Attachments
Attach files to an item from the Attachments tab, a comment’s composer, drag-and-drop onto the section, or by pasting a screenshot.
- Images (PNG, JPEG, GIF, WebP) render as a thumbnail gallery; click for a lightbox preview with download and delete. SVG never renders inline — it stays a download card by design (it can carry scripts).
- Documents appear as cards with an extension chip, size, uploader, and date.
- Uploads stage through a queue: cancel while waiting, retry on failure, and oversize files (>10 MB) are rejected inline before any upload starts.
- Deleting confirms first and is recorded in the item’s activity history.
All file bytes flow through authorization-checked API routes — there are no public bucket URLs.
Safety scanning
Section titled “Safety scanning”When scanning is enabled for your workspace’s deployment, every new upload is checked before anyone can download it:
- Scanning… — the file was just uploaded and is being checked. This usually takes seconds; the download appears when it finishes.
- Blocked — the file failed the safety scan and can never be downloaded.
- Unavailable — the file could not be scanned. Re-uploading usually helps; otherwise ask a workspace admin.
The project Files view shows the same states. The check happens on the server for every download, whatever the page shows.