Changelog
Changelog
All notable changes to DevKit are documented here. The format follows Keep a Changelog, and DevKit uses Semantic Versioning.
[Unreleased]
Changed
- The macOS app is signed with a Developer ID and notarised by Apple, so it opens without the Open Anyway step.
Added
- DevKit for Windows can be downloaded from getdevkit.app. The installer isn’t signed yet, so Windows asks you to choose More info › Run anyway the first time.
- getdevkit.app has a social preview image: links shared in Slack, iMessage, X or LinkedIn show the share wire from a
.testsite to its public address.
Fixed
- Downloads give up when a server stalls (no data for a minute) or doesn’t answer, instead of showing Downloading forever.
[0.1.0] - 2026-10-11
Changed
- DevKit is proprietary freeware, not open source. The licence, manifests and docs say so.
- DevKit targets macOS and Windows. The macOS app ships first; Windows is in progress.
- Windows (not yet tried on a Windows machine): setup adds one
.testname resolution rule with one administrator prompt and trusts the CA in your user’s certificate store; Remove system changes… undoes both. DNS listens on port 53, a busy port names the program holding it, and Settings › Terminal adds DevKit’sbinfolder to your userPath.
Added
- Serving:
devkitdwith the HTTPS proxy on127.0.0.1:80/443(launchd socket handoff),.testDNS, a local CA limited to.test, PHP through static php-fpm pools, Python through uv and granian, static folders, and any dev command behind a.testaddress. - Runtimes: PHP 8.0–8.5 downloaded on first use; Python versions through uv; Node from nodejs.org with
.nvmrcsupport; per-site PHP or Python plus a separate Node version for project tooling. PHP memory, upload and time limits, and a sharedconf.dfor your own ini files. - Xdebug: a switch per PHP version. DevKit builds
xdebug.soagainst php.net headers the first time, and runs it in a separate pool that only requests with an Xdebug trigger use. - Site processes: queue workers, schedulers and watchers per site, with Keep running (restart with back-off), suggestions detected from the project, logs, and
devkit process. - Services: Mail (Mailpit), MySQL 8.0/8.4/9.7, PostgreSQL 14–18, Valkey (built from source on first use), Meilisearch and RustFS. Several versions side by side with their own data and ports;
.envlines; open in TablePlus, Sequel Ace, Postico or Redis Insight. - Mail: caught mail with per-app inboxes (the SMTP username), HTML, text, headers and source, and SMTP settings for Laravel, Symfony, Django, Rails and Node.
- Dumps:
dump()anddd()from sites, Artisan commands and workers, sent by a php.ini prepend file; no project changes. - Laravel details: queries (with bindings and time, slow ones marked), jobs, rendered views, outgoing HTTP calls and log messages from Laravel apps on the Dumps screen, through DevKit’s own service provider; no changes to
composer.jsonorconfig/app.php. One switch turns it off. - AI tools:
devkit mcp, an MCP server with 19 tools for sites, services, sharing, requests, dumps, logs, mail and Artisan; Settings › AI tools has the setup for Claude Code and other editors. - Menu bar: the icon shows whether DevKit is serving, sharing or stopped.
- Packaging and updates:
DevKit.appbundlesdevkitdanddevkit, is ad-hoc signed, and ships as a DMG for Apple silicon and Intel. Settings › About checks for updates fromdownloads.getdevkit.appand installs signed ones.just releasebuilds the DMG locally. - Licences: third-party notices generated from the dependency trees (
just notices), shown in Settings › About;scripts/check-licences.pyfails the build if a copyleft dependency is linked. - Sharing with Vite: shared Laravel sites load their CSS, JavaScript and fonts (and live reload) from Vite’s dev server through the share.
- Slow queries and requests: the Queries tab filters by time (10, 50 or 100 ms), searches SQL, requests and files, and sorts slowest first; Requests filter by duration.
- Running now filters: group pills with counts and a filter box; Stop all stops only what’s shown.
- Windows PHP (not yet verified on Windows): PHP from windows.php.net checked against its published SHA-256, a pool of four
php-cgiworkers per version on127.0.0.1that are replaced after 500 requests, Xdebug as xdebug.org’s checked DLL, andphp.cmd/composer.cmdshims for the terminal. - Verified downloads: Node and every GitHub-hosted download (cloudflared, Mailpit, PostgreSQL, Meilisearch, RustFS) are checked against their published SHA-256.
- Settings: the Cloudflare token’s permissions as a list;
devkit mcpwithout a path when DevKit is on your PATH; third-party licences as filterable tables. - Tests: the real
devkitdbinary (sites,.testDNS, HTTPS redirect, shutdown), the whole New Laravel site job and the Xdebug build offline, the Composer, cloudflared and Python installers, the app’s real client and screens against the running daemon (just test-live), the Node installer against a local copy of nodejs.org, the daemon API end to end, the CLI and MCP tools against a temporary daemon, Cloudflare and Mailpit clients against local fakes, a real PHP-FPM pool, and UI tests for every screen’s actions (sharing, services, runtimes, processes, mail, requests and sites);just coveragereports both suites. - Garnet on Windows: the Redis-compatible service on Windows, downloaded from Microsoft’s releases and checked against their SHA-256; PostgreSQL there listens on TCP only.
- Windows port (not yet run on a Windows PC): setup with one elevated prompt (NRPT rule for
.test, CA in your user’s certificate store), DNS on port 53, port holders named fromnetstat, PHP from windows.php.net run as a pool of php-cgi workers, Xdebug DLLs, site processes throughcmd,.cmdshims and your userPath, Node’s Windows builds, Garnet for Redis, and an NSIS installer in the release workflow. The test suite runs on Windows in CI, andjust check-windowstype-checks it from a Mac. - Windows groundwork: the daemon’s API over a local-only named pipe, and the whole workspace builds and passes clippy for Windows, checked in CI. Setup, PHP workers and downloads for Windows are still to come (ADR 0015).
