Documented changes
33 typed entries
Verified contributors
Credits being verified. Attribution coverage is unknown.
Attribution coverage
attribution not yet verified; history inventory partial.
Install
Scope
Guard v3.38.0 is a stable release published 2026-10-09. Upstream documents: Guard 3.38.0 is a stable release cut from [`a1c20ef`](https://github.com/hashgraph-online/hol-guard/commit/a1c20ef1144988f8918046b61035025c38a07a8a). **19 commits • 19 merged pull requests • 2 contributors** since [Guard 3.37.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.37.0). Attribution for this release is being verified.
Changes
Added
1- **native**: Derive local CLI grant identity in the resident ([#3842](https://github.com/hashgraph-online/hol-guard/pull/3842)) Evidence for: **native**: Derive local CLI grant identity in the resident ([#3842](https://github.com/hashgraph-online/hol-guard/pull/3842))
Fixed
25- **doctor**: Warn when Codex skips untrusted Guard hooks or OMP code mode routes tools through eval ([#3843](https://github.com/hashgraph-online/hol-guard/pull/3843)) Evidence for: **doctor**: Warn when Codex skips untrusted Guard hooks or OMP code mode routes tools through eval ([#3843](https://github.com/hashgraph-online/hol-guard/pull/3843))
- Codex hook trust.** Codex runs user-layer hooks only when their stored `trusted_hash` matches the current hook definition. Guard binds hook commands to the exact versioned runtime, so every install or update changes… Evidence for: Codex hook trust.** Codex runs user-layer hooks only when their stored `trusted_hash` matches the current hook definition. Guard binds hook commands to the exact versioned runtime, so every install or update changes…
- **sonar**: Suppress S5856 false positive on fancy_regex lookbehind ([#3857](https://github.com/hashgraph-online/hol-guard/pull/3857)) Evidence for: **sonar**: Suppress S5856 false positive on fancy_regex lookbehind ([#3857](https://github.com/hashgraph-online/hol-guard/pull/3857))
- **codex**: Stop Desktop installs from blocking plain Git reads and cd ([#3847](https://github.com/hashgraph-online/hol-guard/pull/3847)) Evidence for: **codex**: Stop Desktop installs from blocking plain Git reads and cd ([#3847](https://github.com/hashgraph-online/hol-guard/pull/3847))
- **Desktop/MDM Codex bridge.** The frozen entry point answers Codex hooks before Guard is imported, and that path never attached the execution environment. With no environment, the native edge could not check Git helper… Evidence for: **Desktop/MDM Codex bridge.** The frozen entry point answers Codex hooks before Guard is imported, and that path never attached the execution environment. With no environment, the native edge could not check Git helper…
- **Pager settings.** `PAGER` or `GIT_PAGER` set to `less`, with only flags that take no argument, is now treated like Git's default pager, which is `less` anyway. Before this, a common shell setting was stricter than… Evidence for: **Pager settings.** `PAGER` or `GIT_PAGER` set to `less`, with only flags that take no argument, is now treated like Git's default pager, which is `less` anyway. Before this, a common shell setting was stricter than…
- **gpg.program.** A configured `gpg.program` no longer blocks `git log` or `git show` when signatures are not being shown. Evidence for: **gpg.program.** A configured `gpg.program` no longer blocks `git log` or `git show` when signatures are not being shown.
- **guard**: Launch Codex hooks on Windows ([#3846](https://github.com/hashgraph-online/hol-guard/pull/3846)) Evidence for: **guard**: Launch Codex hooks on Windows ([#3846](https://github.com/hashgraph-online/hol-guard/pull/3846))
- **gauntlet**: Keep Codex harness cases on the fixture's Codex home ([#3831](https://github.com/hashgraph-online/hol-guard/pull/3831)) Evidence for: **gauntlet**: Keep Codex harness cases on the fixture's Codex home ([#3831](https://github.com/hashgraph-online/hol-guard/pull/3831))
- **Cause:** `codex.exe` on Windows finds its home through the OS profile API, not `USERPROFILE`. The fixture sets `USERPROFILE`, but Codex never reads it. Evidence for: **Cause:** `codex.exe` on Windows finds its home through the OS profile API, not `USERPROFILE`. The fixture sets `USERPROFILE`, but Codex never reads it.
- **Effect:** Codex never saw the Guard hooks installed into the fixture, and it picked up the operator's own plugins and instructions. Every case reported "N of N tool calls ran without a Guard review", so the Windows… Evidence for: **Effect:** Codex never saw the Guard hooks installed into the fixture, and it picked up the operator's own plugins and instructions. Every case reported "N of N tool calls ran without a Guard review", so the Windows…
- **ci**: Queue main runs instead of cancelling in-flight ([#3852](https://github.com/hashgraph-online/hol-guard/pull/3852)) Evidence for: **ci**: Queue main runs instead of cancelling in-flight ([#3852](https://github.com/hashgraph-online/hol-guard/pull/3852))
- **gauntlet**: Accept Guard's observe-only answer to harness lifecycle hooks ([#3833](https://github.com/hashgraph-online/hol-guard/pull/3833)) Evidence for: **gauntlet**: Accept Guard's observe-only answer to harness lifecycle hooks ([#3833](https://github.com/hashgraph-online/hol-guard/pull/3833))
- they report `native_hook_event_unavailable`, Evidence for: they report `native_hook_event_unavailable`,
- they let the turn continue. Evidence for: they let the turn continue.
