Releases: ZenNotes/zennotes
Release list
ZenNotes v2.61.0
ZenNotes 2.61.0 makes ZenNotes Cloud say what it is waiting on. A note paused by a sync conflict says so on the note, Cloud's limits name the file and the limit, and a deleted Cloud vault no longer stops syncing in silence. Videos and audio play in the editor, the backup browser reaches every file, and heading links follow in the reading view.
Released from 80c284b8 through PR #887 on October 2, 2026. All installers are verified.
Features
- A note paused by a sync conflict says so on the note. When the same note changes on two devices, a one-row banner across its top reads "Sync is paused for this note. It changed on this device and on another device.", in Edit, Preview and split alike, with a Review button that opens the conflict queue on that note (with Vim on,
Space rdoes the same and the banner names it). A notification with Review appears once for each new conflict, stays quiet while the queue is open, and comes back if a resolved conflict returns. Before, the only sign was "1 file needs review" in the status bar, which zen mode hides. - Videos and audio play in the editor. Attaching or dropping an image, PDF, audio or video file now embeds it (
![[path]]) instead of writing a link, and Edit mode draws a standalone audio or video line as the same player the reading view uses, with Open and</>(edit the line) in its header. - The backup browser reaches every file. Settings → Cloud → Backups → Browse notes now reads "Showing 50 of N notes" with Load more, and its search asks Cloud, matching any part of a path across the whole backup. Before, it listed the first 50 files and searched only those, so a note that sorted later could not be restored on its own.
- Deleting a Cloud vault asks for its name. The dialog reads "Delete “Name” for every device?", says what is lost and what stays on your devices, points to Unlink this device for stopping on one device only, and keeps Delete disabled until the vault's exact name is typed.
Fixes
- Cloud names what stopped a sync. The status bar and Settings say "1 file too large for Cloud", "Cloud storage full" or "Cloud item limit reached" instead of "Sync incomplete", the message names the file ("“clip.mov” is larger than the 10 MB Cloud file-size limit, so it stays on this device."), and the note itself shows "Not synced to Cloud: larger than the 10 MB file-size limit, so it stays on this device." under that file. A 10 GB plan now reads 10 GB rather than 9.3 GB.
- A deleted Cloud vault no longer stops syncing in silence. When a Cloud vault is deleted on another device or on the website, the devices still linked to it used to unlink quietly and show the success color. Now the status bar says "Cloud vault deleted" (or "Cloud vault unavailable" when Cloud refuses it to this account), and Settings → Cloud → This vault explains what happened until you link or create a vault, or dismiss the notice; Review,
Space rand the new Review Cloud Vault palette entry all open it, and the notice survives a restart. Settings also stops offering a vault that is gone. - Settings → Cloud after signing in. Signing in while the page was still loading reported "Cloud account changed while loading credentials."; the newest load now wins and a cancelled one retries. Failures of This vault's actions appear inside This vault instead of at the top of the page, and messages no longer start with an internal class name such as "CloudServiceRequestError:".
- Large files sync in bounded steps. Cloud now hands over large revisions as references fetched in bounded pages, downloads go to a staging file checked for length and SHA-256 before they replace a note or attachment, an interrupted catch-up keeps its place, sync honors Cloud's retry delays across windows, and it stops cleanly on sign-out and quit (#884).
- Heading links follow in the reading view. A Markdown
[text](#heading)had nothing to scroll to because rendered headings carried no id; it now lands on the heading, as do#Heading%20Textand#heading-slug, and a click on a[[#Heading]]link no longer opens the hover card first. - Folder pickers on touch screens open without the keyboard. On a touch screen, Move to… for a note or a folder shows the whole folder list; tap the field to type a path. Prompts with nothing to tap still open with the keyboard.
- Cloud never syncs another device's bookkeeping. A vault that is also open on a phone could carry the phone's
zennotes-cloud-syncfolder, which then synced back and forth on every run; sync now skips it. - The Review Cloud Sync Conflicts palette entry names
Space ronly with Vim on, since the leader does nothing without it.
