Skip to content

Releases: Parakh-Shinde/GCP-IAMGraph

GCP IAMGraph v0.2.0 — Explainable Authorization Engine

Choose a tag to compare

@Parakh-Shinde Parakh-Shinde released this 30 Aug 18:13
e1abb17

Highlights

GCP IAMGraph v0.2.0 introduces an explainable authorization engine for more accurate GCP IAM attack-path analysis.

Added

  • Explicit ALLOW, DENY, and UNKNOWN authorization decisions
  • Inherited IAM deny-policy evaluation
  • Deny-rule principal and permission exceptions
  • Structured and deterministic decision evidence
  • Conservative handling of unsupported IAM Conditions
  • Authorization-aware project IAM escalation detection
  • Authorization-aware service-account key paths
  • Authorization-aware actAs and Compute Engine paths
  • Authorization-aware multi-hop service-account impersonation
  • End-to-end deny-policy CLI integration tests
  • Reproducible deny-policy example environment

Security impact

Applicable deny policies now prevent blocked permissions from generating confirmed attack paths. Unsupported or conditional authorization semantics remain visible as UNKNOWN instead of being assumed allowed.

Validation

  • 74 automated tests passed
  • 91.33% test coverage
  • Python 3.10, 3.11, and 3.12 CI validation
  • Ruff formatting and lint checks passed
  • Wheel validated in an isolated environment
  • JSON, Markdown, SARIF, and attack-graph reporting

See CHANGELOG.md for full details.

GCP IAMGraph v0.1.1 — Repository Hardening

Choose a tag to compare

@Parakh-Shinde Parakh-Shinde released this 29 Aug 13:34
3e91e24

GCP IAMGraph v0.1.1

This release hardens GCP IAMGraph's CI pipeline, Python packaging, CLI reliability, automated testing, and security documentation.

Highlights

  • Enforced Ruff formatting and lint checks in CI
  • Added automated testing across Python 3.10, 3.11, and 3.12
  • Added an 85% minimum test-coverage gate
  • Reached 87.96% total coverage with 27 passing tests
  • Added friendly CLI errors for invalid report and attack-graph output paths
  • Added automated tests for filesystem write failures
  • Improved Python package metadata and project links
  • Added reusable development dependencies through .[dev]
  • Updated the package license declaration to SPDX format
  • Strengthened private vulnerability-reporting guidance
  • Clarified that Code Scanning alerts originate from the intentionally vulnerable IAM example
  • Refreshed JSON and SARIF proof artifacts
  • Added updated testing and package-validation evidence

Supported outputs

  • JSON security reports
  • Markdown security reports
  • SARIF 2.1.0
  • JSON attack graphs
  • Graphviz DOT attack graphs
  • SVG and PNG graph rendering

Validation

  • 27 automated tests passed
  • 87.96% total test coverage
  • 85% minimum CI coverage gate passed
  • Ruff formatting checks passed
  • Ruff lint checks passed
  • Wheel package built successfully
  • Source distribution built successfully
  • Vulnerable example: 5 resources and 8 findings
  • Hardened example: 2 resources and 0 findings
  • Invalid output paths return a clean error with exit code 2

Installation from source

git clone https://github.com/Parakh-Shinde/GCP-IAMGraph.git
cd GCP-IAMGraph
git checkout v0.1.1
python -m venv .venv
pip install -e .

Development installation

pip install -e ".[dev]"

Full comparison: v0.1.0...v0.1.1

GCP IAMGraph v0.1.0

Choose a tag to compare

@Parakh-Shinde Parakh-Shinde released this 28 Aug 19:27
3a68137

GCP IAMGraph v0.1.0

The first public release of GCP IAMGraph—an explainable Google Cloud IAM attack-path and least-privilege analyzer.

Highlights

  • Models organization, folder, project, and resource hierarchy.
  • Resolves inherited IAM allow-policy bindings.
  • Supports predefined and custom role definitions.
  • Ingests native IAMGraph JSON and Google Cloud Asset Inventory JSONL.
  • Detects direct IAM risks and multi-step privilege-escalation paths.
  • Generates explainable evidence and remediation guidance.
  • Exports JSON, Markdown, SARIF 2.1.0, graph JSON, and Graphviz DOT.
  • Uploads findings automatically to GitHub Code Scanning.

Detection rules

  • GCP-IAM-001 — Broad primitive Owner or Editor role
  • GCP-IAM-002 — Public or globally authenticated access
  • GCP-IAM-003 — Project IAM policy modification
  • GCP-IAM-004 — Service-account key creation
  • GCP-IAM-005 — Impersonation path to a privileged service account
  • GCP-IAM-006 — VM creation with privileged service-account actAs
  • GCP-IAM-007 — IAM policy modification leading to project Owner
  • GCP-IAM-008 — Key creation for a privileged service account

Security integrations

  • SARIF 2.1.0 output
  • GitHub Code Scanning workflow
  • Configurable CI failure thresholds
  • Downloadable SARIF workflow artifacts
  • JSON and Graphviz attack-graph export

Quality

  • Python 3.10, 3.11, and 3.12 CI coverage
  • 25 automated tests
  • Ruff formatting and lint validation
  • Vulnerable and hardened demonstration environments
  • Read-only analysis with no automatic IAM modification

Quick start

python -m venv .venv
source .venv/bin/activate
pip install -e .

gcp-iamgraph examples/vulnerable-environment.json \
  --format markdown \
  --output report.md