Actual

A local-first personal finance app

Open Source

Actual Source Code

Author

actualbudget

Description

A local-first personal finance app

#budgeting#finance#money#personal-finance

Homepage

https://actualbudget.org

Repository

  • LicenseMIT
  • Created29 Apr 22
  • Primary languageTypeScript
  • Size601,733 KB
  • Stars29,113
  • Forks3,011
  • Watchers29,113

Language Usage

Language Usage

Project Health

  • Last commit6 days ago
  • Open issues260
  • Latest releasev26.9.0

Recent Commits

  • Matt Fiddaman(23 Sept 26)

    sidebar: trigger group balance updates on sync (#8994) * trigger group balance updates on sync * note * coderabbit

  • Baris Ari(23 Sept 26)

    [AI] Migrate create-folders migration to TypeScript (#8851) * [AI] Migrate create-folders migration to TypeScript * [AI] Add release note for create-folders migration * [AI] Preserve migration titles after TypeScript conversion * [AI] Reject duplicate normalized migration titles --------- Co-authored-by: Baris Arı <[email protected]> Co-authored-by: Baris Ari <[email protected]>

  • flafleur(22 Sept 26)

    [AI] Detect CSV file encoding and add a per-account encoding selector (#8924) * [AI] Detect CSV file encoding and add a per-account encoding selector Read CSV/TSV files as raw bytes and decode them based on the detected encoding instead of always assuming UTF-8: the byte order mark, BOM-less UTF-16 (NUL byte analysis), strict UTF-8 validation, and a windows-1252 fallback that also decodes ISO-8859-1 content. A mostly-valid UTF-8 file with a few corrupted bytes still decodes as UTF-8 with replacement characters instead of falling back to windows-1252. Add an encoding selector to the CSV import options, persisted per account like the delimiter, for files in encodings that cannot be detected automatically (e.g. windows-1250, ISO-8859-2). Adds fixtures and tests for UTF-16 (with and without BOM), UTF-8 with BOM, corrupted UTF-8, NUL-padded UTF-8, and windows-1252 content. Fixes #6327 * Update VRT screenshots Auto-generated by VRT workflow PR: #8924 * Update VRT screenshots Auto-generated by VRT workflow PR: #8924 * [AI] Address review: require dominant NUL parity and translate encoding labels Require one parity to clearly dominate (>= 90% of NUL bytes) before detecting BOM-less UTF-16, so a UTF-8 file with dense contiguous NUL padding (even split across parities) is no longer misdetected as UTF-16. Adds a fixture with padding above the 10% density threshold. Wrap the encoding selector labels in t() per the repository's translated user-facing text requirement. * [AI] Drop iso-8859-1 from the CSV encoding selector TextDecoder resolves the iso-8859-1 label to the windows-1252 decoder per the WHATWG encoding spec, so the option was redundant and could mislead users into expecting true ISO-8859-1 decoding. windows-1252 already covers ISO-8859-1 content; keep the alias accepted in decodeCsvBytes with a clarifying comment and an alias test. * [AI] Make the iso-8859-1 alias test distinguish Windows-1252 The alias test now uses a fixture containing the 0x80 byte, which windows-1252 decodes as the euro sign while a true ISO-8859-1 decoder would produce a C1 control character, so the assertion actually verifies the windows-1252 alias semantics. * [AI] Simplify CSV encoding detection to BOM and explicit selection Follow the review suggestion: the byte order mark selects UTF-16 LE/BE and everything else decodes as UTF-8; other encodings are handled by the manual per-account selector this PR adds. Drop the speculative BOM-less UTF-16, windows-1252 fallback, and corrupted UTF-8 heuristics along with their fixtures and tests. --------- Co-authored-by: François Lafleur <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

  • John Costa(21 Sept 26)

    [AI] Fix YNAB4 import dropping the parent payee on split children (#8973) * fix YNAB4 import dropping the parent payee on split children YNAB4 stores the payee on the parent transaction only, but the importer spread a `payee: undefined` key onto every non-transfer sub transaction. `makeChild` treats a present key as explicit, so the children never fell back to the parent's payee and showed up with no payee at all. Only emit the key when a payee was actually resolved; transfer children are unchanged. Fixes #3561 * Update packages/loot-core/src/server/importers/ynab4.ts --------- Co-authored-by: Tim <[email protected]>

