usememos/memos
55.1
Adequate · 6 August 2026
83.8k
lines of production code
Go
with TypeScript
3
measurements over time
What this system is
Memos is a self-hostable, multi-user note-taking and knowledge management system that supports rich markdown editing, media attachments, and AI-powered audio transcription. It provides a flexible backend with support for SQLite, MySQL, and PostgreSQL databases, alongside S3-compatible storage and configurable identity providers. The system features a modern React-based frontend with a redesigned editor, unified sidebar navigation, and comprehensive API surface for managing memos, users, and instance settings.
How it got here
2021–2023 — Multi-database support and frontend modernization
32 changes.
This period focused on modernizing the application's architecture by introducing support for multiple database backends (MySQL, PostgreSQL, and SQLite) and migrating the frontend to a modern React/Vite stack. The work also involved significant refactoring of the editor, authentication flows, and API structures to improve maintainability and user experience.
2024–2025 — API v1 and Editor Refactor
45 changes.
This period focused on establishing the v1 API contract via Protobuf and generating corresponding Go and TypeScript code, while simultaneously refactoring the frontend to use a modular, hook-based architecture for the MemoEditor and MemoView components. The work also introduced significant backend features including AI transcription, S3 presigned URLs, and RSS feeds, alongside database schema modernization and improved caching strategies.
2026 — UI modernization and backend extensibility
27 changes.
This period focused on a comprehensive overhaul of the user interface, introducing new components for memo previews, metadata, and attachments, alongside a redesigned sidebar and grid layouts. Simultaneously, the backend was extended with new capabilities including a Model Context Protocol (MCP) server, a CEL-based filter engine, and support for AI providers and SMTP email notifications.
Features
Add OverflowTip and SquareDiv kit components
The web application now includes two new UI primitives in the kit: OverflowTip, which displays a tooltip for truncated text that overflows its container, and SquareDiv, which dynamically adjusts a div's height to match its width (or vice versa) to maintain a square aspect ratio. These components provide reusable building blocks for handling text overflow states and responsive square layouts.
web/src/components/kit · high confidence
Add PostgreSQL database driver and store implementation
Introduces the PostgreSQL implementation for the application's data store, providing full CRUD operations for core entities including memos, attachments, user accounts, identity providers, and inbox notifications. This change enables the application to persist data in a PostgreSQL database, offering an alternative to the existing SQLite backend.
store/db/postgres · high confidence
Add SMTP email notification support
Users can now receive inbox notifications via email. The system sends email alerts for memo comments and mentions, using configurable SMTP settings (host, port, credentials, TLS/SSL) to deliver messages to users' email addresses.
server/notification · high confidence
Add SMTP email sending capability for self-hosted instances
Self-hosted Memos administrators can now configure and send emails via SMTP. This change introduces an internal email package that supports sending messages through standard SMTP servers (including Gmail, SendGrid, AWS SES, and generic SMTP providers) with TLS/STARTTLS or SSL/TLS encryption. The implementation includes configuration validation, message formatting, and both synchronous and asynchronous sending methods, enabling features like password resets and notifications to be delivered via email.
internal/email · high confidence
Add animated bird sprite placeholders
The Placeholder component now renders animated pixel-art bird sprites (Owl, Eagle, Toucan) for empty, loading, no-results, and not-found states. The new TileSpriteStrip component handles the CSS-driven horizontal scrolling animation of the SVG tilemaps, respecting the user's reduced-motion preference. Each bird has a unique idle animation with breathing, blinking, or head-turning movements.
web/src/components/Placeholder · high confidence
Add configurable log level and version subcommand
Users can now control the application's logging verbosity using the new \--log-level\ flag (accepting \debug\, \info\, \warn\, or \error\), which replaces the previous default logging behavior. Additionally, a \version\ subcommand has been added to the CLI, allowing users to print the current Memos version directly from the command line.
cmd · high confidence
Add internal scheduler package for cron-based job scheduling
The internal/scheduler package has been added to provide a production-ready, GitHub Actions-inspired cron job scheduler for Go. It supports standard 5-field and 6-field (with seconds) cron expressions, timezone-aware scheduling, and a middleware pattern for cross-cutting concerns like logging, metrics, panic recovery, and timeouts. The package includes comprehensive tests covering job registration, scheduling, middleware chaining, and graceful shutdown.
internal/scheduler · high confidence
Add internal utility functions for string, email, and random string generation
A new internal utility package has been added, providing shared helper functions for the application. This includes string conversion and prefix checking, email validation using the standard library's mail parser, UUID generation, and a cryptographically secure random string generator. Tests have been added to verify the email validation logic.
internal/util · high confidence
Add support for Gemini and Anthropic AI providers with dedicated STT and multimodal audio capabilities
Users can now configure and use Google's Gemini and Anthropic as AI providers. The update introduces a dedicated speech-to-text (STT) interface for providers like OpenAI, allowing explicit configuration of provider, model, and transcription prompts. For providers that support multimodal audio understanding (like Gemini), the system can now process audio inputs directly via the \audiollm\ interface. Additionally, the \internal/ai\ package now includes a pure-Go WebM/Opus to WAV converter, enabling browser-recorded audio to be transcribed by providers that require specific audio formats.
internal/ai · high confidence
Add thread-safe in-memory cache with TTL and eviction
A new in-memory cache implementation has been added to the store/cache package. It provides a thread-safe, configurable cache supporting time-to-live (TTL) expiration, maximum item limits with eviction, and optional eviction callbacks. The cache is designed to be used as a concurrent-safe component, with tests verifying basic operations, concurrency safety, and eviction behavior.
store/cache · high confidence
Add user profile memo map component
A new UserMemoMap component has been introduced to display a map of a user's memos that include location data. The component fetches and clusters memos by their geographic coordinates, rendering them on an interactive map with popups showing memo content, creation date, and a link to the memo. It also handles empty states and displays a count of mapped memos.
web/src/components/UserMemoMap · high confidence
Added PWA manifest for improved mobile and desktop app-like experience
A new site.webmanifest file has been added to the public directory, configuring the Progressive Web App (PWA) settings for the Memos application. This includes defining the application name, description, and specific icon assets (192x192 and 512x512 PNGs) to support standalone display modes and theme colors, enhancing the user experience on mobile devices and enabling app-like behavior in supported browsers.
