Whether you're an individual, part of a team, or managing a business, Bitwarden helps you store, share, and sync your data safely across all your devices. With secure cloud syncing, you can access your vault anytime, anywhere – on mobile, desktop, or web.

Password theft is a growing threat. Every day, websites and apps face attacks that can expose your credentials. Reusing passwords puts all your accounts at risk – from email to banking. Bitwarden helps you generate and manage strong, unique passwords to keep your information safe.

How secure is Bitwarden's encryption?

Bitwarden uses zero-knowledge encryption, meaning your data is encrypted locally on your device before it is ever sent to their servers. It employs AES-256 encryption (AES-CBC) alongside PBKDF2 SHA-256 or Argon2id key derivation. The encryption key is generated from your master password locally and never leaves your device. Only an irreversible hash of your password is sent to authenticate you, not the key itself.

What is the difference between Bitwarden's free and paid tiers?

Bitwarden offers a free account that includes core features like unlimited passwords, cross-device syncing, and TOTP seed storage. Premium (~$10/year) adds extras such as 1 GB encrypted file attachments, integrated TOTP code generation, YubiKey/FIDO2 support, and the ability to set up trusted emergency contacts.

How can I recover if I'd forgotten my master password?

Bitwarden is a zero-knowledge system and doesn't store or recover your master password. Without it – and without a backup – you can't decrypt your vault. However, premium users can designate emergency contacts who can request access in emergencies.

Is Bitwarden trustworthy?

Yes, Bitwarden is trustworthy. It uses end-to-end encryption, is open source, regularly audited by third parties, and offers strong security features like two-factor authentication and hardware key support.

Should I use generated passwords and enable 2FA for Bitwarden and other sites?

Absolutely. It's best to use Bitwarden's built-in password generator (15 – 25 characters with symbols, numbers, etc.). For your vault, enable two-factor authentication: using options like an authenticator app, FIDO2 key (YubiKey), or email recovery. You can also store TOTP seeds in your vault for use with other services.

Features

Bitwarden is a solid free password manager for several reasons:

  • It is open-source and regularly audited for security
  • Its core features are free, with no device or entry limits
  • Uses 256-bit AES end-to-end encryption
  • Allows unlimited device usage with secure syncing
  • Stores passwords, secure notes, credit cards, and identities
  • Supports free sharing between 2 users (via a free organization)
  • Integrates with email alias services like SimpleLogin and Firefox Relay

End-to-End Encryption

Lock your passwords and private information with end-to-end AES-256 bit encryption, salted hashing, and PBKDF2 SHA-256.

Cross-Platform Applications

Secure and share sensitive data within your Bitwarden Vault from any browser, mobile device, or desktop application.

Global Community

Align to the highest security standards with a global community of password security experts and Bitwarden users.

How do you stay safe?

Security experts recommend that you use a different, randomly generated password for every online account that you create. But how are you supposed to remember and keep up with that many passwords? Bitwarden helps you create and manage secure passwords so that you can get back to enjoying your life online.

Sync all of Your Devices

A password manager is useless if you can't easily access it. Our secure cloud syncing features allow you to access your data from anywhere, on any device! Your vault is conveniently optimized for use on desktop, laptop, tablet, and phone devices.

Since all of your data is fully encrypted before it ever leaves your device, only you have access to it. Not even the team at Bitwarden can read your data, even if we wanted to. Your data is sealed with end-to-end AES-256 bit encryption, salted hashing, and PBKDF2 SHA-256.

What's New

Community Highlight

  • [PM-38362] fix(powermonitor): Improve connection handling and remove unwraps by @ChihweiLHBird in #20919
  • [PM-32423] Add a less confusing argument and environment variable name to disable updates by @marcquark in #19045
  • [PM-35288] feat: auto-close sso tab after authentication completes by @sander-adamse in #20213
  • [PM-38760] Recursively create directory when writing manifest by @pschlan in #21141
  • [PM-36443] fix microsoft totp autofill by @danysigha in #20481
  • [PM-33285] Enhance privacy in password leak detection with response padding by @TheDcoder in #19439
  • [PM-38109] fix(browser): use direct clipboard API when popup has DOM access by @RobinAngele in #20859
  • [PM-39179] fix(desktop): correct various typos in desktop application by @luojiyin1987 in #21322
  • [PM-39180] fix(browser): correct various typos in browser extension by @luojiyin1987 in #21323
  • [PM-39177] fix(libs): correct various typos in shared libraries and documentation by @luojiyin1987 in #21320
  • [PM-38123] [bug] Preserve 1Password archive state on 1pux import (closes #20694) by @999purple999 in #20867
  • [PM-33198] Keeper direct importer by @detunized in #19395

