Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
9844b54
fix: JSON parsing regression in build
benallfree Feb 27, 2026
dea5ed7
Add SECURITY.md
NoodlesNZ Jun 5, 2026
5a342c7
Merge pull request #2691 from NoodlesNZ/security-policy
liamcottle Jun 11, 2026
c94ed29
add github workflow to close stale issues
liamcottle Jun 11, 2026
3b39925
use single quotes for repo name
liamcottle Jun 11, 2026
55ad768
Merge pull request #2748 from liamcottle/github/stale-bot
liamcottle Jun 11, 2026
06130dc
added some missing CLI commands
formtapez Jun 12, 2026
d3444e6
fix formatting
formtapez Jun 12, 2026
e8d3c53
Merge pull request #2753 from formtapez/cli-docs
liamcottle Jun 12, 2026
a951415
Packet Filter V2
gjelsoe Jun 13, 2026
78bd277
Location update
gjelsoe Jun 13, 2026
5efd504
Misc changes
gjelsoe Jun 16, 2026
57563ab
update qr code docs
liamcottle Jul 5, 2026
3c65fcd
Added FILE version
gjelsoe Jul 5, 2026
e67bdd2
Missing save version to file
gjelsoe Jul 6, 2026
56c173f
Test suite updated
gjelsoe Jul 6, 2026
54234b5
implement matrix builds for faster firmware releases
liamcottle Jul 6, 2026
bbb58cc
Merge pull request #2903 from liamcottle/ci/build-matrix
liamcottle Jul 7, 2026
754fcb1
Update number_allocations.md
hpux735 Jul 9, 2026
c242b4e
Update
gjelsoe Jul 11, 2026
a517f9c
Merge pull request #2915 from hpux735/main
ripplebiz Jul 13, 2026
d9cd3ea
Revert "Add StreamSensor allocation for GroupData"
ripplebiz Jul 13, 2026
219812b
Merge pull request #2943 from meshcore-dev/revert-2915-main
ripplebiz Jul 13, 2026
a3a1aa5
Merge pull request #1865 from MeshEnvy/fix/python-json-parse-error
liamcottle Jul 19, 2026
84ceabf
Clarify hashtag privacy and group sender identity
dg1tal Jul 27, 2026
03b6ef4
Merge pull request #3047 from dg1tal/codex/docs-3044-group-privacy
liamcottle Jul 28, 2026
d63b2bd
Merge branch 'meshcore-dev:main' into PowerSaving-v16
gjelsoe Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 11 additions & 2 deletions .github/actions/setup-build-environment/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,5 +25,14 @@ runs:
- name: Extract Version from Git Tag
shell: bash
run: |
GIT_TAG_NAME="${GITHUB_REF#refs/tags/}"
echo "GIT_TAG_VERSION=${GIT_TAG_NAME##*-}" >> $GITHUB_ENV
if [[ "${GITHUB_REF}" == refs/tags/* ]]; then
# triggered by a tag push (e.g: refs/tags/companion-v1.2.3)
GIT_TAG_NAME="${GITHUB_REF#refs/tags/}"
VERSION_STRING="${GIT_TAG_NAME##*-}"
else
# triggered by a workflow dispatch (e.g: refs/heads/main)
# strip "refs/heads/" prefix and replace any remaining "/" with "-" to protect file paths
BRANCH_NAME="${GITHUB_REF#refs/heads/}"
VERSION_STRING=$(echo "$BRANCH_NAME" | tr '/' '-')
fi
echo "GIT_TAG_VERSION=${VERSION_STRING}" >> $GITHUB_ENV
35 changes: 5 additions & 30 deletions .github/workflows/build-companion-firmwares.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,33 +10,8 @@ on:
- 'companion-*'

jobs:

build:
runs-on: ubuntu-latest
steps:

- name: Clone Repo
uses: actions/checkout@v6

- name: Setup Build Environment
uses: ./.github/actions/setup-build-environment

- name: Build Firmwares
env:
FIRMWARE_VERSION: ${{ env.GIT_TAG_VERSION }}
run: /usr/bin/env bash build.sh build-companion-firmwares

- name: Upload Workflow Artifacts
uses: actions/upload-artifact@v7
with:
name: companion-firmwares
path: out

