Changelog
Release notes listed newest first. Published releases are available on GitHub Releases.
v0.3.1
This entry combines the changes introduced in v0.3.0 and the release fixes in v0.3.1.
Languages and Accessibility
- Added application translations in 24 languages, covering the interface, desktop dialogs, browser controls, workflow feedback, and exported security reports.
- Added a first-run language prompt, bilingual language names, and language-specific plural and number formatting.
- Added right-to-left layouts for supported languages while keeping URLs, protocol syntax, and technical viewers readable left to right.
- Improved keyboard navigation, modal focus handling, visible focus indicators, and translated layouts.
HTTP History, Search, and Scope
- Added seek-based pagination, bounded table caches, and visible-page prioritization to reduce memory use and unnecessary work in large histories.
- Removed the loaded-row ceiling from filtered history browsing; additional results are fetched as needed rather than retained together in memory.
- Stabilized row selection, inspected requests, column sizing, and scroll position while new traffic arrives or background refreshes complete.
- Improved live reconciliation when responses change whether a request matches the active filter, including requests outside the currently loaded window.
- Fixed stale scope settings, show-all scope behavior, and manual HTTPQL queries being overwritten by header filters.
- Added the HTTPQL
is_nulloperator for missing-response filters and corrected short Unicode body searches. - Added pinned Search queries, HTTPQL field suggestions, and pagination controls for results beyond the first page.
- Added saved-filter import and export, and improved selected-request exports and history context actions.
Replay, Automate, and WebSocket Testing
- Added project cookie jars with per-session selection in Replay.
- Made Match & Replace application optional for Replay requests and sequences, and added controls for preserving or recalculating Content-Length.
- Added per-session undo, request search, request-file saving, a GET/POST toggle, and target synchronization when pasting raw requests.
- Improved Replay tab shortcuts, request-draft preservation, and attempt selection when opening sessions.
- Added redirect following, response-side Match & Replace processing, payload alignment, a column picker, and bulk deletion in Automate.
- Added placeholder creation from selected request text and hexadecimal payload support.
- Improved WebSocket interception and browser message sending, prevented reconnects after an intentional disconnect, and bounded transcript rendering.
- Improved live SSE history refreshes, filtering, deletion, and WebSocket connection highlighting.
Embedded Browser and Proxy
- Fixed the blank embedded-browser pane caused by an Electron rendering regression and updated Electron to 44.4.5.
- Added website HTTP authentication prompts and proxy-aware handling for authenticated WebSocket upgrades.
- Preserved connection-bound NTLM and Negotiate authentication and native popup contexts used by SSO flows.
- Added TLS client-certificate selection and ensured configured identities are presented to upstream targets and specialized probes.
- Added browser authentication controls and passkey account selection, with credential use restricted to trusted domains.
- Added optional per-instance proxy username and password authentication, with automatic credential handling in the embedded browser.
- Added a network-interface picker for proxy listener addresses and Linux transparent HTTP/HTTPS proxying gated on the required privileges.
- Preserved HTTP/2 request trailers during upstream forwarding and expanded HPACK regression coverage.
Workflows and AI Assistant
- Added workflow creation and testing through AI assistant conversations.
- Added cross-workflow node copy and paste, HTTPQL preset filters, a resizable node configuration panel, and a full URL-encoding mode.
- Allowed structurally incomplete workflows to be saved while keeping validation feedback available for testing and execution.
- Reduced repeated graph serialization and polling updates, and improved node configuration and run-comparison state handling.
- Fixed project switching so Replay drafts are saved and Automate results, workflow execution details, Sitemap, and Search do not retain stale project state.
MCP and Agent Workflows
- Added durable assessment checkpoints and a recovery timeline so agents can resume work after losing context.
- Added bounded tool discovery, exact contract lookup, compact Replay contracts, and actionable follow-up information while keeping the full tool list available.
- Updated MCP tool listings to preserve the protocol-required result type supplied by rmcp.
- Improved background-tab input, active-tab synchronization, browser snapshots, JavaScript dialogs, storage operations, and download metadata.
