<feed xmlns='http://www.w3.org/2005/Atom'>
<title>skunky-art.git/app/cli.go, branch v1.3.3</title>
<subtitle>alternative deviantart frontend, no javascript. go.
</subtitle>
<id>http://git.krz.sh/krz/skunky-art.git/atom?h=v1.3.3</id>
<link rel='self' href='http://git.krz.sh/krz/skunky-art.git/atom?h=v1.3.3'/>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/'/>
<updated>2026-07-15T07:24:58+00:00</updated>
<entry>
<title>fix: harden HTTP transport, server timeouts and panic paths</title>
<updated>2026-07-15T07:24:58+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-15T07:24:58+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=7eb5e5e2230b6fb5b1bed6f0eaa03279aa61555b'/>
<id>urn:sha1:7eb5e5e2230b6fb5b1bed6f0eaa03279aa61555b</id>
<content type='text'>
Correctness and security findings surfaced by golangci-lint, plus two
latent panics found alongside them.

- router: http.ListenAndServe has no timeouts at all (gosec G114), so a
  slow client could hold a connection and its handler open indefinitely.
  Replace it with an explicit http.Server carrying read/write/idle
  timeouts.
- httpclient: InstallDAThrottle asserted http.DefaultTransport was a
  *http.Transport and would panic outright if anything had already
  wrapped it -- which is precisely what that function does. Check the
  assertion and fall back to a fresh transport. Expose ProxiedTransport
  so a configured download-proxy can inherit the same throttle and
  timeouts instead of silently bypassing them.
- cache: the Sys() assertion to *syscall.Stat_t is only valid on unix and
  would panic elsewhere; skip rotation instead. Indexing
  Headers["Content-Type"][0] panics when the header is absent; use
  Headers.Get. Cache files are written 0600 rather than 0700, as they are
  never executed.
- cli, api: check error returns, and exit rather than nil-dereference a
  file handle that failed to open.

SHA-1 and math/rand keep //nolint:gosec with reasons: they are cache-key
hashes and random-artwork picks, not security primitives.
</content>
</entry>
<entry>
<title>fix: point source links and instance fetch at this fork</title>
<updated>2026-07-15T01:28:02+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-15T01:28:02+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=0aff13949a8e9e120a585f00627ef6959f8e0635'/>
<id>urn:sha1:0aff13949a8e9e120a585f00627ef6959f8e0635</id>
<content type='text'>
Upstream references still pointed at git.macaw.me, which is unmaintained
and whose instances.json is a dead link. Repoint them at this repo:

- RefreshInstances now fetches instances.json from raw.githubusercontent
- source/version links in index.htm, about.htm, and CLI help use the
  GitHub releases tag URL
- SETUP.md/SETUP-RU.md language switch links were Gitea-absolute paths
  that 404 on GitHub; make them relative
- --add-instance message says 'main' branch, matching this repo

The fork attribution in README.md is left as-is: it credits upstream
rather than pointing at the source.
</content>
</entry>
<entry>
<title>Add da.opnxng.com + lost-skunk.cc is now in Finland</title>
<updated>2025-04-07T10:53:47+00:00</updated>
<author>
<name>lost+skunk</name>
<email>me@lost-skunk.cc</email>
</author>
<published>2025-04-07T10:53:47+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=210c69e48c2af4d1fdb53c0654ed33a21688696c'/>
<id>urn:sha1:210c69e48c2af4d1fdb53c0654ed33a21688696c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Два API-эндпоинта</title>
<updated>2024-09-03T12:36:19+00:00</updated>
<author>
<name>lost+skunk</name>
<email>skunky@ebloid.ru</email>
</author>
<published>2024-09-03T12:36:19+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=db53a8bd9004098e6a1507e5826a833fd9efa954'/>
<id>urn:sha1:db53a8bd9004098e6a1507e5826a833fd9efa954</id>
<content type='text'>
</content>
</entry>
<entry>
<title>темплейты в бинарнике и улучшенная система кеша</title>
<updated>2024-08-13T12:59:52+00:00</updated>
<author>
<name>lost+skunk</name>
<email>skunky@ebloid.ru</email>
</author>
<published>2024-08-13T12:59:52+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=1537da9b16dfda1ecb2730b5d1de3b9005397618'/>
<id>urn:sha1:1537da9b16dfda1ecb2730b5d1de3b9005397618</id>
<content type='text'>
</content>
</entry>
<entry>
<title>instances.test.json -&gt; instances.json</title>
<updated>2024-08-01T19:54:59+00:00</updated>
<author>
<name>lost+skunk</name>
<email>skunky@ebloid.ru</email>
</author>
<published>2024-08-01T19:54:59+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=4db018fb7f01669cb5e4c1da4b56ccfe3dbadd6f'/>
<id>urn:sha1:4db018fb7f01669cb5e4c1da4b56ccfe3dbadd6f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>v1.3</title>
<updated>2024-08-01T19:48:05+00:00</updated>
<author>
<name>lost+skunk</name>
<email>skunky@ebloid.ru</email>
</author>
<published>2024-08-01T19:48:05+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/skunky-art.git/commit/?id=c5514c3875b9b782688047d547dfd6663a5b77bb'/>
<id>urn:sha1:c5514c3875b9b782688047d547dfd6663a5b77bb</id>
<content type='text'>
</content>
</entry>
</feed>
