Documented changes
59 typed entries
Verified contributors
Credits being verified. Attribution coverage is in progress.
Attribution coverage
attribution in progress; history inventory partial.
Install
Scope
Guard v3.22.0 is a stable release published 2026-10-04. Upstream documents: Guard 3.22.0 is a stable release cut from [`6a551b8`](https://github.com/hashgraph-online/hol-guard/commit/6a551b8877bd1a94bc4a5ffdbc33b64507613637). **21 commits • 12 merged pull requests • 4 contributors** since [Guard 3.21.1](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.21.1). Its comparison base is v3.21.1. It includes 32 verified contribution deliveries with public evidence links. Attribution for this release is being verified.
Changes
Added
5- **command**: Decode bounded Gmail plain-text transfer bodies ([`78aa871`](https://github.com/hashgraph-online/hol-guard/commit/78aa8717f03c28ffb4bd785ede935296ebc8ce2e)) Evidence for: **command**: Decode bounded Gmail plain-text transfer bodies ([`78aa871`](https://github.com/hashgraph-online/hol-guard/commit/78aa8717f03c28ffb4bd785ede935296ebc8ce2e))
- **command**: Extract private bounded plain Gmail inputs ([`f920d9c`](https://github.com/hashgraph-online/hol-guard/commit/f920d9c4388d2ab9aad39693e87c9a747628bd18)) Evidence for: **command**: Extract private bounded plain Gmail inputs ([`f920d9c`](https://github.com/hashgraph-online/hol-guard/commit/f920d9c4388d2ab9aad39693e87c9a747628bd18))
- **extensions**: Add snoboard command source ([#3468](https://github.com/hashgraph-online/hol-guard/pull/3468)) Evidence for: **extensions**: Add snoboard command source ([#3468](https://github.com/hashgraph-online/hol-guard/pull/3468))
- **command**: Prepare pinned gws Gmail sends through native parser ([`b082d0f`](https://github.com/hashgraph-online/hol-guard/commit/b082d0f15582545622031e298d89fbb1ba399f74)) Evidence for: **command**: Prepare pinned gws Gmail sends through native parser ([`b082d0f`](https://github.com/hashgraph-online/hol-guard/commit/b082d0f15582545622031e298d89fbb1ba399f74))
- **command**: Decode bounded Gmail send wire input ([`9084d77`](https://github.com/hashgraph-online/hol-guard/commit/9084d774d0526f18498a047dc1b8988368a65428)) Evidence for: **command**: Decode bounded Gmail send wire input ([`9084d77`](https://github.com/hashgraph-online/hol-guard/commit/9084d774d0526f18498a047dc1b8988368a65428))
Fixed
13- **grok**: Preserve prompt blocks when review is unavailable ([#3519](https://github.com/hashgraph-online/hol-guard/pull/3519)) Evidence for: **grok**: Preserve prompt blocks when review is unavailable ([#3519](https://github.com/hashgraph-online/hol-guard/pull/3519))
- Preserve native prompt blocks using Grok's `decision: "block"` contract. Reviewed benign prompts and authenticated, acknowledged Watch-mode reviews return empty success; session and subagent observations remain passive. Evidence for: Preserve native prompt blocks using Grok's `decision: "block"` contract. Reviewed benign prompts and authenticated, acknowledged Watch-mode reviews return empty success; session and subagent observations remain passive.
- Block an unreviewed prompt when the daemon is unavailable, without launching a cold evaluator that can exceed Grok's deadline. Give prompt review the protected transport budget instead of the short observer budget. Evidence for: Block an unreviewed prompt when the daemon is unavailable, without launching a cold evaluator that can exceed Grok's deadline. Give prompt review the protected transport budget instead of the short observer budget.
- Check managed prompt hooks during update repair and report the prompt gate accurately in harness capabilities. Evidence for: Check managed prompt hooks during update repair and report the prompt gate accurately in harness capabilities.
