v0.2.0 — Claude Code Automations
New Features
Auto-format Rust on save
PostToolUse hook runs rustfmt automatically when .rs files are edited via Claude Code. Includes jq availability guard and proper error reporting — if rustfmt fails, a warning is emitted instead of silently swallowing the error.
Block dependency file edits
PreToolUse hook prevents direct edits to Cargo.toml, Cargo.lock, package.json, pnpm-lock.yaml, and .env* files, enforcing CLI-based dependency management (cargo add/rm/upgrade, pnpm add/remove/update). Fails closed when jq is missing — edits are blocked as a precaution rather than silently allowed.
TDD cycle skill (/tdd-cycle)
Enforces test-driven development workflow with exact Red/Green/Refactor commands for both Rust unit tests (cargo test) and Playwright e2e tests. Defers to CLAUDE.md rules for testing policy, providing only the execution commands.
New command skill (/new-command)
Step-by-step checklist for adding new Tauri commands with correct AppContext/_cmd suffix patterns, HTTP route registration in dev_server.rs, and the axum Result<Json<T>, (StatusCode, String)> return pattern. Notes that test-server binary automatically picks up new routes.
Security reviewer agent
Burrow-specific security audit agent covering:
- API key exposure (OpenRouter key in config/chat)
- External process safety (command injection, timeout enforcement via
wait-timeout) - SQL injection (parameterized queries in history/vectors/indexer)
- Path traversal (file indexer directory walking)
- AppContext safety (optional
app_handleNone-handling)
Pre-push quality gate
lefthook pre-push hook runs full Playwright e2e test suite before allowing git push. Cargo test already runs in pre-commit, so pre-push focuses on the heavier e2e integration tests.
Full Changelog: v0.1.0...v0.2.0