  • Michael Clark(21 Sept 26)

    :bar_chart: Monte carlo performance improvement (#8988) * improve performance of monte carlo * release notes

  • John Costa(21 Sept 26)

    fix(import): accept "Sept" as a month abbreviation in CSV dates (#8957) The month rewrite in parseDate matched "Sep", "Sep." and "September" but not the four-letter "Sept" that some bank exports use. The word boundary after "sep" failed on the trailing "t", so the month was never converted to a number and every September row was rejected as an invalid date. Extend the regex to also accept "Sept" and "Sept." and cover the DD MMM YY, DD MMM YYYY and MMM DD, YYYY forms in the parseDate table. Closes #8888

  • Julian Dominguez-Schatz(21 Sept 26)

    Retry Weblate repository lock conflicts (#8979) * [AI] Retry Weblate repository lock conflicts * [AI] Add release note for translation retries

  • Matt Fiddaman(20 Sept 26)

    ⬆️ better-sqlite3 v13 (#8736) * better-sqlite3 v13 * note * fix build * engine update * fix yarn warning and arm32 docker builds

  • Michael Clark(20 Sept 26)

    :chart_with_upwards_trend: Monte carlo -Warn when contribution is too large (#8971) * warn when monte carlo contribution is too large * feedback

  • Matt Fiddaman(19 Sept 26)

    add account hover card (#8969) * add account hover card * add context menus * note * generalise touch helper * coderabbit

  • Matt Fiddaman(19 Sept 26)

    sidebar pt. 5: account search (#8914) * filter helper * add search * note * review improvements

  • Spaghettio73(19 Sept 26)

    docs: add receipt2actual and actual2ics to Community Projects (#8945)

  • Michael Clark(18 Sept 26)

    :bug: Monte carlo cashflow chart underfunding fix (#8964) * fix underfunded gap amount when using withdrawal rules and min spending amount * release notes

  • Terry Lockett(18 Sept 26)

    fix ToBudget actions not showing in firefox (#8958)

  • Michael Clark(18 Sept 26)

    :hedgehog: Speeding up large budgets by only running rules when needed (#8946) * optimise transactions edits/deletes by making the running balance query find applicable rules first, and only run if required * balance now fetched at most once and only for a rule whos conditions matched

  • Michael Clark(18 Sept 26)

    :chart_with_upwards_trend: Monte Carlo income streams (#8955) * monte carlo income streams * simplify release note * enhancement * fix withdrawal rule floor when income is specified * update screenshots * suplus pot and images * way better description in the run details * covering case where income is all thats setup and spending is the same as the income * feedback * screenshots and rename of minimum withdrawal to min spending * additional docs

  • Stephen Brown II(18 Sept 26)

    [AI] Show a progress bar while importing a YNAB budget (#8956) * [AI] Show a progress bar while importing a YNAB budget * [AI] Name the account in transaction import progress * [AI] Defer scheduled import progress until rule updates finish Change-Id: rnuttktwqnkslztsvklpqxvnwnvqvopy * [AI] Prevent dismissing an import while it is running Change-Id: tnwzlovsmtsqwtkxorqnymtxvwuyrsvk * [AI] Subscribe to import progress before importing Change-Id: kwnmmmslpoxpxrmpzltnwsrqvuryzous

  • Michael Clark(17 Sept 26)

    :hedgehog: Make saving transaction edits slightly faster on big budgets (#8944) * increasing cache size, wrap updatetransactions in one transaction to reduce number * rabbit feedback

  • J-LCRX(16 Sept 26)

    [AI] Rank exact payee matches above tied substring matches (#8811) * [AI] Rank exact payee matches above tied substring matches fzf's tiebreakers default to none, so when two suggestions tie on match score (e.g. querying 'Amazon' against both 'Amazon' and 'Amazon Prime'), the ranking falls back to original array order instead of favoring the exact match. useTags.ts already fixes this for tag filtering via tiebreakers: [byLengthAsc, byStartAsc]; this applies the same fix to payee autocomplete matching. Split out from the combined payee/category fix on fix/exact-match-tiebreak-scoring — the category half is intentionally not carried over, since category suggestions are meant to stay ordered the way they appear within the budget arrangement. * [AI] Use alphabetically-ordered payee names in exact-match tiebreak test 'Amazon Prime'/'Amazon' needed to be listed out of alpha order to demonstrate the bug, which doesn't match how the payee list is naturally sorted. 'AAA Google'/'Google' demonstrates the same fix while staying in alpha order like the rest of the suite. Co-Authored-By: Claude Sonnet 5 <[email protected]> --------- Co-authored-by: Claude Sonnet 5 <[email protected]>

