Skip to main content

0.8.2

· 2676 words

Excalibur 0.8.2 is a patch release that only updates dependencies. Updating to 0.8.2 is recommended but not required.

App

⬆️ Dependencies

  • ⬆️ Updated electron from 41.10.3 to 41.10.7 (#202)

  • ⬆️ Updated @noble/hashes from 2.3.0 to 2.4.0 (#200)

  • ⬆️ Updated Ionic dependencies (#202):

    • @ionic/core from 8.8.14 to 8.8.19
    • @ionic/react from 8.8.14 to 8.8.19
    • @ionic/react-router from 8.8.14 to 8.8.19
  • ⬆️ Updated Vite dependencies (#202):

    • @vitejs/plugin-react from 6.0.5 to 6.1.1
    • vitest development dependency from 5.0.0 to 5.0.1
  • ⬆️ Updated @types/node development dependency from 26.1.2 to 26.6.1 (#196)

  • ⬆️ Updated baseline-browser-mapping development dependency from 2.11.21 to 2.11.24 (#202)

  • ⬆️ Updated cypress development dependency from 15.21.0 to 15.21.1 (#202)

  • ⬆️ Updated ESLint development dependencies (#202):

    • eslint-plugin-cypress from 6.4.3 to 6.4.4
    • eslint-plugin-react-refresh from 0.5.4 to 0.5.7
    • typescript-eslint from 8.69.0 to 8.70.0
  • ⬆️ Updated globals development dependency from 17.8.0 to 17.12.0 (#202)

  • ⬆️ Updated lint-staged development dependency from 17.1.0 to 17.5.1 (#202)

  • ⬆️ Updated prettier development dependency from 3.9.6 to 3.9.7 (#202)

🧹 Miscellaneous

  • 🔧🚨 Replaced __dirname with import.meta.url-related calls to acquiesce to Vite

    • This stops the nuisance warning that the Vite configuration "uses features that are unsupported by configLoader: 'native'"

Server

⬆️ Dependencies

  • ⬆️ Updated rapidfuzz from 3.14.5 to 3.14.6 (#202)
  • ⬆️ Updated uvicorn from 0.52.4 to 0.53.0 (#202)
  • ⬆️ Updated websockets from 17.0.1 to 17.1 (#202)
  • ⬆️ Updated httpx2 test dependency from 2.12.0 to 2.13.0 (#202)

0.8.1

· 2625 words

Excalibur 0.8.1 is a patch release which makes some UI changes to the app. There are no API changes to the server.

Updating to 0.8.1 is recommended but not required. Since the only change to the server is dependency versions, one can omit updating the server to 0.8.1 (i.e., keep it on 0.8.0).

App

🔄 Changes

  • 💄 Allow skipping of already present files when uploading

    • Previously, the only two options presented was to override the (single) file or not (which halts the entire upload)
    • Now we present 5 options:
      • Skip This File
      • Skip All Existing
      • Override This File
      • Override All Existing
      • Abort Upload
  • 💄 Changed the ordering of jobs within the jobs modal:

    • In-progress jobs are now shown first
    • Indeterminate jobs are shown next
    • Failed jobs are shown next
    • Completed jobs are shown last
  • 💄 Created a grid-view for the directory list

    • Only available for large screens (768px and above)

⬆️ Dependencies

  • ⬆️ Updated Capacitor dependencies (#189):

    • @capacitor/android from 8.5.0 to 8.5.1
    • @capacitor/core from 8.5.0 to 8.5.1
  • ⬆️ Updated React dependencies (#186):

    • react from 19.2.8 to 19.3.0
    • react-dom from 19.2.8 to 19.3.0
    • @types/react development dependency from 19.2.18 to 19.3.0
    • @types/react-dom development dependency from 19.2.3 to 19.3.0
  • ⬆️ Updated vite from 8.1.5 to 8.3.0

  • ⬆️ Updated baseline-browser-mapping development dependency from 2.11.19 to 2.11.21 (#188)

  • ⬆️ Updated vitest development dependency from 4.1.11 to 5.0.0

🧹 Miscellaneous

  • 🩹🧑‍💻 Fixed incorrect type annotations for ExplorerContext's presentAlert(), dismissAlert(), and presentSnackbar() functions
  • 🩹 Made vitest tests compliant with Vitest 5