web/public · high confidence
Added memo payload rebuild runner
A new batch-processing runner has been added to rebuild the payload of all memos. This process iterates through memos in batches of 100, extracting metadata such as tags and properties from the memo content using the markdown service, and then updates the stored payload for each memo.
server/runner/memopayload · high confidence
Centralized API access control and new media/AI capabilities
The API router now enforces a single source of truth for public endpoints, ensuring that authentication and authorization checks are consistently applied across both Connect and gRPC-Gateway interceptors. This change introduces a new \acl\_config.go\ file that explicitly defines which API methods are public versus protected, and which remain accessible on private instances. Additionally, the update adds support for Android Motion Photos and Apple Live Photos in attachments, strips EXIF metadata from uploaded images for privacy, and introduces a new AI transcription service that supports OpenAI and Gemini providers for audio-to-text conversion.
server/router/api/v1 · high confidence
Centralized and expanded React hooks for data fetching, filtering, and state management
The web application's \web/src/hooks\ directory has been restructured and expanded to provide a comprehensive set of React hooks for managing application state and data fetching. Key additions include \useMemoFilters\ and \useMemoSorting\ to handle complex memo filtering and sorting logic, \useFilteredMemoStats\ for aggregated statistics, and \useLiveMemoRefresh\ to enable real-time updates via Server-Sent Events (SSE). The refactoring also introduces dedicated hooks for managing attachments (\useAttachmentLibrary\, \useAttachmentQueries\), user identity providers (\useIdentityProviderQueries\), and instance settings (\useInstanceQueries\). Additionally, utility hooks such as \useAsyncEffect\, \useDebouncedEffect\, \useDelayedFlag\, and \useLocalStorage\ have been added to standardize side effects and state management across the frontend.
web/src/hooks · high confidence
Generated Go code for AI, Attachment, and Auth services
The \proto/gen/api/v1\ directory now contains the generated Go code for the \AIService\, \AttachmentService\, and \AuthService\ gRPC and HTTP handlers. This includes the \Transcribe\ endpoint for audio transcription, methods for managing attachments (Create, List, Get, Update, Delete, BatchDelete), and authentication endpoints (SignIn, SignOut, RefreshToken, GetCurrentUser). These changes expose the underlying protobuf definitions as usable Go interfaces and HTTP routes.
proto/gen/api/v1 · high confidence
Generated store models for attachments, identity providers, inbox, instance settings, memos, and user settings
The codebase now includes generated Go files for several protobuf definitions, introducing new data structures and enums. The attachment model now supports S3 and external storage types, and includes metadata for Apple Live Photos and Android Motion Photos. Identity providers are defined with an OAuth2 type. The inbox model supports memo comment and mention notifications. Instance settings are categorized into basic, general, storage, memo-related, tag, notification, and AI provider settings, with storage types including database, local, and S3. Memo payloads now include properties like title extraction, link/task/code detection, and location data. User settings now support shortcuts, webhooks, refresh tokens, personal access tokens, and per-user tag metadata.
proto/gen/store · high confidence
Introduce ColumnGrid component for multi-column memo layouts
Added a new ColumnGrid component that implements a Google-Keep-style absolute-positioned column layout for rendering items in multiple columns. The component calculates the optimal number of columns based on container width and item height estimates, then assigns items to columns to balance the height of each column. It supports features like a leading tile (e.g., a note composer), priority keys to pin items to specific columns, and maximum column/width constraints. The layout is recalculated on resize and item changes, ensuring stable positioning and state preservation for cards.
web/src/components/ColumnGrid · high confidence
Introduce MemoPreview component for consistent memo previews
A new MemoPreview component has been added to render memo previews with support for attachment thumbnails (images, video, and motion photos) and metadata (creator name, memo ID). The component handles both compact and full preview modes, displaying attachment counts or visual thumbnails, and provides a reusable way to show memo content and attachments in a consistent format across the application.
web/src/components/MemoPreview · high confidence
Introduce Model Context Protocol (MCP) server for in-process API access
The server now exposes an MCP endpoint at \/mcp\ using the Streamable HTTP transport, allowing clients to call a curated set of tools that map to the existing REST API operations. The implementation translates MCP tool calls into in-process HTTP requests against the Echo server, reusing the API's authentication and authorization. The initial toolset includes memo, attachment, shortcut, and a read-only 'whoami' identity tool, with schemas derived from the embedded OpenAPI specification. Origin validation is enforced to prevent DNS-rebinding attacks.
server/router/mcp · high confidence
Introduce PagedMemoList component with infinite scroll and grid layout
A new PagedMemoList component has been added to handle paginated memo feeds. It supports infinite scrolling via the window scroll event and auto-fetching when the page is not scrollable. The component manages a responsive column grid layout, calculating estimated card heights to optimize rendering. It also includes logic to hoist newly created memos to the top of the list.
web/src/components/PagedMemoList · high confidence
Introduce automated S3 presigned URL generation for attachments
A new background runner in the s3presign package now automatically generates and updates presigned URLs for S3 attachments every 12 hours. The process batches attachments, checks if existing presigned URLs are still valid (skipping those less than 4 days old), and updates the database with fresh URLs. A corresponding test confirms that the payload cloning logic correctly preserves motion media metadata.
server/runner/s3presign · high confidence
Introduce centralized authentication and authorization logic
The server/auth package now provides a unified Authenticator struct that handles JWT access tokens, refresh tokens, and Personal Access Tokens (PAT) through a single, consistent interface. This centralizes authentication logic previously scattered across the codebase, ensuring that all API endpoints (gRPC, Connect, and file server) use the same validation rules and context propagation. The change adds new test coverage for token generation, parsing, and edge cases like expired or revoked tokens.
server/auth · high confidence
Introduce new ActivityCalendar components for monthly and yearly views
The ActivityCalendar component has been refactored into a modular structure, introducing new components for rendering monthly and yearly calendar grids. Users can now navigate between years and select specific dates, with the calendar displaying activity counts and intensity levels. The implementation includes a year navigation header, month cards, and individual day cells with tooltips showing memo counts.
