Windows junction/reparse security update

usesteady@0.1.0-alpha.72 remains an affected historical release for the Windows junction/reparse containment issue.

usesteady@0.1.0-alpha.73 is now available as the hardened successor for this tested issue. The npm alpha dist-tag resolves to 0.1.0-alpha.73.

npm install -g usesteady@alpha

The interactive approval gate still applies to .72; the affected behavior concerns filesystem destination containment.

Publishing .73 does not retroactively fix .72, and the successor evidence is not a universal filesystem-security or Production-readiness claim.

Security details

Developer CLI

AI proposes. Interactive steps wait for approval. Then the approved step runs.

--yes and break-glass skip per-step prompts.

UseSteady inspects a workflow, shows the exact SYSTEM WILL operation, and waits for approval before each interactive step. Resume from a visible token without inheriting prior approval.

Vague input is not executed as SYSTEM WILL. UseSteady asks for a more specific request.

SYSTEM WILL
- Replace 3000 to 10000 in src/config/api.ts
[a] Approve   [r] Reject

You are reading the exact operation, not a guess.

GitHub · npm alpha.73 · Contact: support@usesteady.dev

Apache 2.0. Shortgigs LLC.