- workers: add tiered extraction with lightweight HTTP fetch before browser
- backend: include missing
thumbnailUrlandfaviconUrlin bookmark list responses - auth: harden Better Auth integration — security fixes, fail-fast init, dead code removal
- frontend: fix SSE connection leak on page refresh
- frontend: improve SSE streaming robustness and eliminate unnecessary re-renders
- frontend: fix re-render issues, remove debug logging, and improve data fetching
- frontend: remove hardcoded manifest link from
index.html - frontend: fix typecheck errors in
use-list-page-stateand test files - backend: correct case-sensitive filename in photos test
- backend: add missing type declaration for
turndown-plugin-gfm - workers: harden job processors with size guards, timeouts, SSRF protection, and dedup
- workers: improve document processor extraction quality, fix bugs, reduce resource usage
- workers: fix image processor bugs, improve robustness and format handling
- docker: add missing
tsconfig.base.jsonandapi-typesto build stages - deps: upgrade hono 4.12.5, @hono/node-server 1.19.11, add overrides for rollup/serialize-javascript/minimatch/tar
- vitest: fix broken frontend alias, clean up configs across monorepo
- backend: standardize all list endpoints to unified pagination shape
- backend: deduplicate schema definitions, review/flag/pin/reprocess endpoints, and route handlers
- backend: consolidate error classes, add
withAuth()wrapper, extract error schemas - backend: clean up routes, fix validation, add lazy sessions
- frontend: deduplicate list pages into shared abstractions, extract shared components
- frontend: split API modules, add CRUD hook factory and tests
- api: consolidate API types, fix pagination offset, and clean up schemas
- core: export const arrays for enum types, eliminate cross-package duplication
- ai: fix bugs and clean up for reusability
- queue: remove dead code, deduplicate adapters, fix layering
- logger: typed levels, explicit
contextKey, extensible context - db: harden PostgreSQL client, type
Txinterface, fix schema issues - storage: decouple adapters from domain key structure, clean up design
- workers: harden bookmark processing, extract
BrowserPipeline, improve content quality - monorepo: standardize TypeScript configuration; simplify and deduplicate utilities across all packages
- backend: fix and expand photo, bookmark, document, notes, and task test suites
- frontend: expand test suite with entity hooks, utilities, and API contract tests
- core: add comprehensive test suite for
@eclaire/core - queue: add core unit tests and strengthen integration test coverage
- storage: restructure tests with conformance suite and unit/integration split
- ai: expand MLX adapter and client test coverage
- deps: upgrade patch and minor dependencies across all workspaces
- deps: bump
actions/checkoutfrom 4 to 6,actions/setup-nodefrom 4 to 6 - lint: consolidate linting config with pnpm catalog
- deps: upgrade hono 4.11.4 → 4.12.2 for multiple CVEs (XSS, cache bypass, IP spoofing, timing attack)
- deps: upgrade axios 1.13.2 → 1.13.5 for GHSA-43fc-jf86-j433 (DoS via
__proto__in mergeConfig) - deps: upgrade node-gyp 12.1.0 → 12.2.0 and refresh transitive deps (tar, minimatch, ajv, qs, brace-expansion)
- deps: resolve seroval and diff vulnerabilities via clean reinstall
- frontend: fix XSS vulnerability from unsanitized
dangerouslySetInnerHTMLuncovered during lint audit
- ci: expand lint workflow into full CI with parallel lint, typecheck, build, and test jobs
- ci: add PR lint workflow enforcing Biome and oxlint with zero warnings
- ci: add Dependabot config for npm security alerts and GitHub Actions auto-updates
- frontend: generate route tree before typecheck to fix CI build order
- packages: resolve types from source for workspace packages so typecheck works without a prior build step
- packages: fix 12 strict null check errors across core/encryption, queue, and storage packages
- lint: resolve stale closure risks from missing
useCallbackdependencies in React hooks - lint: fix accessibility errors across frontend components
- lint: adopt Biome and oxlint as dual linters with unified
pnpm lintscript - lint: resolve all Biome and oxlint errors and warnings across the monorepo (~340 files touched)
