Releases: abrignoni/GLEAPP
Release list
GLEAPP v2026.5.4
What's Changed
- Give the disk image a Retina background and centre its icons on the arrow by @Johann-PLW in #253
- Store the ExoPlayer cache flag in a column instead of calling Python from SQL by @abrignoni in #255
- Open the case connection with no statement cache on Python 3.11 and later by @abrignoni in #256
- Keep the context's counts until a row is written by @abrignoni in #257
- Keep the archive sources' row counts until a row is written by @abrignoni in #258
- Keep a scoped carve's hits inside their free runs by @abrignoni in #259
- Count the context's containers in one statement by @abrignoni in #260
- Index extracted rows by container and kind by @abrignoni in #261
- Open a container that gave nothing once, not on every pass by @abrignoni in #262
- Copy what a walked volume holds: cloud placeholders, holes, hard links and a room check by @abrignoni in #263
- Vendor qnxprobe 1.57 by @abrignoni in #264
- Version 2026.5.4 by @abrignoni in #265
Full Changelog: v2026.5.3...v2026.5.4
Which file to download
| Platform | File |
|---|---|
| Windows 10 or 11, 64-bit | -windows-x64-setup.exe (installer), or -windows-x64-portable.zip to run without installing |
| macOS, Apple silicon | -macos-arm64.dmg |
| macOS, Intel | -macos-x64.dmg |
| Linux, 64-bit | -linux-x64.tar.gz |
First launch
The macOS disk images are signed with a Developer ID and notarised by Apple, so they
open without a warning.
The Windows binaries are not signed yet, so SmartScreen says "Windows protected your
PC" the first time. Choose More info, then Run anyway. If you would rather not clear a
warning, run from source instead; the README has the steps.
Verify what you downloaded
SHA256SUMS.txt covers every binary in this release. On macOS or Linux, from the folder
you downloaded into:
grep <the file you downloaded> SHA256SUMS.txt | shasum -a 256 -c -Use sha256sum in place of shasum -a 256 on Linux. On Windows, in PowerShell:
(Get-FileHash -Algorithm SHA256 .\<the file you downloaded>).Hashand compare it with the line in SHA256SUMS.txt, which is lower case.
Linux
The build is made on Ubuntu 24.04, so it needs glibc 2.39 or newer and will not start on
an older distribution. The native desktop window needs a GTK or Qt webview toolkit that
pip does not install, and CI does not exercise it, so gleapp web in a browser is the
tested path there.
GLEAPP v2026.5.3
What's Changed
- Vendor qnxprobe 1.50 and open encrypted APFS volumes with their password by @abrignoni in #229
- Point the maps docs at GLEAPP Map Downloader by @abrignoni in #230
- List a flag made while tagging in the Flag filter at once by @charpy4n6 in #231
- Vendor qnxprobe 1.51 by @abrignoni in #232
- Vendor qnxprobe 1.52 by @abrignoni in #233
- Vendor qnxprobe 1.55 by @abrignoni in #234
- Show the 0 key on Clear cat by @charpy4n6 in #235
- Show a map, NSRL or Project VIC import's progress on the launcher by @charpy4n6 in #236
- Ask questions in GLEAPP's own window, not the browser's by @charpy4n6 in #237
- Say where appconfig and the hash store keep their files by @abrignoni in #238
- Correct the NSRL source named in the hashstore docstring by @abrignoni in #239
- Match the NSRL notes to NIST's own sources by @abrignoni in #240
- Require OpenCV 5.0, which the content model needs by @abrignoni in #244
- Correct the NSRL download, size and minimal-database notes by @abrignoni in #245
- Hide "Stored at" when the staged copy was never made by @charpy4n6 in #246
- Clear an earlier LAVA export's media before re-exporting into its folder by @charpy4n6 in #247
- Collapse Source storage on case open and show a long job message on hover by @charpy4n6 in #248
- Mark a file joined from an ExoPlayer cache as derived, not on the device by @charpy4n6 in #249
- Extract the media inside PDFs, web pages, MHTML and Safari web archives by @charpy4n6 in #250
- Use Project VIC's category codes: 0 is Non-pertinent, 5 is Uncategorized by @charpy4n6 in #251
- Version 2026.5.3 by @abrignoni in #252
Full Changelog: v2026.5.2...v2026.5.3
Which file to download
| Platform | File |
|---|---|
| Windows 10 or 11, 64-bit | -windows-x64-setup.exe (installer), or -windows-x64-portable.zip to run without installing |
| macOS, Apple silicon | -macos-arm64.dmg |
| macOS, Intel | -macos-x64.dmg |
| Linux, 64-bit | -linux-x64.tar.gz |
First launch
The macOS disk images are signed with a Developer ID and notarised by Apple, so they
open without a warning.
