Brings the dependency tree up to the latest in-range versions of every
package: codemirror ^6.43.13, dompurify ^3.4.16, mermaid stays at
^11.17.2 (v12 needs a rendering QA pass before bumping), highlight.js
^11.12.0, jszip ^3.10.2, katex ^0.18.10, prettier ^3.9.9, etc.
Also pins the dev Node version to >=22 LTS via the engines field.
Currently running on Node 22.22.1.
Deliberately deferred (would each need a QA pass):
- Electron 41 -> 44 (3 majors; would need to re-validate every
IPC + BrowserWindow API used in main.js / preload.js / the
standalone windows).
- Mermaid 11 -> 12 (major rendering pipeline change).
- Marked 17 -> 18 (markdown renderer rewrite).
- ESLint 9 -> 10 (flat-config breaking changes).
- pdfjs-dist 5 -> 6 (worker pipeline rework).
- electron-store 10 -> 11 (storage backend swap).
In-range updates verified by the full test suite (1386/1386).
Amit Haridas
The CI release workflow has been failing on every v4.13.0 push with
'package.json and package-lock.json are out of sync', specifically
missing:
- electron-updater@6.8.9
- lodash.escaperegexp@4.1.2
- lodash.isequal@4.5.0
- semver@7.7.4
- tiny-typed-emitter@2.1.0
These were added when electron-updater was wired up (commit 47315ad,
the auto-updater feature) but the lockfile was never regenerated to
match the new top-level dependency. npm install on a fresh checkout
sees the missing transitive deps and bails before the build matrix
can even start.
Fix: run 'npm install' against the current package.json to regenerate
package-lock.json with the correct dep graph. No package.json change
needed — the lockfile was simply stale.
Amit Haridas
Branding:
- All app icons regenerated from the new vector brand kit (M↓ mark):
icon.png/icon@2x (app + packaging), favicon.png, tray-icon.png, and the
full assets/icons/ size set — generate-icons.js now rasterizes
app-icon.svg directly (docico1.png removed)
- index.html gets proper favicon/apple-touch links from the kit
- Welcome tab hero shows the new mark; README gets the horizontal wordmark
- assets/logo.png (ConcreteInfo) intentionally untouched
CI release fixes (win/mac jobs were failing):
- FiraCode download moved from moving raw/master URLs (hash drifted
upstream, tripping the pin) to the immutable 6.2 release asset; repo
fonts updated to the pinned 6.2 bits
- macOS pandoc extractor locates the binary in the archive instead of
assuming a bin/ layout that the macOS zip doesn't have
Stray upload archive (markdown-converter-assets (1).zip) excluded.
Bundle (v4.7.0):
- MarkItDown frozen to a single ~75MB per-platform binary (PyInstaller via
npm run bundle:markitdown; ML extras excluded) — built and verified
locally: HTML/XLSX/PDF conversions pass through the bundled binary, and
the app resolves bin/linux/markitdown first at runtime
- Packaging copies bundled markitdown alongside Pandoc for win/mac/linux;
FFmpeg/sharp/KaTeX/fonts were already bundled
Legal artifacts:
- THIRD-PARTY-NOTICES.md: complete license inventory of everything
distributed (binaries, npm runtime deps, fonts, embedded Python packages)
- SOURCES.md: GPL §3(b) written source offers for Pandoc 3.9.0.2,
ffmpeg-static's GPL build, and the PyInstaller bootloader; LGPL relinking
note for libvips
- third-party-licenses/: canonical GPL-2.0, LGPL-2.1, MPL-2.0, Apache-2.0,
OFL-1.1, PSF-Python texts
- Help > Third-Party Notices & Licenses: in-app viewer for both documents
- README: 'Bundled Dependencies, Legal Notices & Credits' section
Hardening:
- download-tools.js now SHA-256 pins every artifact, verifies after
download AND against the cache on every run, and hard-fails on mismatch
(closes security finding D6)
Large tools intentionally not bundled (documented): LibreOffice,
MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre.
