Documented changes
40 typed entries
Verified contributors
Credits being verified. Attribution coverage is unknown.
Attribution coverage
attribution not yet verified; history inventory partial.
Install
Scope
Guard v3.37.0 is a stable release published 2026-10-09. Upstream documents: Guard 3.37.0 is a stable release cut from [`3efd6a6`](https://github.com/hashgraph-online/hol-guard/commit/3efd6a606479b944fa33ddd208ea030082c45bd4). **36 commits • 35 merged pull requests • 8 contributors** since [Guard 3.36.1](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.36.1). Attribution for this release is being verified.
Changes
Added
13- **gauntlet**: Run the catalog through Claude Code, Codex and Cursor ([#3818](https://github.com/hashgraph-online/hol-guard/pull/3818)) Evidence for: **gauntlet**: Run the catalog through Claude Code, Codex and Cursor ([#3818](https://github.com/hashgraph-online/hol-guard/pull/3818))
- **guard**: Add agi-memory command safety extension ([#2921](https://github.com/hashgraph-online/hol-guard/pull/2921)) Evidence for: **guard**: Add agi-memory command safety extension ([#2921](https://github.com/hashgraph-online/hol-guard/pull/2921))
- **extension**: Add Formicx agent command safety extension ([#2914](https://github.com/hashgraph-online/hol-guard/pull/2914)) Evidence for: **extension**: Add Formicx agent command safety extension ([#2914](https://github.com/hashgraph-online/hol-guard/pull/2914))
- **guard**: Add rungs command classification extension ([#2818](https://github.com/hashgraph-online/hol-guard/pull/2818)) Evidence for: **guard**: Add rungs command classification extension ([#2818](https://github.com/hashgraph-online/hol-guard/pull/2818))
- **guard**: Review Dispat release starts with an opt-in extension ([#2813](https://github.com/hashgraph-online/hol-guard/pull/2813)) Evidence for: **guard**: Review Dispat release starts with an opt-in extension ([#2813](https://github.com/hashgraph-online/hol-guard/pull/2813))
- **extensions**: Add pyrig command protection ([#3674](https://github.com/hashgraph-online/hol-guard/pull/3674)) Evidence for: **extensions**: Add pyrig command protection ([#3674](https://github.com/hashgraph-online/hol-guard/pull/3674))
- **guard**: List detected CLIs and add a Cloudflare Wrangler profile ([#3795](https://github.com/hashgraph-online/hol-guard/pull/3795)) Evidence for: **guard**: List detected CLIs and add a Cloudflare Wrangler profile ([#3795](https://github.com/hashgraph-online/hol-guard/pull/3795))
- **extensions**: Add publisher listing for mcp.mail-server ([#3805](https://github.com/hashgraph-online/hol-guard/pull/3805)) Evidence for: **extensions**: Add publisher listing for mcp.mail-server ([#3805](https://github.com/hashgraph-online/hol-guard/pull/3805))
- **extensions**: Require approval for mcp-mail-server permanent deletion ([#3278](https://github.com/hashgraph-online/hol-guard/pull/3278)) Evidence for: **extensions**: Require approval for mcp-mail-server permanent deletion ([#3278](https://github.com/hashgraph-online/hol-guard/pull/3278))
- **business**: Classify business operations and add Drive export ([#3798](https://github.com/hashgraph-online/hol-guard/pull/3798)) Evidence for: **business**: Classify business operations and add Drive export ([#3798](https://github.com/hashgraph-online/hol-guard/pull/3798))
- `BusinessOperationV1::action_class()` maps every operation to one of `read`, `draft`, `send`, `share`, `export`, `update`, `delete` or `admin`. The class comes from the operation alone. A producer cannot supply it, and… Evidence for: `BusinessOperationV1::action_class()` maps every operation to one of `read`, `draft`, `send`, `share`, `export`, `update`, `delete` or `admin`. The class comes from the operation alone. A producer cannot supply it, and…
- `drive_export` is a Google Drive operation. Its audience must be `private` or `unknown`. A public or named export is `Inconsistent`, because handing a file to someone else is `drive_share`. Evidence for: `drive_export` is a Google Drive operation. Its audience must be `private` or `unknown`. A public or named export is `Inconsistent`, because handing a file to someone else is `drive_share`.
- The policy schema (both copies) accepts `drive_export`, and a selector may now list up to 12 operations. The review summary, the review queue and the dashboard label it "Export Drive files". Evidence for: The policy schema (both copies) accepts `drive_export`, and a selector may now list up to 12 operations. The review summary, the review queue and the dashboard label it "Export Drive files".
