Skip to content

Latest commit

 

History

History
876 lines (560 loc) · 32.2 KB

File metadata and controls

876 lines (560 loc) · 32.2 KB

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

13 July 2026

13 July 2026

09 July 2026

Fixed

  • Fix new Clippy warnings for Rust 1.97.0 (#2279)
  • Ensure created has a dst and don't add parent when actions already exist (#2264)

07 July 2026

19 June 2026

11 June 2026

Added

  • Remove some long deprecated APIs (#2206)

11 June 2026

Fixed

  • Enable c2pa features in sub-crates since default-features is disabled at the workspace-level (#2219)

Other

  • Use latest release-plz and add a dry run job on release PRs (#2217)

09 June 2026

Fixed

  • DLL hijacking vulnerability in c2patool (CAI-8608) (#2031)

08 June 2026

04 June 2026

03 June 2026

01 June 2026

27 May 2026

Added

  • Add Intent support to c2patool (#2171)
  • Support CAWG callback signing via c_ffi (#2118)

Fixed

  • Share reqwest HTTP clients (#2152)

Added

  • --create <source-type> flag to sign an asset as a new original creation with the specified C2PA digital source type (e.g. digitalCapture, trainedAlgorithmicMedia). Automatically injects a c2pa.created action. Mutually exclusive with --update and --parent.
  • --update flag to generate an update manifest for non-editorial changes applied to an already-signed asset. Automatically injects a c2pa.opened action and sets the source asset as the parent ingredient. The source asset must already contain a C2PA manifest. Mutually exclusive with --create.

Changed

  • Default signing behavior now applies Edit intent: the source asset is automatically added as a parent ingredient and a c2pa.opened action is injected. Previously no intent or parent was set automatically.
  • Signature validation after signing is now enabled by default in all builds (previously only in test builds). Use --no_signing_verify to skip it.(https://github.com/contentauth/c2pa-rs/compare/c2patool-v0.26.58...c2patool-v0.26.59) 12 May 2026

11 May 2026

11 May 2026

04 May 2026

01 May 2026

01 May 2026

29 April 2026

Added

  • Add init trust, trust sidecars, and atomic sidecar writes, plus fixes (#2093)

28 April 2026

Fixed

  • c2pa-c-ffi UB detected by miri (#2089)

27 April 2026

Documented

  • Corrections and clean up (#2057)

16 April 2026

Fixed

  • Multi rendition support (#2058)

15 April 2026

14 April 2026

09 April 2026

08 April 2026

Fixed

  • Allow any file type to be signed with a sidecar (#2014)

07 April 2026

03 April 2026

31 March 2026

27 March 2026

Fixed

  • Updated crJSON Schema (#1975)

Other

  • Update x_509.md (#1942)

23 March 2026

23 March 2026

Added

  • Add cr_json() and cr_json_value() to Reader; remove separate CrJsonReader (#1919)

16 March 2026

Fixed

  • Pin atree to 0.5.2 (#1940)

13 March 2026

12 March 2026

12 March 2026

11 March 2026

10 March 2026

04 March 2026

03 March 2026

02 March 2026

Updated dependencies

  • Bump toml from 0.9.12+spec-1.1.0 to 1.0.2+spec-1.1.0 (#1883)

23 February 2026

12 February 2026

12 February 2026

09 February 2026

06 February 2026

06 February 2026

03 February 2026

03 February 2026

03 February 2026

02 February 2026

30 January 2026

28 January 2026

27 January 2026

Documented

  • Remove outdated ref to CreativeWork, other small edits (#1770)

22 January 2026

21 January 2026

16 January 2026

16 January 2026

15 January 2026

15 January 2026

Fixed

  • Verify after sign not executing (#1638)

14 January 2026

Updated dependencies

  • Bump toml from 0.8.23 to 0.9.10+spec-1.1.0 (#1713)
  • Bump etcetera from 0.10.0 to 0.11.0 (#1712)
  • Bump env_logger from 0.10.2 to 0.11.8 (#1711)
  • Bump mockall from 0.13.1 to 0.14.0 (#1708)

07 January 2026

22 December 2025

19 December 2025

04 December 2025

04 December 2025

Added

  • Support JSON settings in c2patool (#1635)

Documented

  • Add doc for CLI settings, misc copy edits (#1636)

17 November 2025

17 November 2025

13 November 2025

12 November 2025

Fixed

  • Use Digitalsourcetype with Builder intents (#1586)

07 November 2025

06 November 2025

Added

  • Sync/async HTTP resolvers API (#1355)

04 November 2025

Added

  • Allow reading a manifest store as a Builder to continue editing (#1476)

Fixed

  • Update to avoid deprecation warning for Command::cargo_bin (#1548)

Other

  • Revert "chore: release (#1535)"

24 October 2025

Added

  • Add settings structs to the public API (#1447)

Documented

  • Change relative to absolute URLs (#1418)

Fixed

  • Timestamp grace for legacy manifests (#1502)
  • Turn on trust by default (#1483)

Other

  • Update httpmock to 0.8.0 (#1472)

