Skip to content

v0.10.0

Choose a tag to compare

@github-actions github-actions released this 23 Jul 21:45
· 112 commits to master since this release
2d11c1a

Added

  • Standalone MCP mode — run truecopy-mcp with no downstream command and it
    serves two read-only tools of its own, truecopy-verify and truecopy-status,
    instead of exiting. The container image now runs standalone by default (no more
    wrapping @modelcontextprotocol/server-everything just to have something to
    advertise), pre-loaded with the repo's own self-dogfood lock — so an MCP
    directory that introspects the image now grades truecopy's own tools.
  • Per-finding evidence — scan results carry an evidence array
    ({ flag, text, file, line }) pointing at the exact matched fragment, located
    by the detector's own match offset rather than a re-search of the text (more
    reliable: a re-search can land on the wrong occurrence of a short match, or
    mistake a JSON escape or a name-field hit for the real one). Surfaced in
    --json; purely additive.
  • Per-flag acceptance granularity for the watch (#87) — an accept entry can
    name the specific files and flags a human reviewed, rather than the whole
    skill; a new flag, or a reviewed file disappearing, still fails closed, and
    entries carry a mandatory 90-day expiry.
  • Publish-time confabulation self-check in the marketplace watch — every
    published match is re-verified against the pinned source bytes before
    publishing; anything that can't be located is dropped, never published.

Changed

  • Bumped the @askalf/redstamp pin — case-sensitive SECRET_ENV_RE (stops
    flagging ordinary lowercase locals as credentials) and a widened
    base64-to-shell detector (closes 7 of 12 evasive spellings).

Security

  • Docker image hardened — base image pinned by digest, dependency tree
    installed from a hash-pinned lockfile, drops root, and moved off a vulnerable
    @hono/node-server transitive (GHSA-frvp-7c67-39w9).