web/src/components/ActivityCalendar · high confidence
Introduce new default and paper themes with a unified color system
The application now ships with two distinct visual themes: a new default theme and a new 'paper' theme, both built on a standardized color system using OKLCH color space for better perceptual uniformity and accessibility. The default theme provides a modern, high-contrast dark mode alongside a light mode, while the paper theme offers a warmer, softer aesthetic. All color variables are now defined in \default.css\ and \default-dark.css\, mapping to semantic tokens (e.g., \--primary\, \--destructive\) that automatically adapt to the active theme. A new \color\ mapping in \default.css\ ensures these CSS custom properties are correctly exposed to the Tailwind utility classes, ensuring consistent styling across components. The \paper.css\ file introduces an alternative warm palette for users who prefer a more traditional, paper-like appearance. This change improves readability and visual consistency across the application.
web/src/themes · high confidence
Introduce the MemoDetailSidebar component with outline navigation and share management
The memo detail sidebar has been refactored into a dedicated component that provides an outline navigation section for heading-based jumping, a backlink section that displays related memos, and a share panel that allows users to create, copy, and revoke share links with configurable expiration (never, 1 day, 7 days, or 30 days).
web/src/components/MemoDetailSidebar · high confidence
Introduce v1 API proto definitions for core services
The v1 API is now defined in the \proto/api/v1\ directory, establishing the contract for the public API. This includes service definitions for managing users, memos, attachments, identity providers, and instance settings. The proto files introduce new capabilities such as audio transcription via the \AIService\, support for Live/Motion photos in attachments, and the ability to create share links for private memos. Authentication is handled through the \AuthService\ with support for PKCE and SSO, while user management includes personal access tokens, webhooks with signing secrets, and linked SSO identities. Instance configuration is exposed via \InstanceService\ for settings like storage and notifications, and memo management includes relations, reactions, and comments.
proto/api · high confidence
Introduce version comparison and sorting utilities
The internal version package now provides helper functions to compare and sort semantic versions. Users can check if a version is greater than or equal to, or strictly greater than, a target version, and sort a list of version strings correctly. This supports internal logic that needs to evaluate version constraints or order releases.
internal/version · high confidence
Introduced new TypeScript type definitions for the frontend
The web application now includes a set of new TypeScript type definitions in the \web/src/types\ directory. These additions include a generic \FunctionType\, an \ApiError\ interface with a type guard, and specific types for markdown processing (distinguishing tag and mention nodes), relative time elements, statistics views, and dialog callbacks. These changes provide stronger type safety and better developer experience when working with API errors, markdown rendering, and UI components.
web/src/types · high confidence
Introduces file-based deployment configuration and atomic authentication mutations
The store package now supports loading runtime configuration from JSON files in a designated directory (defaulting to /etc/secrets), allowing identity providers and instance settings to be provisioned via the filesystem. This change introduces a new \AuthenticationConfigMutation\ mechanism that validates and applies authentication configuration changes atomically, ensuring that password authentication cannot be disabled unless an effective identity provider is present. The \LoadDeploymentConfiguration\ and \LoadDeploymentConfigurationDir\ methods handle parsing, validation, and shadowing of stored resources, while \UpsertInstanceGeneralSettingSafely\ and \DeleteIdentityProviderSafely\ enforce these safety constraints during mutations.
store · high confidence
Introduces new utility modules for attachments, markdown parsing, and OAuth security
The web/src/utils directory is reorganized into a set of new, focused utility modules. Attachment handling is consolidated in attachment.ts and media-item.ts, which introduce logic for generating URLs, thumbnails, and motion media (Apple Live Photo, Android Motion Photo) previews. Markdown processing is split into dedicated files: gfm-email.ts and gfm-url.ts handle GFM autolink detection via AST parsing; markdown-link.ts, markdown-manipulation.ts, and markdown-task-actions.ts provide AST-based task and heading extraction; and memo-markdown-extension.ts adds math fence support. Additionally, i18n.ts manages locale detection and persistence, oauth.ts implements PKCE-based OAuth state management, and lazy.ts adds chunk-reload error handling. These changes improve how the frontend handles media, markdown content, and authentication flows.
web/src/utils · high confidence
Memo editor gains audio recording, focus mode, and inline timestamp editing
The MemoEditor now includes a new AudioRecorderPanel that displays a live waveform and allows users to record voice memos, with an option to transcribe the audio if an AI provider is configured. A FocusModeOverlay and exit button provide a distraction-free writing environment, while the new TimestampPopover lets users edit the creation and last-updated dates directly within the editor. Additionally, the EditorContent component now handles file uploads and content updates, and the EditorMetadata component manages attachments, relations, and location display, all supporting the new editor state machine and services migration.
web/src/components/MemoEditor/components · high confidence
MySQL store implementation for user, memo, and identity providers
The MySQL database layer is now fully implemented, providing the concrete data access methods for users, memos, attachments, reactions, inboxes, and identity providers. This includes support for custom timestamps on memos, atomic authentication configuration mutations, and filtering by message type in inboxes. The implementation also includes tests for the user deletion process and authentication error handling.
store/db/mysql · high confidence
New Dockerfile, build, and entrypoint scripts for containerized and local builds
The repository now includes a new Dockerfile in the scripts directory that builds the Go backend and creates a minimal Alpine-based image running as a non-root user. A new entrypoint script handles permission fixes and privilege dropping, with a specific fix to prevent restart loops when the target UID is 0. A build.sh script provides a simple local build path, and a compose.yaml simplifies local development. These changes replace the previous .air.toml configuration and provide a more secure, standardized way to run Memos via Docker or build locally.
scripts · high confidence
New MemoActionMenu component with task list and image sharing actions
The memo action menu has been replaced with a new component that adds quick actions for task lists (check/uncheck all items) and a new dialog for sharing memos as images (preview, download, and native share). The menu now includes a copy submenu (link and content), pin/edit/archive/delete actions, and a confirmation dialog for deletion. The implementation includes hooks for handling these actions and a preview model for the image share dialog.
web/src/components/MemoActionMenu · high confidence
New memo comment and mention notification cards in the inbox
The inbox now displays dedicated UI components for memo comments and mentions. Users can view the sender, timestamp, and relevant content snippets. Unread notifications are highlighted with a gradient bar and background color. Users can archive or delete these notifications directly from the inbox list, with toast confirmations for each action.
