Compare commits

...
Author SHA1 Message Date
StandardNotes CI 2df2419341 chore(release): publish
- @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].6
2026-09-16 21:26:06 +00:00
Antonella Sgarlatta 141b2e3b1e chore: pipeline issues (#3051)
* chore: bump android sdk

* chore: fix ios upload

* chore: upgrade electron builder dep

* chore: bump version
2026-09-16 18:19:16 -03:00
Antonella Sgarlatta 1265178100 chore: translation fixes [skip ci] (#3050)
* chore: fix strings with same msgid

* chore: make strings file format consistent

* chore: fix variable names to prevent creating new crowdin entries

* chore: fix lint errors
2026-09-16 17:10:07 -03:00
StandardNotes CI 452f46303e chore(release): publish
- @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].8
 - @standardnotes/[email protected].4
 - @standardnotes/[email protected].3
 - @standardnotes/[email protected].5
2026-09-15 17:02:22 +00:00
Antonella Sgarlatta d73ec8378d fix: Fixes scroll position shift on Super checkbox toggle (#3049) 2026-09-15 13:53:15 -03:00
Antonella Sgarlatta cd90a59559 fix: Fixes potential tag path transversal in plaintext backups (#3048) 2026-09-15 13:53:02 -03:00
Antonella Sgarlatta 24da23096f fix: Fixes blank screen when tagging untagged current note on mobile (#3047) 2026-09-15 13:52:40 -03:00
Antonella Sgarlatta 13e0a9dc24 fix: Fixes command palette shortcut for AZERTY layout (#3046)
* fix: Fixes command palette keyboard shortcut for non-QERTY layouts

* fix: Fixes command palette keyboard shortcut for AZERTY
2026-09-15 13:52:26 -03:00
Antonella Sgarlatta e4e0f6fd08 fix: Ensures minimum encryption version when decrypting payload (#3045)
* fix: Ensures items key version as minimum when decrypting payload

* chore: add more tests
2026-09-15 13:52:01 -03:00
b8ccb0f85c ci: pin third-party actions to full commit SHAs (#3026)
* ci: pin third-party actions to full commit SHAs

Pin third-party actions on mutable @master/@main tags in credentialed jobs:
- chetan/invalidate-cloudfront-action (web.release.prod.yml) — handed production AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY
- convictional/trigger-workflow-and-wait (snjs.pr.yml, e2e jobs) — handed CI_PAT_TOKEN
- johnnyhuy/actions-discord-git-webhook (web.release.prod.yml) — handed DISCORD_WEBHOOK_URL

A moved tag would run unreviewed code with those credentials. Behaviour
unchanged; per GitHub's pin-to-SHA guidance.

Signed-off-by: Kobi Hikri <[email protected]>

* Apply suggestion from @antsgar

---------

Signed-off-by: Kobi Hikri <[email protected]>
Co-authored-by: Antonella Sgarlatta <[email protected]>
Co-authored-by: Antonella Sgarlatta <[email protected]>
2026-09-15 13:44:08 -03:00
StandardNotes CI 6fcb991e62 chore(release): publish
- @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].4
2026-09-07 15:05:45 +00:00
Antonella Sgarlatta 41f95985d8 chore: listed banners 2026-09-07 11:59:25 -03:00
StandardNotes CI 9601d2df99 chore(release): publish
- @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].3
 - @standardnotes/[email protected].3
2026-09-04 03:24:15 +00:00
Antonella Sgarlatta cb697984f4 chore: trigger release 2026-09-04 00:18:30 -03:00
Antonella Sgarlatta 17dd950d08 chore: fix mobile and desktop ts build errors [skip ci] 2026-09-04 00:06:13 -03:00
StandardNotes CI 85afc03aff chore(release): publish
- @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].6
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].1
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].2
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].7
 - @standardnotes/[email protected].9
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].2
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].2
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].2
2026-09-03 15:32:15 +00:00
Antonella Sgarlatta 307d2e961e chore: fix dependencies 2026-09-03 12:24:38 -03:00
Antonella Sgarlatta b5b9e9b8de chore: upgrade ios min os version (#3043) 2026-09-03 10:52:25 -03:00
Antonella Sgarlatta 9091d42fcc chore: adds last viewed note copy for mobile (#3044) 2026-09-03 10:52:10 -03:00
Antonella Sgarlatta 2c09161551 chore: lexical upgrade (#3042)
* chore: lexical upgrade

