Releases: KKloudTarus/synapse-ce
Release list
v0.1.8
Changelog
Features
- 5d6810d: feat(ai-triage): add P1 shadow evaluation harness (@H1eu232)
- ef2ddc8: feat(ai-triage): add durable human review workflow (@H1eu232)
- 5ce338c: feat(ai-triage): add evidence-rich deterministic context (#512) (@VietSory)
- 2f2109a: feat(ai-triage): add observability budgets and resilience (#513) (@H1eu232)
- b7e6361: feat(ai-triage): annotate gate exemptions in SARIF (@XUanhoa04)
- 7e70d83: feat(ai-triage): bound per-scan LLM work (@XUanhoa04)
- 5b2a832: feat(ai-triage): cache decisions by complete context (#510) (@XUanhoa04)
- 9d722e9: feat(ai-triage): complete provider-independent verifier (P1.3) (#502) (@H1eu232)
- e494513: feat(ai-triage): curate reviewer feedback for evaluation (#553) (@VietSory)
- cf224c3: feat(ai-triage): detect input distribution drift (#555) (@XUanhoa04)
- b0667d4: feat(ai-triage): enforce P0 gate-exemption policy (#398) (@H1eu232)
- c432d51: feat(ai-triage): gate promotion against baseline (#554) (@XUanhoa04)
- 8bafbff: feat(ai-triage): gate promotion on adversarial invariance (#562) (@XUanhoa04)
- cffc82b: feat(ai-triage): govern model promotion and rollback (#559) (@H1eu232)
- 1c0c766: feat(ai-triage): reproducible eval CI gate + dataset coverage (#388) (#561) (@nghiadaulau)
- 2e06340: feat(appsec): add sanctioned source snapshot publishing (@VietSory)
- 42a23d0: feat(asset): add asset-centric security management (#474) (@nnatuan03)
- 7d00d60: feat(blueteam): agent-side detection engine, wired into the VM agent (#422 phase 3) (#504) (@nghiadaulau)
- 8c6649a: feat(blueteam): columnar telemetry tier for retro hunting (#424) (#507) (@nghiadaulau)
- 44284ad: feat(blueteam): detection engine domain — rules, events, coverage honesty (#422 phase 1) (#501) (@nghiadaulau)
- f187282: feat(blueteam): detections as hash-chained, attributable evidence (#423) (#505) (@nghiadaulau)
- 4bd89c8: feat(blueteam): eBPF detection sensor — host-wide observers per class (#422 phase 2) (#503) (@nghiadaulau)
- ffbe041: feat(blueteam): governed, reversible, audited response actions (#425) (#508) (@nghiadaulau)
- 62f1831: feat(code-quality): add immutable analysis source and diff workspace (#329) (@pho-veteran)
- 421bd56: feat(codequality): Rust rule pack — 87 rules (#197) (#333) (@nghiadaulau)
- 6727eb1: feat(codequality): add Azure Resource Manager rule pack (#349) (@VietSory)
- 84ff444: feat(codequality): add CSS correctness rule family (#332) (@VietSory)
- d253957: feat(codequality): add HTML correctness rule family (#336) (@VietSory)
- 0fa5eeb: feat(codequality): add HTML security rule family (#337) (@VietSory)
- de376df: feat(codequality): add Kotlin rule pack (#365) (@pho-veteran)
- e4ba787: feat(codequality): add PHP rule pack (#375) (@pho-veteran)
- be75134: feat(codequality): add Ruby and Rails rule pack (#373) (@VietSory)
- 32bcafa: feat(codequality): add Swift rule pack (#364) (@pho-veteran)
- 76337f6: feat(codequality): add Text rule pack with streaming scanner and structured finding identity (#350) (@pho-veteran)
- 001533b: feat(codequality): add VB.NET rule pack (#377) (@pho-veteran)
- ca5b92c: feat(codequality): complete CSS maintainability rule family (#335) (@VietSory)
- ad738c4: feat(codequality): complete HTML maintainability rule family (#348) (@VietSory)
- e0b6204: feat(correlation): gate cross-pillar promotions (#558) (@pho-veteran)
- eb59524: feat(correlation): unified per-asset risk story (#427) (#560) (@nghiadaulau)
- 8b365ae: feat(cspm): live cloud posture connectors for AWS, Azure and GCP (#511) (@pho-veteran)
- a3429ba: feat(dast): add governed authenticated scanning for issues 416 and 417 (@pho-veteran)
- 79cbdec: feat(fleet): Kubernetes collector for cluster inventory (#411) (#443) (@nghiadaulau)
