Release Notes
Fixed
- The
--providerCLI flag now correctly takes precedence over the
SECRETSPEC_PROVIDERenvironment variable. Previously the env var was
consulted before the value forwarded from--provider(viaset_provider),
so users could not temporarily override the provider on the command line
while the env var was set. Fixes
#77. - Per-secret
providers = [...]chains now behave as a true fallback chain
when an upstream provider errors (e.g. a 403 from a vault the current user
cannot access). Previously the first provider's error short-circuited the
whole operation; now the error is logged as a warning and the next provider
in the chain is tried. The original error is only surfaced if every
provider in the chain failed (so genuine outages still bubble up), or if
the secret has no alternative to fall back to. Fixes
#83. secretspec runnow removes the temporary files it creates for
as_path = truesecrets after the child process exits. Previously the
files were leaked under/tmpbecausestd::process::exitskipped the
destructors that own them. Fixes
#71.- Provider URIs now support spaces and special characters in names
(e.g.,onepassword://Home Lab). All providers receive automatically
percent-decoded values via a newProviderUrlwrapper type. - dotenv provider: setting a secret no longer corrupts neighboring values
that contain double quotes, backslashes, dollar signs, or newlines
(e.g. JSON values). The underlyingserde-envfileserializer did not
escape these characters; fix is pinned via a fork until
lucagoslar/serde-envfile#6
lands upstream. Fixes #74. --provider(andSECRETSPEC_PROVIDER) is now honored on every command
even when aproviders = [...]chain is configured for the secret or
profile. Previouslyset,get,check,import, andrunsilently
used the first provider in the chain and ignored the explicit override,
makingsecretspec set --provider <alias>a no-op against the requested
target. The flag now consistently takes precedence:set/import/
generation write only to the chosen provider, andget/validateread
only from it (no chain fallback). Provider aliases declared in
~/.config/secretspec/config.tomlcan now be passed directly to
--provider. Fixes #81.
Added
- BWS (Bitwarden Secrets Manager) provider with async SDK integration, secret caching, and full read-write support (requires
--features bws)
Changed
secretspec-derivenow depends onsecretspecwithdefault-features = false, avoiding pulling in CLI and provider features when only the derive macro is used.
Install secretspec 0.9.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/cachix/secretspec/releases/download/v0.9.0/secretspec-installer.sh | shDownload secretspec 0.9.0
| File | Platform | Checksum |
|---|---|---|
| secretspec-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| secretspec-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| secretspec-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| secretspec-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| secretspec-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |