safe-chains v0.227.0
Released 2026-08-16 · View on GitHub
- feat *(engine)* Make the
userlocus rung reachable, and shield what that exposes - feat *(regions)* Declare the credential dotfiles, then let home dotfiles be ordinary
- feat *(regions)* Shield /etc/ssh, where the host private keys live
- feat *(regions)* Classify raw devices and per-process /proc as what they are
- feat *(engine)* Open local reads to the machine rung
- feat *(regions)* Shield the decision log; correct the docs for the new read policy; v0.227.0
- fix *(engine)* Check unpinnability BEFORE the sentinel is rewritten away
- fix *(engine)* Correct the dotfile claim, and guard the sentinel fix that was untested
- fix *(engine)* Close the last four ways an unknowable read reached the shield uncleared
- fix *(regions)* Ten more credential dotfiles, and the measurement that questions the approach
- fix *(engine)* Bind find/fd -exec through the same stand-in the pipe uses
- fix *(engine)* Build dd's read from its path, so the shield is asked
- fix *(engine)* Fold macOS firmlinks, so /private/etc/shadow is /etc/shadow
- fix *(engine)* An unbounded read cannot be cleared by naming its root
- fix *(engine)* A glob and a glued placeholder name nothing the shield can check
- fix *(engine)* Two spellings that walked straight past the shield
- fix *(pathgate)* An ambiguously glued value is a guess, not a path
- fix *(engine)* One test for "the shield cannot clear this read", not two
- fix *(pathgate)* Gate the recursive copiers — rsync, ditto, pax
- fix *(engine)* Fold case on the firmlink prefix, for shields only
- fix *(cli)* A raw device is not a login-policy file, and say so
- fix *(test)* Two assertions that only held on macOS, caught by CI
- other *(design)* Write up relocation, and the locus a thing came FROM
- other *(engine)* Restate the read invariant as "the shield cannot clear it", not "it is outside the workspace"
- other *(policy)* Enforce the path corpus, which named a guard that never existed