Repository navigation
Releases: rnpgp/rnp-mailapp-extension
Releases · rnpgp/rnp-mailapp-extension
Release list
v0.9.7 — CloudKit sync, KeyManager cleanup, Sparkle, reproducible builds
What's new
- CloudKit sync is wired up. iCloud entitlements are re-enabled and provisioning profiles support iCloud + Push Notifications; the canonical keyring now mirrors to the user's iCloud private database. Mail-extension builds keep iCloud off (the extension doesn't need CloudKit).
- Deprecated
KeyManageris gone from project code. All call sites now useKeyringStoredirectly, withMailSecurityEngine's convenience init constructing the engine internally.MailPluginandRNPboth build clean — zero project-owned warnings. - Manual code signing restored with the
RNPUnitTeststarget wired in for the new Swift Package Manager test bundle. - Sign/verify files, lazy-load, Sparkle auto-update, Homebrew Cask, website, SBOM, pseudo-localization, keyboard shortcuts, async decode cache, snapshot harness, reproducible builds — all landed across this cycle.
Known limitations
- iOS companion app (TODO 38) remains a separate one-month lift; this release is macOS-only.
- App Store submission (TODO 03) is pending ronaldtse's Apple account.
- The macOS Mail extension still requires a manual toggle in System Settings → Extensions → Added Extensions → RNP for Mail → Mail after first install.
Build
- Swift 5.9 / macOS 14 SDK
- Dependencies:
swift-rnp0.2.10,Sparkle2.9.5
Install
brew install --cask rnp-for-mailOr download the signed DMG from the assets below.
What's Changed
- feat: batched improvements — sign/verify, lazy load, Sparkle, website, Cask, TODO specs by @ronaldtse in #184
- feat: expanded engine, ADRs, unified errors/logging, backup/restore, onboarding polish by @ronaldtse in #185
- feat: keyboard shortcuts, keyring index, reproducible builds, SBOM, a11y motion, attachment UI by @ronaldtse in #186
- refactor(contentview): split into Sheets/Banners/Toolbar + wire encrypted attachments by @ronaldtse in #187
- feat: async decode cache, snapshot harness, pseudo-localization, rnp CLI by @ronaldtse in #188
- feat(menu): keyboard shortcuts help + ⌘? to invoke it by @ronaldtse in #189
- feat(sync): protocols for canonical RNP store + read-only import sources by @ronaldtse in #190
- feat(delete): three-step confirmation + mandatory encrypted PGP backup by @ronaldtse in #191
- feat: TODOs 31-38, Phase 1.5 refactor, per-key .asc backend, Sync UI, ADRs by @ronaldtse in #192
- feat: finish Phase 1.5 completion — CloudKit, onboarding storage choice, GnuPG agent, real backends by @ronaldtse in #193
- fix(contentview): route extension keyring through MailSecurityEngine convenience init by @ronaldtse in #194
- chore: bump MARKETING_VERSION to 0.9.7 by @ronaldtse in #195
Full Changelog: v0.9.6...v0.9.7
v0.9.6
What's Changed
- feat: guided enable for RNP for Mail by @ronaldtse in #182
- chore: bump MARKETING_VERSION to 0.9.6 by @ronaldtse in #183
Full Changelog: v0.9.5...v0.9.6
v0.9.5
What's Changed
- feat: PQ keygen picker + App Store readiness checklist by @ronaldtse in #178
- feat: App Intents for Finder Quick Action file encryption by @ronaldtse in #179
- release(v0.9.5) by @ronaldtse in #180
- chore: bump swift-rnp pin to v0.2.8 by @ronaldtse in #181
Full Changelog: v0.9.4...v0.9.5
v0.9.4
What's Changed
- feat: File Tools window for encrypt/decrypt outside Mail by @ronaldtse in #174
- refactor: fold File Tools into sidebar tab instead of separate window by @ronaldtse in #175
- release(v0.9.4) by @ronaldtse in #176
- fix(release): revert to release-direct.sh until match repo is bootstrapped by @ronaldtse in #177
Full Changelog: v0.9.3...v0.9.4
What's Changed
- feat: File Tools window for encrypt/decrypt outside Mail by @ronaldtse in #174
- refactor: fold File Tools into sidebar tab instead of separate window by @ronaldtse in #175
- release(v0.9.4) by @ronaldtse in #176
- fix(release): revert to release-direct.sh until match repo is bootstrapped by @ronaldtse in #177
