Release Notes
Fixed
- The
--provider CLI flag now correctly takes precedence over the
SECRETSPEC_PROVIDER environment variable. Previously the env var was
consulted before the value forwarded from --provider (via set_provider),
so users could not temporarily override the provider on the command line
while the env var was set. Fixes
#77.
- Per-secret
providers = [...] chains now behave as a true fallback chain
when an upstream provider errors (e.g. a 403 from a vault the current user
cannot access). Previously the first provider's error short-circuited the
whole operation; now the error is logged as a warning and the next provider
in the chain is tried. The original error is only surfaced if every
provider in the chain failed (so genuine outages still bubble up), or if
the secret has no alternative to fall back to. Fixes
#83.
secretspec run now removes the temporary files it creates for
as_path = true secrets after the child process exits. Previously the
files were leaked under /tmp because std::process::exit skipped the
destructors that own them. Fixes
#71.
- Provider URIs now support spaces and special characters in names
(e.g., onepassword://Home Lab). All providers receive automatically
percent-decoded values via a new ProviderUrl wrapper type.
- dotenv provider: setting a secret no longer corrupts neighboring values
that contain double quotes, backslashes, dollar signs, or newlines
(e.g. JSON values). The underlying serde-envfile serializer did not
escape these characters; fix is pinned via a fork until
lucagoslar/serde-envfile#6
lands upstream. Fixes #74.
--provider (and SECRETSPEC_PROVIDER) is now honored on every command
even when a providers = [...] chain is configured for the secret or
profile. Previously set, get, check, import, and run silently
used the first provider in the chain and ignored the explicit override,
making secretspec set --provider <alias> a no-op against the requested
target. The flag now consistently takes precedence: set/import/
generation write only to the chosen provider, and get/validate read
only from it (no chain fallback). Provider aliases declared in
~/.config/secretspec/config.toml can now be passed directly to
--provider. Fixes #81.
Added
- BWS (Bitwarden Secrets Manager) provider with async SDK integration, secret caching, and full read-write support (requires
--features bws)
Changed
secretspec-derive now depends on secretspec with default-features = false, avoiding pulling in CLI and provider features when only the derive macro is used.
Install secretspec 0.9.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/cachix/secretspec/releases/download/v0.9.0/secretspec-installer.sh | sh
Download secretspec 0.9.0