Bounded asynchronous command execution for Hooks v2.
Build an inherited environment safe to pass to hook subprocesses.
Strips values whose names look like secrets. Hooks are user-authored trusted code, but secret values should not be ambiently available.
Run one hook command with bounded time and captured output.
Structured diagnostic produced while processing a hook.
Compatible hook output with retained extension fields.
One ordered command handler in a configuration snapshot.
Validated output and diagnostics from one command handler.