Skip to content

Releases: maximilianfeix/spillage

v0.6.9

Choose a tag to compare

@maximilianfeix maximilianfeix released this 28 Sep 14:17
0bf1e41

Fixed

  • a scan crashed when an old session had run in a folder that's now unreadable, or when the current folder had been deleted
  • project folders are found through the same Claude Code and Codex locations the scan uses, so CLAUDE_CONFIG_DIR next to ~/.claude and archived Codex sessions count too; the list is computed once instead of per source
  • SpecStory: the model's "Thought Process" blocks count as the model, not as tool output, and origins are looked up with an index instead of rescanning the file per match
  • the test suite no longer scans the real working directory

v0.6.8

Choose a tag to compare

@maximilianfeix maximilianfeix released this 28 Sep 13:53
8ef718c

Fixed

  • HTML report: a file path containing <!--<script could keep the data block from closing and leave a blank page; every <, > and & in the embedded data is escaped now
  • HTML report: one timestamp the browser can't parse broke the timeline and everything after it
  • HTML report: -f html -o crashed on file names with invalid UTF-8
  • HTML report: colors follow a light/dark switch while it's open, long lists don't wait seconds for their fade-in, and filtering toggles cards instead of rebuilding them on every keystroke
  • render(result, "html") works from Python without importing the CLI first, and the template loads from zipped installs too
  • a Codex session with "cwd": null no longer puts "null" into project names

v0.6.7

Choose a tag to compare

@maximilianfeix maximilianfeix released this 28 Sep 13:25
4c3a424

Fixed

  • the Sentry rule never matched (a typo in its pattern)
  • about 1 in 370 real private keys was dropped because its random body happened to contain a word like "todo"
  • AWS secret keys under names like AWSSecretAccessKey were only caught by the generic rule
  • Goose, Crush and Cursor databases in WAL mode: the newest messages, still in the -wal file, were invisible
  • a single JSONL file over 256 MB was skipped without a word; it's read in parts now, other oversized files are listed as skipped
  • when several rules see the same secret, the most specific one names it (an AWS key that's also in .env is an "AWS secret access key", critical)
  • custom rules passed to Scanner crashed a parallel scan
  • scanning a file in parts decoded invalid bytes differently from reading it whole, which changed fingerprints
  • line numbers are counted incrementally and each JSON line is parsed once, instead of once per hit

v0.6.6

Choose a tag to compare

@maximilianfeix maximilianfeix released this 28 Sep 12:56
4a02e25

Fixed

  • scrub could report success and leave a key on disk: files with Windows line endings (a multi-line key got a different fingerprint on the second read), files the key had vanished from since the scan, and symlinks (the link was replaced, the target kept the key). Scanning and scrubbing now read files through the same function, a file where nothing is found again is reported, and symlink targets are rewritten
  • a single invalid UTF-8 byte made a whole file unscrubbable; bytes are now kept exactly as they were
  • a file that changes while being scrubbed is left alone instead of losing what was appended
  • secrets inside Claude's signed thinking blocks are left alone and reported: editing them breaks --resume of that session
  • the JSON check could miss a broken line that contains U+2028
  • Ctrl-D at the scrub prompt means no instead of a traceback

v0.6.5

Choose a tag to compare

@maximilianfeix maximilianfeix released this 28 Sep 12:25
f5fe345

Fixed

  • guard status only checks the agents installed on the machine, so it no longer fails because Codex or Gemini aren't there
  • Gemini settings.json with comments no longer blocks guard install (a backup keeps the original)
  • one agent with a broken config no longer stops guard install for the others
  • more ways to read secrets are blocked: Gemini's read_many_files with include, MCP filesystem read tools (now also sent to the hook by Claude Code's matcher), and shell argv like bash -l -c …, /usr/bin/env bash -c …
  • --scope local for Codex and Gemini used to write into the shared project config; it's refused now, since only Claude Code has a local-only file

v0.6.4

Choose a tag to compare

@maximilianfeix maximilianfeix released this 28 Sep 11:50
b7a6c00

Fixed

  • an empty value in a .env file (API_KEY=) crashed scan, scrub and watch. A .env file that can't be parsed is now skipped instead of stopping anything

v0.6.3

Choose a tag to compare

@maximilianfeix maximilianfeix released this 28 Sep 11:32
53db9e9

Fixed

  • watch reported keys that were already in JSON, Markdown and SQLite logs whenever those files changed. It now takes a baseline at startup and only reports what's new since then
  • watch --scrub missed a known key showing up in a second file, and replaced files with a rename, which could cut off an agent that still had the file open (Codex keeps its rollout file open). Files are now rewritten in place
  • watch no longer reads half a line when it starts in the middle of a write, notices in-place rewrites that make a file longer, survives files vanishing or being locked, and doesn't re-list every log folder every 2 seconds or read every log at startup

v0.6.2

Choose a tag to compare

@maximilianfeix maximilianfeix released this 28 Sep 10:53
7a29239

Fixed

  • spillage repo and the pre-commit hooks now use one list of transcript patterns (a test keeps .pre-commit-hooks.yaml in sync), matched on path segments: data/rollout-metrics.jsonl or docs/cline_task_template.md no longer count as transcripts, nested .claude/ and .codex/ logs and Cline exports do
  • GitHub annotations point at the right file when the Action's path is a subfolder; with all-files a source file isn't called a transcript anymore
  • the Action scans once instead of twice and can't lose its exit code
  • git errors say what git said (e.g. "dubious ownership") instead of "isn't a git repository"
  • --files outside the repository are ignored; --strict says why it failed

Added

  • .spillageignore in a repository: fingerprints to ignore there, also in CI

v0.6.1

Choose a tag to compare

@maximilianfeix maximilianfeix released this 28 Sep 10:23
01426c1

Fixed

  • .env values: variable names are matched by whole words now (AUTHOR_NAME and NEXTAUTH_URL were treated as secrets), public keys (NEXT_PUBLIC_…, …_PUBLISHABLE_…) and plain URLs are skipped, quoted values with a trailing comment lose their quotes, multi-line values are left out instead of matching their first line
  • a value ending in a backslash could be redacted into broken JSON; the escaped form is matched first now
  • all values are found in one pass instead of one pass per value, and the list reaches worker processes once instead of with every file
  • env-value works with --rules / --skip-rules and shows up in spillage rules; watch has --no-env
  • the guard's session-end scrub also removes values from the project's .env

v0.6.0

Choose a tag to compare

@maximilianfeix maximilianfeix released this 28 Sep 09:50
3185b07

Added

  • Your own secrets: the values in your projects' .env files are looked up verbatim in the logs, raw and JSON-escaped, which catches passwords and keys no pattern could. Reported by variable name and file, never by value. --no-env turns it off