Skip to content

Releases: RBStephenson/STL-Studio

Main Build

Main Build Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 07 Jul 18:59
13a8840

Rolling build from main at 13a8840. This is not a versioned release.

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 04 Sep 11:25
5e0eb4b

Installing on Windows

Download STL-Studio-Setup-<version>.exe below and run it.

Windows will warn you on first run. STL Studio is not code-signed yet, so
SmartScreen shows "Windows protected your PC" with an unknown publisher.
Choose More info → Run anyway. This is expected for every current release
and is not a malware detection.

If there is no More info link, or your browser refused the download, see
Windows blocked the installer.

Verifying this download

Because the installer is unsigned, you can confirm it is exactly what CI
published:

# Checksum — compare against the SHA256SUMS asset below
Get-FileHash .\STL-Studio-Setup-<version>.exe -Algorithm SHA256

# Build provenance — proves it came from this repo's workflow (requires gh CLI)
gh attestation verify .\STL-Studio-Setup-<version>.exe --repo RBStephenson/STL-Studio

Full install guide: Getting started


STL Studio v1.1.0 — STL Installer, swatch-chart import, and a security pass

v1.1.0 is the first feature release on the v1.x line: 74 commits since v1.0.0,
adding two opt-in features alongside 20 bug fixes and a full round of dependency
and security updates. This build soaked as v1.1.0-beta.1 and v1.1.0-beta.2
before promotion.

What's new

STL Installer — experimental, off by default. Turning it on adds an
Install entry to the nav, letting you extract a ZIP or copy a folder
straight into a library as creator/character and skipping the manual
download → extract → move → scan flow. Enable it at Settings → Library →
Enable STL Installer (Experimental)
. Read-only deployments (Docker mounts,
for example) still can't write, regardless of the setting.

Paint Shelf swatch-chart import — off by default. Upload a manufacturer
swatch chart and pull its colors into your Paint Shelf. Vector PDFs are read
deterministically; embedded raster swatches and photographed or scanned pages
fall back to vision extraction. Imported colors are matched by name against
paints you already own, so an import doesn't duplicate your shelf. Paint Shelf
also gained bulk-select and bulk-delete. Enable it at Settings → Painting →
Swatch Chart Import
.

Smaller additions

  • Desktop zoom level now persists across launches.
  • Reorganize plans are scoped per scan root.
  • Support actions added to the desktop Help menu.
  • Faster gallery-image discovery when walking large creator folders.

Notable fixes

  • Refreshing on a deep route serves the app instead of a raw 404.
  • Gallery-image discovery is scoped to the product folder rather than the whole
    creator, so unrelated images stop appearing on a model.
  • Manual variant reordering now actually persists visually.
  • Model sort ties are stable instead of shuffling between loads.
  • Reorganize side effects and Storefront Enrich apply errors are surfaced
    rather than failing quietly.

Security

  • Electron permission requests are denied by default.
  • Raw-byte file endpoints are guarded against cross-origin GET.
  • AI-endpoint outbound calls are routed through the existing URL guard.
  • Dependency advisories cleared: tar DoS, nanoid, and brace-expansion
    (including desktop's nested copies).

Upgrading

  • Direct upgrade is supported from v0.18.0 or newer. Download and run the
    new installer over your existing install — your library folders and
    application database are untouched by the installer itself.
  • Before upgrading, take a backup: Settings → Data Management → Download
    Backup. Keep it until you've exercised the new version against your library.
  • Schema upgrades snapshot the database automatically
    (pre_upgrade_<timestamp>.db) before migrating. If a migration fails,
    startup stops and restores the original database for you.
  • Manual fallback / rollback: downgrades aren't supported (migrations
    aren't reversed). To go back, reinstall the older version and restore your
    backup or the automatic pre-upgrade snapshot.
  • Both new features are off by default, so upgrading changes nothing about how
    the app behaves until you turn one on.
  • Full detail: Support and compatibility policy.

