<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xml:lang="en-US">
  <id>tag:github.com,2008:https://github.com/sqlcipher/sqlcipher/releases</id>
  <link type="text/html" rel="alternate" href="https://github.com/sqlcipher/sqlcipher/releases"/>
  <link type="application/atom+xml" rel="self" href="https://github.com/sqlcipher/sqlcipher/releases.atom"/>
  <title>Release notes from sqlcipher</title>
  <updated>2026-09-15T14:36:24Z</updated>
  <entry>
    <id>tag:github.com,2008:Repository/38617/v5.0.0-beta</id>
    <updated>2026-09-15T16:18:07Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/sqlcipher/sqlcipher/releases/tag/v5.0.0-beta"/>
    <title>v5.0.0-beta</title>
    <content type="html">&lt;p&gt;&lt;strong&gt;WARNING&lt;/strong&gt;: This should only be used for beta testing at this time, not in production. It includes major functional, API, and behavioral changes that are &lt;strong&gt;NOT COMPATIBLE&lt;/strong&gt; with SQLCipher 4 and earlier by default.&lt;/p&gt;
&lt;p&gt;SQLCipher 5.0.0-beta details: &lt;a href=&quot;https://www.zetetic.net/blog/2026/09/15/sqlcipher-5.0.0-beta/&quot; rel=&quot;nofollow&quot;&gt;https://www.zetetic.net/blog/2026/09/15/sqlcipher-5.0.0-beta/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Summary:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Changes architecture to use VFS shims&lt;/li&gt;
&lt;li&gt;Uses AEAD Encryption with AES-256-GCM&lt;/li&gt;
&lt;li&gt;Increases KDF iteration increase to 512K&lt;/li&gt;
&lt;li&gt;Increase default page size to 8192 bytes&lt;/li&gt;
&lt;li&gt;Adds encryption and decryption support to PRAGMA rekey&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;BREAKING CHANGES&lt;/strong&gt; - see CHANGELOG.md and release announcement&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>sjlombardo</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/10047?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/38617/v4.19.0</id>
    <updated>2026-09-08T14:31:26Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/sqlcipher/sqlcipher/releases/tag/v4.19.0"/>
    <title>v4.19.0</title>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Reports an error if a database is opened with an invalid &lt;code&gt;hexkey&lt;/code&gt; URI parameter&lt;/li&gt;
&lt;li&gt;Includes the provider error code in KDF error messages&lt;/li&gt;
&lt;li&gt;Fixes escaping of migration file names&lt;/li&gt;
&lt;li&gt;Fixes escaping of database aliases in &lt;code&gt;sqlcipher_export()&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Avoids returning NULL rows from &lt;code&gt;cipher_settings&lt;/code&gt; if allocation fails&lt;/li&gt;
&lt;li&gt;Adjusts behavior for permanent error states&lt;/li&gt;
&lt;li&gt;Avoids leaking a partially initialized context if an initialization error occurs&lt;/li&gt;
&lt;li&gt;Fixes error reporting for failed rekey operations&lt;/li&gt;
&lt;li&gt;Improves consistency of internal memory utilization tracking&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This maintenance release addresses two low-risk security issues in the core library related to &lt;code&gt;sqlcipher_export&lt;/code&gt; and the &lt;code&gt;hexkey&lt;/code&gt; URI parameters respectively. While the practical risks are low, we recommend that applications upgrade to incorporate the fix and the other improvements in this release. For additional details and release notes please consult &lt;a href=&quot;https://www.zetetic.net/blog/2026/09/08/sqlcipher-4.19.0-release/&quot; rel=&quot;nofollow&quot;&gt;release announcement&lt;/a&gt;.&lt;/p&gt;</content>
    <author>
      <name>sjlombardo</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/10047?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/38617/v4.18.0</id>
    <updated>2026-08-18T15:09:43Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/sqlcipher/sqlcipher/releases/tag/v4.18.0"/>
    <title>v4.18.0</title>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Updates the upstream SQLite baseline to the latest patch release &lt;a href=&quot;https://sqlite.org/releaselog/3_53_4.html&quot; rel=&quot;nofollow&quot;&gt;3.53.4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Avoids allocating memory on Windows during log writes which could cause a crash on Windows under non-default log settings with &lt;code&gt;PRAGMA cipher_memory_security = ON&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixes &quot;relocation truncated to fit&quot; error for optimized GCC builds&lt;/li&gt;
