Skip to content

v2.0.1 - security hardening

Choose a tag to compare

@LongNgn204 LongNgn204 released this 29 Jun 08:51

Hardening from an external code review: realpath root confinement (blocks symlink/junction escape), safe-mode git is read-only (mutations need AGENT_MODE=full), git_status/git_diff handle non-repos cleanly, and the audit log redacts secret/content fields. No breaking changes; full test suite 23/23.