Highlights
GCP IAMGraph v0.2.0 introduces an explainable authorization engine for more accurate GCP IAM attack-path analysis.
Added
- Explicit
ALLOW,DENY, andUNKNOWNauthorization decisions - Inherited IAM deny-policy evaluation
- Deny-rule principal and permission exceptions
- Structured and deterministic decision evidence
- Conservative handling of unsupported IAM Conditions
- Authorization-aware project IAM escalation detection
- Authorization-aware service-account key paths
- Authorization-aware
actAsand Compute Engine paths - Authorization-aware multi-hop service-account impersonation
- End-to-end deny-policy CLI integration tests
- Reproducible deny-policy example environment
Security impact
Applicable deny policies now prevent blocked permissions from generating confirmed attack paths. Unsupported or conditional authorization semantics remain visible as UNKNOWN instead of being assumed allowed.
Validation
- 74 automated tests passed
- 91.33% test coverage
- Python 3.10, 3.11, and 3.12 CI validation
- Ruff formatting and lint checks passed
- Wheel validated in an isolated environment
- JSON, Markdown, SARIF, and attack-graph reporting
See CHANGELOG.md for full details.