safe-chains 0.232.4

Auto-allow safe bash commands in agentic coding tools
Documentation
1
2
3
4
5
6
7
8
9
[[command]]
name = "base64"
aliases = ["gbase64"]
description = "Encodes or decodes data in Base64 representation. No network access and no ability to execute the decoded output. The two implementations differ in a way that matters and that a single flag list cannot express. GNU coreutils reads stdin or a file operand and always writes stdout; its `-i` is `--ignore-garbage`, a boolean that only affects decoding. The macOS/BSD build instead takes `-i INPUT` and `-o OUTPUT` as VALUED flags, so on that platform base64 does write to the filesystem, at whatever path `-o` names — and `-i` is valued rather than boolean, the opposite of GNU. Because the same spelling is a boolean on one platform and takes a value on the other, either modelling is wrong somewhere: read as GNU (as here), a BSD `-i FILE` leaves FILE parsed as a positional, which is still a content read and gated as one. Ships with GNU coreutils and macOS."
url = "https://www.gnu.org/software/coreutils/manual/coreutils.html#base64-invocation"
level = "Inert"
bare = true
standalone = ["--decode", "--help", "--ignore-garbage", "--version", "-D", "-V", "-d", "-h", "-i"]
valued = ["--wrap", "-b", "-w"]