Documented changes
12 typed entries
Verified contributors
1 verified contributor · 3 credits
Attribution coverage
attribution complete; history inventory partial.
Install
Scope
Guard v2.1.0a54 is a preview release published 2026-07-22. Upstream documents: Guard 2.1.0a54 is an opt-in prerelease cut from [`ba3ec14`](https://github.com/hashgraph-online/hol-guard/commit/ba3ec1414c711b58145fd91e07b2ae68fb315d7f). Stable installations remain on the stable channel. **2 commits • 2 merged pull requests • 1 contributor** since [Guard 2.1.0a53](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v2.1.0a53). Its comparison base is alpha/v2.1.0a52. It includes 3 verified contribution deliveries with public evidence links.
Changes
Fixed
8- **guard**: Compose bounded read-only shell workflows ([#1839](https://github.com/hashgraph-online/hol-guard/pull/1839)) Evidence for: **guard**: Compose bounded read-only shell workflows ([#1839](https://github.com/hashgraph-online/hol-guard/pull/1839))
- compose bounded metadata, source-inspection, filter, and status-marker segments into one verified read-only decision Evidence for: compose bounded metadata, source-inspection, filter, and status-marker segments into one verified read-only decision
- add typed validation for multi-step remote run inspection while keeping derived text and identifiers out of executable or mutating positions Evidence for: add typed validation for multi-step remote run inspection while keeping derived text and identifiers out of executable or mutating positions
- preserve review for mutations, local writes, custom hosts, dynamic execution, sensitive reads, executable Git configuration, and unbounded output Evidence for: preserve review for mutations, local writes, custom hosts, dynamic execution, sensitive reads, executable Git configuration, and unbounded output
- **guard**: Prevent stale runtime token refresh ([#1838](https://github.com/hashgraph-online/hol-guard/pull/1838)) Evidence for: **guard**: Prevent stale runtime token refresh ([#1838](https://github.com/hashgraph-online/hol-guard/pull/1838))
- prevent an outdated long-running Guard process from refreshing shared OAuth credentials after the package is upgraded Evidence for: prevent an outdated long-running Guard process from refreshing shared OAuth credentials after the package is upgraded
- simplify revoked-session recovery to the self-repairing `hol-guard connect` flow Evidence for: simplify revoked-session recovery to the self-repairing `hol-guard connect` flow
- align dashboard recovery guidance with the CLI Evidence for: align dashboard recovery guidance with the CLI
Other changes
4- Documented change: Guard 2.1.0a54 is an opt-in prerelease cut from [`ba3ec14`](https://github.com/hashgraph-online/hol-guard/commit/ba3ec1414c711b58145fd91e07b2ae68fb315d7f). Stable installations remain on the stable channel. **2 commits • 2 merged pull requests • 1 contributor** since [Guard 2.1.0a53](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v2.1.0a53). Evidence for: Documented change: Guard 2.1.0a54 is an opt-in prerelease cut from [`ba3ec14`](https://github.com/hashgraph-online/hol-guard/commit/ba3ec1414c711b58145fd91e07b2ae68fb315d7f). Stable installations remain on the stable channel. **2 commits • 2 merged pull requests • 1 contributor** since [Guard 2.1.0a53](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v2.1.0a53).
- Merged pull request #1837: fix(codex): keep global hooks workspace neutral (#1837) Evidence for: Merged pull request #1837: fix(codex): keep global hooks workspace neutral (#1837)
- Merged pull request #1839: fix(guard): compose bounded read-only shell workflows (#1839) Evidence for: Merged pull request #1839: fix(guard): compose bounded read-only shell workflows (#1839)
- Merged pull request #1838: fix(guard): prevent stale runtime token refresh (#1838) Evidence for: Merged pull request #1838: fix(guard): prevent stale runtime token refresh (#1838)
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: alpha/v2.1.0a52
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Contributors
- @kantorcodes
Implementation · 3 credits
Evidence ledger3 credits
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author