Repository navigation
v1.4.0-dev04
Pre-release
Pre-release
Fourth dev pre-release of the 1.4.0 minor
Spanish, a Support page in Settings, uploads that say what went wrong, and security updates.
Added
- Spanish. NutriTrace can be used in Spanish: pick it in Settings → Regional & Units. Translated almost in full by @herver1971 on Weblate; only the new Support page is still in English. Thank you!
- Settings has a Support page, next to About: Ko-fi and GitHub Sponsors, plus free ways to help (star the repo, report a bug, translate). It replaces the support row that used to sit in About.
- About links to the TraceApps family.
Changed
- The in-app updater reuses an update it already downloaded. Coming back to Updates goes straight to installing instead of downloading the whole APK again, and the button says Install. Older downloads are cleared so they stop piling up on the phone.
Fixed
- A file of the wrong type, or over the size limit, is turned away with a clear message. Uploading one answered with a server error instead of saying what was wrong. A file that is too large now says what the limit is.
- Settings pages line up with the section list on desktop and foldables. Every page started 12px below the list beside it.
- The Settings section list keeps its place on desktop and foldables. Opening a section from the Settings page scrolled the list beside it back to Profile.
Security
- undici bumped 6.28.0 to 6.29.0, closes GHSA-3wwx-pv8p-q78v (moderate: a WebSocket server could crash the process). NutriTrace opens no WebSocket connections.
- ip-address bumped 10.4.0 to 10.7.2, closes GHSA-2vr4-cq9g-pvrc (moderate: one IPv6 range was not recognized as local). It only comes in through the MCP server's rate limiter; NutriTrace's own SSRF guard does not use it.
- nodemailer bumped 9.1.1 to 10.0.12 on the server, closes GHSA-6vj9-mwq6-2f5v (moderate: separate mail transports could share one TLS server name). Removed from the web app's own dependencies, where nothing used it.
npm auditreports 0 vulnerabilities for the app and the server.
NutriTrace is free and always will be. Support on Ko-fi goes toward a Mac and an iPhone so my apps can come to Apple devices, and GitHub Sponsors helps with the monthly costs.