All notable changes to PiP Controller Pro will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
assets/icon.ico, generated by icon-gen.ps1): embedded into the exe (tray + taskbar) via Ahk2Exe /icon and used as the installer icon.LicenseFile wired to LICENSE.txt.lastPiPWindow was tracked but never used for restoration, so when detection switched between two PiP windows (or the window changed mid-hover) the previous window was never restored — and a click-through window can’t be clicked to recover it. The loop now restores the previously controlled window whenever detection changes or disappears.ExitApp saved settings but never restored the controlled window, so quitting while hovering stranded it transparent + click-through with no process left to recover it. Now restores before exiting.ToggleEnabled (off) and Ctrl+Alt+P (pause) stopped the timer mid-hover without restoring the window to opaque + interactive. Both now restore the controlled window before stopping.Reset Current PiP desynced the hover state machine and silently did nothing when no PiP was detected: it now clears the applied-state so transparency re-applies on the next tick, and reports when there’s nothing to reset.MSXML2.XMLHTTP call used default timeouts (60s connect, 30s send/receive) on the script’s only thread — the tray and the transparency loop would freeze for minutes on a bad network. Now bounded with SetTimeouts (3s resolve / 5s connect / 5s send / 10s receive).tag_name rendered unsanitized: the regex operated on raw response bytes, so a MitM could inject control characters into the TrayTip text. The tag is now validated against ^\d+\.\d+\.\d+$ before display.build.ps1 failed to parse under Windows PowerShell 5.1: the file is UTF-8 without BOM and contained em-dashes, which 5.1 misreads as ANSI — one inside a Write-Host string became a stray quote and broke the whole parse (CI never caught it because the workflows use pwsh/PS7). The script is now pure ASCII and builds on stock Windows PowerShell.MouseGetPos), not just inside its rectangle — a window stacked on top of the PiP no longer triggers transparency.release.yml verifies the AutoHotkey zip and Inno Setup installer against hardcoded hashes before executing them in the signing job (which holds id-token: write). Closes the vector where a compromised upstream re-upload would be cosign-signed by our own pipeline.release.yml script-injection hardened: the workflow_dispatch tag input is now passed via env: instead of being interpolated into the pwsh script body.SetTransparency* and 5 SetSpeed* near-identical labels are now two handlers driven by preset tables at the top of the script; the submenus themselves are built in loops from the same tables.WinSet Transparent/ExStyle now only runs on state transitions (and when the transparency preset changes), not on every timer tick while hovering.raw/main/pip-controller.exe, which 404s because the exe is gitignored and not committed — now points to releases/latest/download/pip-controller.exe. Portable zip link updated to v2.2.1 and its size corrected (was “~3 MB”, actually ~0.6 MB). Title version bumped to match VERSION. Files section now lists VERSION, assets/icon.ico, and icon-gen.ps1.RELEASE_NOTES.md regenerated for v2.2.1 (was a full version stale at v2.2.0).2024-01-XX dates to the real release dates, annotated [2.1.0] as never-tagged, and refreshed the Version History Summary through v2.2.1.CONTRIBUTING.md: removed a duplicated ### Building heading.https://api.github.com/repos/joganubaid/pip-controller-pro/releases/latest, compare semver, and surface a TrayTip when a newer version is available. The startup check is silent on success; the menu version always reports the result.SHA256SUMS.txt and per-artifact Sigstore keyless signatures (*.sigstore). Verification instructions are in the new SIGNING.md.main now boots the freshly-built pip-controller.exe and requires it to survive 5 seconds without crashing. Catches runtime regressions that pass the syntax check but blow up on first frame.SECURITY.md: documents the supported version, scope, and the private-disclosure flow via GitHub Security Advisories..github/dependabot.yml: monthly bumps for the github-actions ecosystem so the SHA-pinned actions don’t go stale..github/pull_request_template.md: structured PR description with a per-browser “tested on” checklist.actions/checkout@v6, actions/upload-artifact@v7, softprops/action-gh-release@v3, sigstore/cosign-installer@v4). Removes the Node 20 deprecation timeline and adds supply-chain integrity.release.yml permissions: id-token: write added on the release job so cosign can use the GitHub OIDC issuer for keyless signing.ci.yml PSScriptAnalyzer step: now prefers the copy preinstalled on the windows-2025 runner image and only falls back to PSGallery (with 3x retry + backoff) when the module is missing. Absorbs transient PSGallery flake.main: pushes now go through PRs, require the Validate CI check to pass, and disallow force-pushes / deletions. The maintainer can still hot-push when needed (admins are not enforced).