Skip to content

EnvGuard v0.8.0 — Automated Remediation & Secrets Manager Integration

Choose a tag to compare

@neil-data neil-data released this 16 Sep 13:43
· 7 commits to main since this release

What's Changed in EnvGuard v0.8.0

EnvGuard v0.8.0 is the first write-capable release, introducing automated secret remediation and enterprise secrets manager recognition built around a strict safety-over-automation philosophy.


🚀 Key Features & Enhancements

1. Automated Secret Remediation (envguard fix)

  • Safe Code Rewrites: Converts hardcoded Python assignments directly into os.environ.get("ENV_VAR_NAME").
  • Safe Import Injection: Injects import os directly after module docstrings or top-level comments if not already present.
  • Dual Environment Synchronization:
    • Saves extracted secrets directly into .env.
    • Synchronizes .env.example using strictly sanitized placeholders ("your-secret-key-here"), guaranteeing plaintext secrets are never written into version control.
  • Terminal Diffs: Displays clean, colored unified diffs of all proposed modifications before and after application.

2. Strict Safety Rails

  • Dry-Run by Default: Never modifies source files or environment files without the explicit --apply flag.
  • Git Working Tree Protection: Requires a clean Git working tree before modifying code to prevent corrupting uncommitted changes (overridable with --allow-dirty).
  • AST Validation Gate: Leverages Python's Abstract Syntax Tree (ast) to inspect assignments. Multiline strings, dict literals, f-strings, and complex expressions are safely preserved untouched and flagged for manual review.
  • Atomic Writes with Rollback: Prepares modified files and applies changes atomically, restoring in-memory backups if any file operation fails.

3. 100% Offline Secrets Manager Recognition

  • Pattern-recognition for enterprise secret stores and environment lookups:
    • AWS Secrets Manager (boto3.client("secretsmanager"), get_secret_value)
    • HashiCorp Vault (hvac.Client, client.secrets.kv, vault.read)
    • Azure Key Vault (azure.keyvault.secrets, SecretClient, get_secret)
    • Google Cloud Secret Manager (google.cloud.secretmanager, SecretManagerServiceClient, access_secret_version)
    • Environment Lookups (os.environ.get, os.getenv, os.environ[...])
  • Zero cloud SDK credentials, zero network calls, and zero external dependencies.
  • Files/lines already utilizing secrets managers are detected and excluded from blind rewrites.

4. Credential Rotation Advisory

  • Displays prominent warnings post-remediation reminding developers that exposed secrets must be revoked and rotated at the provider level.

🧪 Test Suite & Quality Assurance

  • 208 tests passing (pytest tests/ -q).
  • Full regression test coverage for AST safety, diffing, import injection, Git tree cleanliness, and secrets manager detection.

📦 Installation & Upgrade

Install from wheel:

pip install dist/envguard-0.8.0-py3-none-any.whl