NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #3239 most downloaded on crates.io
Rust SDK for C2PA (Coalition for Content Provenance and Authenticity) implementors
Last release today
06 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 47 of the last 60 stable releases
4 versions withdrawn
withdrawn after publishing
5 years old
247 releases · first in 2022
One column per quarter.
Nothing published for this version
fix: only encode claim CBOR with specVersion if it's present in claim (backport #2746 ) by @caiopensrc in #2747
Full Changelog: c2pa-v0.91.1...c2pa-v0.91.2
feat: Implement pdf manifest writing (backport #2666 ) by @caiopensrc in #2700
release-plz respects release_commits (fixes #2229) (backport #2658) by @caiopensrc in #2727Full Changelog: c2pa-v0.91.0...c2pa-v0.91.1
docs: We no longer accept intentionally-invalid API inputs as vulnerabilities by @scouten-adobe in #2328
release-plz release_commits until upstream is fixed by @ok-nick in #2308cargo-udeps and update nightly toolchain by @ok-nick in #2398RELEASE_PLZ_TOKEN with RELEASE_PLZ_ORG_TOKEN by @ok-nick in #2382safe to test label in version-controlled labels by @scouten-adobe in #2422Builder::add_ingredient_from_stream by @ok-nick in #2432created and kind flags should roundtrip in Builder archives by @tmathern in #2460safe to test trust logic with GitHub native fork-approval by @scouten-adobe in #2420validationResults requires activeManifest when serializing v3 ingredients by @ok-nick in #2429IcaSignatureVerifier methods by @imtherealnaska in #2532ingredient parameter by @cdmurph32 in #2541Error::AssertionEncoding error source to error message by @ok-nick in #2544cargo-udeps build from source version to match supported nightly version by @ok-nick in #2554Note truncated.
fix: Normalize path URIs on collection hash (backport #2605 ) by @caiopensrc in #2625
Full Changelog: c2pa-v0.90.21...c2pa-v0.90.22
fix: identity assertion validation uses the caller's cawg_trust settings (stable backport, #2599 ) by @RobertsRobots in #2604
Full Changelog: c2pa-v0.90.20...c2pa-v0.90.21
feat: Add ZIP support (+ EPUB, Office Open XML, Open Document, and OpenXPS) and Collection Data Hash assertion (backport #499 ) by @ok-nick in #2596
Full Changelog: c2pa-v0.90.19...c2pa-v0.90.20
fix: Handling ingredient manifest label collisions (spec v2.4, 18.16.12) (backport #2585 ) by @caiopensrc in #2595
Full Changelog: c2pa-v0.90.18...c2pa-v0.90.19
fix: Harden against invalid labels as CAWG identity hard bindings (backport #2538 ) by @ssanthosh in #2581
Full Changelog: c2pa-v0.90.17...c2pa-v0.90.18
fix: Merge vulnerability fixes by @ssanthosh in #2579
Full Changelog: c2pa-v0.90.16...c2pa-v0.90.17
fix: Reject BMFF Merkle map location that overflows u32 chunk index (CAI-12884) (backport #2445 ) by @caiopensrc in #2500
Error::AssertionEncoding error source to error message (backport #2544) by @caiopensrc in #2549ingredient parameter (backport #2541) by @caiopensrc in #2546validationResults requires activeManifest when serializing v3 ingredients (backport #2429) by @caiopensrc in #2537Full Changelog: c2pa-v0.90.15...c2pa-v0.90.16
fix: Hardening against potential deep recursion in update manifests with parent cycles (backport #2493 ) by @caiopensrc in #2501
Full Changelog: c2pa-v0.90.14...c2pa-v0.90.15
fix: Diamond inputTo manifest exponential reverifications depending on ingredient paths reachability (backport #2492 ) by @caiopensrc in #2498
Full Changelog: c2pa-v0.90.13...c2pa-v0.90.14
fix(sdk): Parse PEM cert chain to DER for RemoteSigner (backport #2414 ) by @caiopensrc in #2481
Full Changelog: c2pa-v0.90.12...c2pa-v0.90.13
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Harden against integer underflow attacks in PNG iTxt chunks XMP parsing
13 July 2026
Bind OCSP response certId to the signing certificate (CAI-11829)
09 July 2026
Resolve crate audit advisories (lopdf, quick-xml, crossbeam-epoch, ttf-parser)
07 July 2026
Add source to HttpResolverError::Other error message
Remove some long deprecated APIs
Release 0.88.0 removes several long-deprecated APIs. These are breaking changes; update your code before upgrading.
