Documented changes
35 typed entries
Verified contributors
Credits being verified. Attribution coverage is in progress.
Attribution coverage
attribution in progress; history inventory partial.
Install
Scope
Guard v3.0.1a1 is a preview release published 2026-08-27. Upstream documents: Guard 3.0.1a1 is an opt-in prerelease cut from [`b072ee1`](https://github.com/hashgraph-online/hol-guard/commit/b072ee11ded68443e92c8ecdb02e6765a8c0cdfd). Stable installations remain on the stable channel. **10 commits • 8 merged pull requests • 2 contributors** since [Guard 3.0.0a290](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v3.0.0a290). Its comparison base is alpha/v3.0.0a290. It includes 10 verified contribution deliveries with public evidence links. Attribution for this release is being ve
Changes
Added
8- Apply signed custom extension continuity ([#2635](https://github.com/hashgraph-online/hol-guard/pull/2635)) Evidence for: Apply signed custom extension continuity ([#2635](https://github.com/hashgraph-online/hol-guard/pull/2635))
- parse and apply the signed, device-bound Custom Extension continuity v2 projection Evidence for: parse and apply the signed, device-bound Custom Extension continuity v2 projection
- advertise continuity capability only when protected local authority and all Managed Controls prerequisites are active Evidence for: advertise continuity capability only when protected local authority and all Managed Controls prerequisites are active
- preserve local tightening and explicit removals while rejecting stale, mutated, cross-workspace, cross-device, or malformed projections Evidence for: preserve local tightening and explicit removals while rejecting stale, mutated, cross-workspace, cross-device, or malformed projections
- **guard**: Make Rust authoritative for PreToolUse batch 1 ([#2602](https://github.com/hashgraph-online/hol-guard/pull/2602)) Evidence for: **guard**: Make Rust authoritative for PreToolUse batch 1 ([#2602](https://github.com/hashgraph-online/hol-guard/pull/2602))
- Supported command PreToolUse decisions now come from the compiled Rust runtime (`pre-tool --stdin` and resident `pre_tool_use`). Evidence for: Supported command PreToolUse decisions now come from the compiled Rust runtime (`pre-tool --stdin` and resident `pre_tool_use`).
- Python transports and renders that native result, applies it as a CLI policy floor, and fails closed when a present or forced native runtime cannot decide. Evidence for: Python transports and renders that native result, applies it as a CLI policy floor, and fails closed when a present or forced native runtime cannot decide.
- Retired the unused migration applicators and coordinator workflows that failed quality, hygiene, and YAML checks. Evidence for: Retired the unused migration applicators and coordinator workflows that failed quality, hygiene, and YAML checks.
Improved
1- **guard**: Retire legacy cloud review commands ([#2632](https://github.com/hashgraph-online/hol-guard/pull/2632)) Evidence for: **guard**: Retire legacy cloud review commands ([#2632](https://github.com/hashgraph-online/hol-guard/pull/2632))
Fixed
11- **release**: Advance 3.0 patch prerelease train ([#2640](https://github.com/hashgraph-online/hol-guard/pull/2640)) Evidence for: **release**: Advance 3.0 patch prerelease train ([#2640](https://github.com/hashgraph-online/hol-guard/pull/2640))
- advance the `release/3.0` prerelease line to `3.0.1aN` after stable `3.0.0` Evidence for: advance the `release/3.0` prerelease line to `3.0.1aN` after stable `3.0.0`
- preserve the protected release branch while preventing post-stable merges from becoming unpublishable Evidence for: preserve the protected release branch while preventing post-stable merges from becoming unpublishable
- cover first and subsequent patch-alpha computation plus exact release validation Evidence for: cover first and subsequent patch-alpha computation plus exact release validation
- **guard**: Explain native action consequences ([#2638](https://github.com/hashgraph-online/hol-guard/pull/2638)) Evidence for: **guard**: Explain native action consequences ([#2638](https://github.com/hashgraph-online/hol-guard/pull/2638))
- explain the concrete consequences of destructive native tool actions Evidence for: explain the concrete consequences of destructive native tool actions
- preserve classifier-specific risk explanations for other sensitive actions Evidence for: preserve classifier-specific risk explanations for other sensitive actions
- use the same explanation in review summaries and risk signals Evidence for: use the same explanation in review summaries and risk signals
- **guard**: Observe sourced scripts in compound shell commands ([#2612](https://github.com/hashgraph-online/hol-guard/pull/2612)) Evidence for: **guard**: Observe sourced scripts in compound shell commands ([#2612](https://github.com/hashgraph-online/hol-guard/pull/2612))
- Observe user scripts that are sourced or launched inside compound shell commands so they can be offered as custom extensions. Evidence for: Observe user scripts that are sourced or launched inside compound shell commands so they can be offered as custom extensions.
