Documented changes
17 typed entries
Verified contributors
Credits being verified. Attribution coverage is unknown.
Attribution coverage
attribution not yet verified; history inventory partial.
Install
Scope
Guard v3.36.0 is a stable release published 2026-10-08. Upstream documents: Guard 3.36.0 is a stable release cut from [`843c1c7`](https://github.com/hashgraph-online/hol-guard/commit/843c1c7e15983dbeb2a99be27a6e2a5028fc19af). **10 commits • 10 merged pull requests • 3 contributors** since [Guard 3.35.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.35.0). Attribution for this release is being verified.
Changes
Added
1- **mcp**: Support direct-command launcher and add run MCP contribution ([#3325](https://github.com/hashgraph-online/hol-guard/pull/3325)) Evidence for: **mcp**: Support direct-command launcher and add run MCP contribution ([#3325](https://github.com/hashgraph-online/hol-guard/pull/3325))
Fixed
12- **extensions**: Bind the run MCP contribution to the external trust class ([#3784](https://github.com/hashgraph-online/hol-guard/pull/3784)) Evidence for: **extensions**: Bind the run MCP contribution to the external trust class ([#3784](https://github.com/hashgraph-online/hol-guard/pull/3784))
- **update**: Retry native resident retirement before failing the update ([#3781](https://github.com/hashgraph-online/hol-guard/pull/3781)) Evidence for: **update**: Retry native resident retirement before failing the update ([#3781](https://github.com/hashgraph-online/hol-guard/pull/3781))
- **guard**: Allow relative cd into the workspace, piped git reads and pipe-through cat ([#3780](https://github.com/hashgraph-online/hol-guard/pull/3780)) Evidence for: **guard**: Allow relative cd into the workspace, piped git reads and pipe-through cat ([#3780](https://github.com/hashgraph-online/hol-guard/pull/3780))
- **update**: Refresh managed hook clients and keep settings scoped to --guard-home ([#3764](https://github.com/hashgraph-online/hol-guard/pull/3764)) Evidence for: **update**: Refresh managed hook clients and keep settings scoped to --guard-home ([#3764](https://github.com/hashgraph-online/hol-guard/pull/3764))
- `hol-guard update` now rewrites stale bounded hook clients for active ZCode, Devin, Kimi, Copilot, OpenClaw and Hermes installs. These hooks run a stable client script under the Guard home, so the hook command never… Evidence for: `hol-guard update` now rewrites stale bounded hook clients for active ZCode, Devin, Kimi, Copilot, OpenClaw and Hermes installs. These hooks run a stable client script under the Guard home, so the hook command never…
- Frozen (PyInstaller) builds no longer write their per-process extraction directory into the `PYTHONPATH` of managed hook environments. That directory is deleted when the process exits, so the pinned path never resolved. Evidence for: Frozen (PyInstaller) builds no longer write their per-process extraction directory into the `PYTHONPATH` of managed hook environments. That directory is deleted when the process exits, so the pinned path never resolved.
- `settings` and `approval-password` subcommands now keep `--guard-home` and `--home` when they are given before the nested subcommand. Previously the nested parser's defaults reset them, and the command acted on the… Evidence for: `settings` and `approval-password` subcommands now keep `--guard-home` and `--home` when they are given before the nested subcommand. Previously the nested parser's defaults reset them, and the command acted on the…
- **gauntlet**: Bind native edit inputs and bounded corpus reporting ([#3776](https://github.com/hashgraph-online/hol-guard/pull/3776)) Evidence for: **gauntlet**: Bind native edit inputs and bounded corpus reporting ([#3776](https://github.com/hashgraph-online/hol-guard/pull/3776))
- **guard**: Offer and honor exact-action Always on daemon native reviews ([#3772](https://github.com/hashgraph-online/hol-guard/pull/3772)) Evidence for: **guard**: Offer and honor exact-action Always on daemon native reviews ([#3772](https://github.com/hashgraph-online/hol-guard/pull/3772))
- Daemon native PreToolUse reviews now offer "Always allow exact action" when the action has a stable identity. Before this change every native review row was once-only, because its artifact hash embeds the per-delivery… Evidence for: Daemon native PreToolUse reviews now offer "Always allow exact action" when the action has a stable identity. Before this change every native review row was once-only, because its artifact hash embeds the per-delivery…
- The exact-action token binds harness, tool, workspace, launch directory, launch identity, command text, the Rust verdict's capabilities, and the reviewed rule digest plus command-extension binding. A Guard rule or… Evidence for: The exact-action token binds harness, tool, workspace, launch directory, launch identity, command text, the Rust verdict's capabilities, and the reviewed rule digest plus command-extension binding. A Guard rule or…
- `npx`/`bunx`/`pnpm`/`yarn`/`npm` runner commands bind only when the runner resolves to a content-hashed project-local `node_modules/.bin` executable. The binding includes the installed package version and the manager… Evidence for: `npx`/`bunx`/`pnpm`/`yarn`/`npm` runner commands bind only when the runner resolves to a content-hashed project-local `node_modules/.bin` executable. The binding includes the installed package version and the manager…
Other changes
4- Documented change: Guard 3.36.0 is a stable release cut from [`843c1c7`](https://github.com/hashgraph-online/hol-guard/commit/843c1c7e15983dbeb2a99be27a6e2a5028fc19af). **10 commits • 10 merged pull requests • 3 contributors** since [Guard 3.35.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.35.0). Evidence for: Documented change: Guard 3.36.0 is a stable release cut from [`843c1c7`](https://github.com/hashgraph-online/hol-guard/commit/843c1c7e15983dbeb2a99be27a6e2a5028fc19af). **10 commits • 10 merged pull requests • 3 contributors** since [Guard 3.35.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.35.0).
- **release**: Content-addressed release compilation and one build graph ([#3782](https://github.com/hashgraph-online/hol-guard/pull/3782)) Evidence for: **release**: Content-addressed release compilation and one build graph ([#3782](https://github.com/hashgraph-online/hol-guard/pull/3782))
- **guard**: Add seeded generated-input checks for Gmail send preparation ([#3777](https://github.com/hashgraph-online/hol-guard/pull/3777)) Evidence for: **guard**: Add seeded generated-input checks for Gmail send preparation ([#3777](https://github.com/hashgraph-online/hol-guard/pull/3777))
- **release**: 3.36.0 ([#3779](https://github.com/hashgraph-online/hol-guard/pull/3779)) Evidence for: **release**: 3.36.0 ([#3779](https://github.com/hashgraph-online/hol-guard/pull/3779))
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: v3.35.0
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Evidence ledger0 credits
No credits are published for this release yet.