harald
487f999a24
doc(security): Z-03 — document wal and shm ciphertext forensics
2026-09-19 09:49:33 +02:00
harald
e496c418c5
doc(security): M-04 — document session token threat model in userland context
2026-09-19 09:15:05 +02:00
harald
2af14eef36
fix(mount): M-03 — output webdav credentials and manual mount instructions for linux
2026-09-19 09:14:18 +02:00
harald
bdddd812ac
fix(crypto): K-03 — emergency card persistence warning and rekey command
2026-09-19 00:58:39 +02:00
harald
fba7f305e3
release: v0.7.2 — Security Audit Remediation (SA-01 bis SA-07)
...
Sanctum Release / Build & Test (Windows x86_64) (push) Waiting to run
Sanctum Release / Sign & Release (push) Blocked by required conditions
- SA-01: Container-DoS / KDF-Amplification Schutz mit Pre-KDF Validierung, max 2 Slots (nur 0 und 1), Slot 0 Pflicht und strikten BLOB-Laengen
- SA-02: Release-Signierung in CI entkoppelt (getrennte build und sign-and-release Jobs, Secret-Isolation)
- SA-03: Pinned Download-Integritaet fuer minisign.exe in CI via SHA-256
- SA-04: Immutable Action-Pinning (@sha) und Toolchain-Pinning (1.85.0) in CI
- SA-05: Session-Token vollstaendig aus URIs verbannt (403 Forbidden bei Vorkommen im Pfad/Query)
- SA-06: Constant-Time Token- und Auth-Vergleiche via subtle::ConstantTimeEq
- SA-07: Dokumentations-Klarstellung bzgl. logischem Shredding vs. physischer SSD/FTL/CoW-Persistenz
2026-09-18 23:40:35 +02:00
harald
1cdb30147b
release: v0.7.1 — Security-Patch (R-01 bis R-06)
...
Sanctum Release / Build & Release (Windows x86_64) (push) Waiting to run
- R-01: Bereinigung verbliebener Restbehauptungen in Doku und Code (LEGAL.md, README.md, QUICKSTART.md, main.rs, crypto/storage/recovery/verify.rs)
- R-02: Lückenloser Carrier-Schutz in SanctumFs::copy (Quelle & Ziel) und sync (Pull-Skip & Push-Schutz)
- R-03: Shared Dateinamen-Validierung (validate_node_name) in pathutil.rs, durchgesetzt in storage.rs und vfs.rs
- R-04: Fail-closed Release-Packaging & obligatorische Minisign-Signatur in CI (.gitea/workflows/release.yaml) und Scripts
- R-05: Session-Token Beseitigung im argv: In-Process Win32 WNetAddConnection2W/WNetCancelConnection2W, kein gio argv-Token, Multi-Auth HTTP Middleware (Basic Auth, X-Sanctum-Token, Path-Fallback) mit 401 WWW-Authenticate
- R-06: Sofortiges Löschen von SANCTUM_RECOVERY_KEY aus der Prozessumgebung
2026-09-18 19:49:38 +02:00
harald
436790abf0
feat(security): release v0.7.0 with comprehensive security hardening (S-01 to S-11)
Sanctum Release / Build & Release (Windows x86_64) (push) Waiting to run
2026-09-18 19:12:43 +02:00
harald
80a3bd1911
docs: update README.md with sanctum sync and in-place upgrade documentation
2026-09-16 13:46:35 +02:00
harald
4ef0c414fa
feat(linux): add static musl x86_64 build, packaging, and Freedesktop integration
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-10 17:45:04 +02:00
harald
5f2040f8bf
chore(release): bump version to 0.4.0 and update manifests
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-10 17:02:05 +02:00
harald
da2ddbd6ab
feat(distribution): add Scoop/Winget manifests, INSTALL.md, and Unix mount integration
2026-09-10 16:51:24 +02:00
harald
46f976b353
feat(cross-platform): add QUICKSTART.md, live crash test, and platform abstraction module
2026-09-10 16:31:57 +02:00
harald
6cb48f55d9
docs(compliance): add LEGAL.md, THIRD_PARTY_LICENSES.md, and update packaging
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-10 15:14:51 +02:00
harald
7ed0f51fb1
chore(release): bump version to 0.3.1 and update release notes
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-10 14:08:48 +02:00
harald
99813ae2a3
feat(security): add Win32 VirtualLock memory protection, CFA error diagnostics, and ShellBag OpSec
2026-09-10 12:27:57 +02:00
harald
abf395627a
chore: release v0.3.0
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-09 22:00:04 +02:00
harald
bb4268cb62
feat(branding): add 3D shield logo, embed Windows PE icon, and update README banner
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-08 11:24:15 +02:00
harald
952e0cb23a
docs(readme): update documentation for v0.2.0 release
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-08 10:58:23 +02:00
harald
a9c3dd25a3
feat(cli): add passwd command for instant master password changes
2026-09-07 17:29:50 +02:00
harald
eec1971302
feat(release): setup release management with SemVer, packaging script, and Gitea CI/CD
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-07 16:32:41 +02:00
harald
9115596763
Initial commit: Sanctum encrypted single-file container for Windows
2026-09-07 15:40:58 +02:00