SkySend

Share end-to-end encrypted Markdown notes, files, code and passwords/keys, or request secrets from others. Set a password, expiration time and/or maximum views. No account necessary. Self-hostable and has a client and admin CLI.

Open Source

SkySend Source Code

Author

Skyfay

Description

Minimalist, end-to-end encrypted, self-hostable file and note sharing. Zero-knowledge server - files and notes are encrypted in the browser before upload. No accounts, no telemetry, built for speed and security.

#aes-256-gcm#docker#encryption#end-to-end-encryption#file-sharing#privacy#react#s3-storage#self-hosted#typescript#zero-knowledge

Homepage

https://skysend.app

Repository

  • LicenseAGPL-3.0
  • Created06 Apr 26
  • Primary languageTypeScript
  • Size4,935 KB
  • Stars425
  • Forks18
  • Watchers425

Language Usage

Language Usage

Project Health

  • Last commit31 minutes ago
  • Open issues3
  • Latest releasev2.12.2

Top Contributors

Recent Commits

  • Manu(05 Oct 26)

    Download Integrity and Upload Memory Security Fixes and CI Improvements (#77)

  • Manu(05 Oct 26)

    Fix changelog release check matching a pre-release version as already li - `v2.13.0-beta` previously matched the regex check for `v2.13.0`, so a pre-release entry blocked the real release from being written. - Compare the header as plain text instead, requiring an exact line or a space-separated title suffix. - Exclude the docs contributor guide from the VitePress build and add a regression test covering the pre-release case.

  • Manu(05 Oct 26)

    Release v2.12.2: bump version and collect changelog fragments - Bumps all workspace package.json files and apps/client/src/version.ts to 2.12.2 - Moves the six unreleased changelog fragments into docs/changelog.md under the new release section

  • Manu(05 Oct 26)

    Fix ReDoS in report Worker's email validation regex Linear-time pattern plus a 254-char length cap prevent a crafted reply address from backtracking quadratically (CodeQL js/polynomial-redos).

  • Manu(05 Oct 26)

    Credit reporter in security advisories, link docs rule for crediting - Adds "Thanks @rajnisht7" with advisory links to the two GHSA entries - Codifies the crediting convention in docs/CLAUDE.md for future entries

  • Manu(05 Oct 26)

    Fix --no-ws flag not disabling WebSocket upload transport Commander stores a negated boolean flag under its positive name, so checking options.noWs never matched and --no-ws was silently ignored. Renamed the interface field to ws and check options.ws !== false instead. Docs updated to reflect that uploads always use HTTP chunks for now since WebSocket uploads are disabled in the CLI.

  • Manu(05 Oct 26)

    Stream chunked upload bodies to disk instead of memory - Prevents memory exhaustion from oversized or parallel chunk requests by writing each chunk to DATA_DIR/tmp/chunks instead of buffering in RAM - Adds a session-wide byte cap so chunks together can't exceed the declared upload size - Updates docs, tests, and changelog to match the new disk-backed limits

  • Manu(05 Oct 26)

    Bound chunk upload memory and cap WS message size Chunk route read entire bodies into memory before checking size, letting oversized or many parallel chunks exhaust server memory (GHSA-9rmm-v3p2-c26g). Add per-chunk, per-session, and global memory caps checked while the body is read, plus concurrent-request and duplicate-index limits. Also drop the ws library's default maxPayload to 1 MiB since onMessage only fires after a full message is buffered.

  • Manu(05 Oct 26)

    Add truncation check to reject downloads cut short by the server Every ECE record authenticates on its own, so a server dropping records from the end of a stream still decrypts cleanly. Checks the decrypted size against the authenticated metadata (file size or new archiveSize for archives) in every download path: CLI, TUI, and all three web tiers, removing partial files on failure. GHSA-w3p6-2vcf-mmv9.

  • Manu(05 Oct 26)

    Add per-branch changelog fragments to replace the shared vNEXT block - Pull requests running side by side were conflicting over a single shared `## vNEXT` block in docs/changelog.md, so entries now live in their own file under changelog/unreleased/ per branch. - scripts/changelog.mjs parses, validates and renders fragments into the version block a release writes, replacing the vNEXT logic previously baked into sync-version.sh. - Adds a Docker Build workflow that builds and smoke-tests the image on PRs into main, gated by maintainer approval, and extends Validate to also run on PRs into dev and build the website.