Updated dependencies

  • Bump pem from 3.0.5 to 3.0.6 (#1511)
  • Bump clap from 4.5.47 to 4.5.50 (#1506)
  • Bump httpmock from 0.8.1 to 0.8.2 (#1504)

02 October 2025

30 September 2025

Fixed

  • AllActionsIncluded defaults to None (#1459)

24 September 2025

Fixed

  • We lost the ability to read the deprecated instanceId actions parameters field. (#1443)

23 September 2025

Documented

  • Document --external-manifest c2patool argument (#1435)

19 September 2025

Added

  • Allow specifying external binary manifest to c2patool (#1428)

15 September 2025

10 September 2025

Added

  • Remove the v1_api feature and all associated code (#1387)

06 September 2025

Added

  • Implement CAWG X.509 signing via settings (#1388)

03 September 2025

27 August 2025

26 August 2025

15 August 2025

Changelog

All changes to C2PA Tool are documented in this file.

This project adheres to Semantic Versioning, except that – as is typical in the Rust community – the minimum supported Rust version may be increased without a major version increase.

Since version 0.10.0, the format of this changelog is based on Keep a Changelog.

14 August 2025

Added

  • Add option for configuring trust when validating identity assertions (CAI-7980) (#1239)
  • V2 Claims are now generated by default (#1266)
  • Expand settings API (#1192)

Fixed

  • Same file sign for c2patool (#1220)

18 July 2025

Fixed

  • Clippy warnings for Rust 1.88 (#1204)
  • Fix c2patool --info command. (#1190)

17 June 2025

Added

  • Update Validation for 2.2 spec compliance (#1144)

Documented

27 May 2025

Added

  • Make OpenSSL a default feature (#1118)

Fixed

  • Remove use of workspace versioning for the moment (#1136)
  • Add CAWG support for fragmented BMFF (#1114)

Other

  • Remove unreleased changes to c2patool
  • Integrates prebuilt library release workflow (#1126)

16 May 2025

Added

  • [breaking] Merge CAWG identity SDK into main C2PA crate (#1089)

Documented

  • Replace old c2patool release notes with CHANGELOG (#1063)

14 May 2025

Documented

  • Replace old c2patool release notes with CHANGELOG (#1063)

25 April 2025

Fixed

  • Enable post_validate_async for WASI (#1052)

16 April 2025

Documented

  • Remove instructions to install c2patool using binstall (#1038)

Fixed

  • Dynamic assertions should be gathered assertions (#1005)

07 April 2025

Fixed

  • Adjust dependencies to avoid security warnings and yanked versions (#1031)

04 April 2025

Fixed

  • Update openssl to address a recently-announced vulnerability (#1024)

26 March 2025

  • Update to latest c2pa-crypto crate

18 March 2025

Added

  • Adds reader.post_validate method for CAWG validation support (#976)
  • Add WASI to c2patool (#945)

Fixed

  • Remove circular dependency between C2PA and CAWG crates (#982)

Updated dependencies

  • Bump env_logger from 0.11.6 to 0.11.7 (#963)

11 February 2025

Fixed

  • Trigger a release of c2patool to pick up latest c2pa-rs changes

31 January 2025

Fixed

  • Trigger a release of c2patool to pick up latest c2pa-rs changes (#895)

29 January 2025

Added

  • Claim v2 (#707)

22 January 2025

Added

  • Change the definition of Signer.raw_signer() to return an Option defaulting to None (#869)

18 January 2025

Fixed

  • Upload a distinct SBOM per platform (#856)

16 January 2025

Added

  • Move COSE signing into c2pa_crypto crate (#807)

Documented

  • Post move cleanup (#778)

Fixed

  • Fix: Obscure glob error message for missing files

12 December 2024

Fixed

  • No-op change to trigger new c2patool build
  • Update makefile for c2patool's new location in c2pa-rs workspace

12 December 2024

Fixed

  • No-op change to trigger new c2patool release

12 December 2024

Added

Documented

Fixed

  • Compile c2pa-crypto with cargo check (#768)

Other

  • Move c2patool source code into c2pa-rs repo (#723)
  • Move profile settings to workspace Cargo.toml
  • Enlarged description of c2pa command-line behavior (#285)

0.9.12

18 October 2024

  • fix: Update c2pa-rs for RegionOfInterest support. (#269)
  • Fix broken link that was causing os site workflow to fail (#266)
  • Bump codecov/codecov-action from 3 to 4 (#242)
  • chore: Run all CI jobs when user is dependabot[bot]
  • chore: Debug CI again
  • chore: Format for consistency with c2pa-rs CI workflow (#265)
  • chore: Don't skip CI jobs for non-pull-request events
  • chore: Retry debug
  • chore: Debug action context
  • chore: Skip CodeCov upload for non-member PRs (#263)
  • Bump EmbarkStudios/cargo-deny-action from 1 to 2 (#245)
  • chore: Adjust conditions for running CI jobs (#261)

0.9.11

16 October 2024

  • Merge hardening bug fixes (#260)

