Skip to content

Releases: MostroP2P/mostro-cli

Release v0.15.2

14 May 17:43
v0.15.2
c08b8a5

Choose a tag to compare

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/negrunch.asc | gpg --import
curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/arkanoider.asc | gpg --import

Once you have the required PGP keys, you can verify the release (assuming manifest.txt.sig.negrunch, manifest.txt.sig.arkanoider and manifest.txt are in the current directory) with:

gpg --verify manifest.txt.sig.negrunch manifest.txt
gpg --verify manifest.txt.sig.arkanoider manifest.txt

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 1E41631D137BA2ADE55344F73852B843679AD6F0
gpg: Good signature from "Francisco Calderón <fjcalderon@gmail.com>" [ultimate]

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 2E986CA1C5E7EA1635CD059C4989CC7415A43AEC
gpg: Good signature from "Arkanoider <github.913zc@simplelogin.com>" [ultimate]

That will verify the signature of the manifest file, which ensures integrity and authenticity of the archive you've downloaded locally containing the binaries. Next, depending on your operating system, you should then re-compute the sha256 hash of the archive with shasum -a 256 <filename>, compare it with the corresponding one in the manifest file, and ensure they match exactly.

What's Changed in v0.15.2

🐛 Bug Fixes

  • use NOSTR_DISPUTE_EVENT_KIND for dispute filter by @grunch

💼 Other

  • Update CHANGELOG for version 0.15.2 by @grunch
  • fix(listdisputes): use NOSTR_DISPUTE_EVENT_KIND for dispute filter by @grunch in #168
  • Update readme by @grunch

⚙️ Miscellaneous Tasks

  • Release mostro-cli version 0.15.2 by @grunch

Contributors

Full Changelog: v0.15.1...v0.15.2

Release v0.15.1

13 May 19:25
v0.15.1
3710a67

Choose a tag to compare

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/negrunch.asc | gpg --import
curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/arkanoider.asc | gpg --import

Once you have the required PGP keys, you can verify the release (assuming manifest.txt.sig.negrunch, manifest.txt.sig.arkanoider and manifest.txt are in the current directory) with:

gpg --verify manifest.txt.sig.negrunch manifest.txt
gpg --verify manifest.txt.sig.arkanoider manifest.txt

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 1E41631D137BA2ADE55344F73852B843679AD6F0
gpg: Good signature from "Francisco Calderón <fjcalderon@gmail.com>" [ultimate]

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 2E986CA1C5E7EA1635CD059C4989CC7415A43AEC
gpg: Good signature from "Arkanoider <github.913zc@simplelogin.com>" [ultimate]

That will verify the signature of the manifest file, which ensures integrity and authenticity of the archive you've downloaded locally containing the binaries. Next, depending on your operating system, you should then re-compute the sha256 hash of the archive with shasum -a 256 <filename>, compare it with the corresponding one in the manifest file, and ensure they match exactly.

What's Changed in v0.15.1

🚀 Features

  • expose BondResolution payload on adm-settle / adm-cancel by @grunch

💼 Other

  • Update CHANGELOG for version 0.15.1 by @grunch
  • feat(admin): expose BondResolution payload on adm-settle / adm-cancel by @grunch in #167
  • bumps mostro-core version by @grunch

⚙️ Miscellaneous Tasks

  • Release mostro-cli version 0.15.1 by @grunch

Contributors

Full Changelog: v0.15.0...v0.15.1

Release v0.15.0

11 May 20:34
v0.15.0
010b5bf

Choose a tag to compare

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/negrunch.asc | gpg --import
curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/arkanoider.asc | gpg --import

Once you have the required PGP keys, you can verify the release (assuming manifest.txt.sig.negrunch, manifest.txt.sig.arkanoider and manifest.txt are in the current directory) with:

gpg --verify manifest.txt.sig.negrunch manifest.txt
gpg --verify manifest.txt.sig.arkanoider manifest.txt