Supported configurations

Configuration Support level
Windows 11 / Windows 10 22H2, x64 Supported
Linux, x64 (headless binary) Best effort — no desktop window or auto-updater
Docker Compose Best effort — for experienced self-hosters
macOS, Windows on ARM, 32-bit Windows, Windows Server Unsupported

Known limitations

  • The installer is not code-signed. Windows SmartScreen will warn
    "Windows protected your PC" on first run — choose More info → Run
    anyway
    . This is expected for every current release, not a malware
    detection. Verify your download with the published SHA256SUMS checksum or
    gh attestation verify instead of relying on signing — see
    Verifying your download.
  • No packaged desktop app for Linux or macOS. Linux runs as a headless
    local web service; macOS has no build and is best-effort via Docker only.
  • Automatic updates are Windows-only. Linux and Docker installs update by
    re-pulling/re-downloading manually.
  • Solo, self-constructed testing corpora back this release rather than a
    recruited external tester cohort — broad environment diversity (other
    Windows builds, antivirus products, unusual drive/mount setups, non-English
    locales) hasn't been separately exercised. If you hit something environment-
    specific, file a bug.

Getting help

Check the Troubleshooting guide
first. For a reproducible issue, open a
bug report
with your version, OS, repro steps, and the sanitized summary from Help →
About & support → Copy diagnostics
. See the
Support and compatibility policy
for what diagnostics does and doesn't share — nothing is sent automatically.


What's Changed

  • fix(STUDIO-374): serve SPA index.html on deep-route refresh instead of a raw 404 by @RBStephenson in #1266
  • chore(STUDIO-375): gitignore machine-local Docker Norton-TLS workaround by @RBStephenson in #1267
  • fix(STUDIO-377): scope gallery-image walk to the product folder, not the whole creator by @RBStephenson in #1279
  • build(deps-dev): bump fast-uri from 3.1.4 to 3.1.5 in /desktop by @dependabot[bot] in #1280
  • build(deps): bump anthropic from 0.117.0 to 0.120.2 in /backend by @dependabot[bot] in #1271
  • build(deps-dev): bump postcss from 8.5.19 to 8.5.26 in /desktop by @dependabot[bot] in #1281
  • build(deps): bump cryptography from 49.0.0 to 50.0.0 in /backend by @dependabot[bot] in #1268
  • build(deps-dev): bump undici from 7.28.0 to 7.29.0 in /frontend by @dependabot[bot] in #1277
  • build(deps-dev): bump the dev-deps group across 1 directory with 2 updates by @dependabot[bot] in #1262
  • build(deps): bump fastapi from 0.139.2 to 0.141.1 in /backend by @dependabot[bot] in #1269
  • build(deps): bump the prod-deps group across 1 directory with 6 updates by @dependabot[bot] in #1275
  • build(deps): bump ruff from 0.15.22 to 0.16.1 in /backend by @dependabot[bot] in #1270
  • build(deps): bump node from 26.5.0-alpine to 26.5.1-alpine in /frontend by @dependabot[bot] in #1272
  • build(deps-dev): bump undici from 6.27.0 to 6.28.0 in /desktop by @dependabot[bot] in #1278
  • build(deps): bump playwright from 1.61.0 to 1.62.0 in /backend by @dependabot[bot] in #1273
  • build(deps): bump pypdf from 6.14.2 to 6.15.0 in /backend in the pip group across 1 directory by @dependabot[bot] in #1287
  • build(deps-dev): bump postcss from 8.5.21 to 8.5.26 in /frontend by @dependabot[bot] in #1285
  • build(deps): bump dompurify from 3.4.12 to 3.4.13 in /frontend by @dependabot[bot] in #1284
  • fix(STUDIO-379): pin brace-expansion (and desktop's nested copies) to patched versions by @RBStephenson in #1291
  • build(deps-dev): bump the dev-deps group across 1 directory with 8 updates by @dependabot[bot] in #1290
  • build(deps): bump js-yaml from 4.3.0 to 4.3.1 in /desktop by @dependabot[bot] in #1286
  • Fix import-preview title collision and the data-integrity gaps it uncovered by @tpagden in #1282
  • fix(STUDIO-307): surface apply errors and detail in Storefront Enrich by @RBStephenson in #1292
  • fix(STUDIO-297): thread group_by_c...
Read more

v1.1.0-beta.2

v1.1.0-beta.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 25 Aug 11:15
5e0eb4b

Installing on Windows

Download STL-Studio-Setup-<version>.exe below and run it.