For contributors
- New optional bridge method
listCloudBackupItemsPage(backupId, { page, search })with the desktop IPC handlercloud-backup-items:page(the vault comes from main-process state; page and a 200-character search are validated there). Hosts without it keep the old single page with local filtering. ZenNotes Cloud's backup items endpoint acceptssearch(ZenNotes/website#57). - The status row carries
data-cloud-sync-phaseanddata-cloud-sync-review, and Settings marks its dialog withdata-settings-target, so the phone shells can style and route without matching Tailwind classes. - The phones already carry this release's app code: core
2.60.4(core-2.60.4-core.hae0e49f9e5397fc2) is in iPhone 1.17.1 and Android 1.1.31, and the self-hosted web clientweb-2.60.4-web.ha0258ecc7b3c0133is in znserver 2.60.1. No new boundary artifacts are built for 2.61.0: the code is the same.
Verification
How to test locally:
- Build and launch with isolated stores:
npm run build --workspace @zennotes/desktop, thenZENNOTES_USER_DATA_PATH=$(mktemp -d) ZENNOTES_CONFIG_DIR=$(mktemp -d) npx electron apps/desktop/out/main/index.js. - Media: drop a short
.mp4into a note. Before:[clip.mp4](…). After:![[…/clip.mp4]]and a player in Edit mode and in Preview. - Heading links: put
[jump](#section-three)at the top of a note and## Section Threefar below, open Preview and click the link. Before: nothing. After: the note scrolls to the heading. - Cloud (needs an account): link a vault on two devices, take one offline, edit the same line on both, reconnect. Before: only the status bar knew. After: the note shows the banner and a notification offers Review, which opens the queue on that note.
- Cloud backups: Settings → Cloud → Backups → Create backup, wait for Ready, Browse notes on a vault with more than 50 files. Before: 50 rows. After: "Showing 50 of N notes", Load more, and search finds files on later pages.
- Cloud delete: Settings → Cloud → Delete Cloud vault. After: the dialog names the vault and keeps Delete disabled until its exact name is typed. Cancel.
Distribution channels
- AUR 2.61.0-1:
96731c2, mirrored inc9e2427f; tarball SHA-256c0d8d21a...aa69b36matches GitHub's digest, the bundled CLI folder check passed, and the AUR package checks passed onmainand the release branch. - Homebrew: tap
1c0b680, mirrored in9a74e705; both DMGs were downloaded and their SHA-256 matches the cask and GitHub's digests;brew styleclean. - Nix:
fcd44f09; hash-generation run 37078241465 and the main rebuild 37078403704 passed.desktopHashis the same tarball digest the AUR pins. nixpkgs PR #569616 carries 2.60.0 -> 2.61.0 as one commit on current master and awaits upstream review. Its source hash is the tag tarball's, which nixpkgs fetches differently from this repo's package, computed withnix store prefetch-file --unpack; the same command reproduces master's current 2.60.0 hash. verify:channels -- 2.61.0passed for Homebrew, AUR, Nix, and all seven website download routes. GitHub latest is v2.61.0. Website PR #59 merged at7beab52; its main tests and deploy passed (run 37081053002), and zennotes.org/releases serves the 2.61.0 entry.- Self-hosted server: znserver 2.60.1, released the same day, embeds the same client code (
web-2.60.4-web.ha0258ecc7b3c0133); Dockeradibhanna/zennotes:2.60.1,2.60andlatest. No server release follows 2.61.0, because the code is identical. - Phones: iPhone 1.17.1 (33) and Android 1.1.31 (34) carry this release's app code as core 2.60.4 and are in store review.
Release validation
- Fresh typechecks passed (no cache); 5,831 unit tests passed, 5 skipped (shared-domain 1,861, app-core 2,945, desktop 1,025).
- The signed local package (
npm run pack) launched isolated with a CDP page in 1.4 seconds, reporting 2.61.0 and bundling CLI 0.6.2;codesign --verify --deep --strictpassed. Vim editor (12 checks), sidebar navigation (12) and editor improvements (19) smoke suites passed. - Release PR #887: all 9 checks passed on
80c284b8. - Release run 37077212178 passed on every platform on the first attempt, with 25 assets.
