply runs the whole update — stop, offline upgrade, restart, health check; it never moves an install down unless you name an older manifest, and it leaves custom images untouched.
  • create-neuralis convert — a one-time conversion of a folder created by npm create neuralis@0.1.0 into the new install-folder layout, behind a checkpoint, with a rollback.
  • Release notice — platform admins see the installed and the latest version on the Admin dashboard and one Inbox notice per new version. The check reads the published release manifest once a day, sends no identity and installs nothing; turn it off with the updateCheck platform setting, or point updateManifestUrl at a public mirror.
  • Operator packages in the container — a package added with neuralis pkg add in an install folder reaches the container: the install builds one local image on top of neuralisapp/neuralis:0.2.0 with your packages, rebuilt by neuralis rebuild (and by update --apply) only when the package list or the version changes.
  • Docs changelog — every release's notes on the docs site.
  • Brain notifications in the Inbox — a source sync that fails, recovers or completes, a finished re-index, and embedding that degrades or recovers, each with a link to the Sources panel or Vector Health.
  • Setup offers "No embedding model": indexing, text and field search and source-discovered skills run without an embedding model or embedding API cost; a model can be added later in Admin → Vector.
  • Claude Haiku 5.5 in the model catalog.

Changed

  • Node.js 26 or newer — the neuralis command line and npm create neuralis now require Node.js 26 (the image already runs on it); on an older Node they stop at once and name the version they found.
  • npm install folder — a folder made by npm create neuralis is now a plain npm project that pins neuralis to an exact version (save-exact); the @neuralis/* packages come pinned with it, and the packages you registered stay your own lines of its package.json.
  • Companion images — the virtual desktop and the MCP sidecar default to the release version (:0.2.0) instead of a moving dev tag, so a pinned host no longer drifts.
  • Container checkpoints persist — the generated compose file binds <NEURALIS_HOME>/checkpoints, so a checkpoint taken inside the container survives it; an upgrade refuses to write a checkpoint into the container's own writable layer.
  • No data is converted while the app runs — every runtime data converter is gone; a stored-format change ships as an offline upgrade module, and a build that finds data behind its version refuses to start and names neuralis upgrade.
  • Package identity — a package found in a project source is identified by its instance URI, so trust, grants and data stay with that copy; package data folders are a readable mirror of that URI under data/runtime/. The upgrade moves existing folders.
  • Honest embedding state — the Sources panel, Files search and Vector Health say which search mode is in effect and why, and how much embedding work is still owed.
  • Agent Config card — the base form sits above the rails, prompt sections are chips, and one Save stores the whole form.
  • Outbound requests and the MCP client identify themselves with the release version.
  • Claude Haiku 4.5 is removed from the catalog; an agent that used it needs a model chosen by hand. Conversation history and past usage are unchanged.

Fixed

  • Usage and spend — each model call is priced on its own before the totals are summed, so tiered prices are no longer applied to a whole turn; the Claude Sonnet 5.5 cached-input price is corrected.
  • A data source that kept failing its sync every minute on a very large single-line file now syncs in milliseconds; binary files stay out of the text index, and new local sources skip npm cache folders by default.
  • An embedding provider out of credit no longer fails writes or syncs — the file is stored and indexed, and the embedding is caught up later.
  • Pending review — a change for a file that no longer exists can be approved or dismissed, a bulk review groups the records it can act on, and an approve after a conflict no longer replays.
  • Synced copies of the built-in packages no longer appear as extra source packages.
  • neuralis update no longer reads a flag's value as a package name.
  • Diff view — added and removed lines keep a full-width background under horizontal scroll.
  • Stop — stopping a reply keeps the message you sent and its attachments; the turn ends cleanly instead of cutting the connection, and an unacknowledged message can be recovered.
  • Attachments and images — a damaged or unsupported image is marked instead of failing the request, every model receives only the image formats it accepts, and files read from the virtual desktop arrive with their original bytes (images included). Text files such as SVG stay text.
  • Setup — the hidden prompts (owner password, API keys) no longer echo into the terminal stream, and a pasted value ending in a newline is accepted.
  • Docs — a public clone installs with npm install (the documented pnpm install failed), and every page spells operator commands as npx neuralis <verb>, the form a folder and a clone both run.

