Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 7 additions & 8 deletions .github/RELEASE_NOTES_v0.1.0.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@

**Silo is the mod manager Farming Simulator 25 should have shipped with** — a
fast, native desktop app that organizes your FS25 mod library, tells you which
mod crashed you, catches conflicts before they bite, and pulls ModHub, GitHub,
and Nexus into one honest catalog — without ever touching your saves
mod crashed you, catches conflicts before they bite, and pulls ModHub and GitHub
into one honest catalog — without ever touching your saves
destructively. Free, open source, Windows · macOS · Linux.

## Highlights
Expand All @@ -16,11 +16,11 @@ destructively. Free, open source, Windows · macOS · Linux.
instant crash), plus colliding fill types, vehicle types, and scripts across
your active set — with severity and the mods involved.
- **One honest catalog across every source.** Browse a single canonical record
per mod aggregating ModHub + GitHub + Nexus, with the real latest version
per mod aggregating ModHub + GitHub, with the real latest version
across all of them. Search, filter, and sort by popularity, downloads, or
rating — no more false "outdated" flags from mismatched sources.
- **Act through your own accounts.** Star or watch a repo on GitHub, endorse on
Nexus, or deep-link to ModHub to rate — Silo brokers the action and keeps none
- **Act through your own accounts.** Star or watch a repo on GitHub, or deep-link
to ModHub to rate — Silo brokers the action and keeps none
of your credentials.
- **Loadouts, projected safely.** Curate profiles and project only the active set
into the game's flat `mods/` folder at launch via symlink/junction — never by
Expand All @@ -42,9 +42,8 @@ filltype-compatibility bridge generator, and savegame backup.
## Beta — known limits

- **Auto-update isn't in yet** — grab new releases from this page for now.
- **ModHub and Nexus are index + deep-link** — Silo shows their versions and
opens the page (their CDNs gate direct downloads). In-app install works for
GitHub-hosted mods.
- **ModHub is index + deep-link** — Silo shows its version and opens the page
(its CDN gates direct downloads). In-app install works for GitHub-hosted mods.
- **Catalog coverage is still filling in** — the cross-source catalog is growing;
some mods may not be indexed yet.

Expand Down
3 changes: 0 additions & 3 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,3 @@ Thumbs.db
# Internal-only docs — strategy, competitive analysis, launch/ops prep. Kept locally
# for the maintainer + Cowork; never published to the public repo.
docs/internal/

# Nexus Mods upload package — staged installers + page assets, built locally, never published.
nexus-upload/
29 changes: 17 additions & 12 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,17 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [0.7.3] - 2026-08-12

### Removed

- **Nexus Mods integration has been removed entirely.** Silo's catalog now aggregates **ModHub and
GitHub** only. Nexus support flagged our SiloAPI index model as an Acceptable-Use-Policy violation
on a second review — after approving the same approach on the first — so rather than keep
rebuilding toward a moving compliance target for a minor Farming Simulator source, we pulled Nexus
out completely: the app's Browse and per-source UI, the SiloAPI catalog ingest, the website, and
the docs. No Silo feature depended on it.

## [0.7.2] - 2026-08-11

### Added
Expand Down Expand Up @@ -126,12 +137,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- **Browse caches each view, so going back to one is instant.** Revisiting a filter/sort combo
you've already loaded no longer re-polls the catalog — results (and everything you'd paged in)
come straight from an in-session cache.
- **Nexus Mods is now strictly index-only, per Nexus's Acceptable Use Policy.** Removed the
"connect your Nexus account" flow, the personal-API-key storage, and mod endorsing, along with
every live Nexus API call the app made. Nexus metadata now comes from the catalog, and Silo
links back to the mod page for the download — it never queries Nexus directly or handles a key.
(Per-user features like endorsing will return later via the sanctioned OAuth2 flow.)

