Amber's avatar
Amber
npub1am3e...xrv7
Amber is a nostr event signer for Android. It allows users to keep their nsec segregated in a single, dedicated app. The goal of Amber is to have your smartphone act as a NIP-46 signing device without any need for servers or additional hardware. "Private keys should be exposed to as few systems as possible as each system adds to the attack surface," as the rationale of said NIP states. In addition to native apps, Amber aims to support all current nostr web applications without requiring any extensions or web servers.
Amber's avatar
Amber 2 days ago
# Changelog ## Amber 6.6.3 - Fix the "start service on boot" setting not being respected after an app update - Fix a crash on the offline flavor caused by a `SecurityException` from WorkManager network tracking left over from an upgrade - Fix the Russian translation of the "Amber is a free and open source project" string - Fix a release build failure caused by an AGP 9.4.0 regression Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.3) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.6.3.txt` and `manifest-v6.6.3.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.6.3.txt.sig manifest-v6.6.3.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.6.3.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
Amber's avatar
Amber 1 week ago
# Changelog ## Amber 6.6.1 - Fix parsing of incoming permission lists when a permission has no `kind` field in its JSON, so the whole list no longer fails to load - Fix rejected signer requests not returning the request id in the result, leaving calling apps unable to match the rejection to their request - Update the default signer relays to `auth.nostr1.com`, `bucket.coracle.social`, `nrs.primal.net` and `relay.nip46.com`, and add `indexer.coracle.social` to the default indexer relays (#518) - Add missing translations for Marmot protocol event kinds Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.1) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.6.1.txt` and `manifest-v6.6.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.6.1.txt.sig manifest-v6.6.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.6.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
Amber's avatar
Amber 1 week ago
## Amber 6.6.0 - New: pre-approve individual permissions when connecting an app under the "Manually approve each permission" policy — an "Add permission" button lets you pick from the full permission catalog (searchable, including custom sign-event kinds) so those requests are approved automatically while everything else still asks - New: when a NIP-46 connect request arrives while the kill switch is enabled, Amber now asks whether to disable it so the request can be answered, and the kill switch gained a toggle in the Settings network section - Toggling the "Enable biometrics" setting now requires biometric authentication first, so the setting cannot be deactivated without authorization and broken sensors are caught before activation - Toggling "require unlocked device" now shows a progress indicator with a do-not-close warning while every stored secret is re-encrypted, instead of silently freezing - Fix the account picker not scrolling and its title not being visible - Fix a crash in profile feed subscriptions when an account is removed while its events are being processed - Trim the image and trust-score caches when the system reports memory pressure, so the 32 MB bitmap cache no longer stays fully resident while the app is in the background - Performance: cache decrypted application lists so periodic relay refreshes stop re-decrypting every application row through the Keystore (the dominant native memory user on populated accounts), and warm up timezone data off the main thread to remove a ~170 ms disk read during the Applications screen's first composition - Update Kotlin to 2.4.10, Gradle to 9.7.1, Quartz to 1.14.0 and the rest of the dependency stack Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.6.0.txt` and `manifest-v6.6.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.6.0.txt.sig manifest-v6.6.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.6.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
Amber's avatar
Amber 3 weeks ago
# Changelog ## Amber 6.5.2 - Fix the Applications screen taking several seconds to load on populated accounts: the list no longer decrypts the encrypted `secret`/`localKey` columns it doesn't render, and the Keystore key handle is cached instead of re-fetched for every decryption - Warm the account cache at app start so the switch-accounts button lists all accounts again instead of only the current one - Fix a crash when scrolling the activity history screens caused by the same row appearing in two loaded pages at once - Debounce relay status-counter notification updates so the status notification no longer freezes on stale text during bursts of relay traffic Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.2) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.5.2.txt` and `manifest-v6.5.2.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.5.2.txt.sig manifest-v6.5.2.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.5.2.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
Amber's avatar
Amber 0 months ago
# Changelog ## Amber 6.5.1 - Re-encrypt NIP-46 connection secrets stored in the per-account database during Keystore key rotation, so toggling "require unlocked device for key access" no longer leaves connections undecryptable - Fix crash in EditPermission due to an invalid localKey Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.1) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.5.1.txt` and `manifest-v6.5.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.5.1.txt.sig manifest-v6.5.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.5.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
Amber's avatar
Amber 0 months ago