- 87c9c55: feat(fleet): VM agent for host inventory (#410) (#439) (@nghiadaulau)
- 130d6d3: feat(fleet): VM host inventory ingest into the asset model (#446) (#449) (@nghiadaulau)
- 9300625: feat(fleet): agent certificate identity and revocation (#408) (#438) (@nghiadaulau)
- bc5a595: feat(fleet): agent clean-uninstall decommission lifecycle (#412) (#564) (@nghiadaulau)
- a91bb94: feat(fleet): agent health, per-asset coverage and freshness views (#413) (#454) (@nghiadaulau)
- 9582841: feat(fleet): agent version skew + self-update core + release foundation (#412) (#453) (@nghiadaulau)
- 40e4d50: feat(fleet): agent-facing API with agent identity and auth (#409) (#436) (@nghiadaulau)
- f33090f: feat(fleet): cluster snapshot ingest endpoint (#446) (#447) (@nghiadaulau)
- d52845a: feat(fleet): cluster-agent binary + read-only ClusterRole (#411) (#444) (@nghiadaulau)
- bf1abd8: feat(fleet): cluster-inventory to asset mapping core (#411) (#441) (@nghiadaulau)
- 20894da: feat(fleet): cluster-inventory usecase — persist mapped assets (#411) (#442) (@nghiadaulau)
- 037fdea: feat(fleet): fleet asset model, multi-tenant and RLS-enforced (#431) (#434) (@nghiadaulau)
- fb45896: feat(fleet): release-engineering gates, signed update manifest and rollout control (#412) (#472) (@nghiadaulau)
- 4b98f20: feat(fleet): scanned-image digest correlation for cluster coverage (#446) (#450) (@nghiadaulau)
- bfc98da: feat(fleet): web views for agent health and per-asset coverage (#413) (#456) (@nghiadaulau)
- 03ae54c: feat(fleet): wire cluster agent to enrol + report snapshots (#446) (#448) (@nghiadaulau)
- b071436: feat(fleet): work order model, addressed, signed and RLS-enforced (#407) (#435) (@nghiadaulau)
- 490bb49: feat(governance): ingest third-party SARIF under the same governance path (#415) (#465) (@nghiadaulau)
- 95fc793: feat(jsresolve): add R2A workspace metadata inventory (#404) (@VietSory)
- 1921306: feat(jsresolve): add R2B module specifier and alias resolution (#440) (@VietSory)
- b47f6d0: feat(modulegraph): add Phase 5A domain types and JSImportScanner port (#399) (@VietSory)
- 43b9162: feat(platform): Postgres Row Level Security foundation (#432) (#433) (@nghiadaulau)
- ed6a02b: feat(platform): fenced-lease leader election (#406) (#437) (@nghiadaulau)
- 34b9b21: feat(purple): detection coverage from emulation expected vs actual (#426) (#509) (@nghiadaulau)
- 15b6959: feat(reachability): Tier-2 JavaScript affected-export reachability (#378 R5) (#469) (@nghiadaulau)
- 76483cf: feat(reachability): add the Tier-1 JavaScript/TypeScript reachability analyzer (#401) (#461) (@nghiadaulau)
- fe0afa6: feat(reachability): correlate JS/TS imports to SBOM components by exact purl (#400) (#459) (@nghiadaulau)
- aa62033: feat(reachability): harden npm and pnpm lockfile evidence (@VietSory)
- 7e5b698: feat(reachability): implement the JS/TS module import scanner (#379, epic #378) (#458) (@nghiadaulau)
- 8202919: feat(reachability): integrate JavaScript Tier-1 reachability with SCA and judgments (#378 R4) (#462) (@nghiadaulau)
- fbf6fde: feat(reachability): resolve Yarn Berry importers from lockfile evidence (@VietSory)
- 1889557: feat(reachability): select a package version from lockfile importer context (#400) (#460) (@nghiadaulau)
- af6cd14: feat(redteam): add deterministic attack path graph (@pho-veteran)
- 645d8a6: feat(redteam): adversary emulation mapped to a taxonomy, measured against detection (#421) (@nghiadaulau)
- af8b621: feat(redteam): chained exploitation under governance with per-step proof (#420) (@nghiadaulau)
- 8e17581: feat(redteam): fleet-wide chain kill-switch registry (#418/#420 follow-up) (#500) (@nghiadaulau)
- 01207d4...
