Skip to content

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 20:13
· 28 commits to main since this release
v0.2.0
2fd7d95

Newly blocked

Compared with 0.1.0, every change in the behavior fixtures (49 of 710 rows) is a new denial; no fixture that 0.1.0 denied is allowed now.

  • Credential files by any spelling. Credential names match regardless of case, so .ENV, ~/.AWS/credentials, and a Grep glob such as *.ENV are denied on a case-insensitive APFS volume. .env.test and .env.prod are denied; .env.example and .env.age stay allowed.
  • Directories that hold credentials. A search rooted at ~/.aws or ~/.gnupg is denied, as is cat ~/.aws/*. A search with no path operand (rg, ag, ack, grep -r) run from inside ~/.ssh is denied, and so are ls ~/.ssh and find ~/.ssh, which list private key names. Reading a private file under ~/.ssh through input redirection, including a case alias such as ~/.SSH, is denied; public keys, config, allowed_signers, and known_hosts stay readable.
  • Wildcards in directory names. ~/Lib*/Cont*/…, ~/Library/*/…, ~/Library/[C]ontainers/…, and ~/.s*/id_ed25519 are denied because the shell can expand them into App Data or private SSH material. ~/.s*/config and ~/Library/Preferences/*.plist stay allowed.
  • file:// URLs. curl reads file:// from disk, so the guard checks it as the path it names: curl file:///…/Library/Containers/… and curl file:///…/.env are denied.
  • Hidden-file searches. Recursive grep (-r, -d recurse, --directories=recurse), rg --hidden, rg -uu, rg -., and ag --hidden or ag -u are denied because they read dotfiles such as .env. A later -u no longer overrides rg --no-hidden.
  • Home-directory scans without a ~/.ignore. 0.1.0 denied rg and fd run from the home directory only when a flag such as --no-ignore was present, and otherwise relied on the user having a ~/.ignore that excludes ~/Library. Now rg, fd, ag, ack, and tree run from the home directory are denied on their own.
  • Working-directory tracking and case. cd --; rg … and rg … run from <symlink to an App Data tree>/.. are denied because both resolve to a broad scan. Lower-case library/containers in an unresolved expansion or in interpreter code is denied.

Fail-closed changes

  • A known tool whose input field is missing or not a string (command, file_path, or a non-string Grep path) is denied instead of passing. Tools the guard does not know still pass.
  • An empty or relative HOME is denied before the guard starts, and a HOME with a trailing slash no longer disables App Data matching.
  • A supervisor now owns the guard's process group and kills it, with its child processes, at the deadline. The outer watchdog fires 3 s after the supervisor reports the group, so the guard stays under Pi's 4.5 s hook timeout.
  • The package ships its tsconfig.json and refuses to start without it, so an ancestor tsconfig.json cannot redirect the shell parser.

Known limits are listed in AGENTS.md in the repository.