Skip to content

QtPass 2.0.0-rc1

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 24 Sep 21:07
· 28 commits to main since this release
v2.0.0-rc1
5ab26e3

Release candidate for QtPass 2.0. Please test it and report problems in #1812 or as new issues. Translations are in string freeze on Weblate until the final release.

Downloads: Windows installer (.exe), macOS (.dmg), Linux AppImage (x86_64, glibc 2.39+), and source archives. 2.0 needs Qt 6.8 or newer; the 1.8 line (1.8.2) stays available for Qt 5 and older Qt 6.

Worth testing in particular: the first-run wizard, switching profiles and initialising a new store, re-encryption, Ctrl+Q / Ctrl+W and the tray, the AppImage on a Wayland desktop, the Windows WSL setup, and macOS.

Upgrade notes

  • Qt 6.8 or newer. Qt 5 support ended with 1.8; qmake refuses older Qt
    with a clear message. Packagers building 1.8.x against Qt 5 need the
    1.8 branch for that.
  • Ctrl+Q quits. It used to close the window, which with "hide on close"
    meant hiding to the tray; that is Ctrl+W (File ▸ Close window) now. The
    window close button and Alt+F4 behave as before.
  • The menu bar is off by default so the window looks as it did. Alt
    shows it for as long as it is used, so Alt+F and the other mnemonics work;
    Ctrl+M, Settings ▸ Show menu bar or the tray menu keep it on, and the
    choice is remembered. On macOS the bar is the system's and always there.
  • Settings moved, stored values did not. Clipboard and panel autoclear
    are one number each (0 is "Never"), the two template checkboxes are one
    choice, and "Show menu bar" / "Show process output" are toggles in the
    Settings menu instead of the settings dialog. Existing configuration files
    are read and written with the same keys.
  • Generating a GPG key asks for a passphrase. Leaving the fields empty
    used to produce an unprotected private key silently; now OK waits until a
    passphrase is typed twice or "No passphrase" is ticked on purpose.
  • A link inside the store is not part of it. A symbolic link or NTFS
    junction found in the store (a shared repository can carry one) is skipped
    by re-encryption and search and refused by show, edit, add, move, copy and
    re-key, with a message; deleting one removes the link. The configured
    store root itself may still be a link. See SECURITY.md.
  • Debug output comes from the qtpass logging category in every build:
    QT_LOGGING_RULES="qtpass.debug=true" turns it on, no debug build needed
    (see the FAQ). The #ifdef QT_DEBUG tracing is gone.
  • Linux AppImage: new, attached to every release; needs glibc 2.39 or
    newer (Ubuntu 24.04, Debian 13, Fedora 40). It bundles Qt only and uses the
    system's pass, gpg and git.
  • Packagers: the AppStream metainfo installs as
    org.qtpass.QtPass.metainfo.xml (was qtpass.appdata.xml); main/main.pro
    installs the desktop file, metainfo, icons and man page; the RPM spec
    follows; the Flatpak manifest drops rename-appdata-file with the 2.0 tag.
  • Still true from 1.8: the macOS .dmg is not signed or notarized (see the
    macOS page, #1542)
    and the Windows installer is not code-signed (#1643).

The full list of changes is in CHANGELOG.md.