v0.1.7
Changelog
Features
- dff1d6a: feat(sca): extract .rpm/.deb payloads to scan bundled binaries (#330) (@nghiadaulau)
v0.1.6
Changelog
Features
- d7ed4db: feat(sca): scan standalone Python wheel/egg (.whl/.egg) files (#328) (@nghiadaulau)
v0.1.5
Changelog
Features
- 56a6bf3: feat(sca): infer distro for standalone .deb files (CVE matching) (#326) (@nghiadaulau)
v0.1.4
Changelog
Features
- 30a4c32: feat(sca): scan standalone .rpm/.deb/.msi package files (#325) (@nghiadaulau)
v0.1.3
v0.1.2
Changelog
Fixes
- 0ffa7dc: fix(sca): read the accepted-risk policy from the CI repo for image scans (#322) (@nghiadaulau)
v0.1.1
Changelog
Fixes
- adc6014: fix(lint): make golangci-lint pass (green CI) (#320) (@nghiadaulau)
- 4b25275: fix(release): skip docker image build so releases publish (#318) (@nghiadaulau)
- e1b39f5: fix(sca): scope OS-package advisory matching to the distro release (#321) (@nghiadaulau)
Synapse v0.1.0 — deterministic security & code-quality scanner
The first release of Synapse — a deterministic, CI-native scanner that finds security and code-quality problems in one pass, and gates your pipeline on them.
Point it at a source repo or a container image and it returns ranked, evidence-backed findings. Not a wrapper around someone else's engine: Synapse owns its SBOM parsing and advisory matching, adds first-party SAST / secret / IaC analysis, and ranks by real-world risk. No AI in the finding path — every result is deterministic and reproducible.
What's in the box
- Software Composition Analysis — vendor-neutral, owned SBOM across many lockfile ecosystems, matched against OSV · GHSA · CSAF and cross-checked with Grype's offline DB. Container images are cataloged down to OS packages (Debian/dpkg, Alpine/apk) and language dependencies.
- First-party SAST — deterministic pattern rules for Go, Python, JavaScript/TypeScript, Java, C#, C, and C++. Security weaknesses carry a CWE and are kept separate from code-quality lint.
- Secret scanning — redacted and deterministic; test/fixture/example noise suppressed by default.
- IaC misconfiguration — Dockerfile, Terraform, Kubernetes, Helm, CloudFormation, GitHub Actions.
- License policy — allow/deny verdicts with SPDX category and risk.
- Risk-based prioritization — CISA KEV → EPSS × CVSS, never raw CVSS.
- Air-gapped ready — scan local
docker saveimage tarballs with no registry; offline advisory and offline NVD-CVSS databases; full--offlinemode. - CI-native — SARIF 2.1.0 output for GitHub code-scanning,
--fail-on <severity>gate, and a reproducible evidence digest.
Install
GitHub Action (installs the CLI + syft + grype, verifies checksums):
- uses: KKloudTarus/synapse-ce@v0.1.0
with:
fail-on: high
sarif: "true"Binary — download the archive for your platform below (SHA-256 in checksums.txt), extract synapse-cli, put it on PATH. Requires syft (+ grype for the offline DB) alongside it.
From source — go build ./cmd/synapse-cli, or build the CLI image from Dockerfile.cli.
Quickstart
synapse-cli scan . # source: SCA + SAST + secret + IaC misconfig
synapse-cli scan app.tar --image # container image, incl. air-gapped docker-save tarball
synapse-cli scan . --sarif --fail-on high # gate CI and emit SARIF for code-scanningDeterministic. Reproducible. Ships with the evidence.