- Apply an enrolled custom-extension grant when a later compound command sources or launches that same script. Evidence for: Apply an enrolled custom-extension grant when a later compound command sources or launches that same script.
Other changes
15- Documented change: Guard 3.0.1a1 is an opt-in prerelease cut from [`b072ee1`](https://github.com/hashgraph-online/hol-guard/commit/b072ee11ded68443e92c8ecdb02e6765a8c0cdfd). Stable installations remain on the stable channel. **10 commits • 8 merged pull requests • 2 contributors** since [Guard 3.0.0a290](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v3.0.0a290). Evidence for: Documented change: Guard 3.0.1a1 is an opt-in prerelease cut from [`b072ee1`](https://github.com/hashgraph-online/hol-guard/commit/b072ee11ded68443e92c8ecdb02e6765a8c0cdfd). Stable installations remain on the stable channel. **10 commits • 8 merged pull requests • 2 contributors** since [Guard 3.0.0a290](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v3.0.0a290).
- **guard**: Bind managed controls projection vector ([#2626](https://github.com/hashgraph-online/hol-guard/pull/2626)) Evidence for: **guard**: Bind managed controls projection vector ([#2626](https://github.com/hashgraph-online/hol-guard/pull/2626))
- Preserve safe PR validation for plugin notifier ([`8130cf6`](https://github.com/hashgraph-online/hol-guard/commit/8130cf682847998e60adf75aedbebe8673f8d5ee)) Evidence for: Preserve safe PR validation for plugin notifier ([`8130cf6`](https://github.com/hashgraph-online/hol-guard/commit/8130cf682847998e60adf75aedbebe8673f8d5ee))
- Avoid release notifier execution on pull requests ([`2e26414`](https://github.com/hashgraph-online/hol-guard/commit/2e26414c715b05c34ea926926fe1b9daf2a98a38)) Evidence for: Avoid release notifier execution on pull requests ([`2e26414`](https://github.com/hashgraph-online/hol-guard/commit/2e26414c715b05c34ea926926fe1b9daf2a98a38))
- Reconcile main into release/3.0 ([#2641](https://github.com/hashgraph-online/hol-guard/pull/2641)) Evidence for: Reconcile main into release/3.0 ([#2641](https://github.com/hashgraph-online/hol-guard/pull/2641))
- Merged pull request #2630: ci: avoid release notifier execution on pull requests Evidence for: Merged pull request #2630: ci: avoid release notifier execution on pull requests
- Merged pull request #2602: feat(guard): make Rust authoritative for PreToolUse batch 1 (#2602) Evidence for: Merged pull request #2602: feat(guard): make Rust authoritative for PreToolUse batch 1 (#2602)
- Merged pull request #2631: test(hooks): keep real-daemon GitHub reads allowed under review load (#2631) Evidence for: Merged pull request #2631: test(hooks): keep real-daemon GitHub reads allowed under review load (#2631)
- Merged pull request #2612: fix(guard): observe sourced scripts in compound shell commands (#2612) Evidence for: Merged pull request #2612: fix(guard): observe sourced scripts in compound shell commands (#2612)
- Merged pull request #2640: fix(release): advance 3.0 patch prerelease train (#2640) Evidence for: Merged pull request #2640: fix(release): advance 3.0 patch prerelease train (#2640)
- Merged pull request #2638: fix(guard): explain native action consequences (#2638) Evidence for: Merged pull request #2638: fix(guard): explain native action consequences (#2638)
- Merged pull request #2641: chore: reconcile main into release/3.0 Evidence for: Merged pull request #2641: chore: reconcile main into release/3.0
- Merged pull request #2635: feat: apply signed custom extension continuity (#2635) Evidence for: Merged pull request #2635: feat: apply signed custom extension continuity (#2635)
- Merged pull request #2626: test(guard): bind managed controls projection vector (#2626) Evidence for: Merged pull request #2626: test(guard): bind managed controls projection vector (#2626)
- Merged pull request #2632: refactor(guard): retire legacy cloud review commands (#2632) Evidence for: Merged pull request #2632: refactor(guard): retire legacy cloud review commands (#2632)
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: alpha/v3.0.0a290
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Contributors
- @kantorcodes
Implementation · 10 credits
Evidence ledger10 credits
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author