Documented changes
50 typed entries
Verified contributors
Credits being verified. Attribution coverage is in progress.
Attribution coverage
attribution in progress; history inventory partial.
Install
Scope
Guard v3.26.0 is a stable release published 2026-10-05. Upstream documents: Guard 3.26.0 is a stable release cut from [`38df288`](https://github.com/hashgraph-online/hol-guard/commit/38df28809014916787296b6892445517d2b3b664). **14 commits • 12 merged pull requests • 6 contributors** since [Guard 3.25.2](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.25.2). Its comparison base is v3.25.2. It includes 24 verified contribution deliveries with public evidence links. Attribution for this release is being verified.
Changes
Added
4- **extensions**: Add opt-in gog command risk rules ([#3594](https://github.com/hashgraph-online/hol-guard/pull/3594)) Evidence for: **extensions**: Add opt-in gog command risk rules ([#3594](https://github.com/hashgraph-online/hol-guard/pull/3594))
- **mcp**: Add InsumerAPI MCP server contribution ([#3597](https://github.com/hashgraph-online/hol-guard/pull/3597)) Evidence for: **mcp**: Add InsumerAPI MCP server contribution ([#3597](https://github.com/hashgraph-online/hol-guard/pull/3597))
- **mcp**: Support tightening-only native server contributions ([#3578](https://github.com/hashgraph-online/hol-guard/pull/3578)) Evidence for: **mcp**: Support tightening-only native server contributions ([#3578](https://github.com/hashgraph-online/hol-guard/pull/3578))
- **extensions**: Give command.faf-cli a catalog icon ([#3591](https://github.com/hashgraph-online/hol-guard/pull/3591)) Evidence for: **extensions**: Give command.faf-cli a catalog icon ([#3591](https://github.com/hashgraph-online/hol-guard/pull/3591))
Fixed
17- **guard**: Retain process-query output within the original deadline ([`f8500d2`](https://github.com/hashgraph-online/hol-guard/commit/f8500d220ac29952766cda786d13b2ea4e9d593e)) Evidence for: **guard**: Retain process-query output within the original deadline ([`f8500d2`](https://github.com/hashgraph-online/hol-guard/commit/f8500d220ac29952766cda786d13b2ea4e9d593e))
- **ci**: Prevent healthy coverage shards from timing out ([#3608](https://github.com/hashgraph-online/hol-guard/pull/3608)) Evidence for: **ci**: Prevent healthy coverage shards from timing out ([#3608](https://github.com/hashgraph-online/hol-guard/pull/3608))
- raise only the `coverage` matrix job timeout from 5 to 10 minutes Evidence for: raise only the `coverage` matrix job timeout from 5 to 10 minutes
- keep all 128 shards, tests, deselections, coverage requirements, Sonar policy, and security gates unchanged Evidence for: keep all 128 shards, tests, deselections, coverage requirements, Sonar policy, and security gates unchanged
- **extensions**: Unblock contribution friction — bare executable matchers, enumerated staging, no per-MCP tests ([#3598](https://github.com/hashgraph-online/hol-guard/pull/3598)) Evidence for: **extensions**: Unblock contribution friction — bare executable matchers, enumerated staging, no per-MCP tests ([#3598](https://github.com/hashgraph-online/hol-guard/pull/3598))
- **`executable.v1` matchers**: a missing `subcommands` array now compiles as an empty path (match every invocation of the executable), which is exactly what the rendered unclassified fallback already emits. Hand-written… Evidence for: **`executable.v1` matchers**: a missing `subcommands` array now compiles as an empty path (match every invocation of the executable), which is exactly what the rendered unclassified fallback already emits. Hand-written…
- **`stage_guard_cloud_review_artifacts.py`**: contribution payloads are enumerated by scanning `contributions/extensions/` and `contributions/mcp-servers/` instead of a hardcoded list every new contribution had to edit.… Evidence for: **`stage_guard_cloud_review_artifacts.py`**: contribution payloads are enumerated by scanning `contributions/extensions/` and `contributions/mcp-servers/` instead of a hardcoded list every new contribution had to edit.…
- **Extension kit**: MCP kits no longer emit a generated `test_guard_mcp_ _contribution.py` module; the shared contribution checks cover metadata and native registration. Removed the existing generated test for… Evidence for: **Extension kit**: MCP kits no longer emit a generated `test_guard_mcp_ _contribution.py` module; the shared contribution checks cover metadata and native registration. Removed the existing generated test for…
