Changelog
What each Neuralis release changed — the release notes of every published version, newest first.
Every Neuralis release is one version across the host, the @neuralis/*
packages, create-neuralis and the neuralisapp/neuralis image. Its notes list
what an operator notices first, what was added, changed and fixed, the
security fixes, how to upgrade and what limits to know before upgrading.
A running installation tells its platform admins when a newer release is
published: the Admin dashboard shows the installed and the latest version, and
the Inbox carries one notice per new version. The check reads the published
release manifest once a day and installs nothing — moving an installation to a
new release is the operator's update procedure. Turn it off with the
updateCheck platform setting, or point updateManifestUrl at a mirror of the
manifest on a publicly reachable host.
Neuralis 0.2.0
Released: 2026-10-10 · Image: neuralisapp/neuralis:0.2.0 · npm: npm create neuralis@0.2.0
Highlights
- One release is now one version everywhere: the host, the
@neuralis/*packages, the image and its companion images move together, through oneneuraliscommand line, and stored data is only ever raised by an explicit offline upgrade on a stopped app. - A running installation tells its platform admins when a new release is published (Admin dashboard and Inbox, on by default, switchable off).
- Security fix: skill activation never hands a reserved platform secret to a skill. Update to 0.2.0.
Changes
Added
neuraliscommand line — every operator command is one verb of one tool:npx neuralis <command>in an install folder,node bin/neuralis.mjs <command>inside the image (setup, update, upgrade, checkpoint, backup, mount, pkg, user, host-broker and the rest).neuralis upgrade— raises stored data formats on a stopped app: a dry run lists what would change and what blocks it;--applytakes one checkpoint, runs every pending upgrade, resumes an interrupted run and writes nothing when there is nothing to do.neuralis updatereads the release manifest attached to the published GitHub release, so the host, its packages, the image tag and the default companion images move as one tested line, and in an install folder--applyruns the whole update — stop, offline upgrade, restart, health check; it never moves an install down unless you name an older manifest, and it leaves custom images untouched.create-neuralis convert— a one-time conversion of a folder created bynpm create neuralis@0.1.0into the new install-folder layout, behind a checkpoint, with a rollback.- Release notice — platform admins see the installed and the latest version on the Admin dashboard and one Inbox notice per new version. The check reads the published release manifest once a day, sends no identity and installs nothing; turn it off with the
updateCheckplatform setting, or pointupdateManifestUrlat a public mirror. - Operator packages in the container — a package added with
neuralis pkg addin an install folder reaches the container: the install builds one local image on top ofneuralisapp/neuralis:0.2.0with your packages, rebuilt byneuralis rebuild(and byupdate --apply) only when the package list or the version changes. - Docs changelog — every release's notes on the docs site.
- Brain notifications in the Inbox — a source sync that fails, recovers or completes, a finished re-index, and embedding that degrades or recovers, each with a link to the Sources panel or Vector Health.
- Setup offers "No embedding model": indexing, text and field search and source-discovered skills run without an embedding model or embedding API cost; a model can be added later in Admin → Vector.
- Claude Haiku 5.5 in the model catalog.
Changed
- Node.js 26 or newer — the
neuraliscommand line andnpm create neuralisnow require Node.js 26 (the image already runs on it); on an older Node they stop at once and name the version they found. - npm install folder — a folder made by
npm create neuralisis now a plain npm project that pinsneuralisto an exact version (save-exact); the@neuralis/*packages come pinned with it, and the packages you registered stay your own lines of itspackage.json. - Companion images — the virtual desktop and the MCP sidecar default to the release version (
:0.2.0) instead of a movingdevtag, so a pinned host no longer drifts. - Container checkpoints persist — the generated compose file binds
<NEURALIS_HOME>/checkpoints, so a checkpoint taken inside the container survives it; an upgrade refuses to write a checkpoint into the container's own writable layer. - No data is converted while the app runs — every runtime data converter is gone; a stored-format change ships as an offline upgrade module, and a build that finds data behind its version refuses to start and names
neuralis upgrade. - Package identity — a package found in a project source is identified by its instance URI, so trust, grants and data stay with that copy; package data folders are a readable mirror of that URI under
data/runtime/. The upgrade moves existing folders. - Honest embedding state — the Sources panel, Files search and Vector Health say which search mode is in effect and why, and how much embedding work is still owed.
- Agent Config card — the base form sits above the rails, prompt sections are chips, and one Save stores the whole form.
- Outbound requests and the MCP client identify themselves with the release version.
- Claude Haiku 4.5 is removed from the catalog; an agent that used it needs a model chosen by hand. Conversation history and past usage are unchanged.
Fixed
- Usage and spend — each model call is priced on its own before the totals are summed, so tiered prices are no longer applied to a whole turn; the Claude Sonnet 5.5 cached-input price is corrected.
