Skip to content

secretgate v1.2.3

Choose a tag to compare

@tianzhicdev tianzhicdev released this 31 Aug 09:57
· 25 commits to main since this release

scan false-clean fix (C c69 defect #2) + missing-path fail-closed rc2. Pinned by scan-root-matrix M8-M12 (old engine goes red M8/M9/M10/M12). Signed receipt attached (verify: ethkey.py verify proof --require 0xFD4090e27C1f946Ff01a265cAa7d4ACA662acC15).

ALSO WARNING (c85, added 2026-08-31): this gen ALSO silently blesses any secret whose VALUE contains an embedded dictionary word (insert/example/your/changeme/dummy/redacted/placeholder/test-) anywhere — raw-substring arms in PLACEHOLDER_RE, both generic-keyword and entropy-sweep paths. Measured non-vacuous; fixed in v1.2.4 (token-start anchoring, templates stay suppressed, 0 blast-radius on fleet bytes). Pin v1.2.5 or newer (repoint at ship time). (v1.2.4 still carries the measured mid-token 5-x-run bless class, see next paragraph)

ALSO WARNING (c86, added 2026-08-31): this gen ALSO silently blesses any secret whose VALUE contains a literal 5-x run mid-token (e.g. a 40-hex key with 'xxxxx' embedded) — bare unanchored x{5,} arm in PLACEHOLDER_RE, both paths (stranger-measured, C c81 x5_midrun). v1.2.5 bounds it to token-END runs (masking intent); mid-token embeds are now FLAGGED. Pin v1.2.5 or newer (repoint at ship time).

C91 POINTER FIX (2026-08-31, c91 banner-coverage R5): present-tense pin pointers on this page re-pointed at v1.2.5 — the previous pointers (v1.2.3/v1.2.4) were accurate when written and decayed as new bless classes landed on those gens (pointer-decay law, C c86). No tag or asset moved.

C95 P3 HEDGE (2026-08-31, c95): present-tense directives on this page carry a forward hedge — 'or newer' keeps them correct when the next tag ships (P3-cell decay test: simulated next-ship scored 16 unhedged directives red; hedged corpus scores 0). No tag or asset moved.