12.2.0.14

"Alexander Petrari" (via tbbeta Mailing List) <[email protected]> Tue, 14 Jul 2026 15:04:39 +0300
Newsgroups gmane.mail.the-bat.beta
Organization Ritlabs, SRL
Message-ID <[email protected]>
This is a multi-part message in MIME format...

------------=_1784030694-393418-6
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hello,

Further updates to the internal implementation of OpenPGP.

Versions with the auto-update feature:
32-bit https://www.ritlabs.com/download/files3/the_bat/beta/v12/thebat_32_1=
2-2-0-14.msi
64-bit https://www.ritlabs.com/download/files3/the_bat/beta/v12/thebat_64_1=
2-2-0-14.msi

Versions without auto-update:
32-bit https://www.ritlabs.com/download/files3/the_bat/beta/v12/nau_thebat_=
32_12-2-0-14.msi
64-bit https://www.ritlabs.com/download/files3/the_bat/beta/v12/nau_thebat_=
64_12-2-0-14.msi

What's new in v12.2.0.14 since v12.2.0.11:

[+] OpenPGP keys now live in a transactional SQLite keyring (keyring.db) wi=
th on-demand lookups
[+] Backup and Restore now include the SQLite keyring, archived as a consis=
tent snapshot
[+] Text attachments are scanned for inline OpenPGP blocks, so Import Key /=
 Decrypt / Verify are one click away
[+] Pre-generated revocation certificate: revoke a key later without holdin=
g the secret key
[+] Encryption now always includes the sending identity's key, so the Sent =
copy stays readable
[+] Key Manager opens modeless =E2=80=94 it no longer blocks the rest of th=
e program or app exit
[+] PGP Preferences: key-storage toggle + "Export entire keyring to files" =
on the Files tab
[+] A key fetched from a key server/WKD is trusted only if it cryptographic=
ally self-certifies the address
[+] The key-server import dialog now shows the key fingerprint to verify ou=
t of band
[*] Public-key writes can no longer touch secret key material =E2=80=94 enf=
orced by the storage layer
[*] The default (master) key is now visually distinct from the signing key =
in the Key Manager
[*] keyring.pgp files get two rotating backup generations before every atom=
ic rewrite
[*] "Change passphrase" field relabelled "Current passphrase (empty if none=
)"
[*] Account editor tabs and the Calendar menu item gained icons; new Autocr=
ypt and Calendar glyphs
[*] Key-server/WKD HTTP responses are capped at 10 MB and refused mid-strea=
m (memory-flood guard)
[-] Fixed: a GnuPG-revoked or expired key was shown as valid (old-format si=
gnature packets were not parsed)
[-] A signature made by a revoked or expired signing key is now reported as=
 bad, not good
[-] Fixed signing cleartext with trailing whitespace producing a signature =
our verifier and GnuPG rejected
[-] Fixed a keyring data-loss path where importing a public key could wipe =
pubring/secring
[-] Key import now reports its result instead of importing silently
[-] Adding a passphrase-protected subkey to an unprotected key now warns an=
d offers to protect the key

--=20
Alexander Petrari
Ritlabs, SRL



------------=_1784030694-393418-6
Content-Type: text/plain; charset="UTF-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0

________________________________________________________
'Using TBBETA' information:
http://www.silverstones.com/thebat/TBUDLInfo.html

------------=_1784030694-393418-6--