Skip to content

1.7.4.post12

Latest

Choose a tag to compare

@FabioLeitao FabioLeitao released this 30 Jul 01:06
v1.7.4.post12
0eeda68

Release 1.7.4.post12 (PyPI publish counter)

Status: Published on PyPI (2026-07-30 00:42:09 UTC). Operator publish-pypi workflow_dispatch: build → TestPyPI → PyPI.

Public line (marketing): 1.7.4 — README, man pages, stakeholder copy unchanged.

Build / PyPI / About: 1.7.4.post12 — PEP 440 post-release (publish counter per ADR-0073 § PyPI dual counters).

Not in this drop: Git tag · GitHub Release · Docker / container image (PyPI-only .postN).

Theme: Supply-chain floor for gitpython via optional extra [grc-dashboard] (N=1). Nine Dependabot HIGH alerts on the runtime lockfile path; one advisory is only fixed in 3.1.55 (Dependabot PR #1335 stopped at 3.1.54). Streamlit declares gitpython!=3.1.19,<4,>=3.0.7 — compatible with >=3.1.55 (measured against streamlit 1.58.0 and 1.60.0 on PyPI).


Mandatory map: postNmaturity_build

Per ADR-0073: postN counts PyPI uploads; maturity_build counts discrete fixes and may run ahead. This map is the mandatory audit trail.

