NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #3220 most downloaded on crates.io
Rust SDK for C2PA (Coalition for Content Provenance and Authenticity) implementors
Last release 8 days ago
10 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 47 of the last 60 stable releases
4 versions withdrawn
withdrawn after publishing
4 years old
244 releases · first in 2022
One column per quarter.
Combine docs on Context and Settings to reduce duplication
Embeddable manifest API with Context/Settings, CAWG and BMFF.v3 support.
04 March 2026
Release 0.77.0 adds a new embeddable manifest API with Context/Settings, CAWG, and BMFF.v3 support. For details, see Embeddable signing API.
Reader has some new methods:
validation_state() returns ValidationState, which can be Invalid, Valid, or Trusted. Use this method instead of checking for validation_status() = None.validation_results() returns ValidationResults, which is a more complete form of ValidationStatus and returns success, informational, and failure codes for the active manifest and ingredients. ValidationStatus is deprecated in favor of ValidationResults.Ingredient now supports a validation_results() method and a validation_results field.
An AssetType assertion is now supported.
[!NOTE] The library now supports C2PA v2 claims by default. V2 claims have many new checks and status codes.
Additionally:
title() and format() methods of both Manifest and Ingredient objects now return an Option<String> because in v2 claims, title is optional and format does not exist.action must be c2pa.created or c2pa.opened (which requires an ingredient).[!WARNING] Implementations should not generate deprecated v1 claims. If needed, though, you can generate v1 claims by setting the
Buildermanifest definitionclaim_versionfield to1.
Panic when validating boxes hash with no names
Handle meta box without FullBox header from Apple devices
Enable self-signed ephemeral certs on Wasm build
23 February 2026
Builder::sign_async future to be spawnable on Tokio runtime (#1846)No-op re-release to address previous build failure.
12 February 2026
No-op re-release to address previous build failure.
Use ephemeral self-signed cert to sign working store / archive
Settings.builder.created_assertion_lables was not being applied.
Wrong size being written out for XMP box
Capture default values in schema generation
Nothing published for this version
Nothing published for this version
Nothing published for this version
Force Cargo to use sparse crates.io index
03 February 2026
(Re-release since the 0.75.11 release failed.)
03 February 2026
(Re-release since the 0.75.11 release failed.)
Adds thread safe Settings and Context support to c_ffi_api
_02 February 2026_ ### Fixed * Updates to c2pa_cbor 0.77.2 (#1804) ### Updated dependencies * Bump jumbf from 0.4.1 to 0.5.0
Public API for timestamp assertions
Removed dependency on unmaintained serde_cbor crate
Retrigger release-plz release workflow
Trigger a new release to allow generated binaries to be published
22 January 2026
Use patched version of typed-path for zip
Context propagation for Reader to support legacy behavior
Describe what parameter is missing in c2pa.opened/placed/removed validation
_15 January 2026_ ### Fixed * Fix streams handling for TIFF
Report claim version in manifest report
Fix vulnerability with user supplied exclusions.
14 January 2026
Manifest::signature to get Cose_Sign1 signature (#1699)[breaking] Store Context as Arc for shared context and threading support
07 January 2026
Context as Arc for shared context and threading support (#1680)Context to contain settings, HTTPS resolvers, and signers (#1631)codspeed-criterion-compat to 4.2.1 (#1702)Nested ingredient serializing-deserializing (fix for #1685)
Fix case where UUID boxes and BMFF layout confused the insertion
_04 December 2025_ ### Added * Restricted HTTP resolvers
Check if stream matches input format via file signature/structure
04 December 2025
Valid validation state (#1623)json5 dependency and other unused config crate sub-dependencies (#1611)windows-core (#1616)_17 November 2025_ ### Added * Remove x509_certificate (#1547) ### Fixed * Remove ring altogether
Fix and update Builder examples
_13 November 2025_ ### Fixed * Remove a dbg statement
Use Digitalsourcetype with Builder intents
Disallow ureq and reqwest_blocking for WASM and WASI
Better support for remote-only manifests of non-BMFF assets
Update to avoid deprecation warning for Command::cargo_bin
04 November 2025
Add settings structs to the public API
24 October 2025
Reader (#1370)serialize_thumbnails feature (#1492)Mark DigitalSourceType fields as deprecated without warning (new serde update)
Do not generate multiple c2pa.placed actions with settings
We lost the ability to read the deprecated instanceId actions parameters field.
Add support for iso6 boxes (tfra, tfhd and saio)
Expose add_action from the Builder at the C level
Allow v1 claim c2pa.manifest cbor assertions without full valid…
Add cawg_trust.verify_trust_list setting
Implement CAWG X.509 signing via settings
Rewind output stream after adding dynamic assertions
Reset settings after test_stream_thumbnail
*(sdk)* Falls back to fs for large intermediate streams
26 August 2025
Add common name to manifest dump
15 August 2025
All notable changes to this project will be documented in this file.
This project adheres to Semantic Versioning, except that – as is typical in the Rust community – the minimum supported Rust version may be increased without a major version increase.
Since version 0.36.2, the format of this changelog is based on Keep a Changelog.
Mark the CreativeWork assertion as deprecated
14 August 2025
DigitalSourceType as enum (#1260)Send trait for CAIRead on Wasm (#1264)Verifier to hold a Cow<'a, CertificateTrustPolicy rather than a reference (#1238)Metadata assertion (#1251)Add C binding for setting the base path
18 July 2025
Reader::remote_url and Reader::is_embedded (#1150)No-op change to trigger c2pa core crate publish
19 June 2025
No-op change to trigger rebuild
18 June 2025
To_archive does not store resources associated with ingredients
*(sdk)* Introduces get_supported_types api
Es512 support without new dependencies
Add CAWG support for fragmented BMFF
Your coding agent can read these notes before it upgrades. Set up the MCP server →