Foreman

Changelog

Foreman ships fast. Every release, straight from GitHub releases.

Foreman v1.6.7

v1.6.7
Type # to work from a tracker task

Starting work from a ticket used to mean copying it into the message by hand. Type # in the message box and Foreman now lists your repository's open issues together with your tasks from Linear, Jira, ClickUp, Sentry and Notion, with the ones assigned to you first. Pick one and its key goes into your message. If the session's agent can open that tracker itself, it gets a reference to the task. If it can't, Foreman reads the ticket, its description and its latest comments, and sends them along, and a note under the message box says which tool the agent is missing. Picked tasks, and Figma, tracker or GitHub links you paste into a message, show up in the session's list of what it was given. The # picker is part of Pro.

Connect tools in one place

Giving your agents a tool like Figma or Linear used to mean editing each command-line tool's settings and signing in from a terminal. Settings → Integrations now has a Tools section with Figma, Gmail, Google Calendar, Linear, Sentry, Notion, ClickUp and Jira, and each tile says where that tool is connected. Its dialog lets you tick Claude Code, Codex and, for trackers, Foreman's own read-only sign-in, then works through the sign-ins one at a time. Foreman's sign-in is what the # picker uses, and one sign-in covers every machine. For Jira, Sentry and ClickUp you choose which site, organization or workspace it reads. Gmail and Google Calendar come from your claude.ai connectors. A stuck sign-in on the MCP Servers or Plugins pane can now be reset, which clears the stored login and signs in again.

A schematic look

Foreman used to have a single look. Settings → Appearance now has a Style choice. Classic is the look you know. Schematic redraws the whole app and the canvas with square corners, flat one-pixel borders and small monospaced captions. The layout and behaviour stay the same, and it works with every theme, light ones included.

Smaller changes and fixes

A message from another session that arrived while the agent was replying used to be treated as a new turn, and could leave the reply stuck on "thinking". It now appears above the reply it joined, and stays there when you reopen the session. Dragging a card on the canvas no longer makes wires and their labels flicker. The + for chaining a follow-up now moves aside when a wire already leaves the bottom of a card, so it no longer sits on that wire's label. On the Git page, a local branch's right-click menu can force-push it, with lease and after you confirm, and the push menu no longer opens underneath the commit list's header. Authors with a single name now get two letters on their disc, so names starting with letters like Y and V no longer look alike.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.6.6

v1.6.6
A clearer canvas

A session card's border used to look the same whatever the session was doing, with a small dot in the corner to show it needed you. The card's frame now carries that colour itself. It's red when something is broken, amber when the session is waiting for your answer, and your accent colour when it has finished and it's your move. While a session is working, the frame breathes in its status colour. A card that has settled stays neutral, so colour on the canvas always means something is going on. Wires now have an arrow at their midpoint, so you can tell which way they run even when both ends are off screen, and a small dot marks each place a wire meets a card. Hover over a finished session and a + appears under it, so you can chain a follow-up without opening a menu.

Schedules live on the canvas

Scheduled tasks used to have a page of their own, away from the work they started. Each active schedule is now a trigger in its project's box on the canvas. It shows when it fires next, how its last run went, and buttons to run it now, pause it, edit it or delete it. A wire runs from the trigger to the session its latest run started, and sessions a schedule started carry a ◷ badge. You can create a schedule from a project's New menu. The Scheduled page is replaced by an Upcoming button in the header. It opens a drawer listing every schedule, soonest first, including paused ones and ones on a machine that's offline. A dot on the button warns you when a run failed or fired late.

See what a session was given

Once you'd loaded a handoff or a memory into a session, or attached a file to it, nothing on the canvas showed it. A session's card now shows a ◫ count of the files it was given, and clicking it lists them, with a note on any that were deleted or moved since. Hovering over or selecting that session draws a wire from its project's saved context and highlights the cards it read. Each saved card also says how many sessions have read it.

GitLab and Azure DevOps

The Git page's pull requests, CI and issues used to work only for repositories on GitHub. They now work for GitLab, including self-managed GitLab instances, and for Azure DevOps too. Foreman works out which service a project uses from its remotes, and uses that service's own words: merge requests and pipelines on GitLab, and work items on Azure DevOps. You can open a merge request, follow its pipeline, re-run failed jobs and put issues or work items on the Triage board, the same way as on GitHub. When you send a failing check to a session, the agent is told which command-line tool to use for that service. A merge request from a fork opens in the project it was forked from.

Integrations settings

Signing in to GitHub used to happen in a terminal on each machine. Settings now has an Integrations pane for each laptop, with a card for GitHub, GitLab and Azure DevOps. Each card shows whether that service's command-line tool is installed and which account it's signed in as. Sign in opens a terminal there. Foreman then opens the sign-in page and copies the code for you, and this works for remote laptops too. A switch turns a service off for one machine, so Foreman stops using it there without signing you out.

Smaller changes and fixes

A new session that hasn't run yet used to open on an empty page. It now suggests three read-only first tasks, and picking one fills in the message box without sending it. After setup, the cursor starts in the message box too. When a Pro trial ends, Foreman now says so once, with a reminder that your projects, sessions and history all stay, and the trial ends on time even if the app is offline. Skills synced from claude.ai now show up in the slash-command picker. The list also updates while a session runs, so a removed plugin's skills disappear without a restart. Background work that finished without Foreman being told used to leave a session stuck as working in the background. It now clears within a few seconds.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.6.5

v1.6.5
GitLab and Azure DevOps

The Git page's pull requests, CI and issues used to work only for repositories on GitHub. They now work for GitLab, including self-managed GitLab instances, and for Azure DevOps too. Foreman works out which service a project uses from its remotes, and uses that service's own words: merge requests and pipelines on GitLab, and work items on Azure DevOps. You can open a merge request, follow its pipeline, re-run failed jobs and put issues or work items on the Triage board, the same way as on GitHub. When you send a failing check to a session, the agent is told which command-line tool to use for that service. A merge request from a fork opens in the project it was forked from.

Integrations settings

Signing in to GitHub used to happen in a terminal on each machine. Settings now has an Integrations pane for each laptop, with a card for GitHub, GitLab and Azure DevOps. Each card shows whether that service's command-line tool is installed and which account it's signed in as. Sign in opens a terminal there. Foreman then opens the sign-in page and copies the code for you, and this works for remote laptops too. A switch turns a service off for one machine, so Foreman stops using it there without signing you out.

Clone a repository, and choose where pushes go

Adding a project used to mean the repository was already on the machine. "Add a project" now has a Clone tab. It lists the repositories your signed-in accounts can see, or takes a pasted URL, and clones the one you pick next to your other projects before adding it. On the Git page, a badge shows which service the project is on and opens a Remotes dialog. There you can add, edit or remove remotes and choose the default one. Push now picks a remote the same way git does in a terminal, so a branch in a fork pushes to your fork, not to the original repository.

Sharper agent browser

Agent browsers on a remote laptop always streamed at standard resolution, so text could look soft on a high-density screen. The browser node now has a resolution setting. Auto matches your screen and how far the canvas is zoomed in on this computer, and keeps remote browsers at standard resolution so their stream stays fast. Choose 1x to 4x to set a fixed resolution instead, for remote browsers too.

Preview is gone, and fixes

The Preview browser node has been removed. The agent browser does everything it did, including element comments, and is the one browser on the canvas now. A laptop that couldn't connect sometimes disappeared from the fleet while its sessions stayed on the canvas, in a row with nothing to reconnect or remove. It now stays listed as offline, with the reason it couldn't connect. Removing a laptop now also removes its sessions and projects from the canvas, and they no longer come back after a restart.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.6.4

v1.6.4
Tabs in the agent browser

When a page opened a popup or a new tab, the browser node could only show whichever tab had changed most recently, and a page that kept updating its own title pulled the view away from a popup the moment it opened. The node now shows a tab strip whenever more than one tab is open. Click a tab to pin the view to it, so other tabs loading pages no longer move you. New popups still open in front, and "Pinned" switches following back on. The new + button and ⌘T open a blank tab, and ⌘W or a tab's close button closes one. When you mention the browser to its session with more than one tab open, the agent is told which page you mean, so it switches to that tab first.

Use the agent browser like a normal browser

The browser node used to take only clicks, scrolling and typing. It now also passes through hover, drag and drop, and right-clicks, so menus that open on hover, sliders and drag-to-reorder lists all work. Back, forward and reload buttons sit next to the address bar, along with the usual shortcuts: ⌘[ and ⌘], ⌘R, ⌘L for the address bar, and ⌘A, ⌘Z and ⇧⌘Z. Copy, cut and paste now move text between the page and your own clipboard. Use Ctrl in place of ⌘ on Windows and Linux. A browser on this computer now streams at your screen's resolution, so text is sharp. Browsers on remote laptops stay at standard resolution to keep the stream fast.

Checking out remote branches

Checking out a remote branch on the Git page used to ask you to name a new local branch. Double-click a remote branch, or choose "Checkout branch" from its menu, to get a local branch with the same name that tracks the remote, and switch to it. If you already have a local branch tracking it, you're switched to that one. "Create local branch" makes the tracking branch without switching. Merge commits also used to show an empty diff when the merge was clean. They now show what the merge brought in, the same way GitHub does.

Sessions that sat idle before their first message

A Claude session takes a snapshot of the repository's git status when it starts. If you committed or edited files before sending its first message, the agent began from an out-of-date picture. Its first message now includes the current state when the repository has changed since the session started. The first turn's change count also used to include every commit and edit made while the session sat idle, so reading one file could show as 16 files changed. It now counts only what the turn itself did.

Fixes

Opening the agent browser failed about half the time with a "did not answer" error. It now opens reliably. Typing into the agent browser also works better. A full stop used to type nothing and delete the next character, and some brackets and quotes moved the cursor instead of typing. Shortcuts on AZERTY and other non-QWERTY layouts now reach the right key. On Windows, characters typed with AltGr, like @, € and { on a German keyboard, can now be typed at all.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.6.3

v1.6.3
Send a failing PR or CI run to an agent

A red check or a review asking for changes used to mean copying the PR link into a session by hand. Pull requests and CI runs on the Git page now have a send button. It opens a short dialog that suggests what to ask for: fix the failing checks, address the review comments, review the PR, or look into a run. You can edit the message before sending it to an existing session or to a new one. The message links to the PR and its failing checks rather than pasting logs, and tells the agent which gh commands to read them with. If you're asking for code changes and the session is on a different branch, the dialog warns you but still lets you send.