* chore: fix typescript versions

* chore: fix types

* chore: fix types

* chore: fix types

* chore: fix types

* chore: upgrade lint plugins and fix errors

* chore: fix build error

* chore: fix lint errors

* chore: fix lint errors

* chore: fix tests
2026-09-03 10:51:49 -03:00
StandardNotes CI e1ebcba3c3 chore(release): publish
- @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].5
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].1
 - @standardnotes/[email protected]
 - @standardnotes/[email protected]
 - @standardnotes/[email protected].6
 - @standardnotes/[email protected].1
 - @standardnotes/[email protected].1
 - @standardnotes/[email protected].1
2026-08-25 23:07:42 +00:00
Antonella Sgarlatta 84bfa33f63 chore: Allows webview debugging for dev mode only (#3035) 2026-08-25 19:46:54 -03:00
Antonella Sgarlatta cf5ca47185 fix: Sanitizes filename on iOS file share (#3036)
* fix: Sanitizes filename on iOS file share

* fix: move util to mobile package

* chore: fix yarn.lock
2026-08-25 19:46:34 -03:00
Antonella Sgarlatta 369b1f001f fix: Fixes web clipper hardware key auth for Firefox (#3040)
* fix: Fixes web clipper hardware key auth for Firefox

* chore: fix ts errors
2026-08-25 19:46:19 -03:00
Antonella Sgarlatta 6a0a404114 fix: Fixes upgrade prompt string (#3041) 2026-08-25 19:45:52 -03:00
Jayeesha 025ca517f6 fix: preferences sidebar unclickable when opened in focus mode (#3034) 2026-08-25 19:45:38 -03:00
Antonella Sgarlatta b615ddd317 chore: fix publish command in workflow [skip ci] 2026-08-18 12:46:05 -03:00
Antonella Sgarlatta 5089a93011 chore: add option to publish specific package [skip ci] 2026-08-18 12:25:41 -03:00
Antonella Sgarlatta 290d6da457 chore: add skip packages option [skip ci] 2026-08-18 10:54:25 -03:00
Antonella Sgarlatta 83c7b9e9b3 chore: add repository url to features package.json [skip ci] 2026-08-18 10:31:13 -03:00
Antonella Sgarlatta a6f6918b69 chore: fix manual publish workflow [skip ci] 2026-08-18 10:21:35 -03:00
Antonella Sgarlatta dc2fcd29cd chore: add manual publish workflow [skip ci] 2026-08-18 10:08:05 -03:00
Antonella Sgarlatta c14c4b1a93 chore: fix snapcraft job [skip ci] 2026-08-17 19:10:12 -03:00
385 changed files with 2955 additions and 1533 deletions
+4 -2
View File
@@ -330,7 +330,9 @@ jobs:
- name: Install Snapcraft
run: |
sudo snap install snapcraft --classic
# Pin to 8.x: electron-builder's legacy core22 snap target calls `snapcraft snap`,
# which was removed in snapcraft 9.0 (renamed to `pack`).
sudo snap install snapcraft --classic --channel=8.x/stable
- name: Setup LXD
uses: canonical/[email protected]
@@ -414,5 +416,5 @@ jobs:
- name: Publish Snap
run: |
sudo snap install snapcraft --classic
sudo snap install snapcraft --classic --channel=8.x/stable
snapcraft upload dist/standard-notes-${{ env.APP_VERSION }}-linux-amd64.snap --release stable,candidate,beta,edge
@@ -23,6 +23,9 @@ jobs:
with:
distribution: 'zulu'
java-version: '17'
- name: Setup Android SDK
run: |
echo "y" | "$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" "platforms;android-36" "build-tools;36.0.0"
- name: Export version for closed beta
run: |
