Skip to content

v1.0.0-beta.2 — Security update

Pre-release
Pre-release

Choose a tag to compare

@bcsnpc bcsnpc released this 28 Aug 01:35

Security update

This beta hardens vilsem across the board — no feature changes, just security.

  • Power BI bearer token stays in the main process; it never reaches the renderer.
  • HTML sinks sanitized with DOMPurify (narrative + rich text) — desktop app and exported/embedded web apps.
  • Content Security Policy on the desktop renderer (strict script-src self, no unsafe-inline) and on exported web apps.
  • Production dependency advisories fixed (fastify, find-my-way, follow-redirects, form-data, fast-xml-parser).
  • Chromium sandbox re-enabled.

See SECURITY.md for the full policy and details.

Windows only, unsigned — SmartScreen will warn on first launch (More info -> Run anyway).

SHA-256: b98bcb71766a0511901f4a0e72d885687b89e70dfb7a825b15e471ea5cc332ad