Skip to content

Releases: interrupted-inc/murk

v0.10.2

Choose a tag to compare

@github-actions github-actions released this 04 Aug 00:22
v0.10.2
b0c086f

[0.10.2] - 2026-08-04

Other

  • build(deps): bump clap from 4.6.2 to 4.6.4
  • build(deps): bump clap_complete from 4.6.7 to 4.6.8
  • build(deps): bump schemars from 1.2.1 to 1.2.2
  • build(deps): bump pypa/gh-action-pypi-publish from 1.14.1 to 1.14.2
  • build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4
  • build(deps): bump base64 from 0.22.1 to 0.23.0
  • build(deps): bump rmcp from 2.2.0 to 3.0.0
  • chore: migrate repo and npm scope to interrupted-inc
  • ci: build aarch64-unknown-linux-musl target
  • ci: grant contents:read to npm publish job
  • ci: bootstrap npm publish with token for interrupted-inc scope
  • ci: make aarch64-musl cross-compile find zig reliably
  • chore: migrate repo and npm scope to interrupted-inc
  • chore: bump version to 0.10.2
  • chore: release 0.10.2

v0.10.1

Choose a tag to compare

@github-actions github-actions released this 29 Jul 13:52
v0.10.1
35c814b

[0.10.1] - 2026-07-29

Added

  • feat: add agent connect/disconnect to wire murk mcp into AI editors
  • feat: expand agent connect editor support

Documentation

  • docs: add brand guide, align assets to brand purple, and refine agent positioning

Fixed

  • fix: realign napi-derive with napi 3.11 to restore the Node build

Other

  • test: assert crypto invariants with property tests and add mutation testing
  • test: exercise agent connect/disconnect end-to-end
  • build(deps): bump serde_json from 1.0.150 to 1.0.151
  • build(deps): bump libc from 0.2.186 to 0.2.189
  • build(deps): bump the codeql-action group with 3 updates
  • build(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1
  • build(deps): bump tokio from 1.53.0 to 1.53.1
  • build(deps): bump serde from 1.0.228 to 1.0.229
  • build(deps): bump napi from 3.10.5 to 3.11.0
  • build(deps): bump actions/checkout from 7.0.0 to 7.0.1
  • build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0
  • build(deps): bump actions/setup-python from 6.3.0 to 7.0.0
  • chore: bump version to 0.10.1

v0.10.0

Choose a tag to compare

@github-actions github-actions released this 24 Jul 12:55
v0.10.0
dcc6984

[0.10.0] - 2026-07-24

Added

  • feat: enforce signature continuity and surface unanchored signatures

Documentation

  • docs: clarify the MAC's role and signing canonicalization
  • docs: add documentation site served at murk.interrupted.sh
  • docs: correct deprecated command surfaces and target label
  • docs: refresh site branding and humanize copy
  • docs: highlight murk column in comparison table
  • docs: round and tint inline code
  • docs: add robots.txt and pages security headers
  • docs: unbox inline code inside headings
  • docs: add social share image and Open Graph metadata
  • docs: add agent workflow demo tapes and gifs
  • docs: document the python and node library bindings
  • docs: separate the bindings API tables into labelled sections

Fixed

  • fix!: rename bindings identity check and add memory disclosure

Other

  • build: bump spin and anyhow to clear cargo-deny advisories
  • chore: track uv.lock
  • build(deps): bump napi-derive from 3.5.9 to 3.5.10
  • build(deps): bump napi from 3.10.3 to 3.10.5
  • build(deps): bump the codeql-action group with 3 updates
  • build(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2
  • build(deps): bump clap from 4.6.1 to 4.6.2
  • build(deps): bump age from 0.11.3 to 0.12.1
  • build(deps): bump EmbarkStudios/cargo-deny-action from 2.0.20 to 2.1.1
  • build(deps): bump tokio from 1.52.3 to 1.53.0
  • build(deps): bump actions/setup-node from 6.4.0 to 7.0.0
  • ci: deploy docs previews on pull requests
  • chore: ignore wrangler cache directory
  • ci: extend the docs demo pipeline and check guide examples
  • chore: keep local-only reference IDs out of committed files
  • chore: bump version to 0.10.0

v0.9.1

Choose a tag to compare

@github-actions github-actions released this 16 Jul 15:32
v0.9.1
a0b0c7c

[0.9.1] - 2026-07-16

Added

  • feat: warn when a restored phrase yields a non-recipient identity

Changed

  • refactor: reorganize CLI commands into a shared module

Documentation

  • docs: align security claims with actual behavior
  • docs: regenerate cli reference for restore --vault

