Skip to content

Releases: tugboatcoding/clipscrub-core

clipscrub v0.5.0-build.18

Choose a tag to compare

@github-actions github-actions released this 28 Aug 14:26

Verify what you downloaded

Two artifacts, two different checks.

The clipscrub CLI attached below was built in this run, from this repo, at v0.5.0-build.18. It carries a build provenance attestation, so you can check it against the source yourself:

gh release download v0.5.0-build.18 --repo tugboatcoding/clipscrub-core --pattern clipscrub-macos-universal.tar.gz
gh attestation verify clipscrub-macos-universal.tar.gz --repo tugboatcoding/clipscrub-core
tar -xzf clipscrub-macos-universal.tar.gz

Keep the extracted ClipscrubKit_ClipscrubKit.bundle beside the binary. It holds the ruleset and name list, and the tool cannot start without it.

The ClipScrub app disk image from clipscrub.com carries a published checksum:

shasum -a 256 ClipScrub.dmg

The disk image that was live when this tag was cut hashed to:

ClipScrub.dmg  version=0.5.0  build=18  sha256=c0905fbed5037ecb796a93e20087a3b45e26341b6c1cbf6e53dfa80a7c4e5532

If you downloaded ClipScrub since then, that is a newer disk image and a different hash. Check it against the newest release: https://github.com/tugboatcoding/clipscrub-core/releases/latest

clipscrub v0.4.0-build.12

Choose a tag to compare

@github-actions github-actions released this 18 Aug 14:38

Verify what you downloaded

Two artifacts, two different checks.

The clipscrub CLI attached below was built in this run, from this repo, at v0.4.0-build.12. It carries a build provenance attestation, so you can check it against the source yourself:

gh release download v0.4.0-build.12 --repo tugboatcoding/clipscrub-core --pattern clipscrub-macos-universal.tar.gz
gh attestation verify clipscrub-macos-universal.tar.gz --repo tugboatcoding/clipscrub-core
tar -xzf clipscrub-macos-universal.tar.gz

Keep the extracted ClipscrubKit_ClipscrubKit.bundle beside the binary. It holds the ruleset and name list, and the tool cannot start without it.

The ClipScrub app disk image from clipscrub.com holds a closed-source app, built and Developer ID signed on a maintainer machine, so it cannot be attested here. It carries a published checksum instead:

shasum -a 256 ClipScrub.dmg

The disk image that was live when this tag was cut hashed to:

ClipScrub.dmg  version=0.4.0  build=12  sha256=2bae0be3be31d0e416b4dba610a965cedd1b639ceec9cf112bffd7b2a8c57767

If you downloaded ClipScrub since then, that is a newer disk image and a different hash. Check it against the newest release: https://github.com/tugboatcoding/clipscrub-core/releases/latest

clipscrub v0.4.0-build.11

Choose a tag to compare

@github-actions github-actions released this 18 Aug 09:10

Verify what you downloaded

Two artifacts, two different checks.

The clipscrub CLI attached below was built in this run, from this repo, at v0.4.0-build.11. It carries a build provenance attestation, so you can check it against the source yourself:

gh release download v0.4.0-build.11 --repo tugboatcoding/clipscrub-core --pattern clipscrub-macos-universal.tar.gz
gh attestation verify clipscrub-macos-universal.tar.gz --repo tugboatcoding/clipscrub-core
tar -xzf clipscrub-macos-universal.tar.gz

Keep the extracted ClipscrubKit_ClipscrubKit.bundle beside the binary. It holds the ruleset and name list, and the tool cannot start without it.

The ClipScrub app disk image from clipscrub.com holds a closed-source app, built and Developer ID signed on a maintainer machine, so it cannot be attested here. It carries a published checksum instead:

shasum -a 256 ClipScrub.dmg

The disk image that was live when this tag was cut hashed to:

ClipScrub.dmg  version=0.4.0  build=11  sha256=92e16db6f5a3718c452d7890bbb0525417e3fc0dd02c387da0621963cb730d03

If you downloaded ClipScrub since then, that is a newer disk image and a different hash. Check it against the newest release: https://github.com/tugboatcoding/clipscrub-core/releases/latest

clipscrub v0.3.0-build.10

Choose a tag to compare

@github-actions github-actions released this 14 Aug 08:32

Verify what you downloaded

Two artifacts, two different checks.

The clipscrub CLI attached below was built in this run, from this repo, at v0.3.0-build.10. It carries a build provenance attestation, so you can check it against the source yourself:

gh release download v0.3.0-build.10 --repo tugboatcoding/clipscrub-core --pattern clipscrub-macos-universal.tar.gz
gh attestation verify clipscrub-macos-universal.tar.gz --repo tugboatcoding/clipscrub-core
tar -xzf clipscrub-macos-universal.tar.gz

Keep the extracted ClipscrubKit_ClipscrubKit.bundle beside the binary. It holds the ruleset and name list, and the tool cannot start without it.

The ClipScrub app disk image from clipscrub.com holds a closed-source app, built and Developer ID signed on a maintainer machine, so it cannot be attested here. It carries a published checksum instead:

shasum -a 256 ClipScrub.dmg

The disk image that was live when this tag was cut hashed to:

ClipScrub.dmg  version=0.3.0  build=10  sha256=b93e4fb10e596d24c044f766ba7c7d686cf6c22853a8f2761379215a8de10d03

If you downloaded ClipScrub since then, that is a newer disk image and a different hash. Check it against the newest release: https://github.com/tugboatcoding/clipscrub-core/releases/latest

clipscrub v0.3.0

Choose a tag to compare

@github-actions github-actions released this 13 Aug 08:21

Verify what you downloaded

Two artifacts, two different checks.