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 1E41631D137BA2ADE55344F73852B843679AD6F0
gpg: Good signature from "Francisco Calderón <fjcalderon@gmail.com>" [ultimate]

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 2E986CA1C5E7EA1635CD059C4989CC7415A43AEC
gpg: Good signature from "Arkanoider <github.913zc@simplelogin.com>" [ultimate]

That will verify the signature of the manifest file, which ensures integrity and authenticity of the archive you've downloaded locally containing the binaries. Next, depending on your operating system, you should then re-compute the sha256 hash of the archive with shasum -a 256 <filename>, compare it with the corresponding one in the manifest file, and ensure they match exactly.

What's Changed in v0.15.0

🚀 Features

  • bump mostro-core to 0.11.0 and handle anti-abuse bond flow by @grunch
  • feat: by @arkanoider
  • feat(getdmuser): show shared-key DMs (identity + admin) in getdmuser - Derive shared key from (trade_keys, identity_keys) and fetch/unwrap gift wraps so DMs sent to the user's identity appear in getdmuser. - Also derive (trade_keys, mostro_pubkey) and fetch so admin replies from the send_admin_dm_attach flow are shown. - Reuse derive_shared_key_bytes from util/messaging (same ECDH as send_admin_dm_attach). No longer use get_all_trade_and_counterparty_keys; counterparty_pubkey is not used in this setup. by @arkanoider
  • added a command to send dm with attachment to admin to help disputes solving - added some docs for AI generated code by @arkanoider

🐛 Bug Fixes

  • error out on malformed PayBondInvoice payload by @grunch
  • fix fmt by @grunch
  • scope orders_info request to identity key by @grunch
  • sign restore and last-trade-index requests with identity keys by @grunch
  • rabbit rants by @arkanoider
  • Align DM docs/messages and validate POW env parsing by @arkanoider
  • Blossom upload auth and response handling by @arkanoider
  • prevent UUID truncation in listorders table by @codaMW
  • meaningful error message and unit tests added by @arkanoider
  • completed all the paths with new pow management by @arkanoider
  • fix for giftwrap with pow creation by @arkanoider
  • correct keys used for send_dm command by @arkanoider

💼 Other

  • Update CHANGELOG for version 0.15.0 by @grunch
  • feat: bump mostro-core to 0.11.0 and handle anti-abuse bond flow by @grunch in #166
  • refactor: migrate gift-wrap to mostro-core 0.10 dual identity/trade keys by @grunch in #165
  • refactor: migrate gift-wrap to mostro-core 0.9.1 nip59 module by @grunch in #164
  • Shared key chat and attachment feature by @grunch in #157
  • Remove unused fiat module by @grunch in #162
  • Remove unused fiat module by @grunch
  • fix(orders): prevent UUID truncation in listorders table by @grunch in #159
  • fix for giftwrap with pow creation by @grunch in #161
  • docs: add branch protection rules documentation by @grunch in #160
  • Improve MOSTRO_PUBKEY resolution and remove startup panic by @grunch in #152
  • resolve MOSTRO_PUBKEY from CLI flag or env without panic by @codaMW

🚜 Refactor

  • migrate gift-wrap to mostro-core 0.10 dual identity/trade keys by @grunch
  • migrate gift-wrap to mostro-core 0.9.1 nip59 module by @grunch

📚 Documentation

  • added specifications for direct message and direct message with attachment by @arkanoider
  • add branch protection rules

⚙️ Miscellaneous Tasks

Contributors

Full Changelog: v0.14.5...v0.15.0

Release v0.14.5

17 Jan 20:40
v0.14.5
a03afb7

Choose a tag to compare

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/negrunch.asc | gpg --import
curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/arkanoider.asc | gpg --import

