Repository navigation
Release v1.0.4
Version v1.0.4 - April 27, 2025
- Built for multiple platforms
- Precompiled binaries included
- Docker image available at ghcr.io/CybeDefend/cybedefend-cli:v1.0.4
New Features
Enhanced Scan Command
-
Wait for scan completion: The scan command now supports waiting for scan completion with the
--waitflag (enabled by default). This allows users to track the progress of their scan until it finishes. -
Scan status polling: When waiting for scan completion, the tool polls the API at regular intervals (configurable with
--interval, default: 5 seconds) to check scan progress. -
Break build functionality: Two new options have been added to control CI/CD pipeline behaviors:
--break-on-fail: Makes the command exit with an error code if the scan fails--break-on-severity: Makes the command exit with an error code if vulnerabilities of the specified severity or above are detected- Possible values:
critical,high,medium,low,none(to explicitly disable this feature) - Only vulnerabilities in states "to_verify" and "confirmed" are counted (vulnerabilities marked as "resolved" or "not_exploitable" are ignored)
- Possible values:
-
Vulnerability summary: After scan completion, the tool provides a detailed breakdown of vulnerabilities by severity level, showing counts for each severity.
API Improvements
-
Scan ID handling: The tool now correctly handles the scan ID whether it's returned in the
scanIdfield or themessagefield of the API response, ensuring compatibility with API changes. -
Enhanced error handling: Better handling of API errors and scan failures with informative messages.
Example Usage
# Start a scan and wait for it to complete (default behavior)
cybedefend scan --dir ./my-project
# Start a scan and make the build fail if the scan fails
cybedefend scan --dir ./my-project --break-on-fail
# Start a scan and make the build fail if critical vulnerabilities are detected
cybedefend scan --dir ./my-project --break-on-severity critical
# Start a scan and make the build fail if medium or higher vulnerabilities are detected
cybedefend scan --dir ./my-project --break-on-severity medium
# Start a scan, show vulnerability summary but do not break the build regardless of findings
cybedefend scan --dir ./my-project --break-on-severity none
# Change the scan status check interval to 10 seconds
cybedefend scan --dir ./my-project --interval 10Technical Improvements
- Added new API client methods to support scan status checking
- Added vulnerability filtering to exclude resolved and non-exploitable issues
- Improved logging to provide more detailed progress information during scans
- Enhanced error handling for better reliability in CI/CD environments