Skip to content

scode v0.2.0

Choose a tag to compare

@bindsch bindsch released this 25 Feb 21:17
· 25 commits to main since this release

What's new

Added

  • JSON audit log header — Log files now start with a machine-readable #json: line containing session metadata (command, blocked/allowed paths, timestamps). Extract with head -1 log | sed 's/^#json://' | jq .. Legacy comment header preserved for backward compatibility.
  • Property-based JS test suite — 82 tests for the shell tokenizer and --no-sandbox injector using fast-check (test/no-sandbox.test.js).
  • make test-js target — make test now runs both JS and bats suites. Gracefully skips when Node < 18.13 or node_modules is missing; set SCODE_REQUIRE_JS_TESTS=1 to force failure in CI.
  • Exhaustive YAML parser edge-case matrix (12 new tests).
  • Exhaustive audit-log parser edge-case matrix (17 new tests).

Fixed

  • --block now denies process-exec on macOS — previously only denied file-read*/file-write*, so a blocked binary could still be executed. Now blocks execution too.
  • -p flag parsing — command -p chromium and time -p chromium no longer break because -p was consuming the next argument.
  • bash -c -- "cmd" handling — Both JS preload injection and bash harness detection now correctly handle -- after -c.
  • Harness detection skips exec and env assignments — Patterns like exec claude, FOO=bar claude, A=1 B=2 claude now correctly detect the harness.

Changed

  • Restructured lib/no-sandbox.js for testability (pure functions above production guards, conditional module.exports).
  • Log header written by shared write_log_header_json() across macOS and Linux.
  • Log file first line is now #json:{...} instead of # scode session:. Legacy comment header follows on subsequent lines.

Full Changelog: v0.1.1...v0.2.0