Skip to content

Releases: norsehorse-dev/PassPonyAndroid

1.1.3

Choose a tag to compare

@norsehorse-dev norsehorse-dev released this 12 Sep 04:59

PassPony (Android) 1.1.3

1.1.3 adds age identity import for passage stores. After the 1.1.2 sync fix, passage users could clone a store but had no way to add the age identity it was encrypted to, so cloned entries stayed unreadable. You can now import your identities file from Settings or during setup, and the key step stays available after a clone. OpenPGP (pass) stores are unaffected.

Verification

  • Content hash: 86b45c1200d7b3eb63f677613f5ca8320a01cfc524d3430519af471ff1216348
  • SHA-256 checksums: see PassPonyAndroid-1.1.3-SHA256SUMS.txt
  • Reproduce this build yourself: tools/verify_repro.sh rebuild v1.1.3 PassPonyAndroid-1.1.3-foss.apk

See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.

1.1.2

Choose a tag to compare

@norsehorse-dev norsehorse-dev released this 11 Sep 18:21

PassPony (Android) 1.1.2

Remote git sync could not verify the server's TLS certificate on Android, so clone, pull, and push all failed. 1.1.1 bundled the trusted certificate list but loaded it through OpenSSL's file reader, which does not work on the Android build, so verification still failed. 1.1.2 loads the same certificates directly into memory instead, which works. Sync now goes through with no change needed on your end.

Verification

  • Content hash: 60447a46dba26db11407b2200c4b8dc5a1b141792503c3d9070c02fece399fa0
  • SHA-256 checksums: see PassPonyAndroid-1.1.2-SHA256SUMS.txt
  • Reproduce this build yourself: tools/verify_repro.sh rebuild v1.1.2 PassPonyAndroid-1.1.2-foss.apk

See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.

1.1.1

Choose a tag to compare

@norsehorse-dev norsehorse-dev released this 10 Sep 18:22

PassPony (Android) 1.1.1

Verification

  • Content hash: 520ba8a2279770c2742544d095cfe9efa7987487a94ee8c386514d27663f9780
  • SHA-256 checksums: see PassPonyAndroid-1.1.1-SHA256SUMS.txt
  • Reproduce this build yourself: tools/verify_repro.sh rebuild v1.1.1 PassPonyAndroid-1.1.1-foss.apk

See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.

1.1.0

Choose a tag to compare

@norsehorse-dev norsehorse-dev released this 08 Sep 02:03

PassPony (Android) 1.1.0

This release fixes remote sync, which did not work on any earlier version. The app was missing the network permission it needs to reach a git remote, so clone, pull, and push all failed at connection time. Adding the permission restores sync. Thanks to the report on issue #6 for pinning it down.

New in this release:

  • One-time codes (TOTP) can be set up in the app: scan a QR code, paste an otpauth link, or type the key by hand. Entries created with pass otp insert now show their code.
  • The password generator has length and character-class options.
  • Diagnostics has its own screen under Settings, with a copyable report that redacts entry names and tokens.

Verification

  • Content hash: de1e74ac9d1750a7e2c931ba7b216a12537a55ef13c6d3f8be53a056a16ae6ed
  • SHA-256 checksums: see PassPonyAndroid-1.1.0-SHA256SUMS.txt
  • Reproduce this build yourself: tools/verify_repro.sh rebuild v1.1.0 PassPonyAndroid-1.1.0-foss.apk

See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.

1.0.5

Choose a tag to compare

@norsehorse-dev norsehorse-dev released this 28 Aug 17:25

PassPony (Android) 1.0.5

A packaging fix, with no change to the app itself.

The APK now ships native libraries only for the architectures PassPony actually supports, arm64-v8a and x86_64. Earlier builds also bundled partial native libraries for armeabi-v7a, x86, and some dead architectures that never had the Rust core, so the app could install but not run there. Nothing changes for arm64-v8a or x86_64, which covers effectively every current phone and emulator.

Verification

  • Content hash: f987c061f2205a56f087ac60fc2105f257d343eaec9de9349d00d56ac927af5f
  • SHA-256 checksums: see PassPonyAndroid-1.0.5-SHA256SUMS.txt
  • Reproduce this build yourself: tools/verify_repro.sh rebuild v1.0.5 PassPonyAndroid-1.0.5-foss.apk

See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.

1.0.4

Choose a tag to compare

@norsehorse-dev norsehorse-dev released this 25 Aug 02:15

PassPony (Android) 1.0.4

A build and reproducibility release, with no changes to the app itself. If you are on 1.0.3, there is nothing new to see in the UI.

What changed is how the release is built, so F-Droid can reproduce it from source: the F-Droid recipe now uses a gradle build that compiles the Rust core in-tree instead of a separate manual step, and the ART baseline profile (which AGP does not build byte-for-byte reproducibly) is no longer packaged. Dropping that profile can make the very first launch slightly slower on older devices; nothing else changes.

