## Dicklesworthstone/destructive_command_guard — v0.14.2…v0.14.3

_11 commits._

### Fixes
- **fix(evaluator): evaluate a PowerShell assignment's right-hand side as a command** (5e66143)
- **fix(packs): evaluate a keyword-less external pack, and make the listings agree** (070e8c7)
- **fix(database): require SQL statement shape for TRUNCATE** (8a579b5)
- **fix(filesystem): judge an inline payload's redirect in the payload's own coordinates** (99599fe)
- **fix(git): a read-only subcommand survives an unresolvable path operand** (ff3ef99)

### Backend
- **Release v0.14.3 bug fixes** — Released v0.14.3 with fixes for five false-positive reports where unresolved operands incorrectly blocked safe, read-only commands. The release adds stricter evidence validation, expands coverage for missing edge cases like keyword-less packs and $x = cmd /c patterns, and includes a new test corpus of safe developer commands to prevent future regressions. (953c5e3)

### Tests
- **test: pin a corpus of ordinary developer commands against the false-positive class** (87557ea)

### Docs
- **Clarify dcg test vs hook differences** — Added documentation explaining how the `dcg test` command differs from the actual git hook when evaluating commands. The hook evaluates full tool payloads with knowledge of which tool it's gating, while `dcg test` evaluates a conservative union of all tool views, which may be more restrictive. (86288b9)
- **Clarify assignment RHS evaluation** — Updated changelog documentation to clarify that the right-hand side of assignments is properly evaluated by the security pipeline, not skipped. This fix closes a gap where dangerous commands like `$x = cmd /c "del /f /s /q C:\Windows"` were previously not caught. (3dd1e17)
- **docs(changelog): record the five-report false-positive wave** (90a25cd)

### Chore
- **Ignore additional lock files** — Updated git configuration to ignore `.br-db-openers-*.lock` files, which are temporary lock files created during repository operations. This prevents these transient runtime files from appearing as untracked changes. (061426c)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/Dicklesworthstone/destructive_command_guard?utm_source=github-action)._