web/src/components/Inbox · high confidence
New memo filter engine with standard CEL syntax and time accessors
The \internal/filter\ package introduces a new memo filter engine that parses standard Common Expression Language (CEL) into SQL fragments for SQLite, MySQL, and Postgres. The engine supports a three-phase pipeline (parse, normalize, render) and enables time-based filtering using the \now\ variable and \duration()\ function, which are folded to constants at compile time. It also adds timestamp accessors (e.g., \getFullYear\, \getMonth\) for dynamic date-part filters, and text matching functions (\startsWith\, \endsWith\, \contains\) that render to case-insensitive \LIKE\/\ILIKE\ clauses. The change includes comprehensive unit tests for the engine, parser, and renderer, as well as a maintenance guide for extending the filter schema.
internal/filter · high confidence
New shadcn/ui-based UI component library
The \web/src/components/ui\ directory now provides a unified set of UI primitives (Button, Dialog, Select, Tabs, etc.) built on the \@base-ui/react\ library and styled with the \shadcn/ui\ 'new-york' theme. This introduces a consistent component API using \variant\ and \size\ props instead of raw \className\ overrides, and establishes a single source of truth for styling, z-indexing, and color tokens across the application.
web/src/components/ui · high confidence
New shared utility and configuration modules for the web client
The web/src/lib directory now includes a suite of new utility modules that standardize common functionality across the application. browser.ts provides helpers for URL resolution, color scheme detection, and file handling. calendar-utils.ts adds dayjs-based date formatting and manipulation. color.ts converts RGB values to CSS hex strings. constants.ts defines application-wide defaults like page sizes and loading delays. error.ts introduces a robust error handling and toast notification system. markdownStyles.ts centralizes Tailwind classes for rendering markdown content, headings, tags, and mentions. memo-views.ts handles memo scope resolution and routing logic. query-client.ts configures TanStack Query with optimized retry and caching strategies. resource-names.ts provides helpers for building and parsing resource identifiers. tag.ts implements regex-based tag metadata lookup and validation. utils.ts exports a cn() helper for Tailwind class merging.
web/src/lib · high confidence
RSS feed generation and routing implemented
The server now exposes RSS endpoints at /explore/rss.xml and /u/:username/rss.xml. The new RSS service generates feeds for public memos, excludes comments, and caches results with ETag headers. Tests confirm that comments are excluded from the feed and that private instances disable RSS access.
server/router/rss · high confidence
Rebuilt the MemoEditor with a new CodeMirror-based architecture
The MemoEditor has been rebuilt from the ground up using CodeMirror 6, replacing the previous implementation. This change introduces a modular controller pattern for editor state and actions, implements a new formatting system that supports bold, italic, strikethrough, code, and headings, and adds support for tag and @mention autocompletion and syntax highlighting. The editor now handles list indentation, focus mode styling, and file drag-and-drop natively within the CodeMirror instance, providing a more robust and feature-rich editing experience.
web/src/components/MemoEditor/Editor · high confidence
Redesigned Settings page with new reusable components
The Settings page has been restructured into distinct sections (AI, Access Tokens, Instance, Linked Identity, Member, Memo, and Account) using new shared components like ConfirmDialog, InfoChip, and SettingSection. This refactoring improves consistency, accessibility, and maintainability across the settings interface.
web/src/components/Settings · high confidence
Redesigned authentication and user management interface
The login and sign-up pages have been redesigned with a centered card layout that includes a header with the instance logo and title, a footer with a searchable language picker and theme selector, and an optional 'Explore' link. A new \AuthFooter\ component provides immediate locale and theme switching on the auth screens. Additionally, new dialog components have been introduced for managing user accounts and credentials: \CreateUserDialog\ for creating and editing users (including role and password management), \ChangeMemberPasswordDialog\ for updating passwords, and \CredentialFields\ as a shared form element for username and password inputs.
web/src/components · high confidence
Redesigned memo content rendering with enhanced code blocks and metadata cards
The memo content renderer has been refactored into a modular component system. Code blocks now feature syntax highlighting with theme-aware styling, a copy-to-clipboard button, and support for Mermaid diagrams. Links in memos now display rich metadata cards with titles, descriptions, and images. The renderer also supports LaTeX math rendering, interactive task lists, and embedded iframes from trusted sources. A new context-based system handles mention resolution and markdown rendering state.
web/src/components/MemoContent · high confidence
Redesigned memo editor toolbar with focus mode and formatting controls
The memo editor now features a new toolbar interface that includes a formatting toolbar with heading, mark, and block controls, a visibility selector for setting memo privacy, and an insert menu for adding media, files, links, and location data. Users can toggle focus mode to minimize distractions and access formatting options directly within the editor. The toolbar also supports audio recording and location selection, enhancing the editing experience with additional content insertion options.
web/src/components/MemoEditor/Toolbar · high confidence
Redesigned sidebar with quick-find search and tag navigation
The application sidebar has been completely redesigned to unify navigation and improve usability. A new Quick Find dialog (accessible via Ctrl/Cmd+K) allows users to search across memos and collections. The sidebar now features a dedicated Tags section that supports both flat and tree-view modes for browsing content by tags. Additionally, the sidebar includes a new Views section for managing shortcuts and built-in tasks, alongside improved handling of route-based active states and mobile responsiveness.
web/src/components/AppSidebar · high confidence
SQLite store implementation and custom database functions
The SQLite database driver is now fully implemented, providing the backend storage layer for the application. This includes CRUD operations for all core entities such as memos, attachments, reactions, inboxes, and user identities. The implementation also introduces custom SQLite scalar functions to support Unicode case-insensitive text comparisons and regular expression matching, ensuring that search and filter operations work correctly with non-ASCII characters.
store/db/sqlite · high confidence
Support for @mentions, \#tags, and math in markdown content
The markdown parser now recognizes and extracts @username mentions, \#tags, and inline/block math expressions (using $ delimiters) from user-generated content. This enables the system to identify and index these elements for search, notifications, and display. The changes include new AST node types for each feature, corresponding parsers and renderers, and a service interface to extract these elements from markdown content.
internal/markdown · high confidence
Support for extracting video from Motion Photos
The application now detects and extracts embedded video streams from Motion Photos (such as Apple Live Photos or Samsung Motion Photos). A new internal package, internal/motionphoto, provides logic to identify JPEG files containing Motion Photo metadata and extract the embedded MP4 video data. This enables the system to handle these composite media files by separating the still image from the accompanying video clip.
