Releases
Changelogs for safe-chains, workon, jjpr, branchdiff, specdiff · RSS
-
safe-chains v0.230.0 2026-09-03
- feat *(schema)* Optional_valued — a flag whose value is optional
- feat *(guards)* Enumerate long-flag arity mismodelling, and fix the four it found
- feat *(git)* Claim ls-files output as paths, and settle what modes v1 must decide
- feat *(pathgate)* Value-aware mode clauses, and dart format stops being Rust
- feat *(pathgate)* A when clause can re-role a flag's value, not only the positionals
- feat *(cli)* --suggest is informational and writes nothing
- feat *(refusal)* One builder for refusal copy, keyed on what we emit
- feat *(refusal)* Pin the advice to the behaviour with a grant-pairing guard
- fix *(docs+guard)* The proposed
$(which X)output claim is a fail-open, not a gap - fix *(pathgate)* The in-place formatters read by default, like the linters already did
- fix *(facet)* Derive an ordinal's hazard from its direction, and pin the trust ladders
- fix *(dispatch)* A File executor is governed by its own grammar unless it passes argv
- fix *(explain)* A denied compound names the command inside it
- fix *(targets)* --setup refuses a settings file it cannot read, instead of replacing it
- fix *(targets)* Grok and cursor self-filter; neither exemption survived checking
- fix *(grants)* A grant that NAMES a credential store opens it for reading
- fix *(pathgate)* A
whenclause stops scanning at--; refusal copy cannot forge a line - other Reorganize TODO.md around what this repo is responsible for
- other Re-measure the command-modes customers before building; four are served
- other Record why re-tokenizing split words is not built, with the blocker measured
-
safe-chains v0.229.0 2026-08-27
- feat *(log)* Give
statsits flag surface, fix --source arity, gate archive paths - feat *(ghostty)* Cover the read-only +action helpers
- fix *(parse)* Accept the
timekeyword before a compound command - fix *(tsc)* Accept the -p/-t/-m short spellings
- fix *(tsc)* Gate its file reads — both the --pretty quote and @response files
- other Remove superseded docs, finished TODO sections, and decorative comment bars
- feat *(log)* Give
-
safe-chains v0.228.0 2026-08-22
- feat *(php)*
-lis a lint, not an execution — and takes files, not flags - feat *(rails)* Per-database task variants, 28 of 56 no longer prompt
- fix *(engine)* Parse BSD's
sed -i '', which shifted every operand by one - fix *(fuzz)* The prefilter target compared a declared role against a positional the walk gates differently
- fix *(engine)* Project a level-eval pass to the band it earns, not always SafeWrite
- other *(suggest)* A shell keyword is not a command name
- other *(fuzz)* Sync fuzz/Cargo.lock, four versions stale
- other *(regions)* Stop shielding the decision log; record research findings; v0.228.0
- feat *(php)*
-
safe-chains v0.227.0 2026-08-16
- feat *(engine)* Make the
userlocus rung reachable, and shield what that exposes - feat *(regions)* Declare the credential dotfiles, then let home dotfiles be ordinary
- feat *(regions)* Shield /etc/ssh, where the host private keys live
- feat *(regions)* Classify raw devices and per-process /proc as what they are
- feat *(engine)* Open local reads to the machine rung
- feat *(regions)* Shield the decision log; correct the docs for the new read policy; v0.227.0
- fix *(engine)* Check unpinnability BEFORE the sentinel is rewritten away
- fix *(engine)* Correct the dotfile claim, and guard the sentinel fix that was untested
- fix *(engine)* Close the last four ways an unknowable read reached the shield uncleared
- fix *(regions)* Ten more credential dotfiles, and the measurement that questions the approach
- fix *(engine)* Bind find/fd -exec through the same stand-in the pipe uses
- fix *(engine)* Build dd's read from its path, so the shield is asked
- fix *(engine)* Fold macOS firmlinks, so /private/etc/shadow is /etc/shadow
- fix *(engine)* An unbounded read cannot be cleared by naming its root
- fix *(engine)* A glob and a glued placeholder name nothing the shield can check
- fix *(engine)* Two spellings that walked straight past the shield
- fix *(pathgate)* An ambiguously glued value is a guess, not a path
- fix *(engine)* One test for "the shield cannot clear this read", not two
- fix *(pathgate)* Gate the recursive copiers — rsync, ditto, pax
- fix *(engine)* Fold case on the firmlink prefix, for shields only
- fix *(cli)* A raw device is not a login-policy file, and say so
- fix *(test)* Two assertions that only held on macOS, caught by CI
- other *(design)* Write up relocation, and the locus a thing came FROM
- other *(engine)* Restate the read invariant as "the shield cannot clear it", not "it is outside the workspace"
- other *(policy)* Enforce the path corpus, which named a guard that never existed
- feat *(engine)* Make the
-
safe-chains v0.226.0 2026-08-15
- fix *(engine)* A read the credential shield cannot clear now says so, on the secret axis
-
safe-chains v0.225.0 2026-08-14
- feat *(log)* The decision log — an opt-in JSONL record of what safe-chains decided
- other *(design)* Denial log — what to capture at refusal time, and what an entry looks like
- other The user-facing logging page
- other Record three defects the decision log surfaced on its first day
-
safe-chains v0.224.0 2026-08-13
- feat *(pathgate)* Gate ungated output-flag writes with operation-aware roles
- feat *(pathgate)* Sub-scoped gates, and two guards that found live holes
- feat *(git)* Vet the diff display keys for
git -c - feat *(registry)* Sub-scoped stdout claims, so
grep $(git diff --name-only)works - feat *(cargo)* Accept the rustup toolchain selector (
cargo +nightly test) - fix *(allowlist)* A home grant covers both spellings of the same file
- fix *(registry)* A sub-scoped stdout claim follows every trusted spelling of its command
- fix *(git)* Gate
git diff's positionals — it was an ungated credential reader - other Name the command-mode concept and record the output-flag burn-down
- other Regenerate for the cargo toolchain selector examples
- other *(registry)* Make the path-named-flag guard compile, and record the 142 rows it was hiding
- other *(pathgate)* Cap the undeclared-valued-flag backlog a positional gate creates
-
safe-chains v0.223.1 2026-08-07
- fix *(registry)* Return errors from load_toml instead of panicking
- other *(registry)* Cover the validators mutation testing found unguarded
- other *(fuzz)* Run the nightly two hours earlier
- other Ignore cargo-mutants output, and record what it found
-
safe-chains v0.223.0 2026-08-05
- feat *(cargo)* Add cargo mutants, researched at 27.1.0
- feat *(levels)* Clamp permissions.allow coverage by the stated level
- fix *(commands)* Gate relocation flags at their locus
- fix *(systemctl)* Stand the read subs on their enumerated flags
- fix *(cli)* Confine --suggest's config write to the project
- fix *(cst)* Give explain its own classification budget
- fix *(cst)* Cap brace expansion on words produced, not brace count
- other *(safe-chains)* Describe --suggest in our own entry
-
branchdiff v0.74.0 2026-08-05
- other [**breaking**] Cache syntax highlighting instead of re-parsing every frame
- other *(repo)* Add mutation-testing setup and record its findings