GCP IAMGraph v0.1.1 — Repository Hardening
GCP IAMGraph v0.1.1
This release hardens GCP IAMGraph's CI pipeline, Python packaging, CLI reliability, automated testing, and security documentation.
Highlights
- Enforced Ruff formatting and lint checks in CI
- Added automated testing across Python 3.10, 3.11, and 3.12
- Added an 85% minimum test-coverage gate
- Reached 87.96% total coverage with 27 passing tests
- Added friendly CLI errors for invalid report and attack-graph output paths
- Added automated tests for filesystem write failures
- Improved Python package metadata and project links
- Added reusable development dependencies through
.[dev] - Updated the package license declaration to SPDX format
- Strengthened private vulnerability-reporting guidance
- Clarified that Code Scanning alerts originate from the intentionally vulnerable IAM example
- Refreshed JSON and SARIF proof artifacts
- Added updated testing and package-validation evidence
Supported outputs
- JSON security reports
- Markdown security reports
- SARIF 2.1.0
- JSON attack graphs
- Graphviz DOT attack graphs
- SVG and PNG graph rendering
Validation
- 27 automated tests passed
- 87.96% total test coverage
- 85% minimum CI coverage gate passed
- Ruff formatting checks passed
- Ruff lint checks passed
- Wheel package built successfully
- Source distribution built successfully
- Vulnerable example: 5 resources and 8 findings
- Hardened example: 2 resources and 0 findings
- Invalid output paths return a clean error with exit code 2
Installation from source
git clone https://github.com/Parakh-Shinde/GCP-IAMGraph.git
cd GCP-IAMGraph
git checkout v0.1.1
python -m venv .venv
pip install -e .Development installation
pip install -e ".[dev]"Full comparison: v0.1.0...v0.1.1