Releases: dan-build/Still
Releases · dan-build/Still
Release list
Still v0.1.1
This release fixes the data-loss issues found in v0.1.0, and it's the first universal build: it runs natively on Intel and Apple Silicon Macs. Your v0.1.0 vault opens as it is; there's nothing to migrate.
Fixed
- Forgetting your only Lens is now saved. Before, it came back after a restart, both in your Lenses and in the Archive.
- "Delete forever" and "Restore" on the last Lens in the Archive are now saved, and so is the 7-day clean-up when it empties the Archive. Before, those Lenses came back after a restart, and deleted data stayed on disk.
- Lenses that v0.1.0 left in both the list and the Archive (because of the bug above) are no longer duplicated when you restore or forget them.
- A Lens that can't be opened is no longer erased. Before, it was hidden without warning and deleted by your next change. Now it's kept exactly as stored, and Still tells you: "1 Lens couldn't be opened. It's kept safe and unchanged."
- Still no longer creates a new vault on top of existing Lenses when the key that opens them is missing. It shows a recovery screen instead. From there you can restore a backup, or set the old data aside (nothing is deleted) and start a new vault.
- Secrets are stored exactly as typed. Spaces and line breaks at the start or end of a secret were removed before saving. When a secret starts or ends with them, Still now says so and offers to remove them.
- A master password made only of spaces now unlocks its vault. New vaults no longer accept one.
- A change that can't be saved (for example, because storage is full) now shows an error instead of looking saved. Nothing is lost when a save fails partway.
- Revealed secrets keep their spaces and line breaks on screen, so multi-line notes show as written.
- Unlock errors now say what happened: a wrong password, vault data that can't be read, or another failure such as running out of memory. Before, every failure showed "Incorrect password or PIN".
Changed
- One download for every Mac. The macOS app is now a universal build that runs natively on Intel and Apple Silicon. v0.1.0 was Intel-only and ran through Rosetta on Apple Silicon.
- The app is ad-hoc signed. It still isn't signed with an Apple Developer ID, so macOS asks you to allow it once.
- Lock now clears the app's keys from its own memory and closes the open Lens, instead of only hiding the screen.
- Secret fields turn off spellcheck and autocorrect.
- New Lenses and secrets get random ids. The old ones were based on the creation time, so two could clash. Existing ids are unchanged.
Removed
- The optional PIN. It was never implemented: setting one had no effect, and "Use PIN instead" could never unlock. Vaults created with a PIN still open with their master password.
Notes
- Secrets saved by v0.1.0 lost any spaces or line breaks at the start or end. Still can't detect or restore those characters, because they were never stored. If a saved secret doesn't work and the real one starts or ends with a space or line break, delete it and add it again.
- Your vault's format is unchanged. Vaults from v0.1.0 open as before, and v0.1.0 can still open a vault saved by this version.
Still open
- Unlocking freezes the window for a few seconds. This goes away when encryption moves into Rust.
- Lens names, labels, types and dates aren't encrypted yet. Only secret values are.
- Copied secrets stay on the clipboard, and Still doesn't lock itself when you're away.
Install (macOS)
- Download the
.dmgandSHA256SUMS.txt. Optionally, check them withcd ~/Downloads && shasum -a 256 -c SHA256SUMS.txt. - Open the
.dmgand drag Still into Applications. - The app isn't signed with an Apple Developer ID yet, so the first time you open it, go to System Settings → Privacy & Security and click Open Anyway.
v0.1.0 - Initial Release
Still v0.1.0 (pre-release)
First public release of Still, an offline password and secret manager for your Mac. No account, no sync, no telemetry: Still never connects to the internet.
Early pre-release. Please read the known issues below before storing anything you can't afford to lose.
Features
- One master password unlocks everything. The key is derived with Argon2id at libsodium's highest-cost setting.
- Lenses: separate collections, each with its own encryption key.
- Passwords, API keys or tokens, and secure notes. Reveal, copy or delete them.
- Archive: a forgotten Lens is kept for 7 days, and can be restored or deleted for good.
- Offline: no servers, accounts or analytics.
What's encrypted
- Encrypted at rest: every secret value, using XChaCha20-Poly1305 via libsodium, with keys protected by your master password.
- Not encrypted yet: Lens names, secret labels and types, dates, and item counts. See SECURITY.md.
Known issues (fixes planned for v0.1.1)
- Forgetting your only Lens isn't saved. It comes back after a restart. Keep at least one other Lens.
- Changes to the last item in the Archive aren't saved. "Delete forever" and "Restore" on the only archived Lens, and the 7-day clean-up when it empties the Archive, are undone after a restart.
- Spaces and line breaks at the start or end of a secret are removed when you save it.
- The optional PIN does nothing. "Use PIN instead" can never unlock; use your master password.
- A master password made only of spaces can be created but not entered.
- In rare cases (damaged data or a partly missing vault), a Lens that can't be read is hidden without warning, and erased by your next change.
- Unlocking freezes the window for a few seconds, and every failure shows as "Incorrect password or PIN".
Install (macOS)
- Download
Still-0.1.0.dmg. Optionally, check it withshasum -a 256 Still-0.1.0.dmg. It should print:
1ae0e529676abf693350aa85be51c6307e06a88de121a9853bf1155e90453827 - Open the
.dmgand drag Still into Applications. - The app isn't signed yet, so macOS blocks the first launch. Go to System Settings → Privacy & Security and click Open Anyway.
This build is for Intel Macs, and runs on Apple Silicon through Rosetta 2. v0.1.1 is planned as a universal build.
Built with Tauri v2, Next.js and libsodium.