We’re pleased to announce that SecureDrop 2.14.0 has been released. This release ensures KeePassXC remains installed on Tails. It also lays groundwork for the upcoming SecureDrop App.
Other notable changes are highlighted below. For a full list of changes, please refer to the changelog for this release.
What’s new in SecureDrop 2.14.0?
For sources and journalists
- Update Source Interface warning banner to refer to modern mobile browsers (#7751)
For administrators
- Ensure KeePassXC is installed with
securedrop-admin(#7762)
For developers
- v2 Journalist API:
- Update image build automation to drop redundant tag prep jobs (#7742)
- Remove current year from messages.pot (#7753)
- Have
rufflint against Python 3.12 as its baseline (#7764) - Use
uvto update admin requirements (#7774) - Dependency updates:
urllib3from 2.5.0 to 2.6.3 (#7736, #7754)filelockfrom 3.19.1 to 3.20.3 (#7743, #7765)wheelfrom 0.45.1 to 0.46.3 (#7760)python-multipartfrom 0.0.20 to 0.0.22 (#7761)virtualenvfrom 20.34.0 to 20.36.1 (#7765)pynaclfrom 1.5.* to 1.6.2 (#7765)protobuffrom 6.33.0 to 6.33.5 (#7765)pipfrom 25.0 to 26.0 (#7766)cffifrom 1.16.0 to 2.0.0 (#7774)cryptographyfrom 41.0.7 to 46.0.5 (#7774)
What administrators need to do
Please follow our upgrade guide and get in touch with us if you require assistance.
Acknowledgments
This release was made possible thanks to volunteer code contributions from Heath Dutton.
Thanks to Localization Lab for continued support with our translations. Translations were updated thanks to the work of many volunteers:
- French: AO Localization Lab
- German: Curtis Baltimore
- Icelandic: Sveinn à Felli, Oktavia
- Persian: Maryam Azad
- Polish: Adam Rak
- Portuguese (Brazil): Joao Daniel Piccino
If you would like to help expand the languages that SecureDrop supports, please see our instructions on contributing translations.
This release incorporates Freedom of the Press Foundation (FPF) contributions by Martin C; Nathan Dyer; Micah Lee; Kunal Mehta; Cory Francis Myers, localization manager; Vicki Niu; Kevin O’Gorman, release manager; Ethan Paul; Francisco Rocha; John Skinner, communications manager; and Rowen S.
Questions and comments
If you have questions or comments regarding this release, please contact us:
- Via Signal, if you are a member of an existing support group (membership is available to SecureDrop administrators on request)
- Via securedrop@freedom.press (PGP encrypted) for sensitive security issues (please use judiciously), or submit a report via Bugcrowd
We also encourage you to file nonsensitive issues via our GitHub repository.
Thank you for using SecureDrop!