Repository navigation
Android downloads actually land somewhere you can reach
Downloading a file on Android did nothing useful. The bytes arrived, but
they were written into the app's own private storage, where no file
manager, gallery or other app can open them. There was no way to get at
the file afterwards, so "downloaded" meant nothing.
Downloads now go to the phone's Downloads/Local Drive folder, and the
transfer row tells you that instead of an internal path. Files are
visible in any file manager, can be shared to other apps, and survive
uninstalling Local Drive.
Fixes #2.
Notes:
- A file downloaded with 0.0.1 was never reachable and still is not.
Download it again on 0.0.2 and it will land properly. - Downloading the same file twice does not overwrite. The second copy
gets a number beside it, the way a browser does it. - Files kept with "Make available offline" are unchanged. Those live
inside the app on purpose, so that removing them removes the app's
copy and not your file. - On Android 9 and older this asks for storage permission the first
time. Android 10 and newer need no permission at all. Declining only
costs you the Downloads folder, the download itself still works.
Security
- golang.org/x/crypto raised to 0.55.0 for CVE-2026-56854. The flaw
is in the SSH package, which the server never imports, so no install
was exposed. Raised anyway. - The Docker image now applies Alpine's package updates at build
time. Without that it shipped whatever OpenSSL the base image snapshot
happened to freeze, which left CVE-2026-14456 in the image after
Alpine had already published the fix. Self hosters on Docker should
pull the new image.
Build
CI stopped finishing in August. Nothing in the repository had changed:
the Flutter toolchain was installed from the stable channel with no
version, 3.47 shipped, and the code generation step stopped terminating.
Because no job had a timeout, each run sat at GitHub's six hour ceiling
instead of failing.
Flutter is now pinned the same way Go and Node already were, and every
job has a time limit. No effect on the software, only on whether a
broken build says so.