  • Stephen Brown II(15 Sept 26)

    [AI] fix(sync): receive only the latest timestamp to stop counter overflow (#8706) * [AI] fix(sync): receive only the latest timestamp to stop counter overflow Timestamp.recv was called once per incoming message. Each call burns one tick of the 16-bit HLC counter whenever the logical clock does not advance, and the counter only resets when Date.now() moves forward. Browsers that coarsen Date.now() (LibreWolf, or Firefox with resistFingerprinting, which rounds it to 100ms) give the loop enough time to pass 65535 messages in a single tick, so a large sync throws OverflowError and the budget never opens. Receive only the highest incoming timestamp instead. The clock lands in the same place, the drift check still sees the furthest-ahead message, and the counter advances once per batch. * [AI] fix(sync): address timestamp review feedback Change-Id: oowtnqoxrmltvupuxowqqnnynnqwkxqx

  • Michael Clark(15 Sept 26)

    :electron: When data folder is unavailable show a friendly message (#8928) * when data folder is unavailable due to permissions etc, show a friendly prompt * feedback from rabbit

  • danielcovill(15 Sept 26)

    Tips tricks docs fix (#8940) * Update tips-tricks.md Correct out of date documentation. * Add release notes * Clearer writing, filename fix for release notes

  • Matiss Janis Aboltins(13 Sept 26)

    [AI] Warn API users about deferred sync messages and fix stale docs row (#8925) Co-authored-by: Claude Fable 5.1 <[email protected]>

  • Albert Bendicho(13 Sept 26)

    Update enable-banking.md Clarify needed steps (#8821) * Clarify enable-banking.md steps It seems to be a common problem people face that they skip the `Link the accounts you want in the Enable Banking interface` https://github.com/actualbudget/actual/issues/7799#issuecomment-4433943297 https://github.com/actualbudget/actual/issues/7799#issuecomment-4629194825 https://github.com/actualbudget/actual/issues/7799#issuecomment-4641704020 https://github.com/actualbudget/actual/issues/7799#issuecomment-4477748895 https://github.com/actualbudget/actual/issues/7799#issuecomment-4488926240 https://github.com/actualbudget/actual/issues/7799#issuecomment-4511171800 https://github.com/actualbudget/actual/issues/7799#issuecomment-4641704020 * [autofix.ci] apply automated fixes * coderabbitai requested improvements * [autofix.ci] apply automated fixes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

  • Amy Hawkins(13 Sept 26)

    [AI] Fix missing vite-plugin-peggy workspace in sync-server.Dockerfile (#8798) * [AI] Fix missing vite-plugin-peggy workspace in sync-server.Dockerfile The deps stage copies each workspace's package.json individually for Docker layer caching, but packages/vite-plugin-peggy/package.json was never added to that list even though loot-core and api both depend on it via workspace:*, so yarn install fails resolution with Workspace not found. Add the missing COPY line. Co-Authored-By: Claude Sonnet 5 <[email protected]> * release note --------- Co-authored-by: Amy Hawkins <[email protected]> Co-authored-by: Claude Sonnet 5 <[email protected]>

  • Sreetam Das(13 Sept 26)

    [AI] Add Karma to the custom theme catalog (#8930) * [AI] Add Karma to the custom theme catalog Karma is a dark theme for Actual Budget. The CSS is hosted at sreetamdas/karma/actual.css and every --color-* token is mapped from the canonical Karma palette, so the theme stays in step with the Karma ports for VS Code, Zed and iTerm. Colors are the six representative hues for the catalog swatch: the near-black background, the purple primary accent, and the green/pink/orange/cyan accents. * [AI] Add release note for the Karma theme

  • Krzysztof Wójt(13 Sept 26)

    [AI] Expose parent transaction fields to split rule formulas (#8898) * [AI] Expose parent transaction text to split rule formulas * [AI] Categorize split parent context as an enhancement