- **runtime**: Allow read-only documents in supported skill roots ([#3522](https://github.com/hashgraph-online/hol-guard/pull/3522)) Evidence for: **runtime**: Allow read-only documents in supported skill roots ([#3522](https://github.com/hashgraph-online/hol-guard/pull/3522))
- Allow read-only Markdown documents in the supported local skill roots and ZCode's versioned plugin-skill cache. Evidence for: Allow read-only Markdown documents in the supported local skill roots and ZCode's versioned plugin-skill cache.
- Keep credential files, hidden descendants, scripts, malformed cache paths, writes, and mixed secret-read commands guarded. Evidence for: Keep credential files, hidden descendants, scripts, malformed cache paths, writes, and mixed secret-read commands guarded.
- **ci**: Repair Rust formatting and import current-checkout coverage ([#3520](https://github.com/hashgraph-online/hol-guard/pull/3520)) Evidence for: **ci**: Repair Rust formatting and import current-checkout coverage ([#3520](https://github.com/hashgraph-online/hol-guard/pull/3520))
- **ci**: Preserve strict identity decoding in Sonar analysis ([#3515](https://github.com/hashgraph-online/hol-guard/pull/3515)) Evidence for: **ci**: Preserve strict identity decoding in Sonar analysis ([#3515](https://github.com/hashgraph-online/hol-guard/pull/3515))
- **ci**: Prepare source-only extensions without main-sync churn ([#3517](https://github.com/hashgraph-online/hol-guard/pull/3517)) Evidence for: **ci**: Prepare source-only extensions without main-sync churn ([#3517](https://github.com/hashgraph-online/hol-guard/pull/3517))
- **runtime**: Contain inline Python with isolation flags ([`1fb6aff`](https://github.com/hashgraph-online/hol-guard/commit/1fb6aff0c268577189ee6ad94c7c68cb28ab7c58)) Evidence for: **runtime**: Contain inline Python with isolation flags ([`1fb6aff`](https://github.com/hashgraph-online/hol-guard/commit/1fb6aff0c268577189ee6ad94c7c68cb28ab7c58))
- **dashboard**: Preserve keyboard cancellation in approval dialogs ([`bbad78a`](https://github.com/hashgraph-online/hol-guard/commit/bbad78a40cafc40c052f881feb8cfe8f662565e1)) Evidence for: **dashboard**: Preserve keyboard cancellation in approval dialogs ([`bbad78a`](https://github.com/hashgraph-online/hol-guard/commit/bbad78a40cafc40c052f881feb8cfe8f662565e1))
- **pi**: Retry workspace readiness after daemon recovery ([`06fea1c`](https://github.com/hashgraph-online/hol-guard/commit/06fea1c0878cd45982d3aa71502fb9ac6a86c8bf)) Evidence for: **pi**: Retry workspace readiness after daemon recovery ([`06fea1c`](https://github.com/hashgraph-online/hol-guard/commit/06fea1c0878cd45982d3aa71502fb9ac6a86c8bf))
Other changes
41- Documented change: Guard 3.22.0 is a stable release cut from [`6a551b8`](https://github.com/hashgraph-online/hol-guard/commit/6a551b8877bd1a94bc4a5ffdbc33b64507613637). **21 commits • 12 merged pull requests • 4 contributors** since [Guard 3.21.1](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.21.1). Evidence for: Documented change: Guard 3.22.0 is a stable release cut from [`6a551b8`](https://github.com/hashgraph-online/hol-guard/commit/6a551b8877bd1a94bc4a5ffdbc33b64507613637). **21 commits • 12 merged pull requests • 4 contributors** since [Guard 3.21.1](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.21.1).