637/637 tests green; lint clean; clean boot; bundled binary verified.
- File → Import with MarkItDown (Any Format)…: PDF, DOCX, PPTX, XLSX,
Outlook .msg/.eml, EPUB, images, CSV/JSON/XML, ZIP (audio/OCR via the
[all] extras) — verified live against HTML, XLSX (our own exporter's
output), and PDF fixtures
- Command auto-resolution with caching: markitdown binary → python -m
markitdown → python3 -m markitdown
- SEC-1 argv discipline (execFile only, user paths never through a shell),
50MB cap, 120s timeout, sanitized errors that surface markitdown's own
"pip install 'markitdown[pdf]'" hints for missing format extras
- Output lands next to the source as <name>.md (numeric suffix, never
overwrites) and opens in a new tab; markitdown:available/convert IPC
allowlisted for renderer flows
- Help → Dependencies lists MarkItDown; README/UPDATES updated (v4.6.1)
12 new tests (629 green); lint clean; clean app boot
- AI Assistant plugin: multi-provider chat (OpenAI/Anthropic/Ollama/LM Studio),
summarize/improve/translate commands, proofread via ai:analyze; calls
proxied through main so API keys stay out of the renderer
- Collaboration plugin: anchor-based comments in .comments/ sidecars with
drift detection and F8 navigation
- Local knowledge base: [[wiki-links]] with click-to-create + Backlinks panel
- Crash recovery: debounced session snapshots with restore prompt on launch
- Version history: pre-save snapshots, History panel with restore/diff/delete
- Real PDF encryption: swap pdf-lib for @cantoo/pdf-lib (probe-driven UI)
- XLSX export (native workbooks via JSZip), ODT headers/footers + page size
- Offline KaTeX (bundled CSS+fonts), local-first PlantUML rendering
- Editor: vim mode toggle, snippet Tab-expansion, zen word-goal setter,
writing heatmap, writing-studio panels wired with rail icons
- Quick Note global scratchpad (Ctrl+Alt+Q), markdownconverter:// deep links,
REPL first-run confirmation
- Fix: Ctrl+Shift+P collision, pandoc converter availability check, CLI
dangling --css/--reference-doc flags, dead converter button
8 new test suites; 613 tests green; lint clean
- Add jszip (^3.10.1) to dependencies; keep version-pinned in overrides
- Move sharp (^0.34.3) from devDependencies to dependencies for Phase B runtime use
- Add node_modules/sharp/** to build.asarUnpack so native bindings are not packed
Amit Haridas
- Normalize pandoc command parsing with path.basename() to support bundled binary paths
- Use bundled pandoc binary in convertWithPandoc instead of relying on PATH
- Forward includeSubfolders checkbox state from renderer to main process
- Add pandoc availability check before batch conversion
- Re-enable Start button when batch conversion completes
- Clean up obsolete dist build artifact causing test snapshot warning
- Bump version to 4.4.4
- Remove package-lock.json from .gitignore so npm ci works in CI
- Refactor main.js: delegate PDF ops to src/main/PDFOperations.js,
git ops to src/main/GitOperations.js
- getPandocPath(): use bundled binary from resources/bin/ when packaged,
fall back to dev bin/ or system pandoc in development
- getFFmpegPath(): use ffmpeg-static (asarUnpack) when packaged
- Install ffmpeg-static (v5.3.0, bundled 76MB binary)
- Add scripts/download-tools.js to fetch pandoc binary at build time
(idempotent, runs on CI before electron-builder)
- electron-builder: add asarUnpack for ffmpeg-static, extraFiles for
pandoc binary per platform (linux + win32)
- release.yml: switch build-windows to windows-latest runner with native
NSIS support; add cert decode step; add download-tools step for both
linux and windows jobs
- Fix lint error: hoist outlinePanelContainer to module scope so
TabManager methods can reference it without no-undef errors
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>