Repository navigation
Releases: alidaram99/donelatch
Release list
DoneLatch v0.1.2 — human-approved check configuration
DoneLatch v0.1.2 - human-approved check configuration
Fixes security finding S7: a coding agent could rewrite receipts.yml, then receive a completion-hook prompt telling it to execute those changed commands.
- Added donelatch trust: an interactive human review showing exact command/args and relevant policy, requiring the full SHA-256 approval phrase. Approval itself runs no checks; no piped/JSON/yes mode.
- Per-project approvals live in the OS user configuration directory outside the project and containing repository. They pin raw configuration bytes, parsed definitions/defaults, commands/argv, timeouts, markers/exit codes, faults and exclusions.
- run, faultcheck and verify-done require matching approval before using the loaded definitions. Changed or invalid definitions cannot execute through the CLI or core operations.
- All four completion adapters return a human-only refusal for unapproved/changed configuration, without instructions to run checks. Trust refusals do not become allows through ordinary retry flags.
- Deleted approved policies and new nested Git metadata cannot silently opt out. Genuine never-configured projects still opt in explicitly. Malformed Cursor input now reaches refusal instead of an empty response.
- Linked approval directories/files and hardlinks are refused; reviewed hashes are checked again before writing. Corrupt ordinary JSON can be replaced after explicit review. Review output escapes terminal and bidi controls.
- All installation lines and manifests use v0.1.2; source bundles remain self-contained and free under MIT. Tests/demo use isolated fixture approval stores, not personal approvals.
Migration: existing projects need a human to review and run donelatch trust once before running checks. Every configuration change requires re-review. Ordinary source edits still require fresh evidence.
Boundaries: hooks are cooperative guardrails; host limits may end an UNVERIFIED turn. Approval does not pin referenced script contents, PATH/executable resolution or inherited environment. Same-user code can alter approval files/verifier or automate a terminal; the prompt is not human authentication. Temporary copies are not security sandboxes, and local signatures are not independent attestation. No hosted paid service is included.
See the approval guide, agent installation, and security boundaries.
DoneLatch v0.1.1 — Gemini extension and discovery
DoneLatch v0.1.1
Discovery and Gemini CLI extension release. The v0.1.0 completion-evidence engine is unchanged.
- Root
gemini-extension.json,GEMINI.md, and a nativeAfterAgenthook; install from the tagged public repository. - Shared native hook file preserves Claude's
Stophook. Each host skips the other host's event with an unknown-event warning. Do not also install the manual Gemini hook. - Direct-answer website copy, visible FAQ with matching JSON-LD, search/AI crawler directives, sitemap, and AI-reader summary.
- Links to the team's other tools; a scoped IndexNow key and post-deployment notification.
- Regression coverage invokes Gemini's actual shipped command, including the quoted extension path, on real passing and stale receipts.
Included from v0.1.0:
init,run,faultcheck, andverify-done;receiptsanddonelatchcommand aliases.- Current watched-file/configuration/Git binding, latest-failure supersession, Ed25519 receipt signatures and hash chaining.
- Configured behavioral faults in independent temporary copies, with healthy baseline calibration and explicit assertion marker/exit-code detection.
- Claude Code marketplace/plugin, Codex plugin/skill/catalog, Gemini AfterAgent and Cursor stop adapters; capped correction and honest UNVERIFIED output.
- Self-contained runtime bundles, working without npm-installed dependencies in a cloned plugin cache.
- Reproducible persistence demo: weak check refused, strong check accepted, later edit refused.
- Local tests and independent review; public CI runs Node.js 24 on Windows and Linux.
Requires Node.js 24+. Distributed via this GitHub repository and release, not the npm registry.
Hooks are cooperative guardrails. They can be bypassed or fail open, and the host may stop after the one-turn retry cap. Local signatures are not independent attestation. Configured commands are trusted; temporary copies are not a security sandbox. No telemetry, paid service, universal correctness guarantee, or automatic Orcheri modification is included.
See installation, verification, and security boundaries.
DoneLatch v0.1.0 — current evidence before accepted done
DoneLatch v0.1.0
Free local completion-evidence CLI and coding-agent hook plugin.
init,run,faultcheck, andverify-done;receiptsanddonelatchcommand aliases.- Current watched-file/configuration/Git binding, latest-failure supersession, Ed25519 receipt signatures and hash chaining.
- Configured behavioral faults in independent temporary copies, with healthy baseline calibration and explicit assertion marker/exit-code detection.
- Claude Code marketplace/plugin, Codex plugin/skill/catalog, Gemini AfterAgent and Cursor stop adapters; capped correction and honest UNVERIFIED output.
- Self-contained runtime bundles, working without npm-installed dependencies in a cloned plugin cache.
- Reproducible persistence demo: weak check refused, strong check accepted, later edit refused.
- Local tests and independent review; public CI runs Node.js 24 on Windows and Linux.
Requires Node.js 24+. Distributed via this GitHub repository and release, not the npm registry.
Hooks are cooperative guardrails. They can be bypassed or fail open, and the host may stop after the one-turn retry cap. Local signatures are not independent attestation. Configured commands are trusted; temporary copies are not a security sandbox. No telemetry, paid service, universal correctness guarantee, or automatic Orcheri modification is included.
See installation, verification, and security boundaries.