- A data source that kept failing its sync every minute on a very large single-line file now syncs in milliseconds; binary files stay out of the text index, and new local sources skip npm cache folders by default.
- An embedding provider out of credit no longer fails writes or syncs — the file is stored and indexed, and the embedding is caught up later.
- Pending review — a change for a file that no longer exists can be approved or dismissed, a bulk review groups the records it can act on, and an approve after a conflict no longer replays.
- Synced copies of the built-in packages no longer appear as extra source packages.
neuralis updateno longer reads a flag's value as a package name.- Diff view — added and removed lines keep a full-width background under horizontal scroll.
- Stop — stopping a reply keeps the message you sent and its attachments; the turn ends cleanly instead of cutting the connection, and an unacknowledged message can be recovered.
- Attachments and images — a damaged or unsupported image is marked instead of failing the request, every model receives only the image formats it accepts, and files read from the virtual desktop arrive with their original bytes (images included). Text files such as SVG stay text.
- Setup — the hidden prompts (owner password, API keys) no longer echo into the terminal stream, and a pasted value ending in a newline is accepted.
- Docs — a public clone installs with
npm install(the documentedpnpm installfailed), and every page spells operator commands asnpx neuralis <verb>, the form a folder and a clone both run.
Security
- Skill activation never projects a reserved platform secret (a Git access token, an MCP access token, a channel token, a workflow signing secret) into a skill; a skill that asks for one sees it as missing. Every 0.1.0 install should update.
- Skill credentials are bounded by the caller: a skill always gets the caller's own user credentials, project- and agent-level ones only with credential-write permission in the project, global ones only with platform scope as well. A conversation continued by another member never inherits the previous member's skill credentials or shell scratch folder.
- The Git client library is updated to
simple-git4.0.2, clearing four published advisories.
Upgrading
- Before you start: install Node.js 26 or newer on the machine that runs
npx neuralis/npm create neuralis(node --version). The Docker image brings its own. - npm install folder:
npx neuralis update --apply. It reads the published release manifest (--version 0.2.0names it explicitly), moves the code and the image tags, regenerates the compose file, stops only this install's app (Qdrant keeps running), runs the offline upgrade behind a checkpoint, recreates the stack and waits for/api/health. A failing step stops it and prints where it stopped and the way back. Without--applyit prints that plan: the folder, the compose project, the services and the tags. - A folder created by
npm create neuralis@0.1.0: once, with the app stopped,npx --yes create-neuralis@0.2.0 convert ., thennpx neuralis update --version 0.2.0 --apply. The converter comes fresh from npm, so the installed 0.1.0 code does not take part. A folder that was run natively (it holds a.next/build) is refused with nothing written: a native run moves to a source clone. - Public clone:
git fetch --tags && git checkout v0.2.0 && npm install, thennpx neuralis update --version 0.2.0 --applyand the steps it prints. - Image only: set
NEURALIS_IMAGE_TAG=0.2.0andNEURALIS_MACHINE_IMAGE=neuralisapp/webtop-ubuntu-xfce:0.2.0in.env(a pinned MCP sidecar image is changed in Admin → Config), thendocker compose stop neuralis,docker compose run --rm --no-deps neuralis node bin/neuralis.mjs upgrade --apply,docker compose up -d -V. - From 0.1.0, every channel: the offline upgrade checks that every stored credential opens with the key file (it names any that do not and writes nothing) and records each vector point's embedding proof. It does not re-embed, but it writes every point once: on a large index it keeps Qdrant busy for minutes, and it prints its progress every 10 000 points. Stop only the app, never
docker compose down— Qdrant must keep running. A compose file generated by 0.1.0 has no checkpoints bind;update --applyregenerates it, and a hand-run upgrade refuses until one is in place and says so. - Agents on Claude Haiku 4.5: choose another model in the agent's settings.
- Virtual desktops: an existing desktop keeps its old file-reading agent until it is recreated; recreate it from the machine settings to read original file bytes.
Rollback
- Code:
npm install neuralis@0.1.0 --save-exactin the install folder (a clone:git checkout v0.1.0 && npm install; a converted 0.1.0 folder:npx neuralis convert --rollback <checkpoint id> && rm -rf node_modules && npm install). - Images:
npx neuralis update --manifest <the previous release-manifest.json> --apply, or the previous.envlines by hand, thendocker compose up -d -V. - Data:
npx neuralis checkpoint restore <id>(app stopped) — the checkpointupgrade --applynamed.
Known limits
- Running Neuralis natively, without Docker, needs a clone of the public host repository; an npm install folder runs the container.
- A public clone run with Docker cannot carry operator packages (its
package.jsonis the host's own manifest); register them in annpm create neuralisfolder, or run the clone natively. - 0.1.0 has no release notice, so this release is announced only here; from 0.2.0 on, the Admin dashboard and the Inbox name every newer release.
- Neuralis is in beta; the docs maturity page states how far each capability has come.