0.50.0 — A foreground push asks first
🚦 A foreground push now asks first
A foreground git push ran with no prompt at all. The prose also called push the human's own, so agents stopped short and asked Mike to push.
The gate now prompts for a push on the same route as a commit. The human approves one exact command, in one directory, and it runs once.
🧱 The gate stopped parsing shell
Two review rounds tried to teach the gate more bash. Each round found new shell that it read wrong. The worst case was two apostrophes in # comments pairing up and hiding a commit and a push.
So the gate now sorts every command into three classes.
| Class | Example | Result |
|---|---|---|
| Plain form | git commit -m "...", git push origin main |
🔐 prompted |
| Could hide one | a comment, $(...), a loop, git pull && git push |
🛑 refused, with a request for the plain form |
| Everything else | git status, git log, gh pr view |
✅ passes |
The refusal test is a case-insensitive substring match with no parsing. No quote, comment, or line break can hide a verb from it.
🔒 What an approval is bound to
- A commit is bound to HEAD and the staged diff. It also covers the working tree when the commit takes files from there.
- A push is bound to its branches, tags, HEAD, and remote, branch, push and url config.
- Any change before the approved command runs voids the approval.
Force pushes and pushes that delete remote refs are refused outright, in every spelling git accepts.
📝 Also in this release
- The warmup and the develop, orchestrate and git-commit skills teach the plain form. Stage with its own
git add, and put a multi-line message in a scratchpad file for-F. - Sub-agents stay refused on every hidden shape, and the pipeline stays exempt.
- Shell aliases such as
gpstay outside the gate, and the README says so.