The Windows binaries are not signed yet, so SmartScreen says "Windows protected your
PC" the first time. Choose More info, then Run anyway. If you would rather not clear a
warning, run from source instead; the README has the steps.
Verify what you downloaded
SHA256SUMS.txt covers every binary in this release. On macOS or Linux, from the folder
you downloaded into:
grep <the file you downloaded> SHA256SUMS.txt | shasum -a 256 -c -Use sha256sum in place of shasum -a 256 on Linux. On Windows, in PowerShell:
(Get-FileHash -Algorithm SHA256 .\<the file you downloaded>).Hashand compare it with the line in SHA256SUMS.txt, which is lower case.
Linux
The build is made on Ubuntu 24.04, so it needs glibc 2.39 or newer and will not start on
an older distribution. The native desktop window needs a GTK or Qt webview toolkit that
pip does not install, and CI does not exercise it, so gleapp web in a browser is the
tested path there.
GLEAPP v2026.5.2
What's Changed
- Re-vendor qnxprobe 1.36 by @abrignoni in #196
- Recover deleted media from YAFFS2, JFFS2 and UBIFS volumes by @abrignoni in #197
- Update README and release page by @Johann-PLW in #198
- Find similar: matches and similar content, indexed in the background by @charpy4n6 in #200
- Clear the downloaded-from-the-internet mark so the Windows portable build opens by @abrignoni in #199
- Re-vendor qnxprobe 1.37 by @abrignoni in #201
- Let the release binary reach the browser interface when the window cannot start by @abrignoni in #202
- Reattach a folder source whose paths were recorded on another system by @abrignoni in #203
- Join the pieces of an Android app's ExoPlayer media cache by @abrignoni in #204
- Take key frames from a transport stream by reading it in order by @abrignoni in #205
- Sign and notarise the macOS release, and lay out its disk image by @Johann-PLW in #206
- Join an ExoPlayer DASH stream's segments from its cached manifest by @abrignoni in #207
- Put a DASH video and its audio in one file without re-encoding by @abrignoni in #208
- Combine every cached audio track, and read ExoPlayer caches through exoprobe by @abrignoni in #209
- Join HLS streams from their cached playlists by @abrignoni in #210
- Use the new GLEAPP logo by @abrignoni in #211
- Ingest Ex01, SMART, AFF and AFD acquisitions, and refuse L01 by @abrignoni in #212
- Ingest Apple disk images (.dmg, .sparseimage), and refuse encrypted ones by @abrignoni in #213
- Ingest segmented .dmg sets and sparse bundles by @abrignoni in #214
- Read encrypted Apple disk images with their password by @abrignoni in #215
- Find similar: show a spinner on the file being searched by @charpy4n6 in #217
- Play an intro video when GLEAPP opens, with a box to stop it by @abrignoni in #216
- Read FTK Imager AD-encrypted images with their password by @abrignoni in #219
- Stop test apps' background threads, and floor pillow-heif at 1.2.1 by @abrignoni in #218
- Name a Project VIC import after its JSON file by @charpy4n6 in #220
- Record that the installed app's OpenBLAS survives a fork under load by @abrignoni in #221
- Credit Kevin Pagano for the GLEAPP logo by @abrignoni in #222
- Index and list a source added while the case is busy by @charpy4n6 in #223
- Show the sliding stripe while a job's total is unknown by @charpy4n6 in #224
- Re-vendor qnxprobe 1.49 and ewfprobe 0.12.0: new images, private keys and BitLocker by @abrignoni in #225
