| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| site-files.sha256 | 2026-09-30 | 1.2 kB | |
| cadenas-v1.5.0-windows-x64.exe | 2026-09-30 | 94.6 MB | |
| cadenas-v1.5.0.intoto.jsonl | 2026-09-30 | 2.4 kB | |
| cadenas-v1.5.0.sigstore.json | 2026-09-30 | 11.8 kB | |
| cadenas-site-v1.5.0.zip | 2026-09-30 | 155.9 kB | |
| cadenas-v1.5.0-linux-arm64 | 2026-09-30 | 123.9 MB | |
| cadenas-v1.5.0-linux-x64 | 2026-09-30 | 127.5 MB | |
| cadenas-v1.5.0-macos-arm64 | 2026-09-30 | 121.9 MB | |
| SHA256SUMS | 2026-09-30 | 548 Bytes | |
| README.md | 2026-09-30 | 3.5 kB | |
| v1.5.0 - hide file names, verify, large files, English source code.tar.gz | 2026-09-30 | 924.2 kB | |
| v1.5.0 - hide file names, verify, large files, English source code.zip | 2026-09-30 | 974.0 kB | |
| Totals: 12 Items | 469.9 MB | 0 | |
Hide file names, verify a file without decrypting it to disk, open encrypted files straight from the system, large files on Firefox and Safari without memory limits, and everything in English or French. No change to the file format or the encryption.
Added
- "Hide file name" option (website) and
--hide-name(CLI): the file is placed in a.ziparchive before encryption, and the result is given a neutral name (cadenas-YYYY-MM-DD.zip.cadenas). The original name is only visible after decryption. No change to the format. - CLI:
cadenas verify <file>command, which checks that a.cadenasor.agefile is intact and the password is correct, without writing anything (exit code 0 or 1, handy for verifying backups). - Website, Firefox and Safari: above 256 MiB, the result is downloaded as encryption proceeds, served by the service worker, instead of being kept entirely in memory. No more memory-related size limit on these browsers (after a first visit to the site).
- Installed website (Chrome, Edge): cadenas appears in "Open with" for
.cadenasand.agefiles, which open ready to decrypt. - Documentation in English by default, with a French version of each document (
*.fr.md) and a language switch at the top. The website footer links to the documents in the displayed language, and release notes are in English. packaging/: Homebrew formula (macOS, Linux) and winget manifests (Windows), generated for a released version byscripts/packaging.jsfrom the release checksums and the npm package. Publishing procedure inpackaging/README.md.- End-to-end tests of the website in Chromium, Firefox and WebKit (Playwright), enforced by CI: encrypt then decrypt, interoperability with the library and the age format, multi-file archive, wrong password, offline operation, CSP actually applied, no requests outside the site, axe accessibility audit (WCAG 2.1 AA, light and dark themes) and full keyboard navigation.
npm run test:e2e. - CI: the website is built on Linux, Windows and macOS, with Node.js 22 and 24, and the six builds must be bit-for-bit identical (reproducible build).
scripts/site-hashes.jsproduces the list of hashes (site-files.sha256in releases);SECURITY.mdexplains how to verify for yourself that the published site matches the source code.
Changed
- CLI: messages in English or French, following the system language (
LC_ALL,LC_MESSAGES,LANG,LANGUAGE, or the regional settings on Windows).cadenas passphraseuses the word list of that language unless--langis given. - CLI: messages are now in English unless the system language is French (they were always in French). Scripts that read them should rely on the exit code, which is unchanged.
cadenas passphrase: without--lang, the word list follows the interface language (it was always French).
Security
- Publishing:
scripts/verify-tag.jsalso checks that the tag points to the commit carrying its version (package.json); the release, npm and Docker workflows therefore reject a tag placed on the wrong commit, before any publication. - New
npm run release:tagscript: creates the signed tag only from a clean, up-to-date main, for a version listed in the CHANGELOG, then verifies it. - Website: the Content Security Policy now allows frames from the site itself (
frame-src 'self'), used only for streamed downloads; frames from other sites stay blocked.
Full changelog: CHANGELOG.md (github.com)