internal/motionphoto, internal/testutil · high confidence
Support for multiple database backends via a unified driver interface
The application now supports multiple database backends (SQLite, MySQL, and PostgreSQL) through a new \store/db\ module. This change introduces a \NewDBDriver\ function that dynamically selects and initializes the appropriate database driver based on the configured profile, allowing users to choose their preferred database system.
store/db · high confidence
Webhook delivery now supports optional HMAC-SHA256 signing and SSRF protection
Webhooks can now be signed using HMAC-SHA256 to ensure message integrity. The system validates the signing secret, supporting the 'whsec\_' base64 format, and rejects malformed secrets. Additionally, outbound webhook requests are now protected against Server-Side Request Forgery (SSRF) by blocking connections to reserved and private IP addresses.
internal/webhook · high confidence
Removals
Removal of common error handling and utility helpers
The common package no longer provides shared error codes, the generic error handler, or utility functions for generating UUIDs and timestamps. Specifically, the error codes map (NOT\_AUTH, REQUEST\_BODY\_ERROR, DATABASE\_ERROR), the ServerError/ErrorResponse structures, and the ErrorHandler function have been removed, as has the GenUUID and GetNowDateTimeStr utility functions. Users must now implement their own error handling and utility logic or rely on other packages.
common · high confidence
Security
Secure HTTP getter with internal IP blocking
The internal HTTP getter now enforces strict security measures to prevent DNS rebinding and SSRF attacks. It blocks requests to internal IP addresses (loopback, private, link-local, and unspecified) at both the URL validation and network dialing layers. Additionally, it supports extracting metadata from HTML pages, including title, description, and image, with case-insensitive handling of meta tags.
internal/httpgetter · high confidence
Architecture
Refactor MemoEditor into a structured, three-layer component with a single markdown source of truth
The MemoEditor component has been restructured into a three-layer architecture (Presentation, State, Service) with a single source of truth for content: raw markdown stored in the editor's state. This change introduces a new \EditorController\ interface that abstracts the underlying CodeMirror 6 implementation, allowing the rest of the app to interact with the editor without accessing CodeMirror internals directly. The editor now stores content as verbatim markdown, with styling applied via CodeMirror decorations, ensuring that the visual representation and the underlying data remain consistent. This refactoring improves maintainability and testability, as the service layer contains pure functions that are easy to unit test. The \README.md\ file documents this new architecture, providing a clear overview of the component's structure and usage.
web/src/components/MemoEditor · high confidence
Behavioural changes
Add insecure\_skip\_tls\_verify option for S3 storage
The S3 storage client now supports an \insecure\_skip\_tls\_verify\ configuration option. When enabled, the client will accept self-signed TLS certificates for the S3 endpoint, which is useful for internal or non-public S3-compatible services. By default, the client enforces standard TLS certificate validation.
internal/storage · high confidence
Added fallback HTML template for frontend distribution
A new index.html file has been added to the server/router/frontend/dist directory. This template displays a 'No embeddable frontend found' message in the body, serving as a fallback when the frontend build artifacts are missing.
server/router/frontend/dist · high confidence
Centralized editor formatting commands and state
The MemoEditor's formatting logic has been refactored to use a central, backend-agnostic catalog of commands and an active state interface. This change introduces a unified \EDITOR\_COMMANDS\ registry and \ActiveFormatState\ interface, allowing the toolbar and active-state hooks to derive labels, icons, and grouping from a single source of truth. This ensures consistent formatting behavior across the editor's UI components.
web/src/components/MemoEditor/formatting · medium confidence
Centralized editor logic via new custom hooks
The MemoEditor component's internal logic has been reorganized into a set of dedicated React hooks (e.g., useAudioRecorder, useAutoSave, useFileUpload, useLocation, useMemoInit, useMemoSave) to manage specific features like audio recording, auto-saving, file uploads, and memo initialization. This refactoring isolates complex state management and side effects from the main component, improving maintainability and enabling more robust handling of editor states such as focus mode, active formatting, and draft preservation.
web/src/components/MemoEditor/hooks · high confidence
Centralized routing and authentication guards
The router configuration has been refactored to use React Router v6's nested routing model, introducing dedicated guard components (RequireAuthRoute, RequireGuestRoute, LandingRoute) that control access based on authentication and initialization states. This change standardizes how routes are protected, ensuring that unauthenticated users are redirected to the sign-in page while authenticated users are blocked from guest-only routes, and provides a more maintainable structure for future route additions.
web/src/router · high confidence
Centralized state management for UI view and filter settings
The web application now uses dedicated React Contexts to manage user interface preferences and filter states. The \ViewContext\ persists view settings (such as column count, sorting order, compact mode, and link preview) to local storage, while the \MemoFilterContext\ synchronizes memo filters with the browser URL. Additionally, the \AuthContext\ has been expanded to handle session recovery via refresh cookies and immediately publish the authenticated user identity to allow route modules to start data queries before all user settings have loaded.
web/src/contexts · high confidence
Consolidate memo metadata components into a unified module
The memo metadata UI has been refactored into a new \MemoMetadata\ directory, introducing shared \MetadataSection\ and \SectionHeader\ components that standardize the display of attachments, locations, and relations. This change centralizes the structure for metadata sections, providing a consistent header with icon, title, count, and optional tabs, while exporting the full set of attachment, location, and relation components from a single entry point.
web/src/components/MemoMetadata · high confidence
Database schema updates for new features and refactoring
The database schema has been updated to support new capabilities and internal improvements. A new 'reaction' table was added to support emoji reactions on content. The 'memo' table was extended with a 'pinned' column to allow pinning notes, and a 'payload' column was added to store structured data. To support private sharing, a new 'memo\_share' table was introduced to manage share links. User profiles were enhanced with a 'description' column, and user settings were migrated to store tag preferences. Additionally, the schema was refactored by renaming the 'resource' table to 'attachment' and migrating the 'HOST' user role to 'ADMIN'.
store/migration/postgres · high confidence
Extracted MemoView subcomponents for improved maintainability
The MemoView component has been refactored by extracting its internal logic into dedicated subcomponents: MemoBody, MemoHeader, MemoCommentListView, and MemoSnippetLink. This change improves the maintainability and structure of the memo viewing interface by separating concerns for the header, body, comments, and snippet links.
