Skip to content

Neo Angband 0.31.0

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 24 Aug 04:50
· 1382 commits to master since this release

What you can download

Platform File
Windows (installer) Neo Angband Setup 0.31.0.exe
Windows (portable, one file) Neo Angband-0.31.0-portable.exe
macOS .dmg, or the .zip if you prefer to unpack it yourself
Linux .AppImage (no install), .deb, or .tar.gz
Self-hosting neo-angband-web-0.31.0.zip - static files, any web server

The portable Windows build and the AppImage need no installer:
download, run, and the game keeps its saves in a folder beside itself.

These builds are not code-signed

There is no Apple Developer identity or Windows certificate behind this
project yet, so your OS blocks the first launch.

Windows is one click: SmartScreen says "Windows protected your PC",
choose More info then Run anyway.

macOS is not one click, and the dialog it shows you does not contain the
way through
- it offers only Done and Move to Trash. Do this:

  1. Drag the app out of the .dmg, then double-click it and press Done
    on the refusal. This step is required: it is what makes the permission
    below appear, and it expires about an hour later.
  2. Open System Settings -> Privacy & Security and scroll to
    Security, near the bottom.
  3. Press Open Anyway on the line naming Neo Angband, authenticate, and
    launch it again.

Or, the same decision in one command:
xattr -d com.apple.quarantine "/Applications/Neo Angband.app"

The old right-click -> Open trick does NOT work: Apple removed that
bypass in macOS 15 Sequoia.

On Apple Silicon take the arm64 build. The x64 one is for Intel Macs,
not a fallback - Apple is withdrawing Rosetta 2, so on a current Mac it is
likelier to refuse to launch than to run slowly.

If that trade is not one you want to make, build it yourself -
docs/INSTALL.md - or play in the browser, which needs no trust decision.

Your save

Saves survive an update. Every save-format change ships the conversion that
reads the version before it, and a save this build cannot open is left
untouched rather than replaced.


Security

  • The desktop updater no longer accepts a download URL or checksum from the
    renderer. The main process re-reads the named release from GitHub and
    resolves the platform asset's URL, digest, and size itself; redirects are
    followed manually with a host check on every hop, and extraction now
    enforces archive size, entry count, and expansion-ratio limits.
  • A content patch path such as __proto__.x no longer reaches
    Object.prototype. Every path-walking entry point in the patch and compose
    modules now rejects __proto__, prototype, and constructor and reads
    only a container's own properties.
  • Repository mod downloads and imported .neochar saves now decompress
    within the same resource limits the local mod importer already enforced,
    instead of expanding an untrusted archive or save with no ceiling.
  • The game window no longer navigates away from its own origin on a
    same-window navigation. The check that decides what counts as the game's
    own address now parses the URL instead of matching a string prefix.
  • Three dependencies pinned to versions with published advisories
    (fast-uri, js-yaml, nanoid) are updated.

Found something that does not match Angband 4.2.6? Open an issue or come and say so in the Discord.