Fixed
26- **runtime**: Name the business context floor for shell-wrapped Workspace CLIs ([#3826](https://github.com/hashgraph-online/hol-guard/pull/3826)) Evidence for: **runtime**: Name the business context floor for shell-wrapped Workspace CLIs ([#3826](https://github.com/hashgraph-online/hol-guard/pull/3826))
- **guard**: Repair extension-control catalog bound and error type ([#3817](https://github.com/hashgraph-online/hol-guard/pull/3817)) Evidence for: **guard**: Repair extension-control catalog bound and error type ([#3817](https://github.com/hashgraph-online/hol-guard/pull/3817))
- `ExtensionControlApiError` was a `@dataclass(frozen=True, slots=True)` exception. `contextlib` assigns `__traceback__` on raise, so `super()` inside the slots class raised `TypeError: super(type, obj)` and froze.… Evidence for: `ExtensionControlApiError` was a `@dataclass(frozen=True, slots=True)` exception. `contextlib` assigns `__traceback__` on raise, so `super()` inside the slots class raised `TypeError: super(type, obj)` and froze.…
- Parallelized the coverage critical path: shards run `xdist -n 3 --dist=loadfile --max-worker-restart 0`; Rust nextest `--test-threads 4`. `pytest_duration_report` writes only from the controller so workers cannot… Evidence for: Parallelized the coverage critical path: shards run `xdist -n 3 --dist=loadfile --max-worker-restart 0`; Rust nextest `--test-threads 4`. `pytest_duration_report` writes only from the controller so workers cannot…
- Serialized the collection-time `git diff`/`fetch` in `extension_freshness` across xdist workers with an `fcntl` lock (concurrent module imports raced `.git`). Evidence for: Serialized the collection-time `git diff`/`fetch` in `extension_freshness` across xdist workers with an `fcntl` lock (concurrent module imports raced `.git`).
- **package-shims**: Judge the dashboard intercept test by shell-profile PATH ([#3827](https://github.com/hashgraph-online/hol-guard/pull/3827)) Evidence for: **package-shims**: Judge the dashboard intercept test by shell-profile PATH ([#3827](https://github.com/hashgraph-online/hol-guard/pull/3827))
- The dashboard **Package managers -> Test** action now judges PATH activation with `package_shim_dashboard_status`, the same shell-profile projection the status cards use. The resident daemon never loads shell profiles… Evidence for: The dashboard **Package managers -> Test** action now judges PATH activation with `package_shim_dashboard_status`, the same shell-profile projection the status cards use. The resident daemon never loads shell profiles…
- `probe_package_shim_intercepts` gains a `project_shell_profile` option. The CLI and runtime callers keep probing against the caller's real PATH. Evidence for: `probe_package_shim_intercepts` gains a `project_shell_profile` option. The CLI and runtime callers keep probing against the caller's real PATH.
- New `hol-guard package-shims test [--manager ] --json` subcommand runs the intercept proof from a shell, behind the same approval gate as the dashboard action. Evidence for: New `hol-guard package-shims test [--manager ] --json` subcommand runs the intercept proof from a shell, behind the same approval gate as the dashboard action.
- **guard**: Load Cursor hooks by replacing unsupported beforeWriteFile ([#3825](https://github.com/hashgraph-online/hol-guard/pull/3825)) Evidence for: **guard**: Load Cursor hooks by replacing unsupported beforeWriteFile ([#3825](https://github.com/hashgraph-online/hol-guard/pull/3825))
- **New hook entry.** Guard now installs a `preToolUse` entry with `failClosed: true`. Its `matcher` is `^(Write|Edit|StrReplace|MultiEdit|Delete)$`, so the entry only fires for file mutation tools. Shell, MCP, and read… Evidence for: **New hook entry.** Guard now installs a `preToolUse` entry with `failClosed: true`. Its `matcher` is `^(Write|Edit|StrReplace|MultiEdit|Delete)$`, so the entry only fires for file mutation tools. Shell, MCP, and read…
- **Review decisions become deny.** Cursor only stops a `preToolUse` call when the answer is `deny`; an `ask` lets the tool run. Guard therefore answers review decisions for these tools with `deny`, the same way it… Evidence for: **Review decisions become deny.** Cursor only stops a `preToolUse` call when the answer is `deny`; an `ask` lets the tool run. Guard therefore answers review decisions for these tools with `deny`, the same way it…
- **Reinstall cleans up the old entry.** Reinstalling or upgrading removes the `beforeWriteFile` entries that earlier Guard releases wrote, so Cursor loads the file again. Hooks written by other tools under that event… Evidence for: **Reinstall cleans up the old entry.** Reinstalling or upgrading removes the `beforeWriteFile` entries that earlier Guard releases wrote, so Cursor loads the file again. Hooks written by other tools under that event…
- **sync**: Scrub CLI credential arguments from synced receipt commands ([#3824](https://github.com/hashgraph-online/hol-guard/pull/3824)) Evidence for: **sync**: Scrub CLI credential arguments from synced receipt commands ([#3824](https://github.com/hashgraph-online/hol-guard/pull/3824))
- When a receipt had no full action envelope, `envelopeRedacted` was forwarded as stored, `command` included, even if the current sync level is `full`. Evidence for: When a receipt had no full action envelope, `envelopeRedacted` was forwarded as stored, `command` included, even if the current sync level is `full`.
