v0.5.2
0.5.2 (2026-07-25)
Bug Fixes
- correct release-please output name for dispatch (#100) (9c1d75d)
- security: harden 7 audit findings — npm shim, logging, cross-DB authz (#102) (7649383)
Security clarification (added 2026-10-02)
The public hardening report identifies these security fixes in this release:
- F1: reject archive traversal, absolute paths and symlink/hardlink entries before npm-shim extraction.
- F2: require database access in the database-parameter validation used by discovery tools. This does not turn Restricted mode into a database-authorization boundary.
- F3: reject log-path traversal and linked final log targets.
- F5: verify cached binary SHA-256 against its sidecar before reuse. This is integrity verification, not independent publisher authentication.
- F6: redact malformed credential values completely and return redaction rather than raw input on regex timeout.
- F7: reject download redirects outside the allowed GitHub hosts.
See the public hardening report and fixing PR #102. The identifiers above are those actually listed in the historical report; they are not CVE assignments. The later linked-parent/rotation hardening in PR #150 is not part of this release.