Skip to content

v0.2.0 — the security update

Latest

Choose a tag to compare

@github-actions github-actions released this 08 Oct 18:08
· 3 commits to main since this release

v0.2.0 — the security update

The release where "is it secure like Tauri?" got an evidence-based answer, plus the biggest feature requests from launch.

Security, published

  • Threat model — every guarantee linked to the tinyjs release that shipped it, open holes listed, not hidden.
  • Adversarial suite (test/adversarial) — a hostile page attacking our own wraps, verified live against tinyjs v0.50.1. It published tinyjs #36 open, then proved its fix from the outside.
  • Security page on the site — the wrapper posture in user language.

The gate became a GUI

  • Permissions section in the wrap form: wrapper / none / custom chips over the real wire methods, subdomains toggle, camera & mic consent keyhole, live preview of the generated api config.
  • Gate tab in the inspector: per-origin keyholes for any project, one-glance trust summary, warnings for the runtime's sharp edges (absent gate, unknown preset, media consent).

Wrapping

  • Unread badge selector and open-in-browser domains in the form; Reset data wipes an app's cookies/site storage (guarded paths).
  • Import Nativefier app… — pick your archived-Nativefier app, the Studio prefills the wrap (MIGRATING.md).
  • Catalog tab — one-click recipes (Notion, Linear, Figma, Gmail, WhatsApp, Slack, Discord, ChatGPT…), community-contributable via PR.
  • Custom user-agent strings; preact/lit/alpine templates; --origins passed explicitly (deterministic on tinyjs 0.50+).

Measured (same page, same signal — methodology)

TinyJS wrap Electron shell
Disk 8 MB 337 MB
RAM (page live) 49 MB 143 MB

Under the hood

  • Built with tinyjs v0.50.1 (was v0.42.2) — every hardening release since v0.44 ships in these binaries.
  • macOS builds are ad-hoc signed (notarization tracked in the roadmap); unpackaged source runs anywhere tinyjs dev does.

Full changelog: v0.1.1...v0.2.0