Feature Development

  • [PM-38565] Replace tray settings with "Keep Bitwarden running in the background" by @quexten in #21044
  • [PM-39048] Feat: scaffold @bitwarden/pam library by @Hinton in #21259
  • [PM-34779] Add accept method to OrganizationInviteLinkApiService by @r-tome in #21266
  • [PM-31884] implemented controls for send policy access dropdown by @bmbitwarden in #19777
  • Auth/PM-38298 - Org Invite Acceptance Refactor by @JaredSnider-Bitwarden in #21011
  • [PM-35059] Coachmark tour for Access Intelligence by @voommen-livefront in #20808
  • [PM-38580] Adds copy to invite member role select by @BTreston in #21280
  • [PM-38787] Pin vault bulk-actions bar to the viewport on scroll by @nick-livefront in #21154
  • [PM-34023] Remove 2FA account recovery flag by @eliykat in #21291
  • PM 35229 [Browser/Desktop] Stripe Checkout from upgrade dialog by @cyprain-okeke in #20592
  • [PM-36835] implement logging in the weak-passwords component by @voommen-livefront in #21305
  • Revert "[PM-36835] implement logging in the weak-passwords component" by @voommen-livefront in #21343
  • Revert "Revert "[PM-36835] implement logging in the weak-passwords component"" by @voommen-livefront in #21344
  • IPC Desktop <-> Browser transport by @coroiu in #19908
  • [PM-34053] Swap verify trust to new SDK method by @Thomas-Avery in #21347
  • [PM-39070] Create new permissions screen by @dan-livefront in #21311
  • [PM-39129] Add UsePam organization capability by @Hinton in #21298
  • [PM-39195] Add banner to scimv2 component for invite link by @BTreston in #21363
  • [BEEEP] [PM-38226] Add disable auto-start option for snap by @quexten in #20855
  • [PM-38834]Allow programmatic changes to Firefox settings by @dan-livefront in #21177
  • [PM-37986] Centralized ownership UI rework by @BTreston in #21348
  • [PM-35230] clients Web Checkout success page by @cyprain-okeke in #20653
  • Auth/PM-38742 - SSO Invited Existing User Flow Improvement - Show SSO redirect error notification on LoginComponent by @JaredSnider-Bitwarden in #21134
  • [PM-36864] Refactor vault routing to use VaultV2Component directly, removing feature flagged code by @JaredScar in #21419
  • [PM-37875] Automatic V2 Upgrade Migration by @quexten in #20831
  • [PM-38778]Make Bitwarden default password manager, callout implementation. by @dan-livefront in #21156
  • [PM-39195] Back port banner to old component by @BTreston in #21415
  • [PM-34580] Rename "Note" to "Secure note" for SecureNote cipher type by @nick-livefront in #21423
  • [PM-33740] Remove unlock service for password flagged logic by @mzieniukbw in #21427
  • [PM-37555] add autofill lifecycle by @audreyality in #20949
  • [PM-33408] Add OrganizationUserNotification banner to vault by @jengstrom-bw in #21209
  • [PM-37807] Implement VaultBatchBarComponent on organization vault by @gbubemismith in #21345
  • [PM-32696] Add data field to Cipher object to support blob encryption by @nikwithak in #20765
  • [PM-24223] Add feature flagged support for password v2 registration by @eligrubb in #20782
  • [PM-38345] block account, remove card, remove free fam, and desktop autotype to simple toggle by @JaredScar in #21097
  • [PM-3841] - Default the new collection organization select to the active org by @jaasen-livefront in #21374
  • [PM-38343] 2 step and require sso and remove unlock and remove export into simple toggle by @JaredScar in #21092
  • [PM-33410] Add organizationusernotification banners to vault desktop by @jengstrom-bw in #21462
  • [PM-29785] Abstract Windows Passkey Plugin Authenticator COM implementation by @iinuwa in #20285
  • [PM-33409] Add organizationusernotification banner to vault browser by @jengstrom-bw in #21461
  • [PM-37978] update UI for MP policy, refactor org lookup by @BTreston in #21313
  • [CL-1138] Add stacked drawer support with back button by @willmartian in #19804
