Releases: jabbott-iii/Cryptare
Release list
Release v1.3.2
Full Changelog: v1.3.1...v1.3.2
Release v1.3.1
Full Changelog: v1.3.0...v1.3.1
Cryptare v1.3.1
A maintenance release: correct Unicode normalisation of passwords, Linux binaries built against musl, and updated dependencies.
Changes
- Password normalisation fix. v1.3.0 used a version of
golang.org/x/textwhose Unicode normalisation had a bug. In a rare kind of password, it attached a combining accent to an earlier letter across a character that should have blocked it. This release usesgolang.org/x/textv0.42.0, which follows the Unicode standard. A test now pins how passwords are normalised, so a future library update can't change it unnoticed. - Linux binaries are linked against musl. They are still fully static and run on any Linux distribution, but no longer contain glibc.
THIRD_PARTY_LICENSES.txtnow also lists the C libraries in each binary: musl on Linux, and the MinGW-w64 runtime on Windows. - Dependencies:
golang.org/x/crypto0.57.0,golang.org/x/text0.42.0,golang.org/x/sys0.48.0.
Upgrading from v1.3.0
- Only one rare kind of password is affected: one with a vowel sign or length mark from a script such as Tamil, Malayalam, Bengali, Oriya, Kannada, Sinhala or Myanmar, followed later by a combining accent such as an acute. If you encrypted a file with such a password in v1.3.0, it won't open in this version: decrypt it with v1.3.0, then encrypt it again with this version. Stored keys and key exports protected that way also open only in v1.3.0; stored keys aren't used for encryption yet, so generating a new key is the simplest fix. Every other password works as before, and data from v1.2.0 and earlier is not affected.
Install
Download your platform's archive and checksums.txt, check the hash (sha256sum --ignore-missing -c checksums.txt), and put the binary on your PATH. See the README for details.
Release v1.3.0
Full Changelog: v1.2.0...v1.3.0
Cryptare v1.3.0
This release moves the key store out of the current folder, makes passwords independent of how their characters were typed, and ships licence files with every download. Read "Upgrading" before you install it on one machine and not the others.
Highlights
- The key store has a fixed home. Without
CRYPTARE_DB_PATH, keys are stored incryptare/cryptare.dbin your user data folder:~/.local/share(or$XDG_DATA_HOME) on Linux,~/Library/Application Supporton macOS,%LocalAppData%on Windows. The folder is created readable only by you. Running a command in a different folder no longer gives you a different, or someone else's, key store. cryptare keys pathprints which key store is in use, without creating anything.- Passwords are normalised. An accented letter typed as one character or as a letter plus a combining accent, full-width letters, ligatures and similar variants now give the same key (Unicode NFKC, as NIST SP 800-63B recommends). A byte order mark that an editor put at the start of a
--password-fileis ignored. The 15-character minimum counts the normalised password. - Licences in every archive: each download now holds
LICENSE,NOTICEandTHIRD_PARTY_LICENSES.txt, with the licences of the Go standard library and every Go module built into the binary.
Security fixes
- The default key store no longer depends on the current folder, so a
cryptare.dbplanted in a shared folder, a cloned repository or an extracted archive is never used unless you pointCRYPTARE_DB_PATHat it. - CI now fails if a key database or key export is ever committed to the repository.
Upgrading from v1.2.0 or earlier
- Key store: your existing keys stay in
cryptare.dbin whichever folder you ran Cryptare from. When akeyscommand or the TUI finds one in the current folder, it prints a notice with the command to move it to the new location (or tells you to setCRYPTARE_DB_PATHif the new store already exists). Cryptare never opens or moves that file itself. To keep the old behaviour, setCRYPTARE_DB_PATH=./cryptare.db. The Docker image already setsCRYPTARE_DB_PATHand is unaffected. - Format: data protected with a password that normalisation changes (accents typed as combining characters, full-width letters, a password file starting with a byte order mark) is marked in its header, and v1.2.0 and earlier refuse it with "unsupported encrypted data: key derivation 2". Upgrade every machine that needs to read it. Data protected with any other password is written exactly as before, and v1.2.0 reads it.
- Files and keys that v1.2.0 or earlier protected with a password typed with combining accents still need the password typed that way.
- If
HOME(or%LocalAppData%on Windows) isn't set, thekeyscommands and the TUI ask you to setCRYPTARE_DB_PATHinstead of using the current folder.
Install
Download your platform's archive and checksums.txt, check the hash (sha256sum --ignore-missing -c checksums.txt), and put the binary on your PATH. See the README for details.
Release v1.2.0
Full Changelog: v1.1.0...v1.2.0
Cryptare v1.2.0
This release changes how new data is encrypted, and fixes a number of security issues and bugs found in a full review. Read "Upgrading" before you install it on one machine and not the others.
