Location: src/commands/secrets.ts:109-110.
Kind: insecure file permissions.
Impact: The whole branch secret bundle (DB DSNs, provider keys) is written to .env (or -o <file>) with writeFile(out, serializeEnv(bundle)) and no mode, so it lands at 0644 under umask 022. The command's own tip ("credentials must never be committed") shows the git threat model is understood; the filesystem one is not.
Evidence:
const out = opts.output ?? '.env'
await writeFile(out, serializeEnv(bundle))
Fix would touch: this write only: { mode: 0o600 } plus chmod for a pre-existing file (create-only caveat), and consider preserving a stricter existing mode on -o <file> the way src/commands/storage.ts:127-129 does for downloads.
Found by Yun Tianming: nightly sweep 2026-09-17-1000 at ecfe5168a32e. Report only; no code was changed for this finding.
🤖 Generated with Claude Code
Issue cleanup — 2026-09-29
Canonical tracker for duplicate #273, closed during this cleanup. The defect remains open. Preserve #273’s additional observation about symlink-following when deciding the output-file write contract.
Location:
src/commands/secrets.ts:109-110.Kind: insecure file permissions.
Impact: The whole branch secret bundle (DB DSNs, provider keys) is written to
.env(or-o <file>) withwriteFile(out, serializeEnv(bundle))and nomode, so it lands at 0644 under umask 022. The command's own tip ("credentials must never be committed") shows the git threat model is understood; the filesystem one is not.Evidence:
Fix would touch: this write only:
{ mode: 0o600 }pluschmodfor a pre-existing file (create-only caveat), and consider preserving a stricter existing mode on-o <file>the waysrc/commands/storage.ts:127-129does for downloads.Found by Yun Tianming: nightly sweep
2026-09-17-1000atecfe5168a32e. Report only; no code was changed for this finding.🤖 Generated with Claude Code
Issue cleanup — 2026-09-29
Canonical tracker for duplicate #273, closed during this cleanup. The defect remains open. Preserve #273’s additional observation about symlink-following when deciding the output-file write contract.