changelog 0.7.5 · Entire

changelog 0.7.5

caf774d→main·

Soph·1mo ago·1 file·+10 added/-0 removed

Sessions

9ede0afcc51eView transcript

[?
Update Changelog for Versions 0.7.4 and 0.7.5Claude Code·Opus 4.8[1m]·2 steps](/content/gh/entireio/cli/session/1b8dad00-b139-4cf3-b7c2-53c99e7a4228#timeline-9ede0afcc51e/index.html)

Changes

1

4 unmodified lines

5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20

4 unmodified lines

The format is based on [Keep a Changelog](https://keepachangelog.com/),
and this project adheres to [Semantic Versioning](https://semver.org/).

## [0.7.5] - 2026-06-04

### Security

- Closed a path-traversal / arbitrary-file-write vulnerability across the checkpoint, session, and agent-lifecycle paths: identifiers read from the shared `entire/checkpoints/v1` branch or from agent hook input flowed into filesystem paths without validation, so a crafted session ID could overwrite arbitrary files on `entire session resume` / `entire checkpoint rewind`. IDs are now validated at the read/dispatch boundaries, with `os.Root` containment as defense in depth ([#1365](https://github.com/entireio/cli/pull/1365))

### Fixed

- `git-remote-entire` now relays helper-status before checking the send-pack exit code, so per-ref rejections (branch protection, ref-name conflicts, permission denials) surface as `! [remote rejected]` with the real reason instead of a bare `send-pack exited with error: exit status 1` ([#1364](https://github.com/entireio/cli/pull/1364))

## [0.7.4] - 2026-06-04

### Added