v0.1.1 — first cut with all 7 security fixes
First release cut after the 2026-08-22 full-repo security review. Closes 7 private security advisories (2 High, 5 Medium) — every one fail-closed, with tests (178/178) and conformance (Docker + Firejail, plugin + standalone) green.
Security fixes
| Advisory | Severity | Fix |
|---|---|---|
| GHSA-h5c5-76pv-6g85 | High | SANDY_TEST_RUNTIME sandbox-detection bypass removed from production code (detectRuntime()); CLI test determinism now goes through runCli's SandyDeps.detection overrides. SB-03 "refuse to start without a boundary" can no longer be defeated by one env var. |
| GHSA-38wj-6mjh-2jf9 | High | MCP oauth/mtls auth no longer silently connects unauthenticated — authHeaders() throws "not yet implemented"; the failure surfaces via MCP-10 (mcp.failed in sandy check, RG-05 report gaps). |
| GHSA-qx23-r762-x2j9 | Medium | Loopback local API CSRF hardening: readJsonBody() requires application/json (415) and handleRequest() rejects foreign Origin headers (403). |
| GHSA-w84c-rwhv-mrgx | Medium | Undo (reverse()) re-resolves journal paths through PathConfinement — a symlink swapped in after the original mutation is refused (SandboxViolationError), not followed (TOCTOU escape closed). |
| GHSA-r885-qm59-2mxf | Medium | list() applies ignore_patterns against the confinement root (not the queried directory), so a direct list("secrets") no longer leaks filenames a pattern like secrets/*.key was meant to hide. |
| GHSA-rm4r-g5vv-mvrm | Medium | rename() requires the (forced-minimum) overwrite confirmation when the destination exists — rename can no longer defeat the overwrite gate write() enforces. |
| GHSA-6q24-xhv7-3jg6 | Medium | scripts/provision-model.sh now SHA256-pins and fail-closed-verifies the llama-server release tarball before extracting/executing it (it is executable code); a release/variant override without an explicit SANDY_LLAMA_SHA256 fails closed. |
Other changes in this release
- Per-advisory entries in
docs/DIARY.md(one per fix). - Version identity strings bumped to
0.1.1(package, plugin, MCP server/client).
Verification
npm run typecheck/npm run build— greennpm test— 178/178 (was 169 at review time; +9 security tests)- CI conformance matrix (Docker × Firejail × plugin × standalone) — byte-identical signatures, egress harnesses pass