Repository navigation
fix(view): block SSRF in remote images - #1693
Open
kawacukennedy wants to merge 83 commits into
Open
kawacukennedy wants to merge 83 commits into
kawacukennedy wants to merge 83 commits into
Conversation
## What? Adds a v1 release backporting, merge queue behaivor, e.t.c. ## Why? We are ready to start working on v1 of matcha. v0 will still be maintained and supplied security updates, bug fixes, QoL features --------- Signed-off-by: drew <me@andrinoff.com>
## What? Uses [`go-keybind`](https://github.com/floatpane/go-keybind). ## Why? Easier to maintain/expand Signed-off-by: drew <me@andrinoff.com>
## What? Implements a complete test suite for the `encryption.go`. ## Why? The previous implementation had no test coverage for the `encryption.go`. Closes floatpane#886
## What? Deduplicate unread badge counting across `emailsByAcct` and `folderEmails` by tracking seen emails with `AccountID + UID`. Added a regression test for the case where the same unread email exists in both stores. <img width="595" height="652" alt="image" src="https://github.com/user-attachments/assets/8c837fb8-017c-4c7c-aa2c-052f244288b2" /> ## Why? Closes floatpane#1107 `syncUnreadBadge` counted unread emails from both stores independently, but the stores can contain the same fetched messages. This could make the macOS unread badge show roughly double the real unread count. <img width="598" height="647" alt="image" src="https://github.com/user-attachments/assets/f2b1c267-29bc-4d4c-a116-4c91af789722" />
## What? Updates `flake.lock` to the latest revisions of all flake inputs (`nixpkgs`, `flake-utils`, etc.). ## Why? Keeps Nix inputs current so contributors and CI build against fresh `nixpkgs`. Picks up upstream security and toolchain fixes. Generated automatically by the flake-lock update workflow on changes to `go.sum`.
## What? Regenerates `gomod2nix.toml` to reflect the current `go.mod` / `go.sum`. ## Why? Keeps the Nix build in sync with Go module changes. Without this, `nix build` fails when new or upgraded Go deps are missing from `gomod2nix.toml`. Generated automatically by the gomod2nix sync workflow.
## What? This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [charm.land/bubbletea/v2](https://redirect.github.com/charmbracelet/bubbletea) | `v2.0.6` → `v2.0.7` |  |  | --- ### Release Notes <details> <summary>charmbracelet/bubbletea (charm.land/bubbletea/v2)</summary> ### [`v2.0.7`](https://redirect.github.com/charmbracelet/bubbletea/releases/tag/v2.0.7) [Compare Source](https://redirect.github.com/charmbracelet/bubbletea/compare/v2.0.6...v2.0.7) ### A few lil’ stability patches Hi! This is a patch release with a few solid improvements around stability and correctness. - [@​lrstanley](https://redirect.github.com/lrstanley), one of our faves, fixed a race condition around mice in the Cursed Renderer - [@​lawrence3699](https://redirect.github.com/lawrence3699) fixed a panic that could happen when input's not available - We fixed a correctness issue with regard to mouse releases when Kitty Keyboard was active (thanks, [@​mitchellh](https://redirect.github.com/mitchellh)) Thanks for using Bubble Tea, and if you see anything awry please do let us know! —Charm 👋 #### Changelog ##### Fixed - [`c60f0c5`](https://redirect.github.com/charmbracelet/bubbletea/commit/c60f0c53042238305ec13b486326588f12aea0ec): fix: prevent data race with cursedRenderer.onMouse ([#​1691](https://redirect.github.com/charmbracelet/bubbletea/issues/1691)) ([@​lrstanley](https://redirect.github.com/lrstanley)) - [`074596e`](https://redirect.github.com/charmbracelet/bubbletea/commit/074596e14e2f5ca5e3986ee72e7c08f1569c4178): fix: skip input reader restore when input is disabled ([#​1680](https://redirect.github.com/charmbracelet/bubbletea/issues/1680)) ([@​lawrence3699](https://redirect.github.com/lawrence3699)) - [`878d7df`](https://redirect.github.com/charmbracelet/bubbletea/commit/878d7df2f2b02f3ca8db177fa8553834bc35ea7c): fix(deps): bump ultraviolet for kitty keyboard fix ([@​meowgorithm](https://redirect.github.com/meowgorithm)) *** <a href="https://charm.land/"><img alt="The Charm logo" src="https://stuff.charm.sh/charm-banner-next.jpg" width="400"></a> Thoughts? Questions? We