Skip to content

v0.8.18

Choose a tag to compare

@github-actions github-actions released this 09 Oct 11:23
· 4 commits to main since this release

Patch release built with Go 1.26.9, which fixes the standard library advisories in net/http, crypto/tls, net/textproto and mime/multipart that every earlier release carried. A high-risk prompt, such as a shell command Claude Code asks about, is no longer masked as confidential, and a URL that does not parse no longer prints its credentials, a leak the move to Go 1.26 exposed.

Fixed

  • A high-risk prompt was displayed as a confidential one. The display mask covered every high-risk event, so a shell command Claude Code asks about showed the title "Confidential input required", a masked answer field and no command — the command had to be read in the terminal. Masking now covers only what is a secret: an event the adapter marked sensitive, or a credential prompt. A high-risk prompt keeps an honest label and takes a normal, visible answer, in the decision modal and in the TUI, whose notifications now carry the summary the prompt is shown with rather than the adapter's raw text. The decision modal also shows the last lines of the agent's output, redacted and cut; for a Claude Code shell command they are the terminal's raw text, escape sequences included. The command itself is still not in the prompt's summary, which for Claude Code is a constant: read it on the agent's card. A prompt whose text contains token, secret, password or otp, even inside a longer word such as footprint, is still marked sensitive and still masked. The audit journal is unchanged: a high-risk entry is still recorded sensitive, with the constant sensitive_event summary.

  • A URL that does not parse no longer prints its credentials. The redaction that every summary, notification and journal entry goes through returned a URL it could not parse unchanged. Go 1.25 parsed https://bot:secret@host:443:443/repo.git and masked its user and password; Go 1.26, which Relayer is now built with, refuses a host with an extra colon, so the password stayed in clear. The text up to the last @ of a URL that does not parse is now masked, whatever the URL would have meant.

Security

  • Relayer is built with Go 1.26.9. The Go standard library has advisories in net/http, crypto/tls, net/textproto and mime/multipart (GO-2026-6603, GO-2026-6607, GO-2026-6608, GO-2026-6613 and GO-2026-6617 among them; govulncheck reported at least seven) that are fixed in Go 1.26.9 and in Go 1.27.2. Go 1.27.0 and 1.27.1 are affected. The 1.25 series, which every release was built with (1.25.13 from v0.1.1-alpha to v0.8.17, 1.25.8 for v0.1.0-alpha), is no longer supported and gets no fix. The web gateway serves net/http, and the desktop's update check and the webhooks speak HTTP and TLS as clients. Building from source needs Go 1.26.9, or 1.27.2 or newer. Moving the go line to 1.26 also changes the defaults of three GODEBUG settings: TLS clients offer two more hybrid ML-KEM key exchange groups, and url.Parse refuses a host with an extra colon (see the fix above).

Full commit list: v0.8.17...v0.8.18