- All four update manifests and their 13 referenced files passed size and downloaded SHA-512 verification. The app in the arm64 DMG passed notarization (
Notarized Developer ID), staple and strict deep signature checks, reports 2.61.0, and its bundledznreports v0.6.2. - Cloud: the changes we...
web-2.60.4-web.ha0258ecc7b3c0133
Immutable boundary artifacts. Validate consumer pins before publishing this draft.
core-2.60.4-core.hae0e49f9e5397fc2
Immutable boundary artifacts. Validate consumer pins before publishing this draft.
core-2.60.3-core.h44232ae9fc126112
Immutable boundary artifacts. Validate consumer pins before publishing this draft.
ZenNotes v2.60.0
ZenNotes 2.60.0 keeps its command-line tool up to date on its own, makes switching notes fast again in large vaults with lots of links, and bundles CLI 0.6.2 on macOS and Linux.
Released from 15829394 through PR #882 on October 1, 2026. All installers are verified.
Features
- zn updates itself. For a
zninstalled from Settings → CLI, ZenNotes checks the latest CLI release once a day and installs it when it is newer, so CLI fixes no longer wait for a ZenNotes release. Every release carries a manifest signed with the ZenNotes release key; ZenNotes checks the signature and the download's checksum and runs the newznonce before switching to it, so a failed or tampered download never replaces a working CLI, and the previous version stays on disk. Thezna ZenNotes build ships is its floor. Settings → CLI → Updates shows the installed and bundled versions, has Check for updates, and a switch to be told instead of updating automatically; Check for zn Updates… is in the command palette. Homebrew, Go and manual installs keep their own installer. - Open CLI Settings in the command palette now opens the CLI page instead of whichever Settings page was open last.
Fixes
- Switching notes no longer freezes in large vaults. The status bar's backlink count used to check every link in the vault against every note each time you opened a note, which took about five seconds in a 6,577-note vault with 13,672 links. ZenNotes now builds its link index once and looks the count up, so opening a note, or going back to one already in a tab, is immediate. Backlink counts and which note a link opens are exactly as before. Thanks to @yfernandes for the profile and diagnosis (#880).
- CLI 0.6.2 is bundled with the desktop app. It includes 0.6.1's fixes:
zn vault listmarks each entryapp(saved by the desktop app) orterminal(saved by zn), sozn vault remove,zn disconnectandzn usestop being trial and error. Every command starts without waiting five seconds on terminals that never answer a background-color query, help output lines up, and a config file zn cannot read is no longer overwritten with an empty list. 0.6.2 is the first CLI release signed by its own release workflow, the manifest this app updates its managedznfrom. CLI 0.6.1 notes, CLI 0.6.2 notes.
Performance
Click to paint on a vault shaped like the #880 report (6,542 notes, 12,973 links), M-series Mac:
| 2.59.0 | 2.60.0 | |
|---|---|---|
| Switch to another note (median) | 1,077 ms | 77 ms |
| Reopen a note already opened | 1,077 ms | 61 ms |
Wikilink rendering, link clicks, Atlas and the Connections panel's wikilink matching use the same index, so they stop scanning the vault for each link too.
For contributors
npm run perf:desktop-runtimecan seed wikilinks (ZEN_PERF_WIKILINKS_PER_NOTE, default 0, so default runs seed the same vault as before) and now times note switches from click until the note is on screen, with anote switch wall p50budget of 150 ms. The oldnote.open.*sample finishes before React renders the note, which is how #880 passed the benchmark. On the 2.59.0 code the new metric reads 1,513.6 ms; on 2.60.0, 33.7 ms. The search step sends Ctrl+P instead of Meta+P on Linux and Windows.- CLI integration stays at protocol 1; the 0.6.2 pin is that release's signed
terminal-release.json, copied byte for byte after verifying. - Every ZenNotes/tui release now publishes
terminal-release.jsonand an Ed25519 signature (keyzn-release-1, public key in that repo'spackaging/release-signing/), built and verified byscripts/releasemanifestin its release workflow. The manifest uses the same schema asapps/desktop/terminal-release.json, so a desktop release raises its bundled CLI by copying the verified asset. A change to the CLI's integration protocol still needs a desktop release.
