Download Latest Version dcg-x86_64-pc-windows-msvc.zip (5.9 MB)
Email in envelope

Get an email when there's a new version of Destructive Command Guard

Home / v0.9.0
Name Modified Size InfoDownloads / Week
Parent folder
destructive_command_guard-v0.9.0-manifest.json.sigstore.json 2026-08-02 3.8 kB
install.ps1 2026-08-02 85.5 kB
install.ps1.minisig 2026-08-02 280 Bytes
install.ps1.sha256 2026-08-02 78 Bytes
install.ps1.sigstore.json 2026-08-02 3.8 kB
install.sh 2026-08-02 130.8 kB
install.sh.minisig 2026-08-02 280 Bytes
install.sh.sha256 2026-08-02 77 Bytes
install.sh.sigstore.json 2026-08-02 3.8 kB
dcg-x86_64-pc-windows-msvc.zip.sha256 2026-08-02 97 Bytes
dcg-x86_64-pc-windows-msvc.zip.sigstore.json 2026-08-02 3.8 kB
dcg-x86_64-unknown-linux-musl.tar.xz 2026-08-02 4.9 MB
dcg-x86_64-unknown-linux-musl.tar.xz.intoto.jsonl 2026-08-02 1.3 kB
dcg-x86_64-unknown-linux-musl.tar.xz.intoto.jsonl.minisig 2026-08-02 280 Bytes
dcg-x86_64-unknown-linux-musl.tar.xz.intoto.jsonl.sigstore.json 2026-08-02 3.7 kB
dcg-x86_64-unknown-linux-musl.tar.xz.minisig 2026-08-02 280 Bytes
dcg-x86_64-unknown-linux-musl.tar.xz.sha256 2026-08-02 103 Bytes
dcg-x86_64-unknown-linux-musl.tar.xz.sigstore.json 2026-08-02 3.8 kB
destructive_command_guard-v0.9.0-manifest.json 2026-08-02 12.2 kB
destructive_command_guard-v0.9.0-manifest.json.minisig 2026-08-02 280 Bytes
destructive_command_guard-v0.9.0-manifest.json.sha256 2026-08-02 113 Bytes
dcg-minisign-release.pub 2026-08-02 113 Bytes
dcg-minisign-release.pub.sha256 2026-08-02 91 Bytes
dcg-x86_64-apple-darwin.tar.xz 2026-08-02 4.5 MB
dcg-x86_64-apple-darwin.tar.xz.intoto.jsonl 2026-08-02 1.3 kB
dcg-x86_64-apple-darwin.tar.xz.intoto.jsonl.minisig 2026-08-02 280 Bytes
dcg-x86_64-apple-darwin.tar.xz.intoto.jsonl.sigstore.json 2026-08-02 3.8 kB
dcg-x86_64-apple-darwin.tar.xz.minisig 2026-08-02 280 Bytes
dcg-x86_64-apple-darwin.tar.xz.sha256 2026-08-02 97 Bytes
dcg-x86_64-apple-darwin.tar.xz.sigstore.json 2026-08-02 3.7 kB
dcg-x86_64-pc-windows-msvc.zip 2026-08-02 5.9 MB
dcg-x86_64-pc-windows-msvc.zip.intoto.jsonl 2026-08-02 1.3 kB
dcg-x86_64-pc-windows-msvc.zip.intoto.jsonl.minisig 2026-08-02 280 Bytes
dcg-x86_64-pc-windows-msvc.zip.intoto.jsonl.sigstore.json 2026-08-02 3.8 kB
dcg-x86_64-pc-windows-msvc.zip.minisig 2026-08-02 280 Bytes
dcg-aarch64-pc-windows-msvc.zip.minisig 2026-08-02 280 Bytes
dcg-aarch64-pc-windows-msvc.zip.sha256 2026-08-02 98 Bytes
dcg-aarch64-pc-windows-msvc.zip.sigstore.json 2026-08-02 3.8 kB
dcg-aarch64-unknown-linux-gnu.tar.xz 2026-08-02 4.5 MB
dcg-aarch64-unknown-linux-gnu.tar.xz.intoto.jsonl 2026-08-02 1.3 kB
dcg-aarch64-unknown-linux-gnu.tar.xz.intoto.jsonl.minisig 2026-08-02 280 Bytes
dcg-aarch64-unknown-linux-gnu.tar.xz.intoto.jsonl.sigstore.json 2026-08-02 3.9 kB
dcg-aarch64-unknown-linux-gnu.tar.xz.minisig 2026-08-02 280 Bytes
dcg-aarch64-unknown-linux-gnu.tar.xz.sha256 2026-08-02 103 Bytes
dcg-aarch64-unknown-linux-gnu.tar.xz.sigstore.json 2026-08-02 3.7 kB
dcg-cosign-release.pub 2026-08-02 178 Bytes
dcg-cosign-release.pub.sha256 2026-08-02 89 Bytes
dcg-aarch64-apple-darwin.tar.xz 2026-08-02 4.2 MB
dcg-aarch64-apple-darwin.tar.xz.intoto.jsonl 2026-08-02 1.3 kB
dcg-aarch64-apple-darwin.tar.xz.intoto.jsonl.minisig 2026-08-02 280 Bytes
dcg-aarch64-apple-darwin.tar.xz.intoto.jsonl.sigstore.json 2026-08-02 3.8 kB
dcg-aarch64-apple-darwin.tar.xz.minisig 2026-08-02 280 Bytes
dcg-aarch64-apple-darwin.tar.xz.sha256 2026-08-02 98 Bytes
dcg-aarch64-apple-darwin.tar.xz.sigstore.json 2026-08-02 3.8 kB
dcg-aarch64-pc-windows-msvc.zip 2026-08-02 5.6 MB
dcg-aarch64-pc-windows-msvc.zip.intoto.jsonl 2026-08-02 1.3 kB
dcg-aarch64-pc-windows-msvc.zip.intoto.jsonl.minisig 2026-08-02 280 Bytes
dcg-aarch64-pc-windows-msvc.zip.intoto.jsonl.sigstore.json 2026-08-02 3.9 kB
SHA256SUMS 2026-08-02 1.0 kB
SHA256SUMS.minisig 2026-08-02 280 Bytes
SHA256SUMS.sigstore.json 2026-08-02 3.9 kB
SHA256SUMS.txt 2026-08-02 1.0 kB
README.md 2026-08-02 2.7 kB
v0.9.0 source code.tar.gz 2026-08-02 6.8 MB
v0.9.0 source code.zip 2026-08-02 7.2 MB
Totals: 65 Items   43.9 MB 0