Once you have the required PGP keys, you can verify the release (assuming manifest.txt.sig.negrunch, manifest.txt.sig.arkanoider and manifest.txt are in the current directory) with:

gpg --verify manifest.txt.sig.negrunch manifest.txt
gpg --verify manifest.txt.sig.arkanoider manifest.txt

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 1E41631D137BA2ADE55344F73852B843679AD6F0
gpg: Good signature from "Francisco Calderón <fjcalderon@gmail.com>" [ultimate]

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 2E986CA1C5E7EA1635CD059C4989CC7415A43AEC
gpg: Good signature from "Arkanoider <github.913zc@simplelogin.com>" [ultimate]

That will verify the signature of the manifest file, which ensures integrity and authenticity of the archive you've downloaded locally containing the binaries. Next, depending on your operating system, you should then re-compute the sha256 hash of the archive with shasum -a 256 <filename>, compare it with the corresponding one in the manifest file, and ensure they match exactly.

What's Changed in v0.14.5

🚀 Features

💼 Other

⚙️ Miscellaneous Tasks

Contributors

Full Changelog: v0.14.4...v0.14.5

Release v0.14.4

24 Nov 21:12
v0.14.4
07f54fd

Choose a tag to compare

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/negrunch.asc | gpg --import
curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/arkanoider.asc | gpg --import

Once you have the required PGP keys, you can verify the release (assuming manifest.txt.sig.negrunch, manifest.txt.sig.arkanoider and manifest.txt are in the current directory) with:

gpg --verify manifest.txt.sig.negrunch manifest.txt
gpg --verify manifest.txt.sig.arkanoider manifest.txt

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 1E41631D137BA2ADE55344F73852B843679AD6F0
gpg: Good signature from "Francisco Calderón <fjcalderon@gmail.com>" [ultimate]

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 2E986CA1C5E7EA1635CD059C4989CC7415A43AEC
gpg: Good signature from "Arkanoider <github.913zc@simplelogin.com>" [ultimate]

That will verify the signature of the manifest file, which ensures integrity and authenticity of the archive you've downloaded locally containing the binaries. Next, depending on your operating system, you should then re-compute the sha256 hash of the archive with shasum -a 256 <filename>, compare it with the corresponding one in the manifest file, and ensure they match exactly.

What's Changed in v0.14.4

🚀 Features

💼 Other

  • Update CHANGELOG for version 0.14.4 by @arkanoider
  • refactor: Make ADMIN_NSEC optional and rename from NSEC_PRIVKEY by @arkanoider in #149

🚜 Refactor

⚙️ Miscellaneous Tasks

Contributors

Full Changelog: v0.14.3...v0.14.4

Release v0.14.3

06 Nov 21:18
v0.14.3

Choose a tag to compare

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/negrunch.asc | gpg --import
curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/arkanoider.asc | gpg --import

Once you have the required PGP keys, you can verify the release (assuming manifest.txt.sig.negrunch, manifest.txt.sig.arkanoider and manifest.txt are in the current directory) with:

gpg --verify manifest.txt.sig.negrunch manifest.txt
gpg --verify manifest.txt.sig.arkanoider manifest.txt

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 1E41631D137BA2ADE55344F73852B843679AD6F0
gpg: Good signature from "Francisco Calderón <fjcalderon@gmail.com>" [ultimate]

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 2E986CA1C5E7EA1635CD059C4989CC7415A43AEC
gpg: Good signature from "Arkanoider <github.913zc@simplelogin.com>" [ultimate]

That will verify the signature of the manifest file, which ensures integrity and authenticity of the archive you've downloaded locally containing the binaries. Next, depending on your operating system, you should then re-compute the sha256 hash of the archive with shasum -a 256 <filename>, compare it with the corresponding one in the manifest file, and ensure they match exactly.