&lt;li&gt;Adds comments clarifying intent of &lt;code&gt;crypto_openssl.c&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Other miscellaneous fixes and general improvements&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For additional details and release notes please consult the &lt;a href=&quot;https://www.zetetic.net/blog/2026/08/18/sqlcipher-4.18.0-release/&quot; rel=&quot;nofollow&quot;&gt;4.18.0 release announcement&lt;/a&gt;.&lt;/p&gt;</content>
    <author>
      <name>sjlombardo</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/10047?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/38617/v4.17.0</id>
    <updated>2026-07-08T14:22:06Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/sqlcipher/sqlcipher/releases/tag/v4.17.0"/>
    <title>v4.17.0</title>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Update baseline to SQLite 3.53.3&lt;/li&gt;
&lt;li&gt;Normalize error behavior for incorrect keys when first operation attempts to modfiy the schema&lt;/li&gt;
&lt;li&gt;Improve error detection, propagation, and fix fortuna reinitialization in LibTomCrypt provider&lt;/li&gt;
&lt;li&gt;Improve thread safety for debug memory counters and xoshiro state&lt;/li&gt;
&lt;li&gt;Add optional &lt;code&gt;SQLCIPHER_OMIT_MALLOC&lt;/code&gt; macro to improve testability with Address Sanitizer&lt;/li&gt;
&lt;li&gt;Numerous miscellaneous fixes and general improvements&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For additional details and release notes please consult the &lt;a href=&quot;https://www.zetetic.net/blog/2026/07/08/sqlcipher-4.17.0-release/&quot; rel=&quot;nofollow&quot;&gt;4.17.0 release announcement&lt;/a&gt;.&lt;/p&gt;</content>
    <author>
      <name>sjlombardo</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/10047?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/38617/v4.16.0</id>
    <updated>2026-05-12T13:48:10Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/sqlcipher/sqlcipher/releases/tag/v4.16.0"/>
    <title>v4.16.0</title>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Updates the upstream SQLite baseline to the latest patch release &lt;a href=&quot;https://sqlite.org/releaselog/3_53_1.html&quot; rel=&quot;nofollow&quot;&gt;3.53.1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Fixes an allocation issue that could cause an increase in mlock warning messages (most frequently on Android)&lt;/li&gt;
&lt;li&gt;Removes redundant logging of &lt;code&gt;mlock&lt;/code&gt; and &lt;code&gt;VirtualLock&lt;/code&gt; failures at WARN level&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For additional details and release notes please consult the &lt;a href=&quot;https://www.zetetic.net/blog/2026/05/12/sqlcipher-4.16.0-release/&quot; rel=&quot;nofollow&quot;&gt;4.16.0 release announcement&lt;/a&gt;.&lt;/p&gt;</content>
    <author>
      <name>sjlombardo</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/10047?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/38617/v4.15.0</id>
    <updated>2026-04-28T13:51:53Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/sqlcipher/sqlcipher/releases/tag/v4.15.0"/>
    <title>v4.15.0</title>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Update baseline to SQLite 3.53.0&lt;/li&gt;
&lt;li&gt;Sanitize source database name passed to &lt;code&gt;sqlcipher_export&lt;/code&gt; (reported by&lt;br&gt;
Dima Petschke from Deutsche Telekom Security GmbH)&lt;/li&gt;
