Skip to content

v1.0.9

Choose a tag to compare

@github-actions github-actions released this 06 May 23:43
· 7 commits to main since this release

Changelog

All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog,
and the project adheres to Semantic Versioning.

[1.0.9] — 2026-05-06

Closes the two SDK-side gaps the v1.0.8 retest flagged. v1.0.7
hardened the CLI's snapshot path; the Python SDK was never wired
to the same hardening, so adapters that called
processfork.snapshot_filesystem(..., env=dict(os.environ)) (every
adapter in adapters/) re-opened the same secret-leak the CLI
audit had closed, and the SDK's effects ledger was raw JSONL with
no HMAC chain even though the CLI's was.

Security: SDK env capture is no longer unsafe-by-default

  • processfork.snapshot_filesystem() now applies the same default
    scrub regex the CLI uses ((?i)(?:^|_)(token|secret|password| passwd|pwd|api_?key|apikey|auth|bearer)(?:_|$)) — env keys
    matching it are stored as "<redacted>". Operators who genuinely
    need the raw env (rare; CI debugging at most) opt out via
    default_scrub_env=False.
  • New scrub_env: Sequence[str] | None = None parameter for extra
    custom regex patterns, mirroring the CLI's --scrub-env flag.
  • All 5 first-party adapters (Claude Code, LangGraph, OpenInterpreter,
    AutoGen, CrewAI) inherit the safe default automatically — none of
    them ever passed default_scrub_env=False to start with.
  • Regression tests: test_default_scrub_redacts_secret_shaped_env
    asserts that OPENAI_API_KEY, GITHUB_TOKEN, DATABASE_PASSWORD,
    MY_API_KEY are redacted AND that the secret bytes do not appear
    anywhere in the serialized blob; test_default_scrub_can_be_disabled
    asserts the opt-out path still works for operators who need it.

ACRFence: SDK ledger is HMAC-chained for real

  • processfork.snapshot_filesystem(..., effects=[...]) now routes
    every entry through pf_effects::ledger::Ledger::append, computing
    per-entry session_hmac = HMAC(secret, prev_hash || this_hash) —
    the same code path the CLI's --effects-from-jsonl was switched
    to in v1.0.7. Prior versions stuffed the entries into a raw JSONL
    blob with no HMAC at all, so tamper / reorder / delete on the
    on-disk blob was undetectable.
  • A per-snapshot session secret is generated by default and embedded
    in the blob header (tamper-detection mode); operators who want full
    ACRFence supply PF_SESSION_SECRET=<hex> and the secret stays out
    of the blob.
  • pf verify already recognizes the embedded-secret format from
    v1.0.7 — SDK-produced blobs and CLI-produced blobs verify through
    the same code path now.
  • Regression test: test_effects_ledger_is_hmac_chained asserts
    the v1 header marker, the embedded session-secret-hex, and that
    every entry has a non-empty session_hmac ≥32 chars (catching
    the prior raw-JSONL session_hmac="" regression).

Versions

  • processfork (Rust + Python wheel): 1.0.8 → 1.0.9
  • All 8 internal pf-* crate version pins: → 1.0.9
  • npm @processfork/sdk: 1.0.8 → 1.0.9

Why this matters

The v1.0.8 audit retest passed 10 of 12 real-world cases but flagged
two genuine production blockers: (1) the SDK still leaked secret-shaped
env vars by default, and (2) SDK effects were raw JSONL not
HMAC-chained. Both are CLI-side fixes that hadn't been propagated
into pf-py. They are now propagated, with regression tests proving
both paths and confirmation that all 5 adapters inherit the safe
defaults.