github dangel34/PQ-File-Encryption v4.3.3
pqfile v4.3.3

latest releases: v4.3.5, v4.3.4
2 months ago

Full Changelog: v4.3.2...v4.3.3

The headline this release is language bindings: pqfile can now be used directly from Python and Node.js, with a Kotlin/Swift binding layer started (packaging not finished yet). Also ships two carried-over CLI/library features - batch key rotation and resumable encryption for very large files - plus a GUI update with a command palette, toast notifications, and more customizable theming.

Python bindings

New pqfile-python/ package (PyPI: pqfile, PyO3 + maturin) exposes the single-recipient encrypt/decrypt path: keygen, keygen_hybrid, encrypt_bytes, decrypt_bytes, encrypt_file, decrypt_file. Files round-trip with the CLI/GUI's existing .pqf format. See pqfile-python/README.md.

Node.js bindings

New pqfile-node/ package (npm: @dangel34/pqfile, napi-rs) exposes the same operations in camelCase. Every call returns a Promise and runs off Node's main thread, so Argon2id/ML-KEM work never blocks the event loop. See pqfile-node/README.md.

Mobile bindings (partial)

New pqfile-mobile/ crate (uniffi-rs) generates Kotlin and Swift source from one Rust interface definition. The Rust layer and generated bindings are built and tested; actual Android/iOS packaging (NDK cross-compiles, Gradle module, XCFramework) isn't done yet - tracked in docs/ROADMAP.md.

GUI: command palette, toast notifications, theming

  • Command palette (Ctrl/Cmd+K) for quickly jumping between tabs
  • Toast notifications for encrypt/decrypt success and error feedback
  • Custom accent color and UI scale in Settings, for a more personalized/accessible look

Batch/recursive key rotation

pqfile rotate --old-key --new-key --recursive DIR rotates every .pqf file in a directory tree to a new recipient without re-encrypting, reporting a per-file success/failure summary rather than stopping at the first bad file.

Resumable encryption for large files

encrypt --resume checkpoints progress roughly every 64 MiB and continues from there instead of restarting after an interruption; decrypt --resume rounds out the story on the read side. Not a new wire format - a resumed file is byte-identical to one written in a single uninterrupted pass.

Named recipient groups

The CLI config file's new [groups] table lets -r some-team expand to a whole list of recipients instead of retyping them on every invocation.

Also new

  • Forward-error-correction (encrypt --fec / decrypt --fec / check --fec, opt-in fec feature): a Reed-Solomon parity sidecar that can recover from ordinary bit rot on cold storage, separate from (and never weakening) the existing tamper-evident authentication.
  • Encrypted, signed, audit log (--audit-log/--audit-key/--audit-recipient, opt-in audit feature): a hash-chained log of encrypt/decrypt events, readable only by a designated auditor's key.

Under the hood

  • CI coverage added for all three new bindings crates (previously untested)
  • Publish-pipeline scaffolding for PyPI and npm, using Trusted Publishing (OIDC) rather than stored tokens
  • The npm package needed renaming to @dangel34/pqfile after the unscoped pqfile was rejected as too similar to an existing package
  • Fixed a bug where the npm publish workflow would have silently skipped publishing the main package on every future release

Don't miss a new PQ-File-Encryption release

NewReleases is sending notifications on new releases.