aboutsummaryrefslogtreecommitdiffziptar.gz
path: root/CHANGES.md
diff options
context:
space:
mode:
authorgodosa <godosa@godosa.eu>2026-10-07 07:44:16 +0200
committergodosa <godosa@godosa.eu>2026-10-07 07:44:16 +0200
commit9d5641fe6585a61894f7b7427a68c794e5efe76d (patch)
tree79ebae3131df1c50542420db9e5ecb44e3d22076 /CHANGES.md
parent81d4e80fd5aabe4e80f58e960affa795cf7d34ec (diff)
downloadworkflow-9d5641fe6585a61894f7b7427a68c794e5efe76d.tar.gz
workflow-9d5641fe6585a61894f7b7427a68c794e5efe76d.zip
Denylist guard at commit time (pre-commit + commit-msg hooks); drop publish_snapshot
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JEAjUkQRrCYX5MZhWxdtj2
Diffstat (limited to 'CHANGES.md')
-rw-r--r--CHANGES.md1
1 files changed, 1 insertions, 0 deletions
diff --git a/CHANGES.md b/CHANGES.md
index 5f02c1e..e108b07 100644
--- a/CHANGES.md
+++ b/CHANGES.md
@@ -1,4 +1,5 @@
# Changes (newest first)
+- 2026-10-07 Denylist guard at commit time: `.githooks/pre-commit` (staged lines + paths) and `.githooks/commit-msg` run `scripts/denylist_check.py` against the git-ignored `publish-denylist.local` (worktree top + main tree, plus `git config denylist.file` lists; `word` / `!token` exemption / `#`, case-insensitive; output `word #<line>` only; no list → warning). Enable per clone: `git config core.hooksPath .githooks`; audit: `denylist_check.py tree`. `scripts/publish_snapshot.py` removed (history is public now). Projects: nothing.
- 2026-10-07 Tests use generic fixtures (/h/u, 10.0.0.x) instead of real home-dir and LAN paths (publish-scan clean). Projects: nothing.
- 2026-10-06 Tool path is now `/projects/public/workflow` (was `/projects/workflow`): docs, shared CLAUDE.md, skills, wf-worker agent, messages. `wf projects` / `wf usage --report` scan the grandparent when the parent holds no project. Projects: point `~/.claude` symlinks/settings, `wf-res.service` and any script calling `wf.py` at the new path.