Windows will warn you on first run. STL Studio is not code-signed yet, so
SmartScreen shows "Windows protected your PC" with an unknown publisher.
Choose More info → Run anyway. This is expected for every current release
and is not a malware detection.

If there is no More info link, or your browser refused the download, see
Windows blocked the installer.

Verifying this download

Because the installer is unsigned, you can confirm it is exactly what CI
published:

# Checksum — compare against the SHA256SUMS asset below
Get-FileHash .\STL-Studio-Setup-<version>.exe -Algorithm SHA256

# Build provenance — proves it came from this repo's workflow (requires gh CLI)
gh attestation verify .\STL-Studio-Setup-<version>.exe --repo RBStephenson/STL-Studio

Full install guide: Getting started


What's Changed

  • build(deps): bump uvicorn from 0.52.1 to 0.52.4 in /backend by @dependabot[bot] in #1335
  • fix(STUDIO-392): resolve tar DoS advisory in desktop lockfile by @RBStephenson in #1349
  • fix(STUDIO-391): manual variant reorder now actually persists visually by @RBStephenson in #1348
  • build(deps): bump sqlalchemy from 2.0.51 to 2.0.52 in /backend by @dependabot[bot] in #1341
  • build(deps): bump numpy from 2.5.1 to 2.5.2 in /backend by @dependabot[bot] in #1338
  • build(deps): bump ruff from 0.16.2 to 0.16.4 in /backend by @dependabot[bot] in #1340

Full Changelog: v1.1.0-beta.1...v1.1.0-beta.2

v1.1.0-beta.1

v1.1.0-beta.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 23 Aug 20:33
5eb6556

Installing on Windows

Download STL-Studio-Setup-<version>.exe below and run it.

Windows will warn you on first run. STL Studio is not code-signed yet, so
SmartScreen shows "Windows protected your PC" with an unknown publisher.
Choose More info → Run anyway. This is expected for every current release
and is not a malware detection.

If there is no More info link, or your browser refused the download, see
Windows blocked the installer.

Verifying this download

Because the installer is unsigned, you can confirm it is exactly what CI
published:

# Checksum — compare against the SHA256SUMS asset below
Get-FileHash .\STL-Studio-Setup-<version>.exe -Algorithm SHA256

# Build provenance — proves it came from this repo's workflow (requires gh CLI)
gh attestation verify .\STL-Studio-Setup-<version>.exe --repo RBStephenson/STL-Studio

