Releases: zukotuutori/burrow-client
Release list
V1.1.0
Added
Update check. A new Updates section under Settings has a Check for updates button, plus an optional check on every start. The startup check is off by default.
In-app updates for the AppImage. The AppImage can now download, verify and install new versions itself using electron-updater. Each download is checked against the SHA-512 hash in latest-linux.yml.
Download links for macOS and rpm. On these builds the update check opens the matching download in your browser.
Update hint on the home screen. When the startup check finds a new version, an "Update to x.y.z" link appears in the sidebar.
Version number shown in the sidebar.
Custom DMG window on macOS, with a background image and a drag-to-Applications layout.
Changed
The documentation link now points to zukotuutori.dev/burrowclient/documentation.
The repository was renamed from ssh-client to burrow-client. The update check, download links, package.json and the docs were updated to match.
build:mac and build:linux now run with --publish never, so a build never uploads anything to GitHub by accident.
The README's Linux install section now only covers the AppImage. The rpm instructions were removed.
The README and SECURITY.md gained sections on updating, publishing releases and the security of the update process.
Security
Sync server: The server now only believes X-Real-IP when the connection comes from a loopback or private address. A client that reaches the server directly can no longer fake an IP to dodge the login lockout.
Sync server: The list of IPs with failed logins is capped at 10,000 entries, so it can't grow without limit.
V1.0.0
Burrow Client 1.0.0
This is the first release of Burrow Client, a local-first SSH client for macOS and Linux. It has no account, no telemetry and no cloud unless you host one yourself. Your hosts, keys and passwords stay on your machine. Secrets are kept in an encrypted vault that only opens with your master password.
Terminal
- Tabs with split panes, side by side or stacked
- Local shell tabs next to your SSH sessions
- Snippets: save a command once and send it to any terminal, either globally or per host
- Keyboard shortcuts for splitting, closing panes and copy/paste. On Linux, plain Ctrl combos still go to the shell, so Ctrl+C still interrupts a command.
Hosts
- Host profiles with groups, search and notes
- An optional status dot that shows whether a host is reachable
- Password or key login. The password can be saved or asked for on every connect.
Keys and trust
- Generate Ed25519 or RSA 4096 keys, or import existing ones (passphrases work)
- Known hosts: on the first connection you see the server's fingerprint and confirm it. If a host's key changes, the connection is blocked until you decide what to do.
- Legacy SHA-1 algorithms are turned off
Files
- SFTP browser with drag and drop upload, plus download, rename, delete and new folder
Privacy and security
- Passwords, private keys and passphrases are encrypted with your master password (scrypt + AES-256-GCM)
- The vault auto-locks after idle time, on sleep and when the screen locks
- On macOS the window is hidden from screenshots and screen recordings by default. You can turn this off in Settings.
- Vault files with oversized scrypt parameters are rejected, so a tampered file can't make the app use huge amounts of memory
- If a data file is damaged, you get a notice at startup and can reset it. The broken file is kept as a backup.
Sync (optional)
- End-to-end encrypted sync between devices through a server you run yourself
- The server is a single Node.js file with no dependencies. Docker and reverse proxy examples are included.
- The server only sees user names and upload times. It never sees your hosts, passwords or keys.
Other
- The app version is shown in the sidebar
- There's a link to the documentation inside the app
- Licensed under MIT, with a security policy in SECURITY.md
Install notes
- macOS: the build isn't signed. On first launch, go to System Settings → Privacy & Security and click "Open Anyway".
- Linux: there's an
.rpmfor Fedora and other RPM-based distros, and an AppImage for everything else.