v0.9.8 — Scanner Precision, Baseline Exclusions & Quality Fixes
What's Changed in EnvGuard v0.9.8
EnvGuard v0.9.8 addresses key findings from dogfooding and release testing of v0.9.0, focusing on scanner precision, eliminating false positives on remediated code, protecting baseline files, aligning runtime diagnostics with package constraints, and smoothing CLI path ergonomics.
🛡️ Scanner Precision: Zero False Positives on Safe Code & Remediations
- Safe code expressions ignored: Function invocations (e.g.
secret_key = get_secret_key_from_vault(),get_password()) and environment variable lookups (e.g.password = os.environ.get("PASSWORD"),db_password = os.getenv("DB_PASSWORD"),database_password = os.environ.get(...)) are no longer falsely flagged by variable assignment rules. - Secrets manager & environment recognition: Any assignment line using standard environment lookups or offline secrets managers (AWS Secrets Manager, HashiCorp Vault, Azure Key Vault, Google Secret Manager) is automatically recognized and skipped by heuristic assignment detectors.
- Refined assignment regex: Parentheses
()are explicitly excluded from unquoted assignment values inpatterns.jsonand fallback patterns.
🔕 Automatic Baseline & Config File Exclusions
- Built-in baseline ignore:
.envguard-baseline.json(and all.envguard*.json/.envguard*.ymlfiles) are now built intois_path_ignored(). - Clean pre-commit commits: Generating a baseline hash or editing EnvGuard configurations will never trigger
generic-high-entropy-secretor block pre-commit hooks.
🩺 Doctor Python Floor Alignment
- Strict Python >= 3.10 verification:
envguard doctornow checkssys.version_info >= (3, 10)and outputsPython X.Y.Z (Compatible >= 3.10), aligning directly withpyproject.toml.
🖥️ CLI Positional Path Consistency
- Universal path arguments:
envguard baseline create [PATH],envguard doctor [PATH],envguard init [PATH], andenvguard status [PATH]now accept optional positional path arguments (e.g.envguard baseline create .) alongside existing-p / --pathoptions.
🧪 Test Suite & Packaging
- 233/233 tests passing: Added dedicated regression test suite in
tests/test_v098_fixes.py. - Wheel built:
dist/envguard-0.9.8-py3-none-any.whl. - Git: Tagged
v0.9.8and pushed tomain.