Skip to content

v0.6.0 — per-repo config + policy ergonomics

Choose a tag to compare

@bjorges bjorges released this 05 Sep 17:46
· 116 commits to main since this release

Two usability features that make the fail-closed cage pleasant to live in.

Policy ergonomics (#23). When an egress request is blocked, the loop is now one line each: tjor denials shows what got blocked (host + rule) in a session, tjor policy add <host> widens your allow-list, and tjor policy <url> --explain says which policy decided and why. The proxy records each denied egress to a per-session denial log.

Per-repo config (#22). A repo can carry .tjor/policy.toml and .tjor/config.toml so a setup travels with the code — but because a repo config can widen the boundary, it is honored only after tjor trust approves its exact content (content-hash pinned; any edit revokes trust). tjor init scaffolds a starter .tjor/.

Also: a README pass (brew-install quickstart, the deny→add loop, per-repo config/trust). Full CHANGELOG in the repo.