devr-tools Release Notes
80 release notes curated from 3 sources by the Releasebot Team. Last updated: Sep 4, 2026
devr-tools Products
- Sep 4, 2026
- Date parsed from source:Sep 4, 2026
- First seen by Releasebot:Sep 4, 2026
v1.10.0
codeguard adds minimum-confidence policies and stamps its version into written configs.
1.10.0 (2026-09-04)
Features
- config: add a minimum-confidence policy for findings (53c7e5d)
- config: minimum-confidence policy and config version stamp (#178) (d9def6e)
- config: stamp the codeguard version into written configs (7d8ccd4)
- Sep 1, 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Sep 1, 2026
v1.9.0
codeguard releases scanner improvements for bounded vendored source scans and faster, lower-memory full scans.
1.9.0 (2026-09-01)
Features
- scanner: support bounded vendored source scans (11e8b3e)
Bug Fixes
- ci: document safe test profile read (cc307b2)
- scanner: bound and accelerate full scans (fad10f2)
- scanner: bound memory and accelerate full scans (#174) (24cb12c)
All of your release notes in one feed
Join Releasebot and get updates from devr-tools and hundreds of other software products.
- Sep 1, 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Sep 1, 2026
szr by devr-tools
v0.22.0
szr 0.22.0 adds settings for project rules opt-in and fixes shell rewrite and command replacement handling.
0.22.0 (2026-08-20)
Features
- settings: expose project rules opt-in (#85) (045b07a)
Bug Fixes
- engine: block project rewrites in shell wrappers (5189a2b)
- reject command replacement preferences (#89) (1c827f4)
- require opt-in for project rules (816fb20)
- rewrite: quote structured shell arguments (#86) (36d0626)
- Aug 30, 2026
- Date parsed from source:Aug 30, 2026
- First seen by Releasebot:Aug 30, 2026
v1.8.3
codeguard releases 1.8.3 with bug fixes that tighten structural analysis, improve ownership handling for C++ and Go, and stabilize finding identity while closing parser, compatibility, and scope gaps.
1.8.3 (2026-08-30)
Bug Fixes
- avoid conversion shape shadow (4d23d58)
- bound TypeScript captures to lexical scope (cb4f157)
- close C++ scope and namespace gaps (abdb752)
- close structural acceptance parser gaps (202c57f)
- close structural evidence compatibility gaps (7a5210a)
- close structural origin review findings (9cfe717)
- harden C++ structural ownership resolution (5fb8c7d)
- harden Go structural ownership state (2f2c286)
- merge Go field semantics and fallthrough state (ea8fa30)
- preserve Go conversion ownership (cbaa5e9)
- refine structural effect grammar (7c759d2)
- resolve C++ structural mutation ownership (84f1265)
- resolve Go structural mutation ownership (085af1a)
- resolve indexed Go conversions (394689b)
- resolve structural mutation ownership from scopes (#172) (cdac600)
- stabilize structural finding identity (14fe1d4)
- Aug 29, 2026
- Date parsed from source:Aug 29, 2026
- First seen by Releasebot:Aug 30, 2026
v1.8.2
codeguard 1.8.2 fixes scan evidence handling and strengthens security and structural rules awareness.
1.8.2 (2026-08-29)
Bug Fixes
- harden scan evidence edge cases (d2a4a36)
- make security scans workspace and fixture aware (0b86a3b)
- make structural mutation rules ownership aware (92e006a)
- make workspace security scans and structural rules evidence-aware (#170) (888d988)
- preserve evidence across precision boundaries (306b3b1)
- preserve hidden mutation message contract (6b6ec00)
- satisfy security lint checks (0c02e91)
Similar to devr-tools with recent updates:
- Smokeball release notes144 release notes · Latest Sep 4, 2026
- Cosmolex release notes20 release notes · Latest Jul 30, 2025
- PracticePanther release notes36 release notes · Latest Aug 11, 2026
- Salesforce release notes71 release notes · Latest Sep 1, 2026
- Microsoft release notes820 release notes · Latest Sep 4, 2026
- Zoom release notes210 release notes · Latest Aug 31, 2026
- Aug 29, 2026
- Date parsed from source:Aug 29, 2026
- First seen by Releasebot:Aug 29, 2026
v1.8.1
codeguard fixes baseline matching, Go naming and import handling in 1.8.1 bug fixes.