web/src/components/MemoView/components · high confidence
Frontend routing and caching behavior changes
The frontend router has been restructured into a dedicated service that explicitly controls cache headers for different asset types: HTML pages are served with no-cache headers to prevent stale content after redeployments, while static assets receive appropriate caching headers (e.g., immutable for hashed assets, max-age for stable assets). The service also handles /robots.txt and /sitemap.xml routes, ensuring sensitive data is not cached and that public memos are correctly listed in the sitemap. Tests verify these cache header behaviors and route handling.
server/router/frontend · high confidence
Improved tag recognition with updated Unicode data and safer object handling
Tag recognition now uses freshly generated Unicode data (release 17.0.0) to better identify valid tag characters. Additionally, the underlying protobuf library is patched to safely handle the '\_\proto\\_' key in JavaScript objects, preventing prototype pollution issues.
web/patches, web/scripts · medium confidence
Introduce centralized theme type definition
A new \setting.d.ts\ file has been added to define the \Theme\ type, which standardizes the available theme options to 'system', 'default', 'default-dark', and 'paper'. This change provides a strict type definition for theme selection, ensuring that only these four specific theme values are accepted across the application's settings.
web/src/types/modules · high confidence
Introduce dedicated StatisticsView component with month navigation
The StatisticsView component has been refactored to include a new MonthNavigator, allowing users to browse activity statistics by month. The view now renders a calendar header with previous/next month controls and passes the selected month to the underlying calendar component, enabling time-based navigation through statistical data.
web/src/components/StatisticsView · high confidence
Introduce dedicated, lazy-loaded map component with dark mode support
Replaces the generic LeafletMap with a new, dedicated LocationPicker component that is lazy-loaded to reduce initial bundle size. The implementation includes a custom map control for zoom and Google Maps integration, and adds dark mode support by dynamically switching between light and dark CartoDB tile layers based on the user's theme setting.
web/src/components/map · high confidence
Introduce private instance mode and improve default data directory handling
The server now supports a private instance mode, where anonymous access is disabled unless an InstanceURL is configured. Additionally, the default data directory handling has been improved to check for writability in /var/opt/memos on Linux/macOS, falling back to the current directory if not writable, and SQLite database files are now named based on the mode (prod or demo).
internal/profile · high confidence
Introduce user-level settings, notifications, and storage schemas
New protobuf definitions in the store layer establish the data models for user-specific configurations, including personal access tokens, refresh tokens, and shortcut preferences. The changes also introduce schemas for user-level tag metadata (such as background color and content blurring), inbox message payloads for memo comments and mentions, and attachment storage details supporting S3 and motion media types. Additionally, instance-wide settings for AI providers and transcription are defined, alongside webhook configurations with optional signing secrets.
proto/store · high confidence
Memo editor types are consolidated into a shared types directory
The type definitions for the MemoEditor component have been extracted from various locations and organized into a new \web/src/components/MemoEditor/types/\ directory. This refactoring introduces dedicated type files for attachments (\attachment.ts\), component props (\components.ts\), the editor controller interface (\editorController.ts\), and the insert menu (\insertMenu.ts\). This change improves maintainability by centralizing the memo editor's data structures and interfaces.
web/src/components/MemoEditor/types · medium confidence
MemoView hooks extracted for improved maintainability
The MemoView component's logic has been refactored into dedicated React hooks to improve code organization and maintainability. A new hooks directory was created, exporting three new hooks: useImagePreview, which manages the state and actions for the image preview modal; useMemoActions, which handles memo-specific actions like unpinning; and useMemoHandlers, which manages user interactions such as clicking images to open the preview and double-clicking to edit. These changes consolidate related logic into reusable, testable units.
web/src/components/MemoView/hooks · high confidence
Memos 0.30.0 release and project restructuring
Memos has been updated to version 0.30.0, introducing a new CodeMirror-based Markdown editor, a redesigned memo detail sidebar, and configurable multi-column feeds. The release also replaces the MCP server with an OpenAPI-driven tool surface, adds standard Webhooks with HMAC-SHA256 signing, and enforces private-mode access control for instances without an explicit instance URL. Additionally, the project has been restructured: the legacy \main.go\ entry point was removed in favor of a Cobra/Viper CLI setup, and the repository now includes a \.golangci.yaml\ configuration, a \CHANGELOG.md\, and updated documentation files (\AGENTS.md\, \SECURITY.md\) to support the new development workflow.
(repo-wide) · high confidence
Migrate web build tooling to Vite and Biome
The web application's build and development environment has been migrated to Vite, replacing the previous setup. This includes a new \vite.config.mts\ for the build pipeline, a \vitest.config.mts\ for testing, and a \biome.json\ configuration for code formatting and linting. The \index.html\ entry point has been updated to align with the new structure, and a \.gitignore\ file has been added to manage build artifacts and local configurations.
web · high confidence
Migrated API server to Connect-Go
The API server's gRPC/HTTP implementation has been replaced with the Connect-Go framework. This change updates the generated client and server stubs for all services (including AuthService, MemoService, and InstanceService) to use the Connect protocol, which provides a unified way to support HTTP/2, gRPC, and gRPC-Web. For users, this means the API endpoints are now served via the Connect RPC framework, which may affect how clients interact with the API, though the underlying Protobuf schemas remain compatible.
proto/gen/api/v1/apiv1connect · high confidence
Modernizes web app architecture with React Router, i18n, and improved auth state management
The web application has been refactored to use React Router for navigation, i18next for internationalization, and a new auth-state module for token management. This introduces cross-tab token synchronization via BroadcastChannel to prevent race conditions during refresh, while also enabling dynamic application of instance-level custom styles and scripts. The app now initializes authentication and instance profiles in parallel for faster startup, and automatically redirects to the signup page if the instance requires initial setup.
web/src · high confidence
MySQL schema modernization and new features
The MySQL database schema has been updated with several structural changes and new capabilities. Users can now share private memos via unique links, and the system supports linking external identity providers (SSO) to user accounts. The 'resource' table has been renamed to 'attachment' to better reflect its purpose, and the 'activity' table has been removed in favor of a new 'inbox' table for notifications. Additionally, user roles have been migrated from 'HOST' to 'ADMIN', and the 'memo\_organizer' table has been dropped as pinning logic moved to the 'memo' table directly.