- Preserved primary finding evidence when linking supporting requests and added persisted WebSocket conversations for evidence workflows.
- Improved Match & Replace tool contracts, request-body searches, scope declaration, sitemap results, and long-running passive scan progress.
- Reduced redundant project lookups and browser health probes, and retained execution receipts across uncertain sends and session recovery.
Project Data and Interface Reliability
- Improved project activation so stale list responses cannot restore the wrong active project.
- Added local-filesystem paths for saving and importing project backups, and a backup-management interface.
- Added Markdown and fullscreen finding descriptions, complete-project finding exports, and project-prefixed export filenames.
- Improved Sitemap navigation, path display, persisted expansion state, and endpoint details.
- Added collapsible navigation groups, additional appearance themes, shortcut import/export, and a CodeMirror editor for custom JavaScript and CSS.
- Reduced unnecessary allocations, repeated list refreshes, local-storage writes, and heavy syntax highlighting across the interface.
- Fixed stale plugin commands, file-upload and deletion state, export polling, scanner settings, and generated finding notifications.
- Improved startup progress, desktop window geometry, quit dialogs, and recovery from partially migrated databases.
Build and Release
- Migrated application metadata to OgmaBox and updated compatible frontend and Rust dependencies.
- Bounded generated release notes so the first release in a new repository cannot exceed GitHub's description limit.
- Fixed retries to reuse existing draft releases instead of attempting to create them again.
- Restricted Linux capability helpers to Linux production builds while retaining cross-platform unit-test coverage, fixing the macOS and Windows compilation errors found during the v0.3.0 build.
v0.2.20
HTTP History and Scope
- Restore cached rows and scroll position immediately when returning to a long HTTP history, without waiting for background refresh requests.
- Add persistent controls for URL truncation and inline query display, while preserving table row heights and column widths.
- Add a request-to-scope preset menu directly in HTTP history.
- Apply ordered scope rules consistently and refresh active history when scope settings change.
Workflows
- Keep passive workflow execution and run logs tied to the project that captured the request.
- Stop downstream workflow nodes when an HTTPQL condition does not match, while preserving explicit true/false branches and conditional joins.
MCP and Browser Automation
- Fill individual inputs or multiple form fields using snapshot element references, with submission kept explicit.
- Add focused browser snapshots, text search, bounded output, and changes-only snapshots that include updated values and states.
- Let browser actions optionally wait for an expected outcome and return a compact observation.
- Support consistent explicit and snapshot-derived tab targeting across browser actions, waits, and dialogs, and report the tab used.
- Unify request editing inputs across direct sending and replay, including compatible request identifiers, header formats, and text, JSON, or base64 bodies. Preserve duplicate headers and exact raw HTTP bytes.
- Add tools to read paginated WebSocket replay transcripts and disconnect replay sessions.
- Return compact structured results with output schemas for commonly used tools, while retaining compatibility text and optional detail.
- Return browser screenshots as native MCP images, preserve form validation and submit handlers, and include controls beneath ignored accessibility nodes.
- Honor navigation and wait timeouts, improve browser logs, report missing selectors and unavailable resources correctly, and retain bounded API error diagnostics.
Replay and Proxy
- Preserve edited raw HTTP framing end to end, including malformed CRLF sequences, and retain raw requests in replay attempts.
- Expose diagnostic details when a WebSocket replay handshake is rejected or returns an invalid accept value.
- Decode complete multi-member gzip bodies and repeated Content-Encoding headers.
- Keep plugin-modified request targets and Host headers consistent, and preserve zero Content-Length headers through upstream proxies.
Application Fixes
- Preserve environment editor values after saving.
- Keep plugin tabs tied to the selected plugin and prevent cleared logs from reappearing through stale responses.
- Recover export polling after transient API failures and discard stale pagination results after refreshing the export list.
- Return saved OAST settings when changing listener ports.
- Clear MCP loading state after superseded status requests.
v0.2.19
Released 2026-09-08 · GitHub release
WebSocket Replay
- Added managed connection modes for Socket.IO 3/4, GraphQL graphql-transport-ws, and legacy graphql-ws.
