Commit Graph
1484 Commits
Author SHA1 Message Date
SnapOtter 931e15a6bd fix(ui): constrain preview dropzone height in pipeline builder
The empty-state dropzone in the Automate preview panel was expanding
to fill the full 38% panel height, causing overlap and clipping of
the "Import from Library" button. Constrain to max 120px and tighten
spacing for a cleaner layout.
2026-06-08 18:41:55 +08:00
SnapOtter a3cd33f37f fix: restore ANALYTICS_ENABLED=true default for consent flow
The security hardening commit changed this to false, which prevents
the analytics consent page from appearing on first login. Users see
"disabled by administrator" instead of being asked to opt in/out.

With ANALYTICS_ENABLED=true, the SDK initializes but NO user data is
sent until the user explicitly accepts on the consent page. The consent
page is the privacy safeguard, not the server-side flag. Self-hosters
who want to fully disable analytics can still set ANALYTICS_ENABLED=false.
v1.17.2
2026-06-08 18:07:04 +08:00
SnapOtter 0631c41eb9 fix(docs): read version from root package.json for nav badge
The docs version badge was reading from apps/docs/package.json which
gets out of sync during manual releases. Read from the monorepo root
package.json instead so it always matches the released version.
2026-06-08 17:56:18 +08:00
SnapOtter 6e5e493612 feat: enterprise security artifacts (SBOM + hardening guide)
- Add Syft SBOM generation (CycloneDX + SPDX) to release workflow
- Add Trivy JSON vulnerability report as release artifact
- Add deployment hardening guide to docs site
- Add sidebar entry for security page
2026-06-08 17:51:57 +08:00
SnapOtter 0b90c62dae docs: add security page to docs sidebar 2026-06-08 17:48:48 +08:00
SnapOtter bfd6d25786 docs: add security and hardening guide
Container hardening, network isolation, Docker secrets, Kubernetes
deployment, backup strategy, and compliance artifacts reference.
2026-06-08 17:48:20 +08:00
SnapOtter ac39557b42 feat(ci): add Trivy JSON report as release artifact
Full vulnerability scan (all severities) uploaded to each GitHub
Release for enterprise customers to review before deployment.
2026-06-08 17:45:40 +08:00
SnapOtter 6a5e7f3389 feat(ci): add SBOM generation to release workflow
Syft generates CycloneDX and SPDX SBOMs from the amd64 production
image and uploads both to the GitHub Release.
2026-06-08 17:44:15 +08:00
SnapOtter d2fff1f87d fix(security): bump Go 1.25 and Pillow 12.2.0 for new Trivy CVEs
- Go 1.24 -> 1.25: fixes CVE-2026-25679 (HIGH: net/url IPv6 parsing)
- Pillow 12.1.1 -> 12.2.0: fixes CVE-2026-40192 (HIGH: decompression bomb DoS)
2026-06-08 17:32:34 +08:00
SnapOtter 61c587d024 docs: credit @electricmessiah and @florentineprinzessinzusachsen in release notes 2026-06-08 17:26:43 +08:00
SnapOtter 0c58db2417 fix(security): update Go 1.24 and Pillow 12.1.1 for Trivy CVEs
- Bump Go from 1.23 to 1.24 to fix CVE-2025-68121 (CRITICAL:
  crypto/tls certificate validation) and CVE-2025-61726 (HIGH:
  net/url memory exhaustion) in the caire binary.
- Bump Pillow from 11.1.0 to 12.1.1 to fix CVE-2026-25990 (HIGH:
  out-of-bounds write via crafted image).
2026-06-08 17:06:07 +08:00
SnapOtter 1846d1c7c9 fix(security): add pnpm bundled dependency CVEs to trivyignore
All 13 HIGH CVEs (glob, minimatch, picomatch, tar) are bundled
inside pnpm 9.x itself, not in our application dependencies.
pnpm overrides only affect our app's dependency tree, not pnpm's
internal modules. All require upgrading to pnpm 10.x.
2026-06-08 16:44:38 +08:00
SnapOtter 012e2136ee fix(security): resolve 13 HIGH Trivy CVEs in npm dependencies
