Skip to content

0.6.2

Choose a tag to compare

@github-actions github-actions released this 12 Aug 08:09
· 9 commits to main since this release
Repo and bundle hygiene for a public repo with real users

Audited the public repo for leaked secrets: all 47 files ever committed, plus
every commit's content, scanned for keys, tokens, certificates, connection
strings and private keys. Nothing found. No repository secrets are configured, so
CI has nothing to leak. Screenshots use Contoso, not real customers.

Hardening, since the repo is public and other people run this:

- .gitignore now blocks Portra's own data and exports (customers.enc,
  portra-export*.json), which contain customer names and admin usernames, and
  signing material (*.p12, *.pfx, *.pem, *.key, .env). None of this was ever
  committed; this stops the first accident.
- Added .github/SECURITY.md so vulnerabilities get reported privately rather than
  in a public issue — Portra holds admin sessions for other people's tenants, so
  a public report exposes them before a fix exists. It also lists the two known,
  documented limitations so they are not re-reported as findings.
- Stopped shipping electron/dataFormat.test.js inside the app bundle, and moved
  react/react-dom to devDependencies: Vite bundles them into dist/, so
  electron-builder was packaging a second unused copy. app.asar is now 1.9 MB.
  Verified the packaged app still renders and runs.
- build/** narrowed to build/icon.* so the entitlements plist stops shipping.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>