Verification
How to test locally:
- Build and launch:
npm run build --workspace @zennotes/desktop, thennpx electron apps/desktop/out/main/index.js. - Open a large vault with many wikilinks (thousands of notes; links to missing notes and
folder/Notelinks made the old cost worst) and click between notes in the sidebar, then click one already open in a tab. Before: a pause of about a second on an M-series Mac, several seconds on slower machines. After: the note appears at once with the same "N backlinks" in the status bar. - Benchmark:
ZEN_PERF_DESKTOP_NOTES=6577 ZEN_PERF_WIKILINKS_PER_NOTE=2 npm run perf:desktop-runtime, then readnote switch wall p50. - CLI: update and open ZenNotes once, check Settings → CLI for 0.6.2, then run
zn --versionandzn vault list. - CLI updates: with
zninstalled from Settings → CLI, open Settings → CLI → Updates and press Check for updates; it reportszn 0.6.2 is the latest release.The full install path (a build that ships 0.6.0 meeting the signed 0.6.1 release) is scripted indocs/releases/v2.60.0/cli-updates/e2e.mjs.
Distribution channels
- AUR 2.60.0-1:
93bddbf, mirrored inbac448ab; tarball SHA-256bd0896eb...e910ccmatches GitHub's digest, the bundled CLI folder check passed, and the package checks passed onmainand the release branch. - Homebrew: tap
0a64194, mirrored in2250b001; both DMG digests match GitHub's,brew styleclean. - Nix:
77ce3667; hash-generation run 36896053113 and the main rebuild 36896433936 passed.desktopHashis the same tarball digest the AUR pins. nixpkgs PR #568334 now carries 2.57.0 -> 2.60.0 as one commit on current master and awaits upstream review. verify:channels -- 2.60.0passed for Homebrew, AUR, Nix, and all seven website download routes. GitHub latest is v2.60.0. Website PR #53 merged at7fda07b4; its main tests and deploy passed, and zennotes.org/releases, /docs, /tui and /tui/docs serve the 2.60.0 content.- Self-hosted server: znserver 2.60.0 embeds the 2.60.0 web client (
web-2.60.0-web.h5a4dd1242cf8c2c0); Dockeradibhanna/zennotes:2.60.0,2.60andlatest(amd64 and arm64). - CLI: ZenNotes CLI 0.6.2, the bundled version, is the first CLI release signed by its own workflow; Homebrew's
znformula points at it.
Release validation
- Fresh typechecks passed (7 tasks, no cache); 5,553 unit tests passed, 5 skipped (shared-domain 1,700, app-core 2,859, desktop 994).
- The signed local package (
npm run pack) launched isolated with a CDP page in 1.4 seconds, reporting 2.60.0 and bundling CLI 0.6.2. Vim editor (12 checks), sidebar navigation (12) and editor improvements smoke suites passed. - PR CI: the first Windows build failed three new CLI manifest parse tests, which built their manifest for the runner's own platform and so hit "ZenNotes does not manage a CLI on this platform" on Windows. A test-only fix (
15829394) made them name a managed platform; all 9 checks then passed on the release commit. - Release run 36888637663: the first Linux x64 job hung for 47 minutes in "Install Linux packaging tools" before building anything, so no Linux x64 file had been uploaded. After macOS, Windows and Linux arm64 finished green, the run was cancelled and only that job re-run; attempt 2 passed in about 10 minutes. No asset was replaced.
- All four update manifests and their 13 referenced files passed size and downloaded SHA-512 verification. The app in the arm64 DMG passed notarization (
Notarized Developer ID), staple and strict deep signature checks, and its bundledznreports v0.6.2. - CLI self-update: a build shipping CLI 0.6.0 updated itself from the live v0.6.1 and v0.6.2 releases with the production key, plus scripted relaunch, automatic-off, tampered-manifest and no-managed-zn scenarios on the dev and packaged builds.
