<feed xmlns='http://www.w3.org/2005/Atom'>
<title>skunky-art.git, branch v1.3.6</title>
<subtitle>alternative deviantart frontend, no javascript. go.
</subtitle>
<id>http://git.krz.sh/krz/skunky-art.git/atom?h=v1.3.6</id>
<link rel='self' href='http://git.krz.sh/krz/skunky-art.git/atom?h=v1.3.6'/>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/'/>
<updated>2026-07-15T16:05:15+00:00</updated>
<entry>
<title>Bump docker/metadata-action from 5 to 6 (#8)</title>
<updated>2026-07-15T16:05:15+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-15T16:05:15+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=fe4290fab414d27d7b26ea6302bc0ec5bd3bad6e'/>
<id>urn:sha1:fe4290fab414d27d7b26ea6302bc0ec5bd3bad6e</id>
<content type='text'>
Bumps [docker/metadata-action](https://github.com/docker/metadata-action) from 5 to 6.
- [Release notes](https://github.com/docker/metadata-action/releases)
- [Commits](https://github.com/docker/metadata-action/compare/v5...v6)

---
updated-dependencies:
- dependency-name: docker/metadata-action
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;
Co-authored-by: dependabot[bot] &lt;49699333+dependabot[bot]@users.noreply.github.com&gt;</content>
</entry>
<entry>
<title>Bump docker/login-action from 3 to 4 (#7)</title>
<updated>2026-07-15T16:04:50+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-15T16:04:50+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=d498e15a5993bdbb4870f513b5d3d7b3b05bbf03'/>
<id>urn:sha1:d498e15a5993bdbb4870f513b5d3d7b3b05bbf03</id>
<content type='text'>
Bumps [docker/login-action](https://github.com/docker/login-action) from 3 to 4.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](https://github.com/docker/login-action/compare/v3...v4)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;
Co-authored-by: dependabot[bot] &lt;49699333+dependabot[bot]@users.noreply.github.com&gt;</content>
</entry>
<entry>
<title>Bump actions/checkout from 4 to 7 (#6)</title>
<updated>2026-07-15T16:04:29+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-15T16:04:29+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=268d558e3a79e5b9c0e7696e14ae4bf986ef1517'/>
<id>urn:sha1:268d558e3a79e5b9c0e7696e14ae4bf986ef1517</id>
<content type='text'>
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;
Co-authored-by: dependabot[bot] &lt;49699333+dependabot[bot]@users.noreply.github.com&gt;</content>
</entry>
<entry>
<title>Bump docker/setup-buildx-action from 3 to 4 (#5)</title>
<updated>2026-07-15T16:04:08+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-15T16:04:08+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=0239e959d24ea547646eded3bc0dc6296e2c4321'/>
<id>urn:sha1:0239e959d24ea547646eded3bc0dc6296e2c4321</id>
<content type='text'>
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3 to 4.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/v3...v4)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;
Co-authored-by: dependabot[bot] &lt;49699333+dependabot[bot]@users.noreply.github.com&gt;</content>
</entry>
<entry>
<title>Bump docker/build-push-action from 6 to 7 (#4)</title>
<updated>2026-07-15T16:03:50+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-15T16:03:50+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=e6b784d598b6c0435d1716344902893eae165e81'/>
<id>urn:sha1:e6b784d598b6c0435d1716344902893eae165e81</id>
<content type='text'>
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 6 to 7.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](https://github.com/docker/build-push-action/compare/v6...v7)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;
Co-authored-by: dependabot[bot] &lt;49699333+dependabot[bot]@users.noreply.github.com&gt;</content>
</entry>
<entry>
<title>fix: use commas in the viewport meta content</title>
<updated>2026-07-15T16:00:25+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-15T16:00:25+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=b31b5971d8744bf94ef0d30f2be0e17c08b93988'/>
<id>urn:sha1:b31b5971d8744bf94ef0d30f2be0e17c08b93988</id>
<content type='text'>
The viewport directives were separated with a semicolon, which browsers reject:
"';' is not a valid key-value pair separator". Drop the duplicated trailing
user-scalable directive that the semicolon introduced.
</content>
</entry>
<entry>
<title>fix: serve media again by unsetting download-proxy and scoping Host per request</title>
<updated>2026-07-15T08:17:09+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-15T08:17:09+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=83d9cd0b7a3e0ec6beb5c889102211567a6db03f'/>
<id>urn:sha1:83d9cd0b7a3e0ec6beb5c889102211567a6db03f</id>
<content type='text'>
Two independent faults made every image fail while pages still rendered.

