Repository navigation
v1.0.9
Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog,
and the project adheres to Semantic Versioning.
[1.0.9] — 2026-05-06
Closes the two SDK-side gaps the v1.0.8 retest flagged. v1.0.7
hardened the CLI's snapshot path; the Python SDK was never wired
to the same hardening, so adapters that called
processfork.snapshot_filesystem(..., env=dict(os.environ)) (every
adapter in adapters/) re-opened the same secret-leak the CLI
audit had closed, and the SDK's effects ledger was raw JSONL with
no HMAC chain even though the CLI's was.
Security: SDK env capture is no longer unsafe-by-default
processfork.snapshot_filesystem()now applies the same default
scrub regex the CLI uses ((?i)(?:^|_)(token|secret|password| passwd|pwd|api_?key|apikey|auth|bearer)(?:_|$)) — env keys
matching it are stored as"<redacted>". Operators who genuinely
need the raw env (rare; CI debugging at most) opt out via
default_scrub_env=False.- New
scrub_env: Sequence[str] | None = Noneparameter for extra
custom regex patterns, mirroring the CLI's--scrub-envflag. - All 5 first-party adapters (Claude Code, LangGraph, OpenInterpreter,
AutoGen, CrewAI) inherit the safe default automatically — none of
them ever passeddefault_scrub_env=Falseto start with. - Regression tests:
test_default_scrub_redacts_secret_shaped_env
asserts thatOPENAI_API_KEY,GITHUB_TOKEN,DATABASE_PASSWORD,
MY_API_KEYare redacted AND that the secret bytes do not appear
anywhere in the serialized blob;test_default_scrub_can_be_disabled
asserts the opt-out path still works for operators who need it.
ACRFence: SDK ledger is HMAC-chained for real
processfork.snapshot_filesystem(..., effects=[...])now routes
every entry throughpf_effects::ledger::Ledger::append, computing
per-entrysession_hmac = HMAC(secret, prev_hash || this_hash)—
the same code path the CLI's--effects-from-jsonlwas switched
to in v1.0.7. Prior versions stuffed the entries into a raw JSONL
blob with no HMAC at all, so tamper / reorder / delete on the
on-disk blob was undetectable.- A per-snapshot session secret is generated by default and embedded
in the blob header (tamper-detection mode); operators who want full
ACRFence supplyPF_SESSION_SECRET=<hex>and the secret stays out
of the blob. pf verifyalready recognizes the embedded-secret format from
v1.0.7 — SDK-produced blobs and CLI-produced blobs verify through
the same code path now.- Regression test:
test_effects_ledger_is_hmac_chainedasserts
the v1 header marker, the embedded session-secret-hex, and that
every entry has a non-emptysession_hmac≥32 chars (catching
the prior raw-JSONLsession_hmac=""regression).
Versions
processfork(Rust + Python wheel): 1.0.8 → 1.0.9- All 8 internal
pf-*crate version pins: → 1.0.9 - npm
@processfork/sdk: 1.0.8 → 1.0.9
Why this matters
The v1.0.8 audit retest passed 10 of 12 real-world cases but flagged
two genuine production blockers: (1) the SDK still leaked secret-shaped
env vars by default, and (2) SDK effects were raw JSONL not
HMAC-chained. Both are CLI-side fixes that hadn't been propagated
into pf-py. They are now propagated, with regression tests proving
both paths and confirmation that all 5 adapters inherit the safe
defaults.