This release closes three analyzer bypasses that let destructive commands run, and adds CC_SAFETY_NET_PROJECT_TIGHTEN_ONLY=1 so a project policy can only tighten your own. The rule IDs reported for policy-config, policy-apply, and Git-metadata denials were renamed.
Highlights
- Added
CC_SAFETY_NET_PROJECT_TIGHTEN_ONLY=1, which makes a cloned repository's.cc-safety-net/policy.jsonunable to switch off protection you turned on. (#194) - Closed bypasses where
rm -rwithout-f, acaffeinate-wrapped command, and some GNUparalleltemplates escaped the checks their equivalent forms get. (#191, #188, #190) - Every denial now carries a stable rule ID, so
explain --json, the audit log, andcheckCommandalways identify which rule fired. (#193)
Added
- Added
CC_SAFETY_NET_PROJECT_TIGHTEN_ONLY=1. With it set, project policy settings that weaken the user policy — a lowered level, disabled capabilities, disabled protections, rules switched off, worktree relaxations, and added allow paths — are ignored, while the project file's tightenings still apply.statusanddoctorlabel the ignored deltas, and the statusline drops its weakening marker. The variable is listed in--helpanddoctor. (#194) - Added a
ruleIdto denials that previously reported none, including analysis and recursion limits, strict-mode parse failures, unsupported heredoc syntax, unverifiable dynamic shell sources, and working-directory denials.checkCommandnow always returnsruleIdon adenyresult. (#193) - Added a
doctorwarning when a legacy inline rule config (.safety-net.jsonor~/.cc-safety-net/config.json) still exists even though it is no longer loaded, naming the files and pointing tocc-safety-net rule migrate.
Changed
- Changed
find <subdir> -deleteto be allowed when its starting point resolves inside the workspace, matching whatrm -rf <subdir>already allowed.find . -delete, starting points outside the workspace,-Land-follow, and Git metadata in a repository stay blocked, as does any suchfind -deletewhile paranoidrmis on. (#192) - Changed the workspace scoping for
find -deleteto follow the effectiverm.recursive-force-paranoidrule state, so an override of that rule now applies identically torm -rfandfind -delete.
Fixed
- Fixed uninstalling the Kimi CLI hook writing an invalid TOML config when a commented-out hook preceded the managed entry. (#182)
Breaking Changes
- Renamed the rule IDs reported for the pre-analysis guards:
policy-protectionis nowguard.policy-config,policy-apply-protectionis nowguard.policy-apply, andgit-metadata-protectionis nowguard.git-metadata. This affects anything that matches onruleIdfromexplain --json, the audit log, or thecheckCommandlibrary API. Denial reasons and behavior are unchanged.- Migration: Update any dashboard, filter, or script that matches the old IDs to the new
guard.*names.
- Migration: Update any dashboard, filter, or script that matches the old IDs to the new
Security
- Fixed
rm -r,rm -R, andrm --recursivewithout-fskipping the target checks that the-rfforms get, so a recursive delete outside the current directory is now blocked, including throughxargsandparallel. Strict and paranoidrmrules now apply to these forms as well. (#191) - Fixed
caffeinate <command>not being unwrapped likenohupandtimeout, which let the wrapped command skip device, interpreter, and custom-rule checks. (#188) - Fixed GNU
paralleljob values not being shell-quoted the wayparallelitself quotes them, which let templates such asparallel {} ::: 'rm -rf /'andparallel 'sh -c {}' ::: 'rm -rf /'through. A quoted template with a very large job list also no longer exhausts the analysis budget, and such a template no longer picks up the linked-worktree relaxation. (#190)