Skip to content

GCP IAMGraph v0.1.1 — Repository Hardening

Choose a tag to compare

@Parakh-Shinde Parakh-Shinde released this 29 Aug 13:34
· 26 commits to main since this release
3e91e24

GCP IAMGraph v0.1.1

This release hardens GCP IAMGraph's CI pipeline, Python packaging, CLI reliability, automated testing, and security documentation.

Highlights

  • Enforced Ruff formatting and lint checks in CI
  • Added automated testing across Python 3.10, 3.11, and 3.12
  • Added an 85% minimum test-coverage gate
  • Reached 87.96% total coverage with 27 passing tests
  • Added friendly CLI errors for invalid report and attack-graph output paths
  • Added automated tests for filesystem write failures
  • Improved Python package metadata and project links
  • Added reusable development dependencies through .[dev]
  • Updated the package license declaration to SPDX format
  • Strengthened private vulnerability-reporting guidance
  • Clarified that Code Scanning alerts originate from the intentionally vulnerable IAM example
  • Refreshed JSON and SARIF proof artifacts
  • Added updated testing and package-validation evidence

Supported outputs

  • JSON security reports
  • Markdown security reports
  • SARIF 2.1.0
  • JSON attack graphs
  • Graphviz DOT attack graphs
  • SVG and PNG graph rendering

Validation

  • 27 automated tests passed
  • 87.96% total test coverage
  • 85% minimum CI coverage gate passed
  • Ruff formatting checks passed
  • Ruff lint checks passed
  • Wheel package built successfully
  • Source distribution built successfully
  • Vulnerable example: 5 resources and 8 findings
  • Hardened example: 2 resources and 0 findings
  • Invalid output paths return a clean error with exit code 2

Installation from source

git clone https://github.com/Parakh-Shinde/GCP-IAMGraph.git
cd GCP-IAMGraph
git checkout v0.1.1
python -m venv .venv
pip install -e .

Development installation

pip install -e ".[dev]"

Full comparison: v0.1.0...v0.1.1