• 0.8.0 5bf247c485

    0.8.0
    All checks were successful
    CI / test (push) Successful in 41s
    CI / test (almalinux, docker.io/library/almalinux:9, python3.11) (push) Successful in 9m2s
    CI / test (debian, docker.io/library/debian:13, python3) (push) Successful in 13m39s
    Lint / test (push) Successful in 39s
    Stable

    mig5 released this 2026-07-12 19:31:34 -05:00 | 8 commits to main since this release

    • Security: keep sudo-created remote harvest bundles root-owned while root packages and hashes them, expose only the archive to the authenticated SSH uid, and verify the root-computed digest after download. This removes the post-harvest tampering window created by recursively chowning the bundle before packaging without making the plaintext archive world-readable.
    • Security: enforce tar member limits while lazily parsing untrusted archives rather than after TarFile.getmembers() has already indexed the entire archive; count repeated . entries and cap remote compressed downloads as well.
    • Security: apply aggregate byte and total filesystem-entry limits when freezing directory harvest bundles, reject symlinked bundle roots, and abort when files or discovered directories change during the copy, so direct directory inputs remain bounded and fail closed under mutation.
    Downloads