Releases: xardyx2/SimpleDnsCryptPlus
Release list
Simple DNSCrypt Plus 0.9.0-rc.2
Simple DNSCrypt Plus 0.9.0-rc.2
Two channels, built by the same job from the same publish layout, of this fork of
SimpleDnsCrypt, targeting .NET 10.
- Portable zip - self-contained, unzip anywhere, run
SimpleDnsCryptPlus.exeas administrator.
This is the only artifact the in-app updater can apply. - MSI - per-machine install: an entry in Apps & features, the
dnscrypt-proxyservice stopped
and removed on uninstall, per-interface DNS restored, andmsiexec /i ... /qnfor managed
deployment.
Pick one per machine. Both manage the same service and the same dnscrypt-proxy.toml, and a portable
copy next to an installed one will fight over both.
The installer's tables are audited on every build (build/inspect-msi.ps1: identity, per-machine
scope, the service-control row, the licence page, the embedded cabinet). No person has installed or
uninstalled it on a real machine yet - that needs a VM or Windows Sandbox, because uninstalling
runs netsh ... delete dns on each interface. Until this sentence is replaced with a test result,
the portable zip is the recommended channel.
Verify before running
Every archive and every installer is accompanied by a detached minisign signature. The key
that verifies them is not inside the download - it is tools/keys/update.pub in this repository - so
fetch it from the tag you downloaded from, then verify. Needs the minisign CLI:
Invoke-WebRequest `
"https://raw.githubusercontent.com/xardyx2/SimpleDnsCryptPlus/refs/tags/v0.9.0-rc.2/tools/keys/update.pub" `
-OutFile update.pub
$payload = 'SimpleDNSCryptPlus-x64-0.9.0-rc.2-portable.zip' # or the .msi of the same arch
minisign -Vm ".\$payload" -x ".\$payload.minisig" -p .\update.pub
Or check the digest against SHA256SUMS.txt:
Get-FileHash .\SimpleDNSCryptPlus-x64-0.9.0-rc.2-portable.zip -Algorithm SHA256
The in-app updater accepts only artifacts that this key signs.
These binaries are NOT Authenticode-signed
There is no code-signing certificate. Expect a SmartScreen prompt, and expect some
antivirus products to report false positives: the app writes per-interface DNS settings
under HKLM and bundles a Go binary. This is a deliberate trade-off, not an oversight -
see SECURITY.md.
Includes
dnscrypt-proxy 2.1.18 fetched at build time and checked against the
SHA-256 pinned in tools/dnscrypt-proxy.lock.json.
Credits
Original project by Christian Hermann (bitbeans), Simple DNSCrypt up to 0.7.1, and his
minisign-net library, which is what
authenticates this channel.
.NET 8 / MahApps 2 migration carried by instant.sc up to 0.8.2.
This fork is independent and is not affiliated with or endorsed by either, or by the
DNSCrypt organization.
What's Changed
- Build and publish the MSI from CI, on the fee-free WiX v3.14 by @xardyx2 in #8
- Cut 0.9.0-rc.2: the first release CI builds the installers for by @xardyx2 in #9
Full Changelog: v0.9.0-rc.1...v0.9.0-rc.2
Simple DNSCrypt Plus 0.9.0-rc.1
Simple DNSCrypt Plus 0.9.0-rc.1
Portable builds of this fork of SimpleDnsCrypt,
targeting .NET 10. Unzip anywhere and run SimpleDnsCryptPlus.exe as administrator.
Verify before running
Each zip is accompanied by a detached minisign signature made with the release key
published in this repository as tools/keys/update.pub:
minisign -Vm .\SimpleDNSCryptPlus-x64-0.9.0-rc.1-portable.zip `
-x .\SimpleDNSCryptPlus-x64-0.9.0-rc.1-portable.zip.minisig `
-p .\update.pub
Or check the digest against SHA256SUMS.txt:
Get-FileHash .\SimpleDNSCryptPlus-x64-0.9.0-rc.1-portable.zip -Algorithm SHA256
The in-app updater accepts only artifacts that this key signs.
These binaries are NOT Authenticode-signed
There is no code-signing certificate. Expect a SmartScreen prompt, and expect some
antivirus products to report false positives: the app writes per-interface DNS settings
under HKLM and bundles a Go binary. This is a deliberate trade-off, not an oversight -
see SECURITY.md.
Includes
dnscrypt-proxy 2.1.18 fetched at build time and checked against the
SHA-256 pinned in tools/dnscrypt-proxy.lock.json.
Credits
Original project by Christian Hermann (bitbeans), Simple DNSCrypt up to 0.7.1, and his
minisign-net library, which is what
authenticates this channel.
.NET 8 / MahApps 2 migration carried by instant.sc up to 0.8.2.
This fork is independent and is not affiliated with or endorsed by either, or by the
DNSCrypt organization.
What's Changed
- Stage 0: import instantsc modernization + rebrand to Simple DNSCrypt Plus by @xardyx2 in #1
- Stage 1: move to .NET 10 (single theme: target framework only) by @xardyx2 in #2
- Stage 2: current dependencies + fix the log leak (DNSCrypt#19) and the tail stall (DNSCrypt#287) by @xardyx2 in #3
- Stage 2b: automated guards for what a green build cannot see (+ Tagalog was unselectable) by @xardyx2 in #4
- Stage 3: portable zips from CI, proxy binaries out of git (2.1.5 -> 2.1.18) by @xardyx2 in #5
- Stage 4: an update channel authenticated by our own minisign key by @xardyx2 in #6
New Contributors
Full Changelog: https://github.com/xardyx2/SimpleDnsCryptPlus/commits/v0.9.0-rc.1