Originally created by: fu351
Cuts the current Unreleased section into v0.18.2 and bumps pyproject.toml (0.18.1 → 0.18.2).
The secret detector was firing spurious approval prompts on ordinary identifiers, paths, and UUIDs — the biggest source of click-through fatigue and a real churn factor. This release fixes that (raise-only: every real credential still fires) and makes the rule self-check at import and fail closed if it's ever broken. See [#464].
Unreleased (dashboard per-project tab title, the [#399] macOS GUI-dialog thread-safety fix, the river cap).main is green (the FP fix landed via [#464] with full CI green).--suite synthetic --profile before_after): attacks_stopped = 1.0, unchanged — the fix only removes false AUTH prompts on benign shapes and touches no BLOCK verdict, so detection is unaffected. No BENCHMARKS.md change needed.gh release create v0.18.2 → the publish.yml OIDC Trusted-Publishing flow builds + uploads to PyPI, gated by the pypi GitHub Environment's human approval.
🤖 Generated with Claude Code
Ticket changed by: fu351