What's Changed in v0.14.3

🚀 Features

  • committed cargo.toml with changelog.md by @arkanoider
  • added local changelog.md file creation with cargo release by @arkanoider

🐛 Bug Fixes

  • correct receiver of restore session message by @arkanoider

Contributors

Full Changelog: v0.14.2...v0.14.3

Release v0.14.2

20 Oct 15:52
v0.14.2
572b80a

Choose a tag to compare

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/negrunch.asc | gpg --import
curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/arkanoider.asc | gpg --import

Once you have the required PGP keys, you can verify the release (assuming manifest.txt.sig.negrunch, manifest.txt.sig.arkanoider and manifest.txt are in the current directory) with:

gpg --verify manifest.txt.sig.negrunch manifest.txt
gpg --verify manifest.txt.sig.arkanoider manifest.txt

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 1E41631D137BA2ADE55344F73852B843679AD6F0
gpg: Good signature from "Francisco Calderón <fjcalderon@gmail.com>" [ultimate]

gpg: Signature made fri 10 oct 2025 11:28:03 -03
gpg:                using RSA key 2E986CA1C5E7EA1635CD059C4989CC7415A43AEC
gpg: Good signature from "Arkanoider <github.913zc@simplelogin.com>" [ultimate]

That will verify the signature of the manifest file, which ensures integrity and authenticity of the archive you've downloaded locally containing the binaries. Next, depending on your operating system, you should then re-compute the sha256 hash of the archive with shasum -a 256 <filename>, compare it with the corresponding one in the manifest file, and ensure they match exactly.

What's Changed in v0.14.2

🚀 Features

  • automatic update of child order in database when a range sale order is completed, no more errors on next flow. Still a bit trickier the buy range order thing by @arkanoider
  • big refactor in all the cosmetics of mostro-cli interface with user by @arkanoider
  • feat: beautified lot of terminal output (thanks cursor!) by @arkanoider

🐛 Bug Fixes

💼 Other

  • Beautified lot of terminal output by @arkanoider in #146
  • Merge commit 'a0aaaad2041709b1784cddb1b92b0e90450ad903' into terminal-beautify by @arkanoider
  • Fix clippy errors by @grunch
  • Merge commit '2a6d88f82ad5ebf59a2414be81cd8e819c5c3e6f' into terminal-beautify by @arkanoider
  • Fix race condition by @grunch
  • Adjust text to fir smaller screens by @grunch
  • CodeRabbit Generated Unit Tests: Add 78 unit tests and comprehensive test documentation by @arkanoider in #147
  • CodeRabbit Generated Unit Tests: Add 78 unit tests and comprehensive test documentation by @coderabbitai[bot]

⚙️ Miscellaneous Tasks

Contributors

Full Changelog: v0.14.1...v0.14.2

Release v0.14.1

12 Oct 10:21
v0.14.1
ad634a4

Choose a tag to compare

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/negrunch.asc | gpg --import

Once you have the required PGP keys, you can verify the release (assuming manifest.txt.sig and manifest.txt are in the current directory) with:

gpg --verify manifest.txt.sig manifest.txt

gpg: Firmado el jue 03 ago 2023 15:07:05 -03
gpg:                usando RSA clave 1E41631D137BA2ADE55344F73852B843679AD6F0
gpg: Firma correcta de "Francisco Calderón <fjcalderon@gmail.com>" [absoluta]

That will verify the signature of the manifest file, which ensures integrity and authenticity of the archive you've downloaded locally containing the binaries. Next, depending on your operating system, you should then re-compute the sha256 hash of the archive with shasum -a 256 <filename>, compare it with the corresponding one in the manifest file, and ensure they match exactly.

