Ants Projects Hub
← Rolodex

Changelog

Rolodex

Every release, newest first — 8 in total.

v1.6.0

Rolodex 1.6.0

Added

  • Field types now show an icon, not just a colour (ROLO-0016) Each field in the detail view carries a small icon before its label — a padlock for passwords, a cog for keys and tokens, a face for usernames and email, a network symbol for web addresses, a clock for dates, a document for anything else. The coloured bar down the left is still there; the icon says the same thing in a form that survives greyscale, colourblindness and a screen reader, which colour alone cannot.

Security

  • Releases are now signed, so in-app updates can actually install (ROLO-0041) The app has always checked the signature on a downloaded update before installing it, but the key it checked against was a deliberate blank — so no update could ever pass, and "Update now" was a button that could only fail. The real signing key is now in place. Nothing changes for anyone until the first signed release exists; from then on the app can install an update and will still refuse one that was tampered with or signed by anybody else.

v1.5.0

Rolodex 1.5.0

Added

  • Show one category at a time, and search by several words (ROLO-0009) A drop-down above the list shows all entries, one category, or the uncategorised ones. Search now finds entries containing every word you type, in any order and in any field, so "gmail work" finds "Work Gmail".

Fixed

  • The Linux download starts on every distribution, not just Ubuntu-like ones (ROLO-0088) The downloadable Linux binary was missing part of the GTK 4 toolkit and only worked where the system happened to supply it; elsewhere, such as openSUSE, it closed at once with "Namespace Gtk not available". It now carries everything it needs, and its built-in self-test checks that it does.

v1.4.0

Rolodex 1.4.0

Known issue — fixed in 1.5.0: the Linux download starts only on Ubuntu-like systems; elsewhere it closes at once with "Namespace Gtk not available". The Mac download may do the same on Macs without Homebrew's GTK. Please use 1.5.0.

Added

  • Rolodex reopens on the entry you last had open (ROLO-0026) After an unlock, the entry you were viewing when you locked or closed the app is selected again. Only the entry's random ID is kept in the settings file, never its name or contents.

  • A sample import file and a description of the import format (ROLO-0029) examples/sample-import.txt is a ready-made example, and the README's "Importing a list" section explains the format.

  • Release downloads carry build provenance (ROLO-0076) Each binary comes with a signed record of the workflow run and commit that built it. Check one with gh attestation verify <file> --repo milnet01/rolodex.

  • Reorder fields and categories from the keyboard (ROLO-0053) Ctrl+Up and Ctrl+Down move the focused field or category. Screen readers now announce the icon-only buttons by name, and the category count badge reads as "3 entries" instead of a bare number.

  • Warning when your clock may make two-factor codes wrong (ROLO-0068) If your computer's clock is not synchronised, each two-factor code shows a note saying the code may be rejected.

  • Restore from a backup when your vault will not open (ROLO-0045) If the vault file is damaged (not a wrong password), the unlock screen offers "Restore from Backup…" and "Start a New Vault…". The damaged file is never deleted: it is kept beside the original with ".unreadable-" and the date added.

  • Use an existing vault file when setting up (ROLO-0078) The create-a-vault screen has "Use an Existing Vault File…". This helps if you move from running Rolodex from source to the downloadable app, which keeps its vault in a different folder.

  • Choose a category for imported entries (ROLO-0067) The import preview has an "Add to category" picker. Every imported entry is filed there. It defaults to "No category", as before.

  • Regression tests for every fix above that can be tested without a display 31 new tests covering the vault, config, import, clipboard, two-factor and updater fixes. Verified by mutation testing: reintroducing each defect makes the suite fail.

  • Opt-in update check that only ever installs a signed release (ROLO-0037) Rolodex can now tell you when a newer version is out and install it for you. It never checks on its own until you turn it on — tick "Check for updates automatically" in the app menu. You can also check once at any time with "Check for updates...", which contacts GitHub whether or not automatic checking is on, because choosing it is itself the consent.

    When an update is found you are shown what changed and choose Later, Skip This Version, or Update Now. Nothing installs on its own.

    An update is only ever installed if it carries a valid signature from the Rolodex release key, checked over the exact bytes downloaded. A tampered download, a wrong signature, or a missing one all mean nothing is installed and your current version is untouched. The check sends nothing about you and nothing from your vault, needs no unlock, and is the app's only network access — see DESIGN.md and SECURITY.md.

    In-app updating applies to the downloadable builds. Running from source, updating is git pull as before.