The following Ingredient methods and types have been removed:
| Removed | Use instead |
|---|---|
Ingredient::from_file(path) |
Open the file and call Ingredient::from_stream(format, &mut stream) |
Ingredient::from_file_with_folder(path, folder) |
Ingredient::from_stream(format, &mut stream) |
Ingredient::from_file_with_options(path, options) |
Ingredient::from_stream(format, &mut stream) + builder setter methods |
Ingredient::from_memory(format, bytes) |
Ingredient::from_stream(format, &mut std::io::Cursor::new(bytes)) |
Ingredient::set_memory_thumbnail(format, bytes) |
Ingredient::set_thumbnail(format, bytes) |
IngredientOptions, DefaultOptions |
Use builder setter methods directly on Ingredient |
The following C API functions have been removed:
| Removed | Use instead |
|---|---|
c2pa_read_file |
c2pa_reader_from_context() |
c2pa_read_ingredient_file |
c2pa_reader_from_context() |
c2pa_sign_file |
c2pa_builder_from_context() |
[breaking] Split c2pa-raw-crypto into its own crate
NOOP PR for release-plz trigger
[breaking] Remove unused Error variant types
Exact ingredient redaction URI matching
03 June 2026
Preserve validation status log kind after deserialization
Support CAWG callback signing via c_ffi
27 May 2026
Case-insensitive enums in settings to preserve backwards compatibility with config crate
12 May 2026
config crate (#2138)Archive preserves duplicate label assertions
Large and complex benchmark suite
Harden against integer underflow attack in GIF XMP validation
Harden against unbounded HTTP response body read in DID web server
Harden against integer underflow attacks in parsing purpose field in BMFF UUID box
Add init trust, trust sidecars, and atomic sidecar writes, plus fixes
Adds redaction docs and example
28 April 2026
c2pa-c-ffi UB detected by miri (#2089)Harden against empty certificates during OCSP certificate validation
27 April 2026
Add ingredient archive FFI functions and relax Builder mutability
Handle more thumbnail redaction edge cases
Wrap Error::NotImplemented in Err() for wasip1 tempfile_builder
Release 0.79.4 deprecates all legacy thread-local configuration APIs in favor of explicit Context-based equivalents. These are not breaking changes: All deprecated methods retain their original behavior and continue to work, but will produce compiler warnings. Note that some of these deprecated methods were subsequently removed in Version 0.88.0.
Builder::default() and Reader::default() are now the idiomatic way to construct with default settings, replacing the more verbose Builder::from_context(Context::new()) and Reader::from_context(Context::new()).
The following methods are now deprecated:
| Deprecated | Use instead |
|---|---|
Builder::new() |
Builder::default() |
Builder::from_json(json) |
Builder::default().with_definition(json) |
Builder::from_archive(stream) |
Builder::default().with_archive(stream) |
Reader::from_stream(format, stream) |
Reader::default().with_stream(format, stream) |
Reader::from_file(path) |
Reader::default().with_file(path) |
Reader::from_manifest_data_and_stream(...) |
Reader::default().with_manifest_data_and_stream(...) |
Reader::from_fragmented_files(path, fragments) |
Reader::default().with_fragmented_files(path, fragments) |
Settings::from_toml(toml) |
Settings::new().with_toml(toml) |
Settings::from_string(str, format) |
Settings::new().with_json(str) or Settings::new().with_toml(str) |
Settings::signer() |
Configure a signer on a Context and pass it to Builder::from_context |
To use custom settings, create a Context with Context::new().with_settings(...) and pass it to Builder::from_context(context) or Reader::from_context(context).
The following C API functions are deprecated:
| Deprecated | Use instead |
|---|---|
c2pa_load_settings |
c2pa_settings_new() + c2pa_context_builder_set_settings() |
c2pa_reader_from_stream |
c2pa_reader_from_context() |
c2pa_reader_from_file |
c2pa_reader_from_context() |
c2pa_reader_from_manifest_data_and_stream |
c2pa_reader_from_context() + c2pa_reader_with_manifest_data_and_stream() |
c2pa_builder_from_json |
c2pa_builder_from_context() + c2pa_builder_set_definition() |
c2pa_builder_from_archive |
c2pa_builder_from_context() + c2pa_builder_with_archive() |
c2pa_signer_from_settings |
c2pa_context_builder_set_signer() |
c2pa_read_file, c2pa_read_ingredient_file, c2pa_sign_file |
Context-based equivalents (removed in Version 0.88.0) |
c2pa_reader_free, c2pa_builder_free, c2pa_string_free, c2pa_manifest_bytes_free, c2pa_signer_free, c2pa_release_string, c2pa_signature_free |
c2pa_free() |
C and C++ headers now emit compiler deprecation warnings when deprecated functions are called.
*(sdk)* Ingredient JUMBF archives, archive metadata typing
Harden against integer overflow panic in big tiff processing
08 April 2026
Redact thumbnails in databoxes (v1 claims)
Redacting things in multiple ingredients
Expose a C FFI API to help determine the hashtype a Builder uses with embeddable APIs
Adds a progress/cancel feature to Context for the c2pa-rs sdk
27 March 2026
_23 March 2026_ ### Added * Add FLAC format support
Add cr_json() and cr_json_value() to Reader; remove separate CrJsonReader
Remove exponential memory growth from nested claim reconstruction
Impl Send + Sync on EphemeralSigner
Your coding agent can read these notes before it upgrades. Set up the MCP server →