Five new themes, and a tidier theme menu

The theme menu now has Cobalt2, Noctis, GitHub Light, Atom One Light and Solarized Light, and lists every theme under Dark and Light headings. Buttons and highlights on the accent colour now use a text colour picked for that theme, so the bright yellow and cyan accents stay readable. In Settings → Appearance, themes and text size are dropdowns, and each text-size option is shown at the size it sets.

Insight notes you can fold away

Claude's Explanatory and Learning output styles add "★ Insight" notes to their replies, which used to show up as raw text between two rules of dashes. They now appear as a card that starts collapsed to its first line, and you can open it to read the rest. Settings → Appearance has a new Insights option to have them start expanded. A note the model quotes inside a code block stays as code, and one that is never closed stays plain text, so the reply after it is never hidden inside a collapsed card.

Plugin changes reach running sessions

Installing, removing, enabling or disabling a Claude plugin used to leave running sessions on the old set until you restarted them. Changes made in Foreman now reload into running Claude sessions straight away, and the skill picker picks up the new skills. Codex sessions still need a restart, and the panel says so. When the CLI refuses a plugin change, the panel now shows the CLI's own reason instead of a generic failure.

Handoff errors that say what went wrong

A failed handoff used to say only that it had failed. It now shows the CLI's own reason along with what to do about it. For example: log in again, pick a model with a larger context window, check your plan or credits, the session's folder was moved or its worktree removed, or the CLI isn't installed on that machine.

Fixes

Resuming, forking or rewinding a Claude session counted everything the session had already spent a second time, because newer Claude Code versions carry the running total into the resumed process. Cost now counts only what the new process spends. Codex pricing now covers the GPT-6 models and the current gpt-5.6-sol rate, and a Codex session on an API key that uses the default model is priced correctly instead of showing $0. When the agent withdraws a permission request, for example because the turn was interrupted, its approval card now goes away instead of waiting for an answer. A message from another session that this session's inbound policy holds back now shows as a card saying who sent it and why it was held, or why it was dropped, instead of disappearing. The desktop app now renews its sign-in in the background, so it stays signed in after the server starts expiring old logins.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.6.2

v1.6.2
Git Insights: what your agents actually shipped

Cost and Insights could tell you what the agents spent and how busy they were, but nothing said whether any of it reached your main branch. Analytics has a third tab now, Git Insights, which follows the code instead of the sessions. Each agent turn records the files it wrote, only on this machine, and those records are matched against trunk history. So for a project you can see how much of what landed was written by an agent and how much by hand, what share of agent-written files made it through untouched, edited first, or never landed, how long code took to go from a turn to trunk, and what each landing cost. Weekly charts split this by Claude, Codex and hand-written code, and every landing lists the sessions behind it. Tracking starts with this release, so history from before it is left out rather than counted as hand-written.

Race Claude against Codex

A fan-out used to send every lane to the same agent, so there was no way to put Claude and Codex on the same task and compare them. The fan-out dialog now has a Multiple option that sets the agent for each lane separately. Lane names never mention the agent, so the AI judge doesn't know which agent wrote which lane. Each decision you make is recorded, and Git Insights keeps a scoreboard of who got picked and whether the pick then landed. It names a leader only after ten mixed races, and it compares picks against each agent's share of the lanes, because an agent holding two of three lanes would otherwise win most races by chance. The Run on choice between subscription and API key now applies to each agent separately, and the dialog shows one status row per agent instead of two full warnings.

The project map shows what's heavy, busy and flagged

The map showed how files depend on each other but not which of them deserve attention. Files now show uncommitted line counts, a flame for files changed often in the last six months, an amber or red dot for medium or high complexity, and a count of findings from your latest Project Review. Hovering a file lists all of its numbers. Right-clicking a folder offers "Review this folder…", which opens Project Review already scoped to it, and nothing runs until you start it. Files open in a side drawer from the map, the Git page's working-tree list and the findings in a review, with syntax colouring for every language the map reads. Two map fixes: the "both ways" dependency view no longer spreads across most of the repo after two hops, and a project inside a larger repo now places review findings on its own files rather than same-named files at the repo root.

Cost charts that don't double-count or spike

The same model could appear under several names in the cost tables (with and without the long-context suffix, dated builds, older aliases), which split its spend across rows. They now merge into one row, for past history as well as new. Cost has a new chart of daily spend split by model. The top four models keep the same colour on every chart and the rest are grouped as "Other", instead of cycling through colours that were hard to tell apart. Model colours also follow the day-by-day spend history, so a model that paid for most of the month no longer turns grey because its sessions were deleted. Insights gained a day-by-day "Work by agent" chart comparing Claude and Codex by turns, lines or cost.

A commit list you can size

The commit list had no column headers, and each row sized itself to its own text, so a long author name pushed that row's change bar out of line with the others. The list now has a header with Graph, Message, Change and Author columns you can drag to resize (double-click to reset), and every row uses the same widths, so the bars line up. When a repo has more branch lanes than fit, the graph column scrolls sideways with the trackpad or its own scrollbar instead of squeezing the lanes together.

Fixes

The subscription or API key choice used to be based on how your last session was launched, so running one session on your API key hid the toggle that switched back, and deleting the key was the only way out. The choice now reads each CLI's own login, for Claude and Codex alike. MCP servers that failed to connect are now listed as failed again. A newer Claude Code release changed the icon it prints for them, and the app had stopped listing those servers at all.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.6.1

v1.6.1
A git graph you can read at a glance

The graph drew every commit as the same small dot on a thin coloured line, so working out who did what, on which branch, meant reading three columns of text per row. Commits are author discs now — initials derived locally, no avatar fetched from anywhere — sitting in lanes wide enough not to collide, and each branch prints its name once, in a gutter to the left, with a leader line to the commit it names rather than the same chip repeated down every row. A Changes column gives each commit a green/red bar scaled against the rest of the window, so a one-line fix and a four-hundred-line rewrite stop looking alike; the exact counts are on hover. The lane palette follows the theme instead of being tuned for a dark background and going to pastel mush on a light one. Hovering a branch's CI dot now lists the jobs behind the number — and if the list is too long to show, the passing ones are what get dropped, never the failures. The pull-request list gained state chips that default to open work, the branch drawer's error messages can be dismissed instead of waiting for something else to clear them, and pulling a branch you already have checked out just pulls it rather than relaying git's refusal to fetch into a checked-out ref.

The CI runs that no pull request carries

Every CI surface in the app read the checks hanging off a pull request, which structurally cannot show a run that has no pull request — so a broken nightly, a failed deploy or a manual dispatch was invisible here. The branch drawer has a CI/CD section now, listing the repo's recent Actions runs whatever triggered them, with a badge on the ones worth noticing and a header that counts only the workflows failing now rather than every failure still in the window. A failed run offers Re-run, which re-runs its failed jobs and not the ones that already passed. It loads when you expand it and never on a timer, so it costs nothing on a repo you don't open.

Insights counts what your tools actually did

The permission table was the only record of tool activity, which meant it described your permission settings rather than your work: under accept-edits or bypass, most calls never stop to ask and so never appeared at all. There is a second ledger now — every call the agent made, and the ones that came back an error — with a Tool failure rate card beside it, counting a call you refused as a denial and never as a failure. The per-session figures also stopped being erased by tidying up: they used to divide by the sessions that still existed, so closing a few could put an install with seventy launches into "too few to read as a pattern" while the cost above it stayed real. They now count launches, which can only go up. Each card carries a thirty-day trend line scaled to its own range, the window splits by agent and by project so Claude and Codex can be compared directly, and metrics that have never recorded anything collapse into one line naming them instead of taking four card slots to say nothing.

Codex file edits show up in the transcript

A Codex session's edits were missing from its transcript entirely — the shell commands were there, the git diff next door showed the changes, and nothing in between said where they came from. Codex stopped reporting a patch as a shell command a while ago and reports it as its own kind of event, which the app didn't read, live or on reload. Both paths read it now, and the edit is drawn as a diff card with the file it touched, the same as Claude's. The approval that goes with it used to arrive as a contentless "Allow Bash?" pointing at a card that was never drawn; it now names the edit and shows you the change you are being asked about.

The project map goes deeper than one level

The map drew only leaf folders, which gave it no altitude: a monorepo came out as hundreds of identical boxes with their whole path squeezed into the label, and no arrow ever said "core depends on shared". Folders now contain folders. A closed one stands for everything beneath it and carries its subtree's arrows, levels that neither branch nor hold files fold into a single header, and the folders with the most files in scope open first until the budget runs out — so the structure is readable before you touch anything. Hovering lights a whole subtree rather than one box, a pin stays lit while you look around and the pointer lights its own at half strength, and the import counts on the arrows are placed so that several feeding one box no longer print on top of each other.

A review lens that reads your history

Every review lens described the repository at one commit, so none of them could see which parts are moving. Change hotspots is a new lens that reads the recorded history instead: which files churn, which of those have nothing testing them, which keep appearing in the same commits as each other, and which have a history of repair rather than growth. Its window is anchored to the commit under review rather than to today, so the same commit gives the same numbers next week, and a comparison against an earlier run says so if the window's length moved. Two existing lenses also stopped reporting "none available" for tooling that exists: outside JavaScript the audit and dead-code analyzers are usually not installed, and they can now be fetched into a throwaway environment for the run — picking the lens is the consent for that, and nothing is added to your machine.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.6.0

v1.6.0
A map of the whole project, not just the diff

The change map could only draw the files a diff touched, so it was no help before you had changed anything. The canvas has a second mode now: Map draws a project's files as folder boxes with an arrow for every import between them, thick where a folder leans on another. Because a whole project is noise, every view is a scope — the files your sessions have touched, one folder plus a hop out, or one file's dependency cone up to six hops in either direction. Hover a file or a folder to light what it reaches and dim the rest, click to pin that, and type in the filter box to narrow to a name and whatever hangs off it. It is built on the machine that owns the checkout, so a remote laptop's project maps as fast as a local one.

Read and explain any file, with no session running

Reading a file used to mean a session open on that checkout. Clicking a file on the map now opens it read-only and syntax-highlighted in the drawer, session or no session — and "Open in session" is still there when you want to comment on lines and send them. Beside it is Explain: a read-only side chat that can tell you what a file does, how it is wired into the rest of the project, what a folder-to-folder arrow is standing for, or what a few lines you have selected mean. It runs on its own throwaway session that can't write anything, keeps its answers while you move around the app, and goes away when you close it.

Rename, move and delete files from the map

Housekeeping meant leaving for a terminal. Right-clicking a file on the map now offers rename or move — one box holding the whole path, so changing the folder part moves it — as well as delete, which asks first, and Send to session, which drops the path into that session's composer for you to finish the sentence. Everything lands in the working tree and nothing is staged or committed, so it shows up as an ordinary change you can review or throw away.

