Skip to content

Release v1.0.4

Choose a tag to compare

@github-actions github-actions released this 27 Apr 17:38
· 82 commits to main since this release

Version v1.0.4 - April 27, 2025

  • Built for multiple platforms
  • Precompiled binaries included
  • Docker image available at ghcr.io/CybeDefend/cybedefend-cli:v1.0.4

New Features

Enhanced Scan Command

  • Wait for scan completion: The scan command now supports waiting for scan completion with the --wait flag (enabled by default). This allows users to track the progress of their scan until it finishes.

  • Scan status polling: When waiting for scan completion, the tool polls the API at regular intervals (configurable with --interval, default: 5 seconds) to check scan progress.

  • Break build functionality: Two new options have been added to control CI/CD pipeline behaviors:

    • --break-on-fail: Makes the command exit with an error code if the scan fails
    • --break-on-severity: Makes the command exit with an error code if vulnerabilities of the specified severity or above are detected
      • Possible values: critical, high, medium, low, none (to explicitly disable this feature)
      • Only vulnerabilities in states "to_verify" and "confirmed" are counted (vulnerabilities marked as "resolved" or "not_exploitable" are ignored)
  • Vulnerability summary: After scan completion, the tool provides a detailed breakdown of vulnerabilities by severity level, showing counts for each severity.

API Improvements

  • Scan ID handling: The tool now correctly handles the scan ID whether it's returned in the scanId field or the message field of the API response, ensuring compatibility with API changes.

  • Enhanced error handling: Better handling of API errors and scan failures with informative messages.

Example Usage

# Start a scan and wait for it to complete (default behavior)
cybedefend scan --dir ./my-project

# Start a scan and make the build fail if the scan fails
cybedefend scan --dir ./my-project --break-on-fail

# Start a scan and make the build fail if critical vulnerabilities are detected
cybedefend scan --dir ./my-project --break-on-severity critical

# Start a scan and make the build fail if medium or higher vulnerabilities are detected
cybedefend scan --dir ./my-project --break-on-severity medium

# Start a scan, show vulnerability summary but do not break the build regardless of findings
cybedefend scan --dir ./my-project --break-on-severity none

# Change the scan status check interval to 10 seconds
cybedefend scan --dir ./my-project --interval 10

Technical Improvements

  • Added new API client methods to support scan status checking
  • Added vulnerability filtering to exclude resolved and non-exploitable issues
  • Improved logging to provide more detailed progress information during scans
  • Enhanced error handling for better reliability in CI/CD environments