Full install guide: Getting started


What's Changed

  • fix(STUDIO-374): serve SPA index.html on deep-route refresh instead of a raw 404 by @RBStephenson in #1266
  • chore(STUDIO-375): gitignore machine-local Docker Norton-TLS workaround by @RBStephenson in #1267
  • fix(STUDIO-377): scope gallery-image walk to the product folder, not the whole creator by @RBStephenson in #1279
  • build(deps-dev): bump fast-uri from 3.1.4 to 3.1.5 in /desktop by @dependabot[bot] in #1280
  • build(deps): bump anthropic from 0.117.0 to 0.120.2 in /backend by @dependabot[bot] in #1271
  • build(deps-dev): bump postcss from 8.5.19 to 8.5.26 in /desktop by @dependabot[bot] in #1281
  • build(deps): bump cryptography from 49.0.0 to 50.0.0 in /backend by @dependabot[bot] in #1268
  • build(deps-dev): bump undici from 7.28.0 to 7.29.0 in /frontend by @dependabot[bot] in #1277
  • build(deps-dev): bump the dev-deps group across 1 directory with 2 updates by @dependabot[bot] in #1262
  • build(deps): bump fastapi from 0.139.2 to 0.141.1 in /backend by @dependabot[bot] in #1269
  • build(deps): bump the prod-deps group across 1 directory with 6 updates by @dependabot[bot] in #1275
  • build(deps): bump ruff from 0.15.22 to 0.16.1 in /backend by @dependabot[bot] in #1270
  • build(deps): bump node from 26.5.0-alpine to 26.5.1-alpine in /frontend by @dependabot[bot] in #1272
  • build(deps-dev): bump undici from 6.27.0 to 6.28.0 in /desktop by @dependabot[bot] in #1278
  • build(deps): bump playwright from 1.61.0 to 1.62.0 in /backend by @dependabot[bot] in #1273
  • build(deps): bump pypdf from 6.14.2 to 6.15.0 in /backend in the pip group across 1 directory by @dependabot[bot] in #1287
  • build(deps-dev): bump postcss from 8.5.21 to 8.5.26 in /frontend by @dependabot[bot] in #1285
  • build(deps): bump dompurify from 3.4.12 to 3.4.13 in /frontend by @dependabot[bot] in #1284
  • fix(STUDIO-379): pin brace-expansion (and desktop's nested copies) to patched versions by @RBStephenson in #1291
  • build(deps-dev): bump the dev-deps group across 1 directory with 8 updates by @dependabot[bot] in #1290
  • build(deps): bump js-yaml from 4.3.0 to 4.3.1 in /desktop by @dependabot[bot] in #1286
  • Fix import-preview title collision and the data-integrity gaps it uncovered by @tpagden in #1282
  • fix(STUDIO-307): surface apply errors and detail in Storefront Enrich by @RBStephenson in #1292
  • fix(STUDIO-297): thread group_by_character through split_pack's re-walk by @RBStephenson in #1293
  • refactor(STUDIO-228): remove legacy thumbnail discovery implementation by @RBStephenson in #1294
  • refactor(STUDIO-300): pairwise hash-bucket evidence, not star-from-first by @RBStephenson in #1305
  • build(deps): bump uvicorn from 0.51.0 to 0.52.1 in /backend by @dependabot[bot] in #1297
  • build(deps): bump anthropic from 0.120.2 to 0.121.0 in /backend by @dependabot[bot] in #1300
  • build(deps): bump ruff from 0.16.1 to 0.16.2 in /backend by @dependabot[bot] in #1298
  • build(deps): bump alembic from 1.18.5 to 1.19.1 in /backend by @dependabot[bot] in #1295
  • build(deps): bump pydantic-settings from 2.14.2 to 2.15.0 in /backend by @dependabot[bot] in #1296
  • build(deps): bump the prod-deps group across 1 directory with 2 updates by @dependabot[bot] in #1301
  • build(deps): bump node from 26.5.1-alpine to 26.7.0-alpine in /frontend by @dependabot[bot] in #1303
  • fix(STUDIO-362): pin nanoid to 3.3.18 to clear the desktop audit gate by @RBStephenson in #1308
  • fix(STUDIO-371): resolve pre-supported pack layouts to one model per product by @RBStephenson in #1307
  • build(deps-dev): bump the dev-deps group across 1 directory with 2 updates by @dependabot[bot] in #1304
  • Refresh README pitch and links by @RBStephenson in #1309
  • build(deps-dev): bump the dev-deps group across 1 directory with 6 updates by @dependabot[bot] in #1310
  • Add Contributor Covenant Code of Conduct by @RBStephenson in #1311
  • chore(STUDIO-330): add pymupdf dependency + NOTICE for AGPL carve-out by @RBStephenson in #1312
  • feat(STUDIO-331): deterministic vector PDF swatch-chart extraction by @RBStephenson in #1313
  • feat(STUDIO-332): embedded-raster-swatch vision fallback for Paint Shelf import by @RBStephenson in #1314
  • feat(STUDIO-333): swatch-chart import endpoints + fix silently-failing license gate by @RBStephenson in #1315
  • feat(STUDIO-334): Paint Shelf swatch-chart import UI + settings toggle by @RBStephenson in #1316
  • feat(STUDIO-381): photo/scanned-page vision fallback for swatch import by @RBStephenson in #1317
  • Paint Shelf: bulk-select + bulk-delete paints by @RBStephenson in #1318
  • Import from Chart: match swatch colors to existing paints by name by @RBStephenson in #1319
  • fix(STUDIO-384): pick topmost fill for stacked-opaque swatch shapes by @RBStephenson in #1320
  • refactor(STUDIO-385): extract shared cross-device copy primitive by @RBStephenson in #1321
  • feat(STUDIO-386): installer ZIP/folder extraction service by @RBStephenson in #1322
  • feat(STUDIO-387): install endpoint + installer_enabled flag by @RBStephenson in #1323
  • test(STUDIO-388): confirm creator-scan indexes freshly-installed content correctly by @RBStephenson in #1324
  • feat(STUDIO-389): add installer frontend flow by @RBStephenson in #1325
  • fix(STUDIO-363): remove name_parser's module-level user-rule globals by @RBStephenson in #1326
  • fix(STUDIO-367): reconcile boot backfill and scan grouping with a CHARACTER signal by @RBStephenson in #1327
  • fix(STUDIO-326): stabilize model sort ties by @RBStephenson in #1328
  • fix(STUDIO-260): deny Electron permissions by default by @RBStephenson in #1329
  • test(STUDIO-369): pin creator case identity policy by @RBStephenson in #1330
  • STUDIO-172: Surface Reorganize side effects by @RBStephenson in #1331
  • STUDIO-345: Add desktop support actions to Help menu by @RBStephenson in #1332
  • fix(STUDIO-321): run import cleanup asynchronously by @RBStephenson in #1333
  • STUDIO-376: scope Reorganize preview by scan root by @RBStephenson in #1334
  • STUDIO-361: bound grouping strategy regroup...
Read more

