Conversation
ZeeCrypt v1.50: Windows-only rebrand + Picocrypt security audit fixes
Sync testing into main: latest screenshot, README note, and stale asset cleanup
zeecrypt-logo.png and zeecrypt.png were added to main independently of the testing branch's history (separate upload events), so merging testing's later deletion of these same files never propagated. They were superseded by zeecrypt-logo-scaled.png. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Remove stray pre-rebrand logo images from main
Add MSI installer for Windows releases
Pin WiX Toolset to v5 in the release build
Fix invalid XML comment in installer.wxs
Fix second literal -- in installer.wxs comment
Fix broken installer download link in README
Add SECURITY, CONTRIBUTING, Code of Conduct, and PR template
Add Explorer right-click integration
Add version display and manual update checker
Release v1.51: Explorer context menu and update checker
Fix MSI installer: per-machine install, x64 path, completion dialog
Update README screenshot to v1.51
Document Explorer integration and update checker in README Features
Simplify Windows build pipeline: replace Resource Hacker with go-winres
Security:
- Derive the header-MAC subkey after the keyfile key is mixed in. For
keyfile-only volumes it depended only on argon2id("", salt), so the
header could be forged; since the data MAC doesn't cover the nonce,
a forged nonce decrypted "successfully" to garbage. Breaking change
for keyfile volumes from v1.50/1.51, which are recognized (never
accepted) and pointed at v1.51. Password-only volumes are unaffected.
- broken() deleted outputFile instead of outputFile.incomplete, leaving
unauthenticated plaintext behind and deleting a file the user chose
to overwrite.
- Failed/cancelled deniable decrypts left the unwrapped .tmp (which has
a readable header) next to the volume. Temp inputs are now tracked
and removed by removeTempInput(), which only deletes files work()
created and refuses to clobber an existing *.tmp.
Fixes:
- RS repair pass re-ran recombine/unwrap: crashed on deniable volumes,
always failed on split ones. work(prepared bool) skips preparation.
- Crashes on an invalid PKCS#7 byte, a <136-byte RS tail, a too-short
deniable file, and a deniable keyfile volume opened without keyfiles.
- Split cleanup used the wrong chunk names and globbed with
metacharacter-unsafe paths.
- Enter could start a second work() mid-operation; the update modal
and applyUpdate could exit mid-operation.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Drive onDrop()/work() the way the UI does, without a window: round trips across every option, tampering and corruption, RS repair on deniable/split volumes, temp-file cleanup on failure and cancel, the keyfile header forgery, and compatibility with v1.51 volumes checked in under testdata/legacy-v1.51. Each bug test was confirmed to fail against v1.51. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
v1.52: decryption cleanup, RS repair, keyfile header MAC fix + headless tests
TheZeekA
added a commit
that referenced
this pull request
Sep 24, 2026
Merge pull request #29 from TheZeekA/main
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings
testingup to date withmainafter the v1.52 merge (#28).testinghas no commits that aren't already inmain, so this is a pure catch-up with no content changes.