GitNexus/gitnexus-desktop
Sparsh b9b3ec6a63 fix(security): resolve CodeQL findings in package.mjs build script
TOCTOU (CWE-367): fs.statSync(entry.from).isDirectory() was called
before mirrorDirectory/cpSync without error handling. If the path
disappears between stat and use, the subsequent operation throws
unhandled. Wrap in try/catch and continue on error.

Indirect uncontrolled command line (CWE-78): appBuilderLibVersion is
read from desktopPackageLock (an external file) and embedded directly
in an npm pack CLI argument. Validate it matches a semver pattern
before use to prevent injection via a compromised lockfile.
2026-05-19 01:16:26 +05:30
..
build fix(validation): Simplify keyGenerator function in createRouteLimiter 2026-05-16 10:54:40 +05:30
scripts fix(security): resolve CodeQL findings in package.mjs build script 2026-05-19 01:16:26 +05:30
src fix(desktop): restart GitNexus server on macOS activate when all windows closed 2026-05-19 01:16:22 +05:30
test feat: add validation job to GitHub Actions for desktop packaging 2026-04-24 13:45:23 +05:30
.gitignore clean setup and ckeleton created at gitnexus-desktop 2026-04-19 14:38:36 +05:30
electron-builder.yml Merge branch 'main' into feat/Desktop-app 2026-05-15 03:39:22 +05:30
electron.vite.config.ts feat: add electron-vite configuration and automated packaging script for desktop application 2026-04-25 14:35:09 +05:30
package-lock.json feat: add validation job to GitHub Actions for desktop packaging 2026-04-24 13:45:23 +05:30
package.json feat: add validation job to GitHub Actions for desktop packaging 2026-04-24 13:45:23 +05:30
README.md fix(desktop): validate unpacked app startup in packaging flow 2026-04-20 21:58:01 +05:30
tsconfig.json style(desktop): format gitnexus-desktop package 2026-04-20 10:13:29 +05:30
tsconfig.node.json style(desktop): format gitnexus-desktop package 2026-04-20 10:13:29 +05:30
tsconfig.renderer.json style(desktop): format gitnexus-desktop package 2026-04-20 10:13:29 +05:30
tsconfig.vitest.json feat: add validation job to GitHub Actions for desktop packaging 2026-04-24 13:45:23 +05:30
vitest.config.ts feat: add validation job to GitHub Actions for desktop packaging 2026-04-24 13:45:23 +05:30

GitNexus Desktop

Electron desktop shell for GitNexus. The app starts the local backend and loads the real gitnexus-web UI inside the desktop window.

Commands

npm run dev
npm run build:dir
npm run build:win
npm run build:mac
npm run build:linux
  • npm run dev starts the Electron shell plus the local GitNexus backend.
  • npm run build:dir creates an unpacked desktop app directory.
  • npm run build:win creates a Windows NSIS installer .exe.
  • npm run build:mac creates a macOS .dmg.
  • npm run build:linux creates a Linux .AppImage.
  • npm run smoke:unpacked launches the latest unpacked desktop build, verifies startup, and exits.

Build output is written under gitnexus-desktop/release/<timestamp>/.

PR Artifacts

The Desktop Packaging GitHub Actions workflow builds an unpacked desktop app, smoke-tests startup, then uploads preview desktop artifacts for pull requests that touch .github/workflows/desktop-packaging.yml, gitnexus-desktop/**, gitnexus/**, gitnexus-web/**, or gitnexus-shared/**.

  • gitnexus-desktop-windows contains the Windows NSIS installer .exe and win-unpacked/.
  • gitnexus-desktop-macos contains the macOS .dmg and mac*/ output.
  • gitnexus-desktop-linux contains the Linux .AppImage and linux-unpacked/.

GitHub artifact URLs are run-specific and expire, so use the artifact names above from the latest successful PR workflow run.