Installing on Windows
Download STL-Studio-Setup-<version>.exe below and run it.
Windows will warn you on first run. STL Studio is not code-signed yet, so
SmartScreen shows "Windows protected your PC" with an unknown publisher.
Choose More info → Run anyway. This is expected for every current release
and is not a malware detection.
If there is no More info link, or your browser refused the download, see
Windows blocked the installer.
Verifying this download
Because the installer is unsigned, you can confirm it is exactly what CI
published:
# Checksum — compare against the SHA256SUMS asset below
Get-FileHash .\STL-Studio-Setup-<version>.exe -Algorithm SHA256
# Build provenance — proves it came from this repo's workflow (requires gh CLI)
gh attestation verify .\STL-Studio-Setup-<version>.exe --repo RBStephenson/STL-StudioFull install guide: Getting started
STL Studio v1.1.0 — STL Installer, swatch-chart import, and a security pass
v1.1.0 is the first feature release on the v1.x line: 74 commits since v1.0.0,
adding two opt-in features alongside 20 bug fixes and a full round of dependency
and security updates. This build soaked as v1.1.0-beta.1 and v1.1.0-beta.2
before promotion.
What's new
STL Installer — experimental, off by default. Turning it on adds an
Install entry to the nav, letting you extract a ZIP or copy a folder
straight into a library as creator/character and skipping the manual
download → extract → move → scan flow. Enable it at Settings → Library →
Enable STL Installer (Experimental). Read-only deployments (Docker mounts,
for example) still can't write, regardless of the setting.
Paint Shelf swatch-chart import — off by default. Upload a manufacturer
swatch chart and pull its colors into your Paint Shelf. Vector PDFs are read
deterministically; embedded raster swatches and photographed or scanned pages
fall back to vision extraction. Imported colors are matched by name against
paints you already own, so an import doesn't duplicate your shelf. Paint Shelf
also gained bulk-select and bulk-delete. Enable it at Settings → Painting →
Swatch Chart Import.
Smaller additions
- Desktop zoom level now persists across launches.
- Reorganize plans are scoped per scan root.
- Support actions added to the desktop Help menu.
- Faster gallery-image discovery when walking large creator folders.
Notable fixes
- Refreshing on a deep route serves the app instead of a raw 404.
- Gallery-image discovery is scoped to the product folder rather than the whole
creator, so unrelated images stop appearing on a model. - Manual variant reordering now actually persists visually.
- Model sort ties are stable instead of shuffling between loads.
- Reorganize side effects and Storefront Enrich apply errors are surfaced
rather than failing quietly.
Security
- Electron permission requests are denied by default.
- Raw-byte file endpoints are guarded against cross-origin GET.
- AI-endpoint outbound calls are routed through the existing URL guard.
- Dependency advisories cleared: tar DoS,
nanoid, andbrace-expansion
(including desktop's nested copies).
Upgrading
- Direct upgrade is supported from v0.18.0 or newer. Download and run the
new installer over your existing install — your library folders and
application database are untouched by the installer itself. - Before upgrading, take a backup: Settings → Data Management → Download
Backup. Keep it until you've exercised the new version against your library. - Schema upgrades snapshot the database automatically
(pre_upgrade_<timestamp>.db) before migrating. If a migration fails,
startup stops and restores the original database for you. - Manual fallback / rollback: downgrades aren't supported (migrations
aren't reversed). To go back, reinstall the older version and restore your
backup or the automatic pre-upgrade snapshot. - Both new features are off by default, so upgrading changes nothing about how
the app behaves until you turn one on. - Full detail: Support and compatibility policy.
Supported configurations
| Configuration | Support level |
|---|---|
| Windows 11 / Windows 10 22H2, x64 | Supported |
| Linux, x64 (headless binary) | Best effort — no desktop window or auto-updater |
| Docker Compose | Best effort — for experienced self-hosters |
| macOS, Windows on ARM, 32-bit Windows, Windows Server | Unsupported |
Known limitations
- The installer is not code-signed. Windows SmartScreen will warn
"Windows protected your PC" on first run — choose More info → Run
anyway. This is expected for every current release, not a malware
detection. Verify your download with the publishedSHA256SUMSchecksum or
gh attestation verifyinstead of relying on signing — see
Verifying your download. - No packaged desktop app for Linux or macOS. Linux runs as a headless
local web service; macOS has no build and is best-effort via Docker only. - Automatic updates are Windows-only. Linux and Docker installs update by
re-pulling/re-downloading manually. - Solo, self-constructed testing corpora back this release rather than a
recruited external tester cohort — broad environment diversity (other
Windows builds, antivirus products, unusual drive/mount setups, non-English
locales) hasn't been separately exercised. If you hit something environment-
specific, file a bug.
