Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
74 commits
Select commit Hold shift + click to select a range
563e820
chore(deps): update dependency @tailwindcss/vite to ~4.3.0 (#458)
renovate[bot] May 9, 2026
c0696db
chore(deps): update dependency @biomejs/biome to v2.4.15 (#414)
renovate[bot] May 10, 2026
62ce24a
chore(deps): lock file maintenance (#459)
renovate[bot] May 11, 2026
92b297c
chore(deps): update cloudflare/wrangler-action action to v4 (#460)
renovate[bot] May 13, 2026
a927b9e
chore(deps): update step-security/harden-runner action to v2.19.2 (#461)
renovate[bot] May 13, 2026
9057d4b
chore(deps): update step-security/harden-runner action to v2.19.3 (#462)
renovate[bot] May 15, 2026
fda0bce
chore(deps): lock file maintenance (#463)
renovate[bot] May 18, 2026
31c4c45
chore(deps): update step-security/harden-runner action to v2.19.4 (#464)
renovate[bot] May 21, 2026
a452a18
chore(deps): lock file maintenance (#466)
renovate[bot] May 25, 2026
e1e5b58
chore(deps): update dependency @biomejs/biome to v2.4.16 (#467)
renovate[bot] May 27, 2026
a186b5c
chore(deps): update docker/login-action action to v4.2.0 (#465)
renovate[bot] May 31, 2026
e7bb50f
chore(deps): update actions/checkout action to v6.0.3 (#468)
renovate[bot] Jun 2, 2026
88a2bc3
chore(deps): update dependency sort-package-json to v4 (#469)
renovate[bot] Jun 4, 2026
91f4cd9
chore(deps): update jdx/mise-action action to v4.1.0 (#470)
renovate[bot] Jun 4, 2026
b54a581
chore(deps): lock file maintenance (#471)
renovate[bot] Jun 8, 2026
65a96ce
chore(deps): lock file maintenance (#473)
renovate[bot] Jun 15, 2026
c5fc943
chore(deps): update jdx/mise-action action to v4.2.0 (#474)
renovate[bot] Jun 17, 2026
70b510c
chore(deps): lock file maintenance (#476)
renovate[bot] Jun 22, 2026
9386bdf
chore(deps): update actions/checkout action to v7 (#475)
renovate[bot] Jun 22, 2026
4e1627b
chore(deps): update actions/attest action to v4.1.1 (#479)
renovate[bot] Jun 26, 2026
594a4d7
fix(deps): update dependency daisyui to ~5.6.0 (#478)
renovate[bot] Jun 28, 2026
590ae54
chore(deps): update dependency vite to ~8.1.0 (#477)
renovate[bot] Jun 28, 2026
3d83923
chore(deps): lock file maintenance (#480)
renovate[bot] Jun 29, 2026
90823d8
fix(deps): update module github.com/andybalholm/brotli to v1.2.2 (#482)
renovate[bot] Jun 29, 2026
a9fe6d0
fix(deps): update module github.com/klauspost/compress to v1.18.7 (#483)
renovate[bot] Jun 30, 2026
8e14ef8
fix(deps): update module github.com/valyala/fasthttp to v1.72.0 (#481)
renovate[bot] Jul 2, 2026
03baac1
fix(deps): update module github.com/klauspost/compress to v1.19.0 (#484)
renovate[bot] Jul 2, 2026
bb0e88d
chore(deps): update docker/login-action action to v4.3.0 (#485)
renovate[bot] Jul 2, 2026
521d7c7
chore(deps): update docker/login-action action to v4.4.0 (#486)
renovate[bot] Jul 4, 2026
c0354e6
chore(deps): lock file maintenance (#487)
renovate[bot] Jul 6, 2026
ce30b0f
chore(deps): lock file maintenance (#491)
renovate[bot] Jul 13, 2026
f068574
chore(deps): update actions/attest action to v4.2.0 (#492)
renovate[bot] Jul 17, 2026
0cdee65
chore(deps): update jdx/mise-action action to v4.2.1 (#493)
renovate[bot] Jul 17, 2026
530ce2b
chore(deps): update actions/checkout action to v7.0.1 (#494)
renovate[bot] Jul 20, 2026
b578d0d
fix(deps): update module github.com/klauspost/compress to v1.19.1 (#495)
renovate[bot] Jul 20, 2026
59ee157
chore(deps): update jdx/mise-action action to v4.2.2 (#498)
renovate[bot] Jul 24, 2026
f558f8d
fix(deps): update module github.com/tdewolff/minify/v2 to v2.24.14 (#…
renovate[bot] Jul 25, 2026
6e30025
