Skip to content

Envelope v1.3.0 — rShield

Choose a tag to compare

@github-actions github-actions released this 23 Sep 14:35
· 212 commits to main since this release
cad9d69

rShield checks every message you receive for phishing and dangerous attachments, explains why it flagged each one, and blocks risky downloads, all on your machine.

  • rShield: a local threat score (0-100) for each message from six analyzers, a reader banner with "Why?", "Mark safe" and "Report", envelope threat scan|show|explain|mark-safe|release|report|stats, and blocked downloads of malware-grade attachments (override with --unsafe).
  • Egress: every outbound HTTP request goes through one guarded client that refuses private addresses, follows no redirects, and times out.
  • Read tracking: reads made on another client (phone, Apple Mail) show up as message_seen events and in envelope analytics show.
  • Rules: one executor runs rules everywhere, envelope watch --run-rules now works, and a new confirm action offers actions for you to approve.
  • Behaviour change: envelope watch --webhook refuses a private or localhost URL at startup.
  • Behaviour change: add_tag rules now apply their tags. Existing tag rules start tagging mail on the next run.
  • Behaviour change: snooze and unsubscribe rules are skipped until you run envelope rule enable <name> --acknowledge-batch-actions.

See CHANGELOG.md for details.

What's Changed

  • fix(email): one guarded HTTP client for every outbound request by @tymrtn in #139
  • feat(store): detect reads from other clients as message_seen events by @tymrtn in #140
  • feat(rules): one attributed executor, watch --run-rules, confirmable offers by @tymrtn in #141
  • feat(threat): rShield threat core (A4) by @tymrtn in #142
  • chore(release): prepare v1.3.0 by @tymrtn in #143

Full Changelog: v1.2.8...v1.3.0