v0.7.0 — Developer Workflow Integration (Git Pre-Push Hook, Filesystem Watcher, IDE JSON)
🚀 What's New in v0.7.0
- Production Git Pre-Push Hook (envguard pre-push & envguard install-hook --type pre-push)
A dedicated gate before outgoing commits reach remote branches:
Full Git Protocol Compliance: Intercepts Git's stdin stream ( ) across single, multiple, or tag pushes.
Deep Commit Range Resolution: Automatically calculates rev-list remote_sha..local_sha for updates, --not --remotes for new branches, and cleanly handles branch deletions (0000... or (delete)).
True Git Object Inspection: Scans files across outgoing commits directly from Git objects using git diff-tree and git show :, catching intermediate leaks in commit chains even if undone in subsequent commits.
Injection Defense in Depth: Strictly rejects ref names, SHAs, or remote arguments beginning with - or containing null bytes, and terminates commands with --.
One-Step Installation:
bash
envguard install-hook --type pre-push
2. Zero-Dependency Filesystem Watch Mode (envguard watch [PATH])
Continuous monitoring detects secrets the moment files are saved to disk — right from your terminal:
100% Python Standard Library: Implemented using native os.scandir and filesystem mtime_ns / size caching with zero third-party dependencies (no watchdog).
Debounced Event Processing: Configurable debounce interval (default 0.3s) batches rapid file saves, preventing scan storms and duplicate alerts.
Intelligent Pruning: Automatically prunes .git, node_modules, venv, build, dist, pycache, and respects .gitignore and .envguardignore.
Single Detection Engine: Reuses the core streaming engine for identical detection accuracy across all commands.
bash
Watch current directory
envguard watch
Watch specific directory with custom debounce
envguard watch ./src --debounce 0.5
3. Editor & IDE Diagnostic JSON (--format ide)
A standardized, versioned JSON schema (schema_version: 1) engineered for IDE extensions, Language Server Protocol (LSP) daemons, and editor diagnostics (VS Code, JetBrains, Neovim):
1-Based Character Coordinates: Every finding includes deterministic line, column, end_line, and end_column properties with safe fallback coordinates (min: 1).
Guaranteed Privacy: Plaintext secrets are strictly masked (masked_value) and never exposed in the JSON output.
Command Support:
bash
envguard scan --format ide
envguard ci --format ide
🔒 Security & Policy Consistency
Full Organization Floor Enforcement: Pre-push and watch modes honor both local .envguard.yml and organization .envguard-org.yml policies with transparent blocker attribution (organization policy vs local policy).
Cryptographic Baseline Compatibility: Existing baseline fingerprints (.envguard-baseline.json) are seamlessly respected across pre-push scans without masking new leaks.
100% Local & Zero Telemetry: All scans, diffs, and watch events execute strictly on local CPU and memory.
🧪 Verification & Test Suite
EnvGuard v0.7.0 passes 190 of 190 tests (100%):
text
============================= 190 passed in 22.23s =============================
tests/test_v070_pre_push.py — Stdin protocol parsing, delete handling, injection defense, commit range resolution, blocking alert screens.
tests/test_v070_watch.py — Directory baseline snapshots, debounce settling, instant secret detection, file deletions, clean Ctrl+C shutdown.
tests/test_v070_ide_json.py — Schema validation (schema_version: 1), 1-based character ranges, safe fallbacks, secret masking.
📦 Installation
From wheel:
bash
pip install dist/envguard-0.7.0-py3-none-any.whl
Developer editable mode:
bash
git clone https://github.com/neil-data/envGUARD.git
cd envGUARD
git checkout v0.7.0
pip install -e .
Verify:
bash
envguard --version