harald
84b6a39f3f
chore(release): bump version to 0.8.0, add SECURITY_AUDIT.md, and update changelog
2026-09-19 10:07:42 +02:00
harald
fba7f305e3
release: v0.7.2 — Security Audit Remediation (SA-01 bis SA-07)
...
Sanctum Release / Build & Test (Windows x86_64) (push) Waiting to run
Sanctum Release / Sign & Release (push) Blocked by required conditions
- SA-01: Container-DoS / KDF-Amplification Schutz mit Pre-KDF Validierung, max 2 Slots (nur 0 und 1), Slot 0 Pflicht und strikten BLOB-Laengen
- SA-02: Release-Signierung in CI entkoppelt (getrennte build und sign-and-release Jobs, Secret-Isolation)
- SA-03: Pinned Download-Integritaet fuer minisign.exe in CI via SHA-256
- SA-04: Immutable Action-Pinning (@sha) und Toolchain-Pinning (1.85.0) in CI
- SA-05: Session-Token vollstaendig aus URIs verbannt (403 Forbidden bei Vorkommen im Pfad/Query)
- SA-06: Constant-Time Token- und Auth-Vergleiche via subtle::ConstantTimeEq
- SA-07: Dokumentations-Klarstellung bzgl. logischem Shredding vs. physischer SSD/FTL/CoW-Persistenz
2026-09-18 23:40:35 +02:00
harald
1cdb30147b
release: v0.7.1 — Security-Patch (R-01 bis R-06)
...
Sanctum Release / Build & Release (Windows x86_64) (push) Waiting to run
- R-01: Bereinigung verbliebener Restbehauptungen in Doku und Code (LEGAL.md, README.md, QUICKSTART.md, main.rs, crypto/storage/recovery/verify.rs)
- R-02: Lückenloser Carrier-Schutz in SanctumFs::copy (Quelle & Ziel) und sync (Pull-Skip & Push-Schutz)
- R-03: Shared Dateinamen-Validierung (validate_node_name) in pathutil.rs, durchgesetzt in storage.rs und vfs.rs
- R-04: Fail-closed Release-Packaging & obligatorische Minisign-Signatur in CI (.gitea/workflows/release.yaml) und Scripts
- R-05: Session-Token Beseitigung im argv: In-Process Win32 WNetAddConnection2W/WNetCancelConnection2W, kein gio argv-Token, Multi-Auth HTTP Middleware (Basic Auth, X-Sanctum-Token, Path-Fallback) mit 401 WWW-Authenticate
- R-06: Sofortiges Löschen von SANCTUM_RECOVERY_KEY aus der Prozessumgebung
2026-09-18 19:49:38 +02:00
harald
436790abf0
feat(security): release v0.7.0 with comprehensive security hardening (S-01 to S-11)
Sanctum Release / Build & Release (Windows x86_64) (push) Waiting to run
2026-09-18 19:12:43 +02:00
harald
2e4cf1cef0
feat(upgrade): implement in-place self-upgrade command and bump version to v0.6.0
2026-09-16 12:33:57 +02:00
harald
aa65d96434
feat(sync): add rsync-like sync command with dry-run and bump version to v0.5.0
2026-09-16 10:40:38 +02:00
harald
650cfc7cd4
chore(release): bump version to v0.4.1
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-14 14:02:02 +02:00
harald
5f2040f8bf
chore(release): bump version to 0.4.0 and update manifests
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-10 17:02:05 +02:00
harald
7ed0f51fb1
chore(release): bump version to 0.3.1 and update release notes
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-10 14:08:48 +02:00
harald
abf395627a
chore: release v0.3.0
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-09 22:00:04 +02:00
harald
5c1ac89989
chore(release): bump version to 0.2.0
Sanctum Release / Build & Release (Windows x86_64) (push) Canceled after 0s
2026-09-08 10:50:33 +02:00
harald
38df3d3845
feat(windows): implement explorer shell integration, auto drive allocation, auto-open, and system tray icon
2026-09-08 10:04:24 +02:00
harald
1c8a860184
feat(recovery): implement header backup/restore, BIP-39 recovery key, and integrity verification
2026-09-08 09:49:08 +02:00
harald
2d14c64c3e
feat(compression): implement transparent LZ4 chunk compression with V1 backwards compatibility
2026-09-07 21:59:42 +02:00
harald
9115596763
Initial commit: Sanctum encrypted single-file container for Windows
2026-09-07 15:40:58 +02:00