- Measure the deep member's staged name, not the tmp path in front of it by @abrignoni in #227
- Carve the space outside every volume, and all of an image with no volume by @abrignoni in #226
- Version 2026.5.2 by @abrignoni in #228
New Contributors
- @Johann-PLW made their first contribution in #198
Full Changelog: v2026.5.1...v2026.5.2
Which file to download
| Platform | File |
|---|---|
| Windows 10 or 11, 64-bit | -windows-x64-setup.exe (installer), or -windows-x64-portable.zip to run without installing |
| macOS, Apple silicon | -macos-arm64.dmg |
| macOS, Intel | -macos-x64.dmg |
| Linux, 64-bit | -linux-x64.tar.gz |
First launch
The macOS disk images are signed with a Developer ID and notarised by Apple, so they
open without a warning.
The Windows binaries are not signed yet, so SmartScreen says "Windows protected your
PC" the first time. Choose More info, then Run anyway. If you would rather not clear a
warning, run from source instead; the README has the steps.
Verify what you downloaded
SHA256SUMS.txt covers every binary in this release. On macOS or Linux, from the folder
you downloaded into:
grep <the file you downloaded> SHA256SUMS.txt | shasum -a 256 -c -Use sha256sum in place of shasum -a 256 on Linux. On Windows, in PowerShell:
(Get-FileHash -Algorithm SHA256 .\<the file you downloaded>).Hashand compare it with the line in SHA256SUMS.txt, which is lower case.
Linux
The build is made on Ubuntu 24.04, so it needs glibc 2.39 or newer and will not start on
an older distribution. The native desktop window needs a GTK or Qt webview toolkit that
pip does not install, and CI does not exercise it, so gleapp web in a browser is the
tested path there.
GLEAPP v2026.5.1
What's Changed
- Say where to download, and repeat the unsigned warning on every release by @abrignoni in #192
- Fix the macOS build, and smoke-test the import that starts the app by @abrignoni in #193
- Version 2026.5.1 by @abrignoni in #194
Full Changelog: v2026.5.0...v2026.5.1
Which file to download
| Platform | File |
|---|---|
| Windows 10 or 11, 64-bit | -windows-x64-setup.exe (installer), or -windows-x64-portable.zip to run without installing |
| macOS, Apple silicon | -macos-arm64.dmg |
| macOS, Intel | -macos-x64.dmg |
| Linux, 64-bit | -linux-x64.tar.gz |
The binaries are not signed
Expect a warning the first time you run one.
On macOS you get "GLEAPP cannot be opened because the developer cannot be verified".
Right-click the app, choose Open, then confirm.
On Windows, SmartScreen says "Windows protected your PC".
Choose More info, then Run anyway.
Signing is not wired up yet. If you would rather not clear a warning, run from source
instead; the README has the steps.
Verify what you downloaded
SHA256SUMS.txt covers every binary in this release. On macOS or Linux, from the folder
you downloaded into:
grep <the file you downloaded> SHA256SUMS.txt | shasum -a 256 -c -Use sha256sum in place of shasum -a 256 on Linux. On Windows, in PowerShell:
(Get-FileHash -Algorithm SHA256 .\<the file you downloaded>).Hashand compare it with the line in SHA256SUMS.txt, which is lower case.
Linux
The build is made on Ubuntu 24.04, so it needs glibc 2.39 or newer and will not start on
an older distribution. The native desktop window needs a GTK or Qt webview toolkit that
pip does not install, and CI does not exercise it, so gleapp web in a browser is the
tested path there.
