feat(system): security: expand git deny rules from 10 to 23 — block all mutating git and all gh commands, only drone @git subcommands can modify git state

Co-Authored-By: @devpulse <devpulse@aipass>
This commit is contained in:
AIOSAI
2026-04-23 00:51:23 -07:00
co-authored by @devpulse
parent 23453a30e7
commit 02fb4c8ae5
+21 -8
View File
@@ -10,15 +10,28 @@
],
"deny": [
"EnterPlanMode",
"Bash(git add -f*)",
"Bash(git add --force*)",
"Bash(git add*)",
"Bash(git commit*)",
"Bash(git push*)",
"Bash(git pull*)",
"Bash(git merge*)",
"Bash(git rebase*)",
"Bash(git reset*)",
"Bash(git checkout*)",
"Bash(git switch -c*)",
"Bash(git switch --create*)",
"Bash(git branch -c*)",
"Bash(git branch --copy*)",
"Bash(git branch -m*)",
"Bash(git branch --move*)",
"Bash(git switch*)",
"Bash(git branch*)",
"Bash(git cherry-pick*)",
"Bash(git stash*)",
"Bash(git tag*)",
"Bash(git revert*)",
"Bash(git rm*)",
"Bash(git mv*)",
"Bash(git clean*)",
"Bash(git restore*)",
"Bash(gh pr *)",
"Bash(gh issue *)",
"Bash(gh repo *)",
"Bash(gh api *)",
"Read(/home/patrick/Patrick-Personal/**)",
"Edit(/home/patrick/Patrick-Personal/**)",
"Write(/home/patrick/Patrick-Personal/**)",