Skip to content

Release 0.5.1

Choose a tag to compare

@cedricbonhomme cedricbonhomme released this 29 Apr 11:45
· 11 commits to main since this release
Immutable release. Only release title and notes can be modified.
v0.5.1
d2a6fee

Fixed

  • Privacy: message text could be attached to a sighting whose
    source had fallen back to the encrypted Telegram/<aes-siv> form.
    This happened when the channel URL passed the public-username regex
    but the username field returned by the upstream collector was
    missing, empty, None, or otherwise didn't validate. The source
    correctly became opaque, but the content gate was looser than the
    source gate, so message text from such channels was being pushed to
    Vulnerability-Lookup. The two gates are now structural rather than
    conditional: the line that attaches content lives inside the same
    branch that builds the public https://t.me/<username>/<msg_id>
    source, so a hidden source can never carry text. Operators running
    0.5.0 with include_text = True should audit their
    Vulnerability-Lookup instance for sightings whose source matches
    Telegram/% and whose content field is set, and remove them.