- **ci**: Eliminate remaining Sonar reliability findings ([#3600](https://github.com/hashgraph-online/hol-guard/pull/3600)) Evidence for: **ci**: Eliminate remaining Sonar reliability findings ([#3600](https://github.com/hashgraph-online/hol-guard/pull/3600))
- replace Markdown fence and skill-continuation regexes with deterministic physical-line parsing Evidence for: replace Markdown fence and skill-continuation regexes with deterministic physical-line parsing
- keep transaction rollback/commit semantics while moving all post-yield cleanup under `finally` Evidence for: keep transaction rollback/commit semantics while moving all post-yield cleanup under `finally`
- replace trailing approval punctuation regex cleanup with bounded string operations Evidence for: replace trailing approval punctuation regex cleanup with bounded string operations
- **guard**: Recover native residents and prepare Grok prompt hooks ([#3577](https://github.com/hashgraph-online/hol-guard/pull/3577)) Evidence for: **guard**: Recover native residents and prepare Grok prompt hooks ([#3577](https://github.com/hashgraph-online/hol-guard/pull/3577))
- **ci**: Resolve Sonar reliability regressions ([#3587](https://github.com/hashgraph-online/hol-guard/pull/3587)) Evidence for: **ci**: Resolve Sonar reliability regressions ([#3587](https://github.com/hashgraph-online/hol-guard/pull/3587))
- make skill fence/token/Grok regexes linear and explicit Evidence for: make skill fence/token/Grok regexes linear and explicit
- preserve variadic tuple APIs while avoiding inconsistent fixed-tuple return shapes Evidence for: preserve variadic tuple APIs while avoiding inconsistent fixed-tuple return shapes
- make transaction normal-exit commit work explicit in the context manager `else` path Evidence for: make transaction normal-exit commit work explicit in the context manager `else` path
Other changes
29- Documented change: Guard 3.26.0 is a stable release cut from [`38df288`](https://github.com/hashgraph-online/hol-guard/commit/38df28809014916787296b6892445517d2b3b664). **14 commits • 12 merged pull requests • 6 contributors** since [Guard 3.25.2](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.25.2). Evidence for: Documented change: Guard 3.26.0 is a stable release cut from [`38df288`](https://github.com/hashgraph-online/hol-guard/commit/38df28809014916787296b6892445517d2b3b664). **14 commits • 12 merged pull requests • 6 contributors** since [Guard 3.25.2](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.25.2).
- **release**: 3.26.0 ([`38df288`](https://github.com/hashgraph-online/hol-guard/commit/38df28809014916787296b6892445517d2b3b664)) Evidence for: **release**: 3.26.0 ([`38df288`](https://github.com/hashgraph-online/hol-guard/commit/38df28809014916787296b6892445517d2b3b664))
- **extensions**: Regenerate contribution artifacts ([#3607](https://github.com/hashgraph-online/hol-guard/pull/3607)) Evidence for: **extensions**: Regenerate contribution artifacts ([#3607](https://github.com/hashgraph-online/hol-guard/pull/3607))
- **extensions**: Regenerate contribution artifacts ([#3603](https://github.com/hashgraph-online/hol-guard/pull/3603)) Evidence for: **extensions**: Regenerate contribution artifacts ([#3603](https://github.com/hashgraph-online/hol-guard/pull/3603))
- **extensions**: Regenerate contribution artifacts ([#3596](https://github.com/hashgraph-online/hol-guard/pull/3596)) Evidence for: **extensions**: Regenerate contribution artifacts ([#3596](https://github.com/hashgraph-online/hol-guard/pull/3596))
- Merged pull request #3597: feat(mcp): add InsumerAPI MCP server contribution Evidence for: Merged pull request #3597: feat(mcp): add InsumerAPI MCP server contribution
- Merged pull request #3577: fix(guard): recover native residents and prepare Grok prompt hooks Evidence for: Merged pull request #3577: fix(guard): recover native residents and prepare Grok prompt hooks
- Merged pull request #3598: fix(extensions): unblock contribution friction — bare executable matchers, enumerated staging, no per-MCP tests Evidence for: Merged pull request #3598: fix(extensions): unblock contribution friction — bare executable matchers, enumerated staging, no per-MCP tests
- Direct commit 1462a378329f: fix: extend pytest shard wait barrier Evidence for: Direct commit 1462a378329f: fix: extend pytest shard wait barrier
- Merged pull request #3578: feat(mcp): support tightening-only native server contributions Evidence for: Merged pull request #3578: feat(mcp): support tightening-only native server contributions