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 07 Aug 12:05
f1c3be8

Installing on Windows

Download STL-Studio-Setup-<version>.exe below and run it.

Windows will warn you on first run. STL Studio is not code-signed yet, so
SmartScreen shows "Windows protected your PC" with an unknown publisher.
Choose More info → Run anyway. This is expected for every current release
and is not a malware detection.

If there is no More info link, or your browser refused the download, see
Windows blocked the installer.

Verifying this download

Because the installer is unsigned, you can confirm it is exactly what CI
published:

# Checksum — compare against the SHA256SUMS asset below
Get-FileHash .\STL-Studio-Setup-<version>.exe -Algorithm SHA256

# Build provenance — proves it came from this repo's workflow (requires gh CLI)
gh attestation verify .\STL-Studio-Setup-<version>.exe --repo RBStephenson/STL-Studio

Full install guide: Getting started


STL Studio v1.0.0 — first stable release

STL Studio is a local-first app for cataloguing, browsing, and managing an STL
file library: scanning your folders into a searchable catalog, grouping model
variants, a 3D viewer, collections and a kit builder, metadata editing and web
enrichment, and backup/restore — all running on your own machine.

v1.0.0 marks the app's first stable release line: the installer, application
lifecycle, backup/restore, migration-failure handling, and desktop auto-updater
now have repeatable qualification coverage, and this build completed a soak
period under normal day-to-day use with no schema or installer changes.

Upgrading

  • Direct upgrade is supported from v0.18.0 or newer. Download and run the
    new installer over your existing install — your library folders and
    application database are untouched by the installer itself.
  • Before upgrading, take a backup: Settings → Data Management → Download
    Backup. Keep it until you've exercised the new version against your library.
  • Schema upgrades snapshot the database automatically
    (pre_upgrade_<timestamp>.db) before migrating. If a migration fails,
    startup stops and restores the original database for you.
  • Manual fallback / rollback: downgrades aren't supported (migrations
    aren't reversed). To go back, reinstall the older version and restore your
    backup or the automatic pre-upgrade snapshot.
  • Full detail: Support and compatibility policy.

Supported configurations

Configuration Support level
Windows 11 / Windows 10 22H2, x64 Supported
Linux, x64 (headless binary) Best effort — no desktop window or auto-updater
Docker Compose Best effort — for experienced self-hosters
macOS, Windows on ARM, 32-bit Windows, Windows Server Unsupported

Known limitations

  • The installer is not code-signed. Windows SmartScreen will warn
    "Windows protected your PC" on first run — choose More info → Run
    anyway
    . This is expected for every current release, not a malware
    detection. Verify your download with the published SHA256SUMS checksum or
    gh attestation verify instead of relying on signing — see
    Verifying your download.
  • No packaged desktop app for Linux or macOS. Linux runs as a headless
    local web service; macOS has no build and is best-effort via Docker only.
  • Automatic updates are Windows-only. Linux and Docker installs update by
    re-pulling/re-downloading manually.
  • Solo, self-constructed testing corpora back this release rather than a
    recruited external tester cohort — broad environment diversity (other
    Windows builds, antivirus products, unusual drive/mount setups, non-English
    locales) hasn't been separately exercised. If you hit something environment-
    specific, file a bug.