chore(deps): update jdx/mise-action action to v4.2.3 (#499)
renovate[bot] Jul 25, 2026
4ed39ca
chore(deps): lock file maintenance (#501)
renovate[bot] Jul 27, 2026
2560f0f
fix(deps): update dependency daisyui to ~5.7.0 (#496)
renovate[bot] Jul 27, 2026
495b3a6
chore(deps): update docker/login-action action to v4.5.1 (#497)
renovate[bot] Jul 27, 2026
46feea9
chore(deps): update docker/login-action action to v4.5.2 (#503)
renovate[bot] Jul 28, 2026
dbcc405
chore(deps): update actions/attest action to v4.2.1 (#506)
renovate[bot] Jul 29, 2026
f2eda8b
chore(deps): update jdx/mise-action action to v4.2.4 (#508)
renovate[bot] Aug 1, 2026
b88d7be
chore(deps): lock file maintenance (#509)
renovate[bot] Aug 3, 2026
533e657
chore(deps): update actions/attest action to v4.2.2 (#510)
renovate[bot] Aug 4, 2026
09a8f50
fix(deps): update module github.com/tdewolff/minify/v2 to v2.24.15 (#…
renovate[bot] Aug 5, 2026
3668c69
fix(deps): update module github.com/tdewolff/minify/v2 to v2.24.16 (#…
renovate[bot] Aug 5, 2026
deafa2e
fix(deps): update module github.com/klauspost/compress to v1.19.2 (#513)
renovate[bot] Aug 6, 2026
8f7fca9
chore(deps): lock file maintenance (#514)
renovate[bot] Aug 10, 2026
d270e12
fix(deps): update module github.com/tdewolff/minify/v2 to v2.24.17 (#…
renovate[bot] Aug 12, 2026
ea8bc60
chore(deps): update jdx/mise-action action to v4.2.5 (#516)
renovate[bot] Aug 13, 2026
cd02b29
chore(deps): update step-security/harden-runner action to v2.21.0 (#488)
renovate[bot] Aug 24, 2026
be21a43
fix(deps): update module github.com/valyala/fasthttp to v1.73.0 (#502)
renovate[bot] Aug 24, 2026
0c7a80c
chore(deps): update docker/login-action action to v4.6.0 (#505)
renovate[bot] Aug 24, 2026
42ddfff
chore(deps): update dependency vite to ~8.2.0 (#507)
renovate[bot] Aug 24, 2026
6a0c376
fix(deps): update dependency @solidjs/router to v1 (#504)
renovate[bot] Aug 24, 2026
d7b96bd
chore(deps): update jdx/mise-action action to v4.3.0 (#518)
renovate[bot] Aug 25, 2026
e5f9350
fix(deps): update module github.com/andybalholm/brotli to v1.2.3 (#519)
renovate[bot] Aug 27, 2026
19cbfd8
chore(deps): lock file maintenance (#521)
renovate[bot] Aug 31, 2026
7dd093c
chore(deps): update step-security/harden-runner action to v2.21.1 (#520)
renovate[bot] Aug 31, 2026
b14aadd
fix(deps): update module github.com/klauspost/compress to v1.20.0 (#522)
renovate[bot] Sep 3, 2026
dc3b1f2
chore(deps): lock file maintenance (#523)
renovate[bot] Sep 7, 2026
ba7edb0
fix(deps): update module github.com/valyala/fasthttp to v1.74.0 (#524)
renovate[bot] Sep 9, 2026
275663b
chore(deps): update dependency vite to ~8.3.0 (#525)
renovate[bot] Sep 10, 2026
cb9839a
fix(deps): update module github.com/andybalholm/brotli to v1.2.4 (#526)
renovate[bot] Sep 10, 2026
f1a7914
chore(deps): lock file maintenance (#527)
renovate[bot] Sep 14, 2026
6462dac
chore(deps): lock file maintenance (#528)
renovate[bot] Sep 21, 2026
190ae33
fix(deps): update module github.com/andybalholm/brotli to v1.2.5 (#530)
renovate[bot] Sep 25, 2026
f747753
fix(deps): update module github.com/klauspost/compress to v1.20.1 (#531)
renovate[bot] Sep 25, 2026
0dff3a4
chore(deps): update cloudflare/wrangler-action action to v4.1.3 (#529)
renovate[bot] Sep 25, 2026
4740b6f
fix(deps): update dependency deepmerge-ts to v8 (#517)
renovate[bot] Sep 25, 2026
f1f7ede
chore(deps): update dependency typescript to v7 (#489)
renovate[bot] Sep 26, 2026
7328ce2
maintenance update (#532)
inetol Sep 26, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
Expand Up @@ -9,3 +9,12 @@ insert_final_newline = true
max_line_length = 120
tab_width = 2
trim_trailing_whitespace = true

