Skip to content

v0.3.9 — Security hardening & apply-zip structure fixes

Choose a tag to compare

@akadeepesh akadeepesh released this 26 Aug 16:00
· 41 commits to main since this release

This release focuses on tightening secret handling and fixing a real
correctness bug in apply-zip. No breaking changes.

Security

  • Config file (~/.config/contextzip/config.json) permissions are now
    locked to 0600 on every write, not just creation — closes a gap
    where a pre-existing or loosely-created config file could stay
    group/world-readable and expose a plaintext Gemini API key.
  • The local config UI (contextzip config --ui) now compares its
    session token with hmac.compare_digest instead of ==, removing a
    timing side-channel.
  • Massively expanded the list of secret/credential files that are
    always excluded from packaged zips: SSH private keys, keystores
    (.jks, .keystore, .p12, .pkcs12, .ppk), CLI credential files
    (.npmrc, .netrc, .pypirc, .pgpass, .dockercfg), cloud
    provider credentials (.aws/credentials, service-account JSON,
    kubeconfig), and Terraform state (*.tfstate*, .terraform/).

Fixed

  • apply-zip now detects when an AI-returned zip has everything nested
    under one incidental wrapper folder (the shape produced by zip -r
    or GitHub's "Download ZIP") and strips it automatically when doing so
    clearly improves the match against your project's manifest.
  • apply-zip now warns — instead of silently proceeding — when a zip's
    structure barely matches the project at all.

Changed

  • .contextzip/inbox/applied/ now keeps only the most recently applied
    zip instead of growing indefinitely.

Full changelog: see CHANGELOG.md