Skip to content

Releases: xardyx2/SimpleDnsCryptPlus

Simple DNSCrypt Plus 0.9.0-rc.2

Pre-release

Choose a tag to compare

@github-actions github-actions released this 27 Sep 17:48
190786f

Simple DNSCrypt Plus 0.9.0-rc.2

Two channels, built by the same job from the same publish layout, of this fork of
SimpleDnsCrypt, targeting .NET 10.

  • Portable zip - self-contained, unzip anywhere, run SimpleDnsCryptPlus.exe as administrator.
    This is the only artifact the in-app updater can apply.
  • MSI - per-machine install: an entry in Apps & features, the dnscrypt-proxy service stopped
    and removed on uninstall, per-interface DNS restored, and msiexec /i ... /qn for managed
    deployment.

Pick one per machine. Both manage the same service and the same dnscrypt-proxy.toml, and a portable
copy next to an installed one will fight over both.

The installer's tables are audited on every build (build/inspect-msi.ps1: identity, per-machine
scope, the service-control row, the licence page, the embedded cabinet). No person has installed or
uninstalled it on a real machine yet
- that needs a VM or Windows Sandbox, because uninstalling
runs netsh ... delete dns on each interface. Until this sentence is replaced with a test result,
the portable zip is the recommended channel.

Verify before running

Every archive and every installer is accompanied by a detached minisign signature. The key
that verifies them is not inside the download - it is tools/keys/update.pub in this repository - so
fetch it from the tag you downloaded from, then verify. Needs the minisign CLI:

Invoke-WebRequest `
  "https://raw.githubusercontent.com/xardyx2/SimpleDnsCryptPlus/refs/tags/v0.9.0-rc.2/tools/keys/update.pub" `
  -OutFile update.pub
$payload = 'SimpleDNSCryptPlus-x64-0.9.0-rc.2-portable.zip'   # or the .msi of the same arch
minisign -Vm ".\$payload" -x ".\$payload.minisig" -p .\update.pub

Or check the digest against SHA256SUMS.txt:

Get-FileHash .\SimpleDNSCryptPlus-x64-0.9.0-rc.2-portable.zip -Algorithm SHA256

The in-app updater accepts only artifacts that this key signs.

These binaries are NOT Authenticode-signed

There is no code-signing certificate. Expect a SmartScreen prompt, and expect some
antivirus products to report false positives: the app writes per-interface DNS settings
under HKLM and bundles a Go binary. This is a deliberate trade-off, not an oversight -
see SECURITY.md.

Includes

dnscrypt-proxy 2.1.18 fetched at build time and checked against the
SHA-256 pinned in tools/dnscrypt-proxy.lock.json.

Credits

Original project by Christian Hermann (bitbeans), Simple DNSCrypt up to 0.7.1, and his
minisign-net library, which is what
authenticates this channel.
.NET 8 / MahApps 2 migration carried by instant.sc up to 0.8.2.
This fork is independent and is not affiliated with or endorsed by either, or by the
DNSCrypt organization.

What's Changed

  • Build and publish the MSI from CI, on the fee-free WiX v3.14 by @xardyx2 in #8
  • Cut 0.9.0-rc.2: the first release CI builds the installers for by @xardyx2 in #9

Full Changelog: v0.9.0-rc.1...v0.9.0-rc.2

Simple DNSCrypt Plus 0.9.0-rc.1

Pre-release

Choose a tag to compare

@github-actions github-actions released this 27 Sep 14:11

Simple DNSCrypt Plus 0.9.0-rc.1

Portable builds of this fork of SimpleDnsCrypt,
targeting .NET 10. Unzip anywhere and run SimpleDnsCryptPlus.exe as administrator.

Verify before running

Each zip is accompanied by a detached minisign signature made with the release key
published in this repository as tools/keys/update.pub:

minisign -Vm .\SimpleDNSCryptPlus-x64-0.9.0-rc.1-portable.zip `
  -x .\SimpleDNSCryptPlus-x64-0.9.0-rc.1-portable.zip.minisig `
  -p .\update.pub

Or check the digest against SHA256SUMS.txt:

Get-FileHash .\SimpleDNSCryptPlus-x64-0.9.0-rc.1-portable.zip -Algorithm SHA256

The in-app updater accepts only artifacts that this key signs.

These binaries are NOT Authenticode-signed

There is no code-signing certificate. Expect a SmartScreen prompt, and expect some
antivirus products to report false positives: the app writes per-interface DNS settings
under HKLM and bundles a Go binary. This is a deliberate trade-off, not an oversight -
see SECURITY.md.

Includes

dnscrypt-proxy 2.1.18 fetched at build time and checked against the
SHA-256 pinned in tools/dnscrypt-proxy.lock.json.

Credits

Original project by Christian Hermann (bitbeans), Simple DNSCrypt up to 0.7.1, and his
minisign-net library, which is what
authenticates this channel.
.NET 8 / MahApps 2 migration carried by instant.sc up to 0.8.2.
This fork is independent and is not affiliated with or endorsed by either, or by the
DNSCrypt organization.

What's Changed

  • Stage 0: import instantsc modernization + rebrand to Simple DNSCrypt Plus by @xardyx2 in #1
  • Stage 1: move to .NET 10 (single theme: target framework only) by @xardyx2 in #2
  • Stage 2: current dependencies + fix the log leak (DNSCrypt#19) and the tail stall (DNSCrypt#287) by @xardyx2 in #3
  • Stage 2b: automated guards for what a green build cannot see (+ Tagalog was unselectable) by @xardyx2 in #4
  • Stage 3: portable zips from CI, proxy binaries out of git (2.1.5 -> 2.1.18) by @xardyx2 in #5
  • Stage 4: an update channel authenticated by our own minisign key by @xardyx2 in #6

New Contributors

Full Changelog: https://github.com/xardyx2/SimpleDnsCryptPlus/commits/v0.9.0-rc.1