- `raw_command_text` and the encoded receipt command were sanitized with `redact_sensitive_text` only. Cloud review events already use the stronger scrubber, which also removes those credential arguments. Evidence for: `raw_command_text` and the encoded receipt command were sanitized with `redact_sensitive_text` only. Cloud review events already use the stronger scrubber, which also removes those credential arguments.
- **guard**: Let routine Codex apply_patch edits pass native review ([#3821](https://github.com/hashgraph-online/hol-guard/pull/3821)) Evidence for: **guard**: Let routine Codex apply_patch edits pass native review ([#3821](https://github.com/hashgraph-online/hol-guard/pull/3821))
- Parse the patch with the same grammar as Codex's own `apply_patch` parser, including where Codex trims a line before matching a hunk header. Every header Codex would act on is checked. Any line Codex would not accept… Evidence for: Parse the patch with the same grammar as Codex's own `apply_patch` parser, including where Codex trims a line before matching a hunk header. Every header Codex would act on is checked. Any line Codex would not accept…
- Grant `native_exact_safe_file_write` only when every target passes the existing workspace write check (workspace or registered worktree, sensitive-path, hidden-path, hard-link and autostart checks). Evidence for: Grant `native_exact_safe_file_write` only when every target passes the existing workspace write check (workspace or registered worktree, sensitive-path, hidden-path, hard-link and autostart checks).
- Also refuse targets that are agent instruction files (`AGENTS.md`, `CLAUDE.md` and similar) or sit under agent or VCS metadata directories (`.codex`, `.claude`, `.cursor`, `.agents`, `.git` and others). Both the name… Evidence for: Also refuse targets that are agent instruction files (`AGENTS.md`, `CLAUDE.md` and similar) or sit under agent or VCS metadata directories (`.codex`, `.claude`, `.cursor`, `.agents`, `.git` and others). Both the name…
- **runtime**: Retire the managed resident when its Guard home is deleted ([#3822](https://github.com/hashgraph-online/hol-guard/pull/3822)) Evidence for: **runtime**: Retire the managed resident when its Guard home is deleted ([#3822](https://github.com/hashgraph-online/hol-guard/pull/3822))
- **codex**: Stop holding ordinary Codex Git reads and skill reads, and explain authority repair ([#3808](https://github.com/hashgraph-online/hol-guard/pull/3808)) Evidence for: **codex**: Stop holding ordinary Codex Git reads and skill reads, and explain authority repair ([#3808](https://github.com/hashgraph-online/hol-guard/pull/3808))
- Codex Git reads.** The Codex hook bridge did not forward its execution environment to the daemon. The Claude Code, OpenCode, and bounded CLI bridges already do. Without it, the native Git-helper check treated the… Evidence for: Codex Git reads.** The Codex hook bridge did not forward its execution environment to the daemon. The Claude Code, OpenCode, and bounded CLI bridges already do. Without it, the native Git-helper check treated the…
- **daemon**: Read camelCase toolInput from ZCode, Devin and Grok hooks ([#3820](https://github.com/hashgraph-online/hol-guard/pull/3820)) Evidence for: **daemon**: Read camelCase toolInput from ZCode, Devin and Grok hooks ([#3820](https://github.com/hashgraph-online/hol-guard/pull/3820))
- native reviews never offered **Always allow exact action**; only "Allow just this once" appeared, and `raw_command_text` was empty Evidence for: native reviews never offered **Always allow exact action**; only "Allow just this once" appeared, and `raw_command_text` was empty
- saved exact-action allow/block decisions were never looked up Evidence for: saved exact-action allow/block decisions were never looked up
Other changes
1- Documented change: Guard 3.37.0 is a stable release cut from [`3efd6a6`](https://github.com/hashgraph-online/hol-guard/commit/3efd6a606479b944fa33ddd208ea030082c45bd4). **36 commits • 35 merged pull requests • 8 contributors** since [Guard 3.36.1](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.36.1). Evidence for: Documented change: Guard 3.37.0 is a stable release cut from [`3efd6a6`](https://github.com/hashgraph-online/hol-guard/commit/3efd6a606479b944fa33ddd208ea030082c45bd4). **36 commits • 35 merged pull requests • 8 contributors** since [Guard 3.36.1](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.36.1).
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: v3.36.1
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Evidence ledger0 credits
No credits are published for this release yet.