v0.9.0 — shadow mode + usage heartbeat
Added
shadowmode: a fourth preset posture for pure observation — every severity band flags/logs and nothing ever blocks or sanitizes, including via theblock_thresholdfloor (a threshold of 1.0 now disables the floor). This is the true canary/rollout posture:permissivestill blocks critical-severity payloads by design (unchanged), which bit real gateway deployments when benign-but-credential-shaped context scored ≥ 0.85. Use--mode shadowonserve/proxy/dashboard for measure-first rollouts.- Opt-in usage heartbeat: when
SHADOWSHIELD_HEARTBEAT=1andSHADOWSHIELD_HEARTBEAT_URLare both set,servesends one anonymous packet per 24h —{anon_install_id, version, num_services_seen, ts}and nothing else (no hostnames, IPs, keys, or payloads). Default is fully off; state lives in~/.shadowshield/heartbeat.json; fail-open on any error.
Install: pip install -U shadowshield · Full changelog: https://github.com/0xsl1m/shadowshield/blob/main/CHANGELOG.md