- Merged pull request #3600: fix(ci): eliminate remaining Sonar reliability findings Evidence for: Merged pull request #3600: fix(ci): eliminate remaining Sonar reliability findings
- Merged pull request #3608: fix(ci): prevent healthy coverage shards from timing out Evidence for: Merged pull request #3608: fix(ci): prevent healthy coverage shards from timing out
- Direct commit 2334f7a27014: fix: classify process query capture decoding Evidence for: Direct commit 2334f7a27014: fix: classify process query capture decoding
- Direct commit 77d44ec3c006: Merge branch 'main' into feat/native-mcp-launch Evidence for: Direct commit 77d44ec3c006: Merge branch 'main' into feat/native-mcp-launch
- Merged pull request #3603: chore(extensions): regenerate contribution artifacts Evidence for: Merged pull request #3603: chore(extensions): regenerate contribution artifacts
- Direct commit 8a4fa7055c7a: fix: create MCP staging fixture directory Evidence for: Direct commit 8a4fa7055c7a: fix: create MCP staging fixture directory
- Direct commit 2d8582c9b3dc: chore(extensions): regenerate contribution artifacts Evidence for: Direct commit 2d8582c9b3dc: chore(extensions): regenerate contribution artifacts
- Direct commit cad7b00c2e69: fix: mirror short value option parsing Evidence for: Direct commit cad7b00c2e69: fix: mirror short value option parsing
- Merged pull request #3596: chore(extensions): regenerate contribution artifacts Evidence for: Merged pull request #3596: chore(extensions): regenerate contribution artifacts
- Direct commit 14a717180b38: fix: cache missing quote lookups in redaction scanner Evidence for: Direct commit 14a717180b38: fix: cache missing quote lookups in redaction scanner
- Merged pull request #3587: fix(ci): resolve Sonar reliability regressions Evidence for: Merged pull request #3587: fix(ci): resolve Sonar reliability regressions
- Direct commit 39df139f022f: chore(extensions): regenerate contribution artifacts Evidence for: Direct commit 39df139f022f: chore(extensions): regenerate contribution artifacts
- Merged pull request #3607: chore(extensions): regenerate contribution artifacts Evidence for: Merged pull request #3607: chore(extensions): regenerate contribution artifacts
- Merged pull request #3594: feat(extensions): add opt-in gog command risk rules Evidence for: Merged pull request #3594: feat(extensions): add opt-in gog command risk rules
- Merged pull request #3612: fix(guard): drain process inventory within its original deadline Evidence for: Merged pull request #3612: fix(guard): drain process inventory within its original deadline
- Merged pull request #3591: feat(extensions): give command.faf-cli a catalog icon Evidence for: Merged pull request #3591: feat(extensions): give command.faf-cli a catalog icon
- Direct commit b0f677b2519c: fix: allow Grok prompts without native authority Evidence for: Direct commit b0f677b2519c: fix: allow Grok prompts without native authority
- Direct commit 2404bf7e1c83: chore(extensions): regenerate contribution artifacts Evidence for: Direct commit 2404bf7e1c83: chore(extensions): regenerate contribution artifacts
- Merged pull request #3593: chore(release): 3.26.0 Evidence for: Merged pull request #3593: chore(release): 3.26.0
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: v3.25.2
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Contributors
- @douglasborthwick-crypto
Implementation · 1 credit
- @gitar-bot
Implementation · 6 credits
- @github-actions[bot]
Implementation · 3 credits
- @kantorcodes
Implementation · 4 credits
- @tcballard
Implementation · 1 credit
- @Wolfe-Jam
Implementation · 1 credit
- @zerocodefast
Implementation · 8 credits
Evidence ledger24 credits
- @douglasborthwick-cryptoSource for douglasborthwick-crypto
Implementation · Pull request author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @gitar-botSource for gitar-bot
Implementation · Verified commit author
- @github-actions[bot]Source for github-actions[bot]
Implementation · Verified commit author
- @github-actions[bot]Source for github-actions[bot]
Implementation · Verified commit author
- @github-actions[bot]Source for github-actions[bot]
Implementation · Verified commit author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Verified commit author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @tcballardSource for tcballard
Implementation · Pull request author
- @Wolfe-JamSource for Wolfe-Jam
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author
- @zerocodefastSource for zerocodefast
Implementation · Pull request author