1.8.1 (2026-08-29)
Bug Fixes
- consume baseline matches deterministically (bf865ce)
- improve Go global and boolean naming precision (dcb4ad6)
- repair CodeGuard v1.8.0 regressions (#168) (7443747)
- report installed module version (f828a65)
- resolve Go imports by owning workspace module (8b952e3)
- satisfy strict lint checks (b4a1c18)
- Aug 29, 2026
- Date parsed from source:Aug 29, 2026
- First seen by Releasebot:Aug 29, 2026
v1.8.0
codeguard adds baseline governance and fixes lint checks in 1.8.0.
1.8.0 (2026-08-29)
Features
- add baseline governance (5e532a2)
- add baseline governance (#165) (5b47aba)
Bug Fixes
- satisfy baseline governance lint checks (19f1840)
- Aug 29, 2026
- Date parsed from source:Aug 29, 2026
- First seen by Releasebot:Aug 29, 2026
v1.7.3
codeguard fixes scanner precision for Go repositories in this bug fix release.
1.7.3 (2026-08-29)
Bug Fixes
- improve scanner precision for Go repositories (078c3b3)
- improve scanner precision for Go repositories (#163) (d6d7615)
- Aug 29, 2026
- Date parsed from source:Aug 29, 2026
- First seen by Releasebot:Aug 29, 2026
v1.7.2
codeguard fixes scanner precision issues in 1.7.2, improving release stability.
1.7.2 (2026-08-29)
Bug Fixes
- trigger release for scanner precision fixes (caaa85e)
- trigger release for scanner precision fixes (#161) (4cbb945)
- Aug 25, 2026
- Date parsed from source:Aug 25, 2026
- First seen by Releasebot:Aug 25, 2026
v1.7.1
codeguard fixes dead-code checks and reduces false positives while adding Go 1.23 support in Rust tests.
1.7.1 (2026-08-25)
Bug Fixes
- gate Rust dead-code Cargo execution (0440f94)
- reduce LMP false positives (12c2255)
- reduce LMP false positives (#158) (747086a)
- support Go 1.23 in Rust dead-code test (427c6f6)
- Aug 24, 2026
- Date parsed from source:Aug 24, 2026
- First seen by Releasebot:Aug 25, 2026
v1.7.0
codeguard adds toolchain dead-code scans and reduces LMP false positives in 1.7.0.
1.7.0 (2026-08-24)
Features
- add toolchain dead-code scans (03bd363)
Bug Fixes
- reduce LMP false positives (995501e)
- satisfy dead-code lint gates (67ed8ae)
- Aug 22, 2026
- Date parsed from source:Aug 22, 2026
- First seen by Releasebot:Aug 23, 2026
v1.6.0
codeguard adds benchmark report normalization and security coverage fixes in 1.6.0.
1.6.0 (2026-08-22)
Features
benchmark: normalize external scanner reports (31cb15a)
Bug Fixes
benchmark: release provenance and improve benchmark/security coverage (#152) (81b7cd9)
benchmark: satisfy strict lint (ff61aed)
ci: satisfy codeguard self-scan (a3bf7f6)
ci: use tagged SLSA generator workflow (e0b9a95)
security: reduce secret and OWASP detector gaps (7e9e3f5)
Original source - Aug 19, 2026
- Date parsed from source:Aug 19, 2026
- First seen by Releasebot:Aug 20, 2026
v1.5.4
codeguard 1.5.4 ships bug fixes that improve parser performance, tighten security and reliability, and bound history, provenance, and timeout reads to reduce unsafe behavior and DoS risk.
1.5.4 (2026-08-19)
Bug Fixes
- bound waiver audit history reads (4ecb4da)
- cap rule stats history reads (8aa4345)
- detect zero HTTP client timeouts (c664c33)
- parser: make Python call extraction linear (e3dd6d4)
- parser: make Python call extraction linear (#140) (0970150)
- quality: bound AI provenance git output (#139) (dc17db9)
- quality: cap git provenance output (8e95804)
- reject unsafe typeof null guards (e2f552e)
- reliability: bound zero timeout detection (e838116)
- scope nullable block guards to their bodies (fcb3023)
- security: avoid retaining dynamic regexes (1a55a38)
- security: avoid retaining dynamic regexes (#145) (3b6aa51)
- security: bound git history secret scans (3fa7c09)
- security: bound git-history parsing to prevent DoS (#146) (d0eb42f)
- use errors.Is for bounded history reads (b5076ff)
- Aug 19, 2026
- Date parsed from source:Aug 19, 2026
- First seen by Releasebot:Aug 19, 2026
v1.5.3
codeguard 1.5.3 ships bug fixes and security hardening, with tighter CI and release publishing checks, bounded parser and performance scans, improved goroutine loop detection, and safer TypeScript security scanning.