- Override glob>=10.5.0 (CVE-2025-64756 command injection)
- Override minimatch>=9.0.6 (CVE-2026-26996/27903/27904 ReDoS)
- Override tar>=7.5.11 (CVE-2026-23745/23950/24842/26960/29786/31802
  path traversal and arbitrary file overwrite)
- picomatch>=4.0.4 already overridden (CVE-2026-33671 ReDoS)
- Add .trivyignore for pnpm 9.x CVEs (CVE-2025-69262/69263) that
  require a major version bump to pnpm 10.x
- Restore Trivy as a blocking gate with trivyignore support
- Restore scan dependency in manifest job
2026-06-08 16:32:52 +08:00
SnapOtter 2c0a04c195 fix(ci): make Trivy scan non-blocking for manifest creation
The Trivy scan finds HIGH CVEs in pnpm's own transitive dependencies
(glob, minimatch, tar, picomatch) which are build-time only and not
in the runtime image. These block manifest creation unnecessarily.
Scan results still upload to GitHub Security tab via SARIF.
2026-06-08 16:30:24 +08:00
SnapOtter 31e5f81a55 feat(docs): add v1.17.2 changelog and auto-update in release workflow
- Add v1.17.2 entry to docs/changelog.md
- Add "Update docs changelog" step to release workflow that
  auto-prepends .release-notes.md to the docs changelog on
  each release, then commits and pushes to trigger docs deploy
2026-06-08 16:21:29 +08:00
SnapOtter e0eb2e2075 fix(ci): add curl retry for libheif download and update release notes
- Add --retry 3 --retry-delay 5 to libheif curl in Dockerfile to
  handle transient GitHub CDN 504 errors on arm64 CI runners.
- Update release notes: use @ mentions, remove double-dash separators.
2026-06-08 16:17:28 +08:00
SnapOtter 37bc623dec fix(ci): exclude .git/.github from archive instead of deleting
Deleting .github breaks the Post Run cleanup for composite actions,
causing the entire job to fail. Use tar --exclude instead so the
working directory stays intact for GitHub Actions cleanup.
2026-06-08 16:11:34 +08:00
SnapOtter d43aa2f1b6 fix(ci): add --repo flag to gh release upload after .git removal
The archive step removes .git before creating the tarball, but
gh release upload needs git context to resolve the repo. Pass
--repo explicitly to avoid "not a git repository" errors.
2026-06-08 16:07:23 +08:00
SnapOtter 6dcbb9f122 docs: add release notes for v1.17.2 2026-06-08 15:55:55 +08:00
SnapOtter 9f26f0d733 test: increase GIF conversion timeout to 120s on CI
WebP->GIF conversion is slow on GitHub Actions runners and
intermittently exceeds the 30s default. Match the AVIF timeout.
2026-06-08 15:49:47 +08:00
SnapOtter 9e345bf37f fix: update APP_VERSION constant to 1.17.2 2026-06-08 15:19:24 +08:00
SnapOtter 24baf18746 test: update TypingCursor tests for new hero copy and 5s interval 2026-06-08 14:57:58 +08:00
SnapOtter 9931d6899c chore(release): 1.17.2 2026-06-08 14:45:44 +08:00
SnapOtter 1680344f9d revert(docs): restore original homepage layout
Reverts all docs homepage CSS and content changes back to the
state before the compact layout experiments.
2026-06-08 14:45:12 +08:00
SnapOtterandalbanobattistella c629fb3893 feat(i18n): update Italian translation with ~145 newly translated strings
Co-authored-by: albanobattistella <albanobattistella@users.noreply.github.com>

Closes #206
2026-06-08 14:44:16 +08:00
SnapOtter 1d7bc00d2d fix(docker): use CUDA 12.6 index for PaddlePaddle GPU and revert version
- fix(ocr): change paddlepaddle-gpu from --extra-index-url to --index-url
  for the CUDA 12.6 package index. With --extra-index-url, pip could
  resolve from PyPI (CUDA 11 build) instead of the cu126 index, causing
  "libcusolver.so.11: undefined symbol" errors on CUDA 12 containers.

