safe-chains releases
← Back to safe-chains · RSS
-
- feat *(allowlist)* Read .claude/settings.json from home only
- feat *(custom)* Gate project .safe-chains.toml on trusted-dir pin + hash
- other Specify trusted-customization model (project files require pinning)
-
- feat *(jj)* Allow read-only config path; document config-write risk
- other Reference HARNESS-BEHAVIORS.md from CLAUDE.md
-
- feat *(explain)* Surface per-segment chain breakdowns to agents
- other Add harness-behaviors maintainer reference
-
- feat *(node)* Allow node --check / -c syntax check
- fix *(policy)* Stop valued flags from swallowing option-like values
-
- feat *(xcode)* Accept xcodebuild build / test / archive actions
- feat *(xcode)* Accept xcodegen generate
- feat *(xcode)* Pod install / update / outdated / init / repo update
- feat *(xcode)* Simctl boot / shutdown / install / launch / openurl
- feat *(xcode)* Tuist generate / build / test / clean / install / edit
- feat *(xcode)* Xcrun delegates to inner-tool allowlists
- feat *(xcode)* Agvtool new-version / new-marketing-version / bump
- feat *(xcode)* Swiftformat accepts in-place rewrite mode
- feat *(xcode)* Swiftlint bare invocation + fix / autocorrect sub
- feat *(xcode)* Spctl accepts --verbose=N equals form
- feat *(xcode)* Codesign --entitlements / --requirements read-only forms
- feat *(xcode)* Lipo -create / -thin / -extract write side
- feat *(xcode)* Xcresulttool --legacy + promote export / merge to SafeWrite
- feat *(xcode)* Xccov merge promoted to SafeWrite
- feat *(tools)* Add Allume CLI (Mac note / board companion)
- feat *(vcs)* Add Epic Games' Lore VCS as research stub
- fix *(tools)* Safe-chains accepts hook <TOOL> form
- fix *(plutil)* -convert accepts -o <file> and in-place; add -extract sub
-
- feat *(containers)* Accept toolbx as alias for toolbox
- feat *(qpdf)* Add inspection / diagnostic flags
- feat *(tools)* Add
sem — semantic version-control CLI - feat *(ai)* Accept
antigravity as alias for agy and document models as candidate - feat *(ai)* Add Apple Foundation Models
fm CLI as research stub
-
- feat *(net)* Add
doggo — modern DNS client - feat *(net)* Add
ipcalc — CIDR calculator - feat *(pdf)* Add
pdfcrop — crop PDF to bounding box - feat *(pdf)* Add
pdfjam — n-up / scale / booklet / signature - feat *(net)* Add
wg — WireGuard query / keygen subcommands - feat *(tools)* Add
dot and Graphviz driver aliases - feat *(tools)* Add
pv — Pipe Viewer - feat *(net)* Add
yt-dlp and youtube-dl alias - other *(dasel)* Replace v2 denylist-based handler with a v3 TOML
- other *(pdftk)* Expand description with the actual operation grammar
- other *(weasyprint)* Add missing flags from upstream survey
- other *(net)* Refresh
researched_version to OpenSSH 10.x - other *(hurl)* Re-research against Hurl 8.0.1
-
- feat *(compile)* Add
lld and its driver aliases - feat *(pdf)* Add
pdfgrep — grep-style regex search inside PDFs - feat *(editors)* Add
vim and its driver aliases - feat *(editors)* Add
nvim - feat *(code)* Add
--add-mcp, --remove, singular --disable-extension, --pre-release - feat *(compile)* Add 7 LLVM utilities surfaced by the bucket audit
- feat *(ghostscript)* Add
ps2pdf, ps2pdf12/13/14, pdf2dsc wrappers - feat *(pdf)* Add
pdftoppm and pdftops Poppler tools - feat *(editors)* Add
nano and micro - feat *(compile)* Add
nasm, yasm, and as (GNU assembler) - feat *(editors)* Add
zed - feat *(editors)* Add
emacs - feat *(pdf)* Add
mutool — MuPDF's command-line companion - fix *(qpdf)* Remove erroneous standalone listings for strictly-valued flags
- other Bump action-gh-release to v3
- other *(compile)* Refresh researched_version across the bucket
- other *(pdf)* Refresh researched_version across the bucket
- other *(hx)* Refresh researched_version to Helix 25.07 and add
-v - other *(code)* Add
--disable-lcd-text, --disable-chromium-sandbox, --transient
-
- feat *(eval-safe)* Walker descends DispatchKind::Custom subs
- feat *(eval-safe)* Per-flag value allowlist for valued flags
- feat *(eval-safe)* Required-flag-from-set primitive
- feat *(eval-safe)* Harden schema after adversarial review
- feat *(aws)* Re-tag
configure export-credentials eval-safe (v0.196.0 untag fix) - feat *(fzf)* Tag shell-init flags eval-safe
- feat *(gh)* Add
gh completion <shell> sub and tag eval-safe
-
- feat *(starship)* Tag
starship init eval-safe - feat *(atuin)* Tag
atuin init eval-safe and add --disable-ai flag - feat *(ssh-agent)* Tag eval-safe at command level
- feat *(direnv)* Add
hook sub and tag eval-safe - feat *(zoxide)* Add
init sub and tag eval-safe - feat *(rbenv)* Allow
rbenv init - print mode and tag eval-safe - feat *(pyenv)* Allow
pyenv init - / --path print modes and tag eval-safe - feat *(fnm)* Add
env sub and tag eval-safe - feat *(conda)* Add
shell.<X> hook sub-sub for bash, zsh, fish and tag eval-safe - feat *(nodenv)* Add Node.js version manager with eval-safe
init - - feat *(goenv)* Add Go version manager with eval-safe
init - - feat *(mamba)* Add fast conda alternative with eval-safe
shell hook - feat *(aws)* Add
configure export-credentials sub-sub