CladeForge
Abstract
CladeForge 0.1.0 — first public release. CladeForge is a local-first, cross-platform desktop application for building, annotating and exporting phylogenetic trees with an integrated evolutionary semantic layer: the tree is treated as a hypothesis scaffold you can construct, compare and refine offline. Built on Tauri v2 + React 18 + TypeScript + Vite with a Rust backend. What this release does Tree editing (binary / ternary / polytomy, reroot, collapse, ladderize), four layouts (cladogram, phylogram, time-calibrated with geological era bands, circular) and four orientations Discrete and continuous characters with colour-blind-safe palettes and Sankoff step matrices 15 built-in evolutionary event types across six groups, with two-letter badge codes and causal chains Competing hypothesis layers on a shared topology Advisory inference: Sankoff parsimony, Mk/ER ancestral-state reconstruction (log-space), consistency checks, character-correlation hints, DTL gene-tree/species-tree reconciliation Import Newick/Nexus (NHX round-trip); export SVG/PNG/PDF with auto-generated legends, reproducible R scripts, and versioned .cladeforge.json projects (schema 0.1.0) Fully bilingual interface (English / 中文); no network access and no AI inference inside the app Assets in this release | File | Platform | Notes | |------|----------|-------| | CladeForge_0.1.0_aarch64.dmg | macOS 11+, Apple Silicon | 4.6 MiB installer image; 12.4 MiB installed bundle. Built from this tag. | Known limits of this release Only the macOS arm64 installer is published here. No Windows or Linux build has been produced yet, so the disk figures for those platforms in the README are marked "not yet measured". To build them: npm ci && npm run tauri build on the target platform. The bundle is ad-hoc signed, not notarised (no Apple Developer ID). On first launch macOS may refuse to open it. Resolve with Finder → right-click CladeForge.app → Open, or xattr -d com.apple.quarantine /Applications/CladeForge.app. The app renders into the operating system's own web view (WKWebView / WebView2 / WebKitGTK), which must be present on the host. No other runtime is required. Verification at this tag npm run typecheck passes; the Vitest suite reports 814 passed / 6 skipped across 51 files; cargo test passes (11 tests) and cargo clippy --all-targets -- -D warnings is clean. GitHub Actions runs the same gates on every push to main. Security status of bundled dependencies npm audit still reports four advisories at this tag. They need major dependency upgrades, so they are disclosed here rather than applied under a released version number: | Package | Advisory | Relevance to CladeForge | |---------|----------|-------------------------| | jspdf@2.5.2 | ReDoS, DoS, and a local-file/path-traversal issue (critical) reachable through its HTML/image loading API | PDF export never uses that API: the app builds its own SVG and hands it to svg2pdf.js (.svg()), passing no HTML or external URLs to jsPDF | | dompurify@2.5.9 (transitive, via