  • [PM-38480] Add Staged Event Message by @sven-bitwarden in #21499
  • [PM-32402] Update copy from new to add/create web app by @jengstrom-bw in #21355
  • [PM-35106] Make AES-GCM the default algorithm in crypto.rs for secure memory by @mzieniukbw in #21553
  • [PM-37808] Bulk Selection + Batch Bar for Desktop by @nick-livefront in #21308
  • [PM-39472] Note -> Secure Note by @nick-livefront in #21469
  • [PM-37987] update drawer UI for account recovery administration policy by @JaredScar in #21565
  • [PM-37989] update drawer UI for password generator policy by @JaredScar in #21564
  • [PM-38346] Single Org and Autofill into SimpleTogglePolicyComponent by @JaredScar in #21595
  • [PM-38481] Add Staged Filter for Organization Members by @sven-bitwarden in #21394
  • [PM-29785] CTAP2 CBOR Parser by @iinuwa in #21584
  • [PM-39071]Wire new permissions screen by @dan-livefront in #21391
  • [PM-38828]Change settings order and copy by @dan-livefront in #21464
  • [PM-29785] Allow waiting for Autofill IPC connection in Windows authenticator by @iinuwa in #21615
  • [PM-29790] Prepare for separate Windows Passkey Plugin Authenticator exe by @iinuwa in #21616
  • [PM-29790] Add credential request processing for Windows passkey plugin by @iinuwa in #21618
  • Auth/PM-39774 - SSO - Improve error for existing users without org membership by @JaredSnider-Bitwarden in #21573
  • [PM-29790] Wire up authenticator IPC and COM server for Windows passkey plugin by @iinuwa in #21622
  • [PM-34393] Show invite link events in event log by @r-tome in #21335
  • [CL-1158] update browser footer by @BryanCunningham in #21612
  • [PM-37963] - Add Staged Member Actions by @sven-bitwarden in #21597
  • [PM-29790] Windows passkey plugin: unify signature verification by @iinuwa in #21634
  • windows-plugin: Add plugin entrypoint by @iinuwa in #21635
  • [PM-33362] Autotype Edit Cipher Initial Changes by @coltonhurst in #21500
  • [PM-37988] Add SessionTimeoutPolicyV2 component usage for new policy drawers by @JaredScar in #21561
  • [PM-39147] Batch bar copy fixes – singular/plural toasts and dialog title by @nick-livefront in #21602
  • PM-32187 implemented restrict send type by @bmbitwarden in #20129
  • [PM-40060] Add native messaging permission dialog by @quexten in #21703
  • Pm 31929 new send policy for deletion days by @bmbitwarden in #20128
  • [PM-33054] Remove feature flag cipher-key-encryption by @jengstrom-bw in #21309
  • [PM-36505] Finalize Send Controls policy design, adjust base policy component enabled display logic by @mcamirault in #21739
  • [PM-39876] Implement targeting rules form category by @jprusik in #21715
  • [PM-20344] Disallow multiple attachments with the same name, handle existing in zip export format by @mcamirault in #21596
  • [PM-40060] Split shared unlock setting into desktop and web by @quexten in #21704
  • [PM-35796] Use SDK bindings for invite link generation by @BTreston in #21004
  • [PM-40074] Refactor policy definitions to remove deprecated versions and streamline components by @JaredScar in #21717
  • [PM-37964] Add Ability to Disable Automatic Invitations in SCIM by @sven-bitwarden in #21756
  • [CL-1001] adding new toggle group styles by @BryanCunningham in #20403
  • feat: add Region.Gov to available environments by @addisonbeck in #21211
  • [PM-40126] Update organizationusernotificationpolicy for policy drawer by @jengstrom-bw in #21747
  • [PM-38387] Introduce KeePass KDBX importer by @harr1424 in #21052
  • Finalize Manage Send policy description by @mcamirault in #21786
  • feat(platform): introduce GovModeService for FedRAMP region gating by @addisonbeck in #21366
  • [CL-1274] Add bit-page layout region for bit-layout main content by @willmartian in #21790
  • [PM-37944] Differentiate Send events according to domain by @harr1424 in #20787