store/migration/mysql · high confidence
New HTTP-based fileserver for binary content serving
The application now serves all binary files (attachments, avatars) via a dedicated HTTP fileserver, replacing the previous gRPC-based approach. This change enables native HTTP range requests, which are required for proper video and audio streaming in browsers like Safari. The new fileserver handles authentication (JWT, PAT, and session cookies), permission checks for private content, and generates image thumbnails. It also supports S3 external storage and includes security measures such as XSS prevention for unsafe MIME types. Tests confirm that range requests work correctly and that access controls are properly enforced for attachments and comments.
server/router/fileserver · high confidence
Redesigned attachment library with new UI components
The attachment library has been refactored into a set of new, dedicated React components (e.g., AttachmentMediaGrid, AttachmentFileRows, AttachmentLibraryToolbar) to improve the user interface. This change introduces a more structured layout for viewing, sorting, and managing attachments, including a new empty state display and improved metadata display for files.
web/src/components/AttachmentLibrary · high confidence
Refactor MemoEditor services into modular, testable units
The MemoEditor component's internal logic has been reorganized into distinct, dedicated service modules: cacheService for debounced local storage of drafts and cursor positions; errorService for consistent error message extraction; memoService for handling memo creation, updates, and state mapping; transcriptionService for AI-powered audio transcription; uploadService for managing file and motion media uploads; and validationService to enforce save constraints (e.g., preventing saves during loading, uploading, or recording). This modularization improves maintainability and testability of the memo editor.
web/src/components/MemoEditor/services · high confidence
Refactor markdown rendering with dedicated React components
The memo content renderer now uses a set of dedicated React components (AnchorLink, Blockquote, Heading, HorizontalRule, Image, InlineCode, Link, List, ListItem, and Paragraph) to render Markdown elements. This change improves styling consistency and enables specific behaviors such as in-memo anchor scrolling for footnotes and headings, responsive image handling with height/width support, and improved task list rendering with proper grid layout for checkboxes. The refactoring also supports link preview functionality for single-link paragraphs and ensures proper scoping of anchor links within memo containers.
web/src/components/MemoContent/markdown · high confidence
Refactor memo editor state management with a dedicated store and selector hooks
The memo editor's state management has been refactored into a dedicated store pattern, replacing the previous implementation. This introduces a new \EditorStore\ with a \useEditorSelector\ hook that subscribes to specific slices of the editor state, ensuring that components only re-render when the selected state actually changes. The \EditorProvider\ now manages a stable store instance, and the \actions\ object provides a centralized way to dispatch updates to content, metadata, local files, focus mode, loading states, and recorder status.
web/src/components/MemoEditor/state · medium confidence
Refactor memo reaction list into modular components
The memo reaction list has been reorganized into a new \MemoReactionListView\ directory containing \MemoReactionListView\, \ReactionSelector\, and \ReactionView\ components, along with a \hooks.ts\ file. This change extracts the logic for displaying and selecting reactions into separate, reusable components, improving code structure and maintainability.
web/src/components/MemoReactionListView · high confidence
Refactored MemoView component architecture
The MemoView component has been restructured into a dedicated directory with separated concerns: the main component now manages state for image previews, editor loading, and card width measurement, while a new MemoViewContext provides memo data, user context, and editor controls to child components. This change improves maintainability and code organization within the memo view.
web/src/components/MemoView · high confidence
Refactored attachment rendering into a new Attachment component family
The attachment display logic has been refactored into a new set of components within the MemoMetadata/Attachment directory. This introduces a dedicated AudioAttachmentItem for playback controls, an AttachmentCard for media previews, and an AttachmentListView that renders visual galleries (single, collage, or mosaic layouts) for images, videos, and motion photos. The change also extracts helper utilities for separating attachment types and formatting metadata, consolidating the previous inline rendering logic into reusable, modular components.
web/src/components/MemoMetadata/Attachment · high confidence
Refactored memo location components into a new Location subdirectory
The memo location display and editing logic has been restructured into dedicated components: a new LocationDialog for selecting or editing location data, a LocationDisplayEditor for inline editing, and a LocationDisplayView for read-only display with an interactive map popover. These components are now exported from a new Location folder, consolidating the previous scattered implementation and introducing helper functions for formatting coordinates and display text.
web/src/components/MemoMetadata/Location · high confidence
Refactored memo relation components into a dedicated directory
The memo relation UI has been reorganized into the \web/src/components/MemoMetadata/Relation\ directory, introducing new components for managing and displaying memo relationships. \LinkMemoDialog\ provides a searchable interface for linking memos, while \RelationListView\ and \RelationListEditor\ handle the display and editing of existing relations, utilizing a new \useResolvedRelationMemos\ hook to efficiently fetch and cache memo details. These components are exported via a new \index.ts\ and rely on \relationHelpers.ts\ for logic, consolidating the previous scattered implementation into a cohesive, reusable set of tools for memo metadata.
web/src/components/MemoMetadata/Relation · high confidence
Refined CORS policy to allow token-authenticated cross-origin requests while restricting cookie access to trusted origins
The server now implements a new CORS middleware that reflects the request origin for all requests, enabling token-authenticated clients (e.g., using Access Tokens or PATs) to make cross-origin API calls from any domain. However, the \Access-Control-Allow-Credentials\ header is only set for trusted origins (the same host or the configured \InstanceURL\). This ensures that sensitive cookie-based authentication is restricted to the same site or explicitly trusted domains, preventing cross-site cookie theft while still supporting public API access via tokens.
server · high confidence
Regenerate TypeScript types from updated API v1 proto definitions
The TypeScript type definitions in web/src/types/proto/api/v1/ have been regenerated from the updated API v1 protocol buffer definitions. This update introduces new message types and service definitions for AI transcription, attachment handling (including motion media), authentication, identity providers, instance settings, and memo management, ensuring the client-side code matches the current server API contract.
web/src/types/proto · high confidence
Removed SQLite database schema
The SQLite database schema file (sqlite.sql) has been removed from the project. This file previously defined the structure for the 'users', 'memos', and 'queries' tables, including their columns, primary keys, and foreign key relationships.
resources · high confidence
Removed legacy API routes and authentication middleware
The legacy API implementation files (auth, memo, user, middlewares, and utils) have been removed from the codebase. This eliminates the old cookie-based authentication mechanism and the associated route handlers for sign-up, sign-in, sign-out, and basic user/memo endpoints, indicating a migration to a new API structure.
