Skip to content

v0.3.6-beta

Choose a tag to compare

@Lekssays Lekssays released this 10 Mar 10:12
· 256 commits to main since this release

🚀 Codebadger Release — v0.3.6-beta

v0.3.6-beta
Released Mar 10, 2026


📦 What’s New

  • Improved program slice location mapping in get_program_slice() ([$line] -> [$file:$line] fix).
  • Added flow deduplication to find_taint_flows() to remove duplicate paths and reduce noise.

🛡️ Detection Improvements

  • Replaced contains / endsWith checks with pathBoundaryRegex in vulnerability detectors:

    • find_double_free
    • find_use_after_free
    • find_null_pointer_deref
    • find_integer_overflow

⚙️ Stability & Diagnostics

  • Silent exceptions in:

    • use_after_free.scala
    • null_pointer_deref.scala
    • integer_overflow.scala
      now emit diagnostic notes instead of failing silently.

🧹 Refactors & Cleanup

  • Removed %4d zero-padding on line numbers in variable_flow.scala.
  • Removed unused shutdown_event (asyncio.Event).
  • Removed _setup_signal_handlers and related signal-handling logic.
  • Removed unused imports (asyncio, signal).

🔌 FastMCP v3 Lifecycle Integration

  • Migrated from @asynccontextmanager to FastMCP @lifespan.
  • Replaced lifespan(mcp) with app_lifespan(server) to avoid decorator shadowing.
  • Lifespan now yields a services dictionary, enabling access via ctx.lifespan_context.
  • _graceful_shutdown() moved to a finally block to ensure cleanup on both normal shutdown and exceptions.

🔭 Observability

  • Added OpenTelemetry support for tracing and monitoring analysis operations.

🛠️ Maintenance & Dependencies

  • Bumped fastmcp version.
  • Bumped joern version.
  • General internal cleanup and consistency improvements.

⏱️ Tool Timeout Configuration

  • 600s: generate_cpg
  • 300s: heavy analysis (find_taint_flows, get_program_slice, vulnerability detectors)
  • 120s: medium queries (get_variable_flow, get_call_graph, get_cfg, run_cpgql_query)
  • 60s: store_findings, export_sarif
  • 30s: lightweight lookup tools

🔐 Networking

  • Reserved ports 13371–13399 to avoid conflicts with commonly used ports (e.g., 2222 for SSH).

⚠️ Note: This is a beta release and may include unstable or evolving APIs. Downstream integrations should be validated before production use.

Full Changelog: v0.3.5-beta...v0.3.6-beta