- Guard 2: add /tmp/* to allowlist so normal temp file cleanup is not blocked - Guard 1: block bare `git push --force` (no branch arg) since upstream may point to primary branch - Guard 4: allow flags between verb and branch (`git switch --detach main`), escape branch name for regex safety, exclude -b/-B/-c/-C (branch creation) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| hooks | ||
| agent-session.sh | ||
| ci-debug.sh | ||
| ci-helpers.sh | ||
| env.sh | ||
| load-project.sh | ||
| matrix_listener.service | ||
| matrix_listener.sh | ||
| parse-deps.sh | ||