Skip to content

scode v0.1.0

Choose a tag to compare

@bindsch bindsch released this 25 Feb 21:18
· 27 commits to main since this release

Initial beta release

  • Cross-platform sandboxing via sandbox-exec (macOS) and bubblewrap (Linux).
  • Default mode (allow-default with deny rules) and strict mode (deny-default with allow rules).
  • Config-driven policy support (~/.config/scode/sandbox.yaml) and project configs (.scode.yaml).
  • 20+ default-blocked paths covering credentials, cloud tokens, password managers, and personal files (35+ on Linux).
  • Environment scrubbing (--scrub-env) strips 30 token patterns including wildcards like AWS_*.
  • Browser no-sandbox preload — patches child_process.spawn, spawnSync, exec, execSync, execFile, execFileSync for Chromium binaries.
  • Trust presets (--trust trusted/standard/untrusted).
  • Audit tooling: scode audit parses denial logs, scode audit --watch tails in real-time.
  • Known harness auto-detection (opencode, claude, codex, goose, gemini, droid, qwen, codemux, pi).
  • Strict mode auto-allows harness config directories and macOS Library carve-outs.
  • Automated test suite and release gate checklist.