GLEAPP v2026.5.0
The macOS builds have been withdrawn from this release.
They do not start. A library collision inside the bundle makes
import cv2fail, so
the app exits immediately withSymbol not found: _hb_coretext_font_create. This is
not the Gatekeeper warning, and allowing the app in System Settings does not help. If
you downloaded one, it will not work and there is nothing you can do locally about it.The Windows and Linux builds are still attached. The library that fails, pangocairo,
is in neither of those bundles.A fixed macOS build will follow in the next release.
GLEAPP triages and analyzes large sets of images and video for digital forensics. It
ingests media from folders, full filesystem extractions and disk images, hashes and
de-duplicates it, pulls metadata, extracts video key frames, matches against known hash
lists, and gives you a local review gallery to work the backlog in.
This is the first public release.
Scope and intended use
GLEAPP is a defensive investigative tool for authorized examiners. It ships no
illegal-content hash database, downloads nothing, and performs no content
classification. Categorization is always a human decision. Every case is seeded with the
locked Project VIC 2.0 (US) scheme, codes 0 to 5, and you add your own from code 6.
Which file to download
| Platform | File |
|---|---|
| Windows 10 or 11, 64-bit | -windows-x64-setup.exe (installer), or -windows-x64-portable.zip to run without installing |
| macOS, Apple silicon | -macos-arm64.dmg |
| macOS, Intel | -macos-x64.dmg |
| Linux, 64-bit | -linux-x64.tar.gz |
The binaries are not signed
Expect a warning the first time you run one.
On macOS you get "GLEAPP cannot be opened because the developer cannot be verified".
Right-click the app, choose Open, then confirm.
On Windows, SmartScreen says "Windows protected your PC".
Choose More info, then Run anyway.
Signing is not wired up yet. If you would rather not clear a warning, run from source
instead; the README has the steps.
Verify what you downloaded
SHA256SUMS.txt covers every binary in this release. On macOS or Linux, from the folder
you downloaded into:
grep <the file you downloaded> SHA256SUMS.txt | shasum -a 256 -c -Use sha256sum in place of shasum -a 256 on Linux. On Windows, in PowerShell:
(Get-FileHash -Algorithm SHA256 .\<the file you downloaded>).Hashand compare it with the line in SHA256SUMS.txt, which is lower case.
Linux
The build is made on Ubuntu 24.04, so it needs glibc 2.39 or newer and will not start on
an older distribution. The native desktop window needs a GTK or Qt webview toolkit that
pip does not install, and CI does not exercise it, so gleapp web in a browser is the
tested path there.
Running from source
Python 3.10 through 3.14, on all three platforms. The README has the steps, and the full
manual is built into the app under the Help button and mirrored in docs/MANUAL.md.
Credits
GLEAPP is written by @charpy4n6. Free and open source under the MIT license.
