Release Notes
Added
sshelf add --from-sshsaves a host from a working ssh command line:
sshelf add --from-ssh 'ssh -i key.pem -p 2222 user@host',"$(fc -ln -1)"for the one you
just ran, or the line on stdin. It reads ssh's own options and opens the add form with the user,
port, keys and jump hosts filled in and everything else kept as extra args, so what's left to
type is the secret.-v,-N,-f,-o StrictHostKeyCheckingand a few others are dropped,
with a note saying why.--quietadds the host without the form.- Connecting to a password host with nothing stored, or to a key host whose key needs a
passphrase, asks for it on the terminal, checks it with one throwawayssh ... exit, and keeps
it only if that worked. A key your agent already holds is never asked about, andEnterskips.
This is what a copied, generated or hand-writtenhosts.tomlwas missing, since its hosts have
no secrets stored yet. A 2FA host saves the password without the check, because checking would
use up the code.
Changed
- tmux mode opens the new window or pane in the background, so focus stays on the picker. It used
to switch to the new window. A host that is about to be asked for its first secret connects in
place instead, with a line saying why.
Fixed
- An upload could overwrite a file that appeared in the remote directory after sshelf checked
the listing and before the bytes landed. A single file now uploads to a private
.sshelf-part-name and is installed under its real name withsftp'sln, which the server
refuses if the name is taken, so the send is skipped instead. Downloads have worked this way
since the transfer screen shipped. Folders still rest on the listing check, in both
directions, and are the only send that does. - Uploading a single file into a remote directory whose listing was cut short at 50,000 entries
is no longer refused, since that upload no longer depends on the listing. Folders are still
refused there. - A wrong stored password or passphrase was handed to ssh again on every retry, and the failure
read like the server refusing you. The askpass helper now notices ssh asking the same question
twice in one connect, printssshelf: the stored password for <id> was refused; replace it with sshelf set-password or ^e in the TUI, and stops answering. The stored secret is left alone. The
transfer screen and port forwards name the stored secret in the same situation.
Install sshelf 0.15.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/max-rh/sshelf/releases/download/v0.15.0/sshelf-installer.sh | shInstall prebuilt binaries via Homebrew
brew install max-rh/tap/sshelfDownload sshelf 0.15.0
| File | Platform | Checksum |
|---|---|---|
| sshelf-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| sshelf-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| sshelf-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| sshelf-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo max-rh/sshelfYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>