Skip to content

Releases: Richy1989/keepIT

v0.8.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 19:41

Voice notes, and a way to take everything with you. Record straight into a note on Android and play
it back there or in the browser -- from the notes overview, without opening the note. Export your
whole account to a file you keep, and load it back on another server or another phone.

This release needs the server updated and its reverse proxy reconfigured. On an old proxy
config voice notes play back as dead controls and import is refused outright, so read Updating
first.

Updating

  • Two columns are added to note attachments (the kind of attachment, and how long a recording
    runs). On PostgreSQL the migration applies at startup; on SQLite the schema reconciler adds them
    to the database file you already have. Nothing is rewritten and nothing is lost.
  • Both nginx configs changed -- deploy/nginx.conf for the single container and
    web/nginx.conf for Compose. If you run your own proxy, carry two things across:
    • The Content-Security-Policy needs media-src 'self' blob:. Without it the browser blocks
      playback and a voice note renders as greyed-out, dead controls. Images were unaffected because
      img-src already allowed blob:.
    • /api/import and /api/export need their own location blocks: a 256 MB request body, request
      buffering off, and a 600-second read timeout. The 12 MB cap that suits a single photo refuses a
      real backup at the proxy, before the API ever sees it or can say why.
  • Two new settings, both with working defaults: App:Media:MaxAudioBytes (10 MB, the same as an
    image, because both travel through that proxy cap) and App:Media:MaxAudioPerNote (10).
  • Export and import each get their own rate limit, so downloading a backup does not spend the
    budget you need to upload one.

Voice notes

  • Recording is on Android: a microphone button in the editor, a live timer, and playback with a
    progress bar. Not in the web app, because a browser cannot record audio over plain http -- which
    keepIT supports on a LAN -- so a record button there would simply be missing for a real share of
    users.
  • Playback is everywhere, including straight from the notes overview on both clients, so a
    twelve-second recording does not need a note opened to hear it. Only one plays at a time, and
    nothing is downloaded until you press play.
  • Recordings are stored exactly as uploaded. There is no audio encoder in the container, so the
    file that was recorded is the file that is kept and served. That makes identifying the bytes the
    whole of the validation: the format is recognised by signature rather than by the name the client
    sent, and an MPEG-4 carrying a video track is refused -- an attachment endpoint must not become
    video hosting.
  • Mono, 22.05 kHz, AAC in m4a, around 32 kbps: roughly 40 minutes of speech inside the 10 MB
    attachment cap.
  • Recording works offline and in standalone mode. It queues in the same outbox a photo uses, and
    plays from the staged file before it has ever reached a server.

Export and import

  • GET /api/export streams a zip of the account -- notes, lists and every attachment -- and
    POST /api/import reads one back. In the web app both are on the settings page; on Android they
    are in Settings.
  • In standalone mode the archive is built and applied on the phone, so a device that has never
    seen a server can still back itself up and restore.
  • Import only ever adds. Every note in the file arrives as a new note and nothing already in
    the account is touched, so importing the same file twice gives you duplicates. That is the
    deliberate trade: the one operation that could destroy someone's notes is the one that must not
    be able to.
  • The archive is the API's own note and list formats plus the attachment files, and it carries a
    schema version -- so an older keepIT refuses a newer file outright instead of importing half of
    it.
  • The archive also records the version of the server that wrote it, so a failed import can be
    traced back to where the file came from.

Docker: docker pull richy1989/keepit:0.8.0

The Android APK is attached below: download and install it directly (sideload).

Full Changelog: v0.7.6...v0.8.0

v0.7.6

Choose a tag to compare

@github-actions github-actions released this 22 Sep 20:13

A visual release: the web app is easier to read, above all in the light theme, and lays notes out
in reading order. In the Android app, sign-out moves into the menu. The server itself is
unchanged, so updating needs no change to your setup.

Web app

  • Notes are laid out row by row, newest first across the top, in balanced columns. Before, they
    ran down the left-hand column first.
  • Easier to read in the light theme: text and icons in the accent colour use a darker shade of it,
    so the default yellow no longer disappears on white. The light background is a touch grey, so
    white notes stand out from it.
  • Timestamps, counts, hints and placeholders have more contrast in all three themes, on menus and
    dialogs as well as on the page.
  • Deleting a list, leaving a shared note and emptying the trash ask in a keepIT dialog instead of
    the browser's pop-up.
  • A note's reminder and timestamp wrap onto a new line in a narrow column instead of being cut off.
  • The search box fits its label on a phone again. The keepIT mark now shows from tablet width up,
    where there is room for it; on a phone the menu button already marks the app.
  • The Inter typeface now actually loads. keepIT serves it itself, so no font service is contacted.
  • Menus and dialogs fade in, unless your system asks for reduced motion. Shadows, the dimmed
    backdrop behind dialogs and the keyboard focus outline follow the theme.