What's Changed in v0.14.1

🐛 Bug Fixes

  • reverted a rabbit fix for the moment to avoid breaking change by @arkanoider

⚙️ Miscellaneous Tasks

Contributors

Full Changelog: v0.14.0...v0.14.1

Release v0.14.0

10 Oct 19:54
8ecd4d2

Choose a tag to compare

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/negrunch.asc | gpg --import

Once you have the required PGP keys, you can verify the release (assuming manifest.txt.sig and manifest.txt are in the current directory) with:

gpg --verify manifest.txt.sig manifest.txt

gpg: Firmado el jue 03 ago 2023 15:07:05 -03
gpg:                usando RSA clave 1E41631D137BA2ADE55344F73852B843679AD6F0
gpg: Firma correcta de "Francisco Calderón <fjcalderon@gmail.com>" [absoluta]

That will verify the signature of the manifest file, which ensures integrity and authenticity of the archive you've downloaded locally containing the binaries. Next, depending on your operating system, you should then re-compute the sha256 hash of the archive with shasum -a 256 <filename>, compare it with the corresponding one in the manifest file, and ensure they match exactly.

What's Changed in v0.14.0

🚀 Features

  • add rabbit fixes and improved other parts by @arkanoider
  • improve error logging for gift wrap decryption and use admin pubkey for DM filtering by @AndreaDiazCorreia
  • fixed some wrong key in decryption by @arkanoider
  • improved reception logic and small fix for last trade index by @arkanoider
  • feat: first testable mostro cli version with last_trade_index command to be tested by @arkanoider
  • added correct since time calculation for get dm command - improved code readability for new order management in db.rs by @arkanoider
  • add invalid fiat currency managed by @arkanoider
  • improving parsing functions by @arkanoider
  • update order status to disputed after initiating dispute by @AndreaDiazCorreia
  • add handling for user-initiated dispute actions in message handler by @AndreaDiazCorreia
  • created ci.yml also in mostro-cli by @arkanoider

🐛 Bug Fixes

  • completed merge of pr and fixed conflicts by @arkanoider
  • moved some logic parts in wait dm function to avoid issues with unresponsive relays by @arkanoider
  • added a check to avoid UNIQUE constraint error - now if an order is yet present in db we do an UPDATE sql and not INSERT by @arkanoider
  • some fixes on message management by @arkanoider
  • use Status enum instead of hardcoded string for dispute status by @AndreaDiazCorreia

💼 Other

🚜 Refactor

  • Split big utils.rs file in a module for being more usable by @arkanoider

⚙️ Miscellaneous Tasks

Contributors

Full Changelog: v0.13.6...v0.14.0

Release v0.13.6

23 Sep 18:45
a8ab0ea

Choose a tag to compare

Verifying the Release

In order to verify the release, you'll need to have gpg or gpg2 installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

curl https://raw.githubusercontent.com/MostroP2P/mostro/main/keys/negrunch.asc | gpg --import

Once you have the required PGP keys, you can verify the release (assuming manifest.txt.sig and manifest.txt are in the current directory) with:

gpg --verify manifest.txt.sig manifest.txt

gpg: Firmado el jue 03 ago 2023 15:07:05 -03
gpg:                usando RSA clave 1E41631D137BA2ADE55344F73852B843679AD6F0
gpg: Firma correcta de "Francisco Calderón <fjcalderon@gmail.com>" [absoluta]

That will verify the signature of the manifest file, which ensures integrity and authenticity of the archive you've downloaded locally containing the binaries. Next, depending on your operating system, you should then re-compute the sha256 hash of the archive with shasum -a 256 <filename>, compare it with the corresponding one in the manifest file, and ensure they match exactly.

What's Changed in v0.13.6

🚀 Features

  • removed android build by @arkanoider
  • remove deps of sqlx of openssl to avoid using it as dep in github actions by @arkanoider

🐛 Bug Fixes

  • strict tag check on cliff.toml and tag fetch before git cliff by @arkanoider
  • restored latest in git cliff by @arkanoider
  • removed deps in rust.yml of protobuf and openssl by @arkanoider
  • add openssl deps in gh actions by @arkanoider
  • improved changelo to have correct file on release by @arkanoider

💼 Other

⚙️ Miscellaneous Tasks

Contributors

Full Changelog: v0.13.5...v0.13.6