devtrim 0.6.3
·
28 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Changed
- Global mutation flags are now capability-scoped: report-only commands reject flags they cannot honor, while
scan --shredand Trash purge retain only their meaningful controls - Docker and simulator cleanup now reject
--shredinstead of accepting a flag that cannot affect their exact typed command actions - Release version validation now checks the authoritative changelog heading and exact, unique README and manual version declarations instead of accepting substring matches
Fixed
- The TUI now filters configured protected Trash items before it calculates danger or asks for approval
- Bare
devtrim --jsonnow rejects the implicit TUI before terminal launch, matching explicitdevtrim tui --jsonand preserving automation-only JSON behavior - A present but missing, broken, escaping, or otherwise invalid
swift-latest.xctoolchainreference now blocks toolchain cleanup instead of producing an empty successful scan - The production landing page now points to the actual stable v0.6.2 archive and release while the v0.6.3 candidate is in beta staging
Security
- Human command previews escape the complete action string, closing terminal control-character injection through dynamic but validated command arguments without altering JSON data
- Xcode and Swift toolchain apply now reassert each scanner's exact direct-child target shape before the shared deletion sink, so a forged nested finding cannot borrow the category's authority
- Release verification passed current and MSRV suites, strict Clippy, structural positive controls, root and fuzz dependency audits, all five 60-second fuzz targets, the arm64 build, PTY cancellation, workflow/shell/secret gates, P3 autoreview, Matt Pocock standards/spec review, video build/render/container checks, desktop/mobile browser checks, and a fresh independent verifier