Skip to content

Releases: DobermanCore/Doberman-Core

v0.18.7 — phone approvals and closed bypasses

Choose a tag to compare

@fu351 fu351 released this 09 Sep 22:54
f05b7e5

Doberman can now push an approval challenge to your phone, so you can tap Approve or Deny from anywhere instead of walking back to the machine. The rest of the release closes ways a destructive command could slip past the scanner, and stops a Claude Code hook from failing open when nobody answers in time.

Highlights

  • Phone approvals. doberman phone setup sends two-factor and elevation challenges to your phone through ntfy with Approve and Deny buttons; on the 2FA tiers the tap replaces the TOTP code.
  • Wrapper bypasses closed. A destructive or egress command hidden behind builtin, eval, strace, flock, unshare, or taskset now classifies the same as its unwrapped form instead of passing.
  • Hooks can no longer fail open. Claude Code hook entries pin a timeout that outlasts Doberman's challenge ceiling, so a timed-out hook cannot let the call through before Doberman denies.
  • Deletes approved through a host hook are re-checked. The prompt shows the blast radius, and the delete is verified again before it runs, denying if the files changed since you approved.
  • A post-approval BLOCK revokes the elevation it just granted, instead of leaving it live until its TTL expires.
  • The decision log records who decided. Every row now carries which code path resolved an authentication and whether a person actually approved it, both readable from doberman log --jsonl.

Upgrade
pip install -U doberman-core, then re-run doberman install-hooks (add --host cursor if you use Cursor) to pick up the hook timeout pin. An existing install keeps its old un-pinned entry until you do, and doberman doctor flags it. Phone approvals are opt-in: doberman phone setup.

One thing worth knowing before you turn phone approvals on: the push carries the command the agent asked to run, with credential-shaped tokens masked, so that command line reaches whichever ntfy server you point at. --server points setup at a self-hosted instance instead of the public one.

Full changelog: https://github.com/DobermanCore/Doberman-Core/blob/main/CHANGELOG.md#v0187--2026-09-09 · Compare: v0.18.6...v0.18.7 · Thanks @harshitagrawal2O, @Maqbool61, @Som0111, @be-student, @vortsghost2025, @jasperdingg.

v0.18.6 — security hardening and UX overhaul

Choose a tag to compare

@fu351 fu351 released this 05 Sep 05:06
cd28023

This release closes several detection bypasses, including a dialog bug that let an expired denial execute, and rebuilds setup, the dashboard, the TUI, and the auth dialog.

Highlights

  • Closes detection bypasses in renamed tools, shell wrappers, and reverse shells; a keypress while the auth dialog closes can no longer approve an expired denial
  • Dashboard and TUI become real decision browsers, with filters, keyboard shortcuts, and a full explanation view; the auth dialog asks one question per screen
  • doberman setup is rebuilt with a dry-run preview, honest exit codes, and a closing doctor pass
  • Cursor gets an experimental native-hooks adapter with a session heartbeat and a doctor check

Upgrade
pip install -U doberman-core. If you rely on a custom rule, detector, or auth-provider plugin, run doberman plugins enable <name> after upgrading — plugins no longer auto-load.

Full changelog: https://github.com/DobermanCore/Doberman-Core/blob/main/CHANGELOG.md#v0186--2026-09-04 · Compare: v0.18.5...v0.18.6 · Thanks @thesageak.

v0.18.5 — decision-log retention, update nudges, dashboard polish

Choose a tag to compare

@fu351 fu351 released this 30 Aug 10:13
d7723a8

Decision-log rows can now be pruned by age or row budget without touching pending approvals, and doberman update plus a passive nudge in status tell you when you're behind on PyPI. The dashboard lets you copy a pending approval's details and shows the real Doberman mark; doctor reports your password factor and optional UI extras.

Highlights

  • doberman decision-log-prune deletes resolved rows by age or row budget; pending approvals are never touched.
  • doberman update checks PyPI and prints the upgrade command; status nudges when you're behind.
  • Dashboard: copy a pending approval's redacted details as JSON; stats update the instant a decision lands.
  • doberman doctor reports your password factor and whether the dash/tui extras are installed.
  • doberman egress-velocity sets burst/volume/fan-out thresholds from the CLI, not just by hand-editing policy.