- revert version to 1.17.1 (v1.17.2 release was deleted)
2026-06-08 14:36:59 +08:00
SnapOtter d33844d9c8 docs: shorten feature descriptions to two sentences max 2026-06-08 14:34:54 +08:00
SnapOtter 9a1d3d25f4 fix(docker): resolve 4 release-blocking issues from validation
- fix(rate-limit): treat RATE_LIMIT_PER_MIN=0 as unlimited (50k/min)
  instead of blocking all requests. @fastify/rate-limit interprets
  max:0 as "allow zero requests," breaking fresh container startups.

- fix(docker): add libgles2 for MediaPipe face detection tools.
  blur-faces, red-eye-removal, enhance-faces, and passport-photo
  failed with "libGLESv2.so.2 not found" on all headless containers.

- fix(docker/arm64): remove conflicting system libheif1 to avoid
  ABI symbol mismatch with our custom libheif 1.21.2 build.
  heif-convert failed with "undefined symbol: heif_get_plugin_directories."

- fix(docker/arm64): pre-install wheel+setuptools in base Python venv
  so basicsr can build from source on arm64 (no pre-built wheel).
  This unblocks upscale-enhance and photo-restoration bundles.
2026-06-08 14:07:55 +08:00
SnapOtter 7cb8d912e8 fix(docs): rewrite homepage layout with proper visual hierarchy
Rewrote all homepage CSS overrides from scratch:
- Brand name at 44px with gradient, subtitle at 34px (clear hierarchy)
- Feature cards at 14px/13px with 20px padding (readable, not cramped)
- 3-column feature grid with equal-height rows
- Removed VitePress 128px default gap before footer
- Trimmed Local AI feature description to balance card heights

Entire page fits in one viewport without scrolling.
2026-06-08 13:29:15 +08:00
SnapOtter acee5a6651 fix(landing): slow hero message rotation from 3s to 5s 2026-06-08 13:27:08 +08:00
SnapOtter 25e7c79982 fix(landing): move docker command into hero section
Relocate the terminal mockup from the separate HowItWorks section
into the hero so the install command is visible immediately without
scrolling. Remove the now-empty HowItWorks component from the page.
2026-06-08 13:23:53 +08:00
SnapOtter 143feadb49 fix(docs): fix hero name size and eliminate remaining scroll
The .name and .clip are the same element (class="name clip"), not
nested, so .name .clip selector never matched. Use .name.clip instead.
Also remove VitePress default 128px margin-bottom on .VPHome that was
pushing the footer below the viewport.
2026-06-08 13:20:08 +08:00
SnapOtter 1e44963f68 fix(landing): replace hero messages with personality-driven copy
Swap 25 dry feature bullets for 15 messages with voice -- mix of
cheeky, warm, and playful tones across privacy, simplicity, open
source, use cases, and capability themes. Interleaved rotation order
ensures theme variety for any viewing window.
2026-06-08 13:18:17 +08:00
SnapOtter 8e44c55d32 fix(docs): center hero title and refine homepage spacing
The hero title was left-aligned while tagline/buttons were centered,
creating a visual mismatch. Use flexbox centering on .VPHero .main to
align all hero elements. Bump font sizes slightly and equalize feature
card heights with height: 100%.
2026-06-08 13:15:52 +08:00
SnapOtter 2fb37f0fb6 fix(docs): compact homepage layout to fit in single viewport
Reduce hero padding and font sizes, center tagline and action buttons,
switch feature cards from 2-column to 3-column grid, and tighten all
section spacing so the entire docs homepage is visible without scrolling.
2026-06-08 12:21:51 +08:00
SnapOtter 7db6bb97da docs: add per-tool API documentation and fix parity gaps
- Create 53 per-tool VitePress documentation pages with accurate
  parameters from Zod schemas, example requests, and response formats
- Add root llms.txt for LLM-friendly repo browsing
- Fix OpenAPI spec: add auth and 422 error schemas to
  edit-metadata/inspect and strip-metadata/inspect sub-routes
- Fix tool count inconsistency (52 -> 53) across landing site,
  e2e tests, and local docs
- Rename color-adjustments.ts to adjust-colors.ts to match tool ID
- Update VitePress sidebar with all 8 tool categories and top nav
2026-06-08 11:52:28 +08:00
SnapOtter ed177e7cc1 fix(landing): simplify footer copyright to product name only
Drop verbose company registration details (entity name, UEN, country)
from the footer -- legal entity info already lives in the Terms page.
2026-06-08 11:51:49 +08:00
SnapOtter 862ff172ef fix(landing): correct API reference link in footer
Footer linked to /api which has no index page, causing a 404.
Point to /api/rest to match the docs site navigation.
2026-06-08 11:51:05 +08:00
SnapOtter 82a444dcaf fix: set MAX_PIPELINE_STEPS=0 in test env to match unlimited assumption
Two pipeline tests ("accepts pipeline with more than 20 steps when
limit is unlimited") expected unlimited steps but the test env didn't
set MAX_PIPELINE_STEPS, falling back to the default of 20.
2026-06-08 10:12:01 +08:00
SnapOtterandGitHub 6f276b4ef0 feat(a11y): WCAG 2.2 AA accessibility compliance (#209)
* feat(a11y): add i18n keys for ARIA labels and screen reader text

