Repository navigation
Release 0.5.1
·
11 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Fixed
- Privacy: message text could be attached to a sighting whose
sourcehad fallen back to the encryptedTelegram/<aes-siv>form.
This happened when the channel URL passed the public-username regex
but theusernamefield returned by the upstream collector was
missing, empty,None, or otherwise didn't validate. The source
correctly became opaque, but thecontentgate was looser than the
source gate, so message text from such channels was being pushed to
Vulnerability-Lookup. The two gates are now structural rather than
conditional: the line that attachescontentlives inside the same
branch that builds the publichttps://t.me/<username>/<msg_id>
source, so a hidden source can never carry text. Operators running
0.5.0 withinclude_text = Trueshould audit their
Vulnerability-Lookup instance for sightings whosesourcematches
Telegram/%and whosecontentfield is set, and remove them.