v0.11.2

PlasmoHQ/plasmov0.11.2Jul 2, 2026by github-actions[bot]

AI Summary

This release focuses on security hardening for SQLite paths, compatibility fixes for WhatsApp (including protocol updates and error resolution), and improvements to sync reliability and cache error reporting.

Key Highlights

  • Security: Escaped SQLite file URI paths to prevent connection parameter manipulation.
  • WhatsApp: Updated `whatsmeow` library to fix `405 (Client Outdated)` errors and handle privacy tokens.
  • Sync: Improved linked-device presence accuracy and ensured push notifications resume on shutdown.
  • Channels: Fixed local cache persistence failure reporting to prevent silent errors.

Full Release Notes

## Changelog

### Added

### Security

- Store: escape SQLite file URI path delimiters so store names cannot alter connection parameters. (thanks @vincentkoc)
- Docs: escape raw HTML in generated-site link labels and give duplicate headings stable unique IDs. (thanks @vincentkoc)

### Fixed

- WhatsApp compatibility: update `whatsmeow` for current protocol metadata, privacy tokens on more request types, and pairing/connect handling.
- Sync: keep linked-device presence accurate while sync is running and send unavailable presence on shutdown so phones resume push notifications. (#283)
- WhatsApp connectivity: update `whatsmeow` for the current WhatsApp protocol and fix `405 (Client Outdated)` failures. (#280)
- Channels: report local cache persistence failures instead of silently returning incomplete success. (thanks @vincentkoc)
- Cleanup: reject non-positive `chats cleanup --days` values before opening the store. (thanks @vincentkoc)