Forgeflow V4.3.58 ยท 8 June 2026
Release: Review-Auto Sandbox Proposal Runner
Forgeflow 4.3.58 lands Phase 5 of the review-auto sandbox path. Safe findings can now produce isolated, validated proposal artifacts before any real checkout apply flow exists.
Sandbox Proposal Runner
- New
/forgeflow-review-autofix-sandbox --proposal <json>command generates local proposal artifacts without mutating the source checkout. - New
run-review-autofix-sandbox.jshelper copies the checkout into an isolated temp sandbox, applies explicit deterministic operations there, and runs declared focused validation there. - Successful runs write
proposal.json,proposal.md, andproposal.diffunder.forgeflow/<project>/review-auto/proposals/.
Safety Boundaries
- The runner reuses the Phase 4 policy contract and rejects findings that are not eligible for sandbox proposals.
- Absolute paths, parent traversal, source symlinks, and symlinked proposal-output directories are rejected.
- The runner does not generate patches from prose, apply fixes to the real checkout, commit, push, call GitHub, or dispatch workers.
Install And Docs Wiring
- The helper is managed by install, update, health, runtime inventory, and release-readiness checks.
- README and wiki command references now describe the Phase 5 proposal path beside the Phase 4 classifier and evidence commands.
- The release gate now includes the sandbox runner focused test.
Validation
- Full
scripts/forgeflow/test-*.jssuite node scripts/forgeflow/test-run-review-autofix-sandbox.jsnode scripts/forgeflow/test-install-manifest.jsnode scripts/forgeflow/test-runtime-helper-contract.jsnode scripts/forgeflow/test-command-coverage.jsnode scripts/forgeflow/test-doc-links.jsnode scripts/forgeflow/smoke-check.js --mode source --jsonnode scripts/forgeflow/render-release-readiness.js --jsongit diff --check