v0.2.4 — security hardening + namespace-e2e CI + ADR #58
Security release (outer-ring dual review findings)
🔴 Blocker fixed — project-venev binary execution
detect_toolchain.resolve_tool fell back to executing <project>/.venv/bin/<tool> — a hostile repo could commit an executable there and have the gate run it with the user's full privileges (armed exactly when the tool was absent from PATH). Now PATH-only (per-project opt-in: SF_PROJECT_VENV_TOOLS=1). loop_state_path fails closed likewise. The CC reference implementation still carries both — ledgered as a SECURITY OUTFLOW candidate.
🟠 Major fixed — $-splice gate bypass
String.replace interprets $& $
Carve-out reachability + CI
- ADR #58 mapping carve-out now reachable through the pi bridge (ccPayload translates pi edits → CC Edit/MultiEdit shapes)
- New
namespace-e2eCI job: pi.namespace composition proven against the maskshell/pi fork build (7/7) — the #8834 landing detector - sf-hooks: mkdtemp temp hygiene, once-cached absolute ruff (TOCTOU + PATH-swap hardened), hard timeout bounds everywhere, decode-safe paths
Selftest 15/15; all gates + CI green.