github jchultarsky/mirador v1.19.2
1.19.2 - 2026-10-07

latest release: v1.20.0
3 hours ago

Release Notes

Fixed

  • A calendar with an impossible time no longer crashes the agenda. An
    hour of 25, a minute of 60, or a sign where a digit belongs in a
    DTSTART, DTEND, EXDATE or UNTIL made the time library panic on the
    agenda's reader thread, which left the terminal half-restored under a
    dashboard still drawing and the agenda never reading the file again. Such
    an event is now skipped and counted with the others the agenda could not
    read; a broken EXDATE is ignored and a broken UNTIL ends the rule at
    the date it carries. T240000, which ISO 8601 allows for the end of a day
    and some exporters write, is read as the midnight that begins the next.
  • A monthly event on the 29th, 30th or 31st stays on its day. The rule
    was stepped from each occurrence to the next, and a month without that day
    is clamped to its last, so 31 January became 28 February and then the 28th
    of every month after. Each occurrence is now measured from the first, and a
    month that lacks the day is skipped and not counted, as RFC 5545 says. A
    yearly event on 29 February appears in leap years only.
  • A repeating event repeats in its own time zone. Rules were expanded in
    the reader's zone, so a meeting on Mondays at 00:30 in London
    (BYDAY=MO) appeared in New York on Monday evenings, a day late every
    week. Each occurrence is now worked out in the zone the event was written
    in, then shown in yours.
  • A due date too far away is refused instead of crashing the dashboard.
    Typing an offset past what the time library can hold into a task's due
    field — 99999y, 999999m, 9999999d or 2000000w — panicked and took
    everything down with it. It now gets the form's "out of range" line, the
    same answer as 9000y, which never panicked but lands past the year 9999,
    and as a figure too long to read at all.
  • The agenda scrolls. Its scroll keys and the mouse wheel moved a
    position the list was never drawn with, so the panel always showed its
    first rows and every event below the bottom edge was out of reach, while
    the border, ? and the README all said the keys scrolled. They move the
    view now, a row at a time, ten with Page Up and Page Down, and to either
    end with g and G, and wherever the panel has room the day of the
    events on screen stays at the top as they scroll. A new day or another
    calendar starts at the top again.
    The panel also stops building a line for every event in the window on
    every frame, and builds only the ones on screen.
  • SECURITY.md describes the program that ships. It still called
    mirador pre-1.0 with 0.7.x supported, said it contacts exactly two hosts
    when the default dashboard also reads three news feeds, and left feeds,
    calendars and plugin output out of the inputs worth reporting on. It now
    lists every host by panel, every file read and written, every program it
    can start, and puts a hostile feed, .ics file or plugin message in
    scope.

Security

  • A news link is opened only if it is a web address, and never by a
    shell.
    The README's Windows example for [news].open_command was
    ["cmd", "/c", "start"], and cmd reads its arguments as a command line:
    a feed whose link held & and a command got that command run when you
    pressed Enter on the headline, and an ordinary link with a query string
    opened cut short. mirador now refuses to hand a link to cmd, PowerShell
    or pwsh and says so in the panel, and the Windows example is
    ["rundll32", "url.dll,FileProtocolHandler"]. If you copied the old line,
    replace it. Separately, Enter now opens only http and https links:
    open and xdg-open would otherwise hand a feed's file: or
    custom-scheme link to whatever program is registered for it. A link in
    another script is percent-encoded rather than refused, and one holding a
    control character is not opened.

Install mirador 1.19.2

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/jchultarsky/mirador/releases/download/v1.19.2/mirador-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/jchultarsky/mirador/releases/download/v1.19.2/mirador-installer.ps1 | iex"

Download mirador 1.19.2

File Platform Checksum
mirador-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
mirador-x86_64-apple-darwin.tar.gz Intel macOS checksum
mirador-x86_64-pc-windows-msvc.zip x64 Windows checksum
mirador-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
mirador-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo jchultarsky/mirador

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

Don't miss a new mirador release

NewReleases is sending notifications on new releases.