- Added configurable Socket.IO namespaces, authentication payloads, and GraphQL connection parameters.
- Added protocol initialization, acknowledgement handling, heartbeat responses, and clearer authentication and initialization errors.
- Start independent Socket.IO connections without reusing captured browser session IDs.
- Fixed plain ws:// connections to use the standard HTTP Upgrade handshake.
- Prevent stalled sends from blocking other sessions and keep disconnect operations cancellable.
- Fixed connection-status synchronization and missing final messages when connections close.
- Corrected API limits that rejected otherwise valid large text and binary messages.
- Added indexed, gap-free transcript pagination to prevent missing messages during active capture.
HTTP/2
- Enabled browser-facing HTTP/2 negotiation with HTTP/1.1 fallback.
- Stream responses without waiting for the entire body, improving handling of long-lived responses and concurrent streams.
- Forward large responses completely while limiting the amount retained for capture.
- Preserve partial captures when responses are cancelled.
- Reject oversized requests instead of forwarding an empty request body.
- Correctly combine split HTTP/2 cookie headers when forwarding to HTTP/1.1.
- Preserve response trailers in stored Replay attempts and expose them in response inspection.
HTTP History
- Added independent desktop windows for inspecting captured requests and responses.
- Preserve scroll position when navigating between HTTP History and Replay.
- Fixed single-request actions and Shift-click range selection.
- Added progress feedback while deleting all history entries.
- Give request URLs a full-width row for easier reading and selection.
- Made hexadecimal display independent of the headers/body section selection.
- Fixed compressed body previews by decoding content before applying byte ranges.
HTTP Replay
- Added an expandable JSON tree view for responses.
- Extended hexadecimal editing to the request line, headers, and body.
- Made control characters visible and editable in Raw mode, with corresponding clipboard handling.
- Preserve attempt status information after loading saved sessions.
- Keep Replay statistics isolated to the selected session.
Workflows and Match & Replace
- Restored workflow execution across header, path, query, request-line, response-line, and status-code transformations.
- Added HTTPQL-based matching previews with total counts and query-error feedback.
- Prevent saved rules from being unintentionally changed when loaded into the editor.
- Correctly parse complete header lines when applying Add Header rules.
- Decode compressed response bodies before passing them to conversion workflows and update body-related headers after transformation.
Findings and Endpoints
- Added Delete All for findings across the current project, independent of visible-page limits.
- Refresh finding totals, severity counts, and sidebar badges without reloading.
- Retain HTTP evidence referenced by findings and endpoints after clearing HTTP History.
- Added individual and project-wide endpoint deletion.
- Added individual and project-wide WebSocket history connection deletion.
Notes and Scanner
- Added direct sidebar access to Notes, in-note search, and Markdown formatting and save shortcuts.
- Isolated persisted notes between projects within the same workspace.
- Added workspace-wide controls for endpoint generation, scanner findings, and OAST listeners.
- Added persistent controls for individual passive rules and default active checks.
Build and Release
- Pinned Rust to 1.98.1, refreshed compatible Rust and frontend dependencies, and upgraded electron-builder to 26.15.3.
- Fixed strict pnpm installation failures caused by the unused electron-winstaller build script.
- Corrected Linux container PATH handling, macOS packaged-resource detection, and the shutdown smoke-test assertion.
Regression Coverage
- Expanded coverage for HPACK decoding, HTTP/2 streaming, WebSocket compression, TLS fallback, managed protocols, and transcripts containing 25,000 messages.
- Added regression checks for the affected interface behavior and direct release publishing.
- Verified Linux dependency installation in native x64 and emulated ARM64 containers.
v0.2.13
Released 2026-09-01 · GitHub release
New
- Added 18 standard application themes, including dark, light, Solarized, high-contrast, Arctic, Forest, Ember, Mist, and system-controlled themes.
- Added expanded UI and code font selection with bundled JetBrains Mono, Fira Code, and Source Code Pro fonts.