Upgrade
pip install -U doberman-core. No action needed.

Full changelog: https://github.com/DobermanCore/Doberman-Core/blob/main/CHANGELOG.md#v0185--2026-08-30 · Compare: v0.18.4...v0.18.5 · Thanks @slegarraga, @Maqbool61, @navaneethsankar07.

v0.18.4 — friction fixes; telemetry on by default

Choose a tag to compare

@fu351 fu351 released this 27 Aug 05:57
68b3b11

Repeating an already-approved action now needs only a one-click confirm, not the full ladder again. Two loose ends close too: a global hook that kept firing after uninstall, and a way to spot a hook whose doberman binary is unreachable. Telemetry is now on by default, with a one-time notice and full opt-out.

Highlights

  • A repeat of an already-approved action needs only a one-click confirm, not the full ladder.
  • doberman uninstall --global now removes global hooks, state, factors, then the package.
  • doberman doctor catches a dangling hook with an unreachable doberman binary.
  • Telemetry is on by default; doberman telemetry off or DO_NOT_TRACK still opt out.
  • doberman demo --quiet runs as a CI smoke test, printing only the summary and exit code.

Upgrade
pip install -U doberman-core. Telemetry is on by default now — run doberman telemetry off to opt out.

Full changelog: https://github.com/DobermanCore/Doberman-Core/blob/main/CHANGELOG.md#v0184--2026-08-26 · Compare: v0.18.2...v0.18.4

v0.18.2 — fewer false prompts, hardened secret detection

Choose a tag to compare

@fu351 fu351 released this 26 Aug 07:02
6ee34e2

Doberman was flagging ordinary identifiers, paths, and UUIDs as if they were secrets, firing unnecessary approval prompts — sometimes gating a whole session's egress off one UUID in a temp path. That's fixed: real credentials still catch every time, but benign-looking strings pass now. This release also adds opt-in telemetry and a documentation site.

Highlights

  • Ordinary identifiers, paths, and UUIDs no longer trigger false secret-detection prompts.
  • Every real credential still triggers correctly — detection strength is unchanged, only false positives are removed.
  • The secret rule self-checks at import and fails closed if it's ever broken.
  • New opt-in telemetry: doberman telemetry on|off|status, off by default.
  • A new documentation site at docs.trydoberman.dev, plus a full docs rewrite.

Upgrade
pip install -U doberman-core. No action needed.

Full changelog: https://github.com/DobermanCore/Doberman-Core/blob/main/CHANGELOG.md#v0182--2026-08-26 · Compare: v0.18.1...v0.18.2

v0.18.1 — README images fixed for PyPI

Choose a tag to compare

@fu351 fu351 released this 15 Aug 08:48
17de540

A docs-only patch: the README's logo and demo GIF now use absolute URLs, so they render on the PyPI project page too, not just on GitHub. Nothing else changed.

Highlights

  • README logo and demo GIF render on the PyPI project page, not only on GitHub.

Upgrade
pip install -U doberman-core. No action needed.

Full changelog: https://github.com/DobermanCore/Doberman-Core/blob/main/CHANGELOG.md#v0181--2026-08-15 · Compare: v0.18.0...v0.18.1

v0.18.0 — a security-audit wave and guardrail improvements

Choose a tag to compare

@fu351 fu351 released this 15 Aug 07:42
671386f

Three security fixes, held privately until all were ready, close gaps in how Doberman protects itself: a credential could leak through an error result or a structured/embedded channel, per-user auth state wasn't recognized as protected, and a Windows-style path could slip past a control-plane rule. All three are fixed now.

Highlights

  • A secret in an error result, or in structured/embedded output, is now caught by the output gate too.
  • Per-user auth state (TOTP seed, lockout counter, password hash) is now protected as control plane.
  • A control-plane path spelled with Windows-style separators is now recognized, not just POSIX-style.
  • A previously-fixed path-canonicalization bypass (GHSA-4vvj-9m89-648r) is now published with full detail.
  • Also: a gated doberman uninstall, doberman 2fa reset-lockout, doberman taint clear, and a webhook audit sink.