PyPI / [project] version maturity_build (octet) Notes
1.7.4 .201 GA on PyPI (immutable); release PR #1024
1.7.4.post1 .202 SQL drivers → optional extras (#1047) — published
(fix, unpublished on PyPI) .203 #1026
(fix, unpublished on PyPI) .204 #1028
(fix, unpublished on PyPI) .205 Deploy / packaging fix train
(fix, unpublished on PyPI) .206 main.py --version without config
(fix, unpublished on PyPI) .207 fix(connectors) symlink / reparse-point loop guard (#1080)
1.7.4.post2 .208 Prior upload on this line
(fix, unpublished on PyPI) .209 SQL sampling failures now surface in scan_failures (#1140, #1144)
(fix, unpublished on PyPI) .210 Encrypted/corrupt archive members now surface in scan_failures (open-core slice of #828, #1146)
1.7.4.post3 .211 Published with soupsieve CVE fix (#1177)
(fix, unpublished on PyPI) .212 RBAC now defaults to deny on the full route map (#1133).
(fix, unpublished on PyPI) .213 API key comparison now uses UTF-8 byte-safe compare_digest (#1150).
(fix, unpublished on PyPI) .214 Operator-gated reopen workflow pins were restored to keep governance automation stable.
(fix, unpublished on PyPI) .215 SQL sampling transaction scope is now isolated per connection (#1194).
(fix, unpublished on PyPI) .216 One-class compliance profiles now preserve declared-term detections (#1195).
(fix, unpublished on PyPI) .217 XLSX exports now neutralize formula-leading cells to prevent spreadsheet injection (#1201).
(fix, unpublished on PyPI) .218 Web exposure defaults now enforce a safe-by-default posture for remote surface (#1202).
(fix, unpublished on PyPI) .219 Follow-up CodeQL logging and import-cycle hardening landed on the web-exposure path (#1202).
(fix, unpublished on PyPI) .220 Remaining routes-context import cycle was removed to stabilize route wiring.
(fix, unpublished on PyPI) .221 Config redaction now masks DSN/URL embedded credentials in /config (#1137).
(fix, unpublished on PyPI) .222 Prefilter now preserves recall parity with active profile terms/regexes (#1198).
(fix, unpublished on PyPI) .223 Help output now aligns dev invocation and installed command contract (#1130).
(fix, unpublished on PyPI) .224 Demo sessions now resolve audit trail correctly via /logs/{session_id} (#1218).
(fix, unpublished on PyPI) .225 Logs fallback hardening removed the CodeQL path-injection sink in demo retrieval (#1218, 4bd3e5bc).
1.7.4.post4 .226 Pillow 12.2.012.3.0 (PYSEC-2026-2253..2257); baseline post3 + N=15.
(fix, unpublished on PyPI) .227 Align ATS import footer skill path to private (#1191).
(fix, unpublished on PyPI) .228 Standalone HTML form CSRF without WebAuthn (#1231).
(fix, unpublished on PyPI) .229 Dataverse org_url / token_url SSRF guards (#1232).
(fix, unpublished on PyPI) .230 Aggregate archive decompression budgets (#1233).
(fix, unpublished on PyPI) .231 Reject non-finite max_expansion_ratio (nan/inf).
(fix, unpublished on PyPI) .232 Secret-by-identity lock + reachable JWT GRACE (#1210, #1212).
(fix, unpublished on PyPI) .233 Fail-closed on non-numeric license exp claim.
(fix, unpublished on PyPI) .234 Honest build_digest_matched (no signature_ok overclaim) (#1211).
(fix, unpublished on PyPI) .235 Zero legacy build_digest_matched bit on migrate (#1211).
(fix, unpublished on PyPI) .236 Drop Invoke-Expression from external-review-pack.ps1 (#1192).
(fix, unpublished on PyPI) .237 Read .7z members via py7zr BytesIOFactory (#1250, #1248).
(fix, unpublished on PyPI) .238 Extract pre-budget .7z members on budget stop (#1250, #1248).
(fix, unpublished on PyPI) .239 Orphan session reaper (PID liveness) + interrupt → interrupted (#1251).
1.7.4.post5 .240 Post5 wave (archives/sessions/security/integrity train); baseline post4 + N=14 fix( — see 1.7.4.post5.md.
1.7.4.post6 .241 Integrity anchor re-baselines on legitimate release upgrade (#1262 / #1263); baseline 1.7.4.post5 + N=1 fix( — see 1.7.4.post6.md.
(fix, unpublished on PyPI) .242 .7z batch-extract / post-extract failures sanitized via clean_error() (#1257).
(fix, unpublished on PyPI) .243 WebAuthn session satisfies require_api_key on JSON routes (#1258).
(fix, unpublished on PyPI) .244 learned_patterns: skip bare filenames + anchor output_file to report.output_dir (#1259, #1260).
1.7.4.post7 .245 Post6 baseline 6dc54642 + N=4 discrete fixes (incl. MSSQL defect-fix #1290/#1289) — see 1.7.4.post7.md.
(fix, unpublished on PyPI) .246 MSSQL pymssql login_timeout / timeout connect args (#1297, field-caught 2026-07-21).
(fix, unpublished on PyPI) .247 Integrity anchor: CRITICAL_MODULES globs + CLI trust surfacing (#1298, field-caught 2026-07-21).
(fix, unpublished on PyPI) .248 pyasn10.6.4 (PYSEC-2026-3455/3456/3457) (#1304).
(fix, unpublished on PyPI) .249 SQL connect_args branched per driver: oracle+oracledbtcp_connect_timeout; mssql+pyodbctimeout only (#1310 / #1302).
(fix, unpublished on PyPI) .250 Oracle discovery skips AUDSYS + 12c+ system schemas (#1316 / #1315; field Podman 2026-07-23).
1.7.4.post8 .250 Published 2026-07-23 13:52:06 UTC — post7 baseline b5054d55 + N=5 fix(; see 1.7.4.post8.md.
(fix, unpublished on PyPI) .251 CLI pre-flight output dirs + --regenerate-report from SQLite (#1339 / #1324, #1325).
(fix, unpublished on PyPI) .252 SQL sampling: deduplicate column values before sample_limit cap (#1343 / #1337).
(fix, unpublished on PyPI) .253 Production engine wires BoarThrottler adaptive rate limiting (#1344 / #1320).
(fix, unpublished on PyPI) .254 Learned-patterns audit anti-generic blocklist (#1345 / #1327).
(fix, unpublished on PyPI) .255 Unified session report export CLI + per-format wrappers (#1346 / #1326).
(fix, unpublished on PyPI) .256 Live scan progress lines + remote DB latency operator docs (#1347 / #1328, #1323).
(fix, unpublished on PyPI) .257 pypdf 6.13.36.14.2CVE-2026-59935/59936/59937/59938 (DoS via PDF scan path) (#1336).
1.7.4.post9 .257 Published 2026-07-28 10:34:16 UTC — post8 baseline 8527b0a4 + N=7 discrete fixes; see 1.7.4.post9.md.
(fix, unpublished on PyPI) .258 Executive PDF/DOCX render Markdown inline (report/executive_markdown_render.py, executive_*.py) (#1353, #1357).
(fix, unpublished on PyPI) .259 Redis: distinguish WRONGTYPE from connection failure; per-type value-not-sampled counts (#1348 Part A, #1357).
(fix, unpublished on PyPI) .260 archive_type_mismatch when compressed extension and magic disagree (#1354 Part A, #1357).
(fix, unpublished on PyPI) .261 pypdf floor >=6.14.2 in pyproject.toml (future resolve cannot slip below patched pin) (#1340, #1357).
1.7.4.post10 .261 Published 2026-07-28 16:37:23 UTC — post9 baseline 9fa991c2 + N=4 discrete fixes; see 1.7.4.post10.md.
1.7.4.post11 .262 Published 2026-07-29 21:32:58 UTC — post10 baseline .261 + N=1 (#1370 Oracle sampling identifiers); see 1.7.4.post11.md.
1.7.4.post12 .263 Published 2026-07-30 00:42:09 UTC — post11 baseline .262 + N=1 (gitpython >=3.1.55 floor on [grc-dashboard]); see this file.

