What’s new
Every release, and what it actually changed for you. Newest first.
1.7.3
23 August 2026 · tag v1.7.3
Nabu can look at the computer it is running on. Why is it slow, where did the disk space go, what is that process, why does the connection keep dropping — the questions a chat window cannot answer for you no matter how good the model is, because the answer is on *your* machine and nowhere else.
- Nabu can check things about your computer, and it does not ask you eight times to do it. Working out why a machine is slow is a dozen small observations in a row, and until now every one of them went through the same door as "run this command" — a dozen permission dialogs before you learned anything. Nabu now has a fixed set of eight things it can look at: the system and how long it has been up, disk space, which folders are eating it, what is loading the processor and memory, memory pressure, what starts with the system, what crashed recently, and the network. Those it just looks at, and tells you what it found.
- It cannot ask to run something instead. The reason it stopped asking is not that we decided some commands are safe — it is that there is no longer anywhere to put a command. Nabu picks *which observation* from the list of eight; there is no field for it to write into, no shell involved, and an id it made up is refused rather than falling back to running something. An observation that does not exist on your system says so instead of failing.
- Twelve new playbooks, and a Computer section to keep them in. Six about the machine (why it is slow · where the space went · an app keeps crashing · what is this process · the connection drops · a full check-over in three steps), four about money and paperwork (receipts into a spreadsheet · what am I paying for every month · documents for a tax return · a warranty archive), and two about turning data into a report — which was the thinnest area we had, with five playbooks out of forty-seven. Fifty-nine in the library now.
1.7.2
8 August 2026 · tag v1.7.2
Four small things, all the same complaint: Nabu was not showing you what you are using or what you are paying for.
- How much of your allowance is left is now next to the chat. On a plan where the models are included there was nothing on screen about it — the spend counter is only for people using their own API key — so "you've reached your limit" arrived with no warning on the way. There is now a quiet
Max · 34%where that counter sits, which turns amber and then red as the allowance goes. Clicking it opens your plan. - Let Nabu pick the model is a button now. It was a line inside the model menu, so you only found it if you opened the list and read to the end. It sits next to the model name as an "Auto" switch; while it is on, the model button names whichever model answered last, and choosing a model from the list pins that one and switches Auto off.
- The plan table compares all four plans. It used to be Free against Pro, with the three paid plans folded into one column — so someone on Pro had nothing telling them what Max adds. Free · Pro · Pro+ · Max, the rows where they actually differ first, and the column you are on is marked.
- Your plan badge said someone else's plan. Everyone paying saw "Pro · Supporter" in Settings — the name of one particular plan, shown to all of them. On Max it sat directly above a line reading "Max · Monthly", which is a strange thing to read about your own account.
1.7.1
7 August 2026 · tag v1.7.1
Mostly Windows. There has been a Windows build for a while, but nobody had ever run it — and when someone finally did, four separate things were broken in ways that only Windows can break them. Also in here: two places where Nabu was telling you something untrue.
- Windows works now. Signing in failed outright, because Nabu's own network calls went through a path that ignores Windows' proxy settings and its certificate store — so a machine with corporate networking or antivirus that inspects traffic could reach the internet in every browser and not from Nabu. Everything Nabu does over the network now goes through the same stack the browser uses.
- Stop works on Windows. Stopping a long command, or letting it time out, relied on a way of ending a group of processes that simply does not exist on Windows: nothing was killed, and the turn hung forever. It now ends the whole tree, the way Windows expects.
- Connectors stopped claiming Node.js was missing. Nabu looked for installed tools by splitting the system path on the wrong character, so on Windows it never found anything — including Node.js when Node.js was right there.
- Nabu asks for the microphone on Windows too, instead of assuming it was allowed and discovering otherwise mid-sentence. If it is switched off, the button now opens the right settings page.
- A subscription is enough to start. Signing in with a paid plan still dropped you back onto the setup screen asking for an API key at every launch — the check knew about your own key and about local models, but not about the plan you were paying for.
