v1.0.0-beta.2 — Security update
Pre-release
Pre-release
Security update
This beta hardens vilsem across the board — no feature changes, just security.
- Power BI bearer token stays in the main process; it never reaches the renderer.
- HTML sinks sanitized with DOMPurify (narrative + rich text) — desktop app and exported/embedded web apps.
- Content Security Policy on the desktop renderer (strict script-src self, no unsafe-inline) and on exported web apps.
- Production dependency advisories fixed (fastify, find-my-way, follow-redirects, form-data, fast-xml-parser).
- Chromium sandbox re-enabled.
See SECURITY.md for the full policy and details.
Windows only, unsigned — SmartScreen will warn on first launch (More info -> Run anyway).
SHA-256: b98bcb71766a0511901f4a0e72d885687b89e70dfb7a825b15e471ea5cc332ad