Skip to content

Releases: Chorolee/permitprobe

PermitProbe v0.2.1

Choose a tag to compare

@Chorolee Chorolee released this 08 Oct 08:31
3c58fbe

PermitProbe v0.2.1 release notes

PermitProbe v0.2.1 hardens report confidentiality, validation availability, evidence lineage and
release provenance following an independent adversarial review of v0.2.0.

Report privacy

Discovery no longer guesses whether an observed path segment is sensitive from its length or
entropy. A response-derived literal survives only when it already occurs in a declared resource
path or is explicitly listed in api.discovery.report_path_literals. Query names follow the same
rule through declared public query contracts and report_query_names. All other values become
{value} or a redacted-name count; reports retain only the number of merged observed variants.

Because different raw locations can now share one safe shape, discovery.* findings are not
eligible for known-finding baselines. They remain visible until the operator adds an explicit
route contract or removes the discovery source.

Bounded validation

api.validation_timeout_ms sets a total wall-clock budget, defaulting to 5000 ms, for JSON
parsing, JSON Schema evaluation and collection/object identity checks in one execution batch.
The budget measures local validation work rather than network time. Expiration records
data.validation_budget, preserves completed delivery evidence and exits 2.

This closes cases where a small response combined with an expensive regular expression, or a
bounded response containing a costly uniqueItems comparison, could occupy a runner beyond the
HTTP timeout.

Active exploration shares one validation budget across its batches and clips each validation to
the remaining total exploration deadline. The POSIX signal-based interrupt requires main-thread
execution with no pre-existing ITIMER_REAL; unsupported library embeddings fail closed as
inconclusive instead of validating without a deadline.

Target-bound evidence

The normalized target scheme, hostname and port now participate in the policy digest. Findings,
baselines, exploration checkpoints and retests are therefore bound to the environment that
produced them. A deployment label cannot turn a finding into fixed on a different origin.

This deliberately invalidates v0.2.0 baseline continuity. Run v0.2.1 against the intended target,
review its findings and create a new baseline. Do not copy or edit old digest values.

Release provenance

The registry-publishing workflow checks out the exact requested tag. Before PyPI upload, it
compares every installed package file in the wheel and sdist with that checkout and verifies the
sdist pyproject.toml byte-for-byte. GitHub asset digests, metadata checks and the isolated-wheel
safe demo remain required.

PermitProbe v0.2.0

Choose a tag to compare

@Chorolee Chorolee released this 08 Oct 06:10
563c83f

PermitProbe v0.2.0 release notes

PermitProbe v0.2.0 turns the original API boundary checker into a contract-driven one-shot
website assessment while retaining its explicit request and data boundaries.

Highlights

  • permitprobe scan runs the configured OpenAPI inventory, handoff inspection, bounded route
    discovery, declared GET checks and known-finding baseline as one verdict.
  • Public routes can enforce status, JSON shape, no-store, request variants and latency without
    requiring test accounts.
  • Authorization policies support bearer or cookie identities, complete caller/owner coverage,
    collection ownership, signed-file redirect shapes and private-cache headers.
  • Local OpenAPI documents expose uncovered or stale GET contracts without generating requests.
  • Fixed seed pages, /robots.txt and /sitemap.xml can produce sanitized route proposals. A
    discovered location is never fetched or promoted into executable policy automatically.
  • Known-finding baselines, evidence-linked retests and model-neutral bounded exploration preserve
    incomplete results and failed checks.

Upgrade notes

The policy format remains version 1, and a valid v0.1.1 policy remains valid. Object resources
now probe every declared victim by default, so an existing policy can produce more GET requests.
Set api.probe_victims to "one" only when representative coverage is intentional; max_cases
continues to reject an oversized plan before network delivery.

JSON reports move from schema version 1 to schema version 2. Integrations must accept the new
policy digest, evidence, coverage and grouped-finding fields. Prior schema-version-1 reports
cannot be used as retest inputs.

Proposal discovery is opt-in through api.discovery and is used only by scan. It performs
anonymous GETs to at most four configured seeds and the two optional known files. Reports omit
response bodies, raw discovered URLs and query values, and token-shaped path segments are
replaced with {value}.

