v2026.3 #147
TRC-Loop
announced in
Announcements
v2026.3
#147
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Changes
chore(deps): Bump the frontend-dependencies group across 1 directory with 11 updates -
@dependabot[bot] in #118
Bumps the frontend-dependencies group with 11 updates in the /frontend directory:
5.2.85.3.05.2.85.3.03.44.03.45.03.27.33.28.03.27.33.28.03.27.33.28.03.27.33.28.018.0.618.0.75.56.45.56.74.7.24.7.38.1.48.1.5Updates
@fontsource/familjen-groteskfrom 5.2.8 to 5.3.0Commits
Updates
@fontsource/spline-sans-monofrom 5.2.8 to 5.3.0Commits
Updates
@tabler/icons-sveltefrom 3.44.0 to 3.45.0Release notes
Sourced from @tabler/icons-svelte's releases.
Commits
975920fRelease 3.45.04a4b287Add Astro support for Tabler Icons (#1559)Updates
@tiptap/corefrom 3.27.3 to 3.28.0Release notes
Sourced from @tiptap/core's releases.
... (truncated)
Changelog
Sourced from @tiptap/core's changelog.
Commits
c5f4b57chore(release): release new stable release (#8038)24263ecchore(release): publish a new stable versionUpdates
@tiptap/extension-linkfrom 3.27.3 to 3.28.0Release notes
Sourced from @tiptap/extension-link's releases.
... (truncated)
Changelog
Sourced from @tiptap/extension-link's changelog.
Commits
c5f4b57chore(release): release new stable release (#8038)24263ecchore(release): publish a new stable versionUpdates
@tiptap/pmfrom 3.27.3 to 3.28.0Release notes
Sourced from @tiptap/pm's releases.
... (truncated)
Changelog
Sourced from @tiptap/pm's changelog.
Commits
c5f4b57chore(release): release new stable release (#8038)24263ecchore(release): publish a new stable versionUpdates
@tiptap/starter-kitfrom 3.27.3 to 3.28.0Release notes
Sourced from @tiptap/starter-kit's releases.
... (truncated)
Changelog
Sourced from @tiptap/starter-kit's changelog.
... (truncated)
Commits
c5f4b57chore(release): release new stable release (#8038)24263ecchore(release): publish a new stable versionUpdates
markedfrom 18.0.6 to 18.0.7Release notes
Sourced from marked's releases.
Commits
a8971a1chore(release): 18.0.7 [skip ci]d899c2echore(deps): bump actions/setup-node from 6 to 7 (#4025)7fbf82echore(deps-dev): bump semantic-release from 25.0.7 to 25.0.8 (#4026)738edf2chore(deps-dev): bump brace-expansion from 5.0.2 to 5.0.6 (#4027)9154f8ffix: Avoid O(n^2) masked source rebuild in inline tokenizer (#4017)f945fc5fix: Avoid O(n^2) backtracking in HTML block close and tilde interrupt regexe...3f144a0fix: keep empty list after blockquote as a sibling block (#4004)0de7188fix: preserve code spans adjacent to tildes (#4012)f056437fix: Recognize setext headings whose first line starts with # (#4015)12bfa94chore(deps-dev): bump semantic-release from 25.0.5 to 25.0.7 (#4020)Updates
sveltefrom 5.56.4 to 5.56.7Release notes
Sourced from svelte's releases.
Changelog
Sourced from svelte's changelog.
Commits
b29d700Version Packages (#18560)b791cacchore: provideindentoption forprint(#18474)4a6a85bVersion Packages (#18552)d0dbe1aperf: skip quadratic blocker analysis when no top-level await (#18548)22e0adbfix: rerun derived that had an abort controller on reconnection (#18551)602a873Version Packages (#18497)a4fd67efix: $state.eager() is sometimes incorrect in SSR (#18530)199ffebfix: clear previous_task reference after abort in Tween (#18541)edeef1fchore: add some failing tests (#18528)a91b068fix: abort deriveds own AbortSignal when it disconnects (#18400)Updates
svelte-checkfrom 4.7.2 to 4.7.3Release notes
Sourced from svelte-check's releases.