- Added live syntax highlighting and font previews in Appearance settings.
- Added managed background MCP execution without opening a terminal window.
- Added recent MCP stdout and stderr diagnostics to the MCP settings page.
- Added authenticated desktop lease monitoring to detect and terminate orphaned backend processes.
- Added graceful backend shutdown covering proxy listeners, terminals, MCP processes, and other runtime resources.
- Added lifecycle smoke testing for native Linux, macOS, and Windows builds.
- Added multi-architecture updater metadata for Windows, macOS, and Linux.
Replay
- Replay sessions now retain independent request templates when created from HTTP History.
- Replay sessions continue working after their original HTTP History entries are deleted.
- Deleting HTTP History now detaches Replay sources without deleting Replay sessions.
- Selecting a Replay attempt now displays the exact request and body used for that attempt.
- Re-selecting an attempt reliably refreshes its request and response details.
- Truncated captured request bodies now produce a clear Replay error instead of sending incomplete data.
Workflows
- response.getBody().toText() now transparently decodes compressed response bodies, including Brotli content.
- Chunked and encoded web assets can now be written to disk in their decoded form.
- Raw encoded bytes remain available through response.getRaw() when the original representation is required.
- Added coverage for large decoded workflow responses without silently truncating their contents.
HTTP History
- Full request URLs now wrap instead of being truncated with ellipses.
- Partial URL selections can now be copied without replacing the clipboard with the complete URL.
- Copying selected request or response content no longer triggers the table-level copy handler.
- Added safe handling when clipboard events have no target element.
- Response headers now have an independent scrollable area.
- Resizing a table column no longer accidentally sorts that column.
Desktop Reliability
- Fixed orphaned ogma-server and MCP processes after closing Ogma on Windows.
- Windows shutdown now terminates the complete backend process tree when graceful shutdown is unavailable.
- Fixed the Linux quit dialog failing to appear or leaving the application blocked.
- Added a native fallback when the custom quit dialog cannot load.
- The embedded browser now discovers and uses the proxy port selected by the backend.
- Improved cleanup of active TCP sockets and stable UI proxy listeners.
- Portable Windows builds no longer incorrectly offer installer-based in-place updates.
- Restored the correct Ogma application icon for Windows installers and executables.
- Standalone browser windows and quit dialogs now follow the selected Ogma theme.
v0.1.9
Released 2026-08-24 · GitHub release
HTTP history, intercept, and replay
- Improved HTTP history persistence, filtering, notes, request selection, and large-project performance.
- Fixed navigation cases where captured history could appear to disappear after changing views.
- Improved “Send to Replay” so the newly created replay request is selected immediately.
- Expanded replay editing, templates, placeholders, payload processing, and request execution reliability.
- Improved intercept behavior, request handling, custom rules, exports, imports, and project data consistency.
- Added database indexes and migrations to keep history, findings, replay, workflows, and project operations responsive as data grows.
WebSocket testing
- Improved WebSocket history and replay workflows end to end.
- Expanded replay session handling, message editing, timing, connection lifecycle handling, and error reporting.
- Added
permessage-deflatecompatibility for compressed WebSocket traffic. - Improved WebSocket replay persistence and project isolation.
Browser and certificate setup
- Improved the built-in Ogma Browser experience and proxy integration.
- Added stronger local CA handling for HTTPS interception in the built-in browser.
- Reworked the certificate experience with a dedicated installation guide.
- Added platform-specific certificate instructions for Android, Chrome, Firefox, iPhone/iPad, Linux, macOS, and Windows.
- Added branded platform icons, copyable command blocks, and consistent Ogma branding in browser and certificate screens.
Projects and sessions
- Added in-app save-location selection for projects and session backups.
- Improved Save Session As, open-project, backup-and-quit, and restoration workflows.
- Improved recovery of temporary sessions and persisted assessment data.
- Expanded project export/import behavior and session consistency across HTTP, WebSocket, replay, findings, and workspace state.
MCP and AI-assisted testing
- Expanded MCP capabilities and reliability for AI-driven penetration testing.