## [0.6.0] - 2026-08-06

### Fixed
Expand All @@ -148,7 +153,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
combine), plus an **"available by year"** filter for period-correct playthroughs (only machines
that existed by that year). A mod's tags also show in its detail drawer.
- **The library detail drawer now shows catalog info** — a mod's summary (clamped, with **Read
more** for the full text), where it's **available** (ModHub / GitHub / Nexus, with links), and
more** for the full text), where it's **available** (ModHub / GitHub, with links), and
whether it's **outdated** (⬆ update available vs. ✓ up to date). No more hopping to Browse to
find out if a library mod has a newer version.
- **An "updates" filter in the stat bar.** After running ⟳ Updates, a gold **N updates** chip
Expand Down Expand Up @@ -244,7 +249,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
are uploaded, only the list — each mod pinned to a version and a content hash). Anyone you send it
to can paste that link — gist *or* `github.com/owner/repo` — into "Open a shared link" to preview
exactly what they already have, what's a different version,
what Silo can install for them, and what they'll need to grab from ModHub/Nexus — plus a heads-up
what Silo can install for them, and what they'll need to grab from ModHub — plus a heads-up
for any dependency gaps or mod conflicts among the mods they already have — then import it:
Silo downloads the installable mods, verifies each against the shared build (verified / modified),
and saves the whole set as a loadout to apply. Sharing needs a one-time "Enable collection sharing"
Expand Down Expand Up @@ -293,7 +298,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
### Security

- **Warn when credential storage isn't encrypted.** On a machine with no OS keychain, connecting
a GitHub/Nexus account falls back to storing the token in the local database. Settings now
a GitHub account falls back to storing the token in the local database. Settings now
probes keychain availability and shows a clear warning above the account sections so it's never
a silent fallback — the user decides before connecting. (#20)

Expand Down Expand Up @@ -446,14 +451,14 @@ First public beta.
"sugar beet" fix), with no vehicle edits. Output is per-user and reversible.
- **Savegame backup** — copies saves to a backup folder before edits.
- **Cross-source catalog (Browse)** — one canonical record per mod aggregating
ModHub + GitHub + Nexus (backed by SiloAPI), with search, category filter,
ModHub + GitHub (backed by SiloAPI), with search, category filter,
sort (popular / downloads / rating / newest / name), and pagination past the
result cap. In-app GitHub install with a streaming progress bar; ModHub/Nexus
result cap. In-app GitHub install with a streaming progress bar; ModHub
are index + open-page.
- **Catalog-routed update checking** — checks the whole library against the
catalog's real latest-across-sources, fixing the GitHub-vs-ModHub false
"outdated" reports; per-mod update status also shown in the detail drawer.
- **Per-source interaction** — star/watch a repo on GitHub, endorse on Nexus, and
- **Per-source interaction** — star/watch a repo on GitHub and
deep-link to the ModHub page to rate — all through *your own* accounts. Silo
brokers the action and holds none of your credentials.
- **Cross-platform** — Windows, macOS, and Linux, with per-OS projection and
Expand Down
8 changes: 4 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@

A desktop app for your FS25 mod library that stays quick at 700+ mods. Silo reads the
game log to name the mod that crashed you, flags conflicts before you launch, and shows
the latest version it can find across ModHub, GitHub and Nexus. Everything it changes on
the latest version it can find across ModHub and GitHub. Everything it changes on
disk is reversible. **Free and open source. Windows (tested) · macOS & Linux (experimental).**