Full Changelog: v0.9.3...v0.9.4
v0.9.2
What's Changed
- feat(import): auto-detect ~/.gnupg and ~/.rnp keyrings by @ronaldtse in #167
- release(v0.9.2): bump marketing version by @ronaldtse in #168
Full Changelog: v0.9.1...v0.9.2
v0.9.1
What's Changed
- ci(release): pin Xcode to 16.4 and fail hard if missing by @ronaldtse in #152
- ci(release): pluginkit smoke-test for Mail extension by @ronaldtse in #153
- i18n(onboarding): add labels + Skip button keys by @ronaldtse in #155
- ci: one job per PR via new ci.yml by @ronaldtse in #158
- release(v0.9.1): bump swift-rnp floor to 0.2.3 by @ronaldtse in #157
- ci(release): rename to release.yml + add workflow_dispatch retry by @ronaldtse in #159
- fix(release): pass RELEASE_TAG so workflow_dispatch path passes tag check by @ronaldtse in #160
- refactor: SharedKeyring + Sheet enum + i18n contract test (architecture candidates 1, 2, 4) by @ronaldtse in #161
Full Changelog: v0.9.0...v0.9.1
What's Changed
- ci(release): pin Xcode to 16.4 and fail hard if missing by @ronaldtse in #152
- ci(release): pluginkit smoke-test for Mail extension by @ronaldtse in #153
- i18n(onboarding): add labels + Skip button keys by @ronaldtse in #155
- ci: one job per PR via new ci.yml by @ronaldtse in #158
- release(v0.9.1): bump swift-rnp floor to 0.2.3 by @ronaldtse in #157
- ci(release): rename to release.yml + add workflow_dispatch retry by @ronaldtse in #159
- fix(release): pass RELEASE_TAG so workflow_dispatch path passes tag check by @ronaldtse in #160
- refactor: SharedKeyring + Sheet enum + i18n contract test (architecture candidates 1, 2, 4) by @ronaldtse in #161
Full Changelog: v0.9.0...v0.9.1
What's Changed
- ci(release): pin Xcode to 16.4 and fail hard if missing by @ronaldtse in #152
- ci(release): pluginkit smoke-test for Mail extension by @ronaldtse in #153
- i18n(onboarding): add labels + Skip button keys by @ronaldtse in #155
- ci: one job per PR via new ci.yml by @ronaldtse in #158
- release(v0.9.1): bump swift-rnp floor to 0.2.3 by @ronaldtse in #157
- ci(release): rename to release.yml + add workflow_dispatch retry by @ronaldtse in #159
- fix(release): pass RELEASE_TAG so workflow_dispatch path passes tag check by @ronaldtse in #160
- refactor: SharedKeyring + Sheet enum + i18n contract test (architecture candidates 1, 2, 4) by @ronaldtse in #161
- fix(release): re-sign with Hardened Runtime version 14.0 for macOS 14.x by @ronaldtse in #164
Full Changelog: v0.9.0...v0.9.1
What's Changed
- ci(release): pin Xcode to 16.4 and fail hard if missing by @ronaldtse in #152
- ci(release): pluginkit smoke-test for Mail extension by @ronaldtse in #153
- i18n(onboarding): add labels + Skip button keys by @ronaldtse in #155
- ci: one job per PR via new ci.yml by @ronaldtse in #158
- release(v0.9.1): bump swift-rnp floor to 0.2.3 by @ronaldtse in #157
- ci(release): rename to release.yml + add workflow_dispatch retry by @ronaldtse in #159
- fix(release): pass RELEASE_TAG so workflow_dispatch path passes tag check by @ronaldtse in #160
- refactor: SharedKeyring + Sheet enum + i18n contract test (architecture candidates 1, 2, 4) by @ronaldtse in #161
- fix(release): re-sign with Hardened Runtime version 14.0 for macOS 14.x by @ronaldtse in #164
Full Changelog: v0.9.0...v0.9.1
What's Changed
- ci(release): pin Xcode to 16.4 and fail hard if missing by @ronaldtse in #152
- ci(release): pluginkit smoke-test for Mail extension by @ronaldtse in #153
- i18n(onboarding): add labels + Skip button keys by @ronaldtse in #155
- ci: one job per PR via new ci.yml by @ronaldtse in #158
- release(v0.9.1): bump swift-rnp floor to 0.2.3 by @ronaldtse in #157
- ci(release): rename to release.yml + add workflow_dispatch retry by @ronaldtse in #159
- fix(release): pass RELEASE_TAG so workflow_dispatch path passes tag check by @ronaldtse in #160
- refactor: SharedKeyring + Sheet enum + i18n contract test (architecture candidates 1, 2, 4) by @ronaldtse in #161