- Improved MCP configuration, endpoint management, persistent state, transport handling, and error recovery.
- Improved automation, workflow execution, authentication journeys, active/passive scanning, OAST, discovery, and environment-variable handling.
Interface and desktop experience
- Improved navigation responsiveness, workspace warm-up, loading states, and theme consistency.
- Improved browser navigation, menu behavior, modal layout, quit flow, and startup behavior.
- Updated branding across Ogma Browser, certificate guidance, About Ogma, and inspection interfaces.
- Added a refined session save interface and improved accessibility of larger desktop dialogs.
Desktop packaging and releases
- Improved Linux, macOS, and Windows release packaging.
- Fixed architecture isolation so each CI job packages only its intended CPU architecture.
- Fixed macOS DMG packaging conflicts.
- Made code signing explicitly opt-in and prevented empty certificate values from breaking unsigned builds.
- Replaced shell-dependent release-version handling with a cross-platform Node script, fixing Windows release JSON corruption.
v0.1.5
Released 2026-08-15 · GitHub release
HTTP History
- Fixed selected rows collapsing columns during inspection.
- Kept rows anchored during live updates and retained inspected rows at the window limit.
- Improved batch update handling for sustained traffic.
- Preserved bulk selections during capture.
- Reconciled missed live updates.
- Stabilized paginated request ordering and corrected paged statistics.
- Expanded the table to use the available container width.
Replay
- Added structured request pretty rendering.
- Preserved edits when switching between request views.
- Synchronized query parameter editing correctly.
- Accepted valid header spacing during replay editing.
Settings and Appearance
- Added more font customization presets and font previews.
- Improved editor font fallback behavior.
- Hardened custom JS settings save/reset flows.
- Cancelled pending CSS apply timers on reset.
- Restored community links in About.
- Fixed log path handling across platforms.
Findings, Exports, Files, and Search
- Kept findings pagination valid after deletions and preserved filters after visible bulk updates.
- Fixed findings badge sync across project switches and imports.
- Improved export validation and filename handling.
- Cleared stale file edit buffers when switching files.
- Prevented redundant Search remounts and kept route query updates stable.
Environment and Scope
- Fixed environment variable interpolation and scope isolation per project.
- Restored workspace-scoped global env vars.
- Kept utility query state when switching tabs.
UI and Plugins
- Kept request icons colorful and trimmed noisy request metadata.
- Improved plugin metadata links and duplicate command dispatch handling.
v0.1.4
Released 2026-08-11 · GitHub release
Authenticated Browser Journeys
- Added reusable authenticated browser journey profiles.
- Record and replay login sequences.
- Verify authentication using URLs, DOM state, cookies, or HTTP requests.
- Automatically refresh expired sessions.
- Support manual MFA checkpoints.
- Maintain multiple identities for authorization and IDOR testing.
- Persist journey configuration across application restarts.
- Improve recovery when selectors, navigation targets, or authentication state change.
Schema-Aware API Imports
Expanded OpenAPI 3 support with:
- Request bodies and examples.
- Path, query, header, and cookie parameters.
- Local references and reusable components.
- Security schemes and authentication metadata.
- Server variables.
- Schema-derived values and insertion points.
Added GraphQL introspection import and operation generation.
Added SOAP/WSDL operation and request generation.
Improved Postman variable, URL, body, and authentication handling.
Added schema metadata for type-correct request mutation and automated testing.
Improved format detection and rejection of unsafe external references.
Plugin SDK 1.1
Completed frontend SDK contracts for:
- Request retrieval, raw access, and search.
- Findings.
- Scope.
- Projects.
- Navigation and sidebar integration.
- Backend communication.
- Theme and UI lifecycle.
Added reliable asynchronous SDK initialization.
Added compatibility declarations for Ogma and SDK versions.
Improved plugin permission handling and installation review.
Exposed runtime limits and plugin validation information.
Strengthened plugin runtime isolation and callback failure handling.
Improved Community Marketplace package and registry validation.
Existing unsigned plugins remain fully compatible.
Published @kaijinlab/ogma-sdk@1.1.0 to npm.