- Mobile core: boundary artifact core-2.60.0-core.hb0d0b54f320a8e3f is adopted in ZenNotes/zennotesios#37 and ZenNotes/zennotesandroid#91.
web-2.60.0-web.h5a4dd1242cf8c2c0
Immutable boundary artifacts. Validate consumer pins before publishing this draft.
core-2.60.0-core.hb0d0b54f320a8e3f
Immutable boundary artifacts. Validate consumer pins before publishing this draft.
ZenNotes v2.59.0
ZenNotes 2.59.0 bundles CLI 0.6.0 on macOS and Linux. Update and open ZenNotes once to upgrade an existing desktop-managed zn; Settings → CLI shows its version and offers Repair if needed.
Released from e59e141b through PR #877 on September 30, 2026. All installers are verified.
Features
- CLI 0.6.0 is bundled with the desktop app. Editable settings, restored splits and sessions, comments, attachments, templates, bulk actions, and richer task controls. Run
zninteractively orzn tuito open the editor.zn serverand:serversmanage native local servers;zn status,zn doctor,zn config, and shell completion help with setup. Full CLI manual.
Fixes
- Yank in one terminal note and paste in another. Registers survive switching notes, opening a target, and closing the source within the same TUI session (CLI #4).
- Copy terminal diagnostics.
:versionopens a persistent, scrollable report with CLI, OS, architecture, and optional server details. Presscoryto copy it (CLI #5). - Cloud conflict actions stay visible. The settings list scrolls while the title and actions stay on screen. This shared fix shipped to phones in core 2.58.1.
For contributors
- Two Windows CI flakes are addressed: delayed asset refreshes cannot outlive the test's store, and undo-history pruning is tested with a small cap instead of hundreds of atomic writes. The production history cap is unchanged.
- CLI integration stays at protocol 1; all four release archives are pinned and checksummed.
Verification
How to test locally:
- Update and open ZenNotes, then check Settings → CLI for version 0.6.0. An existing desktop-managed shortcut upgrades automatically.
- Run
zn --version,zn status, andzn doctor. Runzn tui --workspace-source appto explicitly open the desktop workspace. - Yank text in one note, switch to another, and paste. Run
:version, thencto copy the report.
Distribution channels
- AUR 2.59.0-1:
5e4ae99, mirrored ind6a740df; package checks passed. - Homebrew: tap
cf7869a, mirrored infcf5fb41; both DMG digests verified. - Nix:
bf667f3c; hash-generation build 36751141963 and main rebuild 36751746123 passed. nixpkgs PR #568334 targets 2.59.0 and awaits upstream review; the exact nixpkgs source derivation was not built locally. verify:channels -- 2.59.0passed for AUR, Homebrew, Nix, and all seven website download routes. GitHub latest is v2.59.0. Website PR #49 merged atacde3b0; the release page and CLI guide are live.
Release validation
- All four CLI archives passed checksum and architecture checks; the native probe returned 0.6.0/protocol 1.
- Terminal artifact/launcher tests: 13 passed. Desktop CLI installer/runtime tests: 26 passed, 1 skipped.
- Fresh typechecks passed (7 tasks, no cache); 5,534 unit tests passed, 5 skipped. The desktop production build and signed local package passed.
- All four update manifests and their 13 referenced files passed size and downloaded SHA-512 verification. The downloaded arm64 Mac app passed notarization, staple, strict signature, and isolated CDP launch checks (4.9 seconds), reporting desktop 2.59.0 and CLI 0.6.0.
- All 43 built-app smoke checks passed: Vim editor 12, sidebar navigation 12, editor improvements 19.
- All PR checks passed. Installer build 36749192092 passed on every platform without retries or asset replacements.
- Website: 941 local tests passed. PR CI needed one retry for a Chrome startup timeout; the retry passed without code changes.