- fix(release): re-sign with Hardened Runtime version 14.0 for macOS 14.x by @ronaldtse in #164
- fix(entitlements): sandbox the Mail extension for Direct builds by @ronaldtse in #166
Full Changelog: v0.9.0...v0.9.1
What's Changed
- ci(release): pin Xcode to 16.4 and fail hard if missing by @ronaldtse in #152
- ci(release): pluginkit smoke-test for Mail extension by @ronaldtse in #153
- i18n(onboarding): add labels + Skip button keys by @ronaldtse in #155
- ci: one job per PR via new ci.yml by @ronaldtse in #158
- release(v0.9.1): bump swift-rnp floor to 0.2.3 by @ronaldtse in #157
- ci(release): rename to release.yml + add workflow_dispatch retry by @ronaldtse in #159
- fix(release): pass RELEASE_TAG so workflow_dispatch path passes tag check by @ronaldtse in #160
- refactor: SharedKeyring + Sheet enum + i18n contract test (architecture candidates 1, 2, 4) by @ronaldtse in #161
- fix(release): re-sign with Hardened Runtime version 14.0 for macOS 14.x by @ronaldtse in #164
- fix(entitlements): sandbox the Mail extension for Direct builds by @ronaldtse in #166
Full Changelog: v0.9.0...v0.9.1
v0.9.0
What's Changed
- Feature mail plugin by @w-i-n-s in #2
- Feature decrypt by @w-i-n-s in #7
- Feature framework by @w-i-n-s in #8
- Compatibility fixes by @w-i-n-s in #9
- Feature keys by @w-i-n-s in #10
- Feature encoding by @w-i-n-s in #11
- Add SwiftPM package binding librnp directly (CRnp + Rnp) with tests and CI by @ronaldtse in #12
- Make the Apple Mail extension fully functional on the Rnp SwiftPM package by @ronaldtse in #13
- test(mime): expand corpus and add property-based tests by @ronaldtse in #31
- ci: add release dry-run with self-signed certificate by @ronaldtse in #34
- feat: stub MailKit for unit tests via MessageSecurityCore by @ronaldtse in #32
- test: add XCUITest target for container app by @ronaldtse in #33
- refactor: move Mail security banner to MailSecurityUI + snapshot tests by @ronaldtse in #35
- test: expand accessibility audits and fix UI test runner signing by @ronaldtse in #36
- ci: local mail server and Mail end-to-end test harness by @ronaldtse in #37
- test: robust snapshots, localization validation, mail e2e docker, CI UI tests by @ronaldtse in #39
- fix: portable pkgconfig, device-only keychain, testing docs by @ronaldtse in #38
- feat: richer Mail e2e banner assertions with SecurityStateRecorder by @ronaldtse in #40
- feat(l10n): add machine-translated localizations for 10 macOS languages by @ronaldtse in #41
- test: expand XCUITest coverage for import and trust flows by @ronaldtse in #42
- feat(ui): macOS-native redesign of the container app by @ronaldtse in #43
- feat(ui): deep polish redesign of the container app by @ronaldtse in #44
- feat: rebrand container app to RNP with logo and brand palette by @ronaldtse in #45
- feat: direct Mail.app email view integration by @ronaldtse in #46
- docs: landing site and user/developer documentation by @ronaldtse in #47
- feat(mail): encrypt outgoing mail to the sender's own key by @ronaldtse in #58
- fix: extend expiry on subkeys as well as the primary by @ronaldtse in #59
- feat: full rename to RNP (target, scheme, scripts, docs) by @ronaldtse in #60
- feat: auto-fetch recipient keys from keyservers in Mail compose by @ronaldtse in #67
- feat: fetch signer key for unknown signers in the Mail banner by @ronaldtse in #68
- feat: recipient key expired warning and fetch/update action by @ronaldtse in #69
- feat: signature mismatch warning with reason and actions by @ronaldtse in #70
- feat: trust level management (reject key change, trust history) by @ronaldtse in #71
- feat: keyserver management (add known keyservers) by @ronaldtse in #72
- feat: foreign passphrase support for imported secret keys by @ronaldtse in #73
- feat: Touch ID runtime effect for keyring unlock by @ronaldtse in #74
- feat: protected headers (Memory Hole) for PGP/MIME encrypted mail by @ronaldtse in #75
- fix: P3 fixes (auto-flag expired/revoked keys, cleanup trust on delete, doc drift) by @ronaldtse in #76
