You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
v1.1.10 - Tighter Bundle
v1.1.10 ships the v1.1.9 changes (#338). The v1.1.9 release was tagged
but published no installers: its Windows build stopped at the mode CSS
ownership guard, which compared Windows-style paths against /-separated
ones. The guard now compares POSIX paths, so the stricter CSP and the
per-mode lazy stylesheets below reach every platform in this release.
Carried over from v1.1.9 (no installers were published for it)
The shipped CSP no longer lets scripts load from blob: URLs (#334, #335).script-src is now 'self' only, so content injected into the
webview cannot mint executable script URLs; worker-src keeps blob: for
the graph layout worker. The build fails if a Tauri config, the bundle, or
the compiled binary would bring script-src blob: back.
Each mode's styles load with that mode (#334, #335). Today, Tasks,
Calendar, Meetings, Drafts, Gap, and Agents CSS moved out of the startup
stylesheet into their lazy chunks, cutting the initial CSS to about 45 KiB
gzip against the 70 KiB budget. Mode chunks are warmed one at a time in idle
time after launch, and shared chrome such as task dialogs stays in the
startup stylesheet so it is styled before any mode loads.