    Note for maintainers: until scripts/gen-signing-key.py has been run and the signing key added to the repository, the built-in key is a placeholder that verifies nothing, so the feature offers updates it will refuse to install. That is deliberate — it fails closed rather than open.

Changed

  • Rolodex states the toolkit versions it needs (ROLO-0049) It needs GTK 4.12 or newer and libadwaita 1.5 or newer. On an older system it now says so and exits, instead of failing with a technical error. The README lists both.

  • New master passwords must be at least 12 characters, up from 8 (ROLO-0079) Your existing vault is unaffected and still opens exactly as before — unlocking never checks the length. The new minimum applies when you create a vault or change your master password. Eight characters is weak against the offline guessing that SECURITY.md names as the main threat this app faces.

  • Password health no longer calls two fields in the same entry "reused" (ROLO-0066) The reuse warning is there to tell you one password is protecting two different accounts. It used to fire on any repeat at all, so an entry with a "Password" and a matching "Backup password" was flagged even though that is a single account. It now counts across entries only.

  • Saving is no longer slowed by re-scrambling your master password on every edit (ROLO-0043) Rolodex turns your master password into an encryption key using a deliberately slow calculation, so that guessing it is expensive. That calculation used to run again every single time anything changed — adding an entry, renaming one, dragging it to a category, reordering a field. It now runs once when you unlock, and again only if the password itself changes or you restore a backup. Measured on a mid-range desktop, a save went from about 81 milliseconds to under a tenth of one.

  • Build and CI hardening All GitHub Actions are pinned to a specific commit rather than a moving tag, so a re-pointed tag cannot introduce new code into a release build. Checkout no longer leaves credentials in the workspace. The Linux and macOS build self-tests have the same timeout the Windows one already had, so a hang fails the build instead of blocking a runner for six hours. certifi is now named in the build scripts' prerequisites and asserted by the local CI gate, since the release binaries are built with it. A missing typelib now fails the Windows build immediately rather than producing a binary that fails mysteriously at runtime.

Fixed

  • The macOS download builds again (ROLO-0087) A build-script change after 1.3.1 used a tool macOS does not have, so the Mac binary could not be built. Releases include it again.

  • Release pages show what changed (ROLO-0039) A release's notes are now its section of this changelog. 1.3.1 was published with a blank page.

  • Copying a password can no longer freeze the window (ROLO-0046) Clipboard helpers now run in the background. A helper that hangs no longer locks up the app for several seconds.

  • Closing the window now clears a copied secret from the clipboard (ROLO-0034) Locking already did this; closing now does too.

  • Actions that did nothing now say why (ROLO-0070) Saving an entry with no name highlights the name. Importing with nothing ticked, and adding or renaming a category to a name that already exists, show a message. Creating a vault no longer freezes the window. Enter now works in the Change Password dialog. An import file with more than 2000 entries is refused with a message instead of freezing.

  • Dragging a field down by one place now works (ROLO-0053) It used to land back where it started.

  • Two copies of Rolodex can no longer overwrite each other's changes (ROLO-0044) While one copy has the vault unlocked, another copy refuses to unlock it. If the file is changed by anything else (a sync tool, say), your next save asks whether to reload it or overwrite it, instead of silently replacing it. Creating a vault no longer replaces one that appeared in the meantime.

  • A vault kept as a symlink stays a symlink (ROLO-0078) Since 1.3.1, saving replaced the link with a regular file. It now writes to the file the link points at. Note that saving needs permission to create files in the vault's folder; a read-only folder holding a writable vault cannot be saved to.

  • Auto-lock with a dialog open now actually hides your entries (ROLO-0085) If auto-lock fired while an editor or another dialog was open, only the dialog closed. The main window stayed on screen behind the unlock screen. Locking now closes every dialog and the window.

  • Clicking "Check for updates" repeatedly no longer starts several checks (ROLO-0051) Only one check, offer or download runs at a time, and the menu item is greyed out while it does.

  • Turning on update checks says so when the setting could not be saved (ROLO-0063) Before, it reported success even when the settings file was not writable, and the setting was silently lost.

  • Ticking a duplicate in the import preview now imports it (ROLO-0047) A duplicate starts unticked. Before, ticking it did nothing: it was thrown away at import. It now lands as a second entry with the same name. Two same-named entries within one file are now marked too.

  • Duplicate-name checks agree on surrounding spaces (ROLO-0065) The editor's warning and the importer now use one rule, so " GitHub " and "github" count as the same name in both.

