Skip to content
This repository was archived by the owner on Apr 8, 2026. It is now read-only.

Releases: thejuran/seedsync

Release v4.0.3

Choose a tag to compare

@github-actions github-actions released this 08 Apr 16:25

Full Changelog: v4.0.2...v4.0.3

Release v4.0.2

Choose a tag to compare

@github-actions github-actions released this 07 Apr 00:08

What's Changed

  • fix: resolve CI lint failures and vite security vulnerability by @thejuran in #165

Full Changelog: v4.0.1...v4.0.2

v4.0.1

Choose a tag to compare

@thejuran thejuran released this 05 Apr 20:23

Security

  • lodash bumped to 4.18.x — fixes code injection via _.template (high) and prototype pollution via _.unset/_.omit (medium)
  • Pygments bumped to 2.20.0 — fixes ReDoS via inefficient GUID regex matching (low)

Dependencies

  • 22 npm packages updated (Dependabot PR #162), including TypeScript 5.9 → 6.0
  • Full TypeScript 6.0 strict mode migration: 583 type errors fixed across 58 files

Bug Fixes

  • Fixed empty-string file name selection edge case in FileComponent

v4.0.0 — UI Redesign & Full Codebase Review

Choose a tag to compare

@thejuran thejuran released this 29 Mar 12:39

What's New

UI Redesign

  • Deep Moss + Amber palette with Triggarr-style layout
  • Settings page: Flat card sections, two-column layout, labels above inputs
  • Dashboard: Unified multi-select bar with bulk actions (Queue, Stop, Extract, Delete Local, Delete Remote)
  • AutoQueue merged into Settings page with inline pattern CRUD
  • Toast notifications: Triggarr-style with type icons (✓✕⚠ℹ) and slide-in animation
  • Navigation: Streamlined to 4 items (Dashboard, Settings, Logs, About)

Security

  • LFTP escape() rejects newline/CR/null characters (command injection fix)
  • Shell commands use shlex.quote() for path interpolation
  • Credentials redacted from debug log output

Bug Fixes

  • Model read in command processing now protected by lock
  • Auto-delete timer dict has dedicated threading lock
  • SSE subscription properly torn down on reconnect
  • View file indices updated correctly on file-add
  • pexpect TIMEOUT decode crash handled safely
  • Inner Observable subscriptions connected to teardown

Code Quality

  • 55 issues from full-codebase deep review addressed
  • Narrowed exception handlers, correct log levels, concrete types
  • BFS traversals use collections.deque for O(1) popleft
  • Version synced across package.json and debian/changelog

Technical

  • Angular 21, Bootstrap 5.3, system font stack
  • 401 Angular unit tests, 1134 Python unit tests passing

v3.2.0 — Security Hardening & Angular 21

Choose a tag to compare

@thejuran thejuran released this 26 Mar 00:19

🔒 Security Hardening

  • Path traversal guards — realpath-based validation prevents directory traversal attacks
  • Config file permission hardening — config files locked to 0600 on write
  • SSH topology redaction — sensitive SSH connection details stripped from API responses
  • API token config field — new api_token field with automatic redaction in config API
  • Webhook payload size cap — prevents oversized webhook payloads
  • Startup security warnings — alerts on insecure configuration at launch
  • Restart endpoint CSRF fix — restart endpoint changed from GET to POST
  • Secure temp files — replaced insecure tempfile.mktemp with NamedTemporaryFile
  • Resolved 13 dependency security alerts (Dependabot)
  • Resolved undici CVE via npm override

⬆️ Angular 21 Migration

  • Upgraded Angular 19 → 21 with full dependency refresh
  • Migrated to application builder (esbuild)
  • Added change detection waits for esbuild builder in E2E tests

🐛 Fixes

  • First-run SSH timeouts are now recoverable instead of fatal
  • Fixed race condition in extract integration tests