<p align="center">
Expand Down Expand Up @@ -48,21 +48,21 @@ is the management layer the game left out.
and names the mod at fault.
- **Conflict detection** — duplicate active maps (an instant crash), plus colliding
filltypes, vehicle types and scripts across your active set.
- **Cross-source catalog** — one record per mod aggregating ModHub + GitHub + Nexus,
- **Cross-source catalog** — one record per mod aggregating ModHub + GitHub,
with the latest version found across all of them. See the
[verified catalog page](https://silo.hllmr.com/trust/) or
[browse it live](https://silo.hllmr.com/browse/); it's served by the public
[SiloAPI](https://silo-api.hllmr.com) read API.
- **Integrity check** — hashes an installed mod and compares it to the trusted build its
source published: a clean match, or the exact files that changed. Provenance, not
antivirus — it confirms what a mod is, not whether it means well. It works across
ModHub, GitHub and Nexus — a cross-source integrity check that's rare among mod tools.
ModHub and GitHub — a cross-source integrity check that's rare among mod tools.
- **Guided bisection** — when the log can't name the culprit, automates "disable half,
relaunch" to isolate it, and safely restores your active set afterward.
- **Loadouts & projection** — curate profiles and project only the active set into the
game's flat folder at launch, via symlink/junction. Organizing files your zips into a
reversible local archive; Flatten puts everything back.
- **Per-source actions** — star a repo on GitHub, endorse on Nexus, rate on ModHub, all
- **Per-source actions** — star a repo on GitHub, rate on ModHub, all
through *your own* accounts. Silo just opens the door; your credentials stay yours.
- **Multiplayer sync**, a **filltype-compatibility bridge generator**, **savegame backup**,
and a full **control-binding map**.
Expand Down
11 changes: 5 additions & 6 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,14 +37,13 @@ stay anonymous).
- Silo's outbound network calls. Silo talks to:
- **`silo-api.hllmr.com`** — the SiloAPI catalog backend, for cross-source mod
metadata.
- **GitHub, Nexus, and ModHub** — reached **through the user's own accounts
and credentials** (e.g. an OAuth token to star a GitHub repo, or endorse on
Nexus). Silo brokers the action; it does not hold or proxy your credentials
on any server of ours.
- **GitHub and ModHub** — reached **through the user's own accounts
and credentials** (e.g. an OAuth token to star a GitHub repo). Silo brokers
the action; it does not hold or proxy your credentials on any server of ours.

**Generally out of scope:**

- Vulnerabilities in FS25 itself, GIANTS software, GitHub, Nexus, or ModHub —
- Vulnerabilities in FS25 itself, GIANTS software, GitHub or ModHub —
report those to the respective vendor. (A flaw in how *Silo* interacts with
them is in scope.)
- Issues that require a machine already compromised by a local attacker, or that
Expand All @@ -58,7 +57,7 @@ stay anonymous).
Silo has **no analytics, no telemetry, and no account system** — there is
nothing to sign up for and nothing phones home about your usage. Its only
outbound traffic is the catalog lookups to `silo-api.hllmr.com` and the
per-source actions you explicitly trigger through your own GitHub / Nexus /
per-source actions you explicitly trigger through your own GitHub /
ModHub credentials. This is intentional and part of the app's trust model; a
change that quietly adds tracking or exfiltrates data would itself be treated as
a security issue.
Expand Down
8 changes: 4 additions & 4 deletions docs/COLLECTIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ A collection is metadata + a mod list + optional savegame binding. Extends the e
"source": "github", // preferred source for this mod
"sourceUrl": "https://github.com/.../releases/tag/v1.0.2.9",
"manifestHash": "9fea10cd…", // canonical hash (provenance), when known
"installable": true // false → importer opens the page (ModHub/Nexus)
"installable": true // false → importer opens the page (ModHub)
}
// …
]
Expand Down Expand Up @@ -85,7 +85,7 @@ phase; secret-gist link-sharing covers the MP use case without it.
1. Paste a gist/repo URL (or, Phase 3, pick from Browse Collections).
2. Fetch the manifest, resolve each mod against the catalog.
3. **Preview** (organize-preview pattern): what will install (GitHub-source), what needs a manual
"open the page" step (ModHub/Nexus), what's already present, and — via provenance — which
"open the page" step (ModHub), what's already present, and — via provenance — which
resolved mods verify against the collection's declared hashes.
4. Install the installable set, then create/apply a loadout (bound to the savegame if present).
5. **MP path:** `mpsync` diffs the host's manifest against the joiner's library and shows the
Expand Down Expand Up @@ -119,9 +119,9 @@ competitor can follow — it rides the same cross-source hash DB that is the moa
## Caveats to message honestly