  • Saved-at times now record their timezone (ROLO-0048) New and edited entries store the UTC offset, so edits keep their order across a clock change. Times already in your vault are left as they were.

  • Importing a huge file shows a message instead of crashing (ROLO-0050) Files over 10 MB are refused with "That file is too large to import".

  • Generated passwords no longer over-use digits and symbols (ROLO-0069) Every character is now drawn evenly. Each chosen character type is still guaranteed to appear.

  • A damaged or very old vault entry opens instead of failing (ROLO-0071) Missing names, labels or values are filled with blanks when the vault loads. The Edit button, search and Password Health no longer fail on them.

  • Two-factor code generation rejects impossible settings with a clear error (ROLO-0068) An unknown algorithm, a bad digit count or period, or a clock set before 1970 now raise a readable error.

  • An interrupted save no longer leaves a stray copy of your vault behind (ROLO-0060) Saving works by writing to a temporary file first and then swapping it into place, so a failed save can never damage your real vault. If the app was killed at exactly the wrong moment — a Ctrl-C in a terminal, or a shutdown asking it to quit — that temporary file could be left sitting next to the vault, holding a complete encrypted copy of everything in it. It is now cleaned up in those cases too. A hard power cut or a force-kill still cannot be cleaned up, because nothing gets the chance to run; any leftover file is readable only by you, and the design document now says so plainly instead of promising more than the code can deliver.

  • Several smaller correctness fixes A failed update download now reports itself instead of ending silently. A vault written by a future version of Rolodex is refused rather than relabelled. "Hide" no longer re-ticks itself after you un-tick it and then edit the label. Secret fields tell the system not to keep them in input-method history or spellcheck. Generating a password while peeking no longer leaves it on screen. Short generated passwords can now contain digits and symbols. A malformed otpauth:// link no longer makes an entry unopenable. Two-factor settings outside the standard ranges are rejected. A base32 seed containing characters that look like base32 after case-folding is rejected rather than silently decoded to the wrong secret. Toast messages escape field labels, so a label containing "&" or "<" displays correctly. Release notes from GitHub are stripped of control and text-direction characters before being shown.

  • Dragging a category to the bottom of the list now works A dragged category always landed just above the one you dropped it on, so the last position was unreachable and there was no other way to get there.

  • Backups are created private, and an interrupted backup cannot destroy the previous one The backup was created readable by other users and only made private afterwards, leaving a window during which the whole encrypted vault was exposed. It also overwrote the destination in place, so a backup interrupted over a previous good one destroyed it.

  • Importing an empty file no longer creates a nameless entry An empty or blank file produced one entry with no name instead of the "No entries found in file." message.

  • Clearing the search box brings back the entry you had selected Typing until the selected entry dropped out of the results discarded the selection for good; clearing the search then showed nothing. Collapsing a category did the same.

  • A hand-edited settings file can no longer stop the app opening A stray value in .rolodex.conf — which the README invites you to edit — crashed during startup and left the unlock window stuck on "Unlocking..." forever. Bad values now fall back to their defaults, the settings file is written atomically so an interrupted save cannot blank it, and any failure after a successful unlock is now shown rather than freezing the dialog.

  • A corrupt vault now says so instead of reporting a wrong password A truncated or damaged vault file failed to decrypt and was reported as "Wrong password." — which, for an app with no password recovery, invites you to delete the file and start again, destroying something a backup restore could have salvaged.

  • Passwords with a leading or trailing space are stored exactly as typed Saving an entry trimmed spaces off every value, silently altering any secret that deliberately had one, with no way to express it.

  • Copying works on macOS and Windows, and no longer fails on Linux when wl-clipboard is installed under X11 Copying only ever tried the three Linux clipboard tools, so it did nothing at all on macOS and Windows. Separately, it gave up on the first tool it found even when that tool failed — so merely having wl-clipboard installed on an X11 desktop broke every copy, while a working alternative sat untried.

  • Typing now counts as activity for the auto-lock Only mouse movement reset the idle timer, so writing a long note without touching the mouse got you locked out mid-edit, losing the open dialog. The comment in the code had claimed key presses counted; now they do.

  • Cancelling a restore now actually cancels it Pressing Cancel or Escape while a backup was being unlocked closed the dialog but did not stop the work, so a cancelled restore still went on to overwrite your live vault.

