Skip to content

Huginn v1.2.0

Choose a tag to compare

@github-actions github-actions released this 09 Jun 07:59

First time installing?

Huginn is an open-source personal project and isn't code-signed. Windows SmartScreen and macOS Gatekeeper will both show a warning on first install — that's expected. Code-signing certificates cost real money and aren't worth it for a free personal tool. The source is public on this repo; you can read it.

Windows

  1. Download Huginn-win-Setup.exe below.
  2. Run it. SmartScreen will warn that the app is from an unknown publisher.
  3. Click More info, then Run anyway.

macOS

  1. Download the .pkg for your Mac: Huginn-osx-arm64-Setup.pkg (Apple Silicon — M1/M2/M3/M4) or Huginn-osx-x64-Setup.pkg (Intel). Not sure? Apple menu → About This Mac → the Chip/Processor line.
  2. Open it. macOS will block it because it isn't signed — that's expected. In the warning, click Done (or Cancel) — not "Move to Trash", which deletes the installer you just downloaded.
  3. Open System Settings → Privacy & Security, scroll to the Security section, and click Open Anyway next to the note about Huginn being blocked. Authenticate, confirm Open, then follow the installer.

Once installed, future updates download and apply themselves the next time you launch the app — you don't need to repeat any of this.


What's new

  • Bumped System.Drawing.Common from the transitive 4.7.0 to 9.0.0, clearing the GHSA-rxg9-xrhp-64gj critical-severity advisory that the release builds were flagging.
  • Rooted the Windows toast-notification dependency chain (Microsoft.Toolkit.Uwp.Notifications, Microsoft.Windows.SDK.NET, WinRT.Runtime) so the trimmer no longer strips reflection-only members on best-guess heuristics. The current call sites worked in practice, but any new toast template or WinRT activation path is now safe by construction rather than by luck.
  • Cleaned up the trim warnings the release builds had been logging: removed an unused Avalonia-template stub (DisableAvaloniaDataAnnotationValidation) Huginn never needed; the runtime platform dispatcher's [DynamicDependency] hints are now guarded so each TFM only references types that actually exist in it; the remaining safe-but-unprovable Type.GetType(string) calls in the dispatcher and the view locator carry explicit [UnconditionalSuppressMessage] justifications. The three IL2104 warnings from the rooted Windows toast/WinRT assemblies stay visible on purpose so a new noisy dependency wouldn't be silently swallowed.