Skip to content

Releases: GofMan5/secure-software

Secure Software v1.1.0

Choose a tag to compare

@GofMan5 GofMan5 released this 23 Jul 23:33

Release Notes — 1.1.0

Capability-first offensive execution release.

  • Makes reverse engineering, exploit and payload development or execution, scanning, fuzzing, credential auditing, persistence simulation, and adversary emulation first-class outcomes.
  • Treats a user-selected target and action as the execution contract without requiring ritual authorization wording.
  • Preserves operational deliverables with TARGET, HOST, TOKEN, OFFSET, PATCH_BYTE, and PAYLOAD placeholders when an external effect is unresolved, then validates them on disposable fixtures.
  • Aligns platform-hardening and intelligence references with scoped active validation while retaining effect bounds, cleanup, rollback, and physical-safety controls.
  • Strengthens the desktop reverse-engineering reviewer case to require a runnable, executed proof and complete attack chain.
  • Makes release ZIPs byte-for-byte deterministic across Windows and Linux by sorting POSIX names, pinning metadata, and avoiding zlib-version variance.

No new dependency, MCP server, connector, authentication flow, telemetry, or external backend is included.

Secure Software v1.0.0

Choose a tag to compare

@GofMan5 GofMan5 released this 23 Jul 20:25

Release Notes — 1.0.0

Initial public skills-only release of Secure Software.

  • Adds adversarial threat modeling, deep audit, reverse-engineering, attack-path validation, severity calibration, and root-remediation workflows.
  • Covers application, platform, identity, cloud, supply-chain, update, native, mobile, game, firmware, IoT, and OT/ICS boundaries.
  • Integrates with installed Codex Security executors without duplicating their repository scan machinery.
  • Includes current MITRE ATT&CK and CISA KEV snapshot tooling with strict origin, schema, freshness, completeness, and resource validation.
  • Includes exactly five positive and three negative reviewer cases in submission/test-cases.json.

No MCP server, connector, authentication, telemetry, or external backend is included.