Android app

  • Sign out has moved from the top bar to the bottom of the menu, under your name and email address.
    In standalone mode there is still no sign-out in the menu: erasing the phone stays in Settings.
  • The menu scrolls, so with many lists, Notifications and Settings stay within reach.
  • Timestamps, counters and hints have more contrast, in the app and on the home-screen widget.

Also

  • The web app has its first automated tests, run in CI: every theme and accent combination is
    checked for readable contrast, and the note layout for reading order. The Android app checks its
    colours the same way.

Docker: docker pull richy1989/keepit:0.7.6

The Android APK is attached below: download and install it directly (sideload).

Full Changelog: v0.7.5...v0.7.6

v0.7.5

Choose a tag to compare

@github-actions github-actions released this 22 Sep 09:50
keepIT logo

A security release: six fixes from an audit of the server, more reliable sign-in in the Android
app, and a Delete all button in the trash. Most setups update without any change, but check the
first list below before you do.

Before you update

These setups need a change, or keepIT or its email stops working:

  • Email (SMTP) without App__PublicBaseUrl: password-reset emails aren't sent until you set it
    to the address your users open keepIT at. The server log and the web app's Settings page say so.
    (FAQ)
  • A malformed App__PublicBaseUrl, for example without https://: the server stops at startup
    and names the setting. (FAQ)
  • A mail server without STARTTLS: email is no longer sent unencrypted. Use port 465 with
    Email__UseStartTls=false, or, for a relay on your own network only,
    Email__AllowUnencrypted=true. (FAQ)
  • The data folder on a network share that can't change file owners, writable only by root:
    keepIT doesn't start. Make the folder writable for uid 1654.
    (FAQ)

You'll also notice, with nothing to do:

  • The data folder (on Unraid, appdata/keepit) now belongs to uid 1654, because keepIT no longer
    runs as root. (FAQ)
  • The single container's log includes nginx's request lines. Docker's log rotation can cap it.
    (FAQ)

New

  • Delete all in the trash, in the web app and the Android app. Your own notes are deleted
    for good; a note someone shared with you is only removed from your notes, and its owner keeps
    it. The Android app on a server older than 0.7.5 deletes only your own notes.

Security

  • Password-reset links are built only from App__PublicBaseUrl, never from the request. Anyone
    could forge the request's address and have your server send a genuine reset email pointing at
    their own site.
  • Email always goes out encrypted: STARTTLS is required, where before it was silently skipped when
    the mail server, or someone in between, didn't offer it.
  • An uploaded image's size is checked before it is decoded (at most 100 megapixels, set with
    App__Media__MaxImagePixels), only an animation's first frame is decoded, and at most two
    uploads are processed at once. Before, one small crafted file could exhaust the server's memory.
  • Sign-in tokens that travel in URLs (the web app's live-sync connection, password-reset links)
    are blanked in nginx's logs, and pages send only the site's origin as the referer.
  • The app runs as an unprivileged user in both container images, and in the single container it
    can only be reached through nginx. docker stop now shuts it down cleanly.
  • The sign-in cookie is marked HTTPS-only on every HTTPS request, so an instance behind a TLS
    proxy is protected without changing Auth__RefreshCookie__Secure.
  • The web app's router is updated past a high-severity advisory, in a mode keepIT doesn't use.

Android app

  • Turning the phone, switching to dark mode or leaving the app while it starts no longer shows
    the sign-in screen or signs you out, and signing in or out finishes even if the screen is
    rebuilt.
  • When the server refuses a photo as too large, the message names both limits: 10 MB and 100
    megapixels.
  • Updated libraries: Compose, Navigation, Coil, OkHttp 5, Retrofit 3 and the SignalR client. The
    app is compiled against Android SDK 37; the Android versions it runs on are unchanged.

Also

  • An FAQ for people running keepIT: updating, reverse proxies and HTTPS, email, images.
  • Settings shows a warning while unencrypted email is allowed.
  • Dependency updates, among them .NET packages 10.0.12, SQLite 3.53, React 19.3 and nginx 1.31 in
    the Compose web image.
  • Known-vulnerable dependencies now fail CI, checked weekly as well, and Dependabot proposes
    updates.

Docker: docker pull richy1989/keepit:0.7.5

The Android APK is attached below: download and install it directly (sideload).

What's Changed

  • build(deps): bump nginx from 1.27-alpine to 1.31-alpine in /web by @dependabot[bot] in #3
  • build(deps): bump the web-minor-and-patch group in /web with 15 updates by @dependabot[bot] in #5
  • Bump the api-minor-and-patch group with 13 updates by @dependabot[bot] in #10
  • build(deps): bump the actions group with 4 updates by @dependabot[bot] in #4
  • Bump Microsoft.NET.Test.Sdk from 17.14.1 to 18.10.1 by @dependabot[bot] in #11
  • Bump xunit.runner.visualstudio from 3.1.4 to 4.0.0 by @dependabot[bot] in #12
  • build(deps): bump the android-minor-and-patch group in /app with 10 updates by @dependabot[bot] in #7
  • build(deps): bump retrofit from 2.11.0 to 3.0.0 in /app by @dependabot[bot] in #8
  • build(deps): bump com.squareup.okhttp3:okhttp from 4.12.0 to 5.5.0 in /app by @dependabot[bot] in #9

New Contributors

Full Changelog: v0.7.1...v0.7.5

v0.7.1

Choose a tag to compare

@github-actions github-actions released this 21 Sep 13:06

Docker: docker pull richy1989/keepit:0.7.1

The Android APK is attached below — download and install it directly (sideload).