Commits
6a7012cVersion Packages (#3077)d653640feat: zero-config+error.svelteprops (#3076)Updates
vitefrom 8.1.4 to 8.1.5Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
Commits
5e7fe12release: v8.1.56c08c39fix(optimizer): respect importer module format for dynamic import interop wit...5a72b87fix(client): overlay error message format align rolldown (#22869)f8b38e3fix(module-runner): don't crash stack-trace source mapping when globalThis.Bu...8100320fix(bundled-dev): avoid duplicatedbuildEnd(#22931)c88c236docs(build): fix incorrect@defaultfor build.cssMinify (#22948)b59a73ffix(ssr): scope switch-case declarations to the switch, not the function (#22...fef682dfix(deps): update all non-major dependencies (#22921)3c345e4fix(deps): update rolldown-related dependencies (#22922)369ed60docs(build): fix incorrect@defaultfor build.lib.formats (#22911)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionschore(deps): Bump the go-dependencies group across 1 directory with 4 updates -
@dependabot[bot] in #114
Bumps the go-dependencies group with 3 updates in the / directory: github.com/yuin/goldmark, golang.org/x/crypto and modernc.org/sqlite.
Updates
github.com/yuin/goldmarkfrom 1.8.2 to 1.8.4Release notes
Sourced from github.com/yuin/goldmark's releases.
Commits
50ba9fcfix: disable svg in data:image urls2326684fix: #556Updates
golang.org/x/cryptofrom 0.52.0 to 0.54.0Commits
cdce021go.mod: update golang.org/x dependenciesd9474ccopenpgp: make the deprecation message more explicit7626c50ssh: verify declared key type matches decoded key in authorized_keys0471e79ssh/agent: enforce strict limits on DSA key parameters6435c37ssh: sanitize client disconnect messages7d695dassh/agent: drain channel stderr in agent forwarders5b7f841acme/autocert: fix data race in Manager.createCert0b316e7argon2: update RFC 9106 parameter recommendations55aec0ax509roots/fallback: update bundle5f2de1ainternal: remove wycheproof testsUpdates
golang.org/x/netfrom 0.55.0 to 0.56.0Commits
9e7fdbfinternal/http3: fix wrong argument being given when validating header valueb686e5finternal/http3: add gzip support to transport8a34885go.mod: update golang.org/x dependencies72eaf98dns/dnsmessage: correctly validate SVCB record parameter order82e7868dns/dnsmessage: avoid panic when parsing SVCB record with truncated datab64f1fainternal/http3: add server support for "Trailer:" magic prefix2707ee2internal/http3: implement HTTP/3 clientConn methods31358ccinternal/http3: snapshot response headers at WriteHeader time8ecbaa9html: don't adjust xml:base8ae811ahtml: properly handle end script tag in fragment modeUpdates
modernc.org/sqlitefrom 1.53.0 to 1.54.0Changelog
Sourced from modernc.org/sqlite's changelog.
... (truncated)
Commits
693ff38upgrade to SQLite 3.53.35d24346Merge branch 'texttotime-aggregates' into 'master'892d847sqlite: document _texttotime empty-decltype upgrade, widen #248 comment, add ...f2c8758sqlite: _texttotime best-effort parse for empty-decltype TEXT columns (#248)feat: browse themes button in settings -
@TRC-Loop in #122
Closes #121
Adds a "Browse themes" button to the Themes settings category, between "Import theme..." and "Open folder". It opens https://themes.pelton.app in the user's browser via
BrowserOpenURL, the same way About opens links.Nothing is fetched into the webview, so no third-party content reaches the app. Downloads come back in through the existing import flow.
2 new i18n keys in all five locales.
feat: choose which parts of a theme to import -
@TRC-Loop in #120
Closes #106
When a
.peltonthemecarries both colors and custom CSS, the import modal now asks which parts to bring in. Both are checked by default, so a plain import is still one click.Behavior
Implementation
themepack.SelectParts(keepTokens, keepCSS)drops the deselected part's files from the container and rewritesmanifest.json, so the copy written into the themes folder is exactly what was picked. Nothing is filtered at apply time.ConfirmThemeImporttakes the two flags and applies the selection beforeWriteContainer.PreviewThemeImportreportstokenCountso the modal knows whether the theme defines colors at all.Tests
internal/themepack/parts_test.gocovers all three selections through a write/read round trip: dropping CSS keeps tokens and icons, dropping tokens keeps CSS, keeping both changes nothing.6 new i18n keys in all five locales.
feat: customizable in-app menu bar -
@TRC-Loop in #117
Closes #73.
