Conversation
Renames all Picocrypt references to ZeeCrypt across source, docs, and Windows packaging metadata. Drops macOS/Linux/Flatpak/Snapcraft packaging and CI workflows since this fork only targets Windows. External Picocrypt-hosted Go dependencies (github.com/Picocrypt/*) are left untouched since they are real upstream packages, and attribution to the original Picocrypt project is preserved in the README and source header per GPL-3.0. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Use images/lock.ico for the Windows app icon (MAINICON/GLFW_ICON) in place of key.ico, and images/zeecrypt-logo-scaled.png for the README logo. Removes the old key.ico, key.svg, logo.svg, and zeecrypt-logo.png now that nothing references them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Override giu's hardcoded dark theme with a light palette (window/frame backgrounds, text, and accent colors), and retune the RED/GREEN/YELLOW status-text colors for contrast against a light background (the old neutral WHITE status color is renamed NEUTRAL and set near-black). Embed images/lock.ico into the Windows build via go-winres, generating rsrc_windows_386.syso/rsrc_windows_amd64.syso which go build links in automatically. Fix the build commands in src/README.md and both Windows CI workflows to build the package directory (`.`) instead of naming ZeeCrypt.go explicitly, since Go only auto-links .syso resource files in directory-based builds. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The old screenshot was still showing Picocrypt's dark theme. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…s from the Picocrypt security audit - PCC-001/PCC-006: replace the header's stored SHA3-512 hash of the encryption key with an HMAC-SHA3-512 of the header (flags, salts, IVs), keyed by an independent password-derived subkey. This authenticates the header against tampering in addition to verifying the password. Breaking format change: v1.50 cannot open volumes from Picocrypt or earlier ZeeCrypt versions. - PCC-002: fix a crash when previewing a dropped file whose comment-length field was corrupted/tampered to a negative value; the file-drop preview path now validates the length field the same way the decrypt path does. - PCC-005: encrypting with a comment over 99,999 characters now aborts cleanly with a status message instead of panicking. - PCC-003 was already fixed upstream (RNG errors are checked). PCC-004 (decrypt-then-verify) remains open for a future release; see Internals.md for why and what already mitigates it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Internals.mdrather than fixed — a proper fix touches the Reed-Solomon repair path, deniability temp-zip wrapper, and split/recombine handling all at once, too risky to rewrite blind without a way to compile/test it.Breaking changes
Test plan
go build .fromsrc/, not namingZeeCrypt.godirectly — needed for the icon to embed)