Releases: beastyrabbit/schaffa
Release list
Schaffa 0.13.0
Note
🤖 Claude Opus 5.5 responding on behalf of beastyrabbit
Schaffa 0.13.0 lets you delete a guide, page, or file straight from the terminal, as long as you hold the token that created it.
Until now, removing published content meant opening the /admin or /account web interface. Agents and scripts had no way to clean up after themselves. Pass the type and ID, or just the public URL:
npx schaffa delete guide <id>
npx schaffa delete https://schaffa.dev/p/<slug>
npx schaffa delete file <id>.webp --jsonThe same operation is available over HTTP as DELETE /api/guides/:slug, /api/pages/:slug, and /api/files/:id:
curl -X DELETE -H "Authorization: Bearer $SCHAFFA_TOKEN" "$SCHAFFA_URL/api/guides/<id>"Only the token that created the content, or an admin token, can delete it. Other tokens receive 403, and IDs that no longer exist return 404. Output from the built CLI against an isolated local server with synthetic tokens:
$ schaffa delete guide cqb6wbhreajt # another user's token
Error: Schaffa request failed with HTTP 403. This token does not own the guide.
$ schaffa delete http://localhost:3917/g/cqb6wbhreajt --json # owning token
{"deleted":true,"kind":"guide","id":"cqb6wbhreajt"}
$ schaffa delete guide cqb6wbhreajt # again
Error: Schaffa request failed with HTTP 404. Guide not found.
Deletion is permanent: pages lose every version and guides lose every revision and screenshot. The CLI refuses URLs from any origin other than SCHAFFA_URL and rejects version or revision URLs, so it never removes a whole page when you meant one version. Like admin takedowns, deletion keeps working during publishing lockdown. A guide's attached video is a separate file and remains until you delete it.
Reliability. Deleting a guide while one of its screenshots was still being virus-scanned used to fail that upload with HTTP 500. It now returns 404 and removes the stored image.
Upgrade notes. Update both the server and the CLI. Older servers do not have the delete endpoints. No migration, configuration change, or new dependency is required.
Also in this range: pull requests are now analysed by SonarQube in place of OpenGrep, and the README was tidied. (#9)
Type checks, lint, and the full server, release, and CLI test suites pass. The SonarQube quality gate reported no new issues. An independent Codex review found and verified the fix for the scan race; the final small CLI change could not be re-reviewed because the reviewer was rate-limited.
Schaffa 0.12.0
Note
🤖 Codex responding on behalf of beastyrabbit
Schaffa 0.12.0 lets agents check their credentials and publishing permissions before preparing a document.
Run npx schaffa doctor to find a token, verify that the server accepts it, and see which publishing operations it permits. The command reports the token source without displaying its value and publishes no content.
Use npx schaffa doctor --interactive --json for structured results and a failing exit code when interactive HTML is unavailable or cannot be verified. Interactive publishing still requires the correct token scope, account approval, and the instance setting. Permission denials explain what needs to change.
Read the CLI output. Evidence uses synthetic accounts and tokens against an isolated local server, whose address is omitted.
Update both the CLI and server to use this command. Older servers do not expose /api/capabilities; the CLI reports that permissions remain unverified. This checks permissions, not content validation, quotas, or scanner health. No new migration or dependency is introduced relative to 0.11.0.
The shared OpenGrep workflow now separates audit hints from security findings, reports interrupted or incomplete scans explicitly, and verifies cached engine downloads. Pagination and token-path test fixtures are deterministic across Linux and macOS.
Type checks, lint, full server/browser/CLI/release tests, builds, secret scans, and the production dependency audit pass. The supported standalone package installs cleanly and passes its own dependency audit and import smoke checks. Independent Codex correctness/security/release and scope reviews returned no findings. macOS-only tests were skipped on Linux.
Schaffa 0.11.0
Note
🤖 Codex responding on behalf of beastyrabbit
Schaffa 0.11.0 records video walkthroughs, finds saved publishing tokens, and moves all upload scanning to the shared ClamGate service. A Schaffa deployment now needs only its application container and persistent data volume.
Record and publish walkthroughs
Add --video to a guide recording to attach a scanned video player and download. Browser recordings preserve transitions and scrolling. Standalone recordings stay local unless --upload is requested:
npx schaffa@0.11.0 video record --browser https://app.example.com --output ./demo.webmVideo requires ffmpeg with libvpx-vp9 and Chrome or Chromium. Capture pause excludes private screens. Incomplete captures remain failed, and guide edits remove attached videos so stale recordings cannot silently describe a different guide. Video publishing waits up to one hour for scanning and reports existing upload URLs if the queue outlasts that wait. See the video documentation.
Desktop and mobile guide video views, captured from the reviewed release with synthetic content:
Reuse saved tokens
The CLI reads SCHAFFA_TOKEN, local environment files, and standard Schaffa token configuration files. Explicit --token takes precedence. Use --ignore-token to skip lookup and publish a temporary anonymous HTML page. Files, guides, presentations, and interactive pages still require authentication. Invalid token characters fail before request headers are built, without exposing credentials in the error.