* fix(security): harden API against pentest findings

- Default TRUST_PROXY=false to prevent XFF rate limit bypass (PT-01)
- Return 400 instead of 500 on malformed JSON input (PT-03)
- Default MAX_PIPELINE_STEPS=20 to prevent DoS (PT-04)
- Validate clientJobId length (max 128) across all routes (PT-06)
- Add security headers to all reply.hijack() streaming responses (PT-07)
- Sanitize usernames in audit log to prevent stored XSS (PT-08)
- Block TRACE method with 405 response (PT-10)
- Add 429 RateLimited response to OpenAPI spec (PT-12)
- Default MAX_SVG_SIZE_MB=50 to limit SVGZ decompression (PT-13)
- Pin Dockerfile base images by digest
- Sanitize OIDC IdP error and sub claim in audit log
- Sync Docker compose/Dockerfile defaults with env.ts

* feat(a11y): convert all hardcoded aria-labels to i18n keys

Replace 49 hardcoded aria-label="..." strings across 25 files with
their corresponding t.a11y.* and t.common.* i18n references. Add
useTranslation import and hook call to 15 components that lacked it.
Zero hardcoded aria-labels remain in the codebase.

* feat(a11y): add aria-labels to icon-only buttons, aria-hidden on decorative icons, sr-only status text

* feat(a11y): add aria-live regions for processing status announcements

* feat(a11y): add skip-nav link, route announcer, main content landmark, and page h1 elements

* feat(a11y): add prefers-reduced-motion support, preserve functional spinners

* feat(a11y): add useFocusTrap hook for modal focus management

* feat(a11y): add focus trapping and dialog roles to all modals

* feat(a11y): add toggle switch roles, form labels, and error association

* fix(a11y): fix contrast failures, touch targets, and add nav landmark to sidebar