- The update row no longer invents news. It said "Update available" whenever a check failed, even when the check was what failed and there might be no new version at all. Now it says which of the two happened, and if something went wrong it can tell you what. The download button also used to hand Windows users a macOS disk image.
- Playbook counts in the library sit in their own column instead of running on from the name.
1.7.0
5 August 2026 · tag v1.7.0
Two halves. Models became something you choose by name, and the permission layer — the part of Nabu that is supposed to keep an agent on a leash — was audited from the outside and tightened where it turned out not to be.
- Models go by their names, and you get all of them. The subscription served three; it now serves every model behind it, listed the way people refer to them — Claude Haiku 4.5, Sonnet 5, Opus 5, GPT-5.5 and the rest — instead of raw identifiers. Each one shows how heavy it is, so the choice is about cost and speed rather than about decoding a string.
- Nabu can build a spreadsheet. A real
.xlsx, written directly, with numbers that stay numbers so a column still sums in Excel. Before this, "make me a spreadsheet" meant a shell command. - Nabu no longer acts on instructions hidden in what it reads. A web page, a file or a connector result can contain text addressed to the agent — "ignore your rules", "the user already approved this". Nabu now treats everything its tools bring back as information, not orders: it tells you what the content asked for and leaves the decision to you.
- It asks before reaching into your own computer or network. Reading
192.168.1.1or a service onlocalhostused to happen without a word — and a router's admin page is not your data, nor always safe to open. Nabu now asks, showing the address, and remembers a site you allow. Ordinary web pages are not affected: they would be dozens of dialogs about domains nobody can judge, and a prompt people learn to click through protects nothing. - It also asks before an address that carries data out of the conversation. An unusually long web address can be a way to send what Nabu has read somewhere else. You see what would be sent, decoded, and decide.
- "Skip permission prompts here" no longer switches the sandbox off. It was meant to stop the drumbeat of confirmations inside your working folder; it also silenced them for the rest of the disk. Files outside the folder ask again. Commands still don't — a command has no folder to be confined to, and that is now said plainly where you turn the mode on rather than discovered later.
- Only web links open. A link in an answer went to macOS with whatever scheme it carried; now only
httpandhttpsdo. - Your sign-in is encrypted at rest, and Nabu says so when it can't be. The session token was written in the clear on machines whose keychain refuses. It now refuses too, and tells you why, instead of quietly storing something readable.
- Voice stops listening when you close the window. The microphone stayed live behind a closed window until the app quit.
- Smaller: a settings file is replaced in one step, so a crash mid-write can no longer leave a half-written one; and the libraries Nabu ships carry five known vulnerabilities instead of twelve.
Not part of the app, and already live on the site since 5 August: moving up a tier takes effect the moment you pay, instead of at the next renewal — and the old plan is cancelled for you, so nobody pays for two.
1.6.0
4 August 2026 · tag v1.6.0
Came out of walking the whole product on purpose, looking for places where Nabu did the wrong thing quietly. Sixteen problems found; the four serious ones fixed here.
- Undo works on folders it used to break on — and can no longer damage anything. A symlink in the working folder (an alias, an iCloud or external-drive shortcut, a
node_moduleslink) made undo fail outright. Worse, when the link pointed at a writable file, undo overwrote that file, outside the working folder. Snapshots now leave links alone and a restore refuses to write through one. - The working folder is a real boundary again. "Inside" was decided by comparing text, so a link pointing outward looked inward and reading and writing beyond the folder happened with no prompt at all. Nabu now asks the filesystem where a path really leads, and a prompt raised by a link shows the real destination.
- Permission prompts no longer vanish after Nabu opens a web page. One page view sent every later prompt to an invisible window, so a turn waited forever for a decision nobody was shown. The same fault silently broke hands-free voice, model-download progress and connector status for the rest of the session.
- A turn can no longer hang with nothing to say. If the model goes quiet mid-answer, or anything fails before the request leaves — a key the keychain will not decrypt, for instance — Nabu says what happened and ends the turn. Stop also frees a turn waiting on a permission decision.
