Skip to content

v0.5.35

Choose a tag to compare

@github-actions github-actions released this 23 Aug 20:36
· 295 commits to main since this release
0b98ff1

[0.5.35] - 2026-08-23

Bug Fixes

  • scanners: Use capped-regular for /etc/passwd in access alignment (R26-17)
  • sudoers: Single walk, capped passwd and scanner-resolved
  • scoring: Key SEC-005 on scanner-resolved ALL marker (R26-19)
  • scoring: Expose sudoers module internally for marker access
  • models: Move sudo markers to always-compiled module
  • ghost-pid: Gate io_uring imports to glibc Linux
  • scoring: Bump scoring version for sudoers and backup weighting changes (R26-22)
  • sudoers: Parse multiple Cmnd_Alias specs on one line (R26-23)
  • host: Derive last_restic_snapshot from local cache mtime (R26-25)
  • sudoers: Parse transitive sudo tags for NOPASSWD: ALL (R26-27)
  • compare: Detect sudo NOPASSWD grant drift (R26-28)
  • runner: Use capped-regular for /etc/passwd and add doctrine CI guard (R26-29)
  • compare: Flag cross-version collection semantics change (R26-30)
  • scanners: Use read_file_capped_regular for cron and DNS host files (R26-37)
  • provenance: Use read_file_capped_regular for dpkg/apk databases (R26-38)
  • safe_io: Allow dead_code for streaming opener on remote-only builds
  • main: Import Read for streaming JSONL parser (R26-40)
  • safe-io: Remove /dev from procfs doctrine; add literal path check (R26-43, R26-44)
  • ci: Close R26-48 (multi-line literal guard and PCRE2 probe)
  • ci: Install ripgrep, add -U and PCRE2 probe
  • release: Harden release workflow
  • doc: Regenerate changelog
  • security: Close R27-08, R27-09, R27-04
  • output: Sanitize XLSX filename against hostname traversal (R27-11)
  • release: Clear OWLZOPS_SUDO_PASS from environ (R27-12)
  • release: Avoid duplicate .asc upload and harden signature/changelog checks

Build System

  • deps: Bump taiki-e/install-action from 2.85.10 to 2.86.4 (#201)

CI/CD

  • Catch read_file_capped on host-controlled paths (R26-31)
  • Enable raw-open guard and convert operator file readers (R26-40)
  • Enable raw-open guard and annotate remaining operator/procfs exceptions
  • release: Fix SBOM filename and validate artifact set before signing

Features

  • safe_io: Add streaming regular-open primitive (R26-39)

Refactoring

  • safe_io: Rename procfs readers and make capped-I/O guard exact (R26-31/R26-33/R26-36)
  • scanners: Fix misleading comment and dead branch (R26-45, R26-46)
  • scanners: Fix misleading comment and dead branch

Testing

  • sudoers: Parameterize walk and add cross-file alias coverage (R26-24)
  • compare: Add binary-version drift regression test