Getting help

Check the Troubleshooting guide
first. For a reproducible issue, open a
bug report
with your version, OS, repro steps, and the sanitized summary from Help →
About & support → Copy diagnostics
. See the
Support and compatibility policy
for what diagnostics does and doesn't share — nothing is sent automatically.


What's Changed

  • build(deps): bump the prod-deps group across 1 directory with 2 updates by @dependabot[bot] in #1015
  • fix: prune orphaned placeholder creators after reassignment by @tpagden in #1109
  • feat: resolve the real creator at scan time instead of a placeholder by @tpagden in #1111
  • fix: plain-language message for destination-collision apply errors by @tpagden in #1113
  • fix: gallery discovery no longer sweeps in sibling format-variant folders' own images by @tpagden in #1115
  • feat(STUDIO-264): sync Jira issues/epics to GitHub issues/milestones by @RBStephenson in #1116
  • fix(STUDIO-265): migrate Jira client off retired /rest/api/2/search by @RBStephenson in #1117
  • fix(STUDIO-266): log fetched issue/epic counts in sync run by @RBStephenson in #1118
  • fix(STUDIO-267): log raw Jira search/jql response keys by @RBStephenson in #1119
  • fix(STUDIO-268): probe Jira token identity via /myself by @RBStephenson in #1120
  • feat(STUDIO-269): bidirectional sync with per-direction opt-in flags by @RBStephenson in #1177
  • feat(STUDIO-271): back-link reverse-created Jira issues to their GitHub issue by @RBStephenson in #1179
  • feat(STUDIO-273): scoped Jira->GitHub status back-update for linked issues by @RBStephenson in #1181
  • chore(STUDIO-275): take frontend dev-dep bumps minus TypeScript 7 by @RBStephenson in #1183
  • build(deps): bump lucide-react from 1.24.0 to 1.25.0 in /frontend in the prod-deps group by @dependabot[bot] in #1184
  • fix(STUDIO-281): treat 'lys' and other slicer folders as structural by @RBStephenson in #1185
  • fix(STUDIO-282): heal stale structural model names on rescan by @RBStephenson in #1186
  • feat(STUDIO-283): make the release pipeline prerelease-aware by @RBStephenson in #1187
  • feat(STUDIO-284): setting to opt in to pre-release (beta) app updates by @RBStephenson in #1188
  • fix(STUDIO-285): flag prerelease tags on the uploaded GitHub release by @RBStephenson in #1189
  • fix(STUDIO-286): treat sized/shaped base folders as structural by @RBStephenson in #1190
  • fix(STUDIO-288): treat 'semi cut' folders as structural print-prep by @RBStephenson in #1191
  • fix(STUDIO-287): qualify generic leaf names by their owning release by @RBStephenson in #1192
  • fix(STUDIO-290): re-derive model names on every scan, drop the rename guard by @RBStephenson in #1193
  • fix(STUDIO-291): treat variant-selection folders as structural by @RBStephenson in #1194
  • docs(STUDIO-292): add website link and tagline to Help About section by @RBStephenson in #1198
  • fix(STUDIO-293): patch high-severity brace-expansion DoS in desktop deps by @RBStephenson in #1199
  • build(deps): bump actions/setup-python from 6 to 7 by @dependabot[bot] in #1195
  • build(deps): bump @tanstack/react-query from 5.101.2 to 5.101.3 in /frontend in the prod-deps group across 1 directory by @dependabot[bot] in #1197
  • build(deps-dev): bump the dev-deps group across 1 directory with 3 updates by @dependabot[bot] in #1196
  • fix(STUDIO-294): make incremental-scan baseline timezone-correct by @RBStephenson in #1200
  • fix(STUDIO-296): shield _prune_stale_paths from failed creator walks by @RBStephenson in #1201
  • fix(STUDIO-295): only advance ScanRoot.last_scanned on a clean, online walk by @RBStephenson in #1202
  • fix(STUDIO-301): clear variant_group_id before deleting an empty group by @RBStephenson in #1203
  • fix(STUDIO-306): stop clearing needs_review on unreviewed refresh data by @RBStephenson in https://github.com/RBStephenson...
Read more