Verification

  • Content hash: c29674a09d8ccce53f4fbcf06f1c6295d46dc64fa7f000eee7b7cbbe57afa08b
  • SHA-256 checksums: see PassPonyAndroid-1.0.4-SHA256SUMS.txt
  • Reproduce this build yourself: tools/verify_repro.sh rebuild v1.0.4 PassPonyAndroid-1.0.4-foss.apk

See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.

1.0.3

Choose a tag to compare

@norsehorse-dev norsehorse-dev released this 24 Aug 21:59

PassPony (Android) 1.0.3

1.0.2 crashed on launch for everyone who installed the release APK. The release build runs R8 minification, but the keep rules for the crypto layer were never added, so R8 renamed and stripped the UniFFI/JNA bindings and the BouncyCastle classes that the app looks up by reflection at runtime. The store engine is initialized during launch, so the first call into it threw and the process died, then restarted into the same crash. Debug builds are not minified, which is how this reached the 1.0.2 release.

Update to 1.0.3 if 1.0.2 would not open.

  • Add R8 keep rules for the JNA/UniFFI bindings (com.sun.jna, uniffi.pass_ffi) and BouncyCastle (org.bouncycastle, com.pgpony.android.crypto) so the crypto engine survives minification.

Verification

  • Content hash: 666d242c8954489dc2e52f13da9ea59a59a52badd80ee15302db0daefb4b586c
  • SHA-256 checksums: see PassPonyAndroid-1.0.3-SHA256SUMS.txt
  • Reproduce this build yourself: tools/verify_repro.sh rebuild v1.0.3 PassPonyAndroid-1.0.3-foss.apk

See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.

1.0.2

Choose a tag to compare

@norsehorse-dev norsehorse-dev released this 11 Aug 23:18

PassPony (Android) 1.0.2

Reproducible build fixes for F-Droid verification. No user-facing
changes; the app is functionally identical to 1.0.0.

  • The Rust core's embedded OpenSSL build info is now host-independent:
    the build timestamp is pinned to a fixed epoch on every builder, and
    the compiler path is normalized through a fixed location instead of
    recording wherever the NDK happens to be installed
  • Together these make a from-source rebuild on any Linux host,
    F-Droid's build servers included, byte-identical to the published
    release

Verification

  • Content hash: 831e139a4db3a1cd2aaa1eeb14ce083fbe71a974d5a7c44c8db3f959207f3aa2
  • SHA-256 checksums: see PassPonyAndroid-1.0.2-SHA256SUMS.txt
  • Reproduce this build yourself: tools/verify_repro.sh rebuild v1.0.2 PassPonyAndroid-1.0.2-foss.apk

See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.

1.0.1

Choose a tag to compare

@norsehorse-dev norsehorse-dev released this 11 Aug 14:14

PassPony (Android) 1.0.1

F-Droid build compatibility release. No user-facing changes; the app is
functionally identical to 1.0.0.

  • PGPonyCore-Kotlin no longer requests a Gradle JVM toolchain
    (jvmToolchain(17)), which fails on build hosts that disable
    Gradle's toolchain auto-provisioning, F-Droid's buildserver included.
    It now sets the JVM 17 bytecode target directly, producing the same
    output on any JDK 17 or newer
  • The Gradle foojay-resolver toolchain plugin is no longer required by
    any module, so build environments that disallow it can strip it
    without side effects

Verification

  • Content hash: a1fd79339506513ba40e15a666f6b01bd73fef62a30f7035c3ee8e4a9fc9bfa8
  • SHA-256 checksums: see PassPonyAndroid-1.0.1-SHA256SUMS.txt
  • Reproduce this build yourself: tools/verify_repro.sh rebuild v1.0.1 PassPonyAndroid-1.0.1-foss.apk

See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.

1.0.0

Choose a tag to compare

@norsehorse-dev norsehorse-dev released this 10 Aug 21:48

PassPony (Android) 1.0.0

First release. A password manager for pass (OpenPGP) and passage (age)
stores, built on the same Rust crypto core as PassPony iOS.

  • Browse, search, and edit entries in pass and passage stores. Each
    format keeps its own store; switching never touches the other
    store's data
  • Live TOTP codes with a countdown ring
  • An ephemeral clipboard that clears itself after 45 seconds
  • Git sync: clone, push, and per-entry conflict resolution
  • System Autofill. Only entry names are indexed; nothing decrypts
    until you fill
  • Biometric unlock with a 5-minute grace window
  • Localized in English, Spanish, French, German, Simplified Chinese,
    Brazilian Portuguese, and Russian, with live in-app language
    switching

Verification

  • Content hash: df742ffada13752e1a9b2232d8391b6cb91fdd4c183684f3f2fa5df468e2ab12
  • SHA-256 checksums: see PassPonyAndroid-1.0.0-SHA256SUMS.txt
  • Reproduce this build yourself: tools/verify_repro.sh rebuild v1.0.0 PassPonyAndroid-1.0.0-foss.apk

See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.