github cachix/secretspec v0.9.0
0.9.0 - 2026-05-07

latest releases: v0.21.1, secretspec-go/v0.21.1, latest...
4 months ago

Release Notes

Fixed

  • The --provider CLI flag now correctly takes precedence over the
    SECRETSPEC_PROVIDER environment variable. Previously the env var was
    consulted before the value forwarded from --provider (via set_provider),
    so users could not temporarily override the provider on the command line
    while the env var was set. Fixes
    #77.
  • Per-secret providers = [...] chains now behave as a true fallback chain
    when an upstream provider errors (e.g. a 403 from a vault the current user
    cannot access). Previously the first provider's error short-circuited the
    whole operation; now the error is logged as a warning and the next provider
    in the chain is tried. The original error is only surfaced if every
    provider in the chain failed (so genuine outages still bubble up), or if
    the secret has no alternative to fall back to. Fixes
    #83.
  • secretspec run now removes the temporary files it creates for
    as_path = true secrets after the child process exits. Previously the
    files were leaked under /tmp because std::process::exit skipped the
    destructors that own them. Fixes
    #71.
  • Provider URIs now support spaces and special characters in names
    (e.g., onepassword://Home Lab). All providers receive automatically
    percent-decoded values via a new ProviderUrl wrapper type.
  • dotenv provider: setting a secret no longer corrupts neighboring values
    that contain double quotes, backslashes, dollar signs, or newlines
    (e.g. JSON values). The underlying serde-envfile serializer did not
    escape these characters; fix is pinned via a fork until
    lucagoslar/serde-envfile#6
    lands upstream. Fixes #74.
  • --provider (and SECRETSPEC_PROVIDER) is now honored on every command
    even when a providers = [...] chain is configured for the secret or
    profile. Previously set, get, check, import, and run silently
    used the first provider in the chain and ignored the explicit override,
    making secretspec set --provider <alias> a no-op against the requested
    target. The flag now consistently takes precedence: set/import/
    generation write only to the chosen provider, and get/validate read
    only from it (no chain fallback). Provider aliases declared in
    ~/.config/secretspec/config.toml can now be passed directly to
    --provider. Fixes #81.

Added

  • BWS (Bitwarden Secrets Manager) provider with async SDK integration, secret caching, and full read-write support (requires --features bws)

Changed

  • secretspec-derive now depends on secretspec with default-features = false, avoiding pulling in CLI and provider features when only the derive macro is used.

Install secretspec 0.9.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/cachix/secretspec/releases/download/v0.9.0/secretspec-installer.sh | sh

Download secretspec 0.9.0

File Platform Checksum
secretspec-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
secretspec-x86_64-apple-darwin.tar.xz Intel macOS checksum
secretspec-x86_64-pc-windows-msvc.zip x64 Windows checksum
secretspec-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
secretspec-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum

Don't miss a new secretspec release

NewReleases is sending notifications on new releases.