Releases
v0.5.35
Compare
Sorry, something went wrong.
No results found
[0.5.35] - 2026-08-23
Bug Fixes
scanners: Use capped-regular for /etc/passwd in access alignment (R26-17)
sudoers: Single walk, capped passwd and scanner-resolved
scoring: Key SEC-005 on scanner-resolved ALL marker (R26-19)
scoring: Expose sudoers module internally for marker access
models: Move sudo markers to always-compiled module
ghost-pid: Gate io_uring imports to glibc Linux
scoring: Bump scoring version for sudoers and backup weighting changes (R26-22)
sudoers: Parse multiple Cmnd_Alias specs on one line (R26-23)
host: Derive last_restic_snapshot from local cache mtime (R26-25)
sudoers: Parse transitive sudo tags for NOPASSWD: ALL (R26-27)
compare: Detect sudo NOPASSWD grant drift (R26-28)
runner: Use capped-regular for /etc/passwd and add doctrine CI guard (R26-29)
compare: Flag cross-version collection semantics change (R26-30)
scanners: Use read_file_capped_regular for cron and DNS host files (R26-37)
provenance: Use read_file_capped_regular for dpkg/apk databases (R26-38)
safe_io: Allow dead_code for streaming opener on remote-only builds
main: Import Read for streaming JSONL parser (R26-40)
safe-io: Remove /dev from procfs doctrine; add literal path check (R26-43, R26-44)
ci: Close R26-48 (multi-line literal guard and PCRE2 probe)
ci: Install ripgrep, add -U and PCRE2 probe
release: Harden release workflow
doc: Regenerate changelog
security: Close R27-08, R27-09, R27-04
output: Sanitize XLSX filename against hostname traversal (R27-11)
release: Clear OWLZOPS_SUDO_PASS from environ (R27-12)
release: Avoid duplicate .asc upload and harden signature/changelog checks
Build System
deps: Bump taiki-e/install-action from 2.85.10 to 2.86.4 (#201 )
CI/CD
Catch read_file_capped on host-controlled paths (R26-31)
Enable raw-open guard and convert operator file readers (R26-40)
Enable raw-open guard and annotate remaining operator/procfs exceptions
release: Fix SBOM filename and validate artifact set before signing
Features
safe_io: Add streaming regular-open primitive (R26-39)
Refactoring
safe_io: Rename procfs readers and make capped-I/O guard exact (R26-31/R26-33/R26-36)
scanners: Fix misleading comment and dead branch (R26-45, R26-46)
scanners: Fix misleading comment and dead branch
Testing
sudoers: Parameterize walk and add cross-file alias coverage (R26-24)
compare: Add binary-version drift regression test
You can’t perform that action at this time.