Neo Angband 0.31.0
Pre-releaseWhat you can download
| Platform | File |
|---|---|
| Windows (installer) | Neo Angband Setup 0.31.0.exe |
| Windows (portable, one file) | Neo Angband-0.31.0-portable.exe |
| macOS | .dmg, or the .zip if you prefer to unpack it yourself |
| Linux | .AppImage (no install), .deb, or .tar.gz |
| Self-hosting | neo-angband-web-0.31.0.zip - static files, any web server |
The portable Windows build and the AppImage need no installer:
download, run, and the game keeps its saves in a folder beside itself.
These builds are not code-signed
There is no Apple Developer identity or Windows certificate behind this
project yet, so your OS blocks the first launch.
Windows is one click: SmartScreen says "Windows protected your PC",
choose More info then Run anyway.
macOS is not one click, and the dialog it shows you does not contain the
way through - it offers only Done and Move to Trash. Do this:
- Drag the app out of the
.dmg, then double-click it and press Done
on the refusal. This step is required: it is what makes the permission
below appear, and it expires about an hour later. - Open System Settings -> Privacy & Security and scroll to
Security, near the bottom. - Press Open Anyway on the line naming Neo Angband, authenticate, and
launch it again.
Or, the same decision in one command:
xattr -d com.apple.quarantine "/Applications/Neo Angband.app"
The old right-click -> Open trick does NOT work: Apple removed that
bypass in macOS 15 Sequoia.
On Apple Silicon take the arm64 build. The x64 one is for Intel Macs,
not a fallback - Apple is withdrawing Rosetta 2, so on a current Mac it is
likelier to refuse to launch than to run slowly.
If that trade is not one you want to make, build it yourself -
docs/INSTALL.md - or play in the browser, which needs no trust decision.
Your save
Saves survive an update. Every save-format change ships the conversion that
reads the version before it, and a save this build cannot open is left
untouched rather than replaced.
Security
- The desktop updater no longer accepts a download URL or checksum from the
renderer. The main process re-reads the named release from GitHub and
resolves the platform asset's URL, digest, and size itself; redirects are
followed manually with a host check on every hop, and extraction now
enforces archive size, entry count, and expansion-ratio limits. - A content patch path such as
__proto__.xno longer reaches
Object.prototype. Every path-walking entry point in the patch and compose
modules now rejects__proto__,prototype, andconstructorand reads
only a container's own properties. - Repository mod downloads and imported
.neocharsaves now decompress
within the same resource limits the local mod importer already enforced,
instead of expanding an untrusted archive or save with no ceiling. - The game window no longer navigates away from its own origin on a
same-window navigation. The check that decides what counts as the game's
own address now parses the URL instead of matching a string prefix. - Three dependencies pinned to versions with published advisories
(fast-uri,js-yaml,nanoid) are updated.
Found something that does not match Angband 4.2.6? Open an issue or come and say so in the Discord.