Skip to content

Ju571nK/sigil](https:

v0.2.1 Maintenance

This release keeps dependencies and maintenance posture current for teams operating this tool.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai-agent ai-coding-agent ai-security ai-spm claude-code codex
+14 more
cursor developer-security endpoint-security file-integrity-monitoring gemini-cli mcp mcp-security modelcontextprotocol posture-management prompt-injection rust security-monitoring siem tool-poisoning

Summary

AI summary

Minor fixes and improvements.

Full changelog

Install (macOS / Linux)

curl --proto '=https' --tlsv1.2 -fsSL https://raw.githubusercontent.com/Ju571nK/sigil/main/install.sh | sh

Pin a version with SIGIL_VERSION, or install elsewhere with SIGIL_INSTALL_DIR.

Verify a download

sha256sum -c SHA256SUMS                              # integrity
gh attestation verify <archive> --repo Ju571nK/sigil # provenance

If build-manifest.json is attached, an installed agent can verify itself
against it:

sigil doctor --verify-self --manifest build-manifest.json

Windows

Download the .zip for your architecture (x86_64 for most PCs,
aarch64 for Arm devices such as Surface Pro X) and add it to your PATH.

Every archive contains all five binaries: sigil, sigil-sender, sigil-server, sigil-sign, sigil-mcp.

sigil-mcp is the read-only fleet MCP server — point an MCP client (Claude Desktop/Code) at a sigil-server's read API to query and reason over fleet posture. See crates/sigil-mcp/README.md.

Server + agent (Linux, x86_64 and aarch64)

Prebuilt .deb / .rpm packages (static binaries — work on RHEL/Rocky and
Debian/Ubuntu, on both x86_64 and ARM64). See docs/install-server.md.

sudo dnf install ./sigil-server-*.x86_64.rpm     # RHEL / Rocky / Fedora (x86_64)
sudo dnf install ./sigil-server-*.aarch64.rpm    # … ARM64
sudo apt  install ./sigil-server_*_amd64.deb     # Debian / Ubuntu (x86_64)
sudo apt  install ./sigil-server_*_arm64.deb     # … ARM64

Each package ships a hardened, disabled-by-default systemd unit + config example.
(armv7 is supported by packaging/build.sh --target armv7-unknown-linux-gnueabihf
but is not built in CI.)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Ju571nK/sigil](https:

Get notified when new releases ship.

Sign up free

About Ju571nK/sigil](https:

All releases →

Beta — feedback welcome: [email protected]