Releases: kerviaHerve/AG-VAULT
Release list
AG-VAULT v1.0.12
AG-VAULT v1.0.12 — 2026-09-22
- [strix vuln-0001, CWE-200, CVSS 5.3]
/setup/inforecon hardening:
once setup is done, the public endpoint returns only{"setup_done":true}—
the internal listen address and exact version are no longer disclosed
unauthenticated (they were only ever needed by the first-boot wizard).
Verified by a first autonomous pentest (Strix + DeepSeek V4 Pro) against
the production instance; 18 attack surfaces covered, 1 finding, fixed.
Install
sudo bash install.shThe installer verifies the sha256 checksum before installing.
Updates: webui → Settings → Version → Update now (self-update, data untouched).
Full history: CHANGELOG.md
AG-VAULT v1.0.11
AG-VAULT v1.0.11 — 2026-09-22
- Security audit (full code Sentinel pass). All surfaces reviewed —
auth chains, per-secret grant re-verification, crypto, webui, MCP,
installer, CI, dependencies (govulncheck/npm: clean). - Fix [audit trail]: the webui secret reveal now leaves a
read
trace in the append-only audit (SPEC: repudiation — every decrypted
read is an action; agents were audited, the admin reveal wasn't). - Fix [memory hygiene]: expired admin sessions are swept every hour
— the in-memory session map grew forever before (one leaked entry
per login on a long-lived process).
Install
sudo bash install.shThe installer verifies the sha256 checksum before installing.
Updates: webui → Settings → Version → Update now (self-update, data untouched).
Full history: CHANGELOG.md
AG-VAULT v1.0.10
AG-VAULT v1.0.10 — 2026-09-22
- Quick copy from the list. A copy button next to the eye on every
secret row (and in search results): copies the main credential
(token/password/key field for templated secrets, the value for
free-form) straight to the clipboard with a toast — no dialog needed.
Install
sudo bash install.shThe installer verifies the sha256 checksum before installing.
Updates: webui → Settings → Version → Update now (self-update, data untouched).
Full history: CHANGELOG.md
AG-VAULT v1.0.9
AG-VAULT v1.0.9 — 2026-09-22
- Eye toggle in edit fields. Editing a sensitive field (API token,
password, secret…) now shows a small eye in the input to reveal the
value while editing — both in the secret dialog and the create form.
Install
sudo bash install.shThe installer verifies the sha256 checksum before installing.
Updates: webui → Settings → Version → Update now (self-update, data untouched).
Full history: CHANGELOG.md
AG-VAULT v1.0.8
AG-VAULT v1.0.8 — 2026-09-22
- No JSON anywhere in the UI. Secret reveal and edit moved to a
proper dialog: labeled field cards (masked sensitive values, per-field
copy) and one input PER template field for editing — the client sends
{values: {field: value}}, the server validates against the template
and stores the new version. Free-form secrets edit in a plain textarea.
Install
sudo bash install.shThe installer verifies the sha256 checksum before installing.
Updates: webui → Settings → Version → Update now (self-update, data untouched).
Full history: CHANGELOG.md
AG-VAULT v1.0.7
AG-VAULT v1.0.7 — 2026-09-22
- WebUI: elegant secret reveal. Templated secrets now show a labeled
field card (the template's human labels — "API token", not "api_token"),
sensitive fields masked until clicked, per-field copy on hover, and a
discreet "copy raw JSON" for machine use. Free-form secrets unchanged.
Install
sudo bash install.shThe installer verifies the sha256 checksum before installing.
Updates: webui → Settings → Version → Update now (self-update, data untouched).
Full history: CHANGELOG.md
AG-VAULT v1.0.6
AG-VAULT v1.0.6 — 2026-09-22
- SECURITY: the generated skill never contains the API key anymore.
The wizard's SKILL.md used to embed the live key in 9 places (YAML,
stdio, curl, OpenCode CLI+jsonc, Hermes prompt). A key inside a stored/
logged/shared file is a burned key. Now:- the skill documents the connection (URLs, tools, rules) with
placeholders only (Bearer ${MCP_AG_VAULT_API_KEY}interpolation); - install is out-of-band: the agent asks the user for the key via the
client's masked prompt (hermes mcp add), or a user-owned 0600 file; - the key lives only in the one-time displayed screen + the .txt file
(with chmod 600 instructions), and the client's own store.
- the skill documents the connection (URLs, tools, rules) with
- Generated skill + wizard hint + key file: bilingual FR/EN.
- README/docs skill: interpolation-only examples (no
Bearer av_...).
Install
sudo bash install.shThe installer verifies the sha256 checksum before installing.
Updates: webui → Settings → Version → Update now (self-update, data untouched).
Full history: CHANGELOG.md
AG-VAULT v1.0.5
AG-VAULT v1.0.5 — 2026-09-22
- README: technical ASCII architecture diagram + release badge.
- Repo description/version kept in sync.
Install
sudo bash install.shThe installer verifies the sha256 checksum before installing.
Updates: webui → Settings → Version → Update now (self-update, data untouched).
Full history: CHANGELOG.md
AG-VAULT v1.0.4
AG-VAULT v1.0.4
Install (root)
curl -sfL https://github.com/kerviaHerve/AG-VAULT/releases/latest/download/agentvault-linux-$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/').tar.gz -o /tmp/av.tgzOr the full installer (wizard included):
bash install.shThe installer verifies the sha256 checksum before installing.
AG-VAULT v1.0.3
AG-VAULT v1.0.3
Install (root)
curl -sfL https://github.com/kerviaHerve/AG-VAULT/releases/latest/download/agentvault-linux-$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/').tar.gz -o /tmp/av.tgzOr the full installer (wizard included):
bash install.shThe installer verifies the sha256 checksum before installing.