Getting help
Check the Troubleshooting guide
first. For a reproducible issue, open a
bug report
with your version, OS, repro steps, and the sanitized summary from Help →
About & support → Copy diagnostics. See the
Support and compatibility policy
for what diagnostics does and doesn't share — nothing is sent automatically.
What's Changed
- fix(STUDIO-374): serve SPA index.html on deep-route refresh instead of a raw 404 by @RBStephenson in #1266
- chore(STUDIO-375): gitignore machine-local Docker Norton-TLS workaround by @RBStephenson in #1267
- fix(STUDIO-377): scope gallery-image walk to the product folder, not the whole creator by @RBStephenson in #1279
- build(deps-dev): bump fast-uri from 3.1.4 to 3.1.5 in /desktop by @dependabot[bot] in #1280
- build(deps): bump anthropic from 0.117.0 to 0.120.2 in /backend by @dependabot[bot] in #1271
- build(deps-dev): bump postcss from 8.5.19 to 8.5.26 in /desktop by @dependabot[bot] in #1281
- build(deps): bump cryptography from 49.0.0 to 50.0.0 in /backend by @dependabot[bot] in #1268
- build(deps-dev): bump undici from 7.28.0 to 7.29.0 in /frontend by @dependabot[bot] in #1277
- build(deps-dev): bump the dev-deps group across 1 directory with 2 updates by @dependabot[bot] in #1262
- build(deps): bump fastapi from 0.139.2 to 0.141.1 in /backend by @dependabot[bot] in #1269
- build(deps): bump the prod-deps group across 1 directory with 6 updates by @dependabot[bot] in #1275
- build(deps): bump ruff from 0.15.22 to 0.16.1 in /backend by @dependabot[bot] in #1270
- build(deps): bump node from 26.5.0-alpine to 26.5.1-alpine in /frontend by @dependabot[bot] in #1272
- build(deps-dev): bump undici from 6.27.0 to 6.28.0 in /desktop by @dependabot[bot] in #1278
- build(deps): bump playwright from 1.61.0 to 1.62.0 in /backend by @dependabot[bot] in #1273
- build(deps): bump pypdf from 6.14.2 to 6.15.0 in /backend in the pip group across 1 directory by @dependabot[bot] in #1287
- build(deps-dev): bump postcss from 8.5.21 to 8.5.26 in /frontend by @dependabot[bot] in #1285
- build(deps): bump dompurify from 3.4.12 to 3.4.13 in /frontend by @dependabot[bot] in #1284
- fix(STUDIO-379): pin brace-expansion (and desktop's nested copies) to patched versions by @RBStephenson in #1291
- build(deps-dev): bump the dev-deps group across 1 directory with 8 updates by @dependabot[bot] in #1290
- build(deps): bump js-yaml from 4.3.0 to 4.3.1 in /desktop by @dependabot[bot] in #1286
- Fix import-preview title collision and the data-integrity gaps it uncovered by @tpagden in #1282
- fix(STUDIO-307): surface apply errors and detail in Storefront Enrich by @RBStephenson in #1292
- fix(STUDIO-297): thread group_by_character through split_pack's re-walk by @RBStephenson in #1293
- refactor(STUDIO-228): remove legacy thumbnail discovery implementation by @RBStephenson in #1294
- refactor(STUDIO-300): pairwise hash-bucket evidence, not star-from-first by @RBStephenson in #1305
- build(deps): bump uvicorn from 0.51.0 to 0.52.1 in /backend by @dependabot[bot] in #1297
- build(deps): bump anthropic from 0.120.2 to 0.121.0 in /backend by @dependabot[bot] in #1300
- build(deps): bump ruff from 0.16.1 to 0.16.2 in /backend by @dependabot[bot] in #1298
- build(deps): bump alembic from 1.18.5 to 1.19.1 in /backend by @dependabot[bot] in #1295
- build(deps): bump pydantic-settings from 2.14.2 to 2.15.0 in /backend by @dependabot[bot] in #1296
- build(deps): bump the prod-deps group across 1 directory with 2 updates by @dependabot[bot] in #1301
- build(deps): bump node from 26.5.1-alpine to 26.7.0-alpine in /frontend by @dependabot[bot] in #1303
- fix(STUDIO-362): pin nanoid to 3.3.18 to clear the desktop audit gate by @RBStephenson in #1308
