Skip to content

Releases: amplify-lab/damping

v0.8.0

Choose a tag to compare

@github-actions github-actions released this 17 Jul 20:11

Changelog

  • 4b5272e docs(readme): illustrate the dashboard update-available badge and confirm modal
  • 0e05b36 feat(policy): catch the GPT-5.6 Codex $HOME-deletion class across every spelling

v0.7.1

Choose a tag to compare

@github-actions github-actions released this 11 Jul 14:58

Changelog

  • 2c8e5f2 docs(readme): refresh dashboard screenshots to show the version in the header

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 11 Jul 14:21

Changelog

  • 3553a15 feat(cli): damping update, background version check, Windows installer
  • bfa59fa feat(dashboard): version display, one-click self-update, audit cache
  • a1753c8 fix(shell): close four AST-walker policy-bypass classes

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 11 Jul 05:26

Changelog

  • 158a158 docs(readme): refresh dashboard screenshots for v0.4.1, document session click-to-filter
  • 773a75c feat(policy): add destructive.cloud_api_raw_delete (PocketOS incident) — 28th default rule

v0.4.1

Choose a tag to compare

@github-actions github-actions released this 10 Jul 17:26

Changelog

  • 083e753 fix(dashboard): replace confusing "settled/active" session badge with a risk-level dot, add click-to-filter

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 10 Jul 15:37

Changelog

  • 275e093 docs(readme): refresh dashboard screenshot for the new UI, add a zh-TW variant
  • edc0951 feat(cli): add bilingual (EN/繁體中文) CLI — init --lang, TTY prompt, policy test
  • 994a534 feat(dashboard): add keyword search, pagination, policy explainer, and bilingual UI

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 10 Jul 10:43

Changelog

  • 78f78da docs(readme): Homebrew is live — correct the install command and close the gap
  • 12347af docs(readme): lead with install/quick-start, add a Traditional Chinese translation
  • 488fe74 docs(readme): rewrite the zh-TW translation in natural spoken Taiwanese Chinese
  • 5a42234 docs(security): update the vulnerability-report contact email
  • 71c95ad feat(policy): add agent-asset-protection rule family
  • 486ab95 feat(policy): split rm -rf protection into critical vs medium risk tiers
  • df3eed3 fix(shell): close command-wrapper, interpreter-script, pipeline-stage, and compound-command AST bypasses

v0.2.1

Choose a tag to compare

@github-actions github-actions released this 07 Jul 09:11

Changelog

  • df23042 docs(readme): note CI is now actually green as of v0.2.0
  • c32533b feat(dashboard): refresh sessions/stats on live events, not just a timer
  • 66dccf2 feat(doctor): warn when a policy.yaml is missing rules from the current default
  • 552bf16 fix(ci): bump golangci-lint-action v6 -> v9 (v6 cannot run golangci-lint v2 at all)
  • 5f4b669 fix(ci): correct golangci-lint-action version syntax, pin gosec off @master
  • a541549 fix(ci): pin golangci-lint-action to v2, matching go.mod's go 1.26
  • 3cf666d fix(ci): skip the sub-ms OPA benchmark under -race, run gosec natively not via Docker
  • fef844b fix(release): set replace_existing_artifacts so a rerun isn't blocked by its own prior partial success
  • fb47047 fix: Claude Code was misattributed as "codex" in every audit record

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 06 Jul 18:53

Changelog

  • 3715143 docs(readme): add deployment guide and release process, both real-verified
  • 8762487 feat: M1 compliance-report demo — zero new infra, real shipped rules only
  • 9a1431a feat: risk-tiered non-interactive fallback, dashboard stats/charts, compliance-report HTML