config.example.json shipped download-proxy=http://127.0.0.1:8080. Only media
fetches go through that proxy — pages reach DeviantArt via devianter on the
default transport — so when nothing listens there, images 502 and the rest of
the page looks fine. In a scratch container 127.0.0.1 is the container itself,
so the default could never work under Docker. Unset it and document that it must
stay empty unless an operator really runs a proxy.

Host was a package global reassigned by every request, so a concurrent request
could overwrite it mid-render and emit URLs on another origin's host and port.
The instance's own default-src 'self' CSP then blocked those images. Thread the
request's host through skunkyart instead, and take it as an explicit argument in
URLBuilder, ParseMedia, ParseDescription, BuildUserPlate and
ConvertDeviantArtURLToSkunkyArt. Feeds keep their absolute URLs.

Also start RefreshInstances after ExecuteConfig rather than before it: the
goroutine read CFG while json.Unmarshal was writing it (a race the detector
flags), and its fetch escaped both the throttle and the configured User-Agent.

Verified: 300 concurrent requests with distinct Host headers now round-trip
their own host (was 1 leak per 300), go test -race is clean, and
cache+proxy both enabled serves 200 image/jpeg cold and from cache.
</content>
</entry>
<entry>
<title>ci: publish multi-arch image to GHCR on release tags</title>
<updated>2026-07-15T07:55:52+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-15T07:55:52+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=8d08f343c930f556c6ab016be9d00b23f1e516e3'/>
<id>urn:sha1:8d08f343c930f556c6ab016be9d00b23f1e516e3</id>
<content type='text'>
Build and push linux/amd64 + linux/arm64 images to
ghcr.io/zerolabsco/skunky-art on every v* tag, with a signed provenance
attestation. The Dockerfile cross-compiles from $BUILDPLATFORM, so the
arm64 image builds without QEMU emulation.

Default both compose examples to the published image and keep `build: .`
commented out for building from a checkout, and extend dependabot to the
github-actions and docker ecosystems.
</content>
</entry>
<entry>
<title>docs: correct advertised proxifying flag and instance list link</title>
<updated>2026-07-15T07:49:48+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-15T07:49:48+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=47bfe56e728d046fc8fb78b784efe6926f08ff9e'/>
<id>urn:sha1:47bfe56e728d046fc8fb78b784efe6926f08ff9e</id>
<content type='text'>
The published entry for zerolabs.sh claimed proxifying was off while the
instance runs with proxy enabled, so /about advertised the opposite of
what the instance does. The instance list is fetched from main at runtime,
so this corrects the live about page without a rebuild.

Also point the instances.json link at skunky-art/main, which is what the
app actually fetches, rather than the old SkunkyArt/dev path.
</content>
</entry>
<entry>
<title>build: bump builder image to Go 1.25</title>
<updated>2026-07-15T07:44:24+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-15T07:44:24+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=59359fdda9db92d95aa3a2819e87a61d63f560fd'/>
<id>urn:sha1:59359fdda9db92d95aa3a2819e87a61d63f560fd</id>
<content type='text'>
go.mod requires go 1.25.0, but the Dockerfile still pinned the builder to
1.18, which cannot parse a three-part version string and failed with
"invalid go version '1.25.0': must match format 1.23".

Track the 1.25 tag rather than a patch release so the builder does not
drift out of date again.
</content>
</entry>
</feed>
