Memos — a uduapp (upstream: usememos/memos)
Find a file
boojack f497f009ce fix(webhook): fail loud on malformed signing secret and add tests
Follow-up to #6013. The signing path silently fell back to using the raw
secret string as the HMAC key when a whsec_-prefixed secret had invalid
base64, producing signatures no receiver could verify with no server-side
signal.

- Extract resolveSigningKey helper that errors on invalid whsec_ base64
- Post returns that error (logged by the async dispatcher); ValidateSigningSecret
  rejects it at write time so a bad secret is never stored
- Fix stale comment referencing a nonexistent Authorization header
- Add Go tests: key derivation, secret validation, end-to-end signature
  round-trip, and the invariant that the secret never leaks into API responses
2026-06-09 22:58:10 +08:00
.github chore(github): improve issue templates with structured triage fields 2026-06-08 22:21:33 +08:00
cmd/memos feat: add configurable --log-level flag (#5934) 2026-05-12 21:10:05 +08:00
docs feat: add OpenAPI-driven MCP support (#6026) 2026-06-09 09:16:50 +08:00
internal fix(webhook): fail loud on malformed signing secret and add tests 2026-06-09 22:58:10 +08:00
proto feat: add optional webhook signing secret (Standard Webhooks HMAC-SHA256) (#6013) 2026-06-09 22:45:01 +08:00
scripts chore: update backend and frontend dependencies (#5900) 2026-04-28 08:25:26 +08:00
server fix(webhook): fail loud on malformed signing secret and add tests 2026-06-09 22:58:10 +08:00
store feat(settings): move tag metadata to user settings (#6017) 2026-06-07 23:58:00 +08:00
web feat: add optional webhook signing secret (Standard Webhooks HMAC-SHA256) (#6013) 2026-06-09 22:45:01 +08:00
.dockerignore perf: optimize CI/CD workflows and Docker builds 2026-01-14 22:12:28 +08:00
.gitignore feat(auth): add SSO user identity linkage (#5883) 2026-04-23 08:51:45 +08:00
.golangci.yaml fix(ci): remove invalid revive rule 'use-waitgroup-go' from golangci-lint config 2026-01-06 21:12:40 +08:00
.release-please-manifest.json chore(main): release 0.29.1 (#5985) 2026-06-05 08:06:30 +08:00
AGENTS.md docs: rewrite agent repository guide 2026-06-05 09:17:22 +08:00
CHANGELOG.md chore(main): release 0.29.1 (#5985) 2026-06-05 08:06:30 +08:00
CODEOWNERS chore: tweak CODEOWNERS 2026-03-05 19:14:16 +08:00
go.mod feat: add OpenAPI-driven MCP support (#6026) 2026-06-09 09:16:50 +08:00
go.sum feat: add OpenAPI-driven MCP support (#6026) 2026-06-09 09:16:50 +08:00
LICENSE chore: update LICENSE (#4394) 2025-02-11 15:45:20 +08:00
README.md chore: update sponsors 2026-05-25 20:39:25 +09:00
release-please-config.json chore: add release-please automation (#5842) 2026-04-15 23:04:10 +08:00
SECURITY.md chore: update security.md 2026-04-01 08:39:49 +08:00

Memos

Memos

Open-source, self-hosted note-taking tool built for quick capture. Markdown-native, lightweight, and fully yours.

Home Live Demo Docs Discord Docker Pulls

Memos Demo Screenshot

Features

  • Instant Capture — Timeline-first UI. Open, write, done — no folders to navigate.
  • Total Data Ownership — Self-hosted on your infrastructure. Notes stored in Markdown, always portable. Zero telemetry.
  • Radical Simplicity — Single Go binary, ~20MB Docker image. One command to deploy with SQLite, MySQL, or PostgreSQL.
  • Open & Extensible — MIT-licensed with full REST and gRPC APIs for integration.

Quick Start

docker run -d \
  --name memos \
  -p 5230:5230 \
  -v ~/.memos:/var/opt/memos \
  neosmemo/memos:stable

Open http://localhost:5230 and start writing!

Native Binary

curl -fsSL https://raw.githubusercontent.com/usememos/memos/main/scripts/install.sh | sh

Try the Live Demo

Don't want to install yet? Try our live demo first!

Other Installation Methods

  • Docker Compose - Recommended for production deployments
  • Pre-built Binaries - Available for Linux, macOS, and Windows
  • Kubernetes - Helm charts and manifests available
  • Build from Source - For development and customization

See our installation guide for detailed instructions.

Contributing

Contributions are welcome — bug reports, feature suggestions, pull requests, documentation, and translations.

Sponsors

Love Memos? Sponsor us on GitHub to help keep the project growing!

Star History

Star History Chart

License

Memos is open-source software licensed under the MIT License. See our Privacy Policy for details on data handling.


Website • Documentation • Demo • Discord • X/Twitter

Vercel OSS Program