v0.9.0

Closes the entire post-v0.8.0 issue backlog: two new agent surfaces and six user-reported defects, all with regression coverage.

Added

  • Posit Assistant support (idea from PR [#254], independently reimplemented). Installer/uninstaller manage a Claude-compatible PreToolUse hook in ~/.posit/assistant/settings.json with the lowercase exact matcher "bash|powershell" its matcher grammar requires; runtime detection via PA_PROJECT_DIR and the pa process name; a powershell tool inside a Posit hook now gets the Claude-compatible deny payload instead of Codex's minimal shape.
  • VS Code Agent Host batched toolCalls envelope (#252). The newer Copilot Agent Host envelope previously deserialized without a recognized command and failed open. Every shell entry in a batch is now extracted and evaluated; one destructive entry denies the whole batch.

Fixed

  • UTF-8 panic in dcg explain/dcg test when an escape character preceded a multi-byte character (#255) — all 21 escape-scanner sites now advance by the escaped character's real width.
  • Wrapper prefixes defeating data-flag masking (#257): mise exec --, nice, time, nohup, stdbuf, timeout, ionice, setsid, chrt no longer cause a commit-message word to trip core.git:restore-worktree; wrapped destructive commands still deny.
  • Leading VAR="$(cmd)" assignments misread as the executable (#256), which denied benign gh invocations whose search operands contained the letter c.
  • Cross-dialect ; artifacts tripping the git-alias boundary (#250): git status; ls, for d in …; do cd "$d" && git pull; done, and sh -c 'cd {} && git pull' no longer fail closed as git-alias-semantic-unverified.
  • for-loop literal narrowing (#242): for f in a b; do mv "$f" d/; done (and loop-bound redirect targets) now allow when every candidate value independently proves safe; all dynamic/rebinding variants still deny.
  • Installer interactivity (#251): prompts now read /dev/tty, so the documented interactive mode actually prompts under curl … | bash; the no-TTY path announces every auto-decision and honors the documented rustup default.
  • Copilot hook key casing reconciliation (#253): case-insensitive merge, dual-casing file repair, and casing-insensitive uninstall on both platforms.

Verification

Built and published via DSR. Every archive carries a SHA256 sidecar, minisign signature (key 69B3955C8D2E62A8), Sigstore cosign bundle (pinned local-release key), and SLSA provenance; SHA256SUMS is signed. Full CHANGELOG: https://github.com/Dicklesworthstone/destructive_command_guard/blob/main/CHANGELOG.md

Source: README.md, updated 2026-08-02