v1.0.0-beta.9

v1.0.0-beta.9 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 31 Jul 11:35
f1c3be8

Installing on Windows

Download STL-Studio-Setup-<version>.exe below and run it.

Windows will warn you on first run. STL Studio is not code-signed yet, so
SmartScreen shows "Windows protected your PC" with an unknown publisher.
Choose More info → Run anyway. This is expected for every current release
and is not a malware detection.

If there is no More info link, or your browser refused the download, see
Windows blocked the installer.

Verifying this download

Because the installer is unsigned, you can confirm it is exactly what CI
published:

# Checksum — compare against the SHA256SUMS asset below
Get-FileHash .\STL-Studio-Setup-<version>.exe -Algorithm SHA256

# Build provenance — proves it came from this repo's workflow (requires gh CLI)
gh attestation verify .\STL-Studio-Setup-<version>.exe --repo RBStephenson/STL-Studio

Full install guide: Getting started


What's Changed

Full Changelog: v1.0.0-beta.8...v1.0.0-beta.9

v1.0.0-beta.8

v1.0.0-beta.8 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 26 Jul 14:39
bf3297b

Installing on Windows

Download STL-Studio-Setup-<version>.exe below and run it.

Windows will warn you on first run. STL Studio is not code-signed yet, so
SmartScreen shows "Windows protected your PC" with an unknown publisher.
Choose More info → Run anyway. This is expected for every current release
and is not a malware detection.

If there is no More info link, or your browser refused the download, see
Windows blocked the installer.

Verifying this download

Because the installer is unsigned, you can confirm it is exactly what CI
published:

# Checksum — compare against the SHA256SUMS asset below
Get-FileHash .\STL-Studio-Setup-<version>.exe -Algorithm SHA256

# Build provenance — proves it came from this repo's workflow (requires gh CLI)
gh attestation verify .\STL-Studio-Setup-<version>.exe --repo RBStephenson/STL-Studio

Full install guide: Getting started


What's Changed

  • fix(STUDIO-258): enforce CSP at the Electron session layer by @RBStephenson in #1250
  • fix(STUDIO-259): route external links to the browser, deny other navigation by @RBStephenson in #1251
  • fix(STUDIO-298): dedup folder-derived creators case-insensitively by @RBStephenson in #1252
  • fix(STUDIO-366): store host-native paths at the reorganize persistence boundary by @RBStephenson in #1253
  • fix(STUDIO-320): validate image bytes and reuse the guarded fetch for gallery downloads by @RBStephenson in #1254

Full Changelog: v1.0.0-beta.7...v1.0.0-beta.8

v1.0.0-beta.7

v1.0.0-beta.7 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 26 Jul 01:26
611e66c

Installing on Windows

Download STL-Studio-Setup-<version>.exe below and run it.

Windows will warn you on first run. STL Studio is not code-signed yet, so
SmartScreen shows "Windows protected your PC" with an unknown publisher.
Choose More info → Run anyway. This is expected for every current release
and is not a malware detection.

If there is no More info link, or your browser refused the download, see
Windows blocked the installer.