  • Opening Rolodex a second time no longer creates a second window that overwrites the first Launching Rolodex while it was already running put a fresh unlock screen over the live window, and unlocking made a second, independent copy of your vault in memory. Whichever window saved last wiped out the other's changes with no warning. A second launch now just brings the existing window forward.

  • Changing your master password can no longer leave you locked out The new password was adopted before the re-encrypted vault was known to have been written. If that write failed, the app looked like the change had not taken while actually holding the new password — and the next edit would quietly re-encrypt your vault with a password you may never have written down. The vault is now written first and the new password adopted only once it has landed. Restoring from a backup had the same flaw and is fixed the same way.

  • A failed save is now reported instead of silently pretending to work If the vault could not be written — a full disk, a read-only folder — the app carried on as though it had saved. You would only find out at the next unlock, with the change gone. It now tells you.

  • An update that finishes after you lock the app no longer installs itself If a download completed after you locked or closed Rolodex, it went ahead and replaced the program and restarted it — potentially while you were typing your master password into the lock screen. It now discards the download instead. Leftover part-downloaded files, which nothing previously removed, are also cleaned up at startup.

Security

  • Backup errors no longer show the file's full location on screen (ROLO-0072)

  • The updater only connects to GitHub, and a download has a time limit (ROLO-0058) A download link pointing anywhere but GitHub is refused, including after a redirect. A server that sends data very slowly is cut off after 15 minutes instead of holding the download open forever.

  • The updater cannot make an insecure connection even by mistake (ROLO-0080) Its network code has no way to open a plain http:// address at all, rather than relying on a check. The secure-connection setup is also built once instead of on every request.

  • Clear the master password and secret field values out of their widgets (ROLO-0059) The unlock and restore dialogs left the password sitting in the box that took it, and closing an entry editor left every secret it had loaded in the field rows. Each is now cleared once the value has been handed over. A failed unlock still keeps what you typed, so you can correct it.

  • Locking now clears the clipboard and the on-screen entry Locking the vault left a copied password on the clipboard until its timer ran out — and forever if you had turned the clipboard timer off. It also left the last-viewed entry's values in the window. Both are now cleared when you lock.

  • Two-factor seeds are now hidden like any other secret A field holding a 2FA seed was shown in plain text unless its label happened to contain one of the general secret keywords — so a field named "2FA" or "TOTP" displayed the long-term secret openly, right next to the code generated from it. Recognised seeds are now always hidden, including an otpauth:// link pasted under any label at all. This applies to entries already in your vault, not only newly saved ones.

  • The release-signing key no longer sits in a job that has already run third-party code The workflow that builds Rolodex is now split in two. Building happens with no signing key present and read-only permissions; a separate step downloads the finished binaries onto one clean machine, installs a fixed version of its one dependency, and only then signs them. The key is also read straight from its secret store rather than being written to a file, so it can no longer be left behind on disk when a step fails partway.

v1.3.1

Fixed

  • Vault saves are now atomic — an interrupted save can no longer corrupt your vault save_vault (and the plaintext export) now write to a temporary file in the same folder, flush it to disk, then atomically rename it into place. An interrupted write — a crash, a full disk, or a power cut mid-save — leaves the previous vault intact instead of truncating your only copy of your credentials.

v1.3.0

1.3.0 — TOTP 2FA codes, password health checkup, and keyboard shortcuts

Added

  • Generate TOTP 2FA codes from stored authenticator secrets. (ROLO-0006) Store an otpauth:// URI or a 2FA-labelled base32 setup key and Rolodex renders the rotating RFC 6238 code inline with a countdown ring and one-click copy. Pure-stdlib TOTP — no new dependency.

  • Password health checkup: flag weak and reused secrets (ROLO-0008) A new "Password health..." menu item opens a read-only report that scores every stored secret on length and character-class variety (Weak/Fair/Good/Strong) and flags any secret reused across entries, worst first. All analysis runs in-process over the decrypted vault — nothing leaves the app.

  • GitHub Actions CI: ruff lint + pytest on every push/PR (ROLO-0020) New .github/workflows/ci.yml runs ruff and the pytest suite on push and PR to main, installing the system GTK stack from apt so import rolodex resolves. Pinned actions/checkout@v7.

  • Keyboard shortcuts for common actions (ROLO-0007) Ctrl+F focuses search, Ctrl+N adds an entry, Ctrl+Shift+C copies the selected entry's password/secret (plain Ctrl+C still copies selected text), Ctrl+L locks the vault, Escape clears the search box, and Ctrl+? opens a keyboard-shortcuts reference.