ZenNotes v2.58.0
ZenNotes 2.58.0: the bundled zn command works on Linux, the Linux packages install and start where they could not, and Quick Connect saves one server instead of two. On Linux, every package since 2.52.0 (the AUR package, the .deb and the .pacman) installed the bundled command-line tool so that only root could read it, so zn quietly stayed on the old version; upgrading to 2.58.0 switches it to the current one, with nothing to fix by hand (#869, from @diazkev314, who found the cause). The .pacman package installs on an up-to-date Arch again, and the .deb now starts on minimal Ubuntu and Debian systems. Connecting to your own ZenNotes server with Quick Connect saves that server once, without an extra "ZenNotes Server" entry, and a saved server with no token says so when you connect (#870). Settings → Vault stays readable in a narrower window while you are connected to a server (#871). And while an update downloads, the app no longer redraws the whole sidebar and Settings every second.
Released on September 29, 2026 as v2.58.0, at 230844ff. PR #873 fast-forwarded the release branch into main at 17:10 UTC after all checks passed. The branch started at 140cd6a1 (the 2.57.0 Homebrew mirror), carries seven reviewed cycle commits plus the version bump, and was restored after GitHub auto-deleted it. All installers and channels are verified. The three packaging commits follow the tag on v2.58.0 (now at fc87e025) and on main, where the Homebrew mirror is e2b67d56 because main also carries 178fab2b, a phone-only layout fix for the cloud settings dialog that ships in core 2.58.1 for the Android and iPhone apps, not in this desktop release.
🐛 Fixes
-
The bundled
znnow switches to the Go CLI on Linux package installs (#869, from @diazkev314, who found the cause). Every Linux package since 2.52.0 (the tarball the AUR package copies, the.deband the.pacman) installed the bundled CLI's folder so that only root could open it. ZenNotes could not read it as a normal user and quietly keptznon the old Node CLI, while Settings → CLI blamed "an invalid manifest". The folder now ships readable by everyone and under a new name,zn-cli, because Linux package managers keep an existing folder's permissions when they upgrade: the new name is created fresh and the old locked folder is removed. So upgrading to 2.58.0 (from the AUR, a.debor a.pacman) and opening ZenNotes once switchesznto the Go CLI (0.4.1) on its own; thechmodworkaround is no longer needed. If the bundled CLI ever cannot be read, Settings → CLI now says it is a permission problem and names the folder. (3dec2a68,35de243e) -
The
.pacmanpackage installs on current Arch again. It listed an old library,http-parser, that Arch no longer ships, sopacman -Urefused to install it and only-ddgot past. The package now lists what ZenNotes actually needs (gtk3, nss, alsa-lib, mesa, libnotify, libsecret, xdg-utils and desktop-file-utils) and installs with plainpacman -U. The AUR package (zennotes-bin) was never affected. (49890e3b) -
The
.debpackage now starts on minimal Ubuntu and Debian installs. It did not ask for the audio library ZenNotes links (libasound2), and on Ubuntu 22.04 not forlibgbm1either, so on a system without them it installed fine and then refused to start ("error while loading shared libraries: libasound.so.2"). Desktop installs normally already have both. The package now asks for them, and works with both names the audio library goes by (libasound2t64on Ubuntu 24.04+ and Debian 13,libasound2on Ubuntu 22.04 and Debian 12). (134b5d20) -
Quick Connect saves one remote workspace, not two (#870, from @diazkev314, who found the cause). Connecting to a server with Quick Connect saved the workspace you connected to plus an extra "ZenNotes Server" entry for the same address, with no vault and no token, and the vault switcher listed both. The extra entry is no longer created. One you already have can be removed under Settings → Vault → Saved Remote Workspaces and will not come back. Connecting to a saved workspace that has no token, when the server needs one, now says so and points at Edit, instead of asking you to check a token that was never sent. (
14093022) -
Settings → Vault → Location stays readable on a narrower window (#871, from @diazkev314). Connected to a remote vault, the Location row put its four buttons on one line that never wrapped: in a window around 1000 pixels wide or less they covered the "Remote workspace" label and Quick Connect… was cut off at the edge, and the vault path and server address were squeezed out of sight. The buttons now move under the label as a group, and wrap among themselves if the window is narrower still, so the label, path, address and every button stay visible. (
178f0429) -
Downloading an update no longer redraws the sidebar and Settings every second. While an update downloads, the updater reports its progress about once a second. The sidebar and the Settings dialog each redrew in full on every report to move one percentage, which is 77 components per tick with a note open and 83 with Settings open. Now only the pieces that show the progress update: the Settings badge in the sidebar, the update notice, and the Updates card in Settings > About (8 and 6 components). Everything looks and behaves as before. (
9b2dd31f, a follow-up to #868, which is still open.)
