Skip to content

Vault Prospector 0.2.0-preview.1

0.2.0-preview.1 was the first Windows x64 non-production evaluation release in the 0.2 series. It superseded 0.1.1-preview.1 and brought the completed readiness-integration work into one immutable Preview. See the repository README for the current Preview.

Highlights

  • Advanced managed-identity, certificate, and workload-federation profiles with credential and token-cache isolation from developer tools and interactive accounts.
  • Read-only workload authorization evidence and deterministic provisioning previews without Azure identity, RBAC, or Key Vault mutation.
  • Local encrypted-data recovery, all-or-rollback key rotation, explicit purge controls, and expanded fail-closed corruption and tamper handling.
  • Preview CyberArk Privilege Cloud metadata discovery and explicit verified retrieval with separately protected provider credentials.
  • Preview browser-fill/native-host safeguards with explicit origin/field mappings and one-time desktop confirmation.
  • Machine-managed enterprise policy with packaged ADMX/ADML templates.
  • Native iOS/Android prototypes and fail-closed credential/autofill boundaries validated in CI; mobile binaries are not included in this Windows release.
  • Integrated performance, legal/privacy, operational-readiness, packaging, and policy gates.

Verification

ADO CI build 284 passed from exact source commit c7c8cb3191e392901f1dc0c8271ab62a0947e758, including 370 Windows/shared tests, 44 managed mobile tests, native iOS application and credential-provider extension builds, Android Release App Bundle packaging, full-history secret scanning, dependency inspection, and Windows package gates.

ADO release build 287 created the release packages, checksums, SPDX SBOM, and Key Vault-backed Cosign bundles. All four package hashes and bundles were verified before publication. A credential-free download check then matched every one of the 13 public assets to the retained ADO artifact.

The exact public MSI passed all 27 installer-lifecycle gates on isolated Windows 11 Enterprise Evaluation 25H2: upgrade from 0.1.1-preview.1, deliberate post-InstallFiles failure rollback, successful upgrade, repair, downgrade rejection, uninstall cleanup, and retained local state.

Package hashes

PackageSHA-256
MSIDC15AF609EE6D55933551D24339DB914060E9616D40604D2AD9F10E7625EA4F2
Portable ZIP0C4017FC532704E5D3B86339A202C2A31E00D166972546216B5539A82F8F66F8
Chocolatey NUPKGD2C1A22C3CA13083B1C68D06D36D816326BC9505F90DD4BA9975499D61D584F9
WinGet manifest archive00EF9ED0DA0E56C9FB8FF43F9529A10FEDC13F335CC2899805520D41418F1DA2
SPDX SBOM4211191E9CB0FE67D380F3358EDE333AA470E1C62AB3DEDB81B8030AD68DFA80

Install and upgrade

  1. Download VaultProspector-0.2.0-preview.1-win-x64.msi, its .sha256, and its .sigstore.json from the public release page.
  2. Verify the SHA-256 and Cosign bundle as described in the release verification guide.
  3. Run the MSI and approve the administrator prompt.
  4. Windows displays Unknown Publisher because this Preview is intentionally unsigned.

The MSI ProductVersion is 0.2.1, with a new ProductCode and the stable Vault Prospector UpgradeCode. It upgrades 0.1.1-preview.1 (0.1.101). Uninstall retains %LOCALAPPDATA%\VaultProspector; delete that directory only when all local state should be removed.

Distribution status

  • Direct public MSI and ZIP downloads are available.
  • WinGet submission microsoft/winget-pkgs#407541 is open; catalog acceptance remains external and pending.
  • Two authenticated Chocolatey submissions returned HTTP 504. The package is not in the Chocolatey catalog, so choco install availability is not claimed.

Known Preview limitations

  • Use non-production resources. Live Azure/CyberArk matrices and independent security review are incomplete.
  • Trusted Authenticode signing remains required for stable/GA.
  • Browser integrations are validation-preview features and are not browser-store approved.
  • iOS and Android are source/CI prototypes only; no mobile app is distributed by this release.
  • Representative physical-device, accessibility, usability, legal/privacy approval, operational exercises, and stability windows remain open as listed in the readiness matrix.
  • Project-controlled telemetry is disabled. Do not include credentials, tokens, secret values, or sensitive identifiers in feedback.

See the user guide, Preview scope, release evidence, and release-readiness matrix.

Preview software. Direct packages are unsigned and display Unknown Publisher — verify the published SHA-256 before installing.