Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,8 @@ jobs:
path: |
src-tauri/target/release/bundle/nsis/*.exe
src-tauri/target/release/VEX Launcher Portable.exe
src-tauri/target/release/VEX Launcher Portable.zip
src-tauri/target/release/SHA256SUMS.txt
if-no-files-found: error

linux:
Expand Down
4 changes: 2 additions & 2 deletions FEATURES.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ This roadmap compares the most useful instance-management ideas from Modrinth Ap

## Available In VEX

- Microsoft and offline profiles with saved offline skins.
- Microsoft and offline profiles with a reusable offline skin library and interactive 3D previews.
- Isolated Vanilla, Fabric, Quilt, Forge, and NeoForge instances.
- Official Forge and NeoForge installer integration.
- Automatic compatible Java runtime downloads.
Expand All @@ -17,7 +17,7 @@ This roadmap compares the most useful instance-management ideas from Modrinth Ap
- Modrinth modpack update checks and updates with an automatic full backup.
- Existing Minecraft installation scanner with version, loader, mod, world, resource-pack, and shader summaries.
- Local server creation and console.
- Windows installer, self-contained portable build, and Linux AppImage.
- Windows installer, recommended portable ZIP, optional self-contained portable build, and Linux AppImage.

## Useful Next Features

Expand Down
14 changes: 14 additions & 0 deletions PORTABLE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# VEX Portable

The recommended portable download is `VEX Launcher Portable.zip`.

Extract the ZIP and keep these files together:

- `VEX Launcher.exe`
- `WebView2Loader.dll`

This version does not install the launcher and does not need administrator privileges. It avoids the self-extracting behavior used by the single-file portable executable, which can trigger stricter browser heuristics.

The single-file portable remains available for convenience, but Windows SmartScreen can warn about any newly published unsigned executable. A trusted code-signing certificate is required to display a verified publisher.

Always download VEX from the official GitHub release and compare its SHA-256 hash with `SHA256SUMS.txt`.
6 changes: 3 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ VEX is a free and open-source Minecraft launcher focused on making the path from

The project started as a design experiment built with AI-assisted programming. Its goal is to remain lightweight, direct, and accessible for players using either an official Microsoft account or an offline profile.

