Keep secret get values in locked memory (closes #37) #87

Merged
clawbot merged 1 commits from issue-37-locked-secret-get into next 2026-10-04 11:16:25 +02:00
1 Commits
Author SHA1 Message Date
sneak 23543a7900 Keep secret get values in locked memory (closes #37)
check / check (push) Waiting to run
Vault.GetSecret and Vault.GetSecretVersion return the decrypted value
as a *memguard.LockedBuffer instead of copying it into an ordinary
[]byte that nothing wiped. Every caller destroys the buffer, and
`secret get` writes its bytes straight to stdout, still with no
trailing newline. Instance.Print, which formatted through fmt and had
no other callers, is removed, and so is a debug log line in
`get --version` that held the plaintext value.

Model: opus-5-5
2026-10-04 08:47:20 +00:00