Skip to content

v0.4.2 — Secrets stay out, workspace stays local

Choose a tag to compare

@akadeepesh akadeepesh released this 03 Sep 03:18
· 13 commits to main since this release

Added

  • Secret redaction, for real this time. limits.redact_secrets
    was persisted in config since 0.4.0 but never actually enforced.
    Now, text files going into the archive are scanned for
    secret-shaped values (API keys, tokens, private-key blocks, JWTs)
    and matches are replaced with [REDACTED] before zipping. Binary
    and oversized files are never scanned. Every redaction is called out
    in the terminal and itemized in the .report.txt file — nothing
    happens silently.

Changed

  • .contextzip/ is fully local by default now. config.json used
    to be the one file in the workspace that stayed trackable
    automatically. That exception is gone — the whole workspace is
    git-ignored with no carve-outs. If your team wants to share
    config.json, it's one explicit git add -f .contextzip/config.json
    away, same as it's always been for everything else in there.