The version number checks for updates

The app checked for updates hourly and had nowhere to say so once the fleet sidebar went away, so a waiting update could sit unnoticed and there was no way to ask. The version badge in the header is now the control: click it to check the release feed right away, and it carries the rest itself — the download percentage while one arrives, then a Restart & Install button. Downloads are still automatic, so the button never stands between you and an update you already have.

Import arrows that point where they should

The maps quietly missed edges. A /* inside a tsconfig.json string opened a comment that swallowed the whole paths block, so every alias in a project could go missing at once; a baseUrl with no paths beside it was ignored entirely; and in a monorepo one app's @/* could answer for another app's. Aliases are now read from jsconfig.json and the named variants too, followed through extends and references, and scoped to the directory that declared them. A Go import now reaches every file in the package it names rather than one stand-in, and a regular expression full of escaped slashes no longer hides the imports sitting beside it.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.12

v1.5.12
Read any file, not just the diff

The Diff tab could only show you the lines that changed, so understanding why a change was right meant leaving the app. You can now open any file in the checkout, read-only and syntax-highlighted, with its own diff marked in place. A file path in backticks in the transcript is a link, and so are the paths on Read and Edit cards, on review findings, and on the Git page. Selecting lines works the same as on a diff: comment on them, or hit "Explain this" to ask. There's a "Walk me through" button on the review bar for the whole change.

A map of how the change hangs together

A long diff gives you no sense of which file leads and which follows. The new Map button draws the changed files as a graph, with an arrow for every import, plus one hop of unchanged neighbours around them — so you can see what the change is wired into before you start reading. Click any file to go to it. It understands TypeScript, JavaScript, Python and Go, and falls back to a name-based guess elsewhere.

One file tree instead of two lists

Staged and Changes were separate lists, so a file edited in both showed up twice and nothing told you where it lived. There's now one tree grouped by directory, with a dot for staged and stage, unstage and discard on the row itself. A search box finds any file in the checkout, and a toggle shows the unchanged files sitting beside the changed ones. The commit message box drags to the height you want.

Branches start where they actually started

A branch's line could be drawn running forty commits down the shared spine, which read as work that was never yours — worst on a branch cut from a release branch, or on a laptop with no local main checked out. Each run now ends where its branch's own history ends, using the same answer the drawer's commit count gives. A stretch of history no ref points at is named after the branch that made it rather than "Unnamed branch", and a branch split across two lines keeps one colour.

See which browsers are using your pairing code

Regenerating the pairing code was a button next to Copy with nothing saying what it would break, and there was no way to tell whether anyone else was holding your code. Settings › Account now lists every browser that has connected with it, and which are connected right now. Regenerating asks first, and clears the list along with the code.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.11

v1.5.11
Buy Pro without leaving the app

Upgrading meant finding the website yourself, and nothing in the app ever told you which plan you were on. The Account pane now names it, with the renewal date and a Manage button that opens the billing portal if you're a subscriber. Every Pro lock is also a way to buy: the "included in Pro" notices and the small Pro chips are buttons now, and there's an Upgrade action in the command palette.

New accounts start with 14 days of Pro

Signing in used to be buried in Settings, so you could use Foreman for months without ever being offered anything. Setup now ends with an optional account step — skippable, and it never blocks you — and a new account gets 14 days of Pro free, no card. A badge in the header counts the days down, and you get one heads-up before it ends. When it does, everything on this machine stays; you just move to Free.

Free plan limits, and a removal that keeps your work

Free runs two turns at once, races two fan-out lanes, and holds three projects. A turn waiting its turn now says so above the composer instead of looking stuck, and lanes past the cap are greyed out in the Fan Out dialog rather than failing at launch. Removing a project is no longer destructive either: its setup and run scripts, saved commands and canvas layout are kept under the folder's path and come back if you add it again — so making room costs you nothing.

Bulk launches no longer stall behind the turn cap

Launching ten sessions at once sat on "Launching…" for the length of a whole turn, and sessions four onwards weren't even created until earlier ones finished. Every session is now created up front and its first turn queues on its own, so the dialog closes immediately. If a turn fails to dispatch, a toast says how many and why.

Read a saved handoff, and pick a skill for a scheduled task

A saved handoff showed you a title and a date and nothing else — the only way to read one back was to load it into a session. Handoffs now have the same view/edit modal memories have, rendered as markdown. Scheduled tasks got the skill picker the composer has, listing the skills that exist in the directory the schedule will actually run in.

Fixes

A second account signing in on a machine another account had already used would never connect — the app now takes a fresh device identity for it, leaving the first account untouched. The sign-in window went from five minutes to fifteen, since creating an account on the way could quietly outlast it. Messages from other sessions and dispatched review batches render as markdown again, including after a restart. New installs open in Light, matching the website.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.10

v1.5.10
The session drawer opens as far as you drag it

The canvas drawer stopped with a whole 360px of canvas still showing, which on a wide window capped it at about 58% — so the moment you actually wanted to read a long transcript you were fighting the divider instead of reading. It now goes to 95%, and there is an expand button beside the dock toggle so you don't have to drag there at all: one click fills the window, another restores the exact width you had set, which is kept untouched the whole time. As the canvas gives way the toolbars fold rather than break up. Past the point where the two bars stop fitting side by side the left one becomes a single ⋯ menu holding everything it used to show — the stage lens and Saved context included — instead of wrapping into a pile; past the point where even that won't fit, both bars go. If a stage filter or a search is still dimming the canvas when they do, a small ✕ stays behind to clear it, so the strip can never end up filtered with nothing on screen saying why.

Share and Connect to browser are switches you can see

Both used to live inside a session's gear menu, nine items deep, which is a poor home for the two controls in there that turn something on rather than doing something once — you could not tell at a glance whether a session was shared without opening a menu. They are now buttons in the session header, lit when on. "Manage this laptop's sessions from the dashboard" moved too, in the other direction: it was two dialogs deep, so a user who had never opened Share Laptop had no way to learn that the feature existed, even though nothing on your phone works until it is on. It now has its own button in the app header, beside your account. It is still a separate consent from Share Laptop and still grants only what it says — the dashboard can list and start sessions, never run commands or browse files.

A btw window you can put away

Closing a btw side chat ended it: the process, its transcript and its fork all went, and reopening paid to replay the whole parent conversation from scratch. That was the only exit, and Escape took it — which is a bad thing for the reflex key to do to something you just paid for. Closing is now two separate actions. The — button, and Escape, minimise: the panel goes, the side conversation stays, and reopening it from the composer lands back in the same one. The ✕ ends it, as before, and says so. A minimised btw leaves a dot on the composer's btw button, since that is the only thing on screen that would otherwise tell you a fork is still alive.

Terminals fold, and you can find a script by typing

A canvas terminal's only exit was the ✕, which kills the shell — so a dev server you merely wanted out of the way had nowhere to go, and you either kept a large rectangle on the canvas or restarted the server later. A terminal now collapses to its title bar like the preview and browser nodes do, keeping the process running with Stop and Restart still in reach, and double-clicking the bar brings it back. The Run… list learned to filter at the same time: on a repo with a long scripts list, start typing and it narrows to the matches, with ↑/↓ and Enter walking them and the saved commands still grouped under their own heading, so "saved" as a query narrows to those. Every filter box of this kind in the app now works that way — it takes focus when the list opens, and the arrows move over what you filtered to rather than over the whole list.

A session that refuses messages says so before you type

A session launched to refuse peer messages drops every one it is sent, while the sending tool answers "delivered" regardless — so one session could report handing work to another, and the model relaying it could repeat that, with nothing anywhere having happened. Foreman sets that gate itself, so it is knowable up front. The @ picker now marks such a session refuses and will not let you insert it, by click or by Enter; a session that parks messages for approval is marked holds. Both are stated flatly, unlike the older may hold, which stays hedged because it is inferred from permission modes rather than known. The "talks to" wires between sessions were redrawn as well: they used to leave the top and bottom of a card, which for two sessions in the same column meant a straight line down through every box and card in between. They now leave whichever side faces where they are going and run in a clear lane beside the column, and they no longer cross a node they were only passing.

Clearer icons, and other fixes

Four different actions — refresh, restart, restore and reconnect — had drifted into five interchangeable circular arrows that read as the same glyph at 11px, most visibly on the canvas toolbar where two of them sat side by side. Each is now named by what it acts on or what it does: the toolbar's two refreshes are a branch and a laptop rather than two arrows, and the rest use one consistent icon per verb. Their busy state lasts long enough to register, too — both canvas refreshes usually finish inside a frame or two, so the button used to look inert whether or not you had hit it. Elsewhere: routing those session-to-session wires no longer costs a stutter when you drag a node around a busy canvas, the @ picker's keyboard cursor steps over a session it won't let you pick instead of resting invisibly on it, and a failed change to one of the two sharing consents no longer hides an error about the other.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.9

v1.5.9
The canvas is where sessions live now

Foreman had two places to work on a session — the Sessions page and the canvas — and they had quietly stopped being equals. The canvas drawer had grown into the real thing months ago, the same transcript, composer and Diff panel, so the Sessions page was a second route to the same surface that had to be kept in step and sometimes wasn't. It is gone. The canvas is the only session view, the header calls it Canvas, and anything that used to send you to the Sessions page — a schedule's finished run, a review finding's "Fix this", a session picked from the command palette — now opens that session on the canvas with the right tab already showing. Clicking a session node also selects its project, which is what the Git page and the fan-out, bulk and issue dialogs read, so those stop asking you to go and pick a project you were plainly already looking at. The docked preview pane and the terminal rail retired with the page; both have been canvas nodes for a while. Project Review, which used to be labelled just Review, now says what it is.

Drive a laptop's sessions from your phone

The dashboard could only ever show sessions you had shared one at a time from the desktop, which meant deciding at the desk what you might want later. Turn on "Manage this laptop's sessions from the dashboard" — a new switch in the Share dialog, separate from Share Laptop and deliberately not implied by it — and foremanapps.com lists everything running on that machine, live status included, over a single encrypted connection rather than one per row. From there you can open any of them, start a new session in a project you already have, and read your saved handoffs. It cannot run commands, browse files or delete anything: a new session names a project id and the laptop resolves the directory from its own records, so a browser can only start work somewhere you already added, and detaching a session is the strongest thing it can undo. You can also stop a running turn from the phone now, and cancel a background task individually — a turn interrupt cannot reach one of those by definition. Your phone can be notified too, on the same per-event preferences your desktop already uses: a notification names which session wants you and never what it wants, because the wording is composed from the label the server already holds rather than sent from your laptop.

