Added
- Hardcoded secrets detection in scaffolding scanner — contributed by @nooscraft in #45
- New
include_secretsparameter (default: false) forfossil_detect_scaffolding - Detects ~15 secret patterns: OpenAI, Anthropic, AWS, GitHub, Google, Stripe API keys, PEM headers, Slack/Discord webhooks, DB connection strings with credentials, JWT tokens
- High and medium confidence findings with automatic redaction (first 8 chars +
***) - Environment variable access lines are excluded to reduce false positives
- Known placeholder strings (changeme, your_api_key, etc.) are filtered out
- 17 new tests (unit + integration) covering all pattern types, redaction, and exclusions
- New
Changed
- Dependency updates
Contributors
Thank you to @nooscraft for another great contribution!
Installation
From crates.io
cargo install fossil-mcpPre-built Binaries
Download the appropriate archive for your platform from the assets below, extract, and place fossil-mcp in your PATH.
Platform Support
| Platform | Architecture | Archive |
|---|---|---|
| Linux | x86_64 (recommended) | fossil-mcp-linux-x86_64-musl-*.tar.gz |
| Linux | x86_64 (glibc) | fossil-mcp-linux-x86_64-*.tar.gz |
| Linux | ARM64 | fossil-mcp-linux-aarch64-*.tar.gz |
| macOS | x86_64 (Intel) | fossil-mcp-macos-x86_64-*.tar.gz |
| macOS | ARM64 (Apple Silicon) | fossil-mcp-macos-aarch64-*.tar.gz |
| Windows | x86_64 | fossil-mcp-windows-x86_64-*.zip |
Changelog
See CHANGELOG.md for full details.