This release adds 1 notable feature for engineering teams evaluating rollout.
Published 22h
Secrets & Credentials
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
api-keys
credentials
security
git
gpu
hyperscan
+5 more
pre-commit
rust
secret-detection
secret-scanner
simd
Summary
AI summaryRelease asset verification now accepts both text‑mode and binary‑mode sha256sum manifests.
Full changelog
Added
- The POSIX installer accepts
--no-calibratefor deterministic automation.
It still verifies the signature, checksum, installed binary, GPU literal
sidecar, anddoctorself-test, then warns that automatic routing remains
uncalibrated until you runinstall.sh --calibrate. - The signed Linux release smoke uses the explicit no-calibration path and a
measured-correct SIMD backend. Hosted-runner timing noise can no longer block
publication after payload and product verification have passed.
Fixed
- Release asset verification accepts both text-mode and binary-mode
sha256summanifests, including the*filenameform emitted for Windows
executables. - Manual release recovery dispatches check out and attest the exact requested
immutable tag in every build, installer, signing, container, publication,
and floating-tag job. - Signing uses hardened publication and release-note automation from the
workflow commit while all product bytes remain bound to the requested tag. - The prerelease version bumper tracks every canonical version-bearing guide
and no longer rejects versionless pages. Documentation truth checks now cover
the integration, verification, and out-of-band verification pins updated for
this release.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About santhsecurity/keyhog
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]