js · @bitbonsai/mcpvaultHeads-up
@bitbonsai/mcpvault PathFilter now case-insensitive and canonicalizes per segment
PathFilter in @bitbonsai/mcpvault now uses case-insensitive matching and per-segment canonicalization before deny-list checks, fixing bypasses on case-insensiti
What changed
PathFilter in @bitbonsai/mcpvault now uses case-insensitive matching and per-segment canonicalization before deny-list checks, fixing bypasses on case-insensitive filesystems (macOS, Windows) and Windows trailing dots/spaces.
Who it affects
Users of @bitbonsai/mcpvault on macOS or Windows, or anyone relying on PathFilter's deny-list for .git, .obsidian, node_modules, etc.
What to do today
Update to version 0.11.4 or later to prevent bypasses of path restrictions.
The trail
Collected→
Audited→
Written→
Published