love hearing from you. Feel free to reach out on [X](https://x.com/charmcli), [Discord](https://charm.land/discord), [Slack](https://charm.land/slack), [The Fediverse](https://mastodon.social/@​charmcli), [Bluesky](https://bsky.app/profile/charm.land). </details> ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDcuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIwNy40IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What? This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [react](https://react.dev/) ([source](https://redirect.github.com/facebook/react/tree/HEAD/packages/react)) | [`19.2.6` → `19.2.7`](https://renovatebot.com/diffs/npm/react/19.2.6/19.2.7) |  |  | | [react-dom](https://react.dev/) ([source](https://redirect.github.com/facebook/react/tree/HEAD/packages/react-dom)) | [`19.2.6` → `19.2.7`](https://renovatebot.com/diffs/npm/react-dom/19.2.6/19.2.7) |  |  | --- ### Release Notes <details> <summary>facebook/react (react)</summary> ### [`v19.2.7`](https://redirect.github.com/facebook/react/releases/tag/v19.2.7): 19.2.7 (June 1st, 2026) [Compare Source](https://redirect.github.com/facebook/react/compare/v19.2.6...v19.2.7) ##### React Server Components - Fixed missing `FormData` entries in Server Actions which regressed in 19.2.6 ([#​36566](https://redirect.github.com/facebook/react/pull/36566) by [@​unstubbable](https://redirect.github.com/unstubbable)) </details> ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDcuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIwNy40IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What? Regenerates `gomod2nix.toml` to reflect the current `go.mod` / `go.sum`. ## Why? Keeps the Nix build in sync with Go module changes. Without this, `nix build` fails when new or upgraded Go deps are missing from `gomod2nix.toml`. Generated automatically by the gomod2nix sync workflow.
## What? Adds a mention about v1 release in the README (master branch ## Why? So that people know, that, even, if there are no commits on master, we still are developing Signed-off-by: drew <me@andrinoff.com>
Signed-off-by: drew <me@andrinoff.com>
## What? This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [go](https://redirect.github.com/actions/go-versions) | uses-with | patch | `1.26.3` → `1.26.4` | --- ### Release Notes <details> <summary>actions/go-versions (go)</summary> ### [`v1.26.4`](https://redirect.github.com/actions/go-versions/releases/tag/1.26.4-26891772857): 1.26.4 [Compare Source](https://redirect.github.com/actions/go-versions/compare/1.26.3-25533533231...1.26.4-26891772857) Go 1.26.4 </details> ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDkuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS40IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What? This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/checkout](https://redirect.github.com/actions/checkout) ([changelog](https://redirect.github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd..df4cb1c069e1874edd31b4311f1884172cec0e10)) | action | digest | `de0fac2` → `df4cb1c` | ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMDkuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS40IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: Drew Smirnoff <drew@floatpane.com>
Co-authored-by: Drew Smirnoff <drew@floatpane.com>
## What? Gate the `LIST ... RETURN (STATUS (UNSEEN))` request in `FetchFolders` on the server advertising the LIST-STATUS capability (RFC 5819). When the server doesn't support it, send a plain `LIST "" "*"` and populate unread counts with a per-mailbox `STATUS (UNSEEN)` fallback instead. ## Why? Fixes floatpane#1426 Signed-off-by: drew <me@andrinoff.com>
## What? Checks if the composer has contents at the moment of interrupt signal (`ctrl+c`). If so, it saves the draft before quitting ## Why? It is easy to accidentally quit, and it was unforgiving, without saving anything. Especially including that the default quit keybind is the same as "copy" on linux and windows (`ctrl+c`) Signed-off-by: drew <me@andrinoff.com>
…1437) ## What? This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [github.com/floatpane/bubble-overlay](https://redirect.github.com/floatpane/bubble-overlay) | `v0.0.1` → `v0.1.0` |  |  | --- ### Release Notes <details> <summary>floatpane/bubble-overlay (github.com/floatpane/bubble-overlay)</summary> ### [`v0.1.0`](https://redirect.github.com/floatpane/bubble-overlay/releases/tag/v0.1.0) [Compare Source](https://redirect.github.com/floatpane/bubble-overlay/compare/v0.0.1...v0.1.0) <!