Direct v0.7.29
Immutable
release. Only release title and notes can be modified.
The semantic browser proxy now chooses outgoing network destinations only from the approved origins configured by its owner.
Changes
- Read the outgoing HTTP(S) and CONNECT host, port, and protocol from the approved origin, not the browser request; forward only the validated request path and query.
- Verify that a double-slash path and a conflicting Host header cannot change the destination. Keep foreign-origin denials, HTTPS handling, and cleanup unchanged.
Install
Install this version from its GitHub Release archive with Bun:
bun add --dev https://github.com/hraness/direct/releases/download/v0.7.29/hraness-direct-0.7.29.tgzOr install the same package from the npm mirror:
bun add --dev @hraness/direct@0.7.29Verify
SHA256SUMS lists the SHA-256 of hraness-direct-0.7.29.tgz, npm-pack.json, and release-manifest.json. provenance.jsonl holds the signed build provenance for those files and SHA256SUMS.
- Archive SHA-256:
bacf9fb18848845f7fb99fe560f9b63b1c4258865fdc9ec121b176976f50a4ca - Source commit:
ffb2de9a86b68d0c875724c29b102076a0dd0045
To check the checksums and provenance, follow the publishing guide for v0.7.29.