Skip to content

Releases: emmpaul/the-desk

v1.13.0

Choose a tag to compare

@emmpaul emmpaul released this 20 Jul 23:25
f868406

1.13.0 (2026-07-20)

Features

  • add CSP_EXTRA_FONT_SRC to allow-list an external font host (#654) (00f25ba)
  • declare base-uri, form-action and object-src in the csp (#652) (86017d8)
  • deny framing by default with frame-ancestors and X-Frame-Options (#656) (a4ec64f)
  • proxy remote images so img-src can drop the https: wildcard (#655) (a65b3d6)
  • send hsts on secure responses and default the secure session cookie (#659) (7ee77dd)
  • set a content-security-policy header on web responses (#650) (51bc293)

Bug Fixes

  • fork worktrees from the remote base branch (#642) (edf1639), closes #639
  • give the browser-written cookies samesite and secure flags (#657) (082b967)
  • refuse a candidate release below develop's baseline (#638) (87dbcb6)
  • stop background writes from cancelling the visit in flight (#646) (560e39f)

Performance

  • run the local Pest gate in parallel like CI does (#649) (4d4889c)

📦 Docker image

This release is published to the GitHub Container Registry:

ghcr.io/emmpaul/the-desk:1.13.0

Pull it directly or browse the package page. See the upgrade guide for self-hosting steps.

v1.13.0-rc.2

v1.13.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

@emmpaul emmpaul released this 20 Jul 23:04
0c404bf

1.13.0-rc.2 (2026-07-20)

Features

  • send hsts on secure responses and default the secure session cookie (#659) (7ee77dd)

Bug Fixes

  • give the browser-written cookies samesite and secure flags (#657) (082b967)

🚧 Release candidate

This is a release candidate, published for testing ahead of 1.13.0. It is not supported for production — run it against a copy of your data, not your live workspace, and expect it to be superseded without notice. Self-hosters should stay on the latest stable release.

📦 Docker image

This release is published to the GitHub Container Registry:

ghcr.io/emmpaul/the-desk:1.13.0-rc.2

Pull it directly or browse the package page. See the upgrade guide for self-hosting steps.

v1.13.0-rc.1

v1.13.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@emmpaul emmpaul released this 20 Jul 22:19
4ae5895

1.13.0-rc.1 (2026-07-20)

Features

  • add CSP_EXTRA_FONT_SRC to allow-list an external font host (#654) (00f25ba)
  • declare base-uri, form-action and object-src in the csp (#652) (86017d8)
  • deny framing by default with frame-ancestors and X-Frame-Options (#656) (a4ec64f)
  • proxy remote images so img-src can drop the https: wildcard (#655) (a65b3d6)

🚧 Release candidate

This is a release candidate, published for testing ahead of 1.13.0. It is not supported for production — run it against a copy of your data, not your live workspace, and expect it to be superseded without notice. Self-hosters should stay on the latest stable release.

📦 Docker image

This release is published to the GitHub Container Registry:

ghcr.io/emmpaul/the-desk:1.13.0-rc.1

Pull it directly or browse the package page. See the upgrade guide for self-hosting steps.

v1.13.0-rc.0

v1.13.0-rc.0 Pre-release
Pre-release

Choose a tag to compare

@emmpaul emmpaul released this 20 Jul 20:00
27b7661

1.13.0-rc.0 (2026-07-20)

Features

  • set a content-security-policy header on web responses (#650) (51bc293)

Bug Fixes

  • fork worktrees from the remote base branch (#642) (edf1639), closes #639
  • refuse a candidate release below develop's baseline (#638) (87dbcb6)
  • stop background writes from cancelling the visit in flight (#646) (560e39f)

Performance

  • run the local Pest gate in parallel like CI does (#649) (4d4889c)

🚧 Release candidate

This is a release candidate, published for testing ahead of 1.13.0. It is not supported for production — run it against a copy of your data, not your live workspace, and expect it to be superseded without notice. Self-hosters should stay on the latest stable release.

📦 Docker image

This release is published to the GitHub Container Registry:

ghcr.io/emmpaul/the-desk:1.13.0-rc.0

Pull it directly or browse the package page. See the upgrade guide for self-hosting steps.

v1.12.2

Choose a tag to compare

@emmpaul emmpaul released this 20 Jul 12:19
2ef4618

1.12.2 (2026-07-20)

Bug Fixes

  • fork the worktree branch from a remote-only base (#627) (a96002c)

📦 Docker image

This release is published to the GitHub Container Registry:

ghcr.io/emmpaul/the-desk:1.12.2

Pull it directly or browse the package page. See the upgrade guide for self-hosting steps.

v1.12.2-rc.0

v1.12.2-rc.0 Pre-release
Pre-release

Choose a tag to compare

@emmpaul emmpaul released this 20 Jul 11:43
447d17e

1.12.2-rc.0 (2026-07-20)

Bug Fixes

  • fork the worktree branch from a remote-only base (#627) (a96002c)

🚧 Release candidate

This is a release candidate, published for testing ahead of 1.12.2. It is not supported for production — run it against a copy of your data, not your live workspace, and expect it to be superseded without notice. Self-hosters should stay on the latest stable release.

📦 Docker image

This release is published to the GitHub Container Registry:

ghcr.io/emmpaul/the-desk:1.12.2-rc.0

Pull it directly or browse the package page. See the upgrade guide for self-hosting steps.

v1.12.1

Choose a tag to compare

@emmpaul emmpaul released this 20 Jul 11:27
2dbfe2c

1.12.1 (2026-07-20)

Bug Fixes

  • docs: resync the docs lockfile so npm ci succeeds (#621) (6e68bac), closes #614

📦 Docker image

This release is published to the GitHub Container Registry:

ghcr.io/emmpaul/the-desk:1.12.1

Pull it directly or browse the package page. See the upgrade guide for self-hosting steps.

v1.12.0

Choose a tag to compare

@emmpaul emmpaul released this 20 Jul 02:47
7db9fb8

1.12.0 (2026-07-20)

Features

  • cut release-candidate prereleases from develop (#613) (7e12293)

📦 Docker image

This release is published to the GitHub Container Registry:

ghcr.io/emmpaul/the-desk:1.12.0

Pull it directly or browse the package page. See the upgrade guide for self-hosting steps.

v1.12.0-rc.0

v1.12.0-rc.0 Pre-release
Pre-release

Choose a tag to compare

@emmpaul emmpaul released this 20 Jul 02:42
7964a5e

1.12.0-rc.0 (2026-07-20)

Features

  • cut release-candidate prereleases from develop (#613) (7e12293)

🚧 Release candidate

This is a release candidate, published for testing ahead of 1.12.0. It is not supported for production — run it against a copy of your data, not your live workspace, and expect it to be superseded without notice. Self-hosters should stay on the latest stable release.

📦 Docker image

This release is published to the GitHub Container Registry:

ghcr.io/emmpaul/the-desk:1.12.0-rc.0

Pull it directly or browse the package page. See the upgrade guide for self-hosting steps.

v1.11.1

Choose a tag to compare

@emmpaul emmpaul released this 20 Jul 02:24
ef9ed96

1.11.1 (2026-07-20)

Bug Fixes

  • serialise storage-app volume seeding behind the app service (#611) (3cf9816)

Code Refactoring

  • centralise the v-html sanitize allowlist in one module (#602) (652d901)

📦 Docker image

This release is published to the GitHub Container Registry:

ghcr.io/emmpaul/the-desk:1.11.1

Pull it directly or browse the package page. See the upgrade guide for self-hosting steps.