v2.9.2 — a hostile filename, a cloud metadata address, and a redaction rule that would not work
Security release. Every item here is checkable on the copy you install.
A file name can no longer smuggle a command into the advice token-goat gives. Most hints end by naming a command to run instead of the one you typed, and that command is built by pasting the file's path into a quoted argument. A double quote is legal in a file name on Linux and macOS. Every suggestion is now checked on the way out, and anything whose quoting a path broke out of loses its command and keeps its sentence. What sits outside those quotes is matched against what token-goat itself writes, rather than against a list of dangerous characters, so redirection and substitution are covered along with command separators. File names carrying invisible characters — text-direction overrides, zero-width characters, line separators, the Unicode Tag block — are refused too.
Cloud metadata addresses are refused in every spelling. 169.254.169.254 written as an IPv6 address reaches the same service, and there are more ways to write it than a list can enumerate: IPv4-mapped, IPv4-compatible, both NAT64 prefixes, the RFC 2765 translated form and 6to4, which puts the address somewhere else entirely. The address is now parsed and the positions an IPv4 address can occupy are read. Amazon's instance-data names are refused as well.
Redaction rules of your own that would not work are refused loudly. redaction.custom_patterns takes your own expressions, for an in-house token prefix or an internal account number. A rule that matches the empty string, or whose running time doubles as the text grows, is refused and named by token-goat doctor rather than quietly matching nothing. That second check runs twice: once on the rule's shape, once by measuring how long it actually takes. The environment variable that carries these splits on line breaks, so EMP-[0-9]{4,8} arrives whole, and blank lines no longer count against the limit.
token-goat doctor says when the environment, not your config, is deciding a locked setting. A checked-in .token-goat.toml cannot change the settings governing fetching, redaction, Drive, injection fencing, read confinement or offline mode. An environment variable can, and a repository has ways to set one. A Security config overrides line names all fifteen locked settings the environment is currently deciding and the variable to unset. A default install prints one quiet ok.
The capability inventory covers more of its own surface. The test that reads token-goat's source for anything able to open a network connection now accepts every quote style, and covers WebSocket and EventSource alongside fetch.
Full detail, including each fix's stated limits: CHANGELOG and docs/security.md.
No reindex is needed.