Bug fixes

  • [PM-25277] SSH Key desktop translations by @nick-livefront in #21208
  • [PM-34926] Allow single-character CJK vault searches by @jaasen-livefront in #21013
  • [PM-35212] - allow bulk archive/unarchive of items in a collection by @jaasen-livefront in #20920
  • [PM-37752] - fix collections control when extension loses focus by @jaasen-livefront in #20812
  • [PM- 38988] Fix Trial Dialog Dismissal Caching by @sbrown-livefront in #21240
  • [PM-38830] fix: Display fixed-amount and repeating churn discounts by @amorask-bitwarden in #21281
  • [PM-38275] Fix at-risk application count in Access Intelligence v2 drawer by @Banrion in #21265
  • [PM-38286] Fix Access Intelligence at-risk drawer can reopen by @Banrion in #21314
  • [PM-32445] Extension Scrollbar Fix by @rr-bw in #20478
  • [PM-39206] use block input to ensure radios are displayed stacked by @BryanCunningham in #21361
  • Auth/PM-35783 - Fix Org Invite Policy State Pollution and State Clearing Issue by @JaredSnider-Bitwarden in #21218
  • [PM-39200] - fix notification bar behavior with save and fill by @jaasen-livefront in #21351
  • [PM-38409] - update custom field value on reorder by @jaasen-livefront in #21137
  • [PM-38581] - disable drag for single custom fields by @jaasen-livefront in #21136
  • [Sm-1934] Fixing showing 10/123 secrets issue by @cd-bitwarden in #20783
  • [PM-39295] Fix SDK IPC messages being parsed by legacy IPC, resetting the connection by @quexten in #21387
  • fix(platform): remove hardcoded vault.bitwarden.com checks in getSendUrl and getScimUrl by @addisonbeck in #21373
  • PM-37236 resolved password button issue on browser by @bmbitwarden in #21359
  • [SM-1993][CL-1227] Fix textarea height and fix SM button spacing by @vleague2 in #21417
  • [PM-39392] Use readonly styles for fields intended to be readonly by @vleague2 in #21425
  • [PM-39204] Add extra spacing to vault items when batch bar is visible by @nick-livefront in #21390
  • PM-39289 fixed close to done, misplaced popover and alignment by @voommen-livefront in #21437
  • [CL-1228] hide actions container if empty and always render button outside by @BryanCunningham in #21440
  • [PM-37932] Make IPC content script re-injection idempotent by @coroiu in #21451
  • [PM-39290] Coachmark navigation in v2 by @voommen-livefront in #21456
  • [PM-27041] - CLI - respect passphrase param in /generate by @jaasen-livefront in #21290
  • [PM-39429] remeasure bulk actions bar width when actions change by @BryanCunningham in #21443
  • change link for terraform integration in SM GUI by @vlad-trofimov in #21285
  • manually recompile select css by @BryanCunningham in #21488
  • [PM-39440] Refactor domain verification dialog to improve form control handling by @JaredScar in #21476
  • [CL-1225] Berry should hide when count is 0 in toggle group by @vleague2 in #21491
  • [SM-1483] Fix self-hosted environment URLs in Secrets Manager config by @vincentsalucci in #21375
  • PM-39449 resolved root url issues by @bmbitwarden in #21468
  • [PM-39576] - [Defect] Coachmark tour page number is displaying "$CURRENT$ of TOTAL" in main. by @jaasen-livefront in #21496
  • [PM-38643] Fix default broken on wayland only systems by @quexten in #21079
  • [PM-38985] Fix CipherResponse/CipherData type confusion in archive and emergency access services by @nick-livefront in #21237
  • [PM-39610] Keyboard shortcuts only work once by @gbubemismith in #21520
  • reduce select label font size by @BryanCunningham in #21525
  • [PM-39746] Exclude search and select components from legacy global desktop css by @vleague2 in #21556
  • [PM-37978] Fix stories by @BTreston in #21566
  • [PM-38262] Apply tolerant-validator pattern to V2 read path in Access Intelligence by @Banrion in #21474
