Skip to content

v0.9.8 — Scanner Precision, Baseline Exclusions & Quality Fixes

Choose a tag to compare

@neil-data neil-data released this 17 Sep 12:13
· 4 commits to main since this release

What's Changed in EnvGuard v0.9.8

EnvGuard v0.9.8 addresses key findings from dogfooding and release testing of v0.9.0, focusing on scanner precision, eliminating false positives on remediated code, protecting baseline files, aligning runtime diagnostics with package constraints, and smoothing CLI path ergonomics.

🛡️ Scanner Precision: Zero False Positives on Safe Code & Remediations

  • Safe code expressions ignored: Function invocations (e.g. secret_key = get_secret_key_from_vault(), get_password()) and environment variable lookups (e.g. password = os.environ.get("PASSWORD"), db_password = os.getenv("DB_PASSWORD"), database_password = os.environ.get(...)) are no longer falsely flagged by variable assignment rules.
  • Secrets manager & environment recognition: Any assignment line using standard environment lookups or offline secrets managers (AWS Secrets Manager, HashiCorp Vault, Azure Key Vault, Google Secret Manager) is automatically recognized and skipped by heuristic assignment detectors.
  • Refined assignment regex: Parentheses () are explicitly excluded from unquoted assignment values in patterns.json and fallback patterns.

🔕 Automatic Baseline & Config File Exclusions

  • Built-in baseline ignore: .envguard-baseline.json (and all .envguard*.json / .envguard*.yml files) are now built into is_path_ignored().
  • Clean pre-commit commits: Generating a baseline hash or editing EnvGuard configurations will never trigger generic-high-entropy-secret or block pre-commit hooks.

🩺 Doctor Python Floor Alignment

  • Strict Python >= 3.10 verification: envguard doctor now checks sys.version_info >= (3, 10) and outputs Python X.Y.Z (Compatible >= 3.10), aligning directly with pyproject.toml.

🖥️ CLI Positional Path Consistency

  • Universal path arguments: envguard baseline create [PATH], envguard doctor [PATH], envguard init [PATH], and envguard status [PATH] now accept optional positional path arguments (e.g. envguard baseline create .) alongside existing -p / --path options.

🧪 Test Suite & Packaging

  • 233/233 tests passing: Added dedicated regression test suite in tests/test_v098_fixes.py.
  • Wheel built: dist/envguard-0.9.8-py3-none-any.whl.
  • Git: Tagged v0.9.8 and pushed to main.