BleachBit 6.0.4 is a maintenance release
- Massive security, bug fix, and code cleanup
- Improve startup speed and scanning speed
- Add cleaners for Android Studio, Gradle Cache, fish, Zsh shell, and Python command line
- Improve cleaners for Claude and browser supercookies
- Shrink the Windows installer and installation footprint
- Add early support for macOS: new Safari cleaner, compatibility with existing cleaners (such as Google Chrome and Firefox), full CLI support, and early GUI support
Changes since version 6.0.2
All Platforms
This release makes BleachBit faster, safer, and more reliable, with new cleaners for Python, Claude Android Studio, and Gradle; improved cleaning for Claude and browser data; and fixes for crashes, data-loss risks, and startup issues.
Windows
Access to the application menu moved from the application icon on left side to hamburger menu on right side. Windows users get faster and more reliable cleaning, corrected secure wiping, improved network-path and notification support, stronger security protections, a smaller installer, and a smaller installed footprint.
- Move the menu from application icon on left side to hamburger on right side (now consistent with Linux)
- Use absolute paths for ipconfig and taskkill to prevent binary-planting attack via executable search path
- Fix secure file wiping skipping some clusters that should have been overwritten
- Fix secure file wiping not fully overwriting fragmented files
- Migrate Windows CI builds from ci.bleachbit.org to download.bleachbit.org/ci/ to consolidate on one subdomain. The new Windows CI download page has many enhancements such as filtering by branch and one-click to copy checksums.
- Fix failure to start application from UNC (network) paths
- Preserve the root of folders for temporary files
- Fix: toast notification was broken
- Fix cleaning of folder shortcuts (junctions) and directory symlinks being skipped when the target folder contained files
- Fix pathnames in amule, Adobe Flash, Vuze, VLC, so they clean more files
- Fix: crash reports were not found in Pale Moon on Windows
- Fixed winapp2.ini ExcludeKey with the . pattern, which should exclude the whole folder but was not working. The normal Winapp2.ini file does not contain this pattern, so the bug does not normally affect users.
- Update framework, including new versions of Python and GTK. Reduce the size of GTK by disabling unused code.
- When cleaning system.tmp, preserve new GLib D-Bus nonce files to not allow multiple instances of the application to be open.
- Improve speed of importing Winapp2.ini cleaners
- Speed up the keep list (whitelist) by avoiding repeated lookups of the Windows temporary directory
- Call match directly on precompiled winapp2 regexes
- Remember the Windows version to avoid repeated lookups
- Hoist loop invariants in winapp2.ini parsing
- Skip the unused world-writable stat on Windows
- Improve efficiency in detecting file encoding
- Handle interrupted console output
- Refuse wiping a file through symlink for security
- Remove 89 icon and theme files, reducing the size of the Windows installer by 56 KB.
- Shrink .svg files using SVGO
- Clean Windows clipboard in TUI or wx GUI without requiring GTK
- Write the GTK error report to a unique temporary file
- Skip unknown winapp2 options instead of aborting the section
- Ensure that file wiping releases system resources in case of error
- Cap the wildcard count in winapp2.ini glob patterns for ReDoS (regex denial-of-service) defense
- Use subprocess.list2cmdline for UAC argument encoding
- Reject all insecure winapp2 and update-check URLs
- Harden Windows DLL search path against preloading attacks
- Fix missing icon in preferences dialog
- Use Python's native isjunction function
- Detect encoding for Winapp2.ini (not needed for automatic downloads)
- Soften the error about potential permission issue with configuration file
- Fix: do not shown an error message when the SID owning the configuration file cannot be resolved to an account name
Developers
This update modernizes the CI/CD pipeline by migrating Windows builds and testing from AppVeyor to GitHub Actions (where we already tested Linux). This release adds security scanning. It also improves code security and maintainability through refactoring, cleanup, stronger tests, and removal of legacy code.
Translations
- 60 languages were updated with 790 changes.
- The most active languages were Català (145), Svenska (105), and Қазақ тілі (24).
- This release drops 12 translations that were stale and nearly empty