Download Latest Version dcg-x86_64-pc-windows-msvc.zip (5.9 MB)
Email in envelope

Get an email when there's a new version of Destructive Command Guard

Home / v0.9.2
Name Modified Size InfoDownloads / Week
Parent folder
install.sh 2026-08-03 133.0 kB
install.sh.minisig 2026-08-03 280 Bytes
install.sh.sha256 2026-08-03 77 Bytes
install.sh.sigstore.json 2026-08-03 3.8 kB
dcg-x86_64-unknown-linux-musl.tar.xz 2026-08-03 4.9 MB
dcg-x86_64-unknown-linux-musl.tar.xz.intoto.jsonl 2026-08-03 1.3 kB
dcg-x86_64-unknown-linux-musl.tar.xz.intoto.jsonl.minisig 2026-08-03 280 Bytes
dcg-x86_64-unknown-linux-musl.tar.xz.intoto.jsonl.sigstore.json 2026-08-03 3.7 kB
dcg-x86_64-unknown-linux-musl.tar.xz.minisig 2026-08-03 280 Bytes
dcg-x86_64-unknown-linux-musl.tar.xz.sha256 2026-08-03 103 Bytes
dcg-x86_64-unknown-linux-musl.tar.xz.sigstore.json 2026-08-03 3.7 kB
destructive_command_guard-v0.9.2-manifest.json 2026-08-03 12.2 kB
destructive_command_guard-v0.9.2-manifest.json.minisig 2026-08-03 280 Bytes
destructive_command_guard-v0.9.2-manifest.json.sha256 2026-08-03 113 Bytes
destructive_command_guard-v0.9.2-manifest.json.sigstore.json 2026-08-03 3.8 kB
install.ps1 2026-08-03 85.8 kB
install.ps1.minisig 2026-08-03 280 Bytes
install.ps1.sha256 2026-08-03 78 Bytes
install.ps1.sigstore.json 2026-08-03 3.7 kB
dcg-x86_64-apple-darwin.tar.xz.intoto.jsonl 2026-08-03 1.3 kB
dcg-x86_64-apple-darwin.tar.xz.intoto.jsonl.minisig 2026-08-03 280 Bytes
dcg-x86_64-apple-darwin.tar.xz.intoto.jsonl.sigstore.json 2026-08-03 3.8 kB
dcg-x86_64-apple-darwin.tar.xz.minisig 2026-08-03 280 Bytes
dcg-x86_64-apple-darwin.tar.xz.sha256 2026-08-03 97 Bytes
dcg-x86_64-apple-darwin.tar.xz.sigstore.json 2026-08-03 3.6 kB
dcg-x86_64-pc-windows-msvc.zip 2026-08-03 5.9 MB
dcg-x86_64-pc-windows-msvc.zip.intoto.jsonl 2026-08-03 1.3 kB
dcg-x86_64-pc-windows-msvc.zip.intoto.jsonl.minisig 2026-08-03 280 Bytes
dcg-x86_64-pc-windows-msvc.zip.intoto.jsonl.sigstore.json 2026-08-03 3.8 kB
dcg-x86_64-pc-windows-msvc.zip.minisig 2026-08-03 280 Bytes
dcg-x86_64-pc-windows-msvc.zip.sha256 2026-08-03 97 Bytes
dcg-x86_64-pc-windows-msvc.zip.sigstore.json 2026-08-03 3.6 kB
dcg-aarch64-pc-windows-msvc.zip.sha256 2026-08-03 98 Bytes
dcg-aarch64-pc-windows-msvc.zip.sigstore.json 2026-08-03 3.6 kB
dcg-aarch64-unknown-linux-gnu.tar.xz 2026-08-03 4.5 MB
dcg-aarch64-unknown-linux-gnu.tar.xz.intoto.jsonl 2026-08-03 1.3 kB
dcg-aarch64-unknown-linux-gnu.tar.xz.intoto.jsonl.minisig 2026-08-03 280 Bytes
dcg-aarch64-unknown-linux-gnu.tar.xz.intoto.jsonl.sigstore.json 2026-08-03 3.7 kB
dcg-aarch64-unknown-linux-gnu.tar.xz.minisig 2026-08-03 280 Bytes
dcg-aarch64-unknown-linux-gnu.tar.xz.sha256 2026-08-03 103 Bytes
dcg-aarch64-unknown-linux-gnu.tar.xz.sigstore.json 2026-08-03 3.7 kB
dcg-cosign-release.pub 2026-08-03 178 Bytes
dcg-cosign-release.pub.sha256 2026-08-03 89 Bytes
dcg-minisign-release.pub 2026-08-03 113 Bytes
dcg-minisign-release.pub.sha256 2026-08-03 91 Bytes
dcg-x86_64-apple-darwin.tar.xz 2026-08-03 4.5 MB
dcg-aarch64-apple-darwin.tar.xz.intoto.jsonl 2026-08-03 1.3 kB
dcg-aarch64-apple-darwin.tar.xz.intoto.jsonl.minisig 2026-08-03 280 Bytes
dcg-aarch64-apple-darwin.tar.xz.intoto.jsonl.sigstore.json 2026-08-03 3.8 kB
dcg-aarch64-apple-darwin.tar.xz.minisig 2026-08-03 280 Bytes
dcg-aarch64-apple-darwin.tar.xz.sha256 2026-08-03 98 Bytes
dcg-aarch64-apple-darwin.tar.xz.sigstore.json 2026-08-03 3.8 kB
dcg-aarch64-pc-windows-msvc.zip 2026-08-03 5.6 MB
dcg-aarch64-pc-windows-msvc.zip.intoto.jsonl 2026-08-03 1.3 kB
dcg-aarch64-pc-windows-msvc.zip.intoto.jsonl.minisig 2026-08-03 280 Bytes
dcg-aarch64-pc-windows-msvc.zip.intoto.jsonl.sigstore.json 2026-08-03 3.7 kB
dcg-aarch64-pc-windows-msvc.zip.minisig 2026-08-03 280 Bytes
dcg-aarch64-apple-darwin.tar.xz 2026-08-03 4.2 MB
SHA256SUMS 2026-08-03 1.0 kB
SHA256SUMS.minisig 2026-08-03 280 Bytes
SHA256SUMS.sigstore.json 2026-08-03 3.7 kB
SHA256SUMS.txt 2026-08-03 1.0 kB
README.md 2026-08-02 2.3 kB
v0.9.2 source code.tar.gz 2026-08-02 6.8 MB
v0.9.2 source code.zip 2026-08-02 7.2 MB
Totals: 65 Items   44.0 MB 0

