Changelog
Notable changes to the VibeHost platform, CLI, and API.
Ongoing security hardening across the platform.
Deploy large sites from the browser. Drag-and-drop uploads over 95 MB now go up file by file instead of as one archive, so a site only has to fit the 500 MB total rather than squeeze into a single request. Files you've uploaded before are skipped, so re-deploying a mostly-unchanged site transfers far less. Individual files are still capped at 100 MB.
Drop a folder anywhere to deploy it. The dashboard accepts a drag-and-drop deploy from the apps list, an app page, or the Create dialog, so your first deploy doesn't need the CLI.
The Chrome extension also gets a redesigned popup with dark mode and onboarding, and can deploy a canvas straight from the popup.
Secrets are left out of your deploy. .env files, private keys, and similar sensitive paths are now excluded from static and skill deploys automatically. If your site needs one of those files at runtime, pass --include-sensitive <paths>. Otherwise it won't be in the upload.
Team members hub. Manage members and their roles from one page instead of hunting through workspace settings.
Folders. Group apps into folders, with their own sidebar tab and a visibility filter. Starred is now its own tab. Move apps between folders from the dashboard, the CLI, or MCP. Sharing is still per app: a folder groups apps but doesn't grant access to them.
Folders are rolling out gradually and are enabled per workspace.
Comments you can hold a conversation in. Mention teammates with @ and they get a notification and an email. You can edit, move, and delete your own comments, and reply without leaving the dashboard.
Secret scanning on deploy. VibeHost checks your files for what look like leaked API keys and stops the deploy before anything ships. Override with --allow-secrets when it's a false positive.
Sessions also expire sooner. Access tokens go from 30 days to 24 hours, and refresh tokens from 90 days to 30 days. The CLI refreshes in the background, so day-to-day use is unaffected. If you set VIBEHOST_TOKEN in CI, switch to a personal access token, because a session token now expires after 24 hours. vibehost doctor warns when it sees one.
CLI v4.9.0. Work through comments from the terminal. vibehost comments pull fetches open feedback on a deployed app, and vibehost deploy --resolves <ids> marks those threads addressed as soon as the fix goes live. It's meant for coding agents that loop through review, fix, and redeploy.
Notifications. Deploy results and access requests now reach you in the dashboard instead of going unannounced, and each row links straight to whatever it's about. Comment and mention notifications followed in early July.
Extension v1.2.0. App display names and descriptions now sync across the Chrome extension, CLI, dashboard, and API.
CLI v4.8.0.
- Deploy plain Express/Node.js apps on the Node runtime, not just static sites and Next.js.
- Add a free Neon managed Postgres database to your app.
- Upstash Redis is available as a provider-agnostic managed storage layer.
- Comment mode lets you pin feedback directly on live deployed apps.
- Set a display name and description on your apps.
- Server builds now work with pnpm workspace monorepos.
- Configure install and build commands in
vibehost.json.
VibeHost is live. The platform, CLI, and API are generally available, and you can deploy a static site to a private URL. See the quickstart to get started.