Saved context, on the canvas

The ✦ Memory shelf above each project box held two unrelated things — memories you had saved and Claude Code's own internal memory files — and offered to delete either. It is now ✦ Saved context and holds what you actually own: your saved memories and your handoff digests, newest first. Clicking a handoff opens the load composer straight from the canvas, with a picker for which session to load it into, so continuing yesterday's work no longer starts by hunting for the session that owns the file. Claude's own memory files are no longer listed or deletable from here; they are the CLI's to manage, and offering a delete button for a format we only read was the wrong side of that line.

The context meter says how many turns you have left

A percentage tells you how full the window is but not whether that matters in the next five minutes or the next hour. The meter now learns how fast a session is filling and turns it into "≈N more turns", on the button's tooltip and above the bar, with the measured growth per turn in the breakdown. It appears once there is a real rate to report and stays away when there isn't, rather than turning a single reading into a forecast. The rate is measured per turn rather than per message from the agent, which matters more than it sounds: a turn with six tool calls reports its usage six times, and counting those as six turns would have promised roughly six times the headroom you have. Two figures got more honest alongside it. The window Codex reports is now explained as the effective one — its input limit minus the slice held back for the reply — because a 258k sitting next to a model advertised at 400k reads as a bug when it isn't. And a learned window can now be corrected downward: a direct reading used to lose to whatever larger number had been inferred earlier, so one bad guess stuck forever.

Claude and Codex keep their own session defaults

Session defaults held one record, so it had to be wiped every time you changed which agent starts new sessions — a Claude model id means nothing to Codex, and an effort level like max is not one Codex has. Switching agent therefore threw away the model and effort you had set. The pane now has a tab for each agent, each with its own model, effort, permission mode and credential, and picking the default agent just moves which one is in front. Switch back and forth as often as you like; neither side forgets. Claude-only settings — output style, and whether other sessions may message this one — no longer appear on the Codex tab, where they were controls that did nothing. The handoff digest picker follows the same rule, defaulting to the cheap summarising model on Claude and to the source session's own model on Codex.

Fixes

An AI review's toolbar used to keep its agent, model and file pickers live while the review ran, so changing one mid-run — or the diff simply moving underneath it — left the bar describing a run that wasn't happening; it now states what the running review was actually given, and the file count and line total are frozen from launch. Context loaded into a session that was parked on an approval was sent straight at a CLI that could not read it and was lost; it is queued now, the same as text typed into a session mid-turn. The canvas layout menu gained a "Check laptop connections" button, for when you have just noticed a stale rail and would rather not wait out the heartbeat. A subagent's token usage no longer counts toward its parent session's context meter — it is a separate conversation with its own window, and it made the reading jump and settle back for the length of every Task call. "View this session's changes" in the command palette no longer sits there enabled with no session selected, doing nothing when picked. And the light theme's accent is the same clay as the dark themes', instead of a blue that belonged to no other part of the app.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.8

v1.5.8
Foreman stops paying for a login shell on every command

Every command Foreman ran on your machine — resolving where claude lives, reading a git status, starting a session — opened a fresh interactive login shell first, because that is the only way to see the PATH your own terminal sees. On a fast Mac that costs about four tenths of a second; on a base M1 it is closer to three and a half, and starting one session runs five of them. Foreman now reads your login shell once and remembers what it contributed, so the commands themselves run through a shell that is roughly forty times cheaper. Nothing about which binary gets picked has changed: your profile is still read, just not from scratch every time. It is re-read whenever you come back to the window and whenever a CLI is installed, updated or removed, so a brew install you ran in your own terminal still counts without restarting the app. Removing a session got quicker too, by doing its cleanup at once rather than one round trip after another.

MCP servers and plugins, for both agents

The MCP pane only ever described Claude. A server you connected there did nothing for a Codex session, and the pane didn't say so — a green "Connected" read as a fact about the machine. Servers are now mirrored into both CLIs when you add one, each row names each agent and shows that agent's own verdict, and Connect signs in per CLI, because the two hold separate tokens and authorizing one genuinely leaves the other signed out. Plugins gained a Codex tab beside the Claude one, with its marketplaces, installs and — through the same config write Codex's own interface uses — its enable and disable switches, which its command line has no equivalent for. Plugins are listed per agent rather than merged: unlike a server, a plugin id names a marketplace the other CLI has never heard of. Adding a server on a machine that only has one of the two CLIs no longer reports a failure for the one that isn't there, a removal that doesn't land keeps its row instead of vanishing optimistically, and a schedule now warns about a sign-in only when it is the agent that schedule will actually run.

Codex sessions have skills

The skill picker was hidden for Codex sessions, on the reasoning that skills were a Claude idea. They aren't: Codex has its own full skills system, sharing the same on-disk shape and the same plugin:skill naming. The picker now offers them, read from Codex itself rather than guessed at from disk — which matters, because the enabled state lives in its config file and several versions of the same plugin can sit side by side with nothing on disk naming the live one. Skills from either agent are still never offered to the other; naming one at the wrong CLI just reaches the model as literal text.

The AI commit message runs on the agent you use

The "Generate commit message" button in both commit composers ran claude, hardcoded — so on a machine that only has Codex it failed with a command-not-found, from a control that looked perfectly available. It now runs the session's own agent, or on the Git page the one your session defaults name. The button's tooltip also says who is about to write it and on which model, rather than leaving you to find out from the result.

See which agent a session is running, and change it where you start work

A session card marked Codex and left Claude unmarked, which only answers the question if you already know the convention — and on the canvas the agent picker didn't exist at all, so anyone working there concluded the Settings pane was the only way to switch. Every session now names its agent, on the sidebar row, on the canvas node and in the session info popover, and the picker moved into the New session menu that the sidebar and the canvas share. The agent menus also mark a CLI that isn't installed on the machine you're pointing at — marked, not blocked, since an unreachable laptop hasn't established anything either way, and a laptop that simply didn't answer is no longer reported as having nothing installed. Session cards on the canvas grew wider to fit all of that without truncating the name after a few characters, and a project box now defaults to four of them per row instead of five, so the box keeps the footprint it had.

Fixes

The Codex model picker in Session defaults sat on "Checking for installed Codex models…" forever on any install where you hadn't yet clicked a machine in the fleet list — it was asking a laptop it had never been given. It now uses the same machine every other settings pane does, and says so plainly when there genuinely isn't one. Uninstalling or updating a CLI also used to leave its model catalog on offer for the rest of the app run, listing models from a binary that was no longer there; the pickers now ask again. And $FOREMAN_PORT is exported in every session rather than only in isolated ones, so the run command we suggest in project settings — npm run dev -- --port "$FOREMAN_PORT" — no longer expands to a bare --port and fails to start in an ordinary session. $PORT is still overridden only in isolated sessions, so a plain npm run dev keeps whatever default your dev server picks.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.7

v1.5.7
Codex sessions come back with their history

Reload Foreman, reopen a Codex session, and its conversation was simply gone — an empty transcript above a session that was still very much alive. The cause was that Codex refuses to replay a thread another process is already holding, and the session's own process is exactly that, so the replay could only ever fail for the sessions you'd want it for. Foreman now reads the thread's own record off disk, the same way it has always done for Claude, so history comes back whether the session is running or not. It also comes back complete: the old path replayed messages and dropped every command and tool call between them, and those are now there too.

Context and cost figures you can believe

Several numbers were wrong in ways that pointed in opposite directions. A Codex session's context meter was fed the thread's running total rather than the conversation's current size, and counted the cached prefix twice on top of that, so a session with 31k in context could read as over its window; Codex states its real window per model, and the meter now uses it, which makes it the more exact of the two agents. On the Claude side the window was matched against a hardcoded list of the models that existed when it was written — so a Sonnet 5 session was told it had 200k when it has 1M, while every Opus before 4.6 was told the reverse; a pinned build with a date in its id, and Bedrock and Vertex model ids, are all read correctly now. Per-turn footers gained the token counts they always had room for, and stopped printing "$0.00" for Codex turns, which are reported in tokens and no money at all. And a healthy ChatGPT subscription no longer shows a red "No credits remaining" under every usage reading — that line described a pay-as-you-go balance a subscription simply doesn't have.

Choose which agent does the work, wherever you start it

Starting several sessions at once had no agent picker at all, so it quietly launched Claude however your defaults were set — on a Codex-only machine that meant a batch of sessions that couldn't run. The AI review on a session's Diff tab had the same problem for the same reason. Both now let you pick, and the review's picker is worth having on its own: reviewing a diff with the other agent is a genuinely useful second opinion. Switching agent also stopped leaving pieces of the old one behind — a model id or an effort level from Claude means nothing to Codex, and the launch surfaces disagreed with each other about which of the two to clear, so a Claude reasoning level could survive onto a Codex session that has no such setting. The one place that stays Claude-only is the whole-project Review, and it now says so, with the reason, instead of leaving you to discover it.

Install and remove the agent CLIs from inside Foreman

An install had two minutes to finish or Foreman gave up on it and said "check again shortly" — but a large download over a slow link routinely runs past that while working perfectly, and when it landed there was nothing left watching to notice, so the row sat on "Installing…" forever. Installs are now judged on whether they've gone silent rather than on a stopwatch, they show a progress bar and the installer's own latest line while they run, and they're confirmed against the machine at the end rather than trusted to report honestly. Each CLI also gained an Uninstall button, which removes the real binary the way it arrived — Homebrew, npm or the vendor's own installer — while deliberately leaving your sign-in and session history alone. It won't run while a session on that machine is mid-work, it asks first, and where removal would genuinely need administrator rights it hands you the exact command rather than taking them.

Project boxes that fit on the screen, and can be renamed

A project box grew one column per session with no ceiling, so seven unrelated sessions made a box about fifteen hundred pixels wide with the vertical space beside it left empty. Sessions now wrap into a grid, packed so a short one drops into the gap beside a tall one instead of starting a new row below everything, and lineage and fan-out groups stay intact as units. Drag the box's right edge to set how many fit per row; the width is remembered. Projects can also be renamed now — click the name on the box, or use the Name field in project settings. It's a label and only a label: nothing on disk is touched, so two checkouts can share a name and a long directory can have a short one.

