v0.3.0: Merge pull request #3 from SimCubeLtd/feat/google_fonts
What's Changed
- feat: relax link and styling so archify can work by @prom3theu5 in #3
Full Changelog: v0.2.0...v0.3.0
Highlights
Two upload rules become configurable per-server, both off by default. Documents that were rejected
outright can now be accepted deliberately, without loosening the policy for everyone.
--allow-font-links/KERYX_ALLOW_FONT_LINKSaccepts a<link>whoserelis only
stylesheet,preconnect,dns-prefetchorpreloadand whosehrefhost is
fonts.googleapis.comorfonts.gstatic.com.<base>and every other host stay blocked. The
flag also widens the CSP on served drafts withstyle-src https://fonts.googleapis.comand
font-src https://fonts.gstatic.com, without which an accepted font link would still be blocked
in the browser.--allow-safe-handlers/KERYX_ALLOW_SAFE_HANDLERSaccepts an inlineon*handler whose body
is nothing but;-separated assignments of literals or dotted property paths, the async-CSS
idiomonload="this.media='all'". Anything containing(,[,<, a template literal, or a
blocked scheme is still rejected, so a permitted handler can set properties but cannot call
anything.
Also in this release:
keryx uploadreads the server's effective policy fromGET /api/mebefore validating locally.
--max-html-bytesexisted in 0.2.0 but had no effect on CLI uploads, which always validated
against the hardcoded 512 KB default. Raising the server cap now works end to end.<script type="application/json">andapplication/ld+jsonare accepted with no flag. The HTML
spec classifies these as data blocks that no browser executes, so rejecting them was a bug in the
type allowlist rather than a safety control.module,importmapandspeculationrulesstay
blocked.- URL attributes block a dangerous scheme only at the start of the value, so a URL such as
https://example.com/?q=javascript:1is no longer a false positive.
PDF publication keeps its own stricter policy and is unchanged: keryx publish still rejects
scripts and external assets.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The
release archives also include the README, licence, and ready-made Keryx agent skills.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.3.0-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.3.0-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download v0.3.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.3.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your
PATH.
macOS (Apple Silicon)
gh release download v0.3.0 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.3.0-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.3.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.3.0-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.3.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser may attach a
quarantine flag and cause Gatekeeper to refuse it; clear that flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs: no binary is published. Build from source, or run the Apple Silicon build under
Rosetta 2. Rosetta is unsupported for this release and untested.
Windows (x86-64)
In PowerShell:
gh release download v0.3.0 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.3.0-x86_64-pc-windows-msvc.zip*'
# Compare against the published checksum
Get-FileHash keryx-0.3.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.3.0-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.3.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.3.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen may warn on first run. Nothing here needs
administrator rights.
Build from source (any platform)
Install the Rust nightly toolchain, then:
rustup toolchain install nightly --profile minimal
git clone --branch v0.3.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly build --release --locked
./target/release/keryx --versionOr install the tagged release straight into ~/.cargo/bin:
cargo +nightly install --git https://github.com/SimCubeLtd/keryx \
--tag v0.3.0 --locked keryx--locked uses the exact dependency versions in the committed Cargo.lock.