# Changelog ## Amber 6.5.0 - Fix relay-auth whitelist authorizing any requester (GHSA-vx4h-56qj-wcp7) - Fix NIP-46 freshness and replay protection (GHSA-h9fv-9247-3582) - Envelope-encrypt NIP-46 connection secrets at rest (GHSA-5fjp-ghh8-wch8) - Add opt-in unlocked-device requirement for Keystore key (GHSA-8844) - Authorize before decrypt in SignerProviderQuery (GHSA-8844) - Redact key material from logs and crash reports (GHSA-8844) - Set FLAG_SECURE on sensitive QR surfaces (GHSA-8844) - Warn on insecure ws:// connections to non-onion relays (GHSA-8844) - Parse unknown permission remember types as NEVER to fail closed (GHSA-8844) - Lazy-load account keys on cache miss and properly zeroize them on logout (GHSA-8844) - Update translations for new string resources - Fix CI test failures and linter violations Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.5.0.txt` and `manifest-v6.5.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.5.0.txt.sig manifest-v6.5.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.5.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
Amber's avatar
Amber 1 month ago
## Amber 6.4.0 - Redesign the multi-request approval screen with explicit Approve/Deny toggles per request and per group, replacing the select-and-confirm flow, with proper error responses for denied bunker requests - Add support for 113 more event kinds with localized labels across all shipped locales, including the Concord kinds, NIP-51 git repository bookmarks and NIP-53 room presence - Add light/dark Compose previews for the multi-event approval screens - Ignore platform finalizer-watchdog TimeoutExceptions in crash reports - Fix a NegativeArraySizeException crash in relay subscriptions by guarding shared maps for concurrent access - Translate the new approval strings (approve, confirm, remember my choice for) in all supported locales - Update translations Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.4.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.4.0.txt` and `manifest-v6.4.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.4.0.txt.sig manifest-v6.4.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.4.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
Amber's avatar
Amber 1 month ago
# Changelog ## Amber 6.3.0 - Group multi-request approval lists by type and kind, with collapsible groups and per-group remember and scope options - Only use the fullscreen layout when there is a single bunker request - Add support for Expert List (kind 12022) and Expert Pack (kind 32022) events - Add a privacy mode setting to disable logs and activity stats - Add a setting to disable relay trust scores - Add a restart action and live status to the built-in Tor notification - Fetch the user's NIP-65 relay list before fetching profile metadata - Remove relay.damus.io from the default relay lists - Fix the event date shown as Jan 1970 in the Show Details modals - Fix all Android Lint warnings and enforce lint in the git hooks - Upgrade Gradle to 9.6.1 and AGP to 9.3.0 - Move older release notes to per-version files under docs/changelogs - Update translations Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.3.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.3.0.txt` and `manifest-v6.3.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.3.0.txt.sig manifest-v6.3.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.3.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly. ## Older versions Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
Amber's avatar
Amber 2 months ago
## Amber 6.2.3 - Add a configurable profile fetch interval setting with never/always options - Show a profile picture in the account switch bottom sheet - Scope profile subscriptions by the current account, driven by composables - Add error handling to bunker permission parsing - Trim the shipped languages to the curated set of locales - Set the benchmark build app name to "Amber Benchmark" - Fix a StrictMode DiskReadViolation in Coil onSuccess logging - Load the account off the main thread to fix a StrictMode keystore violation - Read account name and picture off the main thread in the account switch sheet - Avoid eager KeyPair() on the main thread in the login/signup screens - Fix the settings section header contrast in the light theme - Fix an unescaped apostrophe in the Turkish profile fetch interval string - Update translations Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.2.3) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.2.3.txt` and `manifest-v6.2.3.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.2.3.txt.sig manifest-v6.2.3.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.2.3.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 3 months ago
## Amber 6.2.1 - Reduce battery drain from relay reconnects and websocket pings - Drop dead relays from the subscription pool instead of only backing off reconnects - Do not wake the device when updating the relay notification - Modernize the settings screen with grouped Material 3 cards and distinct icons - Fix navigation crash when opening application permissions - Fix a crash when writing the Bunker connect screen state off the main thread - Reply with an error for invalid bunker request methods - Add NIP-46 logout method support - Add support for event kind 39701 (Public web bookmark) - Fix a per-account database connection leak by building databases atomically - Refresh app bar titles when the language changes - Update Kotlin to 2.4.0 and Gradle to 9.5.1 - Update translations Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.2.1) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.2.1.txt` and `manifest-v6.2.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.2.1.txt.sig manifest-v6.2.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.2.