Terminals stop leaving dev servers running

Closing a terminal only ever reached the shell, not what the shell was running — so a npm run dev you'd started survived, kept its port, and was reachable only from Activity Monitor. Worse, a terminal's identity lived only in the window, so reloading the app or closing the window orphaned every running command at once with no way back to any of them. All four exits — closing a terminal, reloading, closing the window, quitting — now take the running command with them, on this machine and on any laptop connected to it. Elsewhere: settings that take effect the moment you click them are drawn as switches rather than checkboxes, so they stop looking like something waiting for a Save button that was never there; the Privacy pane's nine-event list folds away while keeping the guarantee that makes it believable on screen; the "New sessions" pane is now "Session defaults" (the old name still finds it); each laptop card shows how many sessions it's carrying and which build it's on; and the session menu's Share and browser toggles no longer slam the menu shut on the first click, which is what had been hiding the new "Show it on the canvas" for an agent browser that was otherwise running invisibly.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.6

v1.5.6
Point at what's wrong, several things at a time

Commenting on a running page meant one element per turn: you clicked something, wrote a note, sent it, and the agent started work on that while the other four things you'd spotted waited behind it — which is the wrong shape for looking at a screen and finding a list. You can now keep picking. "Add another" stages a comment instead of sending it, a tray at the bottom counts what's waiting and lets you drop any of them, and one Send delivers the lot as a single turn with an optional note framing the whole set. The composer also stopped covering the thing it's about: it now opens anchored under the element you picked, with that element outlined, instead of docking across the bottom half of the frame — flipping above only when there's no room below. Two silent failures went with it. A comment aimed at a session that was mid-turn used to be dropped on the floor, and one aimed at a dormant session went nowhere at all; both now queue and resume the way every other composer in Foreman does, and a send that genuinely can't get through says so and leaves your comments staged rather than eating them. And when several comments carried screenshots, every one of them pointed at the last picture written — each now keeps its own.

Comment on the page your agent is actually driving

The agent browser on the canvas was something you could watch and click, but not talk about: to ask about a specific button you described it in words and hoped the agent found the same one. You can now pick an element straight out of the live view. Hovering highlights what's under the pointer, clicking captures it — tag, CSS path, size, rendered HTML and the computed styles that explain how it looks — and the message tells the agent it's already on that page, so it answers instead of navigating somewhere else and losing what you were pointing at. The pick is a pure read: nothing is injected into the page and nothing is drawn in it, so an agent working in the same tab never sees that it happened and no outline turns up in its own screenshots. If it picked something up while you were typing and navigated away, the message names the page the element actually came from rather than quietly implying otherwise.

The page's console, where the agent can read it

A page an agent was driving could throw on every render with nothing anywhere saying so — the errors were real, in a browser with no DevTools you'd think to open, and the agent had no way to read them either, because a snapshot reports the DOM and not the log. Warnings and errors from the page now collect behind a badge in the browser node's title bar, count up as they arrive, and travel with any comment you send about that page, source location included. Only warnings and errors are kept — the rest is the bulk of a dev server's output and none of it answers "is something broken here" — and a new page starts clean, whether you navigated or the agent opened a tab of its own.

Pin the size the agent measures the page against

The agent browser followed the node it was drawn in, so "check this at mobile" was a hope rather than an instruction — the agent looked at whatever width you happened to have dragged the node to. The node's header now has a viewport control: Fit still follows the node and is still the default, and Mobile, Tablet, Laptop and Desktop pin a real device size, with a second click on the one already pinned turning it on its side. The point is that the agent inherits it — its snapshots and its screenshots are taken at whatever is set here, which is what the browser's own device mode can't do for you, since that resizes what you see. A pinned size letterboxes the view here, and clicks still land where you aim them.

Reuse a commit message you've already written

The messages you write again and again are, by definition, already in the log — but reaching one meant scrolling the graph and retyping it. Both commit boxes, on the session's Diff tab and on the Git page, now have a history button that offers the repo's own recent subjects, filtered live by whatever you've typed. It matches anywhere in the line rather than just the start, since the repeated part is often in the middle; merge, revert and squash commits are left out because git wrote those, not you; and picking one drops it in the box to edit rather than committing anything. Separately, a half-written commit message no longer disappears when you glance at the Chat tab and come back — it's kept per session, and survives a restart.

Conversations that have ended stop looking live

When two sessions messaged each other the canvas drew a blue wire between them for half an hour, which meant a blue wire only ever told you "these two talked at some point recently" — not what a live-looking canvas appears to be saying. A wire that's been quiet for three minutes now cools to grey and fades, and its label says how long ago the last message landed, so a finished exchange reads as finished long before it disappears. The arrival dot stopped replaying, too: it used to travel the wire again every time you left the canvas and came back, so a conversation that ended half an hour ago animated as if it were happening. It now plays for messages that are actually new. Elsewhere, a failure in Foreman's own background work — a failed update check most often — could raise a toast carrying an entire HTTP response body and stretch it down the height of the window; those are now trimmed to something readable, and a routine update check that can't reach GitHub no longer announces itself at all.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.5

v1.5.5
Every branch shows its CI

The Git page could tell you what your branches were, but nothing about whether they built — you found that out by opening GitHub. The checked-out branch now carries its CI next to its name in the sync bar, every local branch in the drawer carries the same verdict as a dot, and the pull-request list shows each PR's rollup and expands to the named checks behind it, because "1 failed" without saying which job sends you to the browser anyway. Branches that have a PR get this for free, on the same call that lists the PRs; a branch with no PR is asked about when you select it, and there's a "Check CI status" in its right-click menu when you want to re-read one. Worst state wins, so a mostly-green rollup with one red job reads as red, and a check we can't classify counts as pending rather than being quietly dropped — a failure hiding behind a green badge is the one thing this surface must never do. A repo with no CI configured shows nothing at all instead of a reassuring dot it hasn't earned.

Choose what Foreman interrupts you for

Foreman fired six different desktop notifications and there was no way to change any of them short of silencing the whole app in your OS. There's now a Notifications pane in Settings listing each one — a session needing approval, background work finishing, a session erroring, a scheduled run, a chain step, a review settling — with a switch each and a master switch above them. Everything stays on by default, exactly as it behaved before the pane existed; a settings screen isn't a licence to quietly stop telling people things they never asked to stop hearing. Two of those events are new: a session that hits an error used to be the one outcome you most needed to hear about and the only one that waited silently until you came back, and a finished review now says how many findings it came back with. Notifications still stay quiet while Foreman is in front of you, but that's now a toggle too — on a second monitor the window is often focused and nobody is looking at it.

Stop one background task without stopping the session

A Workflow or background Agent outlives the turn that dispatched it, so the Stop button — which interrupts a turn — never reached one. A dispatch that hung could only be cleared by spending a fresh turn asking the agent to kill it, or by killing the session and losing everything else with it. Each running task in the background list now has its own Stop, with a "Stop all" once there's more than one, and stopping one leaves the session and every other task alone. The task closes the same way one that finished on its own does, so the row moves itself from Running to Finished; if nothing happens, the row says so rather than sitting disabled forever claiming it's stopping.

Errors stop taking the app down with them

Anything that went wrong deep in Foreman's own machinery — a stream, a timer, a background poll — arrived as the operating system's own "A JavaScript error occurred" dialog, with a stack trace in it, and the app exited when you dismissed it. Those now surface as a toast in the app's own voice, with the message available to copy for a bug report, and Foreman keeps running. Two specific crashes are fixed outright. Asking for a diff too large to hold in memory — which a checkout onto the wrong branch will produce — used to take the whole app down; the output is now capped, and any view showing a diff that got cut says so instead of presenting a fraction of the change as if it were all of it, which matters most if you were about to send it for review. And closing Foreman while a terminal was still producing output could throw on the way out and show that same dialog as the last thing you saw.

Send several handoffs at once, and get told when to

Loading a handoff into a session sent exactly one, so picking up work that spanned two sessions meant loading one and pasting the other. The load composer now has an "Also send" picker for other saved handoffs and memories to ride along, previewed exactly as it will be sent, with the handoff you clicked Load on kept as the current state and the extras framed as background — two handoffs both claiming to describe the present is worse than one. Separately, a session filling up used to be something you noticed by watching a meter: Foreman now offers a handoff once a session crosses a share of its context window, defaulting to 75%, adjustable or switchable off under Settings › New sessions. It's a share rather than a token count because the window differs by model and by CLI, and it asks once per crossing rather than on every turn afterwards.

Smaller fixes

If your project pointed at a package inside a monorepo, or at a linked worktree, Foreman couldn't tell you were halfway through a merge or a rebase — it looked in the wrong place for the marker files git leaves behind, found nothing, and showed you a clean tree with no conflict banner and no way to continue or abort, on the one checkout where you were actually stuck. Switching projects while the Git page was still fetching pull requests left it blank for up to a minute; it now loads the repo you switched to immediately. And a scheduled run that failed announced itself twice, once as the schedule and once as a generic session error — you now get the one that names the schedule, and turning schedule notifications off actually silences it.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.4

v1.5.4
The agent browser works on Codex

"Connect to browser" was a Claude-only switch — on a Codex session the control wasn't there at all, because the browser was handed to the agent through a flag only Claude has. Codex takes the same server a different way, so the toggle now means the same thing on either agent, and the browser itself never learns which one is driving it. Approving what the agent does with it works properly too: Codex asks permission for a browser action in a shape nothing was answering, so before this it only ran at all if you had already given the session blanket permission — those prompts now arrive as ordinary approval cards, naming the tool rather than just the server, with "Always allow" offered only where Codex will honour it. Connecting the browser restarts the session, and a Codex session restarted before it had ever taken a turn used to come back unable to run anything; that no longer happens.

Codex transcripts stop hiding MCP tool calls

If you ran a Codex session with any MCP server configured, every call it made to that server was missing from the transcript — no request, no result, no error, just a gap where the agent had done work you couldn't see. Codex reports those calls in a shape of their own that nothing was reading. They now appear like any other tool call, with the arguments the agent sent, whatever the server returned, and failures marked as failures. The agent browser is what made this obvious, but it was true of every MCP server on Codex.

Insights runs on the agent you actually use

The Insights analysis always ran Claude, whichever CLI you had set up — so a Codex user pressed a button that quietly reached for an agent they'd never signed into. It now follows the agent you've chosen as your default. Codex reports what a run spent in tokens rather than dollars, and rather than invent a price for them, the run and the estimate beside the button are shown in tokens too; a run that has never been priced no longer gets quoted a stale dollar figure left over from an earlier Claude run. Those runs also count toward the token totals on the Cost lens now, instead of being spent invisibly.

Insights says what has changed since last time

Running the analysis twice gave you two snapshots and no relationship between them. A second run now shows a line above the findings comparing itself with the previous one — interrupt rate 18% → 12%, and which way that counts — using the numbers each run actually reasoned over rather than recomputing a window that has since moved. It only reports a metric that moved by more than the noise between two overlapping 30-day windows, it stays quiet about readings too thin to mean anything, and if nothing has genuinely moved the line isn't there at all.