Server

⬆️ Dependencies

  • ⬆️ Updated alembic from 1.19.1 to 1.19.2 (#185)
  • ⬆️ Updated gitpython from 3.1.59 to 3.1.62 (#183)
  • ⬆️ Updated pydantic from 2.13.4 to 2.13.5 (#181)
  • ⬆️ Updated sqlmodel from 0.0.39 to 0.0.42 (#182)
  • ⬆️ Updated ruff development dependency from 0.16.3 to 0.16.6 (#184)

0.8.0

· 9668 words

Welcome to Excalibur 0.8! This release improves the Excalibur Encryption Format, which enhances both security and performance. Expect a significant speed-up when encrypting and decrypting files when using the new encryption format.

The Excalibur documentation website was also updated in this release.

If you are developing a custom Excalibur client, please read the 0.8 upgrade guide to learn how to interact with Excalibur 0.8 servers. If you are using the official app and server, there is no need to follow the upgrade guide.

Read all about the changes to Excalibur below. Enjoy!

App

🔒️ Security

  • 🔒️ Overridden version minima of dependencies in pnpm-workspace.yaml to address security vulnerabilities:

    • GHSA-6mj3-qw4j-hgrw, GHSA-g53g-w8rj-fmg7, GHSA-w2rr-34g9-rvrj, GHSA-4w3w-2rp5-g8jm, GHSA-c7q8-3ch8-vqpv, GHSA-27p8-2357-5qqv, GHSA-3px3-54cx-rmw9, GHSA-vr34-hp96-76pp, GHSA-8344-3jmq-59r6, GHSA-965w-775f-mr7g, GHSA-93r5-fhx6-vmg9, GHSA-6gmq-8vp8-gcm6, GHSA-6h8r-xr42-gp59: @xmldom/xmldom to 0.9.12
    • GHSA-c83g-rgw3-j3cx, GHSA-73wf-gq98-2v4g: browserslist to 4.28.7
    • GHSA-2883-xcg3-v3hh: js-yaml to 4.3.2
    • GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf, GHSA-jqff-g426-hqxp: fast-uri to 3.1.6
    • GHSA-x5fp-wj9c-mxmx, GHSA-4mjr-xmp4-gh2g: qs to 6.16.0
    • GHSA-rgj7-g3m4-5g8c: sharp to 0.35.4

✨ New Features

  • ✨ All new encryption performed on the app will now use the Excalibur Encryption Format (ExEF) version 4
    • Read about the performance improvements below
  • 🔧 Added new "file read chunk size" setting to configure file reading operations

🔄 Changes

  • 💬 The displayed value of the file size will now include the ExEF overhead (previously it would have been the raw plaintext size)

⚡️ Performance Improvements

  • ⚡️ Use @noble/ciphers's webcrypto.js implementation for ExEF v4 instead of the aes.js implementation

    • Benchmarking shows that webcrypto.js encryption/decryption is ~35x faster than aes.js

      =================================== 64 KiB ====================================
      aes.js ╢██████████████████████████████████████████████████░░░░░ 40.7 ms
      webcrypto.js ╢█░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 0.7 ms
      ╠═══════════════════════════════════════════════════════
      0 45

      =================================== 256 KiB ===================================
      aes.js ╢████████████████████████████████████████████████████▓░░ 52.5 ms
      webcrypto.js ╢█░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 1 ms
      ╠═══════════════════════════════════════════════════════
      0 55

      ==================================== 1 MiB ====================================
      aes.js ╢██████████████████████████████████████████████████░░░░░ 182.4 ms
      webcrypto.js ╢███░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 9.4 ms
      ╠═══════════════════════════════════════════════════════
      0 200

      ==================================== 4 MiB ====================================
      aes.js ╢██████████████████████████████████████████████████████░ 732.9 ms
      webcrypto.js ╢██░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 30.7 ms
      ╠═══════════════════════════════════════════════════════
      0 750

      =================================== 16 MiB ====================================
      aes.js ╢█████████████████████████████████████████████████████░░ 2888.9 ms
      webcrypto.js ╢██░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 85.7 ms
      ╠═══════════════════════════════════════════════════════
      0 3000

      =================================== 64 MiB ====================================
      aes.js ╢█████████████████████████████████████████████████████░░ 11506 ms
      webcrypto.js ╢██░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 439.9 ms
      ╠═══════════════════════════════════════════════════════
      0 12000
    • This performance improvement only applies to ExEF files and streams. ExEF v3 files do not enjoy this performance improvement (as they still rely on a single-chunk encryption/decryption process)

  • ⚡️ Slightly improved performance of encryption/decryption operations by removing stream chunking.