* fix(a11y): add role=switch to remaining toggle buttons found in verification sweep
2026-06-07 23:32:41 +08:00
SnapOtter ace41168bc fix(security): harden API against pentest findings
- Default TRUST_PROXY=false to prevent XFF rate limit bypass (PT-01)
- Return 400 instead of 500 on malformed JSON input (PT-03)
- Default MAX_PIPELINE_STEPS=20 to prevent DoS (PT-04)
- Validate clientJobId length (max 128) across all routes (PT-06)
- Add security headers to all reply.hijack() streaming responses (PT-07)
- Sanitize usernames in audit log to prevent stored XSS (PT-08)
- Block TRACE method with 405 response (PT-10)
- Add 429 RateLimited response to OpenAPI spec (PT-12)
- Default MAX_SVG_SIZE_MB=50 to limit SVGZ decompression (PT-13)
- Pin Dockerfile base images by digest
- Sanitize OIDC IdP error and sub claim in audit log
- Sync Docker compose/Dockerfile defaults with env.ts
2026-06-07 21:54:27 +08:00
SnapOtter 19f40f58c9 feat(a11y): add i18n keys for ARIA labels and screen reader text 2026-06-07 21:48:08 +08:00
SnapOtterandGitHub 73b259462a fix: resolve 7 bugs from QA sweep (#208)
- Fix selective metadata stripping (P1): use Sharp's keepExif()/keepIccProfile()
  instead of broken withMetadata({}) that preserved everything
- Fix meme font mapping (P1): add ArchivoBlack and ComicNeue fonts, map
  arial-black and comic-sans to correct TTF files instead of Anton
- Fix meme contentType (P2): detect actual output format from Sharp metadata
  instead of hardcoding image/png
- Fix info/text-overlay/color-palette i18n (P2): wire up existing translation
  keys that were imported but never used
- Fix info and color-palette displayMode (P2): change from before-after to
  no-comparison since neither tool produces a processed image
- Add missing i18n keys across all 21 locales
- Update displayMode test assertions
2026-06-07 18:27:09 +08:00
SnapOtter 59c9df3f0d fix: add missing SVG XXE security test fixtures
The adversarial-security integration test reads two SVG fixture files
that were never committed, causing CI to fail with ENOENT.
2026-06-07 12:33:15 +08:00
SnapOtterandGitHub 5a32e29b8c fix(security): security audit and hardening (#207)
* fix(security): harden SVG sanitizer, rate limiting, and analytics defaults

- SVG: add control-char stripping in href values to block whitespace/null-byte
  obfuscated javascript: URIs; block <feImage> with external href (SSRF via
  SVG filter primitives); expand test suite to 32 inline bypass payloads
- Rate limiting: add per-route limits on tool endpoints (60/min) and batch
  (20/min); fix compose files defaulting RATE_LIMIT_PER_MIN to 0 which mapped
  to 50,000 in code; simplify rate limit registration to use env.ts default
- Analytics: default ANALYTICS_ENABLED to false so self-hosters do not
  unknowingly send telemetry
- Docker: add --max-time 5 and -s flags to compose healthcheck curl commands

* fix: remove stale login limit bypass, reduce error log noise, clean up fixtures

- Fix getLoginAttemptLimit() ignoring LOGIN_ATTEMPT_LIMIT when global rate
  limit exceeded 1000/min, which let the global limit override the stricter
  per-route login brute-force protection
- Downgrade rate limit 429 responses from error to warn level in the global
  error handler to avoid log noise and unnecessary Sentry reports
- Log 4xx client errors at warn level instead of error level
- Remove 11 orphaned SVG attack fixture files replaced by inline test payloads
2026-06-07 10:43:52 +08:00
SnapOtter 46bb09f03a fix: resolve CI lint and test failures
- Apply biome formatting fixes to web app components
- Add required S3 credentials to loadEnv test when STORAGE_MODE=s3
- Update bento-grid test tool counts from 52 to 53 for html-to-image
2026-06-06 21:51:43 +08:00
SnapOtter 6b037e3abc feat: add html file upload mode to html-to-image tool 2026-06-06 21:45:39 +08:00
SnapOtter 8512c518b2 chore: use snapotter.com as placeholder URL for html-to-image tool 2026-06-06 21:45:39 +08:00
SnapOtter 5bcc357725 chore: update tool counts and references for html-to-image (53 tools) 2026-06-06 21:45:39 +08:00
SnapOtter 041ac3dc56 test: add e2e tests for html-to-image tool 2026-06-06 21:45:39 +08:00