🔧 CI/CD

  • Dependabot config tuned to ignore minor+ bumps for webpack, TypeScript, and zone.js
  • Migrated to application builder to fix Karma test hang in Docker

Full Changelog: v3.1.2...v3.2.0

Release v3.1.2

Choose a tag to compare

@github-actions github-actions released this 24 Feb 18:46

Full Changelog: v3.1.1...v3.1.2

v3.1.1

Choose a tag to compare

@thejuran thejuran released this 24 Feb 12:43

Bug Fix

  • fix(e2e): add explicit z-index to confirmation modal to prevent sidebar overlap — The bulk Delete Remote E2E test was timing out because the sidebar (z-index: 300) intercepted pointer events on the confirmation modal's Cancel button. Added explicit inline z-index (1050 backdrop, 1055 modal) to guarantee the modal renders above all app content.

v3.0 Terminal UI Overhaul

Choose a tag to compare

@thejuran thejuran released this 17 Feb 21:22

Terminal UI Overhaul

Complete visual redesign from generic Bootstrap/Verdana to a distinctive Terminal/Hacker aesthetic. Dark-only, 21 requirements satisfied.

Key Changes

  • Fonts: Fira Code for data displays, IBM Plex Sans for UI labels (Google Fonts CDN)
  • Colors: Deep dark backgrounds (#0d1117 base) with matrix-green accent palette (#00ff41, #3fb950, #238636)
  • Sidebar: Collapsible 56px icon-rail expanding to 200px on hover, > prompt on active route, version footer
  • Dashboard: ASCII progress bars, colored status borders, green glow on downloading, ghost-style action buttons
  • Pages: Terminal-style Settings headers, colored log levels, ASCII art About page
  • CRT Overlay: Subtle scan-line effect across entire UI
  • Theme Cleanup: Removed light/auto modes entirely — deleted ThemeService, dark-only by design

Stats

  • 6 phases, 12 plans, 21 requirements
  • 32 files changed (+530, -1,235 lines)
  • Net -705 LOC (cleaner codebase)

Docker

```bash
docker pull ghcr.io/thejuran/seedsync:latest

or pin to version:

docker pull ghcr.io/thejuran/seedsync:3.0
```

v2.0.1

Choose a tag to compare

@thejuran thejuran released this 14 Feb 22:12

Bug Fix

  • Fix webhook import matching for child files: When Sonarr/Radarr reported a child file (e.g., an episode inside a show directory), the webhook import silently failed because matching only checked root-level model names. Now builds a comprehensive name lookup via BFS traversal of all children.
  • Upgrade no-match webhook log from DEBUG to WARNING: Previously, failed webhook matches were invisible at the default INFO log level. Now logs a WARNING with context showing how many names were checked.

v2.0.0 Dark Mode & Polish

Choose a tag to compare

@thejuran thejuran released this 12 Feb 20:11

What's New

Dark/Light Theme System

  • Full dark mode with OS prefers-color-scheme auto-detection
  • Manual Light/Dark/Auto toggle in Settings → Appearance
  • FOUC prevention — theme applied before first paint
  • Multi-tab sync via localStorage events

Theme-Aware UI

  • All SCSS hardcoded colors migrated to CSS custom properties
  • Sidebar, action bars, file selections, and dropdowns all respect dark mode
  • Selected row text readable in both themes

Sonarr/Radarr Polish

  • Toast text references both Sonarr and Radarr
  • Auto-delete description references both services
  • Import toasts no longer replay stale events on restart
  • WAITING_FOR_IMPORT enum value for file status pipeline

Bug Fixes

  • Dark mode now applied to sidebar, file options bar, file actions bar, and selection states
  • Stale "Sonarr/Radarr Imported" toast notifications no longer replay on app restart
  • Integration tests updated for webhook_manager constructor arg (CI green)

Stats

  • 4 phases, 5 plans executed
  • 420 Angular unit tests passing
  • 1000 Python tests passing, 84% coverage