# Changelog All notable changes to Feader RSS are documented in this file. ## [Unreleased] ### Security - The panel no longer reads `rss-reader.json` or `preferences.json` whole into the shell. Both are read with a 1 MiB ceiling that is checked before the file is loaded, so an oversized imported or restored file is rejected (with a status message for the feed configuration) instead of exhausting the shell's memory before JSON parsing and the feed limits apply. - `feader-rss-fetch` reads the feed configuration, imported OPML and the legacy `items.json` with byte ceilings (1 MiB, 8 MiB and 64 MiB) instead of loading them whole. ### Fixed - The article title is underlined on hover again (it read a `hovered` property that `MouseArea` does not have). ### Changed - CI runs qmllint 6.11 over the QML files, and a test guards against unbounded reads of user-editable files in both the panel and the Go helper. ## [0.4.0] - 2026-09-21 ### Added - The number of feeds you can configure is now a setting (`maxFeeds`, default 8, at most 100), editable under "Feed limit" in the settings page. OPML import respects it. - The article list scrolls infinitely: 50 articles load first and the next page is fetched as you approach the bottom, up to `maxItems`. `list` and `search` gained an `--offset` flag for this. - Playful status lines: a pulsing spinner with 40 rotating verbs while refreshing, a daily inbox-zero message, and varied "last updated" and empty-filter messages. - A list footer that shows "Loading more…", "Scroll for more" or "that's everything", plus a "Back to top" button on long lists. ### Changed - Leaner panel header: the mark-all button now shows only the relevant action (read or unread) on the same row as Refresh, the duplicated unread line is gone, and the shortcuts hint moved below the list. ## [0.3.4] - 2026-09-15 ### Changed - Reorganized the repository layout: `TODO.md` and `CHANGELOG.md` moved to `docs/`, and `screenshots/` moved under `assets/`. None of these are part of the installed plugin payload (`scripts/install.sh` never copied them), so this only affects repository browsing, not installs. `preview.png` and the shipped plugin files (`manifest.json`, `BarWidget.qml`, `Panel.qml`, `README.md`, `LICENSE`, `example-config.json`) stay at the repository root, matching the layout Omarchy's other first-party plugins use and what the marketplace listing expects. ### Fixed - Fixed raw markup leaking into extracted article text and RSS summaries: `