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 3 months ago
## Amber 6.2.0 - Add NIP-44 v3 encryption support, including a dedicated approval screen, intent preview, bunker preview, history logging and auto-reject for invalid requests - Register NIP-44 v3 ContentProvider authorities - Auto-accept NIP-46 ping requests on connect - Ignore empty `` intents so the app can be opened directly - Simplify the invalid intent screen to only close the app - Use a segmented toggle for option pickers, with a scrollbar and shrinking segments when they get too narrow to fit the screen - Remove the `sign_message` signer method - Remove the 1 minute option from the sign-automatically pickers - Disable resource shrinking in release builds - New Crowdin translations Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.2.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.2.0.txt` and `manifest-v6.2.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.2.0.txt.sig manifest-v6.2.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.2.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 3 months ago
## Amber 6.1.0 - Better layout when connecting a new app - Fix some reported crashes - Fix signer dialog not closing after accepting a bunker request - Show name and npub when showing your account - Add a select/deselect all option in the permissions screen when connecting a new app - Show a invalid request screen when receiving a invalid request - Preview missing translation report before sending it - Add a rate limiting for intents based on app/type/event kind (rate limiting only applies to apps that don't implement sending multiple requests at once) - Some optimizations when accepting/rejecting intent requests - Added a stop service in the notification, this force closes the app and you have to manually open it again before using bunker applications - Added a option to disable the service start on boot - Only start the profile subscription for the current account - Always return hex key when logging in to an app to comply with nip 55 - Added a close button in the empty requests screen - Added loading state to the report screens - Support for beta releases for the auto updater - Add a reset button for bunkers - Fix a connection issue when connecting to a new bunker by @Alex Gleason - Fix app starting on boot when not enabled - Support for sign psbt method - Fix relay auth whitelist when the relay contains port number - Change selectable options to be a bottom sheet - Added more options to the automatically sign this for - Add an encrypted applications backup that can be restored on a new device Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.1.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.1.0.txt` and `manifest-v6.1.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.1.0.txt.sig manifest-v6.1.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.1.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 3 months ago
## Amber 6.1.0-pre3 - Better layout when connecting a new app - Fix some reported crashes - Fix signer dialog not closing after accepting a bunker request - Show name and npub when showing your account - Add a select/deselect all option in the permissions screen when connecting a new app - Show a invalid request screen when receiving a invalid request - Preview missing translation report before sending it - Add a rate limiting for intents based on app/type/event kind (rate limiting only applies to apps that don't implement sending multiple requests at once) - Some optimizations when accepting/rejecting intent requests - Added a stop service in the notification, this force closes the app and you have to manually open it again before using bunker applications - Added a option to disable the service start on boot - Only start the profile subscription for the current account - Always return hex key when logging in to an app to comply with nip 55 - Added a close button in the empty requests screen - Added loading state to the report screens - Support for beta releases for the auto updater - Add a reset button for bunkers - Fix a connection issue when connecting to a new bunker by @Alex Gleason - Fix app starting on boot when not enabled - Support for sign psbt method - Fix relay auth whitelist when the relay contains port number - Change selectable options to be a bottom sheet - Added more options to the automatically sign this for Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.1.0-pre3) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.1.0-pre3.txt` and `manifest-v6.1.0-pre3.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.1.0-pre3.txt.sig manifest-v6.1.0-pre3.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.1.0-pre3.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 4 months ago
## Amber 6.1.0-pre2 - Better layout when connecting a new app - Fix some reported crashes - Fix signer dialog not closing after accepting a bunker request - Show name and npub when showing your account - Add a select/deselect all option in the permissions screen when connecting a new app - Show a invalid request screen when receiving a invalid request - Preview missing translation report before sending it - Add a rate limiting for intents based on app/type/event kind (rate limiting only applies to apps that don't implement sending multiple requests at once) - Some optimizations when accepting/rejecting intent requests - Added a stop service in the notification, this force closes the app and you have to manually open it again before using bunker applications - Added a option to disable the service start on boot - Only start the profile subscription for the current account - Always return hex key when logging in to an app to comply with nip 55 - Added a close button in the empty requests screen - Added loading state to the report screens - Support for beta releases for the auto updater - Add a reset button for bunkers - Fix a connection issue when connecting to a new bunker by @Alex Gleason - Fix app starting on boot when not enabled Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.1.0-pre2) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.1.0-pre2.txt` and `manifest-v6.1.0-pre2.