Skip to content

CodeRiskTools Scanner 3.1.1

Choose a tag to compare

@9batalion 9batalion released this 27 Jul 07:07

CodeRiskTools Scanner 3.1.1 is a hotfix release for local vulnerability scanning against the signed starter database.\n\nHighlights:\n- adds secret-scanner vuln scan --sbom FILE for local CycloneDX, SPDX and Syft JSON SBOM scans against an active SQLite vulnerability database;\n- preserves the signed starter database workflow from v3.1.0: 243,381 real CVE/OSV records, explicitly partial, SHA-256/Ed25519 verified;\n- verified positive local SBOM smoke against the active osv-partial-2026-07-23 database: pkg:bitnami/abantecart@1.3.1 produced 3 vulnerability findings;\n- documents the full OSV source ceiling currently at 813,101 records after future updates.\n\nThe v3.1.1 scanner reuses the pinned signed OSV database release asset from v3.1.0; this release updates the Python package and README/CLI behavior, not the database snapshot.\n\nVerification run:\n- focused SBOM/vuln/bootstrap suite: 17 tests OK;\n- full unittest suite: 1019 tests OK, 1 skipped;\n- compileall and diff check: PASS;\n- baseline self-scan: 0 findings, 0 stale baseline;\n- installed wheel smoke: secret-scanner 3.1.1, vuln scan --sbom returned 3 findings against the 243,381-record active DB.