🧰 For contributors
-
The updater state is subscribed in leaves only:
SidebarSettingsActioninSidebar.tsx(the footer's Settings row, badge and title) andAppUpdatesCardinSettingsModal.tsx(the About page's Updates card, with its check/download/install handlers and release notes), next to the existingAppUpdateNoticeinApp.tsx.useAppUpdateStatehas no other callers; keep it out of large components, sincedownload-progressbroadcasts about once a second for the whole download. The Settings row takes itssidebarIdxas a prop from Sidebar's pass, so its lone re-renders keep the index Vim navigation uses. -
Measurement harness:
docs/releases/v2.58.0/issue-868/measure.mjs(local) launches a build with both stores isolated, installs a minimal__REACT_DEVTOOLS_GLOBAL_HOOK__that counts components with PerformedWork per commit, broadcastsapp-updater:on-statefrom the main process over--inspect, and runs 12 behavior checks. Numbers inPERFORMANCE.md. The build directory must be namedout:isTrustedRendererUrlonly trusts.../out/renderer/index.html, so a baseline copied toout-before/gets every IPC call blocked. -
Terminal bundle folder (#869): packaged as
resources/zn-cli(named inapps/desktop/build/after-pack.js, read incli-install.ts; the dev pathapps/desktop/build/terminal/<platform>-<arch>is unchanged). Renamed fromterminalbecause dpkg and pacman keep an existing directory's mode on upgrade (pacman: "directory permissions differ ... filesystem: 700 package: 755"), so a mode fix alone never reached installs of 2.52.0 to 2.57.0; the release skill'scheck-linux-tarball.shnow rejects a tarball that still hasresources/terminal/. -
Terminal bundle permissions (#869):
installStageintooling/scripts/terminal-artifact.mjsstages withmkdtemp(always 0700) and renames the stage toresources/terminal; it nowchmods the folder andznto 0755 andLICENSEandmanifest.jsonto 0644 (chmod is not narrowed by umask).prepare()inapps/desktop/src/main/terminal-runtime.tsmapsEACCES/EPERMon the manifest read to a permission message naming the folder, and keeps "invalid" for everything else butENOENT. Tests: "the staged folder is readable by every user, whatever the umask" interminal-artifact.test.mjs(runs under umask 077; the old stager fails it with 0o700), and the permission case interminal-runtime.test.ts(skipped as root, which reads through any mode). Evidence harness:docs/releases/v2.58.0/issue-869/cli-check.mjs(local) opens Settings → CLI over CDP. -
.pacmandependencies:build.pacman.dependsinapps/desktop/package.jsonreplaces electron-builder's default pacman list (c-ares, ffmpeg, gtk3, http-parser, libevent, libvpx, libxslt, libxss, minizip, nss, re2, snappy, libnotify, libappindicator-gtk3). Derived on a bare Arch install withreadelf -d+ldd+pacman -Qo: every library the binary links is owned by gtk3, nss, alsa-lib or what they pull in, plus mesa (libgbm, linked directly); libnotify and libsecret are loaded at runtime (notifications, safeStorage keyring); xdg-utils for external opens; desktop-file-utils for thex-scheme-handler/zennotesentry.build.deb.dependskeeps electron-builder's default deb list and addslibasound2t64 | libasound2(the t64 rename; on 24.04+ plainlibasound2is virtual and also provided by the OSS shimliboss4-salsa-asound2, so the real package is named first) andlibgbm1(linked directly; Ubuntu 22.04 did not pull it in). The rpm list is unchanged: a clean Fedora 44 installs the released.rpmwith nothing missing. -
Remote profiles (#870):
normalizePersistedConfiginapps/desktop/src/main/vault.tsmakes up a "ZenNotes Server" profile fo...
core-2.58.1-core.h87d94b8810f1f1d1
Immutable boundary artifacts. Validate consumer pins before publishing this draft.