Releases: iammurtaza53/hostlatch
Releases · iammurtaza53/hostlatch
Release list
HostLatch v0.2.0 — snapshot validation
HostLatch 0.2.0 adds complete repository snapshot auditing and publishes the project's first real-world corpus validation.
Highlights
--snapshotcompares the complete current tree with Git's empty tree.- Git index and tree-mode reads are batched, fixing the Windows scalability issue discovered during validation.
- A privacy-safe report covers 12 repositories, 2,359 files, 77 rule-fit findings, and recorded performance.
- Five public repository results are commit-pinned and reproducible; seven private repositories are aggregate-only.
- A dedicated project page, structured software metadata, robots policy, sitemap, and expanded package keywords improve discovery.
Verification
- 12/12 tests pass.
- CI passes on Ubuntu and Windows with Node.js 22.13 and 24.x.
- npm package dry run and JSON validation pass.
HostLatch remains an experimental public beta. Findings identify trust-handoff paths; they are not automatically confirmed vulnerabilities.
HostLatch v0.1.0 — activation scanning and quarantine bundles
HostLatch is an experimental trust-handoff firewall for AI-written repositories.
Highlights:
- Git-delta-aware activation scanning across committed, staged, unstaged, and untracked changes
- Explainable artifact → consumer → trigger → host-effect graphs
- Quarantine-first promotion bundles with content-hash verification
- Coverage for agent, IDE, package, Git, CI, container, shell, executable, and symlink activation surfaces
- Zero runtime dependencies and offline operation
- Passing Linux and Windows CI on Node.js 22 and 24
Try it:
git clone https://github.com/iammurtaza53/hostlatch.git
cd hostlatch
npm ci
npm run demoThis release is defense-in-depth software, not proof that a repository is safe. See SECURITY.md and docs/THREAT_MODEL.md.