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 06 Jul 13:50

Changelog

  • 671b082 docs(architecture): sync shell/MCP sections and repo tree with this session's fixes
  • 53c8ed3 docs(bdd): soften overpromising Gherkin wording for disclosed pass-through steps
  • 5484f51 docs(ci): fix release.yml comment's stale brews: reference
  • 22a539c docs(claude.md): clarify the external materials folder is an active planning hub, not just an archive
  • b7dc586 docs(claude.md): codify README public-only scope + current repo status
  • 8b22e91 docs(claude.md): describe damping/ as one product under a shared project root
  • 06b900b docs(claude.md): remove private-process content, keep only repo-specific technical conventions
  • c7b070e docs(cli-reference): fix hook contract, policy schema drift, dashboard, --follow contradiction
  • 5fc3c83 docs(readme): add the competitor comparison table the plan doc requires
  • 0e7ad15 docs(readme): document the BDD development process
  • 32b7461 docs(readme): expand quick-start into a real 5-step tutorial with a live dashboard screenshot
  • 9e4dcd4 docs(readme): fix stale dangerous_command.feature scenario count (20 → 24)
  • 4a39d0c docs(readme): sync shell-detection description and scenario count with reality
  • 3f6f1ee docs(security): document damping dashboard's threat model and reporting scope
  • c8f5668 docs(threat-model): correct degraded-event check's actual semantics
  • 211c129 feat(cli): implement documented UX that was never actually built (init/off transcripts)
  • 53580b4 feat(dashboard): add ?limit= to /api/events for CLI/dashboard parity
  • 7feee2b feat(dashboard): add damping dashboard — a local, single-user audit-log viewer
  • 035aa35 feat(dashboard): add row-click detail view for the full ActionEvent
  • c1446e7 feat(log): add "damping log --follow" (tail -f style live streaming)
  • 9a9ad34 feat(mcp): persist "always allow/deny" choices for MCP tool calls
  • 23f8c22 feat(policy): add embedded OPA/Rego policy engine (Phase 3)
  • 3051745 feat: add 4 new dangerous-command rule categories, fix a real OPA-parity bug
  • 3d3981b feat: add real Codex support, consolidate agent detection into a registry
  • 08dd0f8 feat: add release engineering (GoReleaser, install.sh, release CI)
  • 4abaaaf feat: implement damping mcp wrap + always-allow/deny persistence (Phase 1 complete)
  • 4531c68 feat: initial Damping V1 scaffold — core engine, CLI, docs, BDD
  • 567cb55 feat: intercept Claude Code Write/Edit/MultiEdit tool calls, not just Bash
  • 328d377 feat: wave 2 dangerous-command coverage — kubectl/cloud-CLI/disk/publish/webhook
  • d0f17a1 fix(agent): --force no longer wipes unrelated PreToolUse hook entries
  • 1562d67 fix(agent): stop truncating Claude Code/Cursor settings files on write
  • bc3c755 fix(agent): write the required top-level "version" field to hooks.json
  • 6680cc3 fix(audit): seed Follow's rotation detection with the caller's real stat
  • 9d95c03 fix(audit): tolerate a torn trailing write instead of erroring ReadAll
  • c202727 fix(audit): wire Rotate into Append, fix a same-second rename collision
  • f139bfe fix(bdd): actually verify the --for 30m duration and auto-reenable in self_protection.feature
  • 9c82ccd fix(bdd): guard against a stale w.decision in self_protection_test.go
  • 3caeb56 fix(bdd): isolate local_dashboard_test.go from real machine state
  • ad32ede fix(bdd): stop mcp_tool_governance_test.go from polluting the real audit log
  • 596c3c0 fix(bdd): strengthen 3 weak/no-op steps in dangerous_command.feature
  • b31dc7b fix(bdd): strengthen audit_log.feature's prompt-decision assertion, disclose degraded-crash simulation
  • bfda252 fix(cmd,dashboard): surface audit-log read errors instead of a false all-clear
  • 7624dce fix(dashboard): clear the truncated-note when an events fetch fails
  • 2283bf7 fix(dashboard): fix misleading spec citation, add dialog focus management
  • c6d3c06 fix(dashboard): roving tabindex on the event table, not one Tab stop per row
  • 2a4f678 fix(hook): actually evaluate Cursor commands (was silently allowing all of them)
  • 5c15d7d fix(hook): recover() around shell-parser analysis instead of relying on Go's default panic exit code
  • 58bb2e1 fix(log): mark degraded events visually in the plain-table view
  • 424387a fix(mcp): close a race in always-allow/deny persistence
  • ff2faab fix(mcp): stop silently discarding audit failures and respect damping off
  • 742b02a fix(policy): check every rm -rf path operand, not just the last word
  • f059c5e fix(policy): recognize base32/uudecode/xxd -r/openssl decode pipelines
  • ebdbb71 fix(policy): recognize real MongoDB destructive operations via mongosh
  • 641ace8 fix(policy): refuse to auto-persist an always-pattern ending in "*"
  • c4004da fix(policy): reject an unrecognized rule risk at config load time
  • 12be536 fix(policy): scope damping_off_attempt to the subcommand position
  • 1e0ab5f fix(policy,event): carry each rule's declared risk into RiskLevel
  • 8a27c54 fix(shell): detect destructive commands hidden in substitutions and heredocs
  • 27fcd6b fix(shell): resolve aliases consistently in pipeline stages; fix doc overclaim
  • 8c7eaf9 fix(status): warn on the headline ON line when the policy fails to load
  • 554dabb fix(status,on): non-zero exit on broken policy; warn on damping on too
  • 626f52e fix: address HIGH/MEDIUM findings from adversarial code review
  • b959677 fix: address findings from release engineering review
  • 018f3a8 fix: address the first real golangci-lint/gosec findings, ever
  • 1fdbea5 fix: log degraded instead of silently allowing unrecognized hook agents
  • 6177c65 harden(audit): cap ActionEvent.Raw so Append stays within Go's single-syscall guarantee
  • 3734430 refactor(audit): extract ParseFilter for CLI/dashboard vocabulary parity
  • 5e3ba67 refactor(cli): extract enforcement.IsDisabled + paths.ClaudeSettings/CursorHooks
  • 40dcac2 test(agent): assert writeJSONObject's actual permission bits
  • b36bb8d test(bdd): wire every V1-scope feature file to real godog execution
  • baba928 test(shell): add native Go fuzz coverage for the shell parser
  • 73aaffb test(shell): seed the fuzzer with the new substitution/heredoc bypass shapes