Lets users customize the in-app menu bar directly on the bar, via an in-place editor mode entered from Settings > Interface.
What
How
menu_bar_layout), so it rides the existing config export/import with no backend changes.resolveBar()drives the normal bar (incl. submenu flyouts); the editor renders the raw layout and writes straight to the store, so edits preview live. A merge step folds in newly shipped built-ins and drops removed ones.svelte-dnd-action,@tabler/icons(icon node data). i18n added to all 5 locales.svelte-check and
vite buildpass. The drag/click GUI interaction still wants a manualmake runsmoke test.feat: offer to set Pelton as the default mail client -
@TRC-Loop in #146
Closes #119 (the default-mail-client half; the
mailto:handling half is #145).Lets Pelton register as the system's default
mailto:handler, offered quietly: one skippable onboarding step, and a passive line in the About section. Nothing nags.What changed
Backend (
internal/desktop/defaultclient*.go) — a small cross-platform surface (DefaultMailClientStatus,SetDefaultMailClient) over per-OS implementations:_darwin.go, cgo/CoreServices): detect withLSCopyDefaultHandlerForURLScheme, set withLSSetDefaultHandlerForURLScheme(which shows the system's own confirmation sheet). Compares against the bundle idsh.arne.pelton._linux.go):xdg-settings get/set default-url-scheme-handler mailto pelton.desktop._windows.go): opensms-settings:defaultapps(Windows does not allow setting it programmatically); detection returns "unknown" until the installer registers a ProgId, so the About line stays hidden rather than guessing wrong._other.go): reports unknown / unsupported.Detection returns a
knownflag; where a platform cannot answer reliably the UI shows nothing.Frontend:
defaultmailstep with a single "Set as default" action, skippable via the nav and the global skip. It is dropped from the flow entirely when Pelton is already the default (or the platform can't say), so it never shows a pointless offer.known && !isDefault. No banner, no modal, no repeat prompting.Notes
LS*calls remain the only supported non-private way to read/set a scheme handler.Verified:
go build ./...,go vet,go test ./internal/desktop/, linux+windows cross-compiles all pass;svelte-checkclean; all 5 locales at key parity;go.mod/go.sumunchanged afterwails generate module.feat: open mailto: links in a prefilled compose -
@TRC-Loop in #145
Part of #119 (the
mailto:handling half). Clicking amailto:link anywhere on the machine now opens a Pelton compose window with the recipient, subject and body prefilled.This is the first of two PRs for #119. The default mail client half (onboarding step + passive About line + per-platform set/detect) is a separate change and will follow; #119 stays open until then.
What changed
internal/desktop/mailto.go) forto(path + query),cc,bcc,subject,body, with additionaltovalues merged. Unknown headers are ignored; a malformed URL yields an empty draft (blank compose) rather than an error. Percent-decoding usesPathUnescape, so+is a literal plus per the spec (not a space) and%0D%0Ain the body is preserved. Fully unit-tested (mailto_test.go).SingleInstanceLock): a second launch (e.g. anothermailto:click) hands its argv to the running app and surfaces its window instead of spawning a second Pelton. The dev build (PELTON_DEV) uses a separate lock id so it never collides with an installed Pelton..desktopfile already declaresMimeType=x-scheme-handler/mailto;andExec=pelton %u); it is stashed at launch and picked up on first mount, or handed over via the single-instance path when already running.mac.Options.OnUrlOpen(the URL arrives as an Apple event, not argv).wails.jsonnow declares themailtoprotocol soInfo.plistrendersCFBundleURLTypes.consumePendingMailto()picks up a launch draft after the sidebar loads;onMailtoComposehandles links opened while running. Both route throughopenComposeWith, which prefills the compose and reveals the cc/bcc rows only when they carry a value.mailto:arrives before any mailbox exists, the draft is held and opened once onboarding finishes or a mailbox is added, rather than dropped.Notes / not in this PR
SOFTWARE\Clients\Mail,Capabilities\URLAssociations) is installer work per the issue and is not part of this change..desktopassociation) needs manual verification from a packaged build; the parser and the delivery/onboarding logic are covered by tests and typecheck.Verified:
go build ./...,go vet,go test(mailto suite) all pass; cross-compiles for linux and windows succeed;svelte-checkclean;go.modconfirmed unchanged afterwails generate module.feat: read-only MCP server for AI agents -
@TRC-Loop in #131
Closes #77
A read-only Model Context Protocol server so external AI agents can browse, read and search Pelton's cached mail. Off by default.
