Repository navigation
Releases: BitterSecurity/Decepticon
Release list
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
Changelog
- 6a9d54c feat(opplan): enforce versioned evidence-backed DAG execution
v1.2.0
v1.1.47
v1.1.46
v1.1.45
v1.1.44
v1.1.44 includes the cumulative changes since the previous public release,
v1.1.40. Versions v1.1.41–v1.1.43
remained unpublished GitHub drafts.
Added
- Autohunt autonomous planning: a separate bootstrap planning lane accepts
an explicitly authorized target and validates planning documents and scope
before marking the engagement ready. Soundwave remains the default
interview-first planner. (#813) - Specialist validation contracts: executable capability contracts,
evidence validation, lane scorecards, held-out evaluation fixtures, CVE-Bench
dispatch plumbing and pinned MITRE STIX bootstrapping. (#811) - Provider support: default AWS Bedrock routes and native Kimi for Coding
support, including launcher onboarding. (#796, #803) - Evidence controls: local API ingestion, dependency reachability evidence
and severity ceilings. Provider calls gain extra-header and streaming
controls; dynamic workload teardown is scoped by engagement and run. (#801) - Typed finding-location guidance in the skill catalog. (#810)
Fixed
-
Restore the Autohunt graph export so the LangGraph server can start and
register all standard assistants. (#820) -
Restore missing OPPLAN workspaces before filesystem bootstrap and preserve
native Ollama tool calls by buffering tool-bound requests. (#807) -
Match recursive domain wildcards in Rules of Engagement. (#800)
-
Fall back correctly when provider status is malformed. (#794)
-
Preserve the release JSON payload used by the installer's stable-version
resolver. (#795) -
Restore OSS installation readiness with the Neo4j pin and stricter handling
of missing installation secrets and legacy salt fallback. (#804) -
Support Python package metadata 2.5 in release publishing. (#805)
-
Disable the oversized, duplicate per-platform BuildKit sandbox SBOM while
retaining provenance and the merged-manifest CycloneDX/signing path. (#806) -
Use the canonical
BitterSecurityrepository and container registry paths
for release publishing, image pulls, installation and launcher updates.
Security and operational changes
- Update Next.js and its ESLint configuration to 16.3.5, addressing the
critical AVIF image-optimization advisory and other Next.js advisories.
Update CLI Vitest to 3.2.7 to remove its critical advisory. Other npm
dependency advisories remain; this is a targeted security update. - Update Python dependencies to address security advisories, including
AnyIO 4.14.2 and SoupSieve 2.9. (#797, #817) - Reject default launcher credentials and disable telemetry in
.env.example.
The onboarding wizard still preselects telemetry sharing; select
"No, keep it off" or setDECEPTICON_TELEMETRY=offto disable it.
Add a release image-digest manifest workflow for immutable image pinning.
Existing installations using default credentials or missing secrets must
update their configuration before starting. (#802, #804) - An Electron dashboard shell and cloud-session support were added, then
marked deprecated. The web dashboard and CLI remain the supported paths.
(#730, #798, #802)