Releases
v0.1.0
Compare
Sorry, something went wrong.
No results found
Initial beta release
Cross-platform sandboxing via sandbox-exec (macOS) and bubblewrap (Linux).
Default mode (allow-default with deny rules) and strict mode (deny-default with allow rules).
Config-driven policy support (~/.config/scode/sandbox.yaml) and project configs (.scode.yaml).
20+ default-blocked paths covering credentials, cloud tokens, password managers, and personal files (35+ on Linux).
Environment scrubbing (--scrub-env) strips 30 token patterns including wildcards like AWS_*.
Browser no-sandbox preload — patches child_process.spawn, spawnSync, exec, execSync, execFile, execFileSync for Chromium binaries.
Trust presets (--trust trusted/standard/untrusted).
Audit tooling: scode audit parses denial logs, scode audit --watch tails in real-time.
Known harness auto-detection (opencode, claude, codex, goose, gemini, droid, qwen, codemux, pi).
Strict mode auto-allows harness config directories and macOS Library carve-outs.
Automated test suite and release gate checklist.
You can’t perform that action at this time.