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.1.0-pre2.txt.sig manifest-v6.1.0-pre2.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.1.0-pre2.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 4 months ago
## Amber 6.1.0-pre1 - Better layout when connecting a new app - Fix some reported crashes - Fix signer dialog not closing after accepting a bunker request - Show name and npub when showing your account - Add a select/deselect all option in the permissions screen when connecting a new app - Show a invalid request screen when receiving a invalid request - Preview missing translation report before sending it - Add a rate limiting for intents based on app/type/event kind (rate limiting only applies to apps that don't implement sending multiple requests at once) - Some optimizations when accepting/rejecting intent requests - Added a stop service in the notification, this force closes the app and you have to manually open it again before using bunker applications - Added a option to disable the service start on boot - Only start the profile subscription for the current account - Always return hex key when logging in to an app to comply with nip 55 Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.1.0-pre1) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.1.0-pre1.txt` and `manifest-v6.1.0-pre1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.1.0-pre1.txt.sig manifest-v6.1.0-pre1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.1.0-pre1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 5 months ago
## Amber 6.0.3 - Fix racing condition when receiving intents - Upgrade gradle and agp - Add account index option when using seed words - Fix relay reconnection on startup if the relay is offline - Add missing periodic worker for app updates - Check for empty request ids when receiving intents Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.0.3) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.0.3.txt` and `manifest-v6.0.3.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.0.3.txt.sig manifest-v6.0.3.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.0.3.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 5 months ago
## Amber 6.0.2 - Fix racing condition when receiving intents - Upgrade gradle and agp - Add account index option when using seed words - Fix relay reconnection on startup if the relay is offline - Add missing periodic worker for app updates Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.0.2) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.0.2.txt` and `manifest-v6.0.2.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.0.2.txt.sig manifest-v6.0.2.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.0.2.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 5 months ago
## Amber 6.0.1 - Fix missing event validation when checking for app updates and profile events - Fix racing condition when receiving intents - Fix subscriptions never closing when removing an app - Remove richtext dependency - Update Quartz library to 1.08.0 - Add two new backup options, webdav and share to google drive - Implement exponential backoff for relay reconnections Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.0.1) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.0.1.txt` and `manifest-v6.0.1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.0.1.txt.sig manifest-v6.0.1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.0.1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 5 months ago
## Amber 6.0.0 - Add per-connection signing keys for NIP-46 bunker protocol - Add NIP-42 relay auth whitelist settings - Add mnemonic recovery phrase login support - Fix a crash when receiving duplicated events - Optimize performance in content resolvers, intents and activity screen - Optimized logs and activities to reduce the size of the database - Fix a crash when pasting from clipboard - Make relays notifications minimized by default - Fix a database migration error - Warn the user when their device has a broken KeyStore - Add a self updater Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.0.0) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.0.0.txt` and `manifest-v6.0.0.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.0.0.txt.sig manifest-v6.0.0.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.0.0.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
Amber's avatar
Amber 5 months ago
## Amber 6.0.0-pre1 - Add per-connection signing keys for NIP-46 bunker protocol - Add NIP-42 relay auth whitelist settings - Add mnemonic recovery phrase login screen - Fix a crash when receiving duplicated events - Optimize performance in content resolvers, intents and activity screen - Optimized logs and activities to reduce the size of the database Download it with [Zapstore]( [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.0.0-pre1) If you like my work consider making a [donation](https://greenart7c3.com) ## Verifying the release In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already: ``` bash gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D ``` Once you have his PGP key you can verify the release (assuming `manifest-v6.0.0-pre1.txt` and `manifest-v6.0.0-pre1.txt.sig` are in the current directory) with: ``` bash gpg --verify manifest-v6.0.0-pre1.txt.sig manifest-v6.0.0-pre1.txt ``` You should see the following if the verification was successful: ``` bash gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03 gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D gpg: Good signature from "greenart7c3 <greenart7c3@proton.me>" ``` That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes: ``` bash cat manifest-v6.0.0-pre1.txt ``` One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.