Release verification

The release commit must pass the complete loopback test suite and Ruff on Python 3.11 and 3.14.
The wheel and source distribution must pass strict Twine validation. The built wheel is then
installed into a new virtual environment, where its version, generated policy schema and safe
synthetic demo are executed before any release assets are published.

PyPI publication remains a separate, manually invoked Trusted Publishing workflow. That workflow
downloads the already-published GitHub release assets, verifies their GitHub SHA256 digests and
package identity, and can validate without uploading.

PermitProbe v0.1.1

Choose a tag to compare

@Chorolee Chorolee released this 07 Oct 06:21

PermitProbe 0.1.1 is the renamed release of the project previously called BoundaryGuard. The PyPI name boundaryguard belongs to an unrelated project, so the repository, Python distribution, import package, CLI, example policy and manifest names now consistently use PermitProbe/permitprobe.

Security Maintainer: Susan (@Chorolee)

Included:

  • Explicit security-maintainer responsibilities and project origin in the public documentation.
  • Enabled GitHub Private Vulnerability Reporting.
  • GET API authorization and response-data checks, plus Gitleaks-backed text handoff checks.
  • A PyPI Trusted Publishing workflow that validates GitHub asset SHA256 digests and package identity before uploading the exact release bytes.

Validation:

  • 106 tests passed, including actual loopback HTTP and Gitleaks integration.
  • Python 3.11 and 3.14 CI passed tests, lint, and package builds.
  • Wheel and sdist passed strict Twine metadata validation.
  • The renamed wheel executed its safe demo outside the repository.
  • Publication-source secret scan: zero findings.

CI: https://github.com/Chorolee/permitprobe/actions/runs/37580915453

Installation:
python -m pip install permitprobe==0.1.1

Alternatively, install from the GitHub release files:
Download permitprobe-0.1.1-py3-none-any.whl and run python -m pip install ./permitprobe-0.1.1-py3-none-any.whl. Install Gitleaks 8.30.1 separately using scripts/install_gitleaks.py from the source distribution/repository.

PyPI publication completed through GitHub Trusted Publishing: https://pypi.org/project/permitprobe/0.1.1/
Both published file hashes match the GitHub assets. The PyPI wheel was downloaded, installed, and its working demo verified. Publication workflow: https://github.com/Chorolee/permitprobe/actions/runs/37581493836
No external user adoption or dependent projects are claimed.

The historical v0.1.0 tag and distribution files are unchanged. This is not a database/RLS audit or an MCP runtime enforcement release. See README and SECURITY.md for supported scope and reporting.

v0.1.0 — API, data and AI handoff boundary checks

Choose a tag to compare

@Chorolee Chorolee released this 07 Oct 05:59

First public release of BoundaryGuard, an Apache-2.0 CLI for repeatable API, response-data, and AI handoff checks.

Implemented:

  • GET-only REST authorization cases planned and classified with Overstep 1.5.0.
  • Per-identity positive controls and returned-object identity verification.
  • JSON Schema contracts for successful and denied responses.
  • Explicit text-file handoff boundaries, Gitleaks 8.30.1 scanning, and exact-byte ZIP bundles with SHA256 manifests.
  • Secret-free reports, strict configuration, auth-only Overstep matrix export, and synthetic safe/leaky/expired demos.

Validation: 94 tests passed locally. Python 3.11 and 3.14 CI both passed tests, lint, and package builds. The built wheel passed its working demo outside the source checkout. Publication-source secret scan found zero matches.

CI: https://github.com/Chorolee/boundaryguard/actions/runs/37578945837

Scope: initial release; declared GET JSON endpoints and selected UTF-8 files only. No direct database/RLS proof, MCP runtime enforcement, complete PII detection, or production-service integration is claimed. Gitleaks is installed separately with the pinned-hash installer in the source distribution.

See README.md for setup and SECURITY.md for private vulnerability reporting.

Package registry note: the PyPI project named boundaryguard is unrelated to this repository. Install this release from the attached wheel or source distribution. The project is now PermitProbe; v0.1.1 contains the renamed package and CLI. PermitProbe 0.1.1 is published at https://pypi.org/project/permitprobe/0.1.1/.