  • Manu(17 Sept 26)

    Link Preview and Branding Improvements, Security Updates and Bug Fixes (#74)

  • Manu(30 Jul 26)

    New Website, Branding & UX Improvements, Security Hardening, and Security Patches (#69) Co-authored-by: Syed Osama Ali Shah <[email protected]>

  • Manu(15 Jul 26)

    Render Turnstile explicitly in report form Switches the report form from implicit `cf-turnstile` auto-rendering with global callbacks to explicit `window.turnstile.render()` when the widget container exists. This fixes late-mounted React container timing issues, tracks script readiness, and adds cleanup by removing the widget and clearing the token on unmount or instance changes.

  • Manu(15 Jul 26)

    Add report worker deploy workflow Add a GitHub Actions workflow to deploy the Cloudflare report worker on pushes to main when the worker or workflow file changes, mirroring the existing instances worker pipeline. Update the changelog to document the new CI/CD deployment automation.

  • Manu(15 Jul 26)

    Add report worker to monorepo Moves the abuse report Cloudflare Worker into `workers/report` with its own Wrangler config, TypeScript setup, and email handling entrypoint.

  • Manu(15 Jul 26)

    Add security headers and home canonical URL Adds a `website/public/_headers` file to enforce clickjacking, MIME sniffing, and referrer protections at the edge. Also sets homepage metadata with a canonical `/` alternate to improve SEO consistency and avoid duplicate URL indexing.

  • Manu(15 Jul 26)

    Disable ProductTour, clarify OIDC/SSO docs Remove the ProductTour component from the homepage since the live Server Instances section now provides a better experience for visitors to test a real public instance. Update the account creation FAQ to clarify that self-hosters can optionally require OIDC/SSO login to restrict private instances to their organization.

  • Manu(15 Jul 26)

    Refresh website instance cards Add country flag icons and a redesigned instance card layout with clearer status, service, and action affordances. Reorder the homepage sections, swap the favicon to the logo, and add GitHub star milestones to the roadmap.

  • Manu(15 Jul 26)

    Add public marketing website Adds a new Next.js 16 website package (`@skysend/website`) to the pnpm workspace. The site includes a homepage (hero, stats, features, product tour, FAQ, blog teaser), a /roadmap page, a /blog with MDX posts, and a /report abuse page. Builds as a static export for deployment on Cloudflare Workers via Wrangler.

  • Manu(21 Jun 26)

    Docs: enforce Argon2id KDF and miscellaneous updates Reflect changes for v2.11.x: remove PBKDF2 fallback and document Argon2id as the sole password KDF across docs and package comments; update NOTE_VIEW_OPTIONS/NOTE_DEFAULT_VIEWS to include 0 (unlimited) in .env.example and env docs; increase supported code languages from 22 to 43; add /api/quota endpoint and bump example client/health versions to v2.11.3; update SQLite path to data/db/skysend.db and add pt-BR/ja locales to the translations list. These edits keep documentation, examples, and inline comments consistent with the current implementation and defaults.

  • Manu(21 Jun 26)

    Dependency Updates and Bug Fixes (#63)

  • Manu(21 Jun 26)

    Bump versions to v2.11.3 and update changelog Prepare and publish v2.11.3: update package version numbers across the monorepo (root, apps/cli, apps/client, apps/server, apps/web, docs, packages/crypto), sync the client runtime APP_VERSION constant, and update docs/changelog.md with the release title, date, and Docker tag changes. This release covers dependency updates and bug fixes.

  • Manu(21 Jun 26)

    Bump commander, @types/node, fflate, typography Upgrade various dependencies across the monorepo: commander -> v15, @types/node -> v26, fflate -> v0.8.3, and @tailwindcss/typography -> v0.5.20. Updated package.json files for apps/cli, apps/client, apps/server, and apps/web, refreshed pnpm-lock.yaml, and noted the changes in docs/changelog.md.

  • Manu(21 Jun 26)

    Bump multiple dependencies across monorepo Update dependency versions across several packages and the lockfile. Notable bumps: ink -> 7.1.0 (apps/client), AWS SDK v3 packages -> 3.1073.0 and s3 presigner (apps/server), better-sqlite3 -> 12.11.1, Radix UI react-select/slot/switch -> newer minor versions, lucide-react, react-router-dom, eslint and typescript-eslint, @cloudflare/workers-types and wrangler (workers/instances). Also update pnpm-lock.yaml and add a brief CI/CD note in docs/changelog.md. Affects apps/client/package.json, apps/server/package.json, apps/web/package.json, workers/instances/package.json, package.json, pnpm-lock.yaml, and docs/changelog.md.

