Releases: fieldnote-ops/keyringseam
Release list
KeyringSeam v0.2.0-rc.1
KeyringSeam 0.2.0-rc.1
This public release candidate replaces the legacy file-Keychain helper with a notarized macOS Broker app for Agent-isolated credential access.
Verified before publication:
- Developer ID Application + Hardened Runtime + secure timestamp
- Apple notarization accepted and stapled (
8941cae5-75a5-4f1c-bdfb-998d1ce578c3) - Universal
arm64+x86_64Broker, including quarantined launch checks - Private Data Protection Keychain access group with explicit user authentication for
get,set, andunset - Independent same-UID reader:
errSecMissingEntitlement (-34018);/usr/bin/security: item not found - DSH
0.1.0-rc.6isolated consumer: plugin add, composed profile replacement, Web HTTP 200, and fail-closed bash-tool attempt - GitHub Actions self-test green across Node 22/24, DSH
0.1.0-rc.6, latest, next, and committed signature checks - macOS 14 provisioning-profile parser compatibility fix included
- Documentation and legacy helper script cleanup included in the refreshed RC
- Frozen candidate archive SHA-256:
7b4c9aef5f0bb5cbb111a9388e11bb95433cd74f4bd3e860316290e2cef1882f
The published v0.1.3 tag remains the legacy storage-only release. This RC supports macOS 13 or newer and is not an independent security audit or a claim about compromised hosts, administrators, debuggers, or users approving unexpected prompts. The 3-machine/24-hour external acceptance round is intentionally deferred.
KeyringSeam v0.1.3 — macOS universal binary
KeyringSeam v0.1.3 — macOS universal binary
KeyringSeam is an independently maintained, macOS-only credential provider for DeepSeek Harness. It replaces the local-file credential provider and stores model credentials in the user's macOS Keychain.
Runtime
- macOS 13 or newer
- Apple Silicon and Intel (
arm64+x86_64) - No runtime dependency on Swift, Xcode, Apple command-line developer tools, or
/usr/bin/security - The helper directly calls Apple's Security framework
Verification
- Release archive SHA-256:
413590a43bb586a1fea9ae4d3811a3b69a15ded880ea9cf46bdc338867460aed - Helper SHA-256:
aa4dbe466baee0e87259b038825765b7e8109497ff76212f57a328e47bca69fc - Developer ID Application signature, Hardened Runtime, and secure timestamp
- Team ID:
TU8DF2JWHF - Apple notarization: Accepted
- Notarization submission:
4a707bd7-4d84-4310-acf1-71d37c3dcebb - Clean-profile DeepSeek Harness replacement boot and disposable Keychain lifecycle passed before publication
Install from the immutable, previously verified source commit:
dsh plugin --profile web add github:fieldnote-ops/keyringseam#15b33d29796cfb2417f9cb8cca940c805f5fc9f6Review the generated profile diff before using real credentials. KeyringSeam intentionally replaces the credentials bundle row.
Evidence boundaries
The Apple notarization result is not an independent security review. Independent-user adoption, non-macOS backends, purchase validation, and income are not claimed.
KeyringSeam is not affiliated with, sponsored by, or endorsed by DeepSeek or Apple. DeepSeek Harness, macOS, Apple, and Keychain are used only to identify compatibility with their respective software and services.