- **windows**: Isolate secure-storage fixtures within one clock tick ([#3525](https://github.com/hashgraph-online/hol-guard/pull/3525)) Evidence for: **windows**: Isolate secure-storage fixtures within one clock tick ([#3525](https://github.com/hashgraph-online/hol-guard/pull/3525))
- **gauntlet**: Qualify mixed native read batches independently ([#3521](https://github.com/hashgraph-online/hol-guard/pull/3521)) Evidence for: **gauntlet**: Qualify mixed native read batches independently ([#3521](https://github.com/hashgraph-online/hol-guard/pull/3521))
- **gauntlet**: Cover native Watch acknowledgements ([#3514](https://github.com/hashgraph-online/hol-guard/pull/3514)) Evidence for: **gauntlet**: Cover native Watch acknowledgements ([#3514](https://github.com/hashgraph-online/hol-guard/pull/3514))
- **gauntlet**: Add contained Bun/Vitest profile ([`345eca2`](https://github.com/hashgraph-online/hol-guard/commit/345eca2edf169c1ea0ea1d2812b6bdddd3d0b0ae)) Evidence for: **gauntlet**: Add contained Bun/Vitest profile ([`345eca2`](https://github.com/hashgraph-online/hol-guard/commit/345eca2edf169c1ea0ea1d2812b6bdddd3d0b0ae))
- **release**: 3.22.0 ([`6a551b8`](https://github.com/hashgraph-online/hol-guard/commit/6a551b8877bd1a94bc4a5ffdbc33b64507613637)) Evidence for: **release**: 3.22.0 ([`6a551b8`](https://github.com/hashgraph-online/hol-guard/commit/6a551b8877bd1a94bc4a5ffdbc33b64507613637))
- RTM-008..026/032/033: Rust-native runtime migration slices (context authority through git/precommit) ([#3424](https://github.com/hashgraph-online/hol-guard/pull/3424)) Evidence for: RTM-008..026/032/033: Rust-native runtime migration slices (context authority through git/precommit) ([#3424](https://github.com/hashgraph-online/hol-guard/pull/3424))
- **extensions**: Regenerate contribution artifacts ([#3513](https://github.com/hashgraph-online/hol-guard/pull/3513)) Evidence for: **extensions**: Regenerate contribution artifacts ([#3513](https://github.com/hashgraph-online/hol-guard/pull/3513))
- **review**: Exempt JSON from file-size limits ([#3508](https://github.com/hashgraph-online/hol-guard/pull/3508)) Evidence for: **review**: Exempt JSON from file-size limits ([#3508](https://github.com/hashgraph-online/hol-guard/pull/3508))
- Merged pull request #3509: fix(pi): retry workspace readiness after daemon recovery Evidence for: Merged pull request #3509: fix(pi): retry workspace readiness after daemon recovery
- Direct commit 16c8ec2d204c: fix: update Grok prompt expectation and formatting Evidence for: Direct commit 16c8ec2d204c: fix: update Grok prompt expectation and formatting
- Merged pull request #3508: chore(review): exempt JSON from file-size limits Evidence for: Merged pull request #3508: chore(review): exempt JSON from file-size limits
- Direct commit b91da87bce26: fix: restore rustfmt array layout Evidence for: Direct commit b91da87bce26: fix: restore rustfmt array layout
- Merged pull request #3424: RTM-008..026/032/033: Rust-native runtime migration slices (context authority through git/precommit) Evidence for: Merged pull request #3424: RTM-008..026/032/033: Rust-native runtime migration slices (context authority through git/precommit)
- Merged pull request #3506: test(gauntlet): add real contained Bun/Vitest profile Evidence for: Merged pull request #3506: test(gauntlet): add real contained Bun/Vitest profile
- Direct commit 05689236c467: fix: normalize pinned provider schema line endings Evidence for: Direct commit 05689236c467: fix: normalize pinned provider schema line endings
- Direct commit 232e085be961: fix: report pre-tool observe mode in receipts Evidence for: Direct commit 232e085be961: fix: report pre-tool observe mode in receipts
- Direct commit 42934ab9625d: fix: fail fast on unsupported contained profile platforms Evidence for: Direct commit 42934ab9625d: fix: fail fast on unsupported contained profile platforms
- Merged pull request #3514: test(gauntlet): cover native Watch acknowledgements Evidence for: Merged pull request #3514: test(gauntlet): cover native Watch acknowledgements
- Merged pull request #3468: feat(extensions): add snoboard command source Evidence for: Merged pull request #3468: feat(extensions): add snoboard command source
- Merged pull request #3507: feat(command): prepare pinned gws Gmail sends through native parser Evidence for: Merged pull request #3507: feat(command): prepare pinned gws Gmail sends through native parser