  • dependabot[bot](12 Sept 26)

    Bump @vitest/mocker from 4.1.10 to 5.0.0 in the npm_and_yarn group across 0 directory (#8923) * Bump @vitest/mocker in the npm_and_yarn group across 0 directory Updates `@vitest/mocker` from 4.1.10 to 5.0.0 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/mocker) --- updated-dependencies: - dependency-name: "@vitest/mocker" dependency-version: 5.0.0 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> * [AI] Fix typecheck failures under vitest 5 Vitest 5 changed two things that broke the typecheck/build jobs: - `vi.fn()`'s inferred type now references `Procedure` from an internal vitest chunk that cannot be named from outside, so the hoisted mocks in `cloud-storage.test.ts` tripped TS2883. Annotate them as `Mock`. - The `expect` package was inlined and the global `jest.Matchers` declaration dropped, so `@testing-library/jest-dom`'s default entry no longer augments vitest's `Assertion`. Use the `/vitest` entry point instead. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Bvwt76cXUoLwfHiy1jhToc * [AI] Bump @actual-app/crdt to 3.1.3 The dependency bump touches packages/crdt/package.json, so the CRDT version bump check requires a new version. Matches how the previous dependabot group bump (#8921) was handled. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Bvwt76cXUoLwfHiy1jhToc * [AI] Add release note for the vitest bump Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Bvwt76cXUoLwfHiy1jhToc --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: MatissJanis <[email protected]> Co-authored-by: Claude Opus 5 <[email protected]>

  • Fabian Markert(12 Sept 26)

    [AI] Fix character encoding corruption when importing CAMT files (#8912) (#8913)

  • Tim(11 Sept 26)

    [AI] Fix theme colour ordering and custom theme refresh (#8922) * [AI] Fix theme colour ordering and custom theme refresh * Apply suggestion from @tim-smart

Actual Security

Security Advisories (14)

  • lowPatched

    CVE-2026-57449CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token

  • highPatchedCVSS 8.3

    CVE-2026-49229Disabled OpenID users keep access through existing session tokens

  • mediumPatchedCVSS 4.2

    CVE-2026-50179CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

  • mediumPatchedCVSS 4.3

    CVE-2026-46700Missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

  • mediumPatchedCVSS 4.6

    CVE-2026-46672CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper

  • mediumPatched

    CVE-2026-42890Electron Run As Node in actual

  • highPatched

    CVE-2026-42604OpenID `client_secret` Disclosure via Broken Authorization Guard in `/openid/config`

  • highPatched

    CVE-2026-50007Shared users can perform owner-only file management actions

  • mediumPatched

    CVE-2026-43872Path traversal vulnerability in actual-server

  • highPatchedCVSS 8.8

    CVE-2026-33318Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers

  • mediumPatched

    CVE-2026-3089Actual Sync Server 26.2.1 - Authenticated Path Traversal

  • criticalPatched

    CVE-2026-27584Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints

  • highPatched

    CVE-2026-27638Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode

  • mediumPatchedCVSS 4.2

    GHSA-xvp7-8vm8-xfxxGocardless service is logging sensitive data including bearer tokens, account numbers, etc...

Actual Website

Website

Your Finances — made simple | Actual Budget

Actual Budget is a super fast and privacy-focused app for managing your finances. At its heart is the well proven and much loved Envelope Budgeting methodology.

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address98.84.224.111
  • Hostnameec2-98-84-224-111.compute-1.amazonaws.com
  • LocationAshburn,Virginia,United States of America,NA
  • ISPAmazon Technologies Inc.
  • ASNAS14618

Associated Countries

  • USUS

Safety Score

Website marked as safe

100%

Blacklist Check

actualbudget.org was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

Actual Docker

Container Info

actual

Actual is a super fast privacy-focused app for managing your finances.

#Finance

Run Command

docker run -d \
  

Compose File

version: 3.8

Actual Socials

Actual Reviews

More Secure Budgeting

About the Data: Actual

Change History

Edit Actual Data

You can edit Actual's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external sources, a list of these can be found data documentation.

Origin Data

Modify Data

API

You can access Actual's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/actual

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share Actual

Help your friends compare Secure Budgeting, and pick privacy-respecting software and services.
Share Actual and Awesome Privacy with your network!