  • Unsaved-changes guard (ROLO-0022) — closing the add/edit dialog with edits in flight now confirms before discarding them.

  • Duplicate-name warning (ROLO-0023) — saving an entry whose name matches another (case-insensitive) now asks for confirmation first.

  • Show/hide (eye) toggle on sensitive fields in the add/edit editor (ROLO-0021) — peek at a masked value while editing, view-only so it never changes whether the field is stored as a secret.

Changed

  • Extract shared helpers: single 0600 file-write, container-clear, dialog scaffold (ROLO-0019) Internal refactor, no behaviour change. The owner-only (0600) write now lives in one write_private_file() used by both the vault save and the plaintext export; a clear_container() replaces three hand-rolled "remove all rows" loops; and make_dialog_scaffold() collapses the ToolbarView+HeaderBar+Clamp boilerplate repeated across all six dialogs. Net 53 fewer lines.

  • Debounced sidebar search (ROLO-0018) — the list rebuilds once typing pauses (~150ms) instead of on every keystroke.

v1.2.0

Added

  • Prebuilt Windows binary (rolodex-windows-x86_64.exe) is now available (ROLO-0031) — the GTK-bundling issue that withheld it from v1.1.0 is resolved, so all three platforms now ship self-contained single-file binaries.

  • Built-in password generator (ROLO-0004) — a button on sensitive fields in the add/edit editor opens a popover to generate a strong random password, with length and character-class options. Uses Python's secrets module and guarantees at least one character from each selected class.

Changed

  • New application icon — a glossy Rolodex card-file design (rolodex.png), replacing the flat rolodex.svg. Corners are transparent (rounded-square silhouette), so the icon renders cleanly on any desktop background. rolodex.desktop, the README, and the file-naming doc now reference the PNG.

Security

  • Automatic clipboard clearing (ROLO-0003) — a copied secret is wiped from the clipboard a few seconds later, but only if you haven't copied something else in the meantime. Delay is configurable via clipboard_clear_seconds in .rolodex.conf (default 20s; 0 disables).

  • Automatic vault lock on idle (ROLO-0002) — after a period of inactivity the vault re-locks, wiping the decrypted data and master password from memory. Adds a Lock button (Ctrl+L) for locking on demand. Idle timeout is configurable via idle_lock_seconds in .rolodex.conf (default 300s; 0 disables).

v1.1.0

Rolodex v1.1.0

First public release of Rolodex — a minimal, encrypted credential manager for the Linux desktop (GTK4/libadwaita).

Downloads (self-contained — nothing else to install)

  • Linux (x86-64): rolodex-linux-x86_64 — chmod +x rolodex-linux-x86_64 && ./rolodex-linux-x86_64. Built on Ubuntu 24.04 (needs a reasonably recent glibc).
  • macOS (Apple Silicon): rolodex-macos-arm64 — unsigned, so the first time right-click → Open to get past Gatekeeper, then confirm.

Each binary bundles Python, GTK4/libadwaita, and all dependencies, and passes a self-test on its own OS in CI before publishing. Your vault is stored in a per-user data directory (~/.local/share/Rolodex, ~/Library/Application Support/Rolodex).

Windows

A Windows build isn't ready yet — the GTK bundle builds but doesn't load at runtime. Tracked as ROLO-0031. Run from source in the meantime (see the README).

Highlights since the pre-open-source baseline

  • Full open-source docs (README, SECURITY, CONTRIBUTING, DESIGN, feature specs, standards).
  • Bug fixes: file-descriptor double-close on write errors, a sensitive-field cleartext leak in the editor, and count-label pluralisation.
  • Seed test suite.

See CHANGELOG.md for the full list.

1.0.0

Initial versioned release of the app as it existed before open-sourcing. (This version predates the public repository, so no v1.0.0 git tag exists yet; the date reflects when the app reached this state, not a tagged release.)

Added

  • Encrypted vault: PBKDF2-HMAC-SHA256 (600k iterations) + Fernet, 0600 file permissions.
  • GTK 4 / libadwaita UI: unlock/create flow, searchable sidebar, detail pane.
  • Categories with collapse/expand, drag-and-drop between categories, and management dialog.
  • Sensitive-field masking with auto-detection, per-entry reveal, and colour-coded field types.
  • One-click clipboard copy (wl-copy / xclip / xsel).
  • Text-file import with preview and duplicate detection.
  • Encrypted backup & restore, plaintext export, and master-password change.
  • Vault schema migration (v1 → v2) applied on load.