Design decisions (agreed in waves)
127.0.0.1only. Pelton runs continuously, so an agent connects to a URL rather than spawning it. ArequireLoopbackguard makes binding to a routable interface impossible.github.com/modelcontextprotocol/go-sdk.list_accounts,list_folders,list_messages,get_message,search_messages.get_messagereturns headers, message metadata (Message-ID, size), the plain-text body, the HTML body when present (most mail has one), and attachment metadata (name, type, size) but never attachment bytes. No tool sends, moves, flags or deletes; that guarantee rests on theMailboxinterface having no mutating method. Write actions are tracked in MCP server: write actions (send, mark, move, delete) #127.Backend
internal/mcpserverholds the protocol plumbing behind the narrowMailboxinterface;internal/desktop/bind_mcp.goadapts the store and search index to it and owns the lifecycle. The server starts at boot when enabled, and any settings change (enable, port, token) stops and restarts it under one lock. Settings persist asmcp_enabled/mcp_port/mcp_token.Tests
internal/mcpserver/mcpserver_test.go: every tool round-trips over an in-memory transport and returns its data (including thatlist_messageshonours the limit and search params are forwarded); typed output is exposed as structured content, not only JSON text; the bearer middleware rejects missing/wrong/prefix-less tokens and admits the correct one;Startrefuses to run without a token;requireLoopbackaccepts loopback and rejects routable addresses.Verification
go build ./..., fullgo test ./internal/...,go vet,gofmtclean; svelte-check 0 errors, frontend build clean. New i18n keys added to all five locales.Summary
AI usage
The change appears Very Likely to have used AI assistance, based on the provided AI-generated file summaries and highly structured implementation. There is no evidence here that it was fully agentic or used 100%; AI was likely used to help with implementation and documentation.
feat: theme creator color picker, metadata and advanced section -
@TRC-Loop in #124
Closes #107
All three parts of the issue.
Color picker
Replaces the native
<input type="color">well withColorPicker.svelte: a saturation/value area, hue and alpha sliders, and typed hex plus R/G/B fields. The color model lives infrontend/src/theme/color.tsand parses#rgb,#rgba,#rrggbb,#rrggbbaa,rgb()andrgba(), in comma or space form.rgba(...). Output is hex while opaque andrgba()once it is not, matching how the built-in palettes are written.color-mix(), named colors) still round-trip: the text field stays authoritative and the picker only overwrites the token once you actually pick something.Editable metadata
Author and version join name in the editor and are written into
manifest.json, so exported.peltonthemefiles carry correct data. Editing an existing theme now loads through a newGetThemeDraftbinding, which returns the theme in editor form rather than apply form.Advanced section
A collapsed
<details>holding:-bgpartners of the status colors stay out, as the save computes those.CSS is stored as one file the editor owns (
css/custom.css), so editing a theme that already ships stylesheets adds to them instead of overwriting the author's work. Remote references are stripped on save: CSS typed or pasted into the editor is held to the same no-network rule as an import, and unlike an import there is no author to ask. Capped at 256 KB with a clear error, well under the container's own limit.Tests
internal/desktop/bind_theme_editor_test.gocovers the stylesheet handling: appended once and never duplicated, remote references and@importstripped, clearing removes both the file and the manifest entry while leaving the theme's own stylesheets alone, oversized input rejected.11 new i18n keys in all five locales.
feat: verbose sync shows current mailbox in status line -
@TRC-Loop in #144
Closes #128.
Adds an opt-in verbose sync mode so a running sync says which mailbox it is working on instead of a plain "Syncing", which made large or slow syncs look stuck.