BASE_VERSION=$(grep '"version"' ../web/package.json | cut -d '"' -f 4 | cut -d "-" -f 1)
@@ -21,6 +21,9 @@ jobs:
with:
distribution: 'zulu'
java-version: '17'
- name: Setup Android SDK
run: |
echo "y" | "$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" "platforms;android-36" "build-tools;36.0.0"
- name: Export version from package.json
run:
echo "PACKAGE_VERSION=$(grep '"version"' ../web/package.json | cut -d '"' -f 4 | cut -d "-" -f 1)" >> $GITHUB_ENV
+97 -5
View File
@@ -3,8 +3,15 @@ name: Publish Packages
on:
push:
branches: [main]
workflow_dispatch:
inputs:
package:
description: 'Package to publish (e.g. @standardnotes/releases)'
required: true
type: string
# Use commit message "[snjs docker only]" to build/push only standardnotes/snjs (:sha + :latest) for E2E; skips full build, web image, and NPM.
# Manual dispatch publishes tagged packages from an existing release commit without bumping versions.
permissions:
id-token: write
@@ -12,7 +19,7 @@ permissions:
jobs:
build:
name: Build & Test
if: "${{ contains(github.event.head_commit.message, 'chore(release): publish') == false && contains(github.event.head_commit.message, '[snjs docker only]') == false }}"
if: "${{ github.event_name == 'push' && contains(github.event.head_commit.message, 'chore(release): publish') == false && contains(github.event.head_commit.message, '[snjs docker only]') == false }}"
runs-on: ubuntu-latest
steps:
- name: Checkout code
@@ -39,7 +46,7 @@ jobs:
build-docker:
name: Build Docker Image
if: "${{ contains(github.event.head_commit.message, 'chore(release): publish') == false }}"
if: "${{ github.event_name == 'push' && contains(github.event.head_commit.message, 'chore(release): publish') == false }}"
runs-on: ubuntu-latest
steps:
- name: Checkout code
@@ -110,7 +117,7 @@ jobs:
publish-web-docker:
name: Build and publish Docker Image for Web App
if: "${{ contains(github.event.head_commit.message, 'chore(release): publish') == false && contains(github.event.head_commit.message, '[snjs docker only]') == false }}"
if: "${{ github.event_name == 'push' && contains(github.event.head_commit.message, 'chore(release): publish') == false && contains(github.event.head_commit.message, '[snjs docker only]') == false }}"
runs-on: ubuntu-latest
steps:
- name: Checkout code
@@ -148,7 +155,7 @@ jobs:
publish:
name: Publish to NPM
if: "${{ contains(github.event.head_commit.message, 'chore(release): publish') == false && contains(github.event.head_commit.message, '[snjs docker only]') == false }}"
if: "${{ github.event_name == 'push' && contains(github.event.head_commit.message, 'chore(release): publish') == false && contains(github.event.head_commit.message, '[snjs docker only]') == false }}"
runs-on: ubuntu-latest
steps:
- name: Checkout code
@@ -186,10 +193,95 @@ jobs:
- name: Publish
run: yarn publish:prod
publish-from-git-tags:
name: Publish to NPM from Git Tags
if: github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v3
with:
token: ${{ secrets.CI_PAT_TOKEN }}
ref: main
fetch-depth: 0
- name: Resolve release commit
id: release-commit
run: |
COMMIT="$(git log main --grep='chore(release): publish' -n 1 --format=%H)"
if [ -z "$COMMIT" ]; then