Usage analytics is on by default

Product analytics used to be off until you switched it on, and almost nobody did, which meant no way to tell whether people who install Foreman ever get an agent running. It now defaults to on, and the app tells you so once — after your first successful session, not at launch — with a different sentence if you're upgrading, because you were previously told it was off. What can be sent is a fixed list of nine events, enumerated in full under Settings › Privacy, every value a number, a yes/no or one option from a fixed list: there is no free-text field in the format, so your code, paths, prompts and output cannot travel even by accident. One event is new — how far the first-run setup wizard got, so a setup that defeats people can be found rather than guessed at. Turning it off deletes the anonymous install id and discards anything not yet sent. Separately, if you have the cross-device session-detail option on under Account, it now also uploads the daily Insights counters — interrupts, permission answers by tool category, rewinds, fan-out lanes, launch timings, lines changed — which are counts only, with tool names reduced to fixed categories before they are ever written down. That one is still off unless you turn it on.

Smaller fixes

Prompts sent to Claude for a review, an Insights analysis or a fan-out judgement were being flattened to a single line on the way out, so the section breaks and indentation the prompt was built with arrived as ordinary spaces — they now reach the agent intact, which is a quiet improvement to anything those runs produce. The Privacy pane no longer shows the analytics checkbox in the wrong position for a moment while it looks up the real setting, which mattered most to exactly the people who had gone there to check that an opt-out had stuck.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.3

v1.5.3
Reviews can now go deep

A project review measured your codebase and reported what the numbers showed — and since proving a pinned number takes most of a run, the findings underneath it were often the thin end of the work. There is now a Depth choice on the setup screen. Standard is exactly what you had. Deep treats the metrics as where the review starts: each lens reads the files its own numbers point at, end to end, and reports up to eight findings rather than five. Two further kinds of agent then run once the lenses have settled — one per lens asking the question a lens cannot ask itself, "what did I miss?", and a last one that reads every lens together and reports only what shows up across them, like the file that is both the biggest hub and the one with no test. It costs roughly twice as much, so it is chosen per run.

Tell a review what to pay attention to

Every review graded your project by textbook, because it had never read the project's own documentation. Lenses now read your CLAUDE.md, AGENTS.md, README and any architecture notes before they begin, so a convention you set on purpose isn't reported as a finding and a deviation from a rule you set for yourself counts for more. There is also a Focus box for a sentence of your own — "the daemon boundary, anything crossing it untrusted". It steers what gets examined and how severely it's rated; it never narrows the review, and it can't change how anything is measured.

See what you fixed since the last review

Running a review twice gave you two reports and no relationship between them. A second review of the same checkout now compares itself against the previous one by default. Each finding is marked New or Still open, resolved ones are listed struck through with what was checked to confirm them, the header reads "3 of 7 fixed, 2 new", and every metric shows what it was last time and which way it moved. Only runs of the same checkout at the same scope are comparable, and where the two runs differed in a way that shifts numbers on its own — a different depth, a different set of lenses, a dead-code analyzer that resolved one time and not the other — the report says so instead of presenting it as progress. The exported HTML carries all of it.

Review numbers stop wobbling between identical runs

Two reviews of an unchanged repository could disagree with each other: 30 test files against 50, a busiest module with 85 dependents against 76. Neither run was lying — each had quietly drawn its own population, one counting only the unit-test folder while the other counted every tracked spec, one searching the folders it happened to think of while the other searched wider. Every fixed metric now pins the set of files it runs over as tightly as the command itself, always the whole tracked repository filtered by name, and a review comparing itself to an earlier one is shown the exact pipeline behind each earlier number. A count now moves when the code moved.

Pull-request signals sit on the project, not on a session

A failed build, or a review waiting on you, is news about a repository and a branch — but the dot announcing it had to live on a session, so one got picked, and a session that had never run a turn would light up the moment someone else's push broke the build. Those signals now mark the project itself: the project box on the canvas, and the project's name in the needs-attention list. Dismissing something sticks properly too. The canvas and the fleet list share one set of acknowledgements instead of each keeping its own, so opening an item from the list puts its mark out everywhere, and it stays out across a restart rather than greeting you again the next morning. The counts rolled up onto the sidebar tree now take the colour of the worst thing underneath them, so a red build can't hide behind three finished turns.

A handoff that comes back empty says so

Generating a handoff digest occasionally produced a dialog with no sections in it, no error, and a Send button that did nothing — and pressing Regenerate usually "fixed" it. The digest runs in plan mode, where a model asked for structured prose sometimes files it away as a plan and replies with a one-line note saying where it put it; nothing downstream could tell that from a real answer. The digest is now told not to write files at all, and a reply with no sections in it is reported as a failure, with the Retry button right there, instead of a dialog that looks broken.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.2

v1.5.2
Sessions stop insisting your login failed

A session that hit an expired CLI login was marked "Auth failed", and that mark was only ever reconsidered when the session next finished a turn. A session you had left idle never produces one — so signing back in fixed the CLI, the app kept saying otherwise, and the warning returned on every launch no matter how often you dismissed it. Verifying a sign-in now clears the mark from that machine's idle sessions too. It stays scoped: verifying Claude says nothing about a Codex session, and a session using its own API key is left alone, since no CLI sign-in would fix that one.

The attention dot lands on the session you were actually working in

When several sessions share one checkout, a pull-request signal — failed CI, a review, a branch ready to merge — is about the checkout rather than any one session, so Foreman marks a single session to carry it. It was picking the oldest record for that folder, which is restore order, not activity: a red CI run would light up a session nobody had opened in weeks while the one doing the work sat unmarked. It now marks the most recently active session instead, and skips sessions with nothing running behind them, where a dot read as "something happened here" when nothing had.

A project's MCP config can no longer run commands on your machine

Foreman's "log in" button for an MCP server built a small script from the server's name. A name is not necessarily yours — claude mcp list includes servers defined by a project's own .mcp.json, so opening a cloned repository could contribute one — and a name containing the right punctuation could break out of that script and run whatever it liked, on macOS, the moment you clicked to sign in to it. Server names are now quoted everywhere they are used, so a hostile one is inert text rather than a command. Nothing about signing in to your own MCP servers changes.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.1

v1.5.1
Sessions stop insisting your login failed

A session that hit an expired CLI login was marked "Auth failed", and that mark was only ever reconsidered when the session next finished a turn. A session you had left idle never produces one — so signing back in fixed the CLI, the app kept saying otherwise, and the warning returned on every launch no matter how often you dismissed it. Verifying a sign-in now clears the mark from that machine's idle sessions too. It stays scoped: verifying Claude says nothing about a Codex session, and a session using its own API key is left alone, since no CLI sign-in would fix that one.

The attention dot lands on the session you were actually working in

When several sessions share one checkout, a pull-request signal — failed CI, a review, a branch ready to merge — is about the checkout rather than any one session, so Foreman marks a single session to carry it. It was picking the oldest record for that folder, which is restore order, not activity: a red CI run would light up a session nobody had opened in weeks while the one doing the work sat unmarked. It now marks the most recently active session instead, and skips sessions with nothing running behind them, where a dot read as "something happened here" when nothing had.

A project's MCP config can no longer run commands on your machine

Foreman's "log in" button for an MCP server built a small script from the server's name. A name is not necessarily yours — claude mcp list includes servers defined by a project's own .mcp.json, so opening a cloned repository could contribute one — and a name containing the right punctuation could break out of that script and run whatever it liked, on macOS, the moment you clicked to sign in to it. Server names are now quoted everywhere they are used, so a hostile one is inert text rather than a command. Nothing about signing in to your own MCP servers changes.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.5.0

v1.5.0
Sessions stop insisting your login failed

A session that hit an expired CLI login was marked "Auth failed", and that mark was only ever reconsidered when the session next finished a turn. A session you had left idle never produces one — so signing back in fixed the CLI, the app kept saying otherwise, and the warning returned on every launch no matter how often you dismissed it. Verifying a sign-in now clears the mark from that machine's idle sessions too. It stays scoped: verifying Claude says nothing about a Codex session, and a session using its own API key is left alone, since no CLI sign-in would fix that one.

The attention dot lands on the session you were actually working in

When several sessions share one checkout, a pull-request signal — failed CI, a review, a branch ready to merge — is about the checkout rather than any one session, so Foreman marks a single session to carry it. It was picking the oldest record for that folder, which is restore order, not activity: a red CI run would light up a session nobody had opened in weeks while the one doing the work sat unmarked. It now marks the most recently active session instead, and skips sessions with nothing running behind them, where a dot read as "something happened here" when nothing had.

A project's MCP config can no longer run commands on your machine

Foreman's "log in" button for an MCP server built a small script from the server's name. A name is not necessarily yours — claude mcp list includes servers defined by a project's own .mcp.json, so opening a cloned repository could contribute one — and a name containing the right punctuation could break out of that script and run whatever it liked, on macOS, the moment you clicked to sign in to it. Server names are now quoted everywhere they are used, so a hostile one is inert text rather than a command. Nothing about signing in to your own MCP servers changes.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.4.8

v1.4.8
Sessions stop insisting your login failed

A session that hit an expired CLI login was marked "Auth failed", and that mark was only ever reconsidered when the session next finished a turn. A session you had left idle never produces one — so signing back in fixed the CLI, the app kept saying otherwise, and the warning returned on every launch no matter how often you dismissed it. Verifying a sign-in now clears the mark from that machine's idle sessions too. It stays scoped: verifying Claude says nothing about a Codex session, and a session using its own API key is left alone, since no CLI sign-in would fix that one.

The attention dot lands on the session you were actually working in

When several sessions share one checkout, a pull-request signal — failed CI, a review, a branch ready to merge — is about the checkout rather than any one session, so Foreman marks a single session to carry it. It was picking the oldest record for that folder, which is restore order, not activity: a red CI run would light up a session nobody had opened in weeks while the one doing the work sat unmarked. It now marks the most recently active session instead, and skips sessions with nothing running behind them, where a dot read as "something happened here" when nothing had.

