You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Added
Workspace-aware chain detection — monorepo support: reads workspace member Cargo.tomls to map each crate to its specific chains, eliminating cross-chain noise (SOL detectors no longer fire on NEAR/CosmWasm code in the same workspace)
Intra-file call graph analysis — builds per-file call graph from AST. Before emitting findings, checks if any caller already performs the relevant security check (signer, owner, input validation). Reduces false positives for helper functions called from checked entry points
Baseline diff for CI — --save-baseline <path.json> captures current findings; --baseline <path.json> shows only new findings. Fingerprints are line-number-independent (stable across code insertions)
Project config — .rustdefend.toml support with ignore (detector IDs), ignore_files (glob patterns), min_severity, min_confidence
Incremental scan caching — --incremental flag caches findings per file keyed by mtime. Unchanged files skip read/parse/detect entirely. Cache stored at --cache-path or <scan_root>/.rustdefend.cache.json