## VEX 0.8
## VEX 0.9

- Combined Modrinth and CurseForge discovery with source, version, loader, and content-type filters.
- Dedicated pages for mods, modpacks, shaders, resource packs, and plugins.
Expand All @@ -13,7 +13,7 @@ The project started as a design experiment built with AI-assisted programming. I
- Compatible Minecraft versions shown directly in the instance editor.
- Modrinth and CurseForge modpack installation with integrity checks when the source provides hashes.
- Automatic compatible Java runtime downloads from Eclipse Adoptium, isolated inside VEX data.
- Saved offline profiles, a skin library, and official Microsoft login on Windows.
- Saved offline profiles, a reusable skin library, an interactive 3D skin viewer, and official Microsoft login on Windows.
- Instance library with cloning, protected deletion, worlds, screenshots, logs, and installed content.
- Instance backups, existing-installation scanning, and safe Modrinth modpack update checks.
- Local Vanilla, Paper, or Fabric servers with a console and a playit.gg guide.
Expand Down Expand Up @@ -70,7 +70,7 @@ On Windows:
.\build-portable.ps1
```

This creates the installer and the self-contained portable executable.
This creates the installer, a self-contained portable executable, a recommended portable ZIP, and SHA-256 checksums.

The Linux AppImage is built and tested automatically by GitHub Actions. It can run on most modern distributions without installation:

Expand Down
43 changes: 26 additions & 17 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,27 +1,36 @@
# Política de segurança
# Security policy

## Dados locais
## Local data

O VEX armazena perfis, skins, logs, instâncias, servidores, mundos, configurações e runtimes Java localmente. Esses dados não fazem parte do repositório e nunca devem ser enviados em commits, issues ou relatórios públicos.
VEX stores profiles, skins, logs, instances, servers, worlds, settings, and Java runtimes locally. These files are not part of the repository and must never be included in commits, issues, or public reports.

O launcher não envia mundos, skins, nomes de usuário, logs ou arquivos de instâncias para serviços próprios. A rede é usada somente para autenticação solicitada pelo jogador e para baixar metadados, conteúdo e runtimes de fontes conhecidas.
The launcher does not upload worlds, skins, usernames, logs, or instance files to a VEX service. Network access is used only for authentication requested by the player and for downloading metadata, content, and runtimes from known sources.

## Credenciais
## Credentials

- No Windows, o token de renovação da conta Microsoft e a chave do CurseForge são protegidos para o usuário atual com DPAPI.
- No Linux, a chave do CurseForge é armazenada em um arquivo local acessível somente pelo próprio usuário.
- Senhas Microsoft são digitadas apenas na página oficial da Microsoft e nunca passam pelo VEX.
- Nenhuma chave, token ou dado pessoal deve ser incluído no código-fonte.
- On Windows, Microsoft refresh tokens and the optional CurseForge API key are protected for the current user with DPAPI.
- On Linux, the CurseForge key is stored in a local user-only file.
- Microsoft passwords are entered only on the official Microsoft page and never pass through VEX.
- Keys, tokens, and personal data must never be included in source code.

## Downloads automáticos
## Automatic downloads

- Java: Eclipse Adoptium, verificado com SHA-256.
- Modrinth: arquivos oficiais, verificados com SHA-512 quando disponível.
- CurseForge: arquivos da CDN oficial, verificados com MD5 quando disponível.
- Forge e NeoForge: instaladores obtidos dos repositórios Maven oficiais.
- Java: Eclipse Adoptium, verified with SHA-256.
- Modrinth: official files, verified with SHA-512 when available.
- CurseForge: official CDN files, verified with MD5 when available.
- Forge and NeoForge: installers obtained from their official Maven repositories.

O VEX restringe instalações automáticas às pastas configuradas do Minecraft, das instâncias e dos servidores.
VEX restricts automatic installations to configured Minecraft, instance, and server directories.

## Relatar uma vulnerabilidade
## Windows SmartScreen

Não publique vulnerabilidades que incluam tokens, caminhos pessoais, logs privados ou dados de jogadores em uma issue pública. Entre em contato de forma privada com o responsável pelo projeto e inclua somente os passos mínimos para reproduzir o problema.
Current public builds are not digitally signed because the project does not yet own a trusted code-signing certificate. Windows SmartScreen and browsers can warn about newly published unsigned executables even when no malware is detected.

- The recommended portable distribution is a ZIP containing the launcher and `WebView2Loader.dll`.