Upgrade to shared scanning
This version removes the local ClamAV client and container. ClamGate is required, with no enable flag, provider selector, or local fallback.
- Provision a trusted Ed25519 public key and set
CLAMGATE_PUBLIC_KEY_FILEandCLAMGATE_PUBLIC_KEY_IDbefore starting the application. The default origin ishttps://virus.heerlab.com. - Inject an existing
CLAMGATE_APPLICATION_TOKENthrough the secret manager when application attribution is needed. - Remove the old ClamAV connection variables and dedicated scanner workload after migration. Back up the complete Schaffa data volume and keep the previous image and its matching configuration available for rollback.
- Schaffa verifies the signed result against the submitted bytes before publication. Scanner failures leave page/file uploads quarantined. Images are scanned before and after conversion.
- The shared service's default budget is ten submissions per minute per egress IP and one active scan. Each image needs two submissions. Allow for other consumers and actual scan time when recording many steps.
Read the deployment guide for timeout, proxy, retention, and migration details. Upgrades from 0.9.1 must also follow the 0.10.0 upgrade notes, including explicit TRUSTED_PROXIES and database backup. Server and development require Node 24 or newer; the CLI requires Node 22.12.0 or newer.
Security and verification
Updated sharp to 0.35.4 and bundled js-yaml to 4.3.2 to address the image-decoder and YAML merge denial-of-service advisories. Production dependency audit, secret scan, types, lint, build, and 155 tests pass locally, including real Chrome recording and video playback. The CLI tarball passes a clean install and entry-point check. Offline signed fixtures cover ClamGate acceptance, rejection, altered bytes, invalid signatures, deadlines, and shutdown.
Schaffa 0.10.0
Note
🤖 Codex responding on behalf of beastyrabbit
Schaffa 0.10.0 makes publishing and guide recording more reliable, carries local images into presentations, and makes large publication libraries easier to manage.
Publishing and recording
- Page updates keep allocating new version URLs after deletion or an interrupted migration.
- Mixed file and page queues drain without starving files. Image conversion respects storage limits, and cleanup failures preserve already-published images.
- Browser and desktop recording recover from a concurrent guide edit. Saved manifests can sync without an active recording session.
- Presentations embed local PNG, JPEG, GIF, and WebP assets, including slide backgrounds.
Guides and administration
Guides now have configurable step, revision, and metadata budgets. Metadata accounting is transactional, and draft edits that reduce usage remain available above lowered limits. Published history stays immutable; reaching a cap requires more capacity or an administrator's full takedown.
Public guides and screenshots support conditional requests and five-minute cache revalidation. Enlarged screenshots open in an accessible new tab. Administration filters publications in SQL and displays at most 50 per page; form errors provide a recovery link.
Desktop administration and a mobile guide, captured from synthetic local fixtures:
Upgrade
- Replace
TRUST_PROXY_HOPSwith explicitTRUSTED_PROXIESIP addresses or narrow CIDRs for the proxy peers the application actually sees. The default trusts no forwarding headers. - Server and development require Node 24 or newer. The standalone CLI requires Node 22.12.0 or newer.
- Back up the complete data volume before startup applies the SQLite migrations. Version numbers deleted before the migration cannot be reconstructed.
- Containers now publish to
ghcr.io/beastyrabbit/schaffa. Pin the immutable reference in the attachedcontainer-digest.txt. - Existing downloaded content cannot be recalled. Sensitive material in published guide history requires full guide takedown. The interactive sandbox does not provide complete network isolation.
The CLI release bundles its locked runtime dependencies and is audited after a clean install. Container release tags are promoted only after the candidate digest passes the vulnerability gate.
Verification
104 tests pass, including real-browser presentation, recording, keyboard, and mobile flows. Type, lint, build, secret, and dependency checks pass. Live identity-provider login and actual desktop input capture were not exercised. See PR #1 for the full resolution mapping and review evidence.
Schaffa v0.9.1
Schaffa v0.9.1
v0.9.1 completes the guide-recorder release that began in v0.9.0 and supersedes that incomplete release.
Guide recording
npx schaffa record --chrome <url>opens a new window in the Chrome session that is already running. It does not create a separate Chrome profile, so existing logins, extensions, and password-manager access remain available.- The recorder binds to that exact macOS window and ignores clicks in other Chrome windows. Drag motions do not create guide steps.
- Each click screenshot uses a compact cursor and a thin red outline around the target, keeping the underlying control readable.
- Recorder locking, idempotency, and shutdown handling reduce unrelated or duplicated steps when recordings overlap or stop early.
Chrome must already be open in the intended signed-in profile. Recording on macOS requires Accessibility and Screen Recording permission.