-- Release notes generated using configuration in .github/release.yml at v0.1.0 --> #### What's Changed ##### Dependencies - chore(deps): github.com/charmbracelet/x/ansi ^ v0.11.7 by [@​floatpanebot](https://redirect.github.com/floatpanebot) in [#​5](https://redirect.github.com/floatpane/bubble-overlay/pull/5) - chore(deps): go ^ 1.26.4 by [@​floatpanebot](https://redirect.github.com/floatpanebot) in [#​11](https://redirect.github.com/floatpane/bubble-overlay/pull/11) #### New Contributors - [@​floatpanebot](https://redirect.github.com/floatpanebot) made their first contribution in [#​5](https://redirect.github.com/floatpane/bubble-overlay/pull/5) **Full Changelog**: <floatpane/bubble-overlay@v0.0.1...v0.1.0> *** **Install:** ```bash go get github.com/floatpane/bubble-overlay@v0.1.0 ``` See the [Go reference](https://pkg.go.dev/github.com/floatpane/bubble-overlay) for full API documentation. </details> ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTEuMCIsInVwZGF0ZWRJblZlciI6IjQzLjIxMS4wIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What? Regenerates `gomod2nix.toml` to reflect the current `go.mod` / `go.sum`. ## Why? Keeps the Nix build in sync with Go module changes. Without this, `nix build` fails when new or upgraded Go deps are missing from `gomod2nix.toml`. Generated automatically by the gomod2nix sync workflow.
## What? Updates `flake.lock` to the latest revisions of all flake inputs (`nixpkgs`, `flake-utils`, etc.). ## Why? Keeps Nix inputs current so contributors and CI build against fresh `nixpkgs`. Picks up upstream security and toolchain fixes. Generated automatically by the flake-lock update workflow on changes to `go.sum`.
## What? Uses `overlay.Center` for the move modal. ## Why? The previous version messed with the inbox contents on both sides. Like in floatpane#1435 Signed-off-by: drew <me@andrinoff.com>
## What? Makes the protocol selection a "combobox" ## Why? Closes floatpane#1230 --------- Signed-off-by: drew <me@andrinoff.com>
## What? Moves the log message for i18n to loglevel `verbose` ## Why? Each time you used to load matcha in secure mode, these messages would appear and possibly block the UI Signed-off-by: drew <me@andrinoff.com>
## What? The code to support JMAP authentication via API tokens was in place, it just wasn't wired up correctly. This fixes that. - JMAP protocol selection ended up getting routed to IMAP code - no way to specify `token` for `account.AuthMethod` - `hasBackendProvider` didn't account for/support `jmap` - modified placeholder when `account.AuthMethod` is `token` to say `API Token` instead of `Password / App Password` - modified tip for `inputAuthMethod` when protocol is `jmap` ## Why? Because I use Fastmail, want to use JMAP, and want to be able to read my email. JMAP authentication with Fastmail via API Tokens wasn't working for multiple reasons. Fastmail is the largest (only?) JMAP supporting email host and they require API Tokens. I have manually confirmed that this authenticates just fine with my Fastmail account via JMAP and the API token.
## What? in `jmap.go` - added a `resolveUID` function - added a `resolveUIDByQuery` function ## Why? Email body fetch always failed with "jmap: no cached ID" (backend/jmap/jmap.go) FetchEmailBody relied on p.idToJMAPID being pre-populated by FetchEmails on the same Provider instance. However, the fetcher layer creates a fresh Provider for every call, so the map is always empty when FetchEmailBody runs. The fix adds a resolveUID method that checks the in-memory cache first (fast path when the daemon reuses the same instance), then falls back to resolveUIDByQuery. The fallback issues an Email/query for the folder, reads the JMAP string IDs directly from QueryResponse.IDs, hashes each one with FNV-32a, and returns the match — also warming the cache as a side effect.
