You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Unknown command-line arguments now exit 2 with a usage message and stdin is not read. Earlier versions ignored them and classified stdin anyway. Consumers that detect an old binary should check for the matches key in match output rather than the exit code.
Added
bash-classify match --rules FILE: answers whether an expression invokes any of the command shapes in a YAML rules file (subcommand path prefix, except, any_option, any_arg_matches). Output is {"matches": [...], "parse_warnings": [...]}, exit 0. The caller decides what to do with a match; bash-classify still does not block anything. See the README section "Matching command shapes" and schemas/match-rules.schema.json.
Python API: load_rules, match_expression, Rule, Match, MatchResult, RulesError, and iter_invocations for walking every invocation of a result, including those nested under wrappers.
Every command in the JSON output carries options (flags present, including unmodelled ones) and positionals.
New delegation mode args_are_expression.
Options modelled for glab mr view, glab mr note, glab ci get|trace|view|status|list and glab api.
Changed
eval and exec are database entries with delegation instead of hardcoded builtins. Classification and risk stay DANGEROUS/HIGH; their inner command is now reported in inner_commands, matched_rule is set, and directories includes paths from the inner command.
parse_warnings now includes syntax errors found inside bash -c, sh -c, zsh -c and eval expressions at any wrapper depth, deduplicated.
Fixed
Commands written after a heredoc opener on the same line (cat <<EOF | cmd, cat > f <<EOF && cmd) were dropped silently; they are now extracted and classified. A ; or & in that position is a tree-sitter parse error and produces a parse_warnings entry.
SPEC corrections: exit code 1 means empty or timed-out stdin, not a parse error; heredoc bodies are dropped, not captured; the special-cased builtins table matches the code.