- fix(STUDIO-371): resolve pre-supported pack layouts to one model per product by @RBStephenson in #1307
- build(deps-dev): bump the dev-deps group across 1 directory with 2 updates by @dependabot[bot] in #1304
- Refresh README pitch and links by @RBStephenson in #1309
- build(deps-dev): bump the dev-deps group across 1 directory with 6 updates by @dependabot[bot] in #1310
- Add Contributor Covenant Code of Conduct by @RBStephenson in #1311
- chore(STUDIO-330): add pymupdf dependency + NOTICE for AGPL carve-out by @RBStephenson in #1312
- feat(STUDIO-331): deterministic vector PDF swatch-chart extraction by @RBStephenson in #1313
- feat(STUDIO-332): embedded-raster-swatch vision fallback for Paint Shelf import by @RBStephenson in #1314
- feat(STUDIO-333): swatch-chart import endpoints + fix silently-failing license gate by @RBStephenson in #1315
- feat(STUDIO-334): Paint Shelf swatch-chart import UI + settings toggle by @RBStephenson in #1316
- feat(STUDIO-381): photo/scanned-page vision fallback for swatch import by @RBStephenson in #1317
- Paint Shelf: bulk-select + bulk-delete paints by @RBStephenson in #1318
- Import from Chart: match swatch colors to existing paints by name by @RBStephenson in #1319
- fix(STUDIO-384): pick topmost fill for stacked-opaque swatch shapes by @RBStephenson in #1320
- refactor(STUDIO-385): extract shared cross-device copy primitive by @RBStephenson in #1321
- feat(STUDIO-386): installer ZIP/folder extraction service by @RBStephenson in #1322
- feat(STUDIO-387): install endpoint + installer_enabled flag by @RBStephenson in #1323
- test(STUDIO-388): confirm creator-scan indexes freshly-installed content correctly by @RBStephenson in #1324
- feat(STUDIO-389): add installer frontend flow by @RBStephenson in #1325
- fix(STUDIO-363): remove name_parser's module-level user-rule globals by @RBStephenson in #1326
- fix(STUDIO-367): reconcile boot backfill and scan grouping with a CHARACTER signal by @RBStephenson in #1327
- fix(STUDIO-326): stabilize model sort ties by @RBStephenson in #1328
- fix(STUDIO-260): deny Electron permissions by default by @RBStephenson in #1329
- test(STUDIO-369): pin creator case identity policy by @RBStephenson in #1330
- STUDIO-172: Surface Reorganize side effects by @RBStephenson in #1331
- STUDIO-345: Add desktop support actions to Help menu by @RBStephenson in #1332
- fix(STUDIO-321): run import cleanup asynchronously by @RBStephenson in #1333
- STUDIO-376: scope Reorganize preview by scan root by @RBStephenson in #1334
- STUDIO-361: bound grouping strategy regroup scope by @RBStephenson in #1342
- fix(STUDIO-262): route AI-endpoint httpx calls through url_guard by @RBStephenson in #1343
- fix(STUDIO-263): guard raw-byte file endpoints against cross-origin GET by @RBStephenson in #1344
- perf(STUDIO-299): memoize gallery-image discovery per creator walk by @RBStephenson in #1345
- feat(STUDIO-344): persist desktop zoom level across launches by @RBStephenson in #1346
- fix(STUDIO-327): get_neighbors filter parity with list_models by @RBStephenson in #1347
- build(deps): bump uvicorn from 0.52.1 to 0.52.4 in /backend by @dependabot[bot] in #1335
- fix(STUDIO-392): resolve tar DoS advisory in desktop lockfile by @RBStephenson in #1349
- fix(STUDIO-391): manual variant reorder now actually persists visually by @RBStephenson in #1348
- build(deps): bump sqlalchemy from 2.0.51 to 2.0.52 in /backend by @dependabot[bot] in #1341
- build(deps): bump numpy from 2.5.1 to 2.5.2 in /backend by @dependabot[bot] in #1338
- build(deps): bump ruff from 0.16.2 to 0.16.4 in /backend by @dependabot[bot] in #1340
Full Changelog: v1.0.0...v1.1.0