Workflow Improvements
- Workflows are now shared across projects in the same workspace by default.
- Project-specific workflows remain supported.
- Restored workflow node details after navigating away and returning.
- Improved workflow selection and editor state restoration.
- Moved workflow action controls below workflow names for a more compact studio layout.
- Increased the usable workspace available to the node editor.
HTTP History Accuracy
- Replaced the misleading inspected state with accurate modification tracking.
- Requests altered by Match & Replace or interception are now identified as modified.
- Corrected HTTPQL filtering when selecting traffic state indicators.
- Improved visual distinction between traffic sources and modified entries.
v0.1.3
Released 2026-08-10 · GitHub release
Run Workflows from HTTP History
- Run active workflows directly from the HTTP History context menu.
- Process single or multiple selected entries.
- Choose from currently enabled active workflows.
HTTPQL-Powered Match & Replace
- Added HTTPQL filters to Match & Replace rules.
- Filter using request and response fields together.
- Response rules can evaluate the associated request method, path, headers, and body.
- Improved named-header matching accuracy and case handling.
Replay Improvements
- Rename sessions using F2 or the context menu.
- Create sessions directly inside collections.
- Move sessions between collections.
- Reorder sessions using drag and drop.
- Move sessions to the top or bottom.
- Send HTTP History entries directly to a Replay collection.
- Delete individual replay attempts.
- Fixed session deletion from the context menu.
- Replaced misleading left/right actions with above/below actions.
- Prevented redundant moves to the current collection.
Workflow Improvements
- Convert workflow executions now appear in Runs and Logs.
- Improved JavaScript line and column diagnostics.
- Added Clear All for workflow run history.
- Workflow connections can be selected and deleted.
- Fixed workflow node renaming.
- Fixed errors when enabling or disabling workflows.
- Testing automatically saves pending workflow changes.
- Test fixtures persist while navigating between views.
- Run history refreshes after test and batch executions.
HTTPQL Fixes
- Named-header substring searches now match values at any position.
- Named-header operators only inspect the selected header.
- Header names are matched case-insensitively.
- Negative operators correctly handle duplicate headers.
- Improved named-header existence checks.
Plugin SDK Fixes
- Fixed sdk.path.join() base-path handling.
- Request paths beginning with a separator no longer replace the base path.
- Added normalization for current-directory and parent-directory segments.
- Preserved platform-specific separators across Windows, Linux, and macOS.
Project Experience
- Removed redundant backup prompts when switching persistent projects.
- Removed redundant backup prompts when closing persistent projects.
- Temporary sessions still warn before closing because their data will be discarded.
- Manual backup and export remain available.
Reliability
- Prevented stale Replay and Workflow context-menu updates.
- Fixed a workflow save timing race.
- Response filters now receive the effective request after interception or modification.
- Improved migration registry validation.
- Added regression coverage across Replay, HTTPQL, Match & Replace, workflows, and plugin path operations.
v0.1.2
Released 2026-08-08 · GitHub release
Workflow Testing
- Added editable HTTP request and response fixtures for active and passive workflows.
- Tests execute through the production workflow engine.
- Test results, step output, and errors are available under Runs and Logs.
- Temporary test fixtures are automatically removed from HTTP history.
- Added Run on history support for active and passive workflows.
- Added
Ctrl+S/Cmd+Sworkflow saving.
Plugin Filesystem and Path APIs
- Added sandboxed
fsandpathmodule support. - Added compatibility methods including:
readFile/readFileSyncwriteFile/writeFileSyncappendFileexists/existsSyncmkdir,list, and related path helpers
- Added destructured imports from
"fs"and"path". - Added protection against directory traversal and symbolic-link escapes.
Match & Replace
- Workflows can now receive and transform the complete HTTP response body.
- Added full-body workflow transformations without forcing literal matching.
Project Management
- Recent projects can now be opened directly from the startup dashboard.
- Added project deletion with an irreversible-action confirmation.
- Projects can be created and imported across different filesystem roots and drives on Windows, macOS, and Linux.
