v0.3.9 — Security hardening & apply-zip structure fixes
This release focuses on tightening secret handling and fixing a real
correctness bug in apply-zip. No breaking changes.
Security
- Config file (
~/.config/contextzip/config.json) permissions are now
locked to0600on every write, not just creation — closes a gap
where a pre-existing or loosely-created config file could stay
group/world-readable and expose a plaintext Gemini API key. - The local config UI (
contextzip config --ui) now compares its
session token withhmac.compare_digestinstead of==, removing a
timing side-channel. - Massively expanded the list of secret/credential files that are
always excluded from packaged zips: SSH private keys, keystores
(.jks,.keystore,.p12,.pkcs12,.ppk), CLI credential files
(.npmrc,.netrc,.pypirc,.pgpass,.dockercfg), cloud
provider credentials (.aws/credentials, service-account JSON,
kubeconfig), and Terraform state (*.tfstate*,.terraform/).
Fixed
apply-zipnow detects when an AI-returned zip has everything nested
under one incidental wrapper folder (the shape produced byzip -r
or GitHub's "Download ZIP") and strips it automatically when doing so
clearly improves the match against your project's manifest.apply-zipnow warns — instead of silently proceeding — when a zip's
structure barely matches the project at all.
Changed
.contextzip/inbox/applied/now keeps only the most recently applied
zip instead of growing indefinitely.
Full changelog: see CHANGELOG.md