api · high confidence
Reworked pages and auth flows
The web application's page structure has been significantly reorganized. Key pages such as Home, Explore, MemoDetail, and Settings have been refactored to use a new routing and layout system, with the About page redesigned to display instance branding and build information. Authentication flows have been updated to support PKCE for OAuth, enforce private instance access boundaries, and stabilize SSO option loading. Additionally, the UI has been updated to support dark mode, and various styling tweaks have been applied to the auth, settings, and memo detail pages.
web/src/pages · high confidence
SQLite database schema updated to support new features and clean up legacy structures
The SQLite database schema has been updated to support new features and clean up legacy structures. This includes adding support for user avatars, identity providers (IDP), storage configurations, and user descriptions. The schema also introduces new tables for activities, inbox messages, reactions, webhooks, and memo sharing links, while removing deprecated tables and columns such as the migration history, memo organizer, shortcuts, and old tag structures. Additionally, the schema now supports case-sensitive usernames, memo pinning, and memo payloads, and migrates user roles from 'HOST' to 'ADMIN'.
store/migration/sqlite · high confidence
Standardized Protobuf code generation with Buf
The project has adopted Buf to standardize Protobuf code generation. A new Buf configuration (buf.yaml, buf.gen.yaml, buf.lock) and a README guide are introduced to manage dependencies and generate Go, gRPC, Connect-RPC, and OpenAPI v2 specifications. The generated OpenAPI YAML is now embedded in the Go binary via openapi\_embed.go, ensuring the API documentation is always in sync with the proto definitions.
proto · high confidence
Support automatic OAuth2 client authentication fallback
The OAuth2 identity provider now automatically detects whether the remote server supports Basic authentication for client credentials. It first attempts to send the client secret via the Authorization header; if that fails, it falls back to sending the credentials in the request body. This ensures compatibility with OAuth2 providers that do not support Basic authentication for client credentials.
internal/idp · high confidence
Unify root layout and introduce demo mode banner
The application's root layout has been refactored into a new \RootLayout\ component that manages authentication gating for private instances, ensuring unauthenticated users are redirected to the sign-in page while preserving the intended destination. Additionally, a demo mode banner is now displayed to users when the instance is in demo mode, and the layout wraps the main content area with an \AppSidebarProvider\ and \MemoFilterProvider\ to support global state for navigation and filters.
web/src/layouts · high confidence
Updated demo instance with realistic multi-user content
The demo instance now features a richer, more realistic set of seed data. It includes four distinct user personas (Steven, Johnny, Bob, and Sam) with varied content types including pinned welcome and sponsor memos, public and protected timeline entries, comments, and reactions. This provides a more comprehensive preview of Memos' features—such as markdown rendering, tags, attachments, and visibility levels—before users sign in.
store/seed · medium confidence
Upgrades Markdown parsing and list rendering
The Markdown parser was updated to support Unicode characters in tags, fix tag syntax rendering on the first line, and ignore tags inside links. Additionally, the system now splits mixed task and bullet lists, disables setext header syntax, and preserves node types during parsing.
web/src/utils/remark-plugins · medium confidence
Fixes
Add validation for resource IDs and usernames
The internal/base package introduces new validation logic for resource identifiers and user accounts. A regular expression (UIDMatcher) is added to validate resource IDs, supporting formats such as UUIDs from IDP sub claims. Additionally, the system enforces a 36-character maximum length for usernames, requiring them to be alphanumeric with hyphens allowed internally but not at the start or end. Corresponding unit tests are provided for both validators.
internal/base · high confidence
Test coverage
Add startup smoke tests for the server; Added comprehensive store tests for attachments, memos, and identity providers; Added comprehensive test coverage for the About page, sidebar, auth, and editor components; Added server-side tests for API v1 services.
Dependencies
Upgrade frontend and backend dependencies
The web application's dependencies have been updated, including React 19, Vite 8, TypeScript 7, and Tailwind CSS 4. Backend dependencies have also been upgraded, including Go 1.26.2, gRPC 1.80.0, and AWS SDK v2.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 55.
Lenses
- Code Health 78
- Architecture 52
- Maturity 70
- Readiness 71
- Security 67
- Domain Modelling 100
- Accessibility 47
Changes since last survey
- 300 commits — 203 feature/other, 97 fixes
By area
- web/src — 155 commits
- server/router — 54 commits
- (root) — 30 commits
- .github/workflows — 7 commits
- proto/gen — 7 commits
- internal/ai — 4 commits
- store/db — 4 commits
- store/seed — 4 commits
- store/test — 4 commits
- internal/filter — 3 commits
- web/package.json — 3 commits
- web/tests — 3 commits
- .github/ISSUE_TEMPLATE — 2 commits
- docs/plans — 2 commits
- internal/httpgetter — 2 commits
- internal/scheduler — 2 commits
- cmd/memos — 1 commit
- docs/identity-provider-bootstrap.md — 1 commit
- docs/issues — 1 commit
- internal/base — 1 commit
Notable commits
- fix: chore: fix coderabbit logo for light and dark theme (#5954)
- fix: chore: fix linter
- fix: fix(api): align resource IDs with AIP conventions
- fix: fix(api): appease image size lint
- fix: fix(api): make credentials write-only and restrict sensitive settings to admins
- fix: fix(api): reduce memory pressure in backend paths
- fix: fix(api): restrict user email exposure to self and admins (#5784)
- fix: fix(api): show clean RPC error messages
- fix: fix(api): switch user resource names to usernames (#5779)
- fix: fix(api): tolerate missing related users in memo conversions (#5809)
- fix: fix(api): update UID compatibility
- fix: fix(attachments): link media to source memos
- fix: fix(auth): enforce private instance access boundaries
- fix: fix(auth): harden authorization and username validation (#5890)
- fix: fix(auth): provision SSO users atomically (#6114)
- fix: fix(auth): stabilize SSO option loading
- fix: fix(auth): support OAuth client auth auto-detection
- fix: fix(ci): stamp canary image with semantic version
- fix: fix(cors): open API to any origin for token auth, keep cookies same-origin
- fix: fix(editor): align CodeMirror markdown event handling
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
usememos/memos was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 5192732cee40020f84c1e57dbcc53ea3d9eaa42f — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.