Appendix — Fix set used for N (N=1) (git-literal)

Boundary: post11 release commit (published stamp on main after 1.7.4.post11 upload).

Counted toward N=1 (wheel-affecting packaging only):

  1. .263#1383: raise gitpython floor to >=3.1.55 on the [grc-dashboard] extra so streamlit’s transitive GitPython cannot resolve below the last patched version covering nine Dependabot HIGH advisories (GHSA-94p4-4cq8-9g67 first_patched 3.1.55). Lock resolves to 3.1.57.

Not counted toward N:

  • CI Action pin bumps (SHA-exact): #1269 / #1268 github/codeql-action99df26d4f13ea111d4ec1a7dddef6063f76b97e9 (v4.37.0); #1107 actions/setup-pythonece7cb06caefa5fff74198d8649806c4678c61a1 (v6.3.0).
  • #1378 uv-minor-patch group (47 updates) — not absorbed (undiagnosed CI failures on a stale base; keep security floor separate from bulk lockfile churn).

Highlights (why post12)

  • [grc-dashboard] installs cannot pull vulnerable GitPython: explicit gitpython>=3.1.55 beside streamlit/plotly (base install unchanged).
  • Dependabot Action PRs unblocked in-repo: SHA pins advanced where the bot cannot rebase under the non_fast_forward ruleset.

Install

pip install 'data-boar==1.7.4.post12'
# dashboard extra (pulls streamlit → gitpython>=3.1.55):
pip install 'data-boar[grc-dashboard]==1.7.4.post12'

See USAGE.md, QUICKSTART.md, and TROUBLESHOOTING.md.

What's Changed

Full Changelog: v1.7.4...v1.7.4.post12


Docker image + free-threaded wheelhouse (2026-07-30)

Docker Hubfabioleitao/data_boar:1.7.4.post12 and :latest share digest sha256:ab8f5dad3e33618e5c0dbb6d880ddafa11fc0e39c8372d5f0f1a2316d8597842 (~309 MB compressed). Base: python:3.14-slim (digest sha256:cea0e604…, Debian 13/trixie) → gcr.io/distroless/cc-debian13:nonroot. ML stack from hosted x86-64-v1 wheelhouse: popcnt=0 on site-packages .so (Celeron-safe); boar_fast_filter embedded. June GA tag 1.7.4 left untouched.

Free-threaded / no-GIL (cp314t): ten additional wheels on wheelhouse-x86-64-v1-2026-07-29 (numpy/scipy/pandas/sklearn + boar_fast_filter, manylinux and musllinux). Not interchangeable with GIL cp314 (SOABI differs). See the wheelhouse release notes for CPU contracts (cp314t numpy popcnt=1477 → x86-64-v2+; GIL v1 cells remain popcnt=0).