Treeship#security-advisoryBlogDocsGitHub

Writing

#security-advisory

Every post tagged security-advisory.

Treeship 0.31.2: sealed packages now verify their signatures

package verify checked the Merkle tree and nothing under it. It now verifies every artifact's Ed25519 envelope, session close seals unchained work, and the MCP bridge reports failures.

Treeship 0.19: the security-hardening release

Two adversarial audits, every confirmed finding in the default binary fixed with a regression test, and a receipt export any Ed25519 library can verify.

Treeship 0.10.4: the audit hardening release

A keystore that claimed AES-GCM but was not, verifiers that trusted embedded keys, and a Merkle downgrade path. 0.10.3 and 0.10.4 close the audit findings and publish TS-2026-001.