Skip to content

QtPass v1.8.0

Choose a tag to compare

@annejan annejan released this 13 Sep 20:21
· 299 commits to main since this release
v1.8.0
9816bf1

New Features

  • Built-in TOTP (RFC 6238): one-time passwords are now generated inside QtPass
    instead of shelling out to the pass-otp extension, so OTP works on every
    platform and with both the pass and direct gpg2/git backends. Store the
    configuration as an otpauth:// URI in the OTP template field; bare
    otpauth:// lines written by pass-otp are still read. The selected entry
    shows a live code with a copy button and a countdown, and
    SHA-1/SHA-256/SHA-512 plus Steam Guard codes are supported #1625
  • Share submenu on folders: re-encrypt, export your public key, add
    recipients, and a "What is this?" explainer #1144, #1162,
    closes #422
  • Import GPG keys from file or clipboard via the Users dialog #1170,
    closes #1167
  • Process output panel (dockable) with command labels, colour-coded errors,
    auto-scroll with hysteresis and a 1000-line cap #1172, #1193,
    closes #252
  • "Open in browser" button for URL fields in the password panel #1517,
    closes #1516
  • Manual SSH_AUTH_SOCK override with gpgconf auto-probe fallback
    #1438, closes #543
  • Opt-in content search across decrypted entries (regular expression)
  • Multiple templates via .templates files, auto-applied to new entries,
    Ctrl+T cycles between them #1141, #1142, #1143
  • Git options are stored per profile #1140, closes #112
  • All fields of an entry can be edited, not only the password #1138,
    closes #132
  • Status bar feedback while creating a profile #1136, closes #1034

Upgrade Notes

  • OTP support is now on by default, so upgrading shows live one-time-password
    codes for entries that contain an otpauth:// secret, even if you had it off
    before. The old setting only ever gated the Unix-only pass-otp extension,
    so its stored value was meaningless on Windows and macOS. To turn it off,
    uncheck Enable one-time password (OTP) support on the Settings tab of
    the configuration dialog; the choice is remembered and is not re-enabled on
    later launches. The upgrade changes only this setting — no stored passwords
    are read, rewritten, or re-encrypted.
  • macOS: the release .dmg is not signed or notarized, and the Homebrew cask
    was disabled by Homebrew on 2026-09-01 for that reason. Install the .dmg
    from the GitHub release and clear the quarantine flag
    (xattr -d com.apple.quarantine /Applications/QtPass.app). Status and how
    to help: the macOS page on qtpass.org and #1542.
  • Windows: the installer is not code-signed; SmartScreen asks for
    More info → Run anyway on first start #1643.
  • 31 single-variant locales were renamed to language-only codes (e.g.
    ar_MA → ar); Qt's locale fallback picks them up automatically
    #1328, #1350

Security

  • Path-traversal hardening for new file, rename and drag-and-drop targets
    #1464
  • .gpg-id is written with mode 0600 #1465
  • URLs are HTML-escaped in the password panel #1584
  • A TOTP shared secret is never rendered in cleartext, also when stored as an
    OTP: field, and Ctrl+C on an otpauth://-only entry no longer copies the
    seed #1625

Bugfixes

  • ConfigDialog no longer silently corrupts saved settings #1602
  • PasswordDialog: no content duplication or data loss on premature save
    #1605
  • ImitatePass Git re-encryption used the wrong recipients and working
    directory, and its copy operation was broken #1604
  • Executor could stall when a stdin-less command failed to start #1606;
    crashed subprocesses no longer hang the UI #1570
  • Use-after-free of the key-generation dialog pointer #1603; keygen start
    failures are reported instead of hanging #1599, closes #1598
  • Clipboard autoclear kept tracking the right entry when navigating #1607
  • The window follows light/dark theme switches at runtime (KDE day/night),
    including the toolbar, which Breeze kept in the previous theme
    #1669, #1661
  • A missing qrencode binary is reported instead of showing an empty QR
    dialog #1659
  • Close button quits when hide-on-close is off and a tray icon is present
    #1580
  • WSL: wslpath translation is a real call instead of a broken shell
    substitution #1569, closes #1509
  • Segfault chain on first launch (focusInput before init) #1187–#1191
  • Process output panel obscured the central widget #1192
  • Locale-aware QTranslator::load() so regional variants fall back correctly
    #1362
  • Plural agreement in the grep status message #1133, closes #1042
  • Coverity and clang-tidy findings (one real bug, bulk modernize/performance)
    #1096, #1100, #1432, #1435

Code Quality (umbrella #1508)

  • Split the Util grab-bag into PathValidator, SshAuthSock and TemplateIO, and consolidated StoreModel drag-drop #1514
  • Tightened the Pass interface: beforeExecute() hook, Move/Copy dedup, documented Grep regular-expression dialect, and PassBackendFactory #1513
  • Decomposed MainWindow into GrepSearchController, PasswordDisplayPanel, a UI watchdog, and StoreModel::rootIndexFor #1512
  • Introduced AppSettings + SettingsSerializer with a QtPassSettings::load()/save() facade, injected through the Pass/dialog layers; 70 dead getter/setter wrappers removed #1511
  • P1 audit sweep: executor crash, StoreModel guard, getKeysFromFile, profile sort order, reencryptPath init #1570, #1571, #1572

Tests

  • Test suites grew from 11 to 25: widget tests for MainWindow, ConfigDialog,
    KeygenDialog, TrayIcon, UsersDialog, PasswordDisplayPanel, Import/Export key
    dialogs; unit suites for Base32, TOTP, PassBackendFactory, UserInfo,
    ProfileInit; GPG end-to-end coverage for multi-recipient encryption,
    per-folder re-encryption and the decrypt-and-edit GUI flow
  • Tests run against an isolated settings directory instead of the user's live
    config #1662

Localization

  • 64 locales, 14 of them new since 1.7.0: Bengali, Hindi, Indonesian,
    Latvian, Lithuanian, Marathi, Persian, Punjabi, Slovenian, Swahili, Telugu,
    Thai, Urdu and Vietnamese. Most locales are complete apart from the strings
    added late in this cycle
  • Hundreds of reviewer-driven corrections across sr_Cyrl, hu, cy, et, pl,
    zh_CN, gl, sv, nl and others; mnemonic and placeholder audit tooling added
  • The strings added this cycle were pre-filled in 46 locales and left
    unfinished for native review on Weblate
    #1665, #1666, #1667,
    #1670
  • Weblate remains the place to translate: https://hosted.weblate.org/projects/qtpass/

Build / CI

  • macOS builds on Qt 6.11; Linux/Windows stay on Qt 6.8 LTS; Qt 5.15 still
    builds #1600
  • Doxygen download resilient to doxygen.nl outages #1538; zero-warning
    Doxygen enforced
  • super-linter v8 (clang-format 21), commitlint, .editorconfig, REUSE
    compliance badge
  • Dead Coverity integration removed #1544

Full Changelog