Rolodex reopens on the entry you last had open (ROLO-0026)
After an unlock, the entry you were viewing when you locked or closed
the app is selected again. Only the entry's random ID is kept in the
settings file, never its name or contents.
A sample import file and a description of the import format (ROLO-0029)
examples/sample-import.txt is a ready-made example, and the README's
"Importing a list" section explains the format.
Release downloads carry build provenance (ROLO-0076)
Each binary comes with a signed record of the workflow run and commit
that built it. Check one with
gh attestation verify <file> --repo milnet01/rolodex.
Reorder fields and categories from the keyboard (ROLO-0053)
Ctrl+Up and Ctrl+Down move the focused field or category. Screen
readers now announce the icon-only buttons by name, and the category
count badge reads as "3 entries" instead of a bare number.
Warning when your clock may make two-factor codes wrong (ROLO-0068)
If your computer's clock is not synchronised, each two-factor code shows
a note saying the code may be rejected.
Restore from a backup when your vault will not open (ROLO-0045)
If the vault file is damaged (not a wrong password), the unlock screen
offers "Restore from Backup…" and "Start a New Vault…". The damaged
file is never deleted: it is kept beside the original with
".unreadable-" and the date added.
Use an existing vault file when setting up (ROLO-0078)
The create-a-vault screen has "Use an Existing Vault File…". This helps
if you move from running Rolodex from source to the downloadable app,
which keeps its vault in a different folder.
Choose a category for imported entries (ROLO-0067)
The import preview has an "Add to category" picker. Every imported entry
is filed there. It defaults to "No category", as before.
Regression tests for every fix above that can be tested without a display
31 new tests covering the vault, config, import, clipboard, two-factor and updater fixes. Verified by mutation testing: reintroducing each defect makes the suite fail.
Opt-in update check that only ever installs a signed release (ROLO-0037)
Rolodex can now tell you when a newer version is out and install it for you.
It never checks on its own until you turn it on — tick "Check for updates
automatically" in the app menu. You can also check once at any time with
"Check for updates...", which contacts GitHub whether or not automatic
checking is on, because choosing it is itself the consent.
When an update is found you are shown what changed and choose Later, Skip
This Version, or Update Now. Nothing installs on its own.
An update is only ever installed if it carries a valid signature from the
Rolodex release key, checked over the exact bytes downloaded. A tampered
download, a wrong signature, or a missing one all mean nothing is installed
and your current version is untouched. The check sends nothing about you and
nothing from your vault, needs no unlock, and is the app's only network
access — see DESIGN.md and SECURITY.md.
In-app updating applies to the downloadable builds. Running from source,
updating is git pull as before.
Note for maintainers: until scripts/gen-signing-key.py has been run and the
signing key added to the repository, the built-in key is a placeholder that
verifies nothing, so the feature offers updates it will refuse to install.
That is deliberate — it fails closed rather than open.
The macOS download builds again (ROLO-0087)
A build-script change after 1.3.1 used a tool macOS does not have, so
the Mac binary could not be built. Releases include it again.
Release pages show what changed (ROLO-0039)
A release's notes are now its section of this changelog. 1.3.1 was
published with a blank page.
Copying a password can no longer freeze the window (ROLO-0046)
Clipboard helpers now run in the background. A helper that hangs no
longer locks up the app for several seconds.
Closing the window now clears a copied secret from the clipboard (ROLO-0034)
Locking already did this; closing now does too.
Actions that did nothing now say why (ROLO-0070)
Saving an entry with no name highlights the name. Importing with nothing
ticked, and adding or renaming a category to a name that already
exists, show a message. Creating a vault no longer freezes the window.
Enter now works in the Change Password dialog. An import file with more
than 2000 entries is refused with a message instead of freezing.
Dragging a field down by one place now works (ROLO-0053)
It used to land back where it started.
Two copies of Rolodex can no longer overwrite each other's changes (ROLO-0044)
While one copy has the vault unlocked, another copy refuses to unlock
it. If the file is changed by anything else (a sync tool, say), your
next save asks whether to reload it or overwrite it, instead of
silently replacing it. Creating a vault no longer replaces one that
appeared in the meantime.
A vault kept as a symlink stays a symlink (ROLO-0078)
Since 1.3.1, saving replaced the link with a regular file. It now
writes to the file the link points at. Note that saving needs
permission to create files in the vault's folder; a read-only folder
holding a writable vault cannot be saved to.
Auto-lock with a dialog open now actually hides your entries (ROLO-0085)
If auto-lock fired while an editor or another dialog was open, only
the dialog closed. The main window stayed on screen behind the unlock
screen. Locking now closes every dialog and the window.
Clicking "Check for updates" repeatedly no longer starts several checks (ROLO-0051)
Only one check, offer or download runs at a time, and the menu item
is greyed out while it does.
Turning on update checks says so when the setting could not be saved (ROLO-0063)
Before, it reported success even when the settings file was not
writable, and the setting was silently lost.
Ticking a duplicate in the import preview now imports it (ROLO-0047)
A duplicate starts unticked. Before, ticking it did nothing: it was
thrown away at import. It now lands as a second entry with the same
name. Two same-named entries within one file are now marked too.
Duplicate-name checks agree on surrounding spaces (ROLO-0065)
The editor's warning and the importer now use one rule, so " GitHub "
and "github" count as the same name in both.
