Phase 3c: re-point health.zig + trust.zig exclusion/path gates onto safety_core (isExcludedFromScan, hasSourceExtension, isExpectedBinaryPath) โ€” both hosts' repo-wide/trust scans now share the one canonical gate; safety.zig's copies drop to 0 external callers. Kept kepr-local: binaryBlobInSource (returns BlobKind core doesn't expose) + isAlwaysSafeUrl (URL context isn't a core concern) + analyzeBuildScriptEco/analyzeSupplyChain/provenance. Suite green 487+2 (v1.56.189)

dev · 9 weeks ago · 2026-06-26 · 14.9 MB

session: safety core extraction ยท agent: claude-opus-4-8

$ koh steal kepr.uk/kepr@7a64b1b2642e
·
← 7676ff698398 c00eb5697616 →
⇓ download .face