Fixed

  • fix: build the python extension as an abi3 wheel
  • fix: prevent panic on adversarial recipient strings during merge
  • fix: hold the init-discovered key in a zeroizing wrapper
  • fix: interpolate the entry kind in scoped merge conflict messages

Other

  • chore: guard against release version drift
  • build(deps): bump astral-sh/setup-uv from 8.3.0 to 8.3.2
  • chore: generate the CLI reference and guard it against drift
  • build(deps): bump rmcp from 2.1.0 to 2.2.0
  • build(deps): bump ed25519-dalek from 2.2.0 to 3.0.0
  • build(deps): bump the codeql-action group with 3 updates
  • ci: verify the python wheel imports on 3.13
  • chore: release v0.9.1

v0.9.0

Choose a tag to compare

@github-actions github-actions released this 10 Jul 13:08
v0.9.0
62cca0b

[0.9.0] - 2026-07-10

Added

  • feat: default to strict access in agent contexts
  • feat: add operator self-scoping for the agent policy
  • feat: add murk agent init onboarding command
  • feat: add murk mcp stdio server subcommand
  • feat: implement murk_plan and murk_get mcp tools
  • feat: add murk_exec mcp tool behind --allow-exec

Documentation

  • docs: add release verification guide and pin PyPI attestations
  • docs: document the murk mcp server for agents
  • docs: document murk mcp in the command reference and threat model
  • docs: correct the pip install package name
  • docs: refresh roadmap with 1.0 readiness criteria

Fixed

  • fix: reject NUL byte in secret value before env injection

Other

  • chore: ignore local mnemopi banks directory
  • test: cover mcp server protocol edge cases
  • test: add mcp client interop and exec output-cap tests
  • chore: release v0.9.0

v0.8.0

Choose a tag to compare

@github-actions github-actions released this 07 Jul 02:32
v0.8.0
5a6df7c

[0.8.0] - 2026-07-07

Added

  • feat: sign vaults with ed25519 so tampering by a repo-writer is detectable
  • feat: add scriptable rotation listing

Fixed

  • fix and reorganize README command reference
  • fix: report not authorized instead of tamper warning for non-recipient keys

Other

  • build(deps): bump rust-lang/crates-io-auth-action from 1.0.4 to 1.0.5
  • build(deps): bump napi from 3.9.2 to 3.9.3
  • build(deps): bump softprops/action-gh-release from 3.0.0 to 3.0.1
  • build(deps): bump actions/checkout from 6.0.3 to 7.0.0
  • serialize VHS demo publish with a concurrency group
  • build(deps): bump napi from 3.9.3 to 3.9.4
  • build(deps): bump napi-derive from 3.5.6 to 3.5.7
  • build(deps): bump actions/attest-build-provenance from 4.1.0 to 4.1.1
  • gate full VHS rendering on tags, keep dress rehearsal on PRs
  • build(deps): bump actions/setup-python from 6.2.0 to 6.3.0
  • build(deps): bump napi-derive from 3.5.7 to 3.5.9
  • build(deps): bump github/codeql-action/upload-sarif
  • build(deps): bump clap_complete from 4.6.5 to 4.6.7
  • build(deps): bump github/codeql-action/init from 4.36.2 to 4.36.3
  • build(deps): bump napi from 3.9.4 to 3.10.3
  • build(deps): bump rand from 0.10.1 to 0.10.2
  • build(deps): bump docker/setup-qemu-action from 4.1.0 to 4.2.0
  • build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3
  • build(deps): bump codeql-action/init to 4.36.3 to match analyze
  • ci: group codeql-action updates so init and analyze bump together
  • build(deps): bump astral-sh/setup-uv from 8.2.0 to 8.3.0
  • build(deps): bump astral-sh/ruff-action from 4.0.0 to 4.1.0
  • ci: reuse the rehearsal release binary and cache the vhs image
  • chore: release v0.8.0
  • build(deps): bump crossbeam-epoch to 0.9.20 to clear a security advisory

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 19 Jun 01:14
v0.7.0
4ae9fbb

Vault format: 0.7.0 introduces integrity-MAC schemes v6–v9 (blake3v4:blake3v7:), added incrementally as you use recipient groups, agent grants, access policy, and post-revoke rotation tracking. A vault written by 0.7.0 that uses any of these features cannot be verified by murk 0.6.2 or earlier — upgrade all collaborators together. Vaults that use none of them stay byte-compatible with older murk. This is an expected pre-1.0 forward-incompatibility.

