Skip to content

Releases: BugTraceAI/BugTraceAI-CLI

BugTraceAI-CLI 4.0.31-beta

Pre-release

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 06 Oct 11:12

BugTraceAI-CLI 4.0.31-beta integrates with the universal visual Launcher for terminal TUI, web-scanning API/MCP, and combined setups. The Installer supports local Python and Docker, prepares missing runtime prerequisites, and can register the global btai command.

Provider/auth setup, real pipeline monitoring, and explicit manual/AI-agent runtime installation remain available. Install and update paths were validated on Ubuntu 24.04 amd64, including retained configuration/data and completed BugStore scans.

Start with the universal Launcher. macOS and ARM runtime validation are not included in this release.

BugTraceAI CLI 4.0.21-beta

Pre-release

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 04 Oct 17:36

The installation wizard now separates two decisions with short explanations:

  • Step 1 selects the terminal TUI, API/MCP backend or both. It clarifies that
    the WEB app is installed separately.
  • Step 2 selects local Python or Docker. It explains where dependencies are
    installed and that a Docker TUI still appears in your terminal.
  • A readable summary shows the selected interfaces and execution method before
    installation and in the completion instructions.

Option numbers, command-line flags, dependency selection and saved profiles
are unchanged. README and INSTALLATION explain the same choices. All text
is English. The existing Docker bootstrap and immediate TUI launch fixes are
retained.

Validation: 41 installer/profile/completion tests passed, including all six
interactive interface/runtime combinations. Shell syntax and whitespace
checks passed. The menu and summary were inspected without installing
packages or starting scans.

To see the questions again in an existing checkout:

git pull --ff-only
./install.sh

Use ./install.sh --reuse to update or repair using the saved selection;
that command skips the interface and execution questions.

BugTraceAI CLI 4.0.20-beta

Pre-release

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 04 Oct 17:11

The installer now offers to open the real TUI when an interactive TUI/both
installation finishes. The launch uses the checkout path, so it works before
the installing terminal has the new btai command directory in PATH.

Global registration distinguishes a command ready now from registration for
new terminals. It provides a current-shell activation command and an immediate
launch path, and clarifies that Docker may still request sudo at startup.

Press Enter at the final prompt to open the workspace, or n to finish.
--launch no skips the prompt; --launch yes launches directly and requires
a terminal. API-only and noninteractive runs do not show the launch prompt.
Quitting the TUI returns cleanly; a launch failure preserves the completed
installation and saved profile. Opening the workspace does not start a scan.

Validation: 54 installer/profile/bootstrap tests, including real-PTY completion
tests and fresh-shell command lookup. The actual installed TUI opened through
the updated completion step with no user command directory in PATH, and
Ctrl+Q returned status 0. Existing Docker/Compose bootstrap fixes are retained.

For an existing installation, update the checkout and reuse its saved profile:

git pull --ff-only
./install.sh --reuse

If the earlier installer stopped before saving a profile, use ./install.sh
instead. An already registered command can be used in the current terminal:

export PATH="$HOME/.local/bin:$PATH"
btai

BugTraceAI CLI 4.0.19-beta — installer fixes

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 04 Oct 14:33

The installer now prepares missing Docker Engine and Compose on Linux instead
of stopping with a manual-install message. Working runtimes are reused, and
the global btai command uses the same Docker access as the installer.

  • Choose TUI, API/MCP or both, then local Python or Docker. TUI-only Docker
    installations do not start server services or publish ports.
  • Fresh Ubuntu installs verify a complete virtual environment with pip and
    prepare missing system dependencies. Local Linux installs select PyTorch CPU.
  • Docker builds select the correct Nuclei binary for AMD64 or ARM64.
  • Installation profiles are saved after successful installation, and --reuse
    keeps the selected profile and configured ports.

Validation included 44 CLI installer tests, real installation of all three
Docker profiles, a complete local installation on Ubuntu 24.04, API/MCP
responses, global btai, Chromium startup and TUI tabs/Provider/Auth controls.
Native macOS and Apple Silicon installation were not tested on physical hardware.

For an existing checkout, update the repository and repair the saved profile:

git pull --ff-only
./install.sh --reuse

If the previous installer stopped before saving a profile, run ./install.sh
instead of --reuse to choose the interfaces and runtime again.

For fresh installations, follow INSTALLATION.md.

BugTraceAI CLI 4.0.16-beta

Pre-release

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 04 Oct 11:41

BugTraceAI CLI 4.0.16-beta brings the real scan pipeline into the Textual terminal workspace.

  • WEB-style purple/coral interface with Recon, Discovery, Strategy, Exploit, Validate and Report.
  • Pipeline, Findings, Agents, Timeline and Logs views with keyboard and mouse navigation.
  • Provider setup with a masked API key; target Auth setup with Bearer tokens or login YAML, including TOTP/2FA.
  • Installer profiles for TUI, API/MCP or both, using local Python or Docker.
  • Optional user-global btai command on macOS and Linux.

Install from the repository and run ./install.sh, then open ./bugtraceai-cli or the registered btai command. See INSTALLATION.md for the complete flow. tui --demo is an explicit offline preview; ordinary startup opens the real workspace.

