SecureDrop Inbox 1.7.0 is now available and will automatically be installed as part of your regular preflight updates; no further action is needed.
This release makes the sidebar width adjustable and lays the groundwork for right-to-left languages once we have translations. Building on the previous release, we’ve implemented more correctness fixes, including specifying immutable fields that shouldn’t be modified by the server, and ensuring that decrypted files are only made available after gzip validation.
For a full list of changes, please refer to the changelog for this release.
Acknowledgments
We’d like to thank Julius Alexandre from Trail of Bits for working with us to identify a number of correctness issues in SecureDrop Inbox as part of their Patch the Planet project.
Thanks to Localization Lab for continued support with our translations. Translations were updated thanks to the work of many volunteers:
- AO yahoe.001
- Anatoli (fr0st)
This release incorporates Freedom of the Press Foundation (FPF) contributions by Giulio B; Martin C; Nathan Dyer, communications manager; Micah Lee, deputy release manager; Kunal Mehta; Cory Francis Myers; Vicki Niu, release manager; Kevin O’Gorman; Francisco Rocha; John Skinner; and Rowen S.
Questions and comments
If you have questions or comments regarding this release, please contact us:
- Via Signal, either in your dedicated SecureDrop Support group, or by contacting the support account listed at securedrop.org/help/.
- Via securedrop@freedom.press (PGP encrypted) for sensitive security issues (please use judiciously), or submit a report via Bugcrowd.
We also encourage you to file nonsensitive issues via our GitHub repository.
Thank you for using SecureDrop!