Skip to content

v0.1.1 — first cut with all 7 security fixes

Choose a tag to compare

@techeretic techeretic released this 23 Aug 05:43
· 90 commits to master since this release

First release cut after the 2026-08-22 full-repo security review. Closes 7 private security advisories (2 High, 5 Medium) — every one fail-closed, with tests (178/178) and conformance (Docker + Firejail, plugin + standalone) green.

Security fixes

Advisory Severity Fix
GHSA-h5c5-76pv-6g85 High SANDY_TEST_RUNTIME sandbox-detection bypass removed from production code (detectRuntime()); CLI test determinism now goes through runCli's SandyDeps.detection overrides. SB-03 "refuse to start without a boundary" can no longer be defeated by one env var.
GHSA-38wj-6mjh-2jf9 High MCP oauth/mtls auth no longer silently connects unauthenticated — authHeaders() throws "not yet implemented"; the failure surfaces via MCP-10 (mcp.failed in sandy check, RG-05 report gaps).
GHSA-qx23-r762-x2j9 Medium Loopback local API CSRF hardening: readJsonBody() requires application/json (415) and handleRequest() rejects foreign Origin headers (403).
GHSA-w84c-rwhv-mrgx Medium Undo (reverse()) re-resolves journal paths through PathConfinement — a symlink swapped in after the original mutation is refused (SandboxViolationError), not followed (TOCTOU escape closed).
GHSA-r885-qm59-2mxf Medium list() applies ignore_patterns against the confinement root (not the queried directory), so a direct list("secrets") no longer leaks filenames a pattern like secrets/*.key was meant to hide.
GHSA-rm4r-g5vv-mvrm Medium rename() requires the (forced-minimum) overwrite confirmation when the destination exists — rename can no longer defeat the overwrite gate write() enforces.
GHSA-6q24-xhv7-3jg6 Medium scripts/provision-model.sh now SHA256-pins and fail-closed-verifies the llama-server release tarball before extracting/executing it (it is executable code); a release/variant override without an explicit SANDY_LLAMA_SHA256 fails closed.

Other changes in this release

  • Per-advisory entries in docs/DIARY.md (one per fix).
  • Version identity strings bumped to 0.1.1 (package, plugin, MCP server/client).

Verification

  • npm run typecheck / npm run build — green
  • npm test — 178/178 (was 169 at review time; +9 security tests)
  • CI conformance matrix (Docker × Firejail × plugin × standalone) — byte-identical signatures, egress harnesses pass