The clipscrub CLI attached below was built in this run, from this repo, at v0.3.0. It carries a build provenance attestation, so you can check it against the source yourself:

gh release download v0.3.0 --repo tugboatcoding/clipscrub-core --pattern clipscrub-macos-universal.tar.gz
gh attestation verify clipscrub-macos-universal.tar.gz --repo tugboatcoding/clipscrub-core
tar -xzf clipscrub-macos-universal.tar.gz

Keep the extracted ClipscrubKit_ClipscrubKit.bundle beside the binary. It holds the ruleset and name list, and the tool cannot start without it.

The ClipScrub app disk image from clipscrub.com holds a closed-source app, built and Developer ID signed on a maintainer machine, so it cannot be attested here. It carries a published checksum instead:

shasum -a 256 ClipScrub.dmg

The disk image that was live when this tag was cut hashed to:

ClipScrub.dmg  version=0.3.0  build=9  sha256=b64f976bc131e261727a1f2e48d593e06234b49cd6878ce73acfccaf5d1e91d3

If you downloaded ClipScrub since then, that is a newer disk image and a different hash. Check it against the newest release: https://github.com/tugboatcoding/clipscrub-core/releases/latest

clipscrub 0.2.0

Choose a tag to compare

@logicalicy logicalicy released this 06 Aug 04:47

clipscrub is the redaction CLI behind ClipScrub: on-device OCR, pattern
matching, face and barcode detection, no network. This is a prebuilt universal (arm64 + x86_64)
macOS binary, so you can run the engine without building it and without installing the app.

Install

tar -xzf clipscrub-0.2.0-macos-universal.tar.gz
xattr -dr com.apple.quarantine clipscrub-0.2.0-macos-universal
./clipscrub-0.2.0-macos-universal/clipscrub --help

The xattr line is recursive and points at the directory on purpose. tar carries the download's
quarantine flag onto the extracted binary, and unzipping in Finder instead puts it on the resource
bundle too, so clearing only the one file leaves a copy that Gatekeeper still refuses. The command
is a no-op if nothing was flagged.

Keep ClipscrubKit_ClipscrubKit.bundle next to the binary. The ruleset, the given-names list and
the model prompt live in it, and without it clipscrub exits with unable to find bundle named ClipscrubKit_ClipscrubKit.

The binary is ad-hoc signed. It is not Developer ID signed and not notarized, which is why the
quarantine flag has to come off at all: macOS flags anything a browser downloaded, and Gatekeeper
refuses an ad-hoc signature while that flag is set. If you would rather not clear a quarantine flag
on a stranger's binary, build it yourself with the command below. The package has no third-party
dependencies, so it resolves and compiles offline.

Requirements

macOS 15 (Sequoia) or later, the same floor as the app. Building it yourself also needs Swift 6
(Xcode 26 or the matching Command Line Tools).

Build this yourself

swift build -c release --product clipscrub --arch arm64 --arch x86_64

That is the whole command. SwiftPM builds both slices and joins them, so there is no separate lipo
step. The universal binary and its resource bundle land side by side in .build/apple/Products/Release/.

Two caveats worth stating plainly. Swift builds are not byte-reproducible, so your binary will not
match this one's hash — verify the download against the hash below, and treat your own build as the
stronger check. And the toolchain picks the SDK, so a different Xcode changes the sdk field in
vtool -arch arm64 -show-build clipscrub while minos stays at 15.0.

Verify the download

shasum -a 256 clipscrub-0.2.0-macos-universal.tar.gz
f571b4e175a315f855e4aa9980b9e810e808ab58c8832f19d1ceaea2e9c70cd1

What this is a copy of

This repository is a snapshot of the redaction engine inside ClipScrub, and this tag points at the
tree the attached binary was built from. Version 0.2.0 matches the shipped app.

Every commit here is minted fresh by the script that publishes the snapshot, so the SHAs in this
repo cannot name the source they came from. The two that can, stated rather than derivable:

  • This tree is the engine as of monorepo commit 9c1f2c166fcf66058c1a895cd80626742e19c8a2.
  • The shipped app's build 7 was built from 67d8b6ad968ddf06f57542a35abf51f260777af7, and stamps
    that SHA into its own Info.plist as ClipScrubSourceCommit, so a copy of the app can be checked
    against it.

Between those two commits the engine changed in three files: Package.swift raised the declared
platform floor from macOS 14 to 15 — the app has always required 15, so 14 was a floor nobody could
stand on — plus a line of README and two comments. Detection and redaction are untouched. The
clipscrub inside the app is compiled from this package by the app's own build, so it is the same
source as this download rather than the same bytes.

clipscrub 0.1.0

Choose a tag to compare

@logicalicy logicalicy released this 23 Jul 15:45

First public release of the ClipScrub redaction engine and the clipscrub CLI.

  • Local PHI/PII redaction for text, images, documents and DICOM/EDF headers. No network code, no third-party runtime dependencies.
  • Builds with Swift 6 under Xcode 26 or the plain Command Line Tools: swift build, then swift run ClipscrubVerify for the headless checks.
  • Optional on-device Foundation Models pass on macOS 26 with Apple Intelligence. --no-llm keeps output deterministic.
  • Security disclosure policy in SECURITY.md.