- **"Private" = unlisted link, not auth-gated** (v1). Say so.
- **ModHub/Nexus mods = guided import**, not one-click (their CDNs gate downloads). GitHub-source
- **ModHub mods = guided import**, not one-click (their CDNs gate downloads). GitHub-source
collections are the frictionless ones — worth nudging authors toward GitHub releases.
- **Version drift:** a collection pins versions; a ModHub/Nexus latest-only source may no longer
- **Version drift:** a collection pins versions; a ModHub latest-only source may no longer
serve the pinned build → provenance correctly reports "the pinned version is gone" (not a bug).
GitHub release assets persist, so GitHub-source collections age best.
- **Writing to a user's GitHub account is trust-sensitive:** creation must be explicit, consented,
Expand Down
9 changes: 4 additions & 5 deletions docs/COLLECTIONS_WIRING.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,7 @@ struct Collection {
struct CollectionMod {
tech_name: String,
version: Option<String>,
source: Option<String>, // "github" | "modhub" | "nexus" — preferred
source: Option<String>, // "github" | "modhub" — preferred
source_url: Option<String>, // page/release URL for the open-page branch
manifest_hash: Option<String>, // canonical provenance hash, when known
installable: Option<bool>, // false → importer opens the page
Expand Down Expand Up @@ -175,7 +175,7 @@ All `spawn_blocking`, `secrets::get(&conn,"gh_token")` for the token, registered
`ALTER TABLE loadout ADD COLUMN savegame_folder TEXT`, ignore-dup pattern `db.rs:138`).
Optionally `set_active` to project it.
- Open-page mods are saved into the loadout by techName, flagged "not installed —
get from ModHub/Nexus."
get from ModHub."
- **MP path:** the joiner can additionally run `mpsync::diff` (manifest vs. local
hashed set) for the four-bucket fix-list — `mp_verify_file` shape unchanged; the
collection's per-mod `version`+`hash` *are* `ManifestEntry` fields.
Expand Down Expand Up @@ -232,13 +232,12 @@ All `spawn_blocking`, `secrets::get(&conn,"gh_token")` for the token, registered
6. **Savegame binding persistence** — recommend a nullable `savegame_folder` column
on `loadout` (additive migration) over a separate table.
7. **`dir`/dev mods in an export** — recommend warn-and-omit for a shareable artifact.
8. **Version drift on ModHub/Nexus pins** — confirm the preview shows "pinned
8. **Version drift on ModHub pins** — confirm the preview shows "pinned
version no longer served → open page for latest" as correct behavior, not an error.

## Coverage / expectations

- Provenance verifies most rows by ModHub build (P3 live, ~6,300 versions,
popular-first; **96% of real installs are ModHub-latest**). GitHub P1 (~128/141);
Nexus provenance still deferred (page-link flow, files not downloadable).
popular-first; **96% of real installs are ModHub-latest**). GitHub P1 (~128/141).
- `mpsync` loads whole zips into RAM for MD5 — fine now, a noted scaling edge for
big-map collections (streaming is a deferred improvement).
2 changes: 1 addition & 1 deletion docs/DECISIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,6 @@ conflict primitive; six namespace surfaces drive conflict detection; saves carry
`required` + `fileHash` per mod. See `reference/fs25-modding-notes.md`.

## 2026-07-14 — Working title "Silo"
**Context:** need a name comparable-in-ambition to Nexus Mod Manager but without
**Context:** need a name comparable-in-ambition to the big mod managers but without
"mod manager" in it. **Decision:** working title **Silo** (a silo = organized,
sealed, retrievable farm storage). Revisit before any public release.
4 changes: 2 additions & 2 deletions docs/RC_TESTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -139,7 +139,7 @@ identity-check the bytes: when the catalog has a canonical hash for the mod (Git
download whose bytes don't match is refused. Verify: **the `.part` temp disappears after every
failure**, **no bad archive ever enters the library**, and the **wrong-valid-mod** case is
**rejected** for a hashed (GitHub) mod (swap the asset → "doesn't match the catalog's known
build"). For an *unhashed* source (ModHub/Nexus/not-yet-hashed) identity can't be proven — only
build"). For an *unhashed* source (ModHub/not-yet-hashed) identity can't be proven — only
archive validity — so confirm that path degrades to the validity check, not a false rejection.

### D. User-ownership conflicts — the most important regression
Expand All @@ -158,7 +158,7 @@ Forensic-diff after each — the user's file must survive every branch.
### E. Degraded network

- No internet at startup · SiloAPI unreachable · SiloAPI returns malformed JSON · catalog image
host down · GitHub down · Nexus down · requests time out · rapid repeated searches · app closed
host down · GitHub down · requests time out · rapid repeated searches · app closed
mid-request.

The **library and diagnostics must stay usable.** Network failure degrades *features*, never
Expand Down
Loading
Loading