v0.9.2

Second hardening patch from the continuing adversarial-review campaign over the v0.9.x line. Three independent reviewers probed the v0.9.1 fixes A/B against the released binaries on both evaluation routes; everything they surfaced is fixed here with regression coverage.

Fixed

  • Warn-mode batch masking: a Warn-mode toolCalls entry ended the request before later entries were evaluated, silently allowing them. The hook now resolves every entry and publishes exactly one response by precedence (Deny > Indeterminate > Ask > Warn > Allow).
  • Batch sibling decoys: a toolCalls envelope carrying a destructive tool_input/tool_args command evaluated only the batch; siblings are now evaluated too.
  • Protocol hijack by non-shell batches: any non-empty toolCalls array forced the Claude wire shape, so Gemini/Hermes/Grok/Codex payloads carrying a readFile-style batch got a deny their parsers drop; the branch now requires a shell entry.
  • mise modeled at its real grammar: global flags before the subcommand (mise -v exec -- …) and post-subcommand flags outside the modeled set bypassed the wrapper model on the real hook path; both engines now share one option table.
  • Constant-propagation hazards hardened: while read f, { read f; }, command read, if read, getopts, select, and IFS changes now refuse the variable proof; the NAME[/NAME= scan requires a word boundary (a regex class like conf[ig] or jq's .n[0] no longer reads as mutation); glob values are rejected only at unquoted use sites.
  • Oversized-command side effects: the v0.9.1 refactor made oversized payloads construct the history database and worker thread; restored to pre-construction refusal with byte-identical output.
  • Installers: install.ps1 quotes the Copilot hook binary path (spaced Windows profiles); the uninstaller anchors its machine marker.

Known-limitation follow-ups filed from the same review: [#259] (mise exec -c inline payloads), [#260] (frontend strip-failure blind spot).

Full details in the CHANGELOG. Same signing chain: SHA256 + minisign (69B3955C8D2E62A8) + Sigstore cosign + SLSA provenance on every artifact.

Source: README.md, updated 2026-08-02