[{*.json,*.jsonc}]
insert_final_newline = false

[{*.yaml,*.yml}]
insert_final_newline = false

[*.html]
insert_final_newline = false
8 changes: 2 additions & 6 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -20,13 +20,9 @@
#?
#? You should remove the comment on variable lines only if you want to set the variable.

##########
## SERVER:
##########
## Address to bind the server to. [[::]]:string
#? ("[::]", "[::1]", "127.0.0.1", ...)
## Hostname to bind: [::]:string
#JSPF_BIND_ADDRESS=[::]

## Listen port for the server. [3000]:integer
## Port to bind: [3000]:integer<0-65535>
#? Port 0 selects a random port.
#JSPF_PORT=3000
2 changes: 1 addition & 1 deletion .github/renovate.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["config:recommended", "customManagers:biomeVersions"],
"extends": ["config:recommended"],
"lockFileMaintenance": {
"enabled": true,
"automerge": true
Expand Down
47 changes: 8 additions & 39 deletions .github/workflows/cd.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,17 +42,17 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: "audit"

- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: "false"

- name: Setup mise-en-place
uses: jdx/mise-action@1648a7812b9aeae629881980618f079932869151 # v4.0.1
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0

- name: Save context
id: ctx
Expand Down Expand Up @@ -119,7 +119,7 @@ jobs:

- if: inputs.artifact-action == 'build-release'
name: Attest artifact
uses: actions/attest@59d89421af93a897026c735860bf21b6eb4f7b26 # v4.1.0
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-path: |
dist/*.tar.xz
Expand All @@ -129,23 +129,18 @@ jobs:
if: github.repository_owner == 'jspaste' && inputs.image-action != 'none'
name: Release container image
runs-on: ubuntu-latest
outputs:
tags: "${{ steps.image.outputs.tags }}"
digest: "${{ steps.release.outputs.digest }}"
registries: "${{ steps.release.outputs.registries }}"

permissions:
packages: write

steps:
- name: Harden Runner
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: "audit"

- name: Setup podman
env:
PODMAN_VERSION: "v5.8.2"
PODMAN_VERSION: "v5.8.7"
run: |
sudo apt-get purge -y podman runc crun conmon

Expand All @@ -161,7 +156,7 @@ jobs:
sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0

- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: "false"

Expand All @@ -176,7 +171,7 @@ jobs:
echo "sha_short=${CTX_SHA::7}" >>"$GITHUB_OUTPUT"

- name: Login to GHCR
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: "ghcr.io"
username: "${{ github.repository_owner }}"
Expand All @@ -194,7 +189,6 @@ jobs:

- if: inputs.image-action == 'build-release'
name: Release container image
id: release
env:
GHA_TAG: "${{ steps.image.outputs.tags }}"
GHA_REGISTRY: "ghcr.io docker.io"
Expand All @@ -203,28 +197,3 @@ jobs:
GHA_REGISTRY_ACCOUNT_NAME: "${{ github.repository_owner }} ${{ secrets.DOCKER_USER }}"
GHA_REGISTRY_ACCOUNT_TOKEN: "${{ secrets.GITHUB_TOKEN }} ${{ secrets.DOCKER_TOKEN }}"
run: ./.github/scripts/release-container.sh

container-attest:
if: github.repository_owner == 'jspaste' && inputs.image-action == 'build-release'
name: Attest container image
runs-on: ubuntu-latest
needs: container-release
strategy:
matrix:
registry: ${{ fromJson(needs.container-release.outputs.registries) }}

permissions:
attestations: write
id-token: write

steps:
- name: Harden Runner
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1
with:
egress-policy: "audit"

- name: Attest image
uses: actions/attest@59d89421af93a897026c735860bf21b6eb4f7b26 # v4.1.0
with:
subject-name: "${{ matrix.registry }}/jspaste/frontend"
subject-digest: "${{ needs.container-release.outputs.digest }}"
10 changes: 5 additions & 5 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,17 +25,17 @@ jobs:
sha_short: ${{ steps.ctx.outputs.sha_short }}
steps:
- name: Harden Runner
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: "audit"

- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: "false"

- name: Setup mise-en-place
uses: jdx/mise-action@1648a7812b9aeae629881980618f079932869151 # v4.0.1
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0

- name: Save context information
id: ctx
Expand Down Expand Up @@ -80,7 +80,7 @@ jobs:
needs: test
steps:
- name: Harden Runner
uses: step-security/harden-runner@a5ad31d6a139d249332a2605b85202e8c0b78450 # v2.19.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

Expand All @@ -91,7 +91,7 @@ jobs:
path: "./dist/frontend/"