- name: Create Release
uses: softprops/action-gh-release@v3
if: startsWith(github.ref, 'refs/tags/')
with:
name: Companion Firmware ${{ env.GIT_TAG_VERSION }}
body: ""
draft: true
files: out/*
build-companion-firmwares:
uses: ./.github/workflows/firmware-builder.yml
with:
firmware_type: 'companion'
release_title_prefix: 'Companion Firmware'
35 changes: 5 additions & 30 deletions .github/workflows/build-repeater-firmwares.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,33 +10,8 @@ on:
- 'repeater-*'

jobs:

build:
runs-on: ubuntu-latest
steps:

- name: Clone Repo
uses: actions/checkout@v6

- name: Setup Build Environment
uses: ./.github/actions/setup-build-environment

- name: Build Firmwares
env:
FIRMWARE_VERSION: ${{ env.GIT_TAG_VERSION }}
run: /usr/bin/env bash build.sh build-repeater-firmwares

- name: Upload Workflow Artifacts
uses: actions/upload-artifact@v7
with:
name: repeater-firmwares
path: out

- name: Create Release
uses: softprops/action-gh-release@v3
if: startsWith(github.ref, 'refs/tags/')
with:
name: Repeater Firmware ${{ env.GIT_TAG_VERSION }}
body: ""
draft: true
files: out/*
build-repeater-firmwares:
uses: ./.github/workflows/firmware-builder.yml
with:
firmware_type: 'repeater'
release_title_prefix: 'Repeater Firmware'
35 changes: 5 additions & 30 deletions .github/workflows/build-room-server-firmwares.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,33 +10,8 @@ on:
- 'room-server-*'

jobs:

build:
runs-on: ubuntu-latest
steps:

- name: Clone Repo
uses: actions/checkout@v6

- name: Setup Build Environment
uses: ./.github/actions/setup-build-environment

- name: Build Firmwares
env:
FIRMWARE_VERSION: ${{ env.GIT_TAG_VERSION }}
run: /usr/bin/env bash build.sh build-room-server-firmwares

- name: Upload Workflow Artifacts
uses: actions/upload-artifact@v7
with:
name: room-server-firmwares
path: out

- name: Create Release
uses: softprops/action-gh-release@v3
if: startsWith(github.ref, 'refs/tags/')
with:
name: Room Server Firmware ${{ env.GIT_TAG_VERSION }}
body: ""
draft: true
files: out/*
build-room-server-firmwares:
uses: ./.github/workflows/firmware-builder.yml
with:
firmware_type: 'room-server'
release_title_prefix: 'Room Server Firmware'
90 changes: 90 additions & 0 deletions .github/workflows/firmware-builder.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,90 @@
name: Firmware Builder

on:
workflow_call:
inputs:
firmware_type:
required: true
type: string
release_title_prefix:
required: true
type: string

jobs:

generate-build-matrix:
runs-on: ubuntu-latest
outputs:
targets: ${{ steps.get-build-targets.outputs.targets }}
steps:

- name: Clone Repo
uses: actions/checkout@v6

- name: Setup Build Environment
uses: ./.github/actions/setup-build-environment

- name: Get Build Targets
id: get-build-targets
run: |
# get list of firmwares to build
TARGET_LIST=$(/usr/bin/env bash build.sh get-${{ inputs.firmware_type }}-firmwares-to-build)

# convert targets separated by new line into a json array string
JSON_ARRAY=$(echo "$TARGET_LIST" | jq -R -s -c 'split("\n") | map(select(length > 0))')

# use json array as targets result
echo "targets=$JSON_ARRAY" >> $GITHUB_OUTPUT

build:
needs: generate-build-matrix
runs-on: ubuntu-latest
continue-on-error: true # don't fail entire build if one board fails to build
strategy:
matrix:
target: ${{ fromJson(needs.generate-build-matrix.outputs.targets) }}
fail-fast: false # don't cancel other builds if one board fails to build
steps:

- name: Clone Repo
uses: actions/checkout@v6

- name: Setup Build Environment
uses: ./.github/actions/setup-build-environment

- name: Build Firmware
env:
FIRMWARE_VERSION: ${{ env.GIT_TAG_VERSION }}
run: /usr/bin/env bash build.sh build-firmware ${{ matrix.target }}

- name: Upload Workflow Artifacts
uses: actions/upload-artifact@v7
with:
name: "${{ matrix.target }}"
path: out

create-release:
needs: build
runs-on: ubuntu-latest
if: startsWith(github.ref, 'refs/tags/') # only create release for tagged builds
steps:

- name: Clone Repo
uses: actions/checkout@v6

- name: Setup Build Environment
uses: ./.github/actions/setup-build-environment

- name: Download All Artifacts
uses: actions/download-artifact@v8
with:
merge-multiple: true
path: out