  • [PM-38836] harden calculateSubFramePositioning by @audreyality in #21282
  • Fix SSH Agent v2 behavior before first unlock by @neuronull in #21273
  • [PM-39799] Fix type errors by @BTreston in #21583
  • [PM-18344] Remove XDG_CURRENT_DESKTOP Unity override to fix clipboard on wayland by @quexten in #21513
  • Revert "[PM-38760] Recursively create directory when writing manifest (#21141)" by @addisonbeck in #21568
  • [PM-39805] fix: Exclude permanent migration-grace machine accounts from billable count by @amorask-bitwarden in #21598
  • [PM-39841] Fix unlocking crashing the desktop app by @quexten in #21610
  • [PM-39780] Toast text is incorrect when editing collection access by @gbubemismith in #21601
  • [PM-39900] Enhance PoliciesComponent to clear drawer reference after closing by @JaredScar in #21639
  • [PM-39447] [Shared Unlock] Shared unlock stuck on lock component by @quexten in #21446
  • [PM-39060] Fix new org button not showing up by @BTreston in #21594
  • [PM-39556] Fix access selector not saving changes when the dialog field is modified by @BTreston in #21640
  • [PM-38763] Exclude sponsorship redemption from premium-to-org upgrade flow by @sbrown-livefront in #21180
  • [PM-36888] Do auto confirm when setting is enabled by @BTreston in #21614
  • [PM-39796] Fix bug in new Send dropdown component that prevented navigation after Send creation by @mcamirault in #21590
  • [PM-37489] Fixes issue where checkbox label does not enable checkbox by @JaredScar in #21657
  • [PM-39977] Fix broken shared unlock for browser-desktop in non-dev mode by @quexten in #21688
  • [PM-37196] Tooltip expand max-width by @JaredScar in #21646
  • [PM-39269] Fix At-Risk Members CSV export including extra columns by @AlexRubik in #21477
  • Revert "[Shared Unlock] [PM-34508] Default enable native messaging pe… by @quexten in #21687
  • [PM-39123] Fix members page filters flicker by @JaredScar in #21656
  • [PM-39570] use correct fill for bup logo by @BryanCunningham in #21694
  • Prevent connect to desktop in ipc background if native messaging permission is missing by @quexten in #21702
  • [PM-38896] Enhance DefaultCollectionService tests and improve decryption by @JaredScar in #21439
  • [PM-39349]] - make ssh key cipher fields readonly by @jaasen-livefront in #21505
  • [PM-39380] Bitwarden unencrypted JSON files containing cipher keys prevent import by @harr1424 in #21587
  • [PM-39695] Send fields are unexpectedly editable and changes cannot be saved by @harr1424 in #21542
  • [PM-39608] Update firefox NMHS permission for snap by @quexten in #21728
  • [PM-31138] Perform full sync on other clients after upgrade key rotation by @quexten in #21628
  • fix(vault): archive and unarchive missing from bulk bar for org items by @nick-livefront in #21741
  • [PM-7036] Add support for latest LogMeOnce CSV import format, add folder mapping by @mcamirault in #21473
  • [PM-39450] [Shared Unlock] Scan Secure Preferences when detecting installed Chrome extensions by @quexten in #21449
  • fix(unlock): Biometric unlock shows error dialog when cancelling by @quexten in #21731
  • [PM-39974] Remove Biometric Integration Setting Fully by @quexten in #21684
  • [PM-31068] Wire send SDK repository for edit/removePassword by @adudek-bw in #21579
  • [PM-38761] Fix hard-coded families plan price in revoke sponsorship dialog by @sbrown-livefront in #21243
  • [PM-39554] Create default collection when admin is demoted to user by @BTreston in #21632
  • [PM-39891] Fix edit member dialog badge by @BTreston in #21637
  • [PM-38595] Update local collections from server response by @BTreston in #21744
  • [PM-38771] - add missing i18n strings for button labels by @jaasen-livefront in #21509
