Security hardening release after repository security scan and targeted pentest.
Fixes:
- Reject restore targets that are symlinks, hardlinks, non-regular files, or path escapes before applying a snapshot.
- Always push vault commits explicitly to origin HEAD:main instead of any existing branch upstream.
- Redact GitHub fine-grained PAT values and pat-style keys in config.toml snapshots.
- Block top-level obvious secret filenames such as .env, token.txt, secret.txt, and password.txt even in risky/full mode.
- Install from pinned release tag v0.1.7 by default and support optional SHA256 archive verification.
Security validation included pytest, ruff, bandit, pip-audit, installer dry-run, direct redaction/blocklist harnesses, Windows hardlink restore harness, plugin validation, and Codex Security report generation.