Security recovery
The v0.9.0 Forgejo release stopped at its container scan before Forgejo package and release assets were created. Its image contained libcrypto3 and libssl3 3.5.7-r0, which are affected by CVE-2026-14456. The v0.9.1 runtime requires 3.5.8-r0 or newer. The native Linux AMD64 image passed the HIGH/CRITICAL Trivy gate.
The v0.9.0 tag, npm package, and image remain preserved for provenance. Do not deploy the v0.9.0 container; use v0.9.1 and pin the digest below.
Artifacts
- npm:
schaffa@0.9.1(latest) - Forgejo CLI tarball:
schaffa-0.9.1.tgz - Checksum:
schaffa-0.9.1.tgz.sha256 - Container:
git.heerlab.com/beasty/schaffa:0.9.1 - Immutable digest:
sha256:ecc73744889e43af79772bef913cf9a52d2bfa5eea6d4c35018d587c36ec99a3 - Release pipeline: Forgejo run 78 (historical; not migrated)
Review evidence
- Recorder implementation: historical Forgejo PR 7
- Security recovery: historical Forgejo PR 9
- Annotated screenshot: desktop and compact
No migration or configuration change is required.
Schaffa v0.9.0 — incomplete; use v0.9.1
Schaffa v0.9.0 — incomplete; use v0.9.1
This release is incomplete and has been superseded by v0.9.1.
The v0.9.0 tag and npm package were published, and its container image was built. The Forgejo pipeline then found CVE-2026-14456 in the image runtime: libcrypto3 and libssl3 were 3.5.7-r0. The job stopped before the Forgejo CLI package and release assets were created. No assets are attached here intentionally.
The tag, npm package, and image remain preserved for provenance. Do not deploy the v0.9.0 container. Use v0.9.1 and its verified immutable digest instead. npm CLI users should also update to 0.9.1 to stay aligned with the completed release.
- Failed v0.9.0 release pipeline: Forgejo run 75 (historical; not migrated)
- Completed recovery: Schaffa v0.9.1
The Chrome recorder source introduced in v0.9.0 is unchanged in v0.9.1: it uses a new window in the existing signed-in Chrome session, records only that window, and renders a compact cursor with a red target outline.
Schaffa v0.8.3
Schaffa v0.8.3
Tagged release with a Forgejo CLI package and immutable container image. npmjs.org publishing runs from the GitHub mirror.
- CLI package:
schaffa@0.8.3 - Container:
git.heerlab.com/beasty/schaffa:0.8.3 - Digest:
sha256:32418236383e96299b60cb1af182e27f043d603182e1a11c5859d4b4a6c0bc53
Schaffa v0.8.2
Schaffa v0.8.2
Official HTML and file skills now work without a user-supplied SCHAFFA_URL setting. The Schaffa server writes its trusted public origin directly into each upload command, so the catalog on schaffa.dev points to https://schaffa.dev and self-hosted catalogs point back to their own instance.
This removes unnecessary setup from installed skills while keeping bearer tokens on the correct origin. CLI, local-development, and self-hosting origin overrides remain available where they belong.
The release adds regression coverage that rejects SCHAFFA_URL in both official skills and verifies the rendered configured origin.
No configuration change or database migration is required.
- Evidence: https://schaffa.dev/p/dg2fd449v3zmg0ao
- Application PR: historical Forgejo PR 5 (not migrated as a pull request)
- CLI package:
schaffa@0.8.2 - Container:
git.heerlab.com/beasty/schaffa:0.8.2 - Digest:
sha256:ef29f7bf8a8d8dcd7f2a29ff663c6a2f5eaeb902843fa9cf54b9fa3da35487b8
Schaffa v0.8.1
Schaffa v0.8.1
Tagged release with a Forgejo CLI package and immutable container image. npmjs.org publishing runs from the GitHub mirror.
- CLI package:
schaffa@0.8.1 - Container:
git.heerlab.com/beasty/schaffa:0.8.1 - Digest:
sha256:2b06f7b56c7b1a871e22184fed93ae5061ce02b3849d96b818f38037b69b3cae
Schaffa v0.8.0
Schaffa v0.8.0
What’s New
Token-Einrichtung
- Neu erzeugte Tokens lassen sich direkt für macOS, Linux oder Windows einrichten.
- Unterstützt Zsh, Bash, Fish, PowerShell, CMD,
.envund temporäre Sitzungen. - Token und Terminal-Befehl können separat kopiert werden.
- Das Betriebssystem wird automatisch erkannt; die mobile Darstellung ist optimiert.
- Zusätzliche Sicherheitshinweise erklären Shell-Verlauf und
.envin Git.
Artefakte
- CLI-Paket:
schaffa@0.8.0 - Container:
git.heerlab.com/beasty/schaffa:0.8.0 - Digest:
sha256:ac222629df701e3e202ca43d04949b97d42cf48967b182f53c763a36db719f86 - npmjs.org-Publishing läuft über den GitHub-Mirror.