  • [CL-1263] Increase active bottom navigation label font weight by @BryanCunningham in #21772
  • [PM-39218] Use global environment for self-hosted env dialog and SSO URL by @trmartin4 in #21723
  • fix(desktop): fix Firefox native messaging host manifest directory creation by @quexten in #21784
  • [PM-38392] Route password-protected Send saves through the SDK by @adudek-bw in #21725
  • fix(desktop): fix crash generating DuckDuckGo native messaging manifests by @quexten in #21783
  • [PM-39705] Edit Access Modal Does Not Display Members With Access When Going Through Bulk Actions by @gbubemismith in #21773
  • Render native form control UI in dark theme with color-scheme: dark by @maxkpower in #21771
  • fix(browser): Fix biometrics setup and connection issues by @quexten in #21782
  • [PM-40147] Fix Send page filters not appearing on browser by @harr1424 in #21759
  • fix(biometrics): Biometric unlock does not work over SDK by @quexten in #21730
  • [PM-38608] [PM-38560] Fix diacritic normalization and multi-word query handling in searchCiphersBasic by @nick-livefront in #21232
  • [PM-40820] fix style by @BTreston in #21821
  • [PM-38940] Cherry-pick to rc: Fix Permissions-Policy VULN-582 (#21466) by @bensbits91 in #21834
  • [PM-40303] Cherry-pick to rc: Fix user logout when missing permissions by @harr1424 in #21846
  • [PM-40236][RC] Logging out throws error mid-logout due to a race condition. User left in locked state by @mzieniukbw in #21869
  • ⚙️ Maintenance
  • [BRE-2013] Fix repo name in PR description link by @vgrassia in #21276
  • fix(codeowners): Added environment selector to auth's responsibilities by @Patrick-Pimentel-Bitwarden in #21284
  • [PM-38892] Remove unused methods invokeMenu and openContextMenu by @djsmith85 in #21197
  • [PM-38958] Add ESLint no package self import rule by @quexten in #21198
  • [CL-1223] simplify banner component by @BryanCunningham in #21301
  • [PM-39182] Migrate to relative imports - @bitwarden/team-vault-dev by @quexten in #21331
  • Remove unneeded import for ChipActionComponent by @jengstrom-bw in #21342
  • [PM-39293] Remove v2 naming from account recovery dialog by @eliykat in #21386
  • [PM-39182] Migrate to relative imports - @bitwarden/team-key-management-dev by @quexten in #21333
  • [PM-39182] Migrate to relative imports - @bitwarden/team-ui-foundation by @quexten in #21328
  • [PM-39182] Migrate to relative imports - @bitwarden/team-auth-dev by @quexten in #21330
  • [PM-39182] Migrate to relative imports - @bitwarden/team-billing-dev by @quexten in #21325
  • [PM-39182] Migrate to relative imports - @bitwarden/team-admin-console-dev by @quexten in #21329
  • [PM-39182] Migrate to relative imports - @bitwarden/team-data-insights-and-reporting-dev by @quexten in #21327
  • [PM-12043] Remove usage of ActiveUserState from biometric-state.service by @mzieniukbw in #20860
  • [deps]: Pin dependencies by @renovate[bot] in #21406
  • [PM 34708] Use new shared enforce label workflow by @djsmith85 in #21365
  • [PM-32249] Electron custom file protocol by @dani-garcia in #19208
  • [deps] Fix Rust nightly toolchain reference in lint workflow by @coroiu in #21457
  • [PM-38904] - Managed to Claimed Rename by @jrmccannon in #21430
  • add data-testids to log in elements by @nthompson-bitwarden in #21458
  • [PM-38190] Improve sanitization of storybook args helper by @vleague2 in #21362
  • [PM-39141] Fail Safari packaging script on xcodebuild/codesign errors and missing executable by @quexten in #21307
  • Auth/BEEEP/PM-21301 - Move SelfHostedEnvConfigDialog out of libs/auth by @JaredSnider-Bitwarden in #21268
  • [PM-39182] Enable no relative imports rule by @quexten in #21515
  • [PM-36835] Logging to reports by @voommen-livefront in #21512
