Skip to content

v0.9.0 — shadow mode + usage heartbeat

Choose a tag to compare

@0xsl1m 0xsl1m released this 18 Aug 05:11
· 27 commits to main since this release
6078804

Added

  • shadow mode: a fourth preset posture for pure observation — every severity band flags/logs and nothing ever blocks or sanitizes, including via the block_threshold floor (a threshold of 1.0 now disables the floor). This is the true canary/rollout posture: permissive still blocks critical-severity payloads by design (unchanged), which bit real gateway deployments when benign-but-credential-shaped context scored ≥ 0.85. Use --mode shadow on serve/proxy/dashboard for measure-first rollouts.
  • Opt-in usage heartbeat: when SHADOWSHIELD_HEARTBEAT=1 and SHADOWSHIELD_HEARTBEAT_URL are both set, serve sends one anonymous packet per 24h — {anon_install_id, version, num_services_seen, ts} and nothing else (no hostnames, IPs, keys, or payloads). Default is fully off; state lives in ~/.shadowshield/heartbeat.json; fail-open on any error.

Install: pip install -U shadowshield · Full changelog: https://github.com/0xsl1m/shadowshield/blob/main/CHANGELOG.md