Upgrade
pip install -U doberman-core. Upgrade promptly — this release closes real security gaps.

Full changelog: https://github.com/DobermanCore/Doberman-Core/blob/main/CHANGELOG.md#v0180--2026-08-15 · Compare: v0.17.1...v0.18.0

v0.17.1 — UX polish and machine-readable output

Choose a tag to compare

@fu351 fu351 released this 07 Aug 22:15
56bd64e

A UX and machine-readable-output pass from a full audit of the CLI and dashboard. Verdicts render the same way everywhere (color-safe, alignment-stable), every AUTH channel now shows its auto-deny deadline, and the read-only commands can emit --json/--jsonl for scripting. Nothing about how decisions are made changes.

Highlights

  • Verdict output is consistent everywhere: color-safe, NO_COLOR-aware, alignment never shifts.
  • Every AUTH prompt (TTY, GUI, dashboard) now shows its auto-deny deadline; doberman status lists recent auto-denials.
  • scan, doctor, policy-history, and log support --json/--jsonl for piping into other tools.
  • doberman dashboard is renamed to doberman session-summary; the old name still works as an alias.
  • Dashboard: AA-contrast verdict badges, a polite live region for pending approvals, arm-then-confirm on Approve.

Upgrade
pip install -U doberman-core. No action needed — doberman dashboard keeps working under its old name.

Full changelog: https://github.com/DobermanCore/Doberman-Core/blob/main/CHANGELOG.md#v0171--2026-08-07 · Compare: v0.17.0...v0.17.1 · Thanks @slegarraga, @AshSgDe29071999, @NanoRisk6.

v0.17.0 — a runtime egress broker, plus three security fixes

Choose a tag to compare

@fu351 fu351 released this 30 Jul 20:23
bd48337

This release adds a runtime egress broker: register one and Doberman enforces a destination allowlist at the socket, not just in static analysis, and can hard-block disallowed egress in Paranoid mode. It's dormant and backward-compatible until you register a broker. Three security fixes also land, closing gaps in auth timeouts and command-hidden network reach.

Highlights

  • New doberman.egress package: a pluggable broker enforces a host allowlist at the socket.
  • An unanswered AUTH challenge now auto-denies on a deadline instead of blocking forever.
  • Network reach hidden inside shell_exec, package_install, or git_op is now visible to guardrails.
  • A padded path spelling (trailing dots or spaces) now matches its unpadded form.
  • CI/CD config protection extends to GitLab CI, Jenkins, CircleCI, and Azure Pipelines.

Upgrade
pip install -U doberman-core. No broker is registered by default, so egress enforcement stays off until you add one.

Full changelog: https://github.com/DobermanCore/Doberman-Core/blob/main/CHANGELOG.md#v0170--2026-07-30 · Compare: v0.16.0...v0.17.0

v0.16.0 — raise-only egress detection in shell, package, and git commands

Choose a tag to compare

@fu351 fu351 released this 23 Jul 23:24
c962a3e

Doberman now looks inside shell_exec, package_install, and git_op commands for a hidden network destination, instead of treating them as opaque. A command that also carries a secret now blocks outright; one with an ambiguity signal (a dynamic host, a proxy override, unbalanced quoting) now requires authentication. This is raise-only: never a new pass, never a lowered verdict.

Highlights

  • Commands like curl, wget, pip, and git push are parsed for the destination they hide.
  • A command carrying both a secret and network egress now blocks outright.
  • An ambiguous command (dynamic host, proxy override, unbalanced quoting) now requires authentication.
  • A parser that fails on a command now fails closed instead of passing it through.
  • doberman.__version__ now comes from package metadata, so it can't drift from the release.

Upgrade
pip install -U doberman-core. No action needed.

Full changelog: https://github.com/DobermanCore/Doberman-Core/blob/main/CHANGELOG.md#v0160--2026-07-23 · Compare: v0.15.0...v0.16.0