jsPDF) | Several XSS-sanitisation bypasses | Only loaded by jsPDF's html() path, which this application does not call | | vite@5.4.21, esbuild (build-time) | Dev-server only: server.fs.deny bypass on Windows alternate paths, dev-server request handling | No dev server ships in the packaged app; these are development-time exposures | Migrating jspdf to 4.x and vite to 8.x is the follow-up work for the next release. Already fixed at this tag: the postcss → nanoid path-traversal advisory in the build chain (3.3.16 → 3.3.19, no change to the shipped bundle). Documentation User Manual (English) · 用户手册(中文) Contributing guide · 贡献指南 Third-party cross-check against ape / phangorn: scripts/cross-check Citation No journal citation is available yet. If CladeForge contributes to your work, please cite the repository together with the version you ran: 曾子超 (Zichao Zeng), 2026. CladeForge (Version 0.1.0) [Computer software]. https://github.com/ZengZichao/CladeForge — ORCID 0000-0001-6553-970X 中文说明 CladeForge 0.1.0 是首个公开发布版本:一款本地优先、跨平台的桌面应用,用于构建、注释和导出 带有演化语义层的系统发育树,把系统发育树当作可以搭建、比较和打磨的"假说脚手架"。技术栈为 Tauri v2 + React 18 + TypeScript + Vite,后端为 Rust。 本版本能力 树的交互编辑(二叉/三叉/多叉、重新定根、折叠、梯形化),四种布局(支序图、系统发育图、 带地质年代条带的时间校准图、圆形图)与四种方向 离散与连续性状,色盲友好配色,支持桑科夫步矩阵 六个分组共 15 种内置演化事件类型,带二字徽章代号与因果链 共享拓扑上的多个竞争性假说层 建议性推理:桑科夫简约法、Mk/ER 祖先状态重建(对数空间)、一致性检查、性状相关性提示、 DTL 基因树/物种树协同重建 导入 Newick/Nexus(NHX 无损往返);导出 SVG/PNG/PDF(自动生成图例)、可复现的 R 脚本, 以及带版本号的 .cladeforge.json 项目文件(架构 0.1.0) 界面完全双语(英文 / 中文);应用内不联网、不含任何 AI 推理 本版本附件 | 文件 | 平台 | 说明 | |------|------|------| | CladeForge_0.1.0_aarch64.dmg | macOS 11 及以上,Apple Silicon | 安装镜像 4.6 MiB,安装后应用包 12.4 MiB;由本标签构建 | 本版本的已知边界 此处只发布 macOS arm64 安装包。 Windows 与 Linux 构建尚未产出,因此 README 中这两个平台的 磁盘占用标注为"尚未实测"。如需其他平台,请在目标系统上执行 npm ci && npm run tauri build。 应用为 ad-hoc 签名,未经 Apple 公证(无 Developer ID)。首次打开可能被 macOS 拦截: 在访达中右键 CladeForge.app → 打开,或执行 xattr -d com.apple.quarantine /Applications/CladeForge.app。 应用使用操作系统自带的 web 视图渲染(WKWebView / WebView2 / WebKitGTK),宿主机需提供对应组件; 不需要其他任何运行时。 本标签的验证情况 npm run typecheck 通过;Vitest 套件 51 个文件、814 项通过、6 项跳过;cargo test 通过(11 项); cargo clippy --all-targets -- -D warnings 无告警。GitHub Actions 在每次推送到 main 时执行同一组门禁。 打包依赖的安全状态 本标签上 npm audit 仍报出四条公告。它们都需要主版本升级,因此在这里如实说明,而不在已发布的版本号下改动依赖: | 依赖 | 公告 | 与 CladeForge 的关系 | |------|------|----------------------| | jspdf@2.5.2 | ReDoS、DoS,以及经由其 HTML/图片加载路径的本地文件读取(critical) | PDF 导出不走该路径:应用自己生成 SVG,再交给 svg2pdf.js(.svg()),不向 jsPDF 传入任何 HTML 或外部 URL | | dompurify@2.5.9(经 jsPDF 间接引入) | 多个 XSS 过滤绕过 | 仅在 jsPDF 的 html() 路径中被加载,本应用不调用该 API | | vite@5.4.21、esbuild(构建期) | 仅限开发服务器:Windows 备用路径绕过 server.fs.deny、开发服务器请求处理 | 打包后的应用不含开发服务器,属于开发期风险 | jspdf 升级到 4.x、vite 升级到 8.x 是下一个版本的后续工作。本标签已修复:构建链中 postcss → nanoid 的路径穿越公告(3.3.16 → 3.3.19,不改变应用产物)。 文档 用户手册(中文) · User Manual (English) 贡献指南 · Contributing guide 与 ape / phangorn 的第三方交叉验证: scripts/cross-check 引用 目前尚无可引用的论文条目。若 CladeForge 对你的工作有帮助,请引用本仓库并注明所用版本: 曾子超 (Zichao Zeng), 2026. CladeForge (Version 0.1.0) [计算机软件]. https://github.com/ZengZichao/CladeForge — ORCID 0000-0001-6553-970X