All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project aims to follow Semantic Versioning.
- Accept
font/ttfandfont/sfntMIME types when validating downloaded TTF files, fixing installs broken byfile-typev21 detection changes.
- Added a cached npm update notification that checks for newer
google-font-clireleases and can be disabled with--no-update-notifier,GFCLI_NO_UPDATE_NOTIFIER, orNO_UPDATE_NOTIFIER.
- Set the loaded flag and replace existing data when populating font lists.
- Prevent filtered
GoogleFontListclones from triggering an initial background load. - Validate single-font GWFH API payloads before parsing font variants.
- Hardened GitHub Actions workflow token permissions.
- Migrated the test runner from Jest to Vitest.
- Removed unused UI dependencies.
- Refreshed development dependencies and release workflow dependencies.
- Updated README badges and development documentation.
- Hardened remote fetching to require HTTPS, reject insecure redirects, and enforce response size limits for both metadata and font downloads.
- Reworked font download handling to use unique temporary directories, validate MIME types from a small sniff buffer, and clean up temporary files more reliably.
- Migrated filename casing from the deprecated
pascal-casepackage tochange-case. - Updated the Node.js support baseline to
>=20and aligned project documentation with that requirement. - Upgraded key dependencies, including
file-type,commander,ink,ora,react,jest,typescript, andnode-powershell. - Refreshed the test suite to cover the new request security model, temp-file handling, and PascalCase filename generation.
- Sadly, we haven't had a CHANGELOG.md before; but it seems like now is a good time to begin.