    • We no longer pre-chunk streams before passing them to the encryption/decryption functions as ExEF v4 handles chunking internally.

⬆️ Dependencies

  • ⬆️ Updated Android dependencies:

    • androidxAppCompatVersion from 1.7.1 to 1.8.0
  • ⬆️ Updated Capacitor dependencies (#151):

    • @capacitor/android from 8.4.0 to 8.5.0
    • @capacitor/core from 8.4.0 to 8.5.0
  • ⬆️ Updated React dependencies (#149):

    • react from 19.2.7 to 19.2.8
    • react-dom from 19.2.7 to 19.2.8
    • @types/react development dependency from 19.2.7 to 19.2.8
  • ⬆️ Updated @capacitor/filesystem from 8.1.2 to 8.1.3 (#169)

  • ⬆️ Updated @noble/ciphers from 2.2.0 to 2.4.0 (#148, #177)

  • ⬆️ Updated @noble/hashes from 2.2.0 to 2.3.0 (#147)

  • ⬆️ Updated immer from 11.1.15 to 11.1.18 (#171)

  • ⬆️ Updated ionicons from 8.0.13 to 8.1.0 (#152)

  • ⬆️ Updated baseline-browser-mapping development dependency from 2.10.44 to 2.11.19 (#167)

  • ⬆️ Updated cypress development dependency from 15.20.0 to 15.21.0 (#150, #162)

  • ⬆️ Updated eslint-plugin-react-refresh development dependency from 0.5.3 to 0.5.4 (#154)

  • ⬆️ Updated start-server-and-test development dependency from 3.0.11 to 3.0.12 (#156)

  • ⬆️ Updated typescript-eslint development dependency from 8.66.0 to 8.69.0 (#172, #175)

  • ⬆️ Updated vitest development dependency from 4.1.10 to 4.1.11 (#176)

Server

💥 Breaking Changes

  • 💥 All encryption performed on the server will now use the Excalibur Encryption Format (ExEF) version 4

    • ExEF v3 is no longer supported
    • This affects all routes that require encryption, including file uploads and downloads

    Please read the documentation for the ExEF v4 specification to learn how to handle ExEF v4 data.

  • 💥 Changed how authentication works for WebSocket endpoints

    • Please see the updated documentation for "authenticating subsequent requests"
  • 💥 Removed include_exef_size query parameter from the following endpoints:

    • /api/files/search
    • /api/files/list/{path}

    The behaviour now is to always include the ExEF additional size (i.e., header and, possibly, footer) in file sizes.

  • 🗑️ Removed the /api/well-known/info endpoint

    • The maximum upload size and times required to compute the time offset will be sent along with login responses
    • To get the version, use the /api/well-known/version endpoint instead
  • 💥 We will now use uv's 0.12.x series to build and install the server package, updating the minimum version from 0.11.26 in pyproject.toml and GitHub actions to 0.12.13

🗑️ Deprecations

  • ⚰️ Removed ExEF v3 code
  • 🗑️ Removed the excalibur user add command
    • User creation must now be done through the API

⬆️ Dependencies

  • ⬆️ Updated alembic from 1.18.5 to 1.19.1 (#146)
  • ⬆️ Updated gitpython from 3.1.58 to 3.1.59 (#145)
  • ⬆️ Updated packaging from 26.2 to 26.3 (#160)
  • ⬆️ Updated pydantic-settings from 2.14.2 to 2.15.0 (#143)
  • ⬆️ Updated uvicorn from 0.52.0 to 0.52.4 (#158)
  • ⬆️ Updated ipython development dependency from 9.15.0 to 9.16.1 (#144)
  • ⬆️ Updated ruff development dependency from 0.16.1 to 0.16.3 (#161)
  • ⬆️ Updated httpx2 test dependency from 2.9.1 to 2.12.0 (#142, #159)

0.7.4

· 3375 words

Excalibur 0.7.4 is a patch release that only updates dependencies. Updating to 0.7.4 is recommended but not required.