Verifying this download

Because the installer is unsigned, you can confirm it is exactly what CI
published:

# Checksum — compare against the SHA256SUMS asset below
Get-FileHash .\STL-Studio-Setup-<version>.exe -Algorithm SHA256

# Build provenance — proves it came from this repo's workflow (requires gh CLI)
gh attestation verify .\STL-Studio-Setup-<version>.exe --repo RBStephenson/STL-Studio

Full install guide: Getting started


What's Changed

  • fix(STUDIO-347): persist whether the encryption key was ever revealed by @RBStephenson in #1232
  • fix(STUDIO-355): allowlist-gate npm audit instead of blind downgrade by @RBStephenson in #1233
  • fix(STUDIO-242): credit only grouping evidence that merges components by @RBStephenson in #1234
  • fix(STUDIO-356): bump brace-expansion and allowlist its unfixable nodes by @RBStephenson in #1235
  • refactor(STUDIO-243): introduce typed grouping evidence and precedence by @RBStephenson in #1236
  • refactor(STUDIO-244): extract pure hierarchy and hash evidence generation by @RBStephenson in #1237
  • refactor(STUDIO-245): extract pure filename and name evidence generation by @RBStephenson in #1238
  • refactor(STUDIO-246): extract pure constrained clustering and group proposals by @RBStephenson in #1239
  • fix(STUDIO-248): make automatic group proposals deterministic by @RBStephenson in #1240
  • refactor(STUDIO-239): drop the unused manual_group_ids parameter by @RBStephenson in #1241
  • refactor(STUDIO-240): expose a public grouping-strategy policy API by @RBStephenson in #1242
  • refactor(STUDIO-241): extract candidate eligibility from orchestration by @RBStephenson in #1243
  • refactor(STUDIO-247): split the pure grouping policy into its own module by @RBStephenson in #1244
  • fix(STUDIO-358): surface scan read failures instead of silently absorbing them by @RBStephenson in #1245
  • refactor(STUDIO-229): introduce a shared filesystem path-boundary abstraction by @RBStephenson in #1246
  • refactor(STUDIO-230): migrate scanner prune operations to shared path boundaries by @RBStephenson in #1247
  • refactor(STUDIO-231): replace scanner rule globals with an explicit context by @RBStephenson in #1248
  • fix(STUDIO-365): match stored paths that differ only by separator style by @RBStephenson in #1249

Full Changelog: v1.0.0-beta.6...v1.0.0-beta.7

v1.0.0-beta.6

v1.0.0-beta.6 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 24 Jul 13:38
3036721

Installing on Windows

Download STL-Studio-Setup-<version>.exe below and run it.

Windows will warn you on first run. STL Studio is not code-signed yet, so
SmartScreen shows "Windows protected your PC" with an unknown publisher.
Choose More info → Run anyway. This is expected for every current release
and is not a malware detection.

If there is no More info link, or your browser refused the download, see
Windows blocked the installer.

Verifying this download

Because the installer is unsigned, you can confirm it is exactly what CI
published:

# Checksum — compare against the SHA256SUMS asset below
Get-FileHash .\STL-Studio-Setup-<version>.exe -Algorithm SHA256

# Build provenance — proves it came from this repo's workflow (requires gh CLI)
gh attestation verify .\STL-Studio-Setup-<version>.exe --repo RBStephenson/STL-Studio

Full install guide: Getting started


What's Changed

Full Changelog: v1.0.0-beta.5...v1.0.0-beta.6

v1.0.0-beta.5

v1.0.0-beta.5 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 23 Jul 03:42
766815d

What's Changed

  • fix(STUDIO-310): stop matching search query against model description by @RBStephenson in #1208
  • fix(STUDIO-311): bump fast-uri to clear high-severity CI audit failure by @RBStephenson in #1209
  • fix(STUDIO-312): preserve mtime on cross-device reorganize moves by @RBStephenson in #1210
  • fix(STUDIO-313): prune never-applied reorganize manifests on next preview by @RBStephenson in #1211
  • fix(STUDIO-314): reorganize perf + edge-case cleanups by @RBStephenson in #1212
  • fix(STUDIO-315): resolve import mapping/bucketing case and remap bugs by @RBStephenson in #1213
  • fix(STUDIO-318): merge other_files on import move instead of overwriting by @RBStephenson in #1214
  • fix(STUDIO-324): complete bulk-delete cascade and align neighbors inbox default by @RBStephenson in #1215
  • fix(STUDIO-328): make tag operations suppress auto-tags instead of no-oping by @RBStephenson in #1216

Full Changelog: v1.0.0-beta.4...v1.0.0-beta.5