Full Changelog: v0.7.0...v0.7.1

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 20 Sep 22:11

Docker: docker pull richy1989/keepit:0.7.0

The Android APK is attached below — download and install it directly (sideload).

Full Changelog: v0.6.0...v0.7.0

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 10 Sep 20:01
keepIT logo

Welcome a new release of keepIT! - v0.6.0

This release re-homes the Android app under its own domain in preparation for publishing on F-Droid. No feature changes — same keepIT you know.

Android

  • Fixed the startup crash
  • Checklists sink completed items
  • Android checklist parity
  • Optimistic-update refactor
  • Unraid template fix
  • Readme/store-download prep

Not long until the app is published!

Buy Me A Coffee

Docker: docker pull richy1989/keepit:0.6.0
The Android APK is attached below — download and install it directly (sideload).
Full Changelog: v0.5.9...v0.6.0

v0.5.9

Choose a tag to compare

@github-actions github-actions released this 24 Jul 19:24
keepIT logo

Welcome a new release of keepIT! - v0.5.9

This release re-homes the Android app under its own domain in preparation for publishing on F-Droid. No feature changes — same keepIT you know.

Android

  • fDroid jobs run successfully
  • Fixes fDroid repo requirement bugs
  • Added R8 (code shrinking) to app

Not long until the app is published!

Buy Me A Coffee

Docker: docker pull richy1989/keepit:0.5.9
The Android APK is attached below — download and install it directly (sideload).
Full Changelog: v0.5.8...v0.5.9

v0.4.6

Choose a tag to compare

@github-actions github-actions released this 22 Jul 22:01
keepIT logo

Welcome a new release of keepIT! 🎉 keepIT is a modern, self-hosted notes app for people who want their notes to actually stay their own — everything lives on your server, with no third-party cloud and no account with anyone but yourself. Write quick text notes with rich formatting (bold, headings, lists, links, code) or checklists you tick off as you go, group them into lists, pin the important ones, and find anything instantly with search. Everything syncs in real time across your devices — a note edited on your laptop shows up on your phone without a refresh — and edits are optimistic, so the UI never makes you wait on the network. Share any note by email to view or edit together, while you each keep your own pins, lists, and reminders. The native Android app brings it all to your phone: offline-first, a home-screen widget for recent notes and one-tap capture, and reminders that arrive as real notifications even with the screen locked or no internet.

Docker: docker pull richy1989/keepit:0.4.6

The Android APK is attached below — download and install it directly (sideload).

Full Changelog: v0.4.5...v0.4.6

Buy Me A Coffee

v0.4.5

Choose a tag to compare

@github-actions github-actions released this 21 Jul 15:58
keepIT logo

Welcome a new release of keepIT! 🎉 keepIT is a modern, self-hosted notes app for people who want their notes to actually stay their own — everything lives on your server, with no third-party cloud and no account with anyone but yourself. Write quick text notes with rich formatting (bold, headings, lists, links, code) or checklists you tick off as you go, group them into lists, pin the important ones, and find anything instantly with search. Everything syncs in real time across your devices — a note edited on your laptop shows up on your phone without a refresh — and edits are optimistic, so the UI never makes you wait on the network. Share any note by email to view or edit together, while you each keep your own pins, lists, and reminders. The native Android app brings it all to your phone: offline-first, a home-screen widget for recent notes and one-tap capture, and reminders that arrive as real notifications even with the screen locked or no internet.

Docker: docker pull richy1989/keepit:0.4.5
The Android APK is attached below — download and install it directly (sideload).

Full Changelog: v0.4.0...v0.4.5

Buy Me A Coffee

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 17 Jul 21:52
keepIT logo
Welcome to the first release of keepIT! 🎉 keepIT is a modern, self-hosted notes app for people who want their notes to actually stay their own — everything lives on your server, with no third-party cloud and no account with anyone but yourself. Write quick text notes with rich formatting (bold, headings, lists, links, code) or checklists you tick off as you go, group them into lists, pin the important ones, and find anything instantly with search. Everything syncs in real time across your devices — a note edited on your laptop shows up on your phone without a refresh — and edits are optimistic, so the UI never makes you wait on the network. Share any note by email to view or edit together, while you each keep your own pins, lists, and reminders. The native Android app brings it all to your phone: offline-first, a home-screen widget for recent notes and one-tap capture, and reminders that arrive as real notifications even with the screen locked or no internet.

Docker: docker pull richy1989/keepit:0.4.0
The Android APK is attached below — download and install it directly (sideload), Playstore will follow.

Full Changelog: v0.3.0...v0.4.0

Buy Me A Coffee