Documented changes
11 typed entries
Verified contributors
Credits being verified. Attribution coverage is unknown.
Attribution coverage
attribution not yet verified; history inventory partial.
Install
Scope
Guard v3.31.0 is a stable release published 2026-10-07. Upstream documents: Guard 3.31.0 is a stable release cut from [`c2b6bfc`](https://github.com/hashgraph-online/hol-guard/commit/c2b6bfc89067f9ad9177e1c43f344c1fa5f8abbf). **4 commits • 2 merged pull requests • 3 contributors** since [Guard 3.30.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.30.0). Attribution for this release is being verified.
Changes
Added
4- **extensions**: Add publisher listing for command.routed ([#3722](https://github.com/hashgraph-online/hol-guard/pull/3722)) Evidence for: **extensions**: Add publisher listing for command.routed ([#3722](https://github.com/hashgraph-online/hol-guard/pull/3722))
- `contributions/extension-listings/command.routed.json` (`guard.extension-listing.v2`) Evidence for: `contributions/extension-listings/command.routed.json` (`guard.extension-listing.v2`)
- Public attribution only: credits @bshea-1 (numeric ID `202353692`, author of #3084 and upstream author of [Routed](https://github.com/bshea-1/routed)) Evidence for: Public attribution only: credits @bshea-1 (numeric ID `202353692`, author of #3084 and upstream author of [Routed](https://github.com/bshea-1/routed))
- Per `.gitar/review/external-extension-submissions.md`, `maintainerGithubIds` is set to `[]` so the listing remains attribution-only until maintainers review and accept the claimant mapping. Evidence for: Per `.gitar/review/external-extension-submissions.md`, `maintainerGithubIds` is set to `[]` so the listing remains attribution-only until maintainers review and accept the claimant mapping.
Fixed
4- **guard**: Keep the Windows policy-integrity key in the local vault so credential-less logons stay protected ([#3717](https://github.com/hashgraph-online/hol-guard/pull/3717)) Evidence for: **guard**: Keep the Windows policy-integrity key in the local vault so credential-less logons stay protected ([#3717](https://github.com/hashgraph-online/hol-guard/pull/3717))
- On Windows the encrypted vault under the Guard home now holds the policy-integrity key for every session (`WindowsPolicyIntegritySecretStore`). OpenSSH key-authenticated and S4U logon sessions cannot open Credential… Evidence for: On Windows the encrypted vault under the Guard home now holds the policy-integrity key for every session (`WindowsPolicyIntegritySecretStore`). OpenSSH key-authenticated and S4U logon sessions cannot open Credential…
- Credential Manager is never written. A key an earlier release stored there is moved into the vault the first time a session can read it, then removed from Credential Manager, so the two stores never hold competing keys… Evidence for: Credential Manager is never written. A key an earlier release stored there is moved into the vault the first time a session can read it, then removed from Credential Manager, so the two stores never hold competing keys…
- If a session cannot reach Credential Manager, reads return no key. The existing key-creation guard still refuses to mint a second key for a home that already has native identity state. Evidence for: If a session cannot reach Credential Manager, reads return no key. The existing key-creation guard still refuses to mint a second key for a home that already has native identity state.
Other changes
3- Documented change: Guard 3.31.0 is a stable release cut from [`c2b6bfc`](https://github.com/hashgraph-online/hol-guard/commit/c2b6bfc89067f9ad9177e1c43f344c1fa5f8abbf). **4 commits • 2 merged pull requests • 3 contributors** since [Guard 3.30.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.30.0). Evidence for: Documented change: Guard 3.31.0 is a stable release cut from [`c2b6bfc`](https://github.com/hashgraph-online/hol-guard/commit/c2b6bfc89067f9ad9177e1c43f344c1fa5f8abbf). **4 commits • 2 merged pull requests • 3 contributors** since [Guard 3.30.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.30.0).
- **packaging**: Shrink native wheels and enforce package size budgets ([`6b450a2`](https://github.com/hashgraph-online/hol-guard/commit/6b450a2a93a880fb77e293fc42c27bd37b421614)) Evidence for: **packaging**: Shrink native wheels and enforce package size budgets ([`6b450a2`](https://github.com/hashgraph-online/hol-guard/commit/6b450a2a93a880fb77e293fc42c27bd37b421614))
- **release**: 3.31.0 ([`c2b6bfc`](https://github.com/hashgraph-online/hol-guard/commit/c2b6bfc89067f9ad9177e1c43f344c1fa5f8abbf)) Evidence for: **release**: 3.31.0 ([`c2b6bfc`](https://github.com/hashgraph-online/hol-guard/commit/c2b6bfc89067f9ad9177e1c43f344c1fa5f8abbf))
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: v3.30.0
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Evidence ledger0 credits
No credits are published for this release yet.