- docs: add Astro + Starlight documentation site (docs-site/) by @ronaldtse in #77
- docs-site: redesign with rnpgp.org design language by @ronaldtse in #78
- docs-site: ultimate polish, command palette, and easter eggs by @ronaldtse in #79
- Roadmap implementation: engine layer, FFI, UI views, docs by @ronaldtse in #81
- Roadmap follow-ups: Autocrypt wiring, AEAD/v6 envelope, symmetric decrypt, UI hooks, docs by @ronaldtse in #82
- Roadmap follow-ups 2: transition certification, v6 keygen, AEAD capability, mailbox scanner, Gossip, reply heuristic, license bundling by @ronaldtse in #83
- Roadmap follow-ups 3: SwiftUI views for BCC, mailbox scan, transition wizard, settings, archived section, licenses by @ronaldtse in #84
- Roadmap follow-ups 4: ComposePolicy, DecryptionFailure banner, OfflinePublishQueue, container view, settings docs by @ronaldtse in #85
- Roadmap follow-ups 5: offline-publish wiring, ComposePolicy encode, per-account Autocrypt, banner buttons, coordinator by @ronaldtse in #86
- Roadmap follow-ups 6: signed ExtensionState, per-account Autocrypt UI, mailbox-scan nav, KeysListWithArchived by @ronaldtse in #87
- Roadmap follow-ups 7: iCloud sync, paper-key restore, recommended-action banner, inline recovery, send-separately, Tools nav by @ronaldtse in #88
- Roadmap follow-ups 8: BCC resolution helper, recipient diagnostics, MailboxScanDriver protocol by @ronaldtse in #89
- Roadmap follow-ups 9: SecurityStateRecordStore tests + scenario updates by @ronaldtse in #90
- Roadmap follow-ups 10: Autocrypt decode tests + ComposePolicy encode tests by @ronaldtse in #91
- Roadmap follow-ups 11: print layout, archived-keys wiring, BCC handler — 106/108 done by @ronaldtse in #92
- Roadmap final: PQ interop tests, KeychainSigningKeyHelper DRY, troubleshooting page by @ronaldtse in #93
- Roadmap final sweep: DRY test helper, features update — 108/108 items complete by @ronaldtse in #94
- fix(ui): wire RecoverySheetWizard iCloud toggle to engine by @ronaldtse in #95
- refactor(engine): EncodingRequest carries bccAddresses as a real field by @ronaldtse in #96
- docs: update features cryptography + development repo layout by @ronaldtse in #97
- refactor: eliminate try! in library code via AutocryptStore.inMemory() by @ronaldtse in #98
- feat(ui): wire paper-key restore into onboarding flow by @ronaldtse in #99
- feat(ui): QR code generation for paper-key print layout by @ronaldtse in #100
- docs(impl): update TODO.impl status fields to actual state by @ronaldtse in #101
- chore: remove accidental .bak files from sed by @ronaldtse in #102
- docs: TODO.human-work.md — remaining human-only tasks by @ronaldtse in #103
- Production-ready: README feature highlights + next steps by @ronaldtse in #104
- Architecture: extract SignedJSONStore generic from KeyStateStore by @ronaldtse in #109
- Architecture: DRY test helpers + SignedJSONStore date strategies by @ronaldtse in #110
- Architecture: TrustStore migrated to SignedJSONStore by @ronaldtse in #111
- Architecture: SecurityStateRecordStore uses KeychainSigningKeyHelper (DRY complete) by @ronaldtse in #112
- refactor: AccountKeyedPolicyStore.inMemory() consistency fix by @ronaldtse in #113
- fix: silence no-op let pattern warning in InlineRecoverySheets by @ronaldtse in #114
- rename: RNP Mail → RNP for Mail (com.rnpgp.RNPForMail) by @ronaldtse in #115
- icon: replace app icon with RNP brand symbol by @ro...
0.1
First Mail.app security plugin release. Featured functionality:
- For all received (and auto-imported) public keys it shows a security menu in composing a new message window
- For received messages with detached signs (sign plain text without encrypting the original text) it shows verification status for the message.
Compatibility: Intel - only
Installation: Uncompress to /Applications folder and start the app (app is just a placeholder). In Mail.app -> Settings -> Extensions -> Switch on the extension