- PDFs in the working folder can be read. Previously only a PDF dragged into the chat could be. A scan with no text layer says so and points at the chat instead.
- Search stops answering "no matches" when it skipped something. Files too large to search were passed over silently; it now says how many it did not look at.
- Signing out says why, instead of looking exactly like a first launch.
- Smaller: links are marked as links in folder listings, sizes read as "53.9 MB" rather than a raw byte count, and the undo dialog agrees in number.
1.5.1
3 August 2026
No features and no fixes: a deliberately empty release, published to exercise the update path itself end to end. Keeping it identical to 1.5.0 meant that if anything misbehaved, the mechanism was to blame and not new code. The update arrived on its own and installed — the first proof that it works.
1.5.0
30 July 2026 · tag v1.5.0
- Signed with an Apple Developer ID and notarized. Opens like any other app: no warnings, no trip through System Settings.
- The microphone is asked for once, ever. Every earlier update reset that permission, because a temporary signature gave macOS no way to recognise the new build as the same app.
- Updates install themselves. Nabu checks shortly after you open it, once a day, and when your Mac wakes; it downloads in the background and offers to restart. If that path fails it falls back to a plain browser download rather than leaving you stuck.
- Last version that had to be installed by hand: macOS refuses to apply an update whose signature does not match the running copy, and every build before this one carried a temporary signature.
1.4.5
29 July 2026
- Nabu tells you when a new version is out — a quiet chip, and a browser download, because installing an update itself needed a certificate it did not have yet.
- Leaving the app open no longer keeps a lapsed subscription alive; the plan is re-checked while it runs, with a two-week cached answer so offline work keeps working.
1.4.4
29 July 2026
- macOS finally remembers that you allowed the microphone. Every build until now carried Electron's own signature rather than Nabu's, with the app's Info.plist outside it — and macOS records a permission against an app's identity, so there was nothing to record it against. This was the bug behind four releases of "I already allowed this".
1.4.3
29 July 2026
- Opening Nabu twice raises the window you already have. Before, a second launch started a second Nabu, and the two shared one set of chats and one microphone with nothing keeping them apart.
- An honest plan badge: Free / Pro / Pro+ / Max, instead of one word for every paid tier.
1.4.2
29 July 2026
- Talking to Nabu looks like Nabu. The voice overlay shows Nabu's own mark instead of a blue circle, the conversation stays readable behind it, and each phase is recognisable without reading a label.
- A voice session that fails now says what went wrong.
1.4.1
29 July 2026
- Talking no longer asks for the microphone over and over. A conversation used to release the microphone after every reply and ask again for the next one. Nabu now holds it for the whole conversation and simply stops listening between turns; dictation shares the same hold.
1.4.0
29 July 2026
- Three models on Pro+ and Max, not one — a fast, a balanced and a heavy one, by name, in Settings or per chat. The heavier ones spend the allowance faster and the app says so, without ever showing a token count or a price.
- Let Nabu choose on the managed plans too, and the reply says which model answered.
1.3.0
29 July 2026
- Your work belongs to your account. Chats, projects, memory, playbooks and settings — including your API key and the folders you granted — are kept per account. Sign in as someone else on the same Mac and you get a clean app, not their conversations; sign back and everything is where you left it.
1.2.0
28 July 2026
- Nabu can explain itself — ask how projects, playbooks, undo, voice, connectors, memory, models, plan mode or settings work and it answers from Nabu's own help instead of guessing.
- Skip the permission prompts in one chat, from that chat's ⋯ menu, for a long run of similar work.
1.1.0
27 July 2026
- Paid tiers: Pro ($9/mo, bring your own key), Pro+ ($19/mo) and Max ($49/mo) with models included.
- On-device voice: dictation, spoken replies and hands-free mode, with speech recognition running locally — your voice never leaves the machine.
- Projects — chats grouped by the work they belong to.
1.0.0
19 July 2026
First public build. Files, terminal and the web, with every step shown, a prompt before anything risky, and one-click undo.