Skip to content

v1.2.1

Choose a tag to compare

@github-actions github-actions released this 07 Jul 08:40
· 2 commits to main since this release

v1.2.1

Security

Defensive hardening of the Electron main process and the IPC boundary β€” no behaviour change for normal use, thanks to a great first community contribution by @fabriziosalmi πŸ™

  • Renderer sandbox enabled; webview disabled; top-frame navigation to external origins blocked (safe web links open in your browser instead).
  • External URLs passed to the OS are limited to http/https/mailto β€” no file:/custom schemes.
  • Git transport safety: reject the ext::/fd:: remote-helper URLs (which can run arbitrary commands) and pin protocol.ext.allow=never as defence-in-depth; validate refs/branches/tags/hashes so a crafted value can't flip a git subcommand.
  • SSH key names can't escape ~/.ssh (no path traversal).
  • Update downloads pinned to GitHub's release-asset hosts.
  • Tightened Content-Security-Policy.

Internal

  • The updater's release repository is now derived from package.json's repository field, so forks/rebrands only change it in one place.

macOS builds are ad-hoc signed (open with right-click β†’ Open); pick the arm64 or Intel installer for your Mac. Windows .exe and Linux .AppImage/.deb are also attached.