OpenDownload v0.1.0
The first release completes the public paste → analyze → choose → download flow
with a minimal glass workspace, English/Arabic, RTL and persistent light/dark themes.
YouTube is not supported in v0.1. Its experimental implementation is deferred
and is not included in this release. The app returns a clear translated message
instead of trying an extraction that cannot be verified on the public host.
Included
- Actual source video/audio choices, MP3 conversion, direct images and available
thumbnails/subtitle sidecars. Bounded image-only collections can produce ZIPs
when the extractor returns them. - Persistent jobs, progress, cancellation, retry, temporary files, explicit
expiry, deletion and owner-scoped HTTP range downloads. - Same-origin mutations, bounded workers/storage, guarded public-only egress,
non-root containers and fail-closed cloud namespace isolation. - Versioned API, web, egress and cloud container images with provenance/SBOM.
Install
git clone --branch v0.1.0 https://github.com/Lord-shaban/OpenDownload.git
cd OpenDownload
cp .env.example .env
docker compose -f compose.yaml -f compose.release.yaml pull
docker compose -f compose.yaml -f compose.release.yaml up --no-build -d --waitOpen http://localhost:3000. See self-hosting and the
single-container cloud profile before changing exposure.
Live instance: OpenDownload.
The public host has finite shared capacity, 15-minute retention and can sleep.
Verification and limitations
Release delivery requires successful go, web and integration CI on the tagged
main commit. The publication workflow pulls the uploaded images, checks Compose
egress isolation, and exercises real owned video/MP3, ranges, ownership, persistence,
private-target refusal and shutdown in the uploaded cloud image. The live deployment
is checked separately; exact evidence is recorded in
release issue #36.
This is solo maintainer verification, not an independent security audit.
TikTok, SoundCloud and direct-media samples have real cloud evidence; other
listed extractors are conditional and not certified across every URL, region or
host. Dedicated social photo galleries remain deferred in
issue #13.
No authentication/access bypass, DRM, private/paid media, live streams or
watermark removal is included. See capabilities.
Compatibility
The API now reports version 0.1.0; YouTube analysis returns HTTP 422 with
youtube_unavailable. Previously queued/retried YouTube jobs cannot extract under
this release policy. Other API routes and SQLite job data remain compatible.
Back up the data volume before upgrading, retain it during rollback, and save
temporary media to your device before its expiry.
Completed delivery — 2026-10-01
- Annotated tag
v0.1.0points tod187d89cf24eb1908ee0098550d806b9da58dd6a, merged through PR #37. - All required main CI checks passed. Local verification included 26 browser tests, 9 unit tests, Go tests/vet, lint and strict TypeScript.
- Publication and uploaded-image runtime verification passed. All four GHCR images are anonymously accessible; exact immutable digests are in the attached
images-v0.1.0.json. - Blitz deployed that exact main commit. The live API reports
0.1.0,ready: true,fixtureMode: false, and both media tools available. - Actual live owned video: 25,532 bytes, 2.0 seconds, video/audio streams. Actual live MP3 conversion: 50,302 bytes, 2.020136 seconds, audio stream. HTTP range serving and deletion/404 checks passed.
- The submitted TikTok video downloaded on the final release: 2,178,061 bytes, 30.6 seconds, audio/video streams. Availability of other links remains conditional.
- The live YouTube boundary returns HTTP 422
youtube_unavailable; the Arabic interface displays the translated recovery message and excludes YouTube from supported sites.
Machine-readable release evidence is attached as verification-v0.1.0.json. These checks verify this release and these samples; they are not an independent security audit or a guarantee of every third-party URL.