DataFog Core 0.4.1 adds three default credential detectors across Rust, Python, Node.js, and browser WASM:
API_KEY: documented GitHub token formats and Stripe secret/restricted keys.BEARER_TOKEN: explicit Authorization headers, quoted JSON headers, and immediate structured Authorization fields; findings cover the token only.CREDENTIAL_URI: scoped password-bearing PostgreSQL connection URIs; findings cover the complete original URI.
Rust and Python capabilities now report 23 supported entities and 14 default text detectors. Capability contract version 1, public binding signatures, finding schemas, exceptions, and original-input byte/code-point/UTF-16 offsets remain unchanged. German detectors and UUID retain their existing opt-in activation. Detection is lexical; no provider authentication or network checks occur.
Packages:
The DataFog Python 4.9 capability adapter consumes these labels without a duplicate inventory update. Its default backend remains unchanged. Legacy overlap resolution still runs before label filtering: API_KEY can suppress a same-span BEARER_TOKEN, BEARER_TOKEN can suppress JWT, and a containing CREDENTIAL_URI can suppress an inner key/JWT. Native datafog.v5 retains the candidates and supports selecting an individual label before transformation overlap resolution.
Validation includes Rust formatting, strict Clippy and all-feature workspace tests; installed Python 3.10–3.14 and source-distribution rebuild; installed Node and real Chromium WASM; Mintlify content/anchors; 352 Python 4.9 adapter/compatibility tests, 10 credential-overlap fixtures and 60 native transformations against the exact candidate. Clean registry installations were verified after publication.
Release source: 175e67548f654c740352a7d909ae55d376dfcb0d. Implementation and candidate PRs: #33, #34, #35, #36. Detailed scopes and integration evidence.