Skip to content

cmcp 0.5.0

Choose a tag to compare

@imran-siddique imran-siddique released this 06 Sep 16:47
· 101 commits to main since this release
d03b9af

Security release. Full detail in CHANGELOG.md.

The one to read first

Cross-boundary compliance recording was dead for HIPAA PHI, PCI data and MNPI.

call_log._HIGH_SENSITIVITY_DOMAINS decides whether a call leaving a domain is recorded as a boundary crossing in the TRACE claim. It was the literal {"pii", "phi", "pci", "restricted"}, while the catalog schema permitted {hipaa_phi, pci_data, mnpi, pii, internal, external, public}.

The two sets overlapped on pii alone. phi, pci and restricted could never appear as a compliance_domain, and the three most regulated domains the field exists to express never matched anything. A session that read HIPAA PHI and then called an external tool recorded no crossing.

The set is now derived from a single COMPLIANCE_DOMAINS vocabulary. Legacy spellings stay in it, so no deployment loses an event.

Also fixed

  • Policy bundle hash now uses RFC 8785 (GHSA-wh6r-6j4v-p4p6), as docs/spec/cedar-policy.md §1 always specified.
  • cert-pinned rotation mode is reachable. The schema's additionalProperties: false rejected the very field the docs told operators to set, so every deployment ran the weaker key-pinned default with no way to opt out.
  • compliance_domain is deployment extensible, mirroring sensitivity_level.
  • Credential redaction is deny-by-default. It covered only Authorization, while the same request carries OPAQUE_API_KEY.
  • Least-privilege CI. All 24 action references pin a commit SHA, four workflows gained a permissions: floor, four ${{ }} interpolations left run: blocks.

Upgrading

Two changes you may see:

  • Policy bundles carrying non-ASCII text or float-typed numbers change hash and need re-pinning. ASCII-only bundles are byte-identical, which is the common case. A mismatch fails at startup with both values named.
  • Catalogs may now use deployment-declared compliance domains via sensitivity.compliance_domains in config. Existing catalogs are unaffected.