Skip to content

KeyringSeam v0.2.0-rc.1

Pre-release
Pre-release

Choose a tag to compare

@fieldnote-ops fieldnote-ops released this 15 Aug 14:57

KeyringSeam 0.2.0-rc.1

This public release candidate replaces the legacy file-Keychain helper with a notarized macOS Broker app for Agent-isolated credential access.

Verified before publication:

  • Developer ID Application + Hardened Runtime + secure timestamp
  • Apple notarization accepted and stapled (8941cae5-75a5-4f1c-bdfb-998d1ce578c3)
  • Universal arm64 + x86_64 Broker, including quarantined launch checks
  • Private Data Protection Keychain access group with explicit user authentication for get, set, and unset
  • Independent same-UID reader: errSecMissingEntitlement (-34018); /usr/bin/security: item not found
  • DSH 0.1.0-rc.6 isolated consumer: plugin add, composed profile replacement, Web HTTP 200, and fail-closed bash-tool attempt
  • GitHub Actions self-test green across Node 22/24, DSH 0.1.0-rc.6, latest, next, and committed signature checks
  • macOS 14 provisioning-profile parser compatibility fix included
  • Documentation and legacy helper script cleanup included in the refreshed RC
  • Frozen candidate archive SHA-256: 7b4c9aef5f0bb5cbb111a9388e11bb95433cd74f4bd3e860316290e2cef1882f

The published v0.1.3 tag remains the legacy storage-only release. This RC supports macOS 13 or newer and is not an independent security audit or a claim about compromised hosts, administrators, debuggers, or users approving unexpected prompts. The 3-machine/24-hour external acceptance round is intentionally deferred.