echo "No release commit found on main."
exit 1
fi
if ! git cat-file -e "${COMMIT}^{commit}" 2>/dev/null; then
echo "Commit ${COMMIT} does not exist."
exit 1
fi
TAG_COUNT="$(git tag --points-at "$COMMIT" | wc -l | tr -d ' ')"
if [ "$TAG_COUNT" -eq 0 ]; then
echo "Commit ${COMMIT} has no release tags."
exit 1
fi
echo "commit=${COMMIT}" >> "$GITHUB_OUTPUT"
echo "Using release commit ${COMMIT}"
git tag --points-at "$COMMIT"
- name: Checkout release commit
run: git checkout "${{ steps.release-commit.outputs.commit }}"
- name: Set up Node
uses: actions/setup-node@v3
with:
registry-url: 'https://registry.npmjs.org'
node-version-file: '.nvmrc'
cache: 'yarn'
- name: Upgrade npm (trusted publishing requirement)
run: npm install -g npm@^11.5.1
- name: Enable Corepack (Yarn)
run: corepack enable
- name: Install dependencies
run: yarn install --immutable
- name: Build
run: yarn build:all
- name: Publish tagged package
env:
PACKAGE: ${{ inputs.package }}
run: |
set -euo pipefail
PACKAGE="$(echo "$PACKAGE" | xargs)"
if [ -z "$PACKAGE" ]; then
echo "Package name is required."
exit 1
fi
mapfile -t TAGS < <(git tag --points-at HEAD --list "${PACKAGE}@*")
if [ "${#TAGS[@]}" -eq 0 ]; then
echo "No release tag found for ${PACKAGE} at the release commit."
exit 1
fi
if [ "${#TAGS[@]}" -gt 1 ]; then
echo "Multiple release tags found for ${PACKAGE}: ${TAGS[*]}"
exit 1
fi
echo "Publishing ${PACKAGE} (${TAGS[0]})..."
yarn workspace "$PACKAGE" npm publish --access public
publish-docker:
name: Publish to Docker Hub
needs: build-docker
if: "${{ contains(github.event.head_commit.message, 'chore(release): publish') == false }}"
if: "${{ github.event_name == 'push' && contains(github.event.head_commit.message, 'chore(release): publish') == false }}"
runs-on: ubuntu-latest
steps:
- name: Login to Docker Hub
+2 -2
View File
@@ -79,7 +79,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Run E2E test suite
uses: convictional/trigger-workflow-and-wait@master
uses: convictional/trigger-workflow-and-wait@224756e4cc7fa0b711a281193496319f816cd880 # master
with:
owner: standardnotes
repo: server
@@ -97,7 +97,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Run E2E vaults test suite
uses: convictional/trigger-workflow-and-wait@master
uses: convictional/trigger-workflow-and-wait@224756e4cc7fa0b711a281193496319f816cd880 # master
with:
owner: standardnotes
repo: server
+2 -2
View File
@@ -31,7 +31,7 @@ jobs:
- name: Deploy static site to S3 bucket
run: aws s3 sync packages/web/dist/ s3://app.standardnotes.com --delete
- name: Invalidate CloudFront Cache
uses: chetan/invalidate-cloudfront-action@master
uses: chetan/invalidate-cloudfront-action@fce6f6f546fae2e9fe55f3bd1411063a908f2557 # master
env:
DISTRIBUTION: ${{ secrets.WEBAPP_CLOUDFRONT_COM_DISTRIBUTION_ID }}
PATHS: '/*'
@@ -46,6 +46,6 @@ jobs:
steps:
- name: Run Discord Webhook
uses: johnnyhuy/actions-discord-git-webhook@main
uses: johnnyhuy/actions-discord-git-webhook@59b728b6b5cd1c18e4b462f4876d3a0d8e26f23a # main
with:
webhook_url: ${{ secrets.DISCORD_WEBHOOK_URL }}
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.

Some files were not shown because too many files have changed in this diff Show More