v0.8.7 — Remediation Safety Fixes
Highlights
This release fixes three issues found during live verification of v0.8.0's new envguard fix command. All three affected real, common scenarios rather than obscure edge cases, and are fixed here before fix sees wider use.
Fixed
-
fixfailed to parse files containing a UTF-8 byte-order-mark (BOM) —scan,check, andcihave always correctly handled BOM-prefixed files (the default output ofOut-File -Encoding utf8in PowerShell), butfix's code-rewriting logic rejected them with a"Failed to parse Python syntax: invalid non-printable character U+FEFF"error, reporting them as requiring manual remediation.fixnow handles BOM-prefixed files the same way the rest of EnvGuard always has. -
fix --applycould leave a real secret exposed to Git — after moving a hardcoded secret into.env,fixdid not ensure.envwas excluded from version control. In a repository with no existing.gitignore, this left the newly created.env— containing the real, unmasked secret value — as a plain untracked file, onegit add .away from being committed into Git history.fix --applynow automatically creates or updates.gitignoreto exclude.envand its common variants (.env.local,.env.*.local) as part of every remediation. -
fixincorrectly re-scanned.envas source code — after.envwas populated with a real secret value, a subsequentfixrun detected that secret inside.envitself and proposed rewriting it, producing a meaningless no-op diff..envand.env.exampleare now correctly excluded fromfix's scan targets, since they are remediation destinations, not source files to be remediated.
Verified in this release
- All three fixes reproduced against the exact failing scenarios from v0.8.0 before the fix, and reconfirmed resolved afterward using the same reproduction steps.
- Re-verified that
fix's core safety behaviors — dry-run-by-default, refusal to run on a dirty Git working tree, and the fallback for structurally unsafe rewrites (f-strings, conditional expressions, function calls) — continue to work correctly and were unaffected by these fixes. - Confirmed the new
.gitignoreentry is created with real content (.env,.env.local,.env.*.local) and thatgit statusno longer flags a freshly created.envas requiring attention.
Recommendation: Anyone who used envguard fix --apply under v0.8.0 should check their repository's .gitignore and confirm .env was not committed before this fix was available.