What changed
verbose_syncpreference (off by default), wired throughUIPrefsDTO, the prefs store, andSettingKeys.sync:progressevents the backend already emitted (folder name + done/total). A newsyncFolderstore holds the mailbox currently being synced; it clears on the trailing progress event and when the sync ends.Notes
syncFolders, it just had no consumer.feat: views (preset searches) -
@TRC-Loop in #135
What
Adds Views (preset searches): user-defined saved searches surfaced as their own entries, per the decisions on the issue.
A View = name + icon + color + a filter (free text, from/to/subject, relative date window, and scope: unread-only / flagged-only / has-attachment / account or all).
Behaviour
Hidden(feature off),In sidebar(a group above the account trees), orSeparate tab(a Mail/Views toggle that swaps the sidebar body).New viewaction in the customizable menu bar, and assignable keyboard shortcuts (new-view,next-view,prev-view).Backend
viewstable (migration 0011) + CRUD + reorder (internal/storage/views.go).internal/desktop/bind_views.go): text criteria go through the full-text index, pure-scope views read the store, then scope/date/hygiene filters apply in Go. Results cap at 500 newest-first. Bound methodsListViews/SaveView/DeleteView/ReorderViews;ListMessagesgains asavedViewkind.views:changedevent drives badge refresh.Frontend
viewsstore (+ global editor state), sidebarSavedViewsgroup and tab toggle,ViewEditorModal, curated icon/color palette,viewsPlacementpreference, and the menu/shortcut wiring.Tests / checks
internal/storageview CRUD + reorder tests; go build + desktop/storage/imap suites pass.Notes
Closes #103
feat: VIP senders with native new-mail notifications -
@TRC-Loop in #142
Adds VIP senders and native OS new-mail notifications (#126).
What it does
Matching
Exact address only. Stored lowercased; a changing display name never breaks the match (bareAddress helper on both sides).
How it's built
Known limitation
beeep has no per-notification click callback, so clicking a notification does not open that exact message. Exact click-to-open would need platform-specific code and is worth a separate issue.
Closes #126
fix: rename settings category Network to Proxy -
@TRC-Loop in #137
Renames the user-facing settings category label from Network to Proxy in all five locales, since the category only holds proxy settings. Internal category id and the network.proxy.* key namespace are unchanged.
Closes #116
fix: resync off the idle connection so new mail arrives promptly -
@TRC-Loop in #133
What
New mail was fetched over the connection that was still parked in IMAP IDLE, so the fetch could not run until IDLE stopped, which only happened on go-imap's 28-minute idle restart (or app shutdown). New mail therefore took minutes to appear instead of seconds.
Fix
internal/imap: addIdleUntil(ctx)which parks on IDLE, blocks until the server pushes an update / ctx is cancelled / the connection drops, and always stops IDLE before returning so the connection is free to FETCH. Removed the now-unusedUpdates()accessor and the oldIdle()that held IDLE open for the whole session (exposing it invited exactly this misuse).internal/desktop:idleSessionis now a single-goroutine loop:IdleUntil-> on update takesyncMu, resync INBOX, release, idle again. No concurrent FETCH on the idling connection;syncMuis held only for the brief resync, so manual/background syncs no longer stall behind it.cmd/imaptest: updated to the new loop API.Tests
TestStopIdle(close/wait error reaping) andTestDrainUpdatesininternal/imap.Closes #125
fix: stop reading pane jitter on fractional display scaling -
@TRC-Loop in #141
The reading pane iframe is sized to its content height via a ResizeObserver that writes each measured body height back onto the iframe. On fractional display scaling (125%/150%, common on Fedora's WebKitGTK) the applied height snaps to a device pixel differently from how getBoundingClientRect measures it back, so the body flips between two adjacent pixel heights forever. That continuous 1px oscillation is the visible shaking that makes mail unreadable.
Fix: add hysteresis in measure() so a new reading only takes effect when it differs from the applied height by more than a pixel. This settles the feedback loop while still tracking real content growth and shrink. No behavior change on integer scaling, where diffs were already 0.
Closes #123
Full Changelog: v1.0.9...v2026.3
This discussion was created from the release v2026.3.
All reactions