- The single-file portable is self-extracting and may trigger stricter heuristic warnings.
- Every release publishes `SHA256SUMS.txt` so downloads can be verified.
- A self-signed certificate is not used because it does not establish public trust and can make warnings more confusing.

## Reporting a vulnerability

Do not publish vulnerabilities containing tokens, personal paths, private logs, or player data in a public issue. Contact the project owner privately and include only the minimum steps required to reproduce the issue.
36 changes: 36 additions & 0 deletions build-portable.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@ if (Test-Path -LiteralPath $tools) {

$releaseRoot = if ($env:CARGO_TARGET_DIR) { Join-Path $env:CARGO_TARGET_DIR "release" } else { Join-Path $PSScriptRoot "src-tauri\target\release" }
$portableOutput = Join-Path $releaseRoot "VEX Launcher Portable.exe"
$portableDirectory = Join-Path $releaseRoot "VEX Launcher Portable"
$portableZip = Join-Path $releaseRoot "VEX Launcher Portable.zip"
$launcherPayload = Join-Path $releaseRoot "vex-launcher.exe"
$loaderPayload = Join-Path $releaseRoot "WebView2Loader.dll"
$bootstrapSource = Join-Path $PSScriptRoot "portable-bootstrap\Program.cs"
Expand All @@ -38,4 +40,38 @@ if (-not (Test-Path -LiteralPath $loaderPayload)) {
if ($LASTEXITCODE -ne 0) {
throw "Não foi possível gerar o portátil autocontido."
}

$portableResolvedRoot = [IO.Path]::GetFullPath($portableDirectory)
$releaseResolvedRoot = [IO.Path]::GetFullPath($releaseRoot)
if (-not $portableResolvedRoot.StartsWith($releaseResolvedRoot, [StringComparison]::OrdinalIgnoreCase)) {
throw "Pasta portátil fora do diretório de build."
}
if (Test-Path -LiteralPath $portableDirectory) {
Remove-Item -LiteralPath $portableDirectory -Recurse -Force
}
New-Item -ItemType Directory -Path $portableDirectory | Out-Null
Copy-Item -LiteralPath $launcherPayload -Destination (Join-Path $portableDirectory "VEX Launcher.exe")
Copy-Item -LiteralPath $loaderPayload -Destination (Join-Path $portableDirectory "WebView2Loader.dll")
Copy-Item -LiteralPath (Join-Path $PSScriptRoot "PORTABLE.md") -Destination (Join-Path $portableDirectory "README.md")
if (Test-Path -LiteralPath $portableZip) {
Remove-Item -LiteralPath $portableZip -Force
}
Compress-Archive -Path (Join-Path $portableDirectory "*") -DestinationPath $portableZip -CompressionLevel Optimal

$installerOutput = Get-ChildItem -LiteralPath (Join-Path $releaseRoot "bundle\nsis") -Filter "*-setup.exe" |
Sort-Object LastWriteTime -Descending |
Select-Object -First 1
$checksumOutput = Join-Path $releaseRoot "SHA256SUMS.txt"
$checksumFiles = @($portableOutput, $portableZip)
if ($installerOutput) {
$checksumFiles += $installerOutput.FullName
}
$checksumLines = $checksumFiles | ForEach-Object {
$hash = Get-FileHash -LiteralPath $_ -Algorithm SHA256
"$($hash.Hash.ToLowerInvariant()) $(Split-Path $_ -Leaf)"
}
Set-Content -LiteralPath $checksumOutput -Value $checksumLines -Encoding UTF8

Write-Host "Portable: $portableOutput"
Write-Host "Portable ZIP recomendado: $portableZip"
Write-Host "Checksums: $checksumOutput"
62 changes: 61 additions & 1 deletion package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 3 additions & 2 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "vex-launcher",
"private": true,
"version": "0.8.0",
"version": "0.9.0",
"type": "module",
"scripts": {
"dev": "vite --host 127.0.0.1",
Expand All @@ -13,7 +13,8 @@
"@tauri-apps/api": "^2.8.0",
"lucide-react": "^0.468.0",
"react": "^19.1.0",
"react-dom": "^19.1.0"
"react-dom": "^19.1.0",
"skinview3d": "^3.4.2"
},
"devDependencies": {
"@tauri-apps/cli": "^2.8.0",
Expand Down
8 changes: 8 additions & 0 deletions portable-bootstrap/Program.cs
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,14 @@
using System.Text;
using System.Windows.Forms;

[assembly: AssemblyTitle("VEX Launcher Portable")]
[assembly: AssemblyDescription("Self-contained portable bootstrap for the open-source VEX Minecraft Launcher")]
[assembly: AssemblyCompany("VEX Launcher")]
[assembly: AssemblyProduct("VEX Launcher")]
[assembly: AssemblyCopyright("Copyright (c) VEX Launcher contributors")]
[assembly: AssemblyVersion("0.9.0.0")]
[assembly: AssemblyFileVersion("0.9.0.0")]

internal static class Program
{
private const string LauncherResource = "VexLauncher.Payload.exe";
Expand Down
2 changes: 1 addition & 1 deletion src-tauri/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion src-tauri/Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "vex-launcher"
version = "0.8.0"
version = "0.9.0"
description = "VEX Launcher - a modern, accessible Minecraft launcher"
authors = ["VEX Launcher contributors"]
edition = "2021"
Expand Down
Loading
Loading