&lt;li&gt;Improve error handling in &lt;code&gt;sqlcipher_extra_init&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Remove const from pzErrMesg in &lt;code&gt;sqlcipher_export_init&lt;/code&gt; (issue &lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;4097509199&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/sqlcipher/sqlcipher/issues/590&quot; data-hovercard-type=&quot;issue&quot; data-hovercard-url=&quot;/sqlcipher/sqlcipher/issues/590/hovercard&quot; href=&quot;https://github.com/sqlcipher/sqlcipher/issues/590&quot;&gt;#590&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Minor code cleanups&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This release includes a fix for a defensive mode bypass in &lt;code&gt;sqlcipher_export&lt;/code&gt;. While the practical risk of the bypass is low, we recommend that applications upgrade to incorporate the fix and the other improvements in this release. For additional details and release notes please consult &lt;a href=&quot;https://www.zetetic.net/blog/2026/04/28/sqlcipher-4.15.0-release/&quot; rel=&quot;nofollow&quot;&gt;release announcement&lt;/a&gt;.&lt;/p&gt;</content>
    <author>
      <name>sjlombardo</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/10047?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/38617/v4.14.0</id>
    <updated>2026-03-17T13:45:19Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/sqlcipher/sqlcipher/releases/tag/v4.14.0"/>
    <title>v4.14.0</title>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Updates the upstream SQLite baseline to &lt;a href=&quot;https://sqlite.org/releaselog/3_51_3.html&quot; rel=&quot;nofollow&quot;&gt;3.51.3&lt;/a&gt;, which fixes a critical &lt;a href=&quot;https://sqlite.org/wal.html#walresetbug&quot; rel=&quot;nofollow&quot;&gt;WAL-reset database corruption bug&lt;/a&gt;. &lt;strong&gt;Applications running SQLCipher in WAL mode are strongly advised to upgrade.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Reintroduces LibTomCrypt cryptographic provider support based on community feedback&lt;/li&gt;
&lt;li&gt;Updates the LibTomCrypt provider with improved logging and error handling&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>sjlombardo</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/10047?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/38617/v4.13.0</id>
    <updated>2026-01-20T17:44:36Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/sqlcipher/sqlcipher/releases/tag/v4.13.0"/>
    <title>v4.13.0</title>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Updates baseline to SQLite 3.51.2&lt;/li&gt;
&lt;li&gt;Corrects encoding for &lt;code&gt;sqlcipher_export()&lt;/code&gt; function registration&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>sjlombardo</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/10047?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/38617/v4.12.0</id>
    <updated>2025-12-08T15:28:10Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/sqlcipher/sqlcipher/releases/tag/v4.12.0"/>
    <title>v4.12.0</title>
    <content type="html">&lt;ul&gt;
&lt;li&gt;Updates baseline to SQLite 3.51.1&lt;/li&gt;
&lt;li&gt;Adds &lt;code&gt;PRAGMA cipher_status&lt;/code&gt; so applications can verify a database handle is using encryption&lt;/li&gt;
&lt;li&gt;Improves guards against key/rekey/attach misuse&lt;/li&gt;
&lt;li&gt;Adds criteria for &lt;code&gt;PRAGMA cipher_migrate&lt;/code&gt; tests&lt;/li&gt;
&lt;li&gt;Fixes check for &lt;code&gt;__has_feature&lt;/code&gt; macro to separate it from use&lt;/li&gt;
&lt;li&gt;Fixes CHANGELOG.md markdown formatting, typos, and inline code snippets&lt;/li&gt;
&lt;li&gt;Fixes conditional in SQLCipher pragma handling&lt;/li&gt;
&lt;li&gt;Removes deprecated providers for LibTomCrypt and NSS&lt;/li&gt;
&lt;li&gt;Removes unnecessary shutdown and URI config changes in core tests&lt;/li&gt;
&lt;li&gt;Ensures all test suite database handles are closed before delete&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>sjlombardo</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/10047?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/38617/v4.11.0</id>
    <updated>2025-10-08T14:10:34Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/sqlcipher/sqlcipher/releases/tag/v4.11.0"/>
    <title>v4.11.0</title>
    <content type="html">&lt;p&gt;&lt;strong&gt;Full Changelog&lt;/strong&gt;: &lt;a class=&quot;commit-link&quot; href=&quot;https://github.com/sqlcipher/sqlcipher/compare/v4.10.0...v4.11.0&quot;&gt;&lt;tt&gt;v4.10.0...v4.11.0&lt;/tt&gt;&lt;/a&gt;&lt;/p&gt;</content>
    <author>
      <name>sjlombardo</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/10047?s=60&amp;v=4"/>
  </entry>
</feed>
