Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,22 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [0.10.6] - 2026-10-02

### Security

- **Unhandled errors no longer print your API key.** A command that failed with an unhandled exception could include the key and other local values in its traceback, printed to the terminal or a CI log. Tracebacks are now printed without local variables.

- **A project's `.env` can no longer supply Rafter's own settings.** Previously, if the working directory had a `.env` file, its `RAFTER_*` values (including `RAFTER_API_KEY`) were read and could override the key and settings you configured yourself — a repository you merely scanned could supply credentials the CLI would then use. `.env` can no longer set any `RAFTER_*` variable; your own shell environment and the value stored in `~/.rafter/config.json` are unaffected. **Behavior change:** if you were relying on `RAFTER_API_KEY` (or another `RAFTER_*` setting) in a project `.env`, move it to your shell environment or to the config file — the CLI will now report the key as missing if `.env` was its only source.

- **`rafter secrets --diff <ref>` and `rafter agent scan --diff <ref>` no longer accept a value that looks like a command-line option.** A ref beginning with `-` could previously be misread by git as an option rather than a ref, which could overwrite an unrelated file and report a scan as clean with no secrets found. Such a value is now rejected before it reaches git.

- **`rafter agent init --local --with-gemini` no longer runs through a shell.** A path containing shell metacharacters could previously have part of it executed as a command during skill registration. Paths are now passed directly to the subprocess, never interpreted by a shell.

### Fixed

- **`rafter run` now checks that an auto-detected branch has been pushed before scanning it.** Running `rafter run` without `--branch` from a local branch that doesn't exist on the remote used to queue a scan that failed later with a "branch not found" error. The CLI now checks first and fails immediately with a clear message to push the branch or pass `--branch` explicitly. If the branch exists on the remote but your local commit is ahead of it, the CLI now notes that the scan covers the pushed commit, not your local changes.

## [0.10.5] - 2026-09-13

### Security
Expand Down
2 changes: 1 addition & 1 deletion node/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@rafter-security/cli",
"version": "0.10.5",
"version": "0.10.6",
"type": "module",
"repository": {
"type": "git",
Expand Down
2 changes: 1 addition & 1 deletion node/resources/rafter-security-skill.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
name: rafter-security
description: Security toolkit for AI workflows. Use when scanning code or repos for vulnerabilities, auditing third-party skills/MCPs/agent configs before installing, evaluating shell commands before running them, or generating secure design questions for new features. Provides `rafter run` (remote SAST + SCA, needs RAFTER_API_KEY), `rafter secrets` (offline secrets-only), `rafter agent exec --dry-run` (command-risk classification), and `rafter skill review`.
version: 0.10.5
version: 0.10.6
homepage: https://rafter.so
metadata:
openclaw:
Expand Down
2 changes: 1 addition & 1 deletion python/pyproject.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[tool.poetry]
name = "rafter-cli"
version = "0.10.5"
version = "0.10.6"
description = "Rafter CLI — the default security agent for AI workflows. Free for individuals and open source."
authors = ["Rafter Team <hello@rafter.so>"]
license = "MIT"
Expand Down
2 changes: 1 addition & 1 deletion python/rafter_cli/resources/rafter-security-skill.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
name: rafter-security
description: Security toolkit for AI workflows. Use when scanning code or repos for vulnerabilities, auditing third-party skills/MCPs/agent configs before installing, evaluating shell commands before running them, or generating secure design questions for new features. Provides `rafter run` (remote SAST + SCA, needs RAFTER_API_KEY), `rafter secrets` (offline secrets-only), `rafter agent exec --dry-run` (command-risk classification), and `rafter skill review`.
version: 0.10.5
version: 0.10.6
homepage: https://rafter.so
metadata:
openclaw:
Expand Down
Loading