Saved-at times now record their timezone (ROLO-0048)
New and edited entries store the UTC offset, so edits keep their order
across a clock change. Times already in your vault are left as they were.
Importing a huge file shows a message instead of crashing (ROLO-0050)
Files over 10 MB are refused with "That file is too large to import".
Generated passwords no longer over-use digits and symbols (ROLO-0069)
Every character is now drawn evenly. Each chosen character type is
still guaranteed to appear.
A damaged or very old vault entry opens instead of failing (ROLO-0071)
Missing names, labels or values are filled with blanks when the vault
loads. The Edit button, search and Password Health no longer fail on them.
Two-factor code generation rejects impossible settings with a clear error (ROLO-0068)
An unknown algorithm, a bad digit count or period, or a clock set before
1970 now raise a readable error.
An interrupted save no longer leaves a stray copy of your vault behind (ROLO-0060)
Saving works by writing to a temporary file first and then swapping it into
place, so a failed save can never damage your real vault. If the app was
killed at exactly the wrong moment — a Ctrl-C in a terminal, or a shutdown
asking it to quit — that temporary file could be left sitting next to the
vault, holding a complete encrypted copy of everything in it. It is now
cleaned up in those cases too. A hard power cut or a force-kill still cannot
be cleaned up, because nothing gets the chance to run; any leftover file is
readable only by you, and the design document now says so plainly instead of
promising more than the code can deliver.
Several smaller correctness fixes
A failed update download now reports itself instead of ending silently. A vault written by a future version of Rolodex is refused rather than relabelled. "Hide" no longer re-ticks itself after you un-tick it and then edit the label. Secret fields tell the system not to keep them in input-method history or spellcheck. Generating a password while peeking no longer leaves it on screen. Short generated passwords can now contain digits and symbols. A malformed otpauth:// link no longer makes an entry unopenable. Two-factor settings outside the standard ranges are rejected. A base32 seed containing characters that look like base32 after case-folding is rejected rather than silently decoded to the wrong secret. Toast messages escape field labels, so a label containing "&" or "<" displays correctly. Release notes from GitHub are stripped of control and text-direction characters before being shown.
Dragging a category to the bottom of the list now works
A dragged category always landed just above the one you dropped it on, so the last position was unreachable and there was no other way to get there.
Backups are created private, and an interrupted backup cannot destroy the previous one
The backup was created readable by other users and only made private afterwards, leaving a window during which the whole encrypted vault was exposed. It also overwrote the destination in place, so a backup interrupted over a previous good one destroyed it.
Importing an empty file no longer creates a nameless entry
An empty or blank file produced one entry with no name instead of the "No entries found in file." message.
Clearing the search box brings back the entry you had selected
Typing until the selected entry dropped out of the results discarded the selection for good; clearing the search then showed nothing. Collapsing a category did the same.
A hand-edited settings file can no longer stop the app opening
A stray value in .rolodex.conf — which the README invites you to edit — crashed during startup and left the unlock window stuck on "Unlocking..." forever. Bad values now fall back to their defaults, the settings file is written atomically so an interrupted save cannot blank it, and any failure after a successful unlock is now shown rather than freezing the dialog.
A corrupt vault now says so instead of reporting a wrong password
A truncated or damaged vault file failed to decrypt and was reported as "Wrong password." — which, for an app with no password recovery, invites you to delete the file and start again, destroying something a backup restore could have salvaged.
Passwords with a leading or trailing space are stored exactly as typed
Saving an entry trimmed spaces off every value, silently altering any secret that deliberately had one, with no way to express it.
Copying works on macOS and Windows, and no longer fails on Linux when wl-clipboard is installed under X11
Copying only ever tried the three Linux clipboard tools, so it did nothing at all on macOS and Windows. Separately, it gave up on the first tool it found even when that tool failed — so merely having wl-clipboard installed on an X11 desktop broke every copy, while a working alternative sat untried.
Typing now counts as activity for the auto-lock
Only mouse movement reset the idle timer, so writing a long note without touching the mouse got you locked out mid-edit, losing the open dialog. The comment in the code had claimed key presses counted; now they do.
Cancelling a restore now actually cancels it
Pressing Cancel or Escape while a backup was being unlocked closed the dialog but did not stop the work, so a cancelled restore still went on to overwrite your live vault.
Opening Rolodex a second time no longer creates a second window that overwrites the first
Launching Rolodex while it was already running put a fresh unlock screen over the live window, and unlocking made a second, independent copy of your vault in memory. Whichever window saved last wiped out the other's changes with no warning. A second launch now just brings the existing window forward.
Changing your master password can no longer leave you locked out
The new password was adopted before the re-encrypted vault was known to have been written. If that write failed, the app looked like the change had not taken while actually holding the new password — and the next edit would quietly re-encrypt your vault with a password you may never have written down. The vault is now written first and the new password adopted only once it has landed. Restoring from a backup had the same flaw and is fixed the same way.
A failed save is now reported instead of silently pretending to work
If the vault could not be written — a full disk, a read-only folder — the app carried on as though it had saved. You would only find out at the next unlock, with the change gone. It now tells you.
An update that finishes after you lock the app no longer installs itself
If a download completed after you locked or closed Rolodex, it went ahead and replaced the program and restarted it — potentially while you were typing your master password into the lock screen. It now discards the download instead. Leftover part-downloaded files, which nothing previously removed, are also cleaned up at startup.