Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,17 @@ jobs:
if (response.ok) console.log(`${name}@${version} is already published; skipping publication.`);
JS

- name: Verify repository provenance identity
run: |
node --input-type=module <<'JS'
import assert from 'node:assert/strict';
import { readFileSync } from 'node:fs';
const { repository } = JSON.parse(readFileSync('package.json', 'utf8'));
const declared = repository.url.replace(/^git\+/, '').replace(/\.git\/?$/, '').replace(/\/$/, '');
const expected = `https://github.com/${process.env.GITHUB_REPOSITORY}`;
assert.equal(declared, expected, 'package.json repository.url must match GitHub provenance, including capitalization');
JS

- name: Test
run: bun run test

Expand Down
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Changelog

## [2.1.2] - 2026-10-04

- Corrected the canonical GitHub repository URL's capitalization to match GitHub Actions provenance. npm rejected the 2.1.1 upload because those identities differed; this version includes the inspection tool and release checks below.

## [2.1.1] - 2026-10-04

- Fixed release verification for npm 12's package metadata format while retaining compatibility with earlier npm versions. Packed package names and versions are checked against the manifest, and publish dry runs still create and install real test artifacts.
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ Pass `detect: shield.options()` to the other wrappers in the same way. Omitting

## AI SDK inspection tool

Shield 2.1.1 adds an inspection tool for AI SDK 5, 6, and 7:
Shield 2.1.2 adds an inspection tool for AI SDK 5, 6, and 7:

```typescript
import { shieldCheck } from "@zeroleaks/shield/ai-sdk/tools";
Expand Down
4 changes: 2 additions & 2 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@zeroleaks/shield",
"version": "2.1.1",
"version": "2.1.2",
"description": "Runtime security for LLM apps and agents: prompt injection detection for user input and tool results, and leak, credential, PII, and exfiltration checks on model output",
"main": "dist/index.js",
"module": "dist/index.mjs",
Expand Down Expand Up @@ -95,7 +95,7 @@
},
"repository": {
"type": "git",
"url": "https://github.com/zeroleaks/shield"
"url": "https://github.com/ZeroLeaks/shield"
},
"homepage": "https://zeroleaks.ai/docs/shield-sdk",
"bugs": {
Expand Down
4 changes: 2 additions & 2 deletions registry/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

The public integration guide is `https://zeroleaks.ai/docs/shield-sdk/providers/ai-sdk-tools`. Its main example must match `entry.ts` exactly. The ZeroLeaks app's package verifier checks that parity; Shield's isolated package verifier type-checks and executes the registry snippet.

Before submitting, confirm that npm serves `@zeroleaks/shield@2.1.1` and the integration guide is live. The source repository, README, public docs, and published package must describe the same exports and supported SDK versions.
Before submitting, confirm that npm serves `@zeroleaks/shield@2.1.2` and the integration guide is live. The source repository, README, public docs, and published package must describe the same exports and supported SDK versions.

Publishing uses the `NPM_TOKEN` Actions secret in the Shield repository's `npm` GitHub environment. The existing workflow configures npm authentication from that secret before publishing. Replace it with `gh secret set NPM_TOKEN --repo ZeroLeaks/shield --env npm`; paste the credential into the hidden prompt, and keep it out of source files.

Expand All @@ -14,7 +14,7 @@ To retry a release, run the current workflow and verify the registry version aft

```bash
gh workflow run publish.yml --repo ZeroLeaks/shield --ref master -f dry_run=false -f npm_tag=latest
npm view @zeroleaks/shield@2.1.1 version
npm view @zeroleaks/shield@2.1.2 version
```

Confirm the integration guide is deployed before submitting upstream. The app documentation PR requires a review before production deployment: https://github.com/x1xhlol/zeroleaks-v2/pull/229.
Expand Down
2 changes: 1 addition & 1 deletion registry/issue.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ The package also provides `shieldLanguageModelMiddleware` to check user messages
- Canonical repository: https://github.com/ZeroLeaks/shield
- AI SDK integration guide: https://zeroleaks.ai/docs/shield-sdk/providers/ai-sdk-tools
- Website: https://zeroleaks.ai/shield
- Version prepared and tested: `@zeroleaks/shield@2.1.1`
- Version prepared and tested: `@zeroleaks/shield@2.1.2`
- Current SDK tested: `ai@7.0.127`
- Additional supported SDKs tested: `ai@5.0.267`, `ai@6.0.292`

Expand Down
2 changes: 1 addition & 1 deletion registry/pr.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ Adds [ZeroLeaks Shield](https://zeroleaks.ai/shield) to the tools registry with

The entry links directly to the [AI SDK integration guide](https://zeroleaks.ai/docs/shield-sdk/providers/ai-sdk-tools). Its example uses current AI SDK imports, AI Gateway, and `isStepCount`. Local detection needs no ZeroLeaks key; the Gateway model needs `AI_GATEWAY_API_KEY`.

Validation for Shield 2.1.1:
Validation for Shield 2.1.2:

- 1,263 passing tests, with two optional model tests skipped.
- Isolated packed-package consumers on AI SDK 5.0.267, 6.0.292, and 7.0.127, covering generation, streaming, malformed inputs, hosted errors, and middleware blocking.
Expand Down
Loading