Highlights
- New encrypted format. Files, folders, stored keys and key exports are written in a versioned format: Argon2id (64 MiB, 3 passes, 4 lanes) instead of PBKDF2, and authenticated 64 KiB chunks, so memory use no longer grows with file size. Everything written by older versions still decrypts.
- Passwords off the command line:
--password-fileonencrypt,decryptand thekeyscommands.--passwordstill works but prints a warning. - New passwords need at least 15 characters and are typed twice at a terminal.
- Nothing is overwritten by default. Add
--forceto replace an existing output. That includeskeys export, which never writes over the key store. A failed or interrupted command leaves no partial output. - Stopping is safe: Ctrl+C,
killor a closed terminal stops a command and removes its unfinished output. The exit status is 128 + the signal (130 for Ctrl+C). Quitting the TUI cancels a running action first. - Extraction limits guard against decompression bombs (10 GiB and 100,000 entries by default;
--max-size,--max-entries). decompress --rawgunzips a file without extracting it, sox.tar.gzgivesx.tarback.- File and folder names in any script (Chinese, Cyrillic, emoji, …) now work with gzip and folder encryption.
Security fixes
- Builds use Go 1.26.8. v1.1.0 was built with Go 1.26.0, whose
archive/tarcould be made to allocate memory without bound by a crafted archive (GO-2026-4869). - Extraction writes only inside the output folder (
os.Root) and ignores permissions stored in archives: folders are 0700 and files 0600 on Linux and macOS. - On Linux and macOS, a key store that another user owns or that others can write to is refused. Stored key IDs are escaped when listed, so a planted key store can't inject terminal escape sequences.
- The key store's SQL statements (with encrypted key blobs) are no longer printed to stdout.
- Directory encryption no longer writes plaintext to the temp folder, and deleted keys are overwritten in the database file.
- The Docker image runs as an unprivileged user, from base images pinned by digest.
Upgrading from v1.1.0 or earlier
- Format: v1.1.0 and earlier can't decrypt files made by this version; they report a wrong password. Upgrade every machine that needs to read them.
- If you encrypted at the old interactive prompt with a multi-word passphrase (v1.0.1 or earlier), decrypt with only the first word. The old prompt kept only the text before the first space.
- Scripts that pass a password shorter than 15 characters to
encrypt,keys generateorkeys exportnow fail. decompress --forceanddecrypt --forcereplace an existing output folder instead of merging into it. Extracted files no longer keep the archive's permissions.- Archives over 10 GiB of output or 100,000 entries need
--max-sizeor--max-entries. Files in the old format are read whole, sodecryptrefuses one larger than--max-size; raise it for bigger ones. keys exportrefuses an existing file unless you add--force.encrypt dir/andencrypt .write the encrypted file next to the folder (dir.enc), not inside it. An--outputinside the folder is refused.compressrefuses a--formatthat contradicts the output's extension, and--levelvalues other than 1–9 or -1.--password ""now means an empty password instead of prompting.- A
CRYPTARE_DB_PATHcontaining?is refused; use afile:URI with%3F. - Docker: the image runs as UID 10001. For a bind-mounted data folder, add
--user "$(id -u):$(id -g)". - Windows: outputs and the key store get the permissions of the folder they're written to. Keep them in a folder only you can read.
Install
Download your platform's archive and checksums.txt, check the hash (sha256sum --ignore-missing -c checksums.txt), and put the binary on your PATH. See the README for details.
Release v1.1.0
Full Changelog: v1.0.1...v1.1.0
Release v1.0.1
What's Changed
- Add ZIP as a first-class compression/archive format across core, CLI, and TUI by @jabbott-iii with @Copilot in #14
- Add opt-in vim keybindings for the TUI by @jabbott-iii with @Copilot in #16
Full Changelog: v1.0.0...v1.0.1
Release v1.0.0
What's Changed
- Add time package import to database.go by @jabbott-iii in #5
- feat: build full CLI/TUI tool — encryption, compression, and key management by @jabbott-iii with @Copilot in #6
- Implement full TUI dashboard functionality matching the CLI in logic-tui.go by @jabbott-iii with @Copilot in #8
- Add single-file directory encryption/decryption via authenticated tar.gz archives by @jabbott-iii with @Copilot in #9
- Add confirmed AES key deletion to CLI/TUI with atomic storage removal and explicit not-found semantics by @jabbott-iii with @Copilot in #10
New Contributors
- @jabbott-iii made their first contribution in #5
- @jabbott-iii with @Copilot made their first contribution in #6
Full Changelog: https://github.com/jabbott-iii/Cryptare/commits/v1.0.0