Sitemap
- Background updates no longer unmount or reset the sitemap graph.
- Zoom, pan, collapsed sections, and manually positioned nodes remain stable during refreshes.
- Failed background refreshes preserve the last usable sitemap.
v0.1.1
Released 2026-08-08 · GitHub release
New Features
- Browser MCP automation expanded with a full browser automation layer (214 MCP tools).
- MCP runtime now supports filesystem and path modules (
sdk.fs,sdk.path) for richer automation workflows. - Added new MCP tools for extended AI-driven testing and workflow interoperability.
- WebSocket replay UI improvements:
- explicit replay lifecycle handling in frontend,
- support for replaying first captured message,
- support for replaying captured WebSocket sequences.
- Decoder/utility state is now preserved across navigation:
- input text and recipe draft persistence improvements.
Fixed
- Fixed instance CA download behavior.
- Fixed HTTP history live-update reliability.
- Fixed WebSocket replay disconnect handling and diagnostics.
- Fixed ws replay URL parsing edge cases.
- Fixed ws replay task lifecycle races (connect/disconnect/cleanup/selection flows).
- Fixed duplicate/invalid connect handling in ws replay.
- Fixed oversized inbound frame handling in ws replay.
- Added protection against duplicate reconnect behaviors and stale state.
- Fixed ws replay handshake-cancel race conditions.
- Fixed ws replay send failures and timeline replay action execution.
- Fixed ws replay keepalive behavior:
- default keepalive behavior hardened,
- ping handling improved,
- keepalive timeout handling hardened.
- Fixed desktop temporary session workspace cleanup behavior.
- Fixed desktop session data handling regressions by clearing stale temp workspace state where needed.
- General bug-fix and refactor pass with improved internal stability.
- UI/runtime adjustments to better reflect WS replay connection/state transitions.
Notes
- Focus of this release is primarily WebSocket replay reliability + MCP/browser automation capabilities.
- Packaging/CI behavior has also been corrected to reduce release inconsistencies and improve artifact handling.
v0.1.0
Released 2026-07-19 · GitHub release
Initial public alpha release.
Core proxy
- HTTPS MITM proxy with CA certificate management
- HTTP/1.1, HTTP/2, and WebSocket capture
- HTTPQL query language for filtering history
- Intercept, inspect, edit, forward, and drop requests
- Match & Replace rules with regex, header, body, and query support
- Scope presets with HTTPQL and wildcard support
Replay and automation
- Replay editor with raw HTTP editing and parallel send
- Automate (Sniper, Pitchfork, Cluster Bomb) with payload extractors and matchers
- Race condition testing
- HTTP request sequences with variable chaining
Scanning
- Passive scanner
- Active scanner (SQLi, XSS, SSRF, CMDi, SSTI, path traversal, open redirect)
- Content discovery with 9,300 path wordlist
- Custom passive rules
Utilities
- Decoder/encoder (base64, hex, URL, JWT, hash, crypto)
- Sitemap and extracted endpoints view
- OAST (out-of-band testing) with HTTP, HTTPS, DNS, SMTP listeners
- Compare, Notes, Payloads, Reverse Shell generator
Data and organization
- Project management with named projects and temporary sessions
- HAR import/export, Burp XML import, OpenAPI/Postman import
- Findings panel with CVSS scoring and evidence links
- Exports (CSV, JSON, Markdown, HTML report)
AI and automation
- Integrated AI assistant with 36 built-in tools
- MCP server with 160+ tools for external AI clients
- Headless pentest CLI:
ogma pentest <url> - Visual workflow builder
Plugin system
- JavaScript/TypeScript plugin SDK (
@kaijinlab/ogma-sdk) - Sandboxed backend and frontend plugin execution
- Plugin marketplace with SHA-256 verified installs
sdk.events,sdk.findings,sdk.requests,sdk.storage,sdk.matchReplace,sdk.workflows,sdk.fs
Desktop
- Electron desktop app (Linux, macOS, Windows)
- Built-in Chromium browser (auto-proxied)
- Auto-updater