Skip to content

Releases: milocosmopolitan/redacton

Redacton 0.1.0

Choose a tag to compare

@milocosmopolitan milocosmopolitan released this 09 Oct 04:18
14fa4bf

Redacton 0.1.0 adds local terminal status and guided custom credential-format management: /redact:status, /redact:config, /redact:add-rule, and /redact:remove-rule.

Validate with the pinned Redact Secret engine, inspect actual synthetic preview outcomes, then explicitly Apply. Personal/project saving, project trust, portable transfer and revision-checked undo are separate actions. Built-in credential redaction and private-key blocking remain enabled.

Install using the two-command quick start. Current actual-host qualification is Claude Code/SDK 2.1.294, macOS ARM64 and Node 22.16.0. Both 140×40 and 80×40 terminal workflows passed. Node 24.21.0 passed unit/helper tests only.

The archive bundles the prebuilt helper and native/WASM dependencies; npm installation or compilation is unnecessary. Verify the archive with SHA256SUMS. RELEASE_MANIFEST.json binds the merged source and runtime fingerprints; QUALIFICATION.json records safe synthetic-only test results and exclusions. npm remains private and unpublished.

Original prompts and tool arguments can remain in host storage. Protection depends on the tested functioning host/outer-guard boundary; encoded credentials can be missed. Desktop, other OS/architecture host combinations and three independent users with seven-day follow-up remain unqualified. Existing-rule editing and names-group actions have unit/controller coverage; their actual terminal follow-up was not qualified. See compatibility.

Implemented in PR #53. The previous release tag and its evidence are preserved.

Redacton 0.1.0-alpha.1, experimental evaluation

Choose a tag to compare

@milocosmopolitan milocosmopolitan released this 09 Oct 01:39
98568b8

Redacton 0.1.0-alpha.1

Experimental local credential protection for supported Claude Code prompt text/context, Read text, and Bash stdout/stderr. /redacton requests ON with explicit readiness; /redactoff bypasses new operations and shows immediate and prompt-area warnings. Operations retain their captured state. Recognized private keys block the whole selected event.

Qualified host scope: Claude Code/SDK 2.1.294, macOS ARM64, Node 22.16.0. Node 24.21.0 passed the 25 helper/protocol/state/adapter tests separately; it does not qualify a Node 24 host. Linux, Windows, Desktop, other versions/architectures and interactive watch/reload are excluded.

Actual host evidence separates model payload, transcript/storage and terminal UI. ON prompt/Read/Bash markers were absent from supported model payloads. OFF scanning bypass, both policy races, strict protocol, 11 fault modes, actual automatic permission refusal, resumed/branched sessions, and SIGINT before/after helper dispatch are recorded. The normal terminal OFF warning remained after typing and actual core Bash activity. Companion probes are explicitly distinguished from the shipped product.

Limits: the host can bypass every failing guard; layered protection is conditional on the functioning host and outer guard. Original prompts and tool arguments can remain in host storage. Plaintext exists temporarily in memory; inherited process environment is not cleaned. The 29-case curated assessment has one base64 credential miss and is not production-accuracy proof. No production-readiness, all-tools, MCP, PII, vault/restore, live validation or telemetry claim is made.

Download redacton-alpha-1-evaluation.tar.gz with its accompanying SHA256SUMS and verify shasum -a 256 -c SHA256SUMS before extraction. Load the extracted plugin directory with claude --plugin-dir <directory>. It contains the prebuilt helper, exact pinned dependencies, project license and dependency notices; lifecycle-script compilation is unnecessary. Artifact-specific identifiers and clean-install evidence accompany the release.

Report vulnerabilities through private GitHub reporting. The maintainer conduct address and conflict-review policy are in CODE_OF_CONDUCT.md; address provenance does not guarantee response or confidentiality.

Three independent installations and seven-day follow-up remain a planned pilot. No simulated users, maintainer demonstrations, CI or downloads are counted as adoption.

Source: merged PR #15, commit 98568b84ac944baf33a3125d76fe25442bcf8036.

Archive SHA-256: d5882c7c4bb024b6565083d370bb607b74a4fb5130517b8d845d66f38c8272df. Final clean extraction/install and native/WASM validation passed; all 86 runtime/dependency files match the actual-host-qualified candidate. Details are attached in RELEASE_MANIFEST.json.