## What? Messages are held for `N` seconds before delivery, with a recall window. ## Why? Saves users from sending mistakes, just like Gmail/Outlook. Closes floatpane#1139
## What? Makes Background daemon optional in the settings ## Why? Temporary fix for floatpane#1448, also a good option to have for users to turn off, if they do not want the daemon on. --------- Signed-off-by: drew <me@andrinoff.com>
## What? Refreshes the feature screenshots in `docs/docs/assets/features/`. ### Screenshots included: - `compose_email.png` - `compose_empty.png` - `drafts.png` - `email_view.png` - `inbox_view.png` - `main_menu.png` - `settings.png` - `theme_settings.png` - `threading_demo.png` ## Why? Keeps documentation visuals aligned with the current TUI. Generated automatically by the Generate Screenshots workflow on the latest release. Co-authored-by: floatpanebot <278062430+floatpanebot@users.noreply.github.com>
## What? Replaces `public/assets/demo.gif` with a freshly recorded VHS run. ## Why? Keeps the demo GIF aligned with the latest release so README and docs reflect current behaviour. Generated automatically by the Update Demo VHS workflow. Co-authored-by: floatpanebot <278062430+floatpanebot@users.noreply.github.com>
## What? Fixes crashes when sending. ## Why? Fixes floatpane#1453 Signed-off-by: drew <me@andrinoff.com>
## What? Improves queue, by making undo non-blocking ## Why? You had to wait for 5 seconds in order to use Matcha again Signed-off-by: drew <me@andrinoff.com>
## What? Improves threaded view, making the first email (latest) accessible ## Why? Previously, you could not access the last email --------- Signed-off-by: drew <me@andrinoff.com>
## What? All Sent mailbox lookups now resolve via `getMailboxByAttr(c, imap.MailboxAttrSent)` with fallback to the hardcoded `getSentMailbox`, matching the existing Trash/Archive pattern. ## Why? Fixes floatpane#1641 Signed-off-by: drew <me@andrinoff.com>
## What? This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [go](https://redirect.github.com/actions/go-versions) | uses-with | patch | `1.26.4` → `1.26.5` | --- ### Release Notes <details> <summary>actions/go-versions (go)</summary> ### [`v1.26.5`](https://redirect.github.com/actions/go-versions/releases/tag/1.26.5-28913679792): 1.26.5 [Compare Source](https://redirect.github.com/actions/go-versions/compare/1.26.4-26891772857...1.26.5-28913679792) Go 1.26.5 </details> ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1NS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What? This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [go](https://go.dev/) ([source](https://redirect.github.com/golang/go)) | golang | patch | `1.26.4` → `1.26.5` | ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1NS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> Co-authored-by: Drew Smirnoff <drew@floatpane.com>
## What? This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [golang.org/x/text](https://pkg.go.dev/golang.org/x/text) | [`v0.38.0` → `v0.40.0`](https://cs.opensource.google/go/x/text/+/refs/tags/v0.38.0...refs/tags/v0.40.0) |  |  | ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTIuNSIsInVwZGF0ZWRJblZlciI6IjQzLjI1Ni4wIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
…1663) ## What? This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [github.com/floatpane/bubble-overlay](https://redirect.github.com/floatpane/bubble-overlay) | `v0.2.0` → `v0.3.0` |  |  | --- ### Release Notes <details> <summary>floatpane/bubble-overlay (github.com/floatpane/bubble-overlay)</summary> ### [`v0.3.0`](https://redirect.github.com/floatpane/bubble-overlay/releases/tag/v0.3.0) [Compare Source](https://redirect.github.com/floatpane/bubble-overlay/compare/v0.2.0...v0.3.0) <!-- Release notes generated using configuration in .github/release.yml at v0.3.0 --> **Full Changelog**: <floatpane/bubble-overlay@v0.2.0...v0.3.0> *** **Install:** ```bash go get github.com/floatpane/bubble-overlay@v0.3.0 ``` See the [Go reference](https://pkg.go.dev/github.com/floatpane/bubble-overlay) for full API documentation. </details> ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1NS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What? This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [golang.org/x/term](https://pkg.go.dev/golang.org/x/term) | [`v0.44.0` → `v0.45.0`](https://cs.opensource.google/go/x/term/+/refs/tags/v0.44.0...refs/tags/v0.45.0) |  |  | ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTYuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI1Ny41IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What? This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [cachix/install-nix-action](https://redirect.github.com/cachix/install-nix-action) ([changelog](https://redirect.github.com/cachix/install-nix-action/compare/8aa03977d8d733052d78f4e008a241fd1dbf36b3..a49548c11d9846ad46ecc0115273879b045f001c)) | action | digest | `8aa0397` → `a49548c` | ## Why? Automated dependency update via Renovate. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTYuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1Ni4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
## What? Adds a Reply-All function (`shift+r`) ## Why? Closes floatpane#1667 --------- Signed-off-by: drew <me@andrinoff.com>
## What? Updates `flake.lock` to the latest revisions of all flake inputs (`nixpkgs`, `flake-utils`, etc.). ## Why? Keeps Nix inputs current so contributors and CI build against fresh `nixpkgs`. Picks up upstream security and toolchain fixes. Generated automatically by the flake-lock update workflow on changes to `go.sum`.
