Skip to content

Still v0.1.1

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 28 Sep 22:50
· 37 commits to main since this release
11d4f71

This release fixes the data-loss issues found in v0.1.0, and it's the first universal build: it runs natively on Intel and Apple Silicon Macs. Your v0.1.0 vault opens as it is; there's nothing to migrate.

Fixed

  • Forgetting your only Lens is now saved. Before, it came back after a restart, both in your Lenses and in the Archive.
  • "Delete forever" and "Restore" on the last Lens in the Archive are now saved, and so is the 7-day clean-up when it empties the Archive. Before, those Lenses came back after a restart, and deleted data stayed on disk.
  • Lenses that v0.1.0 left in both the list and the Archive (because of the bug above) are no longer duplicated when you restore or forget them.
  • A Lens that can't be opened is no longer erased. Before, it was hidden without warning and deleted by your next change. Now it's kept exactly as stored, and Still tells you: "1 Lens couldn't be opened. It's kept safe and unchanged."
  • Still no longer creates a new vault on top of existing Lenses when the key that opens them is missing. It shows a recovery screen instead. From there you can restore a backup, or set the old data aside (nothing is deleted) and start a new vault.
  • Secrets are stored exactly as typed. Spaces and line breaks at the start or end of a secret were removed before saving. When a secret starts or ends with them, Still now says so and offers to remove them.
  • A master password made only of spaces now unlocks its vault. New vaults no longer accept one.
  • A change that can't be saved (for example, because storage is full) now shows an error instead of looking saved. Nothing is lost when a save fails partway.
  • Revealed secrets keep their spaces and line breaks on screen, so multi-line notes show as written.
  • Unlock errors now say what happened: a wrong password, vault data that can't be read, or another failure such as running out of memory. Before, every failure showed "Incorrect password or PIN".

Changed

  • One download for every Mac. The macOS app is now a universal build that runs natively on Intel and Apple Silicon. v0.1.0 was Intel-only and ran through Rosetta on Apple Silicon.
  • The app is ad-hoc signed. It still isn't signed with an Apple Developer ID, so macOS asks you to allow it once.
  • Lock now clears the app's keys from its own memory and closes the open Lens, instead of only hiding the screen.
  • Secret fields turn off spellcheck and autocorrect.
  • New Lenses and secrets get random ids. The old ones were based on the creation time, so two could clash. Existing ids are unchanged.

Removed

  • The optional PIN. It was never implemented: setting one had no effect, and "Use PIN instead" could never unlock. Vaults created with a PIN still open with their master password.

Notes

  • Secrets saved by v0.1.0 lost any spaces or line breaks at the start or end. Still can't detect or restore those characters, because they were never stored. If a saved secret doesn't work and the real one starts or ends with a space or line break, delete it and add it again.
  • Your vault's format is unchanged. Vaults from v0.1.0 open as before, and v0.1.0 can still open a vault saved by this version.

Still open

  • Unlocking freezes the window for a few seconds. This goes away when encryption moves into Rust.
  • Lens names, labels, types and dates aren't encrypted yet. Only secret values are.
  • Copied secrets stay on the clipboard, and Still doesn't lock itself when you're away.

Install (macOS)

  1. Download the .dmg and SHA256SUMS.txt. Optionally, check them with cd ~/Downloads && shasum -a 256 -c SHA256SUMS.txt.
  2. Open the .dmg and drag Still into Applications.
  3. The app isn't signed with an Apple Developer ID yet, so the first time you open it, go to System Settings → Privacy & Security and click Open Anyway.