Skip to content

0.0.2

Latest

Choose a tag to compare

@github-actions github-actions released this 04 Sep 06:01
e1006cb

Android downloads actually land somewhere you can reach

Downloading a file on Android did nothing useful. The bytes arrived, but
they were written into the app's own private storage, where no file
manager, gallery or other app can open them. There was no way to get at
the file afterwards, so "downloaded" meant nothing.

Downloads now go to the phone's Downloads/Local Drive folder, and the
transfer row tells you that instead of an internal path. Files are
visible in any file manager, can be shared to other apps, and survive
uninstalling Local Drive.

Fixes #2.

Notes:

  • A file downloaded with 0.0.1 was never reachable and still is not.
    Download it again on 0.0.2 and it will land properly.
  • Downloading the same file twice does not overwrite. The second copy
    gets a number beside it, the way a browser does it.
  • Files kept with "Make available offline" are unchanged. Those live
    inside the app on purpose, so that removing them removes the app's
    copy and not your file.
  • On Android 9 and older this asks for storage permission the first
    time. Android 10 and newer need no permission at all. Declining only
    costs you the Downloads folder, the download itself still works.

Security

  • golang.org/x/crypto raised to 0.55.0 for CVE-2026-56854. The flaw
    is in the SSH package, which the server never imports, so no install
    was exposed. Raised anyway.
  • The Docker image now applies Alpine's package updates at build
    time. Without that it shipped whatever OpenSSL the base image snapshot
    happened to freeze, which left CVE-2026-14456 in the image after
    Alpine had already published the fix. Self hosters on Docker should
    pull the new image.

Build

CI stopped finishing in August. Nothing in the repository had changed:
the Flutter toolchain was installed from the stable channel with no
version, 3.47 shipped, and the code generation step stopped terminating.
Because no job had a timeout, each run sat at GitHub's six hour ceiling
instead of failing.

Flutter is now pinned the same way Go and Node already were, and every
job has a time limit. No effect on the software, only on whether a
broken build says so.