- **daemon**: Keep the daemon up while a request outlives the idle window ([#3845](https://github.com/hashgraph-online/hol-guard/pull/3845)) Evidence for: **daemon**: Keep the daemon up while a request outlives the idle window ([#3845](https://github.com/hashgraph-online/hol-guard/pull/3845))
- **ci**: Isolate Win32-descriptor test that poisons process-global os.lstat ([#3848](https://github.com/hashgraph-online/hol-guard/pull/3848)) Evidence for: **ci**: Isolate Win32-descriptor test that poisons process-global os.lstat ([#3848](https://github.com/hashgraph-online/hol-guard/pull/3848))
- **ci**: Let xdist restart a crashed worker and bound corpus workers higher ([#3839](https://github.com/hashgraph-online/hol-guard/pull/3839)) Evidence for: **ci**: Let xdist restart a crashed worker and bound corpus workers higher ([#3839](https://github.com/hashgraph-online/hol-guard/pull/3839))
- `--max-worker-restart 4`: a test that monkeypatches process-global `os`/`lstat` can poison an xdist worker; allow requeueing on a fresh worker instead of failing the whole shard on `INTERNALERROR` (observed… Evidence for: `--max-worker-restart 4`: a test that monkeypatches process-global `os`/`lstat` can poison an xdist worker; allow requeueing on a fresh worker instead of failing the whole shard on `INTERNALERROR` (observed…
- Corpus runner `WORKER_TIMEOUT_SECONDS` 60→120: the per-worker subprocess timeout expired under xdist + nested-worker oversubscription; the outer `elapsed<60s` gate still holds. Evidence for: Corpus runner `WORKER_TIMEOUT_SECONDS` 60→120: the per-worker subprocess timeout expired under xdist + nested-worker oversubscription; the outer `elapsed<60s` gate still holds.
- **runtime**: Refuse resident operations for another Guard home ([#3832](https://github.com/hashgraph-online/hol-guard/pull/3832)) Evidence for: **runtime**: Refuse resident operations for another Guard home ([#3832](https://github.com/hashgraph-online/hol-guard/pull/3832))
- **custom-extensions**: Let detected connections be forgotten and age out unused ones ([#3828](https://github.com/hashgraph-online/hol-guard/pull/3828)) Evidence for: **custom-extensions**: Let detected connections be forgotten and age out unused ones ([#3828](https://github.com/hashgraph-online/hol-guard/pull/3828))
- **Retention.** Guard drops detected records that were never added and have not been seen for 30 days. The prune runs inside the write transaction of an observation insert or refresh, and from the discover path, at most… Evidence for: **Retention.** Guard drops detected records that were never added and have not been seen for 30 days. The prune runs inside the write transaction of an observation insert or refresh, and from the discover path, at most…
- **History replay.** Discover rebuilds records from stored approval requests and receipts. It now uses each entry's own timestamp (the latest retry for an approval request) instead of the current time, never moves… Evidence for: **History replay.** Discover rebuilds records from stored approval requests and receipts. It now uses each entry's own timestamp (the latest retry for an approval request) instead of the current time, never moves…
- **Forget.** New `POST /v1/local-clis/forget` (dashboard token, same as the other local-CLI routes). It deletes one detected record and its inventory rows: commands, MCP catalog, provider actions, workflow proposals and… Evidence for: **Forget.** New `POST /v1/local-clis/forget` (dashboard token, same as the other local-CLI routes). It deletes one detected record and its inventory rows: commands, MCP catalog, provider actions, workflow proposals and…
Other changes
7- Documented change: Guard 3.38.0 is a stable release cut from [`a1c20ef`](https://github.com/hashgraph-online/hol-guard/commit/a1c20ef1144988f8918046b61035025c38a07a8a). **19 commits • 19 merged pull requests • 2 contributors** since [Guard 3.37.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.37.0). Evidence for: Documented change: Guard 3.38.0 is a stable release cut from [`a1c20ef`](https://github.com/hashgraph-online/hol-guard/commit/a1c20ef1144988f8918046b61035025c38a07a8a). **19 commits • 19 merged pull requests • 2 contributors** since [Guard 3.37.0](https://github.com/hashgraph-online/hol-guard/releases/tag/v3.37.0).
- **guard**: Run instruction access-graph test under the native digest fixture ([#3849](https://github.com/hashgraph-online/hol-guard/pull/3849)) Evidence for: **guard**: Run instruction access-graph test under the native digest fixture ([#3849](https://github.com/hashgraph-online/hol-guard/pull/3849))
- Pin local authority for opt-in Google Workspace CLI rules ([#3834](https://github.com/hashgraph-online/hol-guard/pull/3834)) Evidence for: Pin local authority for opt-in Google Workspace CLI rules ([#3834](https://github.com/hashgraph-online/hol-guard/pull/3834))
- **desktop-core**: Notarize the onefile and onedir archives concurrently ([#3853](https://github.com/hashgraph-online/hol-guard/pull/3853)) Evidence for: **desktop-core**: Notarize the onefile and onedir archives concurrently ([#3853](https://github.com/hashgraph-online/hol-guard/pull/3853))
- **release**: Trim checkout, discovery and relint time on the release path ([#3851](https://github.com/hashgraph-online/hol-guard/pull/3851)) Evidence for: **release**: Trim checkout, discovery and relint time on the release path ([#3851](https://github.com/hashgraph-online/hol-guard/pull/3851))
- **release**: 3.38.0 ([#3841](https://github.com/hashgraph-online/hol-guard/pull/3841)) Evidence for: **release**: 3.38.0 ([#3841](https://github.com/hashgraph-online/hol-guard/pull/3841))
- **extensions**: Publish descriptors for five command sources ([#3850](https://github.com/hashgraph-online/hol-guard/pull/3850)) Evidence for: **extensions**: Publish descriptors for five command sources ([#3850](https://github.com/hashgraph-online/hol-guard/pull/3850))
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: v3.37.0
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Evidence ledger0 credits
No credits are published for this release yet.