|
# ~/.codex/rules/default.rules |
|
|
|
# Git inspection |
|
prefix_rule( |
|
pattern = ["git", ["status", "diff", "log", "show"]], |
|
decision = "allow", |
|
justification = "Allow read-only Git inspection.", |
|
) |
|
|
|
# Repository search |
|
prefix_rule( |
|
pattern = [["rg", "grep", "sed"]], |
|
decision = "allow", |
|
justification = "Allow source-code inspection.", |
|
) |
|
|
|
# Node.js / TypeScript package managers |
|
prefix_rule( |
|
pattern = ["npm", ["test", "run"]], |
|
decision = "allow", |
|
justification = "Allow npm project scripts.", |
|
) |
|
prefix_rule( |
|
pattern = ["yarn", ["test", "run"]], |
|
decision = "allow", |
|
justification = "Allow Yarn project scripts.", |
|
) |
|
prefix_rule( |
|
pattern = ["pnpm", ["test", "run", "exec"]], |
|
decision = "allow", |
|
justification = "Allow pnpm project scripts.", |
|
) |
|
prefix_rule( |
|
pattern = ["bun", ["test", "run"]], |
|
decision = "allow", |
|
justification = "Allow Bun project scripts.", |
|
) |
|
|
|
# TypeScript tooling |
|
prefix_rule( |
|
pattern = ["npx", "tsc"], |
|
decision = "allow", |
|
justification = "Allow TypeScript compiler execution.", |
|
) |
|
prefix_rule( |
|
pattern = ["npx", ["eslint", "prettier"]], |
|
decision = "allow", |
|
justification = "Allow linting and formatting tools.", |
|
) |
|
|
|
# Dangerous filesystem operations |
|
prefix_rule( |
|
pattern = ["rm", "-rf"], |
|
decision = "forbidden", |
|
justification = "Never recursively force-delete files.", |
|
) |
|
|
|
# Dangerous Git operations |
|
prefix_rule( |
|
pattern = ["git", "push", "--force"], |
|
decision = "forbidden", |
|
justification = "Never force-push.", |
|
) |
|
prefix_rule( |
|
pattern = ["git", "reset", "--hard"], |
|
decision = "forbidden", |
|
justification = "Never discard repository changes with reset --hard.", |
|
) |
|
prefix_rule( |
|
pattern = ["git", "clean", "-fd"], |
|
decision = "forbidden", |
|
justification = "Never recursively remove untracked files.", |
|
) |