- Merged pull request #3518: fix(runtime): contain inline Python with isolation flags Evidence for: Merged pull request #3518: fix(runtime): contain inline Python with isolation flags
- Merged pull request #3522: fix(runtime): allow read-only documents in supported skill roots Evidence for: Merged pull request #3522: fix(runtime): allow read-only documents in supported skill roots
- Merged pull request #3503: feat(command): decode bounded Gmail send wire input Evidence for: Merged pull request #3503: feat(command): decode bounded Gmail send wire input
- Direct commit f73923468b4f: chore(extensions): regenerate contribution artifacts Evidence for: Direct commit f73923468b4f: chore(extensions): regenerate contribution artifacts
- Merged pull request #3517: fix(ci): prepare source-only extensions without main-sync churn Evidence for: Merged pull request #3517: fix(ci): prepare source-only extensions without main-sync churn
- Merged pull request #3515: fix(ci): preserve strict identity decoding in Sonar analysis Evidence for: Merged pull request #3515: fix(ci): preserve strict identity decoding in Sonar analysis
- Direct commit 9a04c8dc0041: Merge main into feat/command-snoboard Evidence for: Direct commit 9a04c8dc0041: Merge main into feat/command-snoboard
- Merged pull request #3525: test(windows): isolate secure-storage fixtures within one clock tick Evidence for: Merged pull request #3525: test(windows): isolate secure-storage fixtures within one clock tick
- Merged pull request #3519: fix(grok): preserve prompt blocks when review is unavailable Evidence for: Merged pull request #3519: fix(grok): preserve prompt blocks when review is unavailable
- Merged pull request #3520: fix(ci): repair Rust formatting and import current-checkout coverage Evidence for: Merged pull request #3520: fix(ci): repair Rust formatting and import current-checkout coverage
- Direct commit 08a15030b382: fix: simplify skill document extension check Evidence for: Direct commit 08a15030b382: fix: simplify skill document extension check
- Direct commit ca9f19144e29: fix(gmail): reject unicode body controls Evidence for: Direct commit ca9f19144e29: fix(gmail): reject unicode body controls
- Direct commit 28f1c7d99bc6: fix: isolate refresh arguments in fixture test Evidence for: Direct commit 28f1c7d99bc6: fix: isolate refresh arguments in fixture test
- Merged pull request #3513: chore(extensions): regenerate contribution artifacts Evidence for: Merged pull request #3513: chore(extensions): regenerate contribution artifacts
- Merged pull request #3510: chore(release): 3.22.0 Evidence for: Merged pull request #3510: chore(release): 3.22.0
- Direct commit 4b62afa20b52: test: align hook reason expectations Evidence for: Direct commit 4b62afa20b52: test: align hook reason expectations
- Merged pull request #3521: test(gauntlet): qualify mixed native read batches independently Evidence for: Merged pull request #3521: test(gauntlet): qualify mixed native read batches independently
- Merged pull request #3523: feat(command): decode bounded Gmail plain-text transfer bodies Evidence for: Merged pull request #3523: feat(command): decode bounded Gmail plain-text transfer bodies
- Merged pull request #3516: fix(dashboard): preserve keyboard cancellation in approval dialogs Evidence for: Merged pull request #3516: fix(dashboard): preserve keyboard cancellation in approval dialogs
- Merged pull request #3512: feat(command): extract private bounded plain Gmail inputs Evidence for: Merged pull request #3512: feat(command): extract private bounded plain Gmail inputs
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: v3.21.1
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Contributors
- @gitar-bot
Implementation · 8 credits
- @github-actions[bot]
Implementation · 1 credit
- @kantorcodes
Implementation · 6 credits
- @serrnovik
Implementation · 1 credit
- @zerocodefast
Implementation · 16 credits
Evidence ledger32 credits
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @github-actions[bot]Source for github-actions[bot]
Implementation · Verified commit author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Verified commit author
- @serrnovikSource for serrnovik
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Verified commit author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author