Releases: Parakh-Shinde/GCP-IAMGraph
Releases · Parakh-Shinde/GCP-IAMGraph
Release list
GCP IAMGraph v0.2.0 — Explainable Authorization Engine
Highlights
GCP IAMGraph v0.2.0 introduces an explainable authorization engine for more accurate GCP IAM attack-path analysis.
Added
- Explicit
ALLOW,DENY, andUNKNOWNauthorization decisions - Inherited IAM deny-policy evaluation
- Deny-rule principal and permission exceptions
- Structured and deterministic decision evidence
- Conservative handling of unsupported IAM Conditions
- Authorization-aware project IAM escalation detection
- Authorization-aware service-account key paths
- Authorization-aware
actAsand Compute Engine paths - Authorization-aware multi-hop service-account impersonation
- End-to-end deny-policy CLI integration tests
- Reproducible deny-policy example environment
Security impact
Applicable deny policies now prevent blocked permissions from generating confirmed attack paths. Unsupported or conditional authorization semantics remain visible as UNKNOWN instead of being assumed allowed.
Validation
- 74 automated tests passed
- 91.33% test coverage
- Python 3.10, 3.11, and 3.12 CI validation
- Ruff formatting and lint checks passed
- Wheel validated in an isolated environment
- JSON, Markdown, SARIF, and attack-graph reporting
See CHANGELOG.md for full details.
GCP IAMGraph v0.1.1 — Repository Hardening
GCP IAMGraph v0.1.1
This release hardens GCP IAMGraph's CI pipeline, Python packaging, CLI reliability, automated testing, and security documentation.
Highlights
- Enforced Ruff formatting and lint checks in CI
- Added automated testing across Python 3.10, 3.11, and 3.12
- Added an 85% minimum test-coverage gate
- Reached 87.96% total coverage with 27 passing tests
- Added friendly CLI errors for invalid report and attack-graph output paths
- Added automated tests for filesystem write failures
- Improved Python package metadata and project links
- Added reusable development dependencies through
.[dev] - Updated the package license declaration to SPDX format
- Strengthened private vulnerability-reporting guidance
- Clarified that Code Scanning alerts originate from the intentionally vulnerable IAM example
- Refreshed JSON and SARIF proof artifacts
- Added updated testing and package-validation evidence
Supported outputs
- JSON security reports
- Markdown security reports
- SARIF 2.1.0
- JSON attack graphs
- Graphviz DOT attack graphs
- SVG and PNG graph rendering
Validation
- 27 automated tests passed
- 87.96% total test coverage
- 85% minimum CI coverage gate passed
- Ruff formatting checks passed
- Ruff lint checks passed
- Wheel package built successfully
- Source distribution built successfully
- Vulnerable example: 5 resources and 8 findings
- Hardened example: 2 resources and 0 findings
- Invalid output paths return a clean error with exit code 2
Installation from source
git clone https://github.com/Parakh-Shinde/GCP-IAMGraph.git
cd GCP-IAMGraph
git checkout v0.1.1
python -m venv .venv
pip install -e .Development installation
pip install -e ".[dev]"Full comparison: v0.1.0...v0.1.1
GCP IAMGraph v0.1.0
GCP IAMGraph v0.1.0
The first public release of GCP IAMGraph—an explainable Google Cloud IAM attack-path and least-privilege analyzer.
Highlights
- Models organization, folder, project, and resource hierarchy.
- Resolves inherited IAM allow-policy bindings.
- Supports predefined and custom role definitions.
- Ingests native IAMGraph JSON and Google Cloud Asset Inventory JSONL.
- Detects direct IAM risks and multi-step privilege-escalation paths.
- Generates explainable evidence and remediation guidance.
- Exports JSON, Markdown, SARIF 2.1.0, graph JSON, and Graphviz DOT.
- Uploads findings automatically to GitHub Code Scanning.
Detection rules
GCP-IAM-001— Broad primitive Owner or Editor roleGCP-IAM-002— Public or globally authenticated accessGCP-IAM-003— Project IAM policy modificationGCP-IAM-004— Service-account key creationGCP-IAM-005— Impersonation path to a privileged service accountGCP-IAM-006— VM creation with privileged service-accountactAsGCP-IAM-007— IAM policy modification leading to project OwnerGCP-IAM-008— Key creation for a privileged service account
Security integrations
- SARIF 2.1.0 output
- GitHub Code Scanning workflow
- Configurable CI failure thresholds
- Downloadable SARIF workflow artifacts
- JSON and Graphviz attack-graph export
Quality
- Python 3.10, 3.11, and 3.12 CI coverage
- 25 automated tests
- Ruff formatting and lint validation
- Vulnerable and hardened demonstration environments
- Read-only analysis with no automatic IAM modification
Quick start
python -m venv .venv
source .venv/bin/activate
pip install -e .
gcp-iamgraph examples/vulnerable-environment.json \
--format markdown \
--output report.md