github kenryu42/cc-safety-net v2.6.7

5 hours ago

Secret-file protection now looks inside scripts handed to pwsh and powershell, closing a gap where a secret read wrapped in pwsh -c was allowed at every safety level.

Changed

  • Changed deeply nested pwsh -c scripts to stop at the derived-command work limit instead of being walked without bound. (#235)
  • Documented in SECURITY.md that findings from Anthropic's OSS Scanner are fixed privately, with a public issue opened only after the fix is released.

Fixed

  • Fixed secret-file protection ignoring the script passed to pwsh or powershell, so a read such as pwsh -c 'Get-Content ~/.ssh/config' is now blocked like the same read through bash -c. Windows-style paths (~\.ssh\config), the -Command spelling, leading switches such as -NoProfile, and the pwsh.exe form are all covered. (#235)
  • Fixed a PowerShell script being analyzed under POSIX rules when the same script text had already been parsed as POSIX earlier in the command, such as after an eval. (#235)

Don't miss a new cc-safety-net release

NewReleases is sending notifications on new releases.