Validation: 95 offline TUI/installer tests passed on the curated release copy; API import, wheel build and real terminal startup/Auth/quit were verified. The release preserves the public attribution documents and public commit history.

Installation documentation update (2026-10-04)

The updated README installation prompt lets your own coding agent install the real TUI and user-global btai, or choose API/MCP and Docker. See the current installation guide.

These documentation updates and the correction aligning public LICENSE/package metadata with the existing Apache-2.0 NOTICE are on main at e1b6d88. The original v4.0.16-beta tag is unchanged; clone main to use the updated files.

BugTraceAI CLI v3.7.28-beta

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 22 Sep 20:18

CLI release: Launcher-selected CLI and MCP listeners, shared-network integration with BugTraceAI-API and WEB, integrated ModelLab improvements, and API handoff support.

BugTraceAI-CLI v4.0.0

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 02 Sep 18:18

BugTraceAI-CLI v4.0.0 — Apache 2.0 refactor standard

What's new

  • Full refactor: CLIFramework migrated to modellab architecture
  • Apache 2.0 licensing (see NOTICE, LICENSE-HISTORY.md)
  • Attribution: Albert Corzo (lead), Ricardo Sánchez (portions)
  • Third-party software credited in THIRD_PARTY_NOTICES.md

Migration

  • Breaking changes from v3.x
  • See CHANGELOG.md for full list

License

  • BugTraceAI-owned portions: Apache 2.0
  • See LICENSE, NOTICE and LICENSE-HISTORY.md

v3.7.26-beta

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 30 Jul 22:06

Highlights

  • JWT head-start: the JWT specialist gets a bounded head-start before the rest of the specialist pool, so a cracked admin token is available to auth-dependent specialists from the start of exploitation instead of arriving mid-run.
  • IDOR accuracy: differential analysis now gates length/sensitive-data indicators on a successful (200) test response, fixing a false-confirm on 404 edge-case IDs that could stop candidate testing before reaching the real vulnerable ID.
  • Reporting accuracy: nuclei-sourced request/response evidence now reaches the PoC and CVSS enrichment prompts. A confirmed file-disclosure finding (e.g. local file inclusion) can no longer be downgraded to "not demonstrated" by the generic-probe guardrail when real evidence exists.
  • Deterministic Nuclei scanning: added a fixed-tag scan phase as a guaranteed floor before the opportunistic auto-scan phase, fixing run-to-run finding variance against an unchanged target. A Nuclei subprocess failure no longer takes down independent app-level checks (headers/cookies/GraphQL/rate-limiting).
  • Provider defaults: updated off a deprecated upstream model in the default OpenRouter preset.

Validation

Validated against BugStore (71.4% detectable recall via the project's benchmark scorer), ginandjuice.shop, and a live third-party target — clean runs, no regressions.

v3.7.17-beta

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 28 Jul 21:22

Fixes

Scanning with Anthropic or Z.ai works again. The pre-scan diagnostics gate read
OPENROUTER_API_KEY unconditionally, so a fully configured scan aborted with
"Diagnostics failed" while /health reported the key as present. The gate now reads the
ACTIVE provider preset, and the connectivity probe targets that provider's host.

Vision validation uses a model the active provider actually serves, instead of a slug
that returns 404 and silently disables visual proof.

Reports are viewable again. Finding.cvss_score was declared as a string while the
pipeline computes a number, so every report carrying a score failed validation and the
html/json/markdown endpoints returned 404.

Proof screenshots show the banner. The visual PoC payload contained literal spaces, so
in an unquoted attribute context the browser cut it at the first space and threw
"Unexpected end of input" — the screenshot never showed impact. The banner is now
whitespace-free.

Payloads survive the report. The narrative's quoted payload is fenced after the visual
upgrade, so it reaches the reader byte-exact instead of losing its backticks to the
markdown renderer. Report URLs keep gospider's FUZZ placeholder verbatim rather than
being rewritten into a URL that was never sent. sqlmap evidence keeps the verdict block
instead of the ASCII banner, which also restores DBMS detection.

Template injection. The CSTI prompt asked the model to prove with {{7*7}} while the
confirmation step only accepts 1000003*1000003 → 1000006000009, so its payloads could
never be accepted. Prompt and predicate now agree.

Known limitations

sqlmap boolean-based cookie SQLi can still report false CRITICALs; the XSS ladder can
still confirm on reflection contexts that cannot execute (<title>, <meta>); GoSpider's
read timeout can truncate recon without saying so.

v3.7.14-beta

Choose a tag to compare

@Acorzo1983 Acorzo1983 released this 27 Jul 15:06

v3.7.14-beta

  • Provider switching (Anthropic): fixed the provider connectivity Test and the runtime hot-switch. Both now use each provider's correct wire format — the Anthropic Messages API via x-api-key (previously an Authorization: Bearer header was always used), so a valid Anthropic API key is no longer falsely rejected. Switching between providers now fully reconfigures the LLM client, so requests aren't sent in a stale format after a switch.

Update: ./launcher.sh update