Full changelog, every pull request since the repository was created
What's Changed
- Add CI: lint, test suite, runtime contract, Windows smoke by @abrignoni in #1
- Stop snapshots taken in the same millisecond overwriting each other by @abrignoni in #2
- Read case/hash-list JSON as utf-8-sig so a BOM doesn't break import by @charpy4n6 in #3
- Drop the thumbnail Fit/Fill toggle - grid thumbnails are always uncro… by @charpy4n6 in #4
- Feat/gui hash set import by @charpy4n6 in #5
- Remove the examiner name from the header by @charpy4n6 in #6
- Don't surface the local VIC-unpack folder in search or the shown path by @charpy4n6 in #7
- feat(report): KMZ geolocation export with embedded thumbnails by @charpy4n6 in #8
- Run the test suite on Windows, not just imports by @abrignoni in #9
- Install sqlite3 on the Windows runner, and unblock the required checks by @abrignoni in #10
- Run from source the way the other LEAPPs do by @abrignoni in #11
- Replace the PowerShell build script with a cross-platform Python driver by @abrignoni in #12
- Guard the one-file build against deleting a folder build, and fix a misleading comment by @abrignoni in #13
- Normalize line endings to LF with a .gitattributes by @abrignoni in #14
- Package a macOS .app and .dmg from the one-folder build by @abrignoni in #15
- Build on packaging changes and weekly, and enforce LF in the required test job by @abrignoni in #16
- Add agent guidance: cross-platform first, CI, build and release, PR workflow by @abrignoni in #17
- fix(imaging): decode Apple CgBI ("iPhone-optimised") PNGs by @charpy4n6 in #19
- Sniff audio-only ISO-BMFF files as other instead of video by @abrignoni in #20
- Ingest a full-file-system extraction zip as a source by @abrignoni in #18
- Read extraction zips in place by default, with a staged mode and source relinking by @abrignoni in #21
- Keep local absolute paths out of stored error text by @abrignoni in #22
- Add Copy into case and Drop copies buttons to the gallery's Source section by @abrignoni in #23
- Floor Pillow at 10.2 so the bundled libjpeg-turbo cannot corrupt thumbnails by @abrignoni in #24
- Keep the source archive's path out of stored archive-unavailable errors by @abrignoni in #25
- Keep the ingest path out of the CSV, HTML, KML and JSON exports by @abrignoni in #26
- Tidy what a removed path leaves in scrubbed error text by @abrignoni in #28
- Accept tar and compressed tar extractions as archive sources by @abrignoni in #29
- Register a file once when an Android extraction carries it under several storage views by @abrignoni in #31
- feat(hashstore): GUI panel to add NSRL / reference data to the global… by @charpy4n6 in #32
- feat(launcher): browse button for extraction archives by @charpy4n6 in #33
- feat(web): filter sidebar — pinned primaries + collapsible feature se… by @charpy4n6 in #34
- Add offline basemaps for the gallery map by @abrignoni in #35
- Add rendered location maps to the HTML report by @abrignoni in #36
- feat(web): full-size button on the details-pane GPS map by @charpy4n6 in #37
- fix(web): limit recent cases shown in launcher to 3 by @charpy4n6 in #38
- Fix/find similar includes self by @charpy4n6 in #39
- fix(web): a group view (stack=/vstack=) now ignores every other filter by @charpy4n6 in #40
- fix(similar): find-similar requires dHash agreement, skips near-featureless pHash by @charpy4n6 in #41
- Read an E01 acquisition as a source and carve its media by @abrignoni in #42
- Write the case as a LAVA project by @abrignoni in #43
- Key frames, Project VIC records, and the lists that were checked by @abrignoni in #44
- The third grouping tier, and what the category names mean by @abrignoni in #45
- Keep the Series and Tags a Project VIC record carried by @abrignoni in #46
- Correct nine claims the artifact notes and descriptions made by @abrignoni in #48
- Walk an acquisition's filesystems, and carve only what a walk cannot reach by @abrignoni in #47
- Re-vendor qnxprobe 1.20, so a scoped carve works on a real disk by @abrignoni in #49
- Leave an artifact with no rows out of the LAVA report by @abrignoni in #50
- Re-vendor qnxprobe 1.21, so a Mac image scopes too by @abrignoni in #51
- Carry a FAT volume's recorded times to the examiner, as stored by @abrignoni in #52
- Take qnxprobe 1.23, so an HFS+ volume is not recorded as unreadable by @abrignoni in #53
- Processing history: a case run log with per-stage outcomes by @charpy4n6 in #54
- Stop copying a walked file's sniff bytes twice by @abrignoni in #55
- Do not read a macOS sidecar as the image it is named after by @abrignoni in #56
- Say how a source's rows were recovered, from the rows by @abrignoni in https://github.com/abrignoni/GLEAPP/pul...