1.5.3 (2026-08-19)
Bug Fixes
- ci: require immutable GitHub Action refs (#111) (cbcea34)
- ci: validate Homebrew formula version (c6b52bd)
- ci: validate Homebrew formula version (#135) (3b14798)
- config: contain performance history path (#126) (5f2f133)
- make goroutine loop detection linear (b560584)
- parser: bound tree-sitter scan resources (c83a2ce)
- parser: bound tree-sitter scan resources (#133) (a0e4e3c)
- performance: cap complexity regression reads (fca8c4e)
- performance: cap complexity-regression reads to use corpus reader (#131) (25c173c)
- prevent tsconfig from narrowing security scans (a464824)
- quality: skip rolling-hash precompute when no full clone window exists (#125) (19c1874)
- release: protect trusted publishing environment (4350eb9)
- release: require protected release-publish environment for npm/PyPI OIDC publishing (#132) (43cff7e)
- reliability: make goroutine-in-loop detection linear to avoid quadratic AST walks (#130) (23f7558)
- security: contain slop history writes (d5209d5)
- security: contain slop history writes (#136) (6ebbafc)
- security: include targeted node_modules files in TypeScript semantic scans (#137) (0ef6ab1)
- security: scan targeted node modules semantically (728e527)
- Aug 18, 2026
- Date parsed from source:Aug 18, 2026
- First seen by Releasebot:Aug 19, 2026
v1.5.2
codeguard releases 1.5.2 with a broad set of bug fixes that tighten security, improve performance, and refine scan handling across AI triage, config, diff, quality, and C++ validation workflows.
1.5.2 (2026-08-18)
Bug Fixes
- ai: reject wrapped triage verdicts (c1b24a5)
- ai: reject wrapped triage verdicts (#113) (170844d)
- ai: scale triage request timeout (a8a6308)
- ai: scale triage timeout and report build versions (#101) (8434c22)
- bound one-use abstraction analysis (328f345)
- ci: restore Homebrew version extraction (ed71e23)
- config: contain legibility history path (94cb937)
- config: resolve dangling symlinks in artifact paths (fb5734d)
- config: restore complete config loader (7ca5d02)
- config: validate derived legibility-history path (#106) (59b0ba7)
- cpp: gate compiler validation behind trust opt-in (aee079d)
- cpp: gate compiler validation behind trust opt-in (#105) (1970289)
- diff: merge colliding diff scopes for overlapping targets (#115) (90744cb)
- diff: merge scopes for overlapping targets (1ca3fe1)
- fail closed when default scan config is missing (07bb894)
- make C-like class smell scans linear (fabf71d)
- performance: bound framework regex matches (62915df)
- performance: bound framework regex matches (#128) (52cfb39)
- prevent filename injection in format targets (e0b7ce8)
- prevent SARIF narrative secret leakage (aebc32c)
- quality: bound pnpm lockfile scanning (551993b)
- quality: bound pnpm lockfile scanning (#121) (d44cd26)
- quality: preserve capped reader failures (5a508f6)
- quality: preserve capped reader failures to prevent uncapped reads in diff scans (#120) (2e82480)
- quality: reuse duplicated knowledge regex (9f112fd)
- respect TypeScript config root exclusions (e86b29b)
- security: bound duplicate-code detection work (2ea8833)
- security: bound duplicate-code detection work (#112) (cc6b95c)
- security: detect multiline C++ TLS disabling (bc382c2)
- security: gate benchmark execution on trust opt-in (8dacc79)
- security: gate benchmark execution on trust opt-in (#102) (a2ea743)
- security: track identifier lines linearly (82ade0f)
- security: track identifier lines linearly (#110) (dc348e8)
- semantic: contain source snapshots within target (5a24381)
- version: read module build info (2f33945)
Curated by the Releasebot team
Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.