A project's MCP config can no longer run commands on your machine

Foreman's "log in" button for an MCP server built a small script from the server's name. A name is not necessarily yours — claude mcp list includes servers defined by a project's own .mcp.json, so opening a cloned repository could contribute one — and a name containing the right punctuation could break out of that script and run whatever it liked, on macOS, the moment you clicked to sign in to it. Server names are now quoted everywhere they are used, so a hostile one is inert text rather than a command. Nothing about signing in to your own MCP servers changes.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.4.7

v1.4.7
Foreman runs on Windows

There is a Windows installer. It carries the same app the Mac and Linux builds do — sessions, the canvas, terminals, the Git page, schedules — with nothing held back or stubbed out. Install it, sign in, add the machine, and a Claude Code or Codex session runs the way it does anywhere else, including the setup wizard installing the CLI for you and walking you through signing in if you don't have one yet.

Underneath, every command Foreman runs on Windows goes through Git for Windows' bash rather than PowerShell, which is what lets one implementation serve all three platforms instead of three that drift apart. Your agent's own tool calls still use whatever shell it prefers — Claude Code reaches for PowerShell on Windows — so nothing about how you work changes.

What a Windows machine needs

Git for Windows, which supplies that bash. If it isn't installed, setup now says so plainly and points you at the download instead of reporting an unrecognised machine with no agents on it, which is what a missing shell used to look like.

The installer is not yet code-signed, so Windows SmartScreen will warn you the first time: choose More info → Run anyway. It installs for your user only, so it never asks for an administrator prompt, and uninstalling leaves your sessions and settings alone.

Windows on ARM is supported through the x64 build, which Windows runs under emulation — there is no separate ARM64 download to choose between.

Linux, one release on

The Linux builds that landed last release have now been run end to end on real hardware rather than just in CI: installing the CLI from scratch, signing in, and running sessions. A handful of things that only a real Linux machine could have surfaced were fixed along the way — a shell command that assumed bash where Debian and Ubuntu use dash, and a global npm install that failed on distro-packaged Node without saying why.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.4.6

v1.4.6
Foreman runs on Windows

There is a Windows installer. It carries the same app the Mac and Linux builds do — sessions, the canvas, terminals, the Git page, schedules — with nothing held back or stubbed out. Install it, sign in, add the machine, and a Claude Code or Codex session runs the way it does anywhere else, including the setup wizard installing the CLI for you and walking you through signing in if you don't have one yet.

Underneath, every command Foreman runs on Windows goes through Git for Windows' bash rather than PowerShell, which is what lets one implementation serve all three platforms instead of three that drift apart. Your agent's own tool calls still use whatever shell it prefers — Claude Code reaches for PowerShell on Windows — so nothing about how you work changes.

What a Windows machine needs

Git for Windows, which supplies that bash. If it isn't installed, setup now says so plainly and points you at the download instead of reporting an unrecognised machine with no agents on it, which is what a missing shell used to look like.

The installer is not yet code-signed, so Windows SmartScreen will warn you the first time: choose More info → Run anyway. It installs for your user only, so it never asks for an administrator prompt, and uninstalling leaves your sessions and settings alone.

Windows on ARM is supported through the x64 build, which Windows runs under emulation — there is no separate ARM64 download to choose between.

Linux, one release on

The Linux builds that landed last release have now been run end to end on real hardware rather than just in CI: installing the CLI from scratch, signing in, and running sessions. A handful of things that only a real Linux machine could have surfaced were fixed along the way — a shell command that assumed bash where Debian and Ubuntu use dash, and a global npm install that failed on distro-packaged Node without saying why.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.4.5

v1.4.5
Spend figures that are actually your spend

Analytics has been overstating cost, and by a lot. Claude's CLI reports a session's running total on every turn, and Foreman added that figure each time — so a turn's spend was counted again on every turn that followed it, and a session that ran twenty turns reported roughly ten times what it cost. On one real month the page read $12,570 against $1,608 for the same work. Each turn's own increment is now what gets recorded, so the totals, the per-model split, the calendar, the per-turn line in the transcript and the header badge all mean what they say.

The old numbers, gone rather than quietly wrong

Because the inflated figures were only ever stored as sums, there is nothing to recompute them from — and the amount of the overcount depends on how many turns each session ran, so no single correction recovers them. The history recorded before this release is therefore dropped once, on first launch, rather than left standing as numbers we know to be false. There's also a "Clear usage history" at the foot of the Analytics page for whenever you want to start the count over yourself; it clears this device's figures everywhere they're kept — the day totals, the per-session costs on the cards, and the copy your account holds for the cross-device view — so a cleared history stays cleared instead of returning on the next sync.

What the turns actually moved

Cost was the only thing the page counted, which left the biggest lever on it invisible. Tokens now sit beside the money — fresh input, what was served from the cache, what was written to it, and output — along with the share of everything read that came from the cache, which on a warm session is most of it and is the difference between a plausible bill and a shocking one. The counts come from each turn first-hand rather than being inferred from the dollar figure, so a Codex session on a subscription — which is never priced, because it isn't billed per token — finally contributes to this page instead of reading as free.

Background work you can look inside

A session that dispatched background agents told you only how many were running and which tool one of them last used, while they spent real time and real money out of sight. The count is now a list: what each task was asked to do, whether it's an agent or a shell command, the tool it's on, what it has spent, and a clock that ticks rather than jumping between heartbeats. Tasks stay listed for a moment after they finish, with the summary of what they actually did — that used to vanish the instant the task closed — and the list no longer waits for your own turn to end before showing anything, which is when most dispatches are made. A session you stop also stops advertising work that died with it.

Schedules that can reach past one repo

Every scheduled run was pinned to a fresh isolated worktree, which is the right default — it keeps an unattended, auto-approved run away from your working tree and leaves a branch you review and merge — but it also walled off any job that genuinely spans more than one repo. A schedule can now be pointed at the project directory itself instead. That choice is also its permission posture: isolated runs stay sandboxed, while a run in the project directory has the same reach as a session you start by hand and allow everything, and the dialog says so plainly before you pick it. Both modes are badged on the schedule card, so the riskier answer is never the one that shows nothing. Existing schedules are unchanged and stay isolated.

Transcripts that stop thinking

Reopening a session you'd worked in for a while showed "thinking…" under every reply except the last one — turns finished days ago, still animating as though they were live. Replayed history now settles all the way through.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.4.4

v1.4.4
Spend figures that are actually your spend

Analytics has been overstating cost, and by a lot. Claude's CLI reports a session's running total on every turn, and Foreman added that figure each time — so a turn's spend was counted again on every turn that followed it, and a session that ran twenty turns reported roughly ten times what it cost. On one real month the page read $12,570 against $1,608 for the same work. Each turn's own increment is now what gets recorded, so the totals, the per-model split, the calendar, the per-turn line in the transcript and the header badge all mean what they say.

The old numbers, gone rather than quietly wrong

Because the inflated figures were only ever stored as sums, there is nothing to recompute them from — and the amount of the overcount depends on how many turns each session ran, so no single correction recovers them. The history recorded before this release is therefore dropped once, on first launch, rather than left standing as numbers we know to be false. There's also a "Clear usage history" at the foot of the Analytics page for whenever you want to start the count over yourself; it clears this device's figures everywhere they're kept — the day totals, the per-session costs on the cards, and the copy your account holds for the cross-device view — so a cleared history stays cleared instead of returning on the next sync.

What the turns actually moved

Cost was the only thing the page counted, which left the biggest lever on it invisible. Tokens now sit beside the money — fresh input, what was served from the cache, what was written to it, and output — along with the share of everything read that came from the cache, which on a warm session is most of it and is the difference between a plausible bill and a shocking one. The counts come from each turn first-hand rather than being inferred from the dollar figure, so a Codex session on a subscription — which is never priced, because it isn't billed per token — finally contributes to this page instead of reading as free.

Background work you can look inside

A session that dispatched background agents told you only how many were running and which tool one of them last used, while they spent real time and real money out of sight. The count is now a list: what each task was asked to do, whether it's an agent or a shell command, the tool it's on, what it has spent, and a clock that ticks rather than jumping between heartbeats. Tasks stay listed for a moment after they finish, with the summary of what they actually did — that used to vanish the instant the task closed — and the list no longer waits for your own turn to end before showing anything, which is when most dispatches are made. A session you stop also stops advertising work that died with it.

Schedules that can reach past one repo

Every scheduled run was pinned to a fresh isolated worktree, which is the right default — it keeps an unattended, auto-approved run away from your working tree and leaves a branch you review and merge — but it also walled off any job that genuinely spans more than one repo. A schedule can now be pointed at the project directory itself instead. That choice is also its permission posture: isolated runs stay sandboxed, while a run in the project directory has the same reach as a session you start by hand and allow everything, and the dialog says so plainly before you pick it. Both modes are badged on the schedule card, so the riskier answer is never the one that shows nothing. Existing schedules are unchanged and stay isolated.

Transcripts that stop thinking

Reopening a session you'd worked in for a while showed "thinking…" under every reply except the last one — turns finished days ago, still animating as though they were live. Replayed history now settles all the way through.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.4.3

v1.4.3
A first launch that tells you what to do

A new install opened on an empty fleet, two panes reading "select a project" and "select a session", and the only real next step hidden as a faint link inside a collapsed row — so the first thing a new user did was guess. There's now a first-run wizard with exactly two steps, because there are exactly two things Foreman can't work without: an agent CLI you're signed into, and a folder to work in. Registering this machine happens quietly underneath rather than being homework. It isn't a gate — "Set up later" leaves the app usable with the setup banner up, because installs fail for reasons we don't own, and a modal you can neither finish nor leave is worse than the dead end it replaces. New installs also open in the sand palette the rest of the brand is drawn in; if you've been using Foreman for months, your theme is left exactly as it is.

Signing in without leaving the app

Every sign-in Foreman depends on — claude auth login, codex login, and the OAuth dance an MCP server or a bundled plugin asks for — wants a real terminal, and until now that meant being thrown out into Terminal.app in the middle of setup, which is precisely where people got lost. Those sign-ins now run in a terminal embedded in the panel that asked for them, and the row updates itself when the login lands. If the shell on that machine can't give a TTY, you're shown the command to run by hand instead of a window that quietly does nothing.

Setup that knows Codex exists

The readiness check only ever asked about Claude, so a Codex-only user was told permanently that their machine wasn't set up — with a banner offering to fix something that was already fine. Both CLIs are now checked, listed, and installable side by side, and the app counts itself ready when either one works. Signing in also moves the new-session default off an agent this machine can't run, including re-pointing a session created by the wizard that never got to start; a session with a transcript is never touched, because that history belongs to the agent that wrote it.