0.9.10

07 October 2024

  • Update c2ptool to use latest c2pa-rs (#258)

0.9.9

17 September 2024

  • Pull in latest bug fixes (#237)
  • Document fragment subcommand (#236)
  • Switch back to using pull_request instead of pull_request_target trigger
  • Bump actions/checkout from 3 to 4 (#243)
  • Remove no-longer-maintained clippy-check action (#238)

0.9.8

30 August 2024

  • Initial fragment support (#230)
  • Add warning about accessing a private key directly (#218)

0.9.7

15 August 2024

  • Update to latest c2pa SDK (#222)
  • Remove rust toolchain version lock (#221)
  • Update security guidance to link to SECURITY.md (#217)

0.9.6

30 July 2024

  • Pull latest c2pa-rs bug fixes into c2patool (#212)
  • only run tests/clippy if labeled (#205)
  • Bump env_logger from 0.10.2 to 0.11.4 (#204)
  • Updates cargo packages and cargo.deny file. (#200)

0.9.5

18 July 2024

  • Update to lastest c2pa-rs (#197)
  • added security.md (#196)

0.9.4

25 June 2024

  • Update c2patool (#190)
  • Match c2pa-rs minimum toolchain version and test in CI (#188)
  • Document how to specify an icon (#182)

0.9.3

29 May 2024

  • Remove binary modules (#179)

0.9.2

24 May 2024

  • Remove integration tests for now due to extraneous binaries (#178)

0.9.1

22 May 2024

  • Add better support for cargo-binstall (#177)

0.9.0

07 May 2024

  • Integrate with c2pa-rs 0.32.0, various test case fixes. (#175)
  • (MINOR) Add HTTP source option for trust config (#174)

0.8.2

28 March 2024

  • fixed c2patool asset name (#171)

0.8.1

25 March 2024

  • use c2pa-rs 0.31.1 for actions.changes support (#170)

0.8.0

20 March 2024

  • (MINOR) allow clients to sign with a process outside of c2patool (#169)
  • Add trust and verification options to c2pa_tool (#168)
  • adds version to c2patool artifact names (#158)

0.7.0

22 November 2023

  • (MINOR) updates to c2pa-rs v0.28.2 (#153)
  • Update to c2pa-rs 0.28.1

0.6.2

05 October 2023

0.6.1

24 July 2023

  • use compress-archive instead of tar (#130)

0.6.0

22 June 2023

  • (MINOR) update to c2pa-rs 0.24.0 (#127)

0.5.4

13 June 2023

0.5.3

04 May 2023

  • Parent Ingredient JSON (#123)

0.5.2

19 April 2023

  • Ingredient thumbnails, extension cleanup, toolkit update (#120)

0.5.1

10 April 2023

  • Update README.md (#118)
  • Update expired sample certs (#113)

0.5.0

28 March 2023

  • (MINOR) New ingredient support and c2pa file formats (#111)
  • Leverage new Manifest & Ingredient, add Ingredient creation. (#107)

0.4.0

01 March 2023

  • (MINOR) Add --certs and --tree options (#106)
  • update to cp2pa 0.17.0 (#105)
  • Update for Clippy in Rust 1.67 (#101)

0.3.9

06 December 2022

  • update to c2pa-rs 0.16.0
  • allows clients to output manifest report to specified directory (#91)

0.3.8

09 November 2022

  • Bump c2pa from 0.13.2 to 0.15.0 (#87)
  • Build infrastructure improvements (#85)
  • Fix new Clippy warning in Rust 1.65 (#84)
  • Readme updates (#62)

0.3.7

22 September 2022

  • Treat a source asset with a manifest store as a default parent (#76)
  • Fetch remote manifests for --info (#75)

0.3.6

16 September 2022

  • Update Cargo.lock when publishing crate (#71)
  • [IGNORE] update readme --info (#70)
  • Update Cargo.lock to 0.3.5

0.3.5

15 September 2022

  • Upgrade cpufeatures to non-yanked version (#68)
  • Add --info option (#65)
  • Updated publish workflow to upload binaries to GitHub (#58)
  • Fix Make release script & update readme (#55)
  • (Some version history omitted as we worked on some release process issues)

0.3.0

18 August 2022

  • (MINOR) Rework c2patool parameters (#53)
  • Update to 0.11.0 c2pa-rs (#38)
  • Remove Homebrew, Git installation methods, and add "update" wording (#33)

0.2.1

29 June 2022

  • Add BMFF support for video & etc (#25)

0.2.0

28 June 2022

  • (MINOR) Upgrade to c2pa Rust SDK version 0.6.0 (#24)
  • Fix an error in the README documentation (#23)
  • Display help if there are no arguments on the command line (#21)
  • Bump anyhow from 1.0.57 to 1.0.58 (#17)
  • Updates examples to use ta_url instead of ta (#15)

0.1.3

17 June 2022

  • Update to latest c2pa Rust SDK (#12)
  • Add built-in default certs to make getting started easier (#9)

0.1.2

10 June 2022

  • Update crate's description field

0.1.1

10 June 2022

  • Initial public release