[0.7.0] - 2026-06-19

Added

  • add murk agent plan for schema-only agent context
  • add murk agent exec strict execution mode
  • add scan happy-path integration tests
  • add MSRV check to CI
  • feat: zeroize generated and prompted secrets in memory
  • feat: label added keys with their SSH type in TOFU pin-change diff
  • add per-secret rotation metadata and expiry checks
  • feat: add --rotate to circle revoke
  • feat: add MURK_STRICT to fail closed when edit can't stay in RAM
  • feat: refuse export/get to a file under MURK_STRICT
  • add per-secret recipient groups
  • add grants vault metadata and MAC v7 (blake3v5)
  • add agent grant/ls/revoke and fail-closed key discovery under MURK_STRICT
  • add agent access policy: tag allow-list in vault header (MAC v8), enforced on agent exec/grant

Changed

  • bump rand to 0.8.6 and js-yaml to 4.2.0 to clear vuln alerts
  • refactor: route murk init key discovery through env's single read path

Documentation

  • document missing commands and flags in SPEC.md and README, fix blake3v2 integrity description
  • document agent plan and agent exec in SPEC.md and README
  • document agent grants in SPEC and THREAT_MODEL
  • document agent grants in docs/ai-agents.md
  • docs: document git as the agent admin audit trail
  • docs: document binding policy enforcement in ai-agents

Fixed

  • fix: bump pyo3 to 0.29 for two python-binding security advisories
  • fix: run on a larger-stack thread to avoid clap stack overflow on Windows

Other

  • drop (MAC ok) from verify output, use ✦ for scoped edit update, document ✦ marker
  • collect resolve_secrets straight into BTreeMap, no intermediate plaintext map
  • ignore RUSTSEC-2026-0173 in deny.toml, build-time proc-macro only
  • test: sandbox integration tests in a temp HOME
  • test: require help text and coverage for every command
  • ci: run parser fuzz targets nightly
  • drop vault_name from agent plan output
  • preserve windows system env vars in exec --clean-env
  • show rotation and expiry in info
  • keep agent grant scoped copy in sync when a granted key is rotated
  • rename scoped secret tier to private (wire format unchanged)
  • accept # Recipient: header in age plugin identity files
  • expand YubiKey hardware-key walkthrough in README
  • enforce agent policy in python and node bindings
  • run murk via execFileSync in node tests, no shell
  • ci: smoke-test the install.sh path against a local fixture
  • test: enforce secret-handling invariants as source-level lints
  • flag secrets that still need rotating after a revoke
  • assert main's branch-protection baseline in release preflight
  • point preflight at PREFLIGHT_APP_* secrets
  • release v0.7.0

v0.6.2

Choose a tag to compare

@github-actions github-actions released this 03 May 18:38
v0.6.2
6482b12

[0.6.2] - 2026-05-03

Changed

  • bump version to 0.6.2

Fixed

  • fix clippy --all-targets lints and gate them in CI
  • fix windows test compile: keep win_body name and gate hardening tests

Other

  • harden release workflow with preflight checks
  • harden github key fetch: disable redirects, cap body, set timeout
  • disable core dumps at startup to prevent leaks of decrypted secrets
  • harden github key fetch: ignore proxy env vars
  • tighten workflow GITHUB_TOKEN permissions to contents:read

v0.6.1

Choose a tag to compare

@github-actions github-actions released this 27 Apr 02:13
v0.6.1
a763881

[0.6.1] - 2026-04-27

Changed

  • bump rustls-webpki to 0.103.13 for RUSTSEC advisory
  • bump version to 0.6.1

Fixed

  • fix node bindings for Zeroizing vault state

Other

  • zeroize decrypted secrets in memory
  • support age plugin identities for hardware-backed keys
  • disambiguate rand::random type for Windows build
  • zeroize plaintext in edit, import, and parse_env paths
  • align public docs with shipped behavior

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 21 Apr 02:54
v0.6.0
02da47b

[0.6.0] - 2026-04-21

Added

  • add doctor command for repo hygiene

Changed

  • bump rustls-webpki to 0.103.12 for RUSTSEC-2026-0098 and 0099
  • bump version to 0.6.0

Other

  • kill .env runtime fallback and route info through hardened loader
  • faster dev builds via unpacked debuginfo
  • turn verify into a real safety check
  • reject ssh-rsa recipients by default, add --allow-ssh-rsa override
  • exclude rust/cleartext-logging from codeql, false positive for a local cli