- lint: replace non-null assertions with runtime guards to satisfy
noNonNullAssertion - lint: use stable keys instead of array indices in React list components
- storage: replace
as unknown ascasts with properNodeWebReadableStreamtypes - backend: use
Number.isFiniteover globalisFinite, fix shadowed variables
- deps: upgrade patch and minor dependencies across all workspaces (biome 2.4.4, bullmq 5.70.1, pg 8.18.0, pino 10.3.1, playwright 1.58.2, react 19.2.4, vite 7.3.1, vitest 4.0.18)
- deps: upgrade better-auth 1.4.19, hono 4.12.2, TanStack Router 1.162.8, tailwindcss 4.2.1, pnpm 10.30.2
- cleanup: remove unused imports, variables, and function parameters across backend and frontend
- cleanup: adopt
node:protocol for all Node.js builtin imports - config: exclude generated service worker files from Biome linting
- config: expand root lint and format scripts to cover entire monorepo
- backend: upgrade hono to 4.11.4 for CVE-2026-22817 (JWT Algorithm Confusion)
- Unified deployment: frontend + backend + workers can run in a single container
- Simplified Self-Hosting - new one-command
setup.shflow, plus a streamlinedcompose.yaml - Better AI Support - New vision models, llama.cpp router, expanded provider support
- Modern Frontend - Migrated from Next.js to Vite + TanStack Router
- New Admin CLI - Manage your instance from the command line
- Unified Deployment: Single container can serve as backend, workers, or both via
SERVICE_ROLEenvironment variable - SQLite Support: Full SQLite database support alongside Postgres with comprehensive parity tests
- Database Queue Mode: Use Postgres or SQLite for job processing instead of Redis/BullMQ
- In-Memory Notifications: Single-process deployments no longer require Redis
- Admin CLI: New
admin-cliintegrated into Docker for instance management - Auto-Upgrade System: Database migrations run automatically at startup
- Qwen3-VL-8B: Added support for Qwen3-VL-8B vision model
- llama.cpp Router: Support for llama-server's new router endpoint
- Request ID Tracing: Better observability and debugging across distributed components
- Version-Prefixed Encryption: Enables future key rotation support
- Frontend: Migrated from Next.js to Vite with TanStack Router for faster builds and modern routing
- ES Modules: Complete migration from CommonJS to ES modules
- Tailwind CSS v4: Upgraded to latest Tailwind with tw-animate-css support
- Transaction Support: Read-Modify-Write for Postgres, mutex serialization for SQLite
- Services Architecture: Thin routes pattern with extracted services layer
- Modular Packages: New @eclaire/ai, @eclaire/storage, @eclaire/queue packages
- AI Tool Calling: More robust native tool calling support
- AI Providers: Improved support for llama.cpp, MLX-LM, MLX-VLM, and LM Studio backends
- Dependency Upgrades: Vite 7, Vitest 4, Playwright 1.57, Pino 10, Recharts 3, Better Auth 1.4.5
- User queue jobs now deleted when account is deleted
- Fixed AI response truncation/repetition detection with improved JSON parsing
- SQLite case-insensitive sorting for text columns
- Docker layer caching optimized for faster builds
- Queue callback race conditions resolved with timeout safety guards
- Route detail views render correctly
- Image URL fallback uses thumbnailUrl consistently
- Auth session tests include Origin header for CSRF validation
- Sharp/native dependency handling with SHARP_IGNORE_GLOBAL_LIBVIPS
- TaskStatus: Removed
cancelledstatus from enum - SERVICE_ROLE: New environment variable for deployment mode configuration
- Data Directories: Changed from
data/dbtodata/postgres,data/pglite,data/sqlite - SQLITE_DB_PATH: Renamed from
SQLITE_DATA_DIR - Environment: Simplified to single
.envfile configuration - Admin CLI:
model-clireplaced withadmin-cli - Build Script:
build.shnow defaults to dev mode (use--prodfor production) - Production Port: Standardized to port 3000
There is no automated upgrade path from v0.5.x to v0.6.0. Due to significant architectural changes, we recommend setting up a fresh v0.6.0 instance and transferring your data from your previous installation.
If you need help migrating, please open an issue or reach out to us - we're happy to assist.
