COMMITS
October 4, 2026
J
Merge pull request #209 from kenryu42/fix/opencode-posix-shell-check
J Liew committed
K
fix(opencode): keep the shell check quote-free and run it through Git Bash
kenryu42 committed
K
fix(opencode): end the shell check at its deadline, not at child exit
kenryu42 committed
K
fix(opencode): accept any POSIX shell by checking it, not its name
kenryu42 committed
J
Merge pull request #205 from kenryu42/fix/rule-write-home-scope
J Liew committed
K
test(rules): cover a first rule init through a symlinked home
kenryu42 committed
K
fix(rules): refuse project-scope rule writes from home
kenryu42 committed
K
fix(gui): refuse the user policy as the project draft from home
kenryu42 committed
K
fix(policy): refuse project-scope policy check and apply from home
kenryu42 committed
K
fix(policy): match the user policy through a symlinked home
kenryu42 committed
K
fix(policy): stop reading the user policy as a project policy from home
kenryu42 committed
October 3, 2026
K
docs(security): say which Devin hook failures let a call proceed
kenryu42 committed
K
fix(devin): accept the comments Devin allows in config.json
kenryu42 committed
K
feat(devin): protect Devin CLI sessions with a PreToolUse hook
kenryu42 committed
K
fix(droid): keep hooks.json on uninstall while settings.json exists
kenryu42 committed
K
fix(io): keep a replaced file's permission bits in atomicWriteFile
kenryu42 committed
K
fix(droid): keep settings.json fallback hooks and flag commandRegex drift
kenryu42 committed
K
feat(droid): protect Factory Droid sessions with a PreToolUse hook
kenryu42 committed
K
refactor(install): share PreToolUse hook entry handling from Grok Build
kenryu42 committed
K
feat(secret): protect Factory Droid and Devin CLI credentials and configs
kenryu42 committed
G
release: v2.5.2
github-actions[bot] committed
J
K
K
ci: run the dependency audit after earlier full-check failures
kenryu42 committed
K
ci: start packed-runtime with the source checks and audit dependencies last
kenryu42 committed
K
fix(policy): measure project capability weakenings against the session level
kenryu42 committed
K
K
feat(gate): give every deny a fixed rule id
kenryu42 committed
K
fix(gate): gate find -delete workspace scope on the paranoid rm rule state
kenryu42 committed
K
feat(gate): allow find -delete under a workspace subdirectory
kenryu42 committed