Releases: batrapulkit/squidbrake
Release list
v0.7.1: usage stats switched on (only after a yes)
Anonymous usage stats from the first-run question (v0.7.0) now reach the Squidbrake team. Nothing changes for anyone who said no, or who turns it off: squidbrake telemetry off, SQUIDBRAKE_TELEMETRY=0 or DO_NOT_TRACK=1. What is sent: squidbrake telemetry status.
v0.7.0: one question on first run, so we can see what Squidbrake catches
The first time you run squidbrake in a terminal, it asks one question (Enter means yes):
Squidbrake can send anonymous usage stats to its team:
- which squidbrake commands run, the version, OS and country
- counts of what it checked, held and blocked: the program only (e.g. "rm"), the rule, and sizes
Never your commands, files, prompts, rules or keys. It shows one small team what to fix next.
Send anonymous usage stats? [Y/n]
- Asked once. Never asked in the agent hooks, scripts, CI or with
--yes, and nothing is sent from them until someone has said yes. squidbrake telemetry statusshows exactly what is sent;squidbrake telemetry off(orSQUIDBRAKE_TELEMETRY=0, orDO_NOT_TRACK=1) stops it.squidbrake register you@company.comtells the team who you are, if you'd like help rolling it out (asks first).- An install already in a pilot keeps its pilot.
Details: telemetry.py and pilot.py.
v0.6.10: fixes from the chain benchmark
Fixes from the new chain benchmark (bench/chains: normal permissions vs Squidbrake on 52 agent sessions).
Now held for a person:
- publishing to the world:
gh gist create --public,gh repo create --public,gh repo edit --visibility public - switching off backups or deletion protection (
--backup-retention-period 0,--no-deletion-protection, suspending S3 versioning) terraform apply/tofu apply(not only with -auto-approve) andpulumi up- SQL against a production database that writes or runs a file
Now runs on its own:
- deleting throwaway files (logs, .tmp, .bak, anything under tmp/)
- pushing a named feature branch (
git push -u origin fix/x); main, master, release, tags and force pushes still wait
New: a risk score (0-100) recorded on every event in shadow. It never changes a decision.
Benchmark: 30 of 31 harmful sessions stopped (an allowlist: 23), 2 false positives out of 34 everyday steps (an allowlist: 10).
v0.6.9: Cursor measures deletes in the open project
Cursor sometimes sends an empty working folder with a shell command. The hook now falls back to the open project, so a held
m -rf build\ shows how many files it would delete (and pilot stats can report it).
v0.6.8: pilot insights show what was caught
For teams in a pilot: besides daily counts, the gateway now shares what was held or blocked, as the program only (e.g. rm, git; never arguments, file names, content or notes), the rule and its reason, what happened, how long a person took, and the size of what it would have changed as numbers ("3 commits", "4,312 rows"). Hosted dashboards report every 2 minutes. squidbrake pilot status and the start page list exactly what is sent; leave anytime with squidbrake pilot leave.
v0.6.7: asking again goes back to a person
- When an agent asks again for something a person rejected, it now goes back to a person, flagged with their earlier "no" and note, instead of being refused with no way to say yes. Set
repeat_of_rejected: blockin rules.yaml for the old behaviour. An unedited rules.yaml updates on the next start. - When nobody approves in time, the agent is told exactly that (and where to approve), not that a rule blocked it.
v0.6.6: security fix for Cursor on Windows
Update now if you use Cursor on Windows. Cursor on Windows sends hook events with a UTF-8 byte-order mark. Squidbrake's hook couldn't read them and answered "allow" without checking, so Cursor's agent commands went through unchecked. The hooks now read events with or without the mark (and in any console code page), and an event they can't read is now blocked, not allowed.
Also: squidbrake doctor reads Cursor's own hooks log and says plainly that the agent (not you, typing in the terminal) has to run a command for the hook to be used.
To update: run the install command from your start page again, then squidbrake doctor.
v0.6.5: doctor reads Cursor's own log
squidbrake doctornow reads Cursor's own hooks log: it says whether Cursor has loaded Squidbrake's hook and whether Cursor has run it yet, and leaves out messages that aren't problems.- A connected Claude Code no longer shows as "not connected" in
doctorandconnect status(its hook's program and arguments are stored apart). doctorno longer counts the test suite's hook calls as real use.
v0.6.4: squidbrake doctor
squidbrake doctor: one command that checks everything end to end and says what to fix: the version, the dashboard your agents' hooks use, their key, and for every agent on the computer whether it's connected, whether its hook really runs (a harmlessechosent the way the agent sends it), Codex trust, and whether the agent has actually called the hook since it was connected. For Cursor it also shows the Cursor version and errors from Cursor's own hooks log. The start-page installers run it at the end.- The hooks note each call (which agent, which hook event, when; never the command, file or key) in
~/.squidbrake/hooks.log, so doctor can tell "connected but never used" from "working". - Shell guard:
squidbrake shell-guard install --shell bash|zsh|powershellprints a snippet that checks lines you type or paste into your own terminal: catastrophic ones are blocked, irreversible ones ask first. Thanks @vinayakpotdar79 (#61).
v0.6.3: easier install, clearer status
- The one-line installers on pilot start pages no longer depend on pipx. If Python 3.10+ is there, Squidbrake gets its own virtual environment; if not (macOS ships 3.9), uv installs it with a Python of its own. Any failure ends with a clear message saying what to do.
squidbrake connect statuschecks the dashboard your agents' hooks actually use (a hosted one too) and says plainly when their key is rejected, instead of suggesting you start a local gateway.