EnvGuard v0.8.0 — Automated Remediation & Secrets Manager Integration
What's Changed in EnvGuard v0.8.0
EnvGuard v0.8.0 is the first write-capable release, introducing automated secret remediation and enterprise secrets manager recognition built around a strict safety-over-automation philosophy.
🚀 Key Features & Enhancements
1. Automated Secret Remediation (envguard fix)
- Safe Code Rewrites: Converts hardcoded Python assignments directly into
os.environ.get("ENV_VAR_NAME"). - Safe Import Injection: Injects
import osdirectly after module docstrings or top-level comments if not already present. - Dual Environment Synchronization:
- Saves extracted secrets directly into
.env. - Synchronizes
.env.exampleusing strictly sanitized placeholders ("your-secret-key-here"), guaranteeing plaintext secrets are never written into version control.
- Saves extracted secrets directly into
- Terminal Diffs: Displays clean, colored unified diffs of all proposed modifications before and after application.
2. Strict Safety Rails
- Dry-Run by Default: Never modifies source files or environment files without the explicit
--applyflag. - Git Working Tree Protection: Requires a clean Git working tree before modifying code to prevent corrupting uncommitted changes (overridable with
--allow-dirty). - AST Validation Gate: Leverages Python's Abstract Syntax Tree (
ast) to inspect assignments. Multiline strings, dict literals, f-strings, and complex expressions are safely preserved untouched and flagged for manual review. - Atomic Writes with Rollback: Prepares modified files and applies changes atomically, restoring in-memory backups if any file operation fails.
3. 100% Offline Secrets Manager Recognition
- Pattern-recognition for enterprise secret stores and environment lookups:
- AWS Secrets Manager (
boto3.client("secretsmanager"),get_secret_value) - HashiCorp Vault (
hvac.Client,client.secrets.kv,vault.read) - Azure Key Vault (
azure.keyvault.secrets,SecretClient,get_secret) - Google Cloud Secret Manager (
google.cloud.secretmanager,SecretManagerServiceClient,access_secret_version) - Environment Lookups (
os.environ.get,os.getenv,os.environ[...])
- AWS Secrets Manager (
- Zero cloud SDK credentials, zero network calls, and zero external dependencies.
- Files/lines already utilizing secrets managers are detected and excluded from blind rewrites.
4. Credential Rotation Advisory
- Displays prominent warnings post-remediation reminding developers that exposed secrets must be revoked and rotated at the provider level.
🧪 Test Suite & Quality Assurance
- 208 tests passing (
pytest tests/ -q). - Full regression test coverage for AST safety, diffing, import injection, Git tree cleanliness, and secrets manager detection.
📦 Installation & Upgrade
Install from wheel:
pip install dist/envguard-0.8.0-py3-none-any.whl