# Kavor 1.7.1

## Highlights

- Refreshes Electron, Chromium, React, the UI toolchain, and runtime dependencies to compatible stable versions.
  This hotfix keeps the existing Canvas and CodingAgent workflows without exposing experimental interfaces.

## Fixes

- Restores native WebBrowser mouse and keyboard input after switching Workspaces, without reloading the retained
  live page or blocking interactive browser controls.
- Clears the owning page's popup state when a WebBrowser popup closes, removing its frame and allowing subsequent
  popups to open without clearing a replacement popup.
- Corrects Markdown colors in light reading mode, including headings, links, code, quotes, and tables. Switching
  between light and dark reading modes now applies one consistent style in both compact and normal views.
- Preserves minute-precision timestamps in one-time Trigger schedules after the dependency update.
- Treats watched Workspace paths literally instead of expanding glob syntax, preserving recursive detection of
  newly created directories.
- Restores compatibility with the native pnpm executable when building Workspace packages, rebuilding native
  dependencies, and generating packaged third-party notices.
- Updates affected gRPC and FTP dependencies and preserves the reviewed CodingAgent tool-schema contract.

## Installation

Download Kavor from <https://download.agentkavor.com>. Existing direct installations can check for this release
from Software Update settings. No manual Workspace-data migration is required.

- Windows x64 is available from Microsoft Store or as the assisted per-User NSIS installer. Microsoft signs and
  updates Store installations. The direct installer remains unsigned, so Microsoft SmartScreen may require explicit
  confirmation.
- macOS 13+ provides separate Apple Silicon and Intel DMGs signed with Kavor's Apple Developer ID and notarized by
  Apple. Automatic updates use the matching architecture-specific ZIP and retain the manual DMG fallback.
- Linux x64 provides AppImage and DEB packages. AppImage supports Kavor-managed updates with an explicit coordinated
  restart; DEB updates are installed manually from the download page.

## Known limitations

- An upstream `braces` dependency advisory remains without a published patch. Recursive Workspace watching now
  disables glob expansion; this is a mitigation, not a patched dependency.
- Kavor's dedicated shared Browser Profile accepts every server certificate to support local development. A hostile
  network can therefore impersonate sites opened in that profile, including sites where the User signs in. The Kavor
  application session retains Chromium's normal certificate verification.
- WebBrowser Nodes do not reuse the User's external Chrome profile, extensions, history, or cookies. Deleting a Node
  does not erase shared site data; the global Kavor settings provide explicit cache, cookie, and site-data clearing.
- Cross-site frames isolated into another Chromium process are reported as omitted and cannot be controlled through
  the guest-scoped security boundary.
- Windows ARM64 and Linux ARM64 packages are not included until their native PTY, SQLite, process-containment, and
  packaged-runtime gates can run on matching CI environments.
- Windows direct downloads do not yet have an Authenticode publisher certificate; Microsoft Store packages are
  signed by Microsoft. Store availability may follow the direct stable release after Microsoft's independent
  certification completes.