- name: Deploy preview
uses: cloudflare/wrangler-action@9acf94ace14e7dc412b076f2c5c20b8ce93c79cd # v3.15.0
uses: cloudflare/wrangler-action@953926a2e2182532811c01a25e53647d93bf07c0 # v4.1.3
with:
apiToken: ${{ secrets.CLOUDFLARE_PAGES_TOKEN }}
command: >-
Expand Down
6 changes: 1 addition & 5 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,11 +1,7 @@
*

!/.github/
!/.github/renovate.json
!/.github/scripts/
!/.github/scripts/*.sh
!/.github/workflows/
!/.github/workflows/*.yml
!/.github/**
!/.zed/
!/.zed/settings.json
!/public/
Expand Down
14 changes: 5 additions & 9 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,21 +18,18 @@ The project uses `mise` to manage scripts. To list all available scripts..:
mise run
```

Scripts are grouped, meaning that a script such as `task run build` will run
Scripts are grouped, meaning that a script such as `mise run build` will run
other scripts under its name to fulfil its function, in this case building the
frontend and compiling the server.

This may not be desired in every case, so it is recommended that scripts be run
in a more granular way..:

```shell
# Bad
mise run build:frontend build:server start:server
# Build and start
mise run build:server start:server

# Good, we don't need to compile a binary
mise run build:frontend start:server

# Better, we can run the development server with HMR
# Better, we can run the development server
mise run start:dev
```

Expand All @@ -47,8 +44,7 @@ Building the Frontend is very straightforward..:
mise run build
```

It will prepare a standalone production binary ready to be run in
`dist/server(.exe)`.
It will prepare a standalone production binary ready to be run in `dist/`.

You can also avoid constantly rebuilding the server and build frontend instead
or the other way around..:
Expand Down
52 changes: 19 additions & 33 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Frontend

The web based editor for JSPaste.
Client-side lightweight web editor

## Supported Browsers

Expand All @@ -13,27 +13,27 @@ Please do not open issues with older browsers than those listed:
*Last checked:
[`1bab598`](https://github.com/jspaste/frontend/commit/1bab5981b4ce47c43d64c873a7224fbd79e9aafa) on 5 November 2025*

## Installation
## Setup

### Binaries
### Binary

1. Download the [latest release](https://github.com/jspaste/frontend/releases/latest) and extract it to a new folder
2. Copy `.env.example` to `.env` and configure it
3. Run the binary:
- Download the [latest release](https://github.com/jspaste/frontend/releases/latest) and uncompress it to a new folder
- Edit the `.env.example` file and rename it to `.env`
- Run the binary...

**Linux & macOS:**
Linux & macOS:

```shell
./server
```

**Windows:**
Windows:

```powershell
powershell -c ".\server.exe"
```

### Container images
### Container

We publish images to multiple registries for redundancy:

Expand All @@ -47,39 +47,25 @@ docker pull docker.io/jspaste/frontend:latest
docker run --env-file=.env -d -p [::1]:3000:3000 docker.io/jspaste/frontend:latest
```

## Security
## Validate

> [!IMPORTANT]
> Only binaries and container images built from the official GitHub `JSPaste/Frontend` repository
> are considered secure by the JSPaste developers.
> All artifacts and images originate from GitHub `JSPaste/Frontend` repository, no other artifacts or images built and
> distributed outside that repository are considered secure nor trusted by the JSPaste team.

All attestations can be manually checked at [JSPaste Attestations](https://github.com/jspaste/frontend/attestations).
You can verify the integrity and origin of an artifact using the GitHub CLI or manually at
[JSPaste Attestations](https://github.com/jspaste/frontend/attestations).

### Binaries

With [GH-CLI](https://cli.github.com).
You must verify the tarball, not its content:

```shell
gh attestation verify ./frontend_latest_linux-amd64.tar.xz --owner jspaste
```

### Container images

With [GH-CLI](https://cli.github.com).
Since version
[`2024.05.19-c3f18d0`](https://github.com/jspaste/frontend/pkgs/container/frontend/218171024?tag=2024.05.19-c3f18d0),
container images are also attested:
Artifacts are attested and can be verified using the following command:

```shell
gh attestation verify oci://docker.io/jspaste/frontend:latest --owner jspaste
gh attestation verify ./frontend_latest_linux-amd64.tar.xz --owner JSPaste
```

## Contributing
## Development

See [`CONTRIBUTING`](CONTRIBUTING.md) for more details.
See the [`CONTRIBUTING`](CONTRIBUTING.md) file for more details.

## License

This project is licensed under the European Union Public License (EUPL).
See [`LICENSE`](LICENSE) for more details.
This project is licensed under the EUPL License. See the [`LICENSE`](LICENSE) file for more details.
Loading
Loading