Security

  • Skill activation never projects a reserved platform secret (a Git access token, an MCP access token, a channel token, a workflow signing secret) into a skill; a skill that asks for one sees it as missing. Every 0.1.0 install should update.
  • Skill credentials are bounded by the caller: a skill always gets the caller's own user credentials, project- and agent-level ones only with credential-write permission in the project, global ones only with platform scope as well. A conversation continued by another member never inherits the previous member's skill credentials or shell scratch folder.
  • The Git client library is updated to simple-git 4.0.2, clearing four published advisories.

Upgrading

  • Before you start: install Node.js 26 or newer on the machine that runs npx neuralis / npm create neuralis (node --version). The Docker image brings its own.
  • npm install folder: npx neuralis update --apply. It reads the published release manifest (--version 0.2.0 names it explicitly), moves the code and the image tags, regenerates the compose file, stops only this install's app (Qdrant keeps running), runs the offline upgrade behind a checkpoint, recreates the stack and waits for /api/health. A failing step stops it and prints where it stopped and the way back. Without --apply it prints that plan: the folder, the compose project, the services and the tags.
  • A folder created by npm create neuralis@0.1.0: once, with the app stopped, npx --yes create-neuralis@0.2.0 convert ., then npx neuralis update --version 0.2.0 --apply. The converter comes fresh from npm, so the installed 0.1.0 code does not take part. A folder that was run natively (it holds a .next/ build) is refused with nothing written: a native run moves to a source clone.
  • Public clone: git fetch --tags && git checkout v0.2.0 && npm install, then npx neuralis update --version 0.2.0 --apply and the steps it prints.
  • Image only: set NEURALIS_IMAGE_TAG=0.2.0 and NEURALIS_MACHINE_IMAGE=neuralisapp/webtop-ubuntu-xfce:0.2.0 in .env (a pinned MCP sidecar image is changed in Admin → Config), then docker compose stop neuralis, docker compose run --rm --no-deps neuralis node bin/neuralis.mjs upgrade --apply, docker compose up -d -V.
  • From 0.1.0, every channel: the offline upgrade checks that every stored credential opens with the key file (it names any that do not and writes nothing) and records each vector point's embedding proof. It does not re-embed, but it writes every point once: on a large index it keeps Qdrant busy for minutes, and it prints its progress every 10 000 points. Stop only the app, never docker compose down — Qdrant must keep running. A compose file generated by 0.1.0 has no checkpoints bind; update --apply regenerates it, and a hand-run upgrade refuses until one is in place and says so.
  • Agents on Claude Haiku 4.5: choose another model in the agent's settings.
  • Virtual desktops: an existing desktop keeps its old file-reading agent until it is recreated; recreate it from the machine settings to read original file bytes.

Rollback

  • Code: npm install neuralis@0.1.0 --save-exact in the install folder (a clone: git checkout v0.1.0 && npm install; a converted 0.1.0 folder: npx neuralis convert --rollback <checkpoint id> && rm -rf node_modules && npm install).
  • Images: npx neuralis update --manifest <the previous release-manifest.json> --apply, or the previous .env lines by hand, then docker compose up -d -V.
  • Data: npx neuralis checkpoint restore <id> (app stopped) — the checkpoint upgrade --apply named.

Known limits

  • Running Neuralis natively, without Docker, needs a clone of the public host repository; an npm install folder runs the container.
  • A public clone run with Docker cannot carry operator packages (its package.json is the host's own manifest); register them in an npm create neuralis folder, or run the clone natively.
  • 0.1.0 has no release notice, so this release is announced only here; from 0.2.0 on, the Admin dashboard and the Inbox name every newer release.
  • Neuralis is in beta; the docs maturity page states how far each capability has come.