- name: Create Release
uses: softprops/action-gh-release@v3
with:
name: "${{ inputs.release_title_prefix }} ${{ env.GIT_TAG_VERSION }}"
body: ""
draft: true
files: out/*
32 changes: 32 additions & 0 deletions .github/workflows/stale-bot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
name: 'Run Stale Bot'
on:
schedule:
- cron: '30 1 * * *' # daily at 1:30am
workflow_dispatch: {}

permissions:
actions: write
issues: write
pull-requests: write

jobs:
close-issues:
# only run on main repo, not forks
if: github.repository == 'meshcore-dev/MeshCore'
runs-on: ubuntu-latest
steps:
- name: Close Stale Issues
uses: actions/stale@v10
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
# auto close issues
days-before-issue-stale: 60
days-before-issue-close: 7
exempt-issue-labels: "keep-open"
stale-issue-label: "stale"
stale-issue-message: "This issue is stale because it has been open for 60 days with no activity. Remove the stale label or add a comment if this issue is still relevant, otherwise this issue will automatically close in 7 days."
close-issue-message: "This issue was closed because it has been inactive for 7 days since being marked as stale."
# don't auto close prs
days-before-pr-stale: -1
days-before-pr-close: -1

57 changes: 57 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
# Security Policy

## Supported Versions

Security fixes are applied to the latest release only. We do not backport
fixes to older versions.

| Version | Supported |
|---------|-----------|
| 1.15+ | ✅ |
| <1.15 | ❌ |

## Reporting a Vulnerability

**Please do not report security vulnerabilities through public GitHub issues.**

Use GitHub's private vulnerability reporting instead:
1. Go to the **Security** tab of this repository
2. Click **Report a vulnerability**
3. Fill in the details and submit

### What to include

A useful report tells us:
- Which component or file is affected
- What an attacker can do (impact) and under what conditions
- A minimal reproduction case or proof-of-concept if you have one
- Whether you believe it is remotely exploitable

You do not need a working exploit to report. An incomplete report is better
than no report.

## What to expect

This is a volunteer-maintained open-source project. We will do our best to
respond in a reasonable timeframe, but cannot commit to specific deadlines.

We ask that you give us a fair opportunity to investigate and address the
issue before any public disclosure. If you have not heard back after
**90 days**, feel free to follow up or proceed with disclosure at your
discretion.

## Scope

In scope:
- Remote code execution, memory corruption, or denial-of-service via crafted
radio packets
- Authentication or encryption bypasses
- Vulnerabilities in the packet routing or path handling logic

Out of scope:
- Physical access attacks (e.g., JTAG, UART extraction of keys)
- Regulatory compliance (duty cycle, frequency restrictions)
- Jamming or other physical-layer radio interference
- Issues in third-party libraries (RadioLib, Crypto, etc.) — report those
upstream
- "Best practice" suggestions without a demonstrated attack path
10 changes: 10 additions & 0 deletions build-repeaters-filter.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# sh ./build-repeaters-filter.sh
export FIRMWARE_VERSION="PowerSaving16-Filter"

############# Repeaters #############
# Commonly-used boards
## ESP32 - 17 boards
sh build.sh build-firmware \
heltec_v4_repeater \
Heltec_t096_repeater \
RAK_4631_repeater
12 changes: 11 additions & 1 deletion build.sh
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
#!/usr/bin/env bash

# exit when any command fails
set -e

global_usage() {
cat - <<EOF
Usage:
Expand Down Expand Up @@ -93,7 +96,7 @@ get_pio_envs_ending_with_string() {
# $1 should be the environment name
get_platform_for_env() {
local env_name=$1
echo "$PIO_CONFIG_JSON" | python3 -c "
printf '%s' "$PIO_CONFIG_JSON" | python3 -c "
import sys, json, re
data = json.load(sys.stdin)
for section, options in data:
Expand Down Expand Up @@ -276,4 +279,11 @@ elif [[ $1 == "build-repeater-firmwares" ]]; then
build_repeater_firmwares
elif [[ $1 == "build-room-server-firmwares" ]]; then
build_room_server_firmwares
elif [[ $1 == "get-companion-firmwares-to-build" ]]; then
get_pio_envs_ending_with_string "_companion_radio_usb"
get_pio_envs_ending_with_string "_companion_radio_ble"
elif [[ $1 == "get-repeater-firmwares-to-build" ]]; then
get_pio_envs_ending_with_string "_repeater"
elif [[ $1 == "get-room-server-firmwares-to-build" ]]; then
get_pio_envs_ending_with_string "_room_server"
fi
Loading