We have additional checks that also check the release assets to catch issues in dependencies etc, that part is not public.
45 karma · joined February 13, 2020
We have additional checks that also check the release assets to catch issues in dependencies etc, that part is not public.
We include very few dependencies, see: <https://help.obsidian.md/credits#Third+party+acknowledgement...>
Everything else is custom as we generally don't use existing frameworks and the large amount of baggage they carry. CodeMirror and Lezer we already used before Bases.
We also had someone from the EteSync/EteBase project take a look at the code before Obsidian Sync was released.
As others have already pointed out, Sync is not the only option to synchronize notes, Obsidian sync is just a convenience option.
For compliance, I am guessing you mean certs like SOC 2 / ISO 27001?, or what are you referencing? As we are a tiny company (6 people, not all full time) we just can't expense the time needed to get such a certificate.
A CM5 based editor is still available as "Legacy Editor" in the settings on desktop, to support older plugins.
Mobile was always using a CM6 editor, while desktop only got CM6 some time after that. Which is probably the source of the confusion.