  • [PM-36841] Align Subtitles for all new Item Types by @jengstrom-bw in #21316
  • [PM-23485] Use a staticlib for UniFFI by @iinuwa in #21495
  • Bump client version(s) by @github-actions[bot] in #21554
  • Auth/PM-39619 - Rename AcceptOrganizationComponent to AcceptOrgDirectInviteComponent by @JaredSnider-Bitwarden in #21522
  • [PM-36407] Ts strict bulk member components by @BTreston in #21455
  • [PM-4439] Replace oidc-client-ts with oauth4webapi by @harr1424 in #20824
  • [PM-23485] Share types between autofill_provider and napi crates by @iinuwa in #18787
  • Bump client version(s) by @github-actions[bot] in #21580
  • Autosync Crowdin Translations for web by @bw-ghapp[bot] in #21508
  • [PM-39398] Refactor Vault Component back to OG naming by @JaredScar in #21569
  • [PM-35812] Remove feature flag by @JaredScar in #21567
  • build: Add arm64-only MacOS pack step by @iinuwa in #21588
  • [VULN-649] ci: Remove deprecated scan workflow by @theMickster in #21429
  • [BRE-1533] Trigger Bitwarden Lite from web vault build by @vgrassia in #21605
  • introduce AutofillLifecycleService by @audreyality in #21530
  • [PM-9420] - add cipher$ observable to cipher service by @jaasen-livefront in #21383
  • [PM-28139] Remove V1 Linux Biometrics by @quexten in #21571
  • [CL-1258] Add NumberInput story to bit-form-field by @willmartian in #21692
  • Fix clippy lint by @iinuwa in #21691
  • [PM-39889] Acknowledge quick-xml advisory by @iinuwa in #21693
  • [PM-33362] Use signals for the app label by @coltonhurst in #21638
  • [CL-1261] Add date input form field story by @willmartian in #21695
  • [BRE-2044] Migrate Auto Bump Desktop Version workflow logic to the deploy repo by @vgrassia in #21641
  • SSH Agent v2: restructure the SignRequest by @neuronull in #21654
  • [BRE-2018] Add snapcraft compatibility note to electron-builder PRs by @brandonbiete in #21735
  • [PM-39259] Migrate FIDO2 credential id to SDK random by @quexten in #21712
  • [PM-39259] Migrate DuckDuckGo secure channel to SDK key generation by @quexten in #21711
  • [PM-39898] desktop_core: Don't compile objc when cross-compiling for non-macOS by @iinuwa in #21636
  • [PM-39259] Migrate key-management consumers to SDK key generation by @quexten in #21707
  • [PM-23485] Use strong types for autofill IPC request parsing by @iinuwa in #21737
  • chore(ci): add platform-community code-review signal by @addisonbeck in #21751
  • Tidy Desktop Autofill Service by @iinuwa in #21736
  • [PM-39427] feat: build Chrome beta extension by @trmartin4 in #21757
  • Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #21647
  • [PM-39259] Migrate vault export and generator to SDK random number client by @quexten in #21708
  • [PM-39259] Migrate risk-insights encryption to SDK key generation by @quexten in #21709
  • [PM-39427] feat: build desktop beta artifacts by @trmartin4 in #21758
  • [PM-35600] Update Password Request Models (Key Management) by @rr-bw in #20665
  • [PM-38210] Remove access-intelligence-trend-chart feature flag by @lastbestdev in #21376
  • test: add Gov region to parametrized environment service test suite by @addisonbeck in #21619
  • [PM-34458] Add release.yml to bitwarden/clients by @djsmith85 in #21732
  • refactor(desktop_native): extract secure_memory into its own crate by @quexten in #21780
  • Stop cosmetic mutations in light DOM from doing rebuild work by @blackwood in #21084
  • [PM-39259] Remove typescript cipherkey generation by @quexten in #21729
  • Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #21779
  • desktop-autofill: Move autofill services and models from platform team by @iinuwa in #21765
  • SSH Agent v2: add README by @neuronull in #21791
  • Bumped client version(s) (#21811) by @addisonbeck in #21817