*.exe process names (they’re Chromium-based with the same PiP window title as Chrome).firefox.exe. Detection depends on the Firefox version exposing “Picture-in-Picture” in the window title.Test <Browser> PiP entry for each supported browser. Each one verifies its specific target process instead of all of them returning “any PiP window found”.FindPiPWindowForExe(exe) helper: extracted from FindPiPWindow() so both the unified scan and per-browser test items share one detection path..github/workflows/ci.yml): on every PR / push to main, pinned AutoHotkey 1.1.37.02 is installed and Ahk2Exe runs against the script as a syntax check. PSScriptAnalyzer runs against build.ps1, the VERSION/AppVersion consistency is verified, and the portable build is smoke-tested..github/workflows/release.yml): pushing a v*.*.* tag triggers a Windows runner that installs AHK 1.1 + Inno Setup 6.3.3, builds the executable + portable zip + installer, extracts release notes from the matching [<version>] CHANGELOG section, and attaches everything to a GitHub Release.VERSION file: single source of truth for the version, consumed by build.ps1 (patches the AHK source’s AppVersion line at build time and names the output artifacts) and installer.iss (read at preprocessor time via AddBackslash(SourcePath) + "VERSION").build.ps1 local-compiler fallback: Get-AhkCompiler now also looks at .ahk/Compiler/Ahk2Exe.exe so contributors who drop the AutoHotkey 1.1 portable zip into .ahk/ can build without a system-wide AHK install.build.ps1 explicit /base: Get-AhkBase finds the .bin next to Ahk2Exe.exe and passes it as /base. The portable AHK distribution does not ship with Ahk2Exe.ini, so Ahk2Exe’s default-base lookup fails (“No default Base file specified” dialog). Passing it explicitly also makes the system-installed path more reproducible.Ctrl+Alt+P actually pauses now (regression / never-worked bug): Suspend only disables hotkeys/hotstrings, not SetTimer — so the transparency loop kept running. The handler now toggles the timer explicitly, and Suspend, Permit makes the hotkey survive the suspend so it can also un-suspend itself.ToggleEnabled / ToggleAutoStart previously did Menu, Tray, Rename, Enable/Disable, … against a label that had already been renamed on the first toggle, so subsequent toggles silently failed to update the visible label. Replaced with a single UpdateMenuState sub that tracks the last-applied label in script-level globals.ResetAllSettings left registry stale: the “factory reset” turned the autoStart flag off but never removed the actual HKCU\…\Run\PiPControllerPro registry value the previous “enable autostart” wrote — so the app would still launch with Windows. Now also drops the registry value.ResetAllSettings did not refresh the menu labels: now calls the unified UpdateMenuState sub.TestChrome / TestEdge were misnamed: both handlers called the generic FindPiPWindow() so each reported “any browser PiP” instead of testing its specific target. Now each per-browser test scans only its own ahk_exe.build.ps1 used $args: this is a PowerShell automatic variable (the script’s argument array). Renamed to $compilerArgs.build.ps1 -BuildPortable was not idempotent: rerunning it failed because [ZipFile]::CreateFromDirectory refuses to overwrite. Now it removes the existing zip first and wipes the staging dir so prior builds don’t leak files.Show All Windows tray menu item: the handler was a stub that opened a MsgBox saying “disabled in simple mode” — it had been advertised in the menu, README, and CHANGELOG without an implementation since v2.1.0. Removed for honesty; a real debug-window listing can be reintroduced later if there’s demand..github/workflows/build.yml: superseded by ci.yml and release.yml. The old one used https://www.autohotkey.com/download/ahk-install.exe which now serves AutoHotkey v2 (which cannot compile v1 scripts), and pinned deprecated actions/checkout@v3 / actions/upload-artifact@v3.CONTRIBUTING.md github.com/yourusername/… template placeholder corrected to the real repo URL. Testing checklist expanded to all supported browsers.installer.iss welcome screen no longer says the tool is “for controlling Chrome Picture-in-Picture windows” — broadened to all supported browsers.RELEASE_NOTES.md rewritten for v2.2.0..github/ISSUE_TEMPLATE/bug_report.md browser list updated to include all supported browsers.Note: This version was never tagged or published as a GitHub release; the entries below are retained for history. The next published release after 2.0.1 was 2.2.0.
%AppData%\PiPController\settings.iniHKCU\Software\Microsoft\Windows\CurrentVersion\Run\PiPControllerPro