- Website and docs: getdevkit.app (Astro and Starlight on Netlify) with the landing page, Terms, Privacy, changelog, licence and support pages, a user guide for every screen, a CLI reference generated by
devkit docs --markdown, ports and files, architecture, security and 14 decision records. - Requests: every request with headers and bodies; tokens and cookies hidden until shown.
- Running now: one panel from the power rail lists every service, PHP pool, app server, process and share with its memory, and stops any or all of them.
- Sharing: quick tunnels with no account, or your own domain through a named Cloudflare tunnel; optional password, IP allowlist (works for both), expiry, and noindex. Shared PHP apps see their public hostname, so assets and redirects work.
- New Laravel site: Add site › New Laravel site runs Laravel’s own installer (starter kit, database, tests, npm, git), then creates the database in DevKit’s MySQL or PostgreSQL (or SQLite), points
.envat DevKit’s mail and HTTPS address, migrates, serves it with HTTPS and can add Vite as a process. Progress shows step by step. - Reverb: a shared Laravel Reverb server at
wss://reverb.test, with generated credentials,.envlines, and Add to site. - Requests: filter by type (pages, fetch/XHR, JS, CSS, images, fonts, media, WebSocket), status, method, path and shared visitors.
- Parked folders: projects created inside them are served within seconds, without a restart.
- Terminal:
devkit php …anddevkit composer …run the folder’s PHP version with DevKit’s ini; optionalphp/composershims on your PATH through a marked block in your shell file; Composer downloaded with its checksum; the Laravel installer installed the usual way so it updates itself. - Tools: regex tester with PHP export, JSON check and format, Base64 (shows images, encodes files), URL, JWT, timestamps, UUID v4/v7 and ULID, MD5 and SHA hashes.
- App: onboarding with real port checks and setup, Settings (parked folders, editor, terminal and database app, recording, open at login, quitting, sharing, removal), menu bar popover with active sites and a filter.
- Repository scaffold: Cargo workspace (
devkit-core,devkitd,devkit-cli) insideapps/desktop, README, CLAUDE.md, contributing guide. - Patch Bay design tokens (
packages/design-tokens): AA-checked colours for graphite and aluminium themes, Recursive type scale, spacing, radii and motion presets. - Icon set (
packages/icons): 39 icons on a 20 px grid, as React components and SVG files. - Brand assets (
packages/brand): logo mark, app icon master, small icon, favicon and menu bar template icons. - Desktop UI prototype (
apps/desktop): app shell with power rail and sidebar, Sites screen with expandable rows and the share wire, menu bar popover, first-run setup, and a design system screen, running against a mocked daemon. - Spikes: unprivileged port binding (launchd socket handoff needed) and FastCGI to static php-fpm (works; 104-byte socket path limit).
Fixed
- After an update, DevKit restarts its background service on the new version instead of carrying on with the old one.
- The website’s Download button scrolls to the download buttons instead of hiding them under the header, and the first-open step matches macOS 15 (Open Anyway in Privacy & Security).
- Docs search works on getdevkit.app: the site’s security policy now lets the search compile its WebAssembly.
- When DevKit’s DNS server can’t open its port, the power rail shows DNS as failed and names the port, instead of showing it running while
.testnames don’t resolve. - Logs name services and site processes as the rest of DevKit does (“MySQL 8.4.9”, “Queue worker for shop.test”), not by their ids.
- Dumps can’t be pushed out by a burst of views or queries: each kind keeps its own latest 500, in the daemon and on the Dumps screen.
- Jobs show on the Dumps screen when they’re queued, not only when a worker runs them.
- Laravel’s HTTP client reaches other
.testsites (PHP’s bundled cURL can’t resolve them on its own). - Laravel apps broadcast to Reverb over loopback; Add to site set a
.testhost that PHP couldn’t resolve. - Quick tunnels come back after Cloudflare drops them, and DevKit shows the new address instead of the dead one. Sharing a site that’s already shared keeps its tunnel.
- Request recording, dump capture and hiding secrets are remembered across restarts; a sharing update no longer resets settings it didn’t mention, such as using your domain.
- Reverb and Mail can be added again from Add a service.
- MCP tool calls check their required arguments;
run_artisantakes a string too. devkit … | headexits quietly instead of panicking.- Starting or stopping a site that doesn’t exist says so, instead of reporting success and leaving settings for that name in the config.
- The Mailpit client no longer depends on the daemon having set up TLS first.
- Screen-reader-only labels deep inside a scrolled pane could make the whole window scroll.
- Generated secrets (such as Reverb’s key and secret) come from the OS random source on every platform; on Windows they would have been all zeros.
just devuses the project’s Tauri CLI, so it works without installingcargo-tauri.- Turning off a service that keeps crashing while it starts takes effect at once; it used to wait for the start timeout (up to 90 seconds).
- On Windows, a PHP request that reaches a php-cgi worker just as it recycles goes to the next worker instead of failing.
- Copy no longer says Copied when the clipboard refused; it says to copy the text yourself.
- Remove system changes says what failed when removal fails or the password prompt is cancelled, instead of nothing.
- Unlinking a site or forgetting its folder stops its app server, processes and share; they used to keep running.
- PHP buffers the first 4 KB of output (
output_buffering = 4096, as standard PHP configs do), so a dump or echo beforeheader()no longer fails with “headers already sent”.