Dependency Updates

  • [PM-18344] Implement Clipboard Support on Wayland/Gnome via RemoteDesktop Portal by @quexten in #21068
  • Update sdk-internal to 0.2.0-main.843 by @bw-ghapp[bot] in #21233
  • [deps] Platform: Update webpack-dev-server to v5.2.4 [SECURITY] by @renovate[bot] in #20700
  • Update sdk-internal to 0.2.0-main.849 by @bw-ghapp[bot] in #21299
  • [deps] Platform: Update Rust crate serde_with to v3.21.0 by @renovate[bot] in #21407
  • [deps] Platform: Update @babel/core to v7.29.6 [SECURITY] by @renovate[bot] in #21277
  • [PM-34331] Update electron to 41 by @dani-garcia in #20448
  • [deps] Platform: Update webpack-dev-server to v5.2.5 [SECURITY] by @renovate[bot] in #21404
  • [PM-39351][PM-39353][PM-39369] Update Angular to 21.2.17 by @vleague2 in #21377
  • Update sdk-internal to 0.2.0-main.857 by @bw-ghapp[bot] in #21393
  • [deps] Vault: Update @koa/router to v15.6.0 by @renovate[bot] in #21114
  • [deps] Vault: Update https-proxy-agent to v9.1.0 by @renovate[bot] in #21408
  • Update sdk-internal to 0.2.0-main.859 by @bw-ghapp[bot] in #21475
  • [deps]: Update Rust crate pbkdf2 to v0.13.0 by @renovate[bot] in #20581
  • Address RUSTSEC-2026-0190 by @neuronull in #21558
  • [deps] Vault: Update form-data to v4.0.6 [SECURITY] by @renovate[bot] in #21279
  • [deps] Vault: Update multer to v2.2.0 [SECURITY] by @renovate[bot] in #21396
  • Bump client version(s) by @github-actions[bot] in #21644
  • Update sdk-internal to 0.2.0-main.870 by @bw-ghapp[bot] in #21482
  • Update sdk-internal to 0.2.0-main.872 by @bw-ghapp[bot] in #21651
  • [deps] Platform: Update Rust crate itertools to v0.15.0 by @renovate[bot] in #21674
  • [deps]: Update dtolnay/rust-toolchain digest to 4be7066 by @renovate[bot] in #21667
  • [deps] Platform: Update macOS/iOS bindings by @renovate[bot] in #20344
  • [deps]: Update codecov/codecov-action action to v7 by @renovate[bot] in #21409
  • [deps]: Update @napi-rs/cli to v3.7.2 by @renovate[bot] in #20121
  • [deps] Desktop Native: Update Rust crate mockall to v0.15.0 by @renovate[bot] in #21671
  • Update sdk-internal to 0.2.0-main.883 by @bw-ghapp[bot] in #21686
  • [PM-35903] Update clients to node 24 by @dani-garcia in #20400
  • chore(deps): move rand to KM Renovate ownership by @addisonbeck in #21719
  • [deps] UI Foundation: Update @storybook/test-runner to v0.24.4 by @renovate[bot] in #17854
  • Fix lockfile by @dani-garcia in #21763
  • [deps]: Update actions/cache action to v6 by @renovate[bot] in #21681
  • [deps] Platform: Update @types/node to v22.20.0 by @renovate[bot] in #21673

Other

  • Bump client version(s) by @github-actions[bot] in #21271
  • Auth/Add CLAUDE.md files to angular/src/auth and common/src/auth on file organization + barrel files by @JaredSnider-Bitwarden in #21283
  • [PM-39182] Migrate to relative imports - @bitwarden/team-platform-dev by @quexten in #21334
  • [PM-39182] Migrate to relative imports - @bitwarden/team-tools-dev by @quexten in #21326
  • [PM-39182] Migrate to relative imports - @bitwarden/team-autofill-dev by @quexten in #21332
  • [PM-39008] Do not show save new password inline menu over generate password menu if a new password has not been filled by @jprusik in #21244
  • Autosync Crowdin Translations for browser by @bw-ghapp[bot] in #21380
  • Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #21379
  • Disable self import rule by @quexten in #21410
  • Autosync Crowdin Translations for web by @bw-ghapp[bot] in #21381
  • Bump client version(s) by @github-actions[bot] in #21420
  • Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #21506
  • Autosync Crowdin Translations for browser by @bw-ghapp[bot] in #21507
  • Add claude snap permissions rule by @quexten in #21514