Filesystem containment security update

usesteady@0.1.0-alpha.72 remains an affected historical release for the Windows junction/reparse containment issue.

usesteady@0.1.0-alpha.73 corrected the tested junction/reparse path, but its released package has a separate confirmed hardlink alias-object defect affecting existing-file mutations. The npm alpha dist-tag currently resolves to 0.1.0-alpha.73; do not treat it as a hardlink correction. See the security notice.

No upgrade command to the current alpha dist-tag is recommended as a correction for the separate hardlink finding. Assess the named risks before using .73.

The interactive approval gate still applies to .72; the affected behavior concerns filesystem destination containment.

Publishing .73 does not retroactively fix .72, and the successor evidence is not a universal filesystem-security or Production-readiness claim.

Developer CLI

AI proposes. Interactive steps wait for approval. Then the approved step runs.

--yes and break-glass skip per-step prompts.

UseSteady inspects a workflow, shows the exact SYSTEM WILL operation, and waits for approval before each interactive step. Resume from a visible token without inheriting prior approval.

Vague input is not executed as SYSTEM WILL. UseSteady asks for a more specific request.

SYSTEM WILL
- Replace 3000 to 10000 in src/config/api.ts
[a] Approve   [r] Reject

You are reading the exact operation, not a guess.

GitHub · npm alpha.73 · Contact: support@usesteady.dev

Apache 2.0. Shortgigs LLC.