Skip to content

Release v1.3.1

Choose a tag to compare

@github-actions github-actions released this 04 Oct 23:20
· 6 commits to main since this release
Immutable release. Only release title and notes can be modified.

Full Changelog: v1.3.0...v1.3.1

Cryptare v1.3.1

A maintenance release: correct Unicode normalisation of passwords, Linux binaries built against musl, and updated dependencies.

Changes

  • Password normalisation fix. v1.3.0 used a version of golang.org/x/text whose Unicode normalisation had a bug. In a rare kind of password, it attached a combining accent to an earlier letter across a character that should have blocked it. This release uses golang.org/x/text v0.42.0, which follows the Unicode standard. A test now pins how passwords are normalised, so a future library update can't change it unnoticed.
  • Linux binaries are linked against musl. They are still fully static and run on any Linux distribution, but no longer contain glibc. THIRD_PARTY_LICENSES.txt now also lists the C libraries in each binary: musl on Linux, and the MinGW-w64 runtime on Windows.
  • Dependencies: golang.org/x/crypto 0.57.0, golang.org/x/text 0.42.0, golang.org/x/sys 0.48.0.

Upgrading from v1.3.0

  • Only one rare kind of password is affected: one with a vowel sign or length mark from a script such as Tamil, Malayalam, Bengali, Oriya, Kannada, Sinhala or Myanmar, followed later by a combining accent such as an acute. If you encrypted a file with such a password in v1.3.0, it won't open in this version: decrypt it with v1.3.0, then encrypt it again with this version. Stored keys and key exports protected that way also open only in v1.3.0; stored keys aren't used for encryption yet, so generating a new key is the simplest fix. Every other password works as before, and data from v1.2.0 and earlier is not affected.

Install

Download your platform's archive and checksums.txt, check the hash (sha256sum --ignore-missing -c checksums.txt), and put the binary on your PATH. See the README for details.