  • Manu(21 Jun 26)

    Bump deps; update @hono/node-server Patch-level dependency bumps across the monorepo (tsx, react/react-dom, @radix-ui components, react-i18next, i18next, idb-keyval, tailwindcss, vitest, prettier, and related type definitions). Updated package.json files in apps/cli, apps/client, apps/server, apps/web, docs, and the root, regenerated pnpm-lock.yaml, and updated the changelog. Notably upgraded @hono/node-server to 2.0.5 to address a serve-static middleware path-prefix bypass on Windows.

  • Manu(21 Jun 26)

    Bump deps and add pnpm security overrides Bump several dependencies and add pnpm overrides to address security advisories. Updates include hono -> 4.12.26 (apps/server), dompurify -> 3.4.11 and vite -> 8.0.16 (apps/web), plus changelog entry documenting the security fixes. Root package.json and pnpm-lock.yaml were updated to add overrides for ws, miniflare>undici, tsx>esbuild, wrangler>esbuild, @babel/core and to tighten vitepress>vite, with corresponding lockfile resolution updates.

  • Manu(06 Jun 26)

    Raise Node keepAliveTimeout; update changelog Set nodeServer.keepAliveTimeout to 120s in apps/server/src/index.ts to avoid intermittent 500/502 errors when reverse proxies (e.g. Traefik with a 90s idle timeout) reuse closed keep-alive sockets. Comment explains keeping headersTimeout at 60s preserves Slowloris protection while letting the proxy control connection lifecycle. Also add a vNEXT entry to docs/changelog.md documenting the bug fix and Docker image/tagging/platform details.

  • Manu(05 Jun 26)

    Build workspace deps before typecheck Ensure type checking resolves cross-package types by building workspace libraries first: update package.json "typecheck" to run builds for @skysend/crypto and @skysend/server before the recursive typecheck. Remove the redundant pnpm build step from .github/workflows/validate.yml. Update changelog to document the change.

  • Manu(05 Jun 26)

    Add typecheck scripts; fix note view update Add `typecheck` (tsc --noEmit) scripts to multiple packages (apps/cli, apps/client, apps/server, packages/crypto, workers/instances) so CI and `pnpm validate` will type-check the whole monorepo. Fix server note route to safely handle an empty update result by assigning `result[0]` to `updated`, returning 410 when absent, and using `updated.viewCount` in the response. Also update the changelog to note the CI/CD change.

  • Manu(05 Jun 26)

    Cache-Control Fiexes & View Count Bug Fix (#60)

SkySend Security

Security Advisories (2)

  • highPatchedCVSS 7.5

    GHSA-9rmm-v3p2-c26gChunk upload endpoint buffers the whole request body in memory before checking its size, and is exempt from rate limiting (unauthenticated memory exhaustion)

  • lowPatchedCVSS 2.4

    GHSA-w3p6-2vcf-mmv9Truncated downloads are accepted as complete files (expectedPlaintextSize is never passed to createDecryptStream)

SkySend Website

Website

SkySend - End-to-End Encrypted File & Note Sharing

End-to-end encrypted, self-hostable file and note sharing service built for speed and security.

Redirects

Does not redirect

Security Checks

2 security checks failed (63 passed)

  • Domain Recently Created
  • Domain Very Recently Created

Server Details

  • IP Address104.21.18.28
  • LocationSan Francisco,California,United States of America,NA
  • ISPCloudFlare Inc.
  • ASNAS13335

Associated Countries

  • USUS
  • CHCH

Safety Score

Website marked as safe

100%

Blacklist Check

skysend.app was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

SkySend Reviews

More Secret Sharing

About the Data: SkySend

Change History

Edit SkySend Data

You can edit SkySend's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external sources, a list of these can be found data documentation.

Origin Data

Modify Data

API

You can access SkySend's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/skysend

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share SkySend

Help your friends compare Secret Sharing, and pick privacy-respecting software and services.
Share SkySend and Awesome Privacy with your network!