Working in half a window

Foreman assumed a wide window: at half a 14" screen the three columns collided, the canvas toolbars ran underneath each other, and settings had no room for a sidebar next to a readable pane. Every view now gives ground in order of what it costs you to lose — the fleet pane falls back to its rail, the sessions list becomes a slide-over, the view switcher keeps all five buttons as icons rather than hiding behind a dropdown, settings turns its sidebar into a strip along the top, and the canvas folds the layout controls you set once behind a ⋯ while leaving the ones you flick on and off out on the bar. The graph's session drawer now docks to whichever edge leaves the canvas the most room, and you can pin it to a side if you'd rather decide yourself. None of this writes over the pane preferences you chose at full width.

Nowhere to go became somewhere to click

Several places said what was missing without offering to fix it: the Git page rendered an empty graph under a faint caption, and the sessions list described a state rather than a next step. Both now explain what a project is and offer the one button that solves it, and removing a project from either the sidebar or the canvas goes through one path that says so out loud when the change couldn't be saved instead of pretending it worked and handing the project back on the next launch.

Cheaper handoffs, and less rummaging afterwards

Handing a session's context to another one ran its summary on your default model, which on a long session cost several dollars a go and could time out just short of finishing. Digests now default to Haiku, which measured at well under a tenth of the cost on a real 380k-token session, and they're given five minutes rather than two — every measured run landed between one and three. A chain link can pick its own summarizer, including "same as the source session", now labelled as the costlier choice it actually is. The handoff itself gained a Files section — which files the session changed, read, or verified — so the session picking it up has pointers instead of a search. Alongside this, new sessions can pick a Claude output style, and browser scratch directories left behind by a force-quit are now reclaimed instead of accumulating under /tmp forever.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.4.2

v1.4.2
A browser the agent drives, and you can watch

An agent asked to check its own work on a running site had nowhere to do it, and wiring a browser tool up by hand gave you something you couldn't see. Turn on "Connect to browser" and a Claude session gets its own isolated Chromium — running on whichever machine that session runs on — with a node on the canvas showing what the page looks like right now, live. The stream follows what you're actually looking at: pan the node off screen or collapse it to its title bar and the frames stop while the agent keeps working. When the agent reaches for the browser, the line between it and the session lights up, so you can tell something is happening in there without reading the transcript.

Taking the wheel when the agent gets stuck at a login

The case that stops an agent dead is a sign-in page, and until now that ended the run. The browser node is a real input surface — click, scroll and type into it and the keystrokes go through to the page — so you can sign in by hand and let the agent carry on past it. If you've already signed into the same site in a preview, the key button hands those cookies and stored logins straight over instead, naming the origins it adopted so a dev server that moved from one port to another doesn't look like a mysteriously broken login. Sending them to a different laptop is a thing you're asked about once, since that moves credentials onto a second computer. Running several sessions' browsers at once is a Pro thing; one at a time is free, and the cap never blocks turning a browser off or reopening one you already have.

Pointing at the thing you mean in a preview

A running preview could be looked at but not talked about — describing which button was wrong took longer than fixing it. Previews are now nodes on the canvas alongside your sessions, and you can pick an element in one, write a note, and send it as a turn: the agent receives the element, its selector, the text in it, the styles it computed, a screenshot, and the warnings and errors the page logged, all stated as things already observed rather than as a page it should try to visit. A badge counts those console messages as they arrive, which catches a page that looks fine while throwing on every render. When a project has more than one session, the composer names which one the comment is going to and lets you change it.

The canvas caught up with the Sessions view

The canvas could show you everything and let you do almost nothing, so half of any session's work meant switching views and finding it again. Right-clicking a session card now offers the same four things its gear menu does, worded identically. Each laptop's rail has a device menu behind a right-click or a ⋯ button — reconnect it, open a terminal, get to its attachments, edit or remove the connection — with reconnect there whatever the machine's status, because a relay drop is exactly when you're staring at the canvas wondering why it went quiet. The toolbar gained a filter that matches a session's path as well as its name, which is what tells apart three worktrees of the same project, and a counter that steps you through the sessions wanting attention, coloured by the one it will jump to next.

"Needs you" marks that know when you're looking

A turn finishing raised an attention mark unless that session was the selected one, which was wrong in both directions on the canvas. A session stays selected while it's scrolled clean off screen, so work you weren't watching finished silently; and the canvas drawer shows the same transcript the Sessions view does, so a turn running in front of your eyes raised "needs you" over the very words appearing there. Being watched now means what it sounds like, and the mark clears when you click the card. Alongside this, branch sizes in the Git graph hold up when the branch underneath keeps moving: a ten-commit branch cut off a busy dev used to revert to counting its distance from the trunk once dev gained a commit of its own, and read as forty-six.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.4.1

v1.4.1
How much of your plan you've actually used

Claude sessions reported which quota window they were in and when it reset, but never how full it was — so the rate-limit panel showed a dash where the number should be, and you found out you were near a limit by hitting one. Both CLIs are now asked outright, on session start and after every turn, and both answer without running a turn or spending anything. The Usage dropdown and the Analytics strip show a real percentage per window with a bar behind it, green through amber to red, next to the plan they should be read against — twenty percent of a five-hour window is a different amount of work on Pro than on Max. Weekly Opus and Sonnet budgets appear as their own rows on the plans that have them. A window that genuinely hasn't been measured yet still says so rather than showing a confident zero.

Launch pauses that match the account

Foreman pauses new launches while an account is refused, and that pause was reading the wrong signal in two directions. A quota window that had already rolled over could leave its old "blocked" verdict attached to the fresh one, holding the launch and review gates for up to five hours on an account sitting at three percent. In the other direction, a usage reading with nothing to say about status could quietly clear a real block, dropping the badge and letting launches pile onto an account that was refusing them. Both are now settled by which reading a verdict actually came from, so the gate opens when the account opens and not before.

Branch sizes measured against the right branch

The Git graph's branch drawer counted a branch's commits as "everything not on the trunk", which is only correct for branches cut straight off it. A two-commit branch sitting on a thirty-seven-commit release line read as thirty-nine commits of its own, and highlighting it lit up the whole release line underneath. Each branch is now measured against the branch it actually sits on — the deepest one it descends from — falling back to the trunk when there isn't one. Its own remote counterpart is never mistaken for its base, so a branch that hasn't been pushed in a while doesn't suddenly appear to own a single commit.

Talking to one session, not to the project

Every session registered itself under its display name, which defaults to the folder it runs in — so three sessions in one project all answered to the same address, and a message meant for one of them reached whichever the CLI picked. Each session now registers under a name of its own, so an @ mention resolves to the session you chose. What you see is unchanged: the picker and your transcript still show the readable name, with the addressing part kept out of sight.

What the context breakdown was really telling you

Clicking a session's context meter opened a panel headed "Live breakdown" that wasn't live — it comes from a separate one-shot probe that can't see your conversation, so it reported almost no messages and nearly all the window free, sitting directly beneath a meter reading two hundred and sixty thousand tokens. It's now labelled as what it is: the baseline a fresh session in that folder starts with, before anything is said. The two rows that only ever described the probe are gone, and the rest — system prompt, tools, memory files — are the ones worth seeing.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Foreman v1.4.0

v1.4.0
Sessions can talk to each other

Two agents working on the same problem had no way to reach each other — you were the wire, copying an answer out of one transcript and pasting it into another. Type @ in the composer now and you get every other Claude session running on that machine, Foreman's own and the ones you started in a terminal; pick one and your message is delivered to it as a real prompt, with the @Label staying readable in your own transcript. What arrives on the other side is drawn as its own card, not as a user bubble — it says who sent it, from which project, and under which permission mode, because a session that suddenly starts working deserves an on-screen answer to "who asked it to?". The canvas draws the traffic as an edge between the two sessions, and when a reply landed in the recipient's own transcript instead of coming back, the edge offers to ask it to send the answer along. Every session can decide what it accepts: the default matches Claude Code's own rule — a message auto-delivers only between sessions running the same permission posture — and you can widen or close that per session from its gear menu, or for everything you create next in Session defaults.

What each session says it's doing

A session card told you "Running" or "Idle" and nothing else, which for a fleet of them is barely more than a light being on. Claude Code can summarise its own state — what it's working on, and what it's waiting for when it's blocked — but only while something is watching for it, so there's now a switch in Appearance that turns that on. Cards and canvas nodes then carry a line in the session's own words, and a blocked one says what it needs from you in amber, which is the thing Foreman genuinely cannot work out for itself: the CLI reports a turn that ended in a question as finished, because it is. It's off by default and says why in the setting itself — the signal is per machine rather than per session, so switching it on covers every Claude session on that laptop and costs each of them a small extra model call at the end of every turn, on your plan.

Attach a file, or paste something enormous

Pasting a long log or a stack trace into the composer buried the conversation in it, and then quietly re-sent the whole wall as context on every turn afterwards. A paste past about twenty thousand characters now becomes an attached file instead, which the agent opens when it needs it and pays for once. Files can be dragged into the composer or picked outright, with image thumbnails; for a session on your own machine nothing is copied at all — the file is referenced where it already lies, so there's no size ceiling and no wait. Sending to another laptop does have to move the bytes, so it's bounded, with a lower ceiling for relay-connected machines where an oversized transfer used to be able to drop the connection rather than just fail. Anything big enough that the agent will only read part of it says so on hover.

Choosing a model without guessing

The model menu was a flat list mixing family aliases with every exact build the CLI knows about, which grew ugly as fast as the model lineup did. It's now one row per family — Fable, Opus, Sonnet, Haiku — where picking the row means "the latest build of it", and expanding it pins a specific version, newest first, with the row holding your current choice already open. "Default" is now labelled "CLI default", since in a menu of model names it read like a model rather than "don't pass one at all". Alongside that, a reasoning-effort level that the newly-picked model doesn't actually offer is cleared instead of being sent anyway, and clicking inside a submenu no longer dismisses the menu you opened it from.

Deleting a session deletes it

Removing a session offered a checkbox to "also delete the on-disk transcript", off by default, which read as the careful choice and wasn't: checkpoints and attachments went either way, and the transcript it spared became unreachable the moment the record pointing at it was gone. There's one road now, and the dialog spells out everything that goes — the conversation, including Claude Code's own history, so claude --resume won't find it in a terminal either, plus every rewind point and any files you attached. Usage and Insights survive, because cost history doesn't depend on the session still existing.

Smaller things

When Foreman's servers rejected this machine's sign-in, the app kept using a stale cached plan and left you looking at features you no longer had; it now clears the cache and signs out properly, so the state on screen is the state you're actually in. The Load Context tabs had the handoff and memory icons the wrong way round.


macOS, Apple Silicon. Signed with a Developer ID certificate and notarized by Apple — opens normally with no Gatekeeper warning, and in-app silent auto-update is enabled.

Changelog — Foreman for Claude Code and Codex