- All dependencies pinned to exact versions for reproducible builds
- Root biome config for consistent formatting/linting
- Restructured tests directory (
__tests__→tests) - TypeScript config standardized (typecheck includes tests, build excludes)
- ioredis pinned to 5.8.2 for BullMQ compatibility
- AI Model Configuration guide with Qwen3-VL-8B examples
- First login instructions added to README
- Clarified WORKER_AI_LOCAL_PROVIDER_URL documentation
- frontend: upgrade Next.js to 15.5.7 for CVE-2025-55182
- build: configure pnpm workspace for Docker deployment with pnpm deploy
- docker: migrate to pnpm deploy for proper dependency resolution in containers
- frontend: invalidate asset list on processing status to show spinner
- dx: add --dev flag to build script and update contributor docs
This release includes significant tooling changes:
-
Node.js Version: Upgraded requirement from v22 to v24 LTS
- Ensure you're running Node.js v24.x
-
Package Manager: Migrated from npm to pnpm
- Enable corepack (one-time setup):
corepack enable - Delete
node_modulesfolders:rm -rf node_modules apps/*/node_modules tools/*/node_modules - Install dependencies:
pnpm install
- Enable corepack (one-time setup):
- deps: migrate to pnpm and update package dependencies
- deps: upgrade Node.js requirement from v22 to v24 LTS
- deps: change Node.js engine from >=24.0.0 to ^24.0.0
- workers: eliminate macOS keychain popup by using non-persistent browser contexts
- workers: add null check for browser context in bookmark processor
- db: correct key length in seed script
- db: complete key length correction in seed script
- docker: use monorepo root as build context for pnpm workspace compatibility
- ci: use repository root as Docker build context in GitHub Actions
- deps: bumped Hono to address security vulnerabilities (GHSA-m732-5p4w-x69g, GHSA-q7jf-gf43-6x6p)
- Upgraded to latest safe version to resolve Improper Authorization vulnerability (CVE-2025-62610)
- Fixed Vary Header Injection leading to potential CORS Bypass
- ai: use json_schema { name, schema } envelope to align with OpenAI structured outputs
- ai: Apple MLX integration with native support for Apple Silicon
- mlx-lm: text inference using MLX
- mlx-vlm: vision model support with multimodal capabilities using MLX
- ai: LM Studio integration for local model inference
- model-cli: enhanced import workflow with provider selection
- Interactive provider selection (MLX-LM, MLX-VLM, LM Studio, Ollama, LlamaCpp, and more)
- Automatic vision capability detection from model metadata
- Smart warnings for incompatible provider/model combinations
- Improved user experience with context-aware prompts
- config: use 127.0.0.1 instead of localhost for service URLs to improve compatibility
- model-cli: display modelFullName instead of name in list command
- readme: added upgrade section with instructions for updating between versions
- docker: bumped default image tags to 0.4
- workflows: explicit semver values for Docker tags
- ci/cd: official GHCR image publishing system with Github Actions
- workflows: overhauled CI/CD workflows and Docker build system
- automation: bootstrap GitHub Actions UI on main branch
- deps: upgraded axios, hono, next.js to resolve security advisories
- deps: bumped axios in tools/models-cli to address security advisory
- deps: migrated to zod v4 and removed zod-openapi integration
- deps: removed unused @hono/zod-validator dependency
- deps: upgraded safe dependencies across frontend, backend, and workers
- readme: added demo video
- readme: added comprehensive Quick Start guide for running official Docker images
- readme: restructured setup options (Quick Start, Development, Building Docker Locally)
- repo: publish core application (backend, frontend, workers) to a public repository
- ui: new logo and refreshed theme with light/dark support
- docs: landing page, high-level architecture overview, updated README with quick start
- tooling: setup scripts for local development and maintenance
- security: signed release tags / verified commits support
- repo: standardized naming and layout for public distribution
- config: aligned package metadata and repository information
- deps: locked dependency versions for reproducible builds
- ui: responsive layout tweaks; hover state fixes; thumbnail edge cases
- processing: improved reliability of background jobs and streaming updates
- content: fixed malformed character extraction in certain inputs
- docs: improved typography and contrast
- ui: dashboard polish; asset list counts and filters; detail view status links
- api: link API docs to GitHub repository
- contrib: contribution guide and issue/PR templates
- security: clarified vulnerability reporting process in
SECURITY.md
- defaults: safer API key handling and configuration defaults
- integrations: disabled non-essential third-party APIs by default
- cleanup: removed legacy share-target functionality
- ui: dashboard redesign; asset list counts and filters; job status links from asset details
- ai: saved AI request/response traces
- pwa: Android support
- processing: fixed pending job execution
- content: resolved malformed character extraction
- workers: reliability improvements; replaced Overmind with PM2
- assets: link related content types
- assistant: create notes; execute tasks with progress tracking
- ui: avatars for users and AI; in-app changelog page; various mobile/PWA improvements
- social: Reddit integration (UI and replies)
- infra: Docker Compose for full deployment
- performance: optimized Redis connection usage; processing streams; search clear button; thumbnail handling
- cli: workers/models/backup CLIs; documentation improvements
- Assorted fixes and stability improvements
- pwa: PWA support and share target
- streaming: SSE for jobs and assistant
- data: React Query integration
- parsing: new text/streaming LLM parser; “thinking” support
- providers: configuration system and build versioning
- conversations: tests; prompt trace replay
- previews: higher-quality document previews
- General fixes and improvements
- Initial internal release