App

⬆️ Dependencies

  • 🔒️ Overridden version minima of dependencies in pnpm-workspace.yaml to address security vulnerabilities:

    • GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895: brace-expansion@<1.1.18 to 1.1.18, brace-expansion@>=2.0.0 <2.1.4 to 2.1.4, and brace-expansion@>=4.0.0 <5.0.9 to 5.0.9
    • GHSA-7p8r-x3mc-p8w7: fast-uri@>=3.0.0 <3.1.5 to 3.1.5
    • GHSA-5p4m-2wfm-xmqj: js-yaml@>=4.0.0 <4.3.1 to 4.3.1
    • GHSA-2v37-7h3g-55p8: nanoid@<3.3.18 to 3.3.18
    • GHSA-fxqj-rqcc-2cmp: postcss@<8.5.23 to 8.5.23
    • GHSA-r292-9mhp-454m: tar@<7.5.21 to 7.5.21
    • GHSA-4cwx-7wf7-3272, GHSA-8xcm-r25x-g524, GHSA-m8rv-5g2x-5cg5, GHSA-jr45-8vmc-qm54, GHSA-v3r7-h72x-cjcm: undici@<6.28.0 to 6.28.0 and undici@>=7.0.0 <7.29.0 to 7.29.0
  • ➕ Added supports-color development dependency

  • ⬆️ Updated @capawesome/capacitor-file-picker from 8.0.3 to 8.0.4 (#140)

  • ⬆️ Updated @vitejs/plugin-react from 6.0.3 to 6.0.5 (#137)

  • ⬆️ Updated buffer from 5.7.1 to 6.0.3 (#127)

  • ⬆️ Updated electron from 41.10.2 to 41.10.3, addressing GHSA-9f4c-93c8-jc8g (#131)

  • ⬆️ Updated @types/node development dependency from 25.9.5 to 26.1.2 (#129)

  • ⬆️ Updated cypress development dependency from 15.17.0 to 15.20.0 (#138)

  • ⬆️ Updated globals development dependency from 17.7.0 to 17.8.0 (#128)

  • ⬆️ Updated prettier development dependency from 3.9.5 to 3.9.6 (#141)

  • ⬆️ Updated typescript-eslint development dependency from 8.64.0 to 8.66.0 (#139)

  • ⬆️ Updated Gradle version for Android builds from 8.14.3 to 8.14.5

Server

⬆️ Dependencies

  • ⬆️ Updated duckdb from 1.5.4 to 1.5.5 (#118)

  • ⬆️ Updated fastapi from 0.139.2 to 0.141.1 (#134)

  • ⬆️ Updated gitpython from 3.1.52 to 3.1.58 (#119, #123)

  • ⬆️ Updated typer from 0.27.0 to 0.27.1 (#133)

  • ⬆️ Updated uvicorn from 0.51.0 to 0.52.0 (#125)

  • ⬆️ Updated websockets from 16.1.1 to 17.0.1 (#122, #135)

  • ⬆️ Updated ruff development dependency from 0.15.22 to 0.16.1 (#121, #136)

  • ⬆️ Updated httpx2 test dependency from 2.7.0 to 2.9.1 (#124)

0.7.3

· 4215 words

Excalibur 0.7.3 is a patch release that primarily updates dependencies and fixes some minor issues.

App

🔒️ Security

  • 🔒️ Overridden version minima of dependencies in pnpm-workspace.yaml to address security vulnerabilities:

