rigscore v2.2.0
- #rigscore
- #security
- #ai
- #devtools
- #open-source
Changes: v2.1.0 → v2.2.0
10 features and 9 fixes. 19 changes total.
Features
- read Codex TOML and Goose YAML MCP surfaces
- CLI strictness, output emitters, badge/SARIF/score-history, pin & verify-state hardening
- BOM sniff, registry-derived scan surfaces, worktree skip, wider fixers + CI providers
- fix vendor MCP/cred paths + add qwen sandbox, new clients, agents/workflows skillDirs
- drive skill and command dirs from the client registry
- add codex-guards least-privilege starter pack
- make the semantic-judge command configurable
- register OpenClaw and Antigravity for config-at-rest scanning
- rename-safety parity + suppress/guards/fixture drift guards
- machine-readable rigscore-facts.json emitter + self-gate
Fixes
- cover the committed .codex/config.toml in the rug-pull pin
- atomic state writes, platform-aware permission tests, script load fixes
- emit POSIX separators in findings, SARIF and baseline keys
- flush help output and load checks via file URLs
- decouple HOME from project score, scan agent prompts + CLAUDE.local.md, tighten skill-files/git-hooks/settings
- retire obsolete toolpage version-patch; stamp docs date directly
- check out default branch for facts generator (tag lacks it)
- warn on unknown/dangling flags; fail loud on a malformed –fail-under
- honor scan opts, rescore suppress/ignore, harden –watch on Node 18
Install
1npx github:Back-Road-Creative/rigscore
No accounts, no telemetry, no network calls. MIT licensed.