## What? Regenerates `gomod2nix.toml` to reflect the current `go.mod` / `go.sum`. ## Why? Keeps the Nix build in sync with Go module changes. Without this, `nix build` fails when new or upgraded Go deps are missing from `gomod2nix.toml`. Generated automatically by the gomod2nix sync workflow.
## What? Replaces `public/assets/demo.gif` with a freshly recorded VHS run. ## Why? Keeps the demo GIF aligned with the latest release so README and docs reflect current behaviour. Generated automatically by the Update Demo VHS workflow. Co-authored-by: floatpanebot <278062430+floatpanebot@users.noreply.github.com>
## What? Refreshes the feature screenshots in `docs/docs/assets/features/`. ### Screenshots included: - `compose_email.png` - `compose_empty.png` - `drafts.png` - `email_view.png` - `inbox_view.png` - `main_menu.png` - `settings.png` - `theme_settings.png` - `threading_demo.png` ## Why? Keeps documentation visuals aligned with the current TUI. Generated automatically by the Generate Screenshots workflow on the latest release. Co-authored-by: floatpanebot <278062430+floatpanebot@users.noreply.github.com>
…lient A malicious HTML email could embed images pointing at internal services (e.g. http://169.254.169.254/latest/meta-data/ on cloud providers, or http://127.0.0.1:* to reach local applications). Every recipient who views such an email triggers a request to the attacker-controlled URL, enabling server-side request forgery. Add isPrivateHost() DNS resolution check that rejects connections to loopback (127.0.0.0/8), RFC 1918 (10/172.16-31/192.168), link-local (169.254.0.0/16), and IPv6 loopback/link-local addresses. Also limit redirect chains to 5 hops using httpclient.NewWithRedirectCap to prevent SSRF via open-redirect chains, and reuse a single HTTP client across calls instead of creating a new one per image fetch.
kawacukennedy
force-pushed
the
fix/view-html-ssrf
branch
from
July 20, 2026 01:31
f5da9c8 to
907e0a1
Compare
floatpanebot
previously requested changes
Jul 20, 2026
floatpanebot
left a comment
Member
There was a problem hiding this comment.
Hi @kawacukennedy! Please fix the following issues with your PR:
- Title: Is too long (55 characters). The PR title must be strictly under 40 characters.
- Body: Missing the
## What?or## Why?headings required by the PR template.
Member
Benchmark report — no significant changeMetrics worse: 0 · better: 0 (threshold: ±3%). benchstat outputauto-generated by benchmarks.yml |
floatpanebot
dismissed
their stale review
July 20, 2026 01:33
Formatting issues have been resolved. Thank you!
Member
|
This has had no activity for 45 days. It will be closed in 21 days unless updated. Comment or remove the |
Contributor
Author
|
Hi @andrinoff — this PR is still open and all CI checks are green; just keeping it off the stale queue. Happy to rebase/adjust if anything needs updating. Thanks! |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What?
Block remote image fetches to private/internal IP addresses and cap redirect chains to 5 hops. Reuse a single HTTP client per image fetch instead of creating one per call.
Why?
A malicious HTML email could embed images pointing at internal services (e.g. cloud metadata at
169.254.169.254, or127.0.0.1). Viewing such an email triggered an outbound request to the attacker-controlled URL, enabling SSRF.The default HTTP client also followed up to 10 redirects, allowing SSRF via redirect chains.