    • GHSA-gcfj-64vw-6mp9, GHSA-42h9-826w-cgv3, GHSA-xj6q-8x83-jv6g, GHSA-pmv8-rq9r-6j72, GHSA-jqh4-m9w3-8hp9, GHSA-mmx7-hfxf-jppx, GHSA-f4gw-2p7v-4548, GHSA-hcpx-6fm6-wx23, GHSA-7q8q-rj6j-mhjq, GHSA-mwf2-3pr3-8698: axios@<1.18.0 to 1.18.0
    • GHSA-3jxr-9vmj-r5cp, GHSA-3jxr-9vmj-r5cp: brace-expansion@<1.1.16 to 1.1.16 and brace-expansion@>=2.0.0 <2.1.2 to 2.1.2
    • GHSA-v2hh-gcrm-f6hx: fast-uri to 3.1.4
    • GHSA-52cp-r559-cp3m: js-yaml to 4.3.0
    • GHSA-f88m-g3jw-g9cj: sharp to 0.35.0
    • GHSA-5xpp-75jx-m839: systeminformation to 5.31.7
    • GHSA-23hp-3jrh-7fpw, GHSA-8x88-c5mf-7j5w, GHSA-w8wr-v893-vjvp, GHSA-gvwx-54wh-qm9j: tar to 7.5.19
    • GHSA-vmh5-mc38-953g, GHSA-vxpw-j846-p89q, GHSA-hm92-r4w5-c3mj, GHSA-p88m-4jfj-68fv, GHSA-pr7r-676h-xcf6, GHSA-35p6-xmwp-9g52, GHSA-g8m3-5g58-fq7m: undici to 7.28.0

⬆️ Dependencies

  • ⬆️ Updated Capacitor dependencies:

    • @capacitor/app from 8.1.0 to 8.1.1
    • @capacitor/keyboard from 8.0.3 to 8.0.5
  • ⬆️ Updated ESLint dependencies:

    • eslint from 9.39.4 to 9.39.5
    • @eslint/js from 9.39.4 to 9.39.5 (#111)
    • eslint-plugin-cypress from 6.4.2 to 6.4.3 (#103)
    • typescript-eslint from 8.62.1 to 8.64.0 (#105)
  • ⬆️ Updated Electron dependencies:

    • electron from 41.9.2 to 41.10.2
    • electron-updater from 6.8.3 to 6.8.9
  • ⬆️ Updated Ionic dependencies:

    • @ionic/core from 8.8.9 to 8.8.14
    • @ionic/react from 8.8.9 to 8.8.14
    • @ionic/react-router from 8.8.9 to 8.8.14
  • ⬆️ Updated Prettier dependencies:

    • prettier from 3.9.4 to 3.9.5 (#109)
    • prettier-plugin-tailwindcss from 0.8.0 to 0.8.1 (#115)
  • ⬆️ Updated TailwindCSS dependencies:

    • tailwindcss from 4.3.0 to 4.3.3
    • @tailwindcss/vite from 4.3.0 to 4.3.3
  • ⬆️ Updated Vite dependencies:

    • vite from 8.0.16 to 8.1.5
    • @vitejs/plugin-react from 6.0.1 to 6.0.3
  • ⬆️ Updated baseline-browser-mapping from 2.10.33 to 2.10.44

  • ⬆️ Updated immer from 11.1.9 to 11.1.15

  • ⬆️ Updated lint-staged from 17.0.5 to 17.1.0

  • ⬆️ Updated start-server-and-test from 3.0.6 to 3.0.11

  • ⬆️ Updated @types/node development dependency from 25.9.1 to 25.9.5

  • ⬆️ Updated globals development dependency from 17.6.0 to 17.7.0

  • ⬆️ Updated vitest development dependency from 4.1.9 to 4.1.10

🧹 Miscellaneous

  • 🔨 Partially fixed somewhat flaky Cypress end-to-end tests

Server

🔄 Changes

  • 🧱 Changed uvicorn WebSocket protocol implementation from websockets (which is soon to be deprecated) to websockets-sansio

🐛 Bug Fixes

  • 🐛 Fixed sporadic "unique file handle conflict" errors that occur when accessing endpoints that use the database

⬆️ Dependencies

  • ⬆️ Updated duckdb from 1.5.3 to 1.5.4
  • ⬆️ Updated fastapi from 0.139.0 to 0.139.2 (#114)
  • ⬆️ Updated gitpython from 3.1.50 to 3.1.52 (#106)
  • ⬆️ Updated tomlkit from 0.15.0 to 0.15.1 (#113)
  • ⬆️ Updated typer from 0.26.8 to 0.27.0 (#110)
  • ⬆️ Updated websockets from 16.0 to 16.1.1
  • ⬆️ Updated ruff development dependency from 0.15.20 to 0.15.22 (#104, #117)
  • ⬆️ Updated httpx2 test dependency from 2.5.0 to 2.7.0 (#108)