Releases: PotenFYR-Studios/HBS-Tool
Releases · PotenFYR-Studios/HBS-Tool
Release list
v0.1.0
Changes
- fix(release): zig is not bundled with prebuilt cargo-zigbuild — install ziglang wheel (b27baae)
- fix(ci): rocky:9 dnf needs --allowerasing (curl-minimal conflicts) + make (9f5a15a)
- fix(ci): container rustup HOME guard + extractor workdir; normalize formatting (6eb795b)
- feat(ci,docs): org theme, docs site + Pages, fixed and parallelized CI (aca0571)
- chore: rename repo references HBS-Work -> HBS-Tool (244c8d3)
- fix(install): bootstrap unzip + ca-certificates before the Bun runtime install (09cd958)
- fix(ci): hermetic ssh test, libc getpriority type, non-systemd install fallback (6a3acc9)
- feat(distribution): installers, tray icon, release-fetched agent templates (da94679)
- feat(network): vendor compatibility round — 8 new platforms, 6 new checks, full-config fixtures (13648e3)
- feat: add webhook notification settings page for admin (443c6fc)
- docs(readme): comprehensive guide — scenarios, flags, features, API, validation, releases (7992240)
- chore(ci): post-CI release workflow — build all targets, create or update the versioned release (cb5714a)
- chore(ci): add Windows runner matrix (2019/2022/2025 + arm64 preview) to GitHub Actions (74cc6e5)
- chore(ci): Linux variants via GitHub Actions; Windows via Docker Windows engine; drop WSL helper (449c590)
- chore(ci): cross-OS GitHub Actions matrix + local WSL matrix helper (5dc591c)
- feat: VM/container awareness, exhaustive fallbacks, no-egress hardening, in-report logs, exec/remediation UI (77ef6e0)
- feat: add Remediation Center page with filtering and export functionality (07bb528)
- Add Windows-specific tests and configuration files for native fallbacks (a156b8c)
- feat: enterprise dashboard UI, professional exports, first-run credentials, platform fixes (f045c57)
- Add comprehensive tests for catalog checks, Windows threat persistence, keyslot parsing, and push policy (fbb5687)
- feat(extractor): add WIN-TH credential protection checks (Task 38) (d8fc1ca)
- docs: clarify legacy server compatibility policy (f488911)
- feat(extractor): add WIN-NET network hardening checks (Task 37) (67a1cc6)
- feat(extractor): WIN-REG permission checks (10) via query-only Get-Acl SDDL and CIM service inventory (Task 36) (e6d1fe2)
- feat(extractor): WIN-SVC service checks (20) via query-only sc qc with registry fallback when sc blocked (Task 35) (2455fec)
- feat(extractor): WIN-DEF defender/update checks (10) with registry fallbacks when PowerShell blocked (Task 34) (22baddf)
- feat(extractor): WIN-EVT event log checks (6) via query-only wevtutil, no invented retention (Task 33) (44c513e)
- feat(extractor): WIN-UR user rights checks (16) via read-only LSA APIs with portable SID requirement table (Task 32) (3637876)
- feat(extractor): WIN-SEC security options checks (22) via read-only registry queries (Task 31) (5f3e8e5)
- feat(extractor): WIN-AU audit policy checks (10) via read-only auditpol CSV with GUID matching and localized fallback (Task 30) (07c0e3a)
- feat(extractor): WIN-ACC account policy checks (12) with strict read-only argv allowlist and TIMEQ_FOREVER semantics (Task 29) (97b2577)
- test: real-world docker validation matrix (8/8 green, 0 errors, 191 checks); run-context per check; peak RSS self-report (1a1c223)
- feat(extractor): LIN-TH containers/EOL/currency checks (14) — Linux catalog complete at 148 checks (70c5420)
- feat(extractor): LIN-TH kernel attack-surface and persistence hunting (26) (1353119)
- feat(extractor): LIN-USER users/permissions checks (20) (412772b)
- feat(extractor): Nessus-style evidence blocks (path header, line+col, ±3 context) + extractor-side secret redaction (8550171)
- feat(extractor): LIN-PAM auth checks (14) (96b4aee)
- feat(extractor): LIN-SSH sshd hardening checks (15) with effective-value fallback (a5a6f3c)
- feat(extractor): LIN-AU auditd checks (12) (5365413)
- feat(extractor): LIN-LOG logging checks (14) (f6e7da5)
- feat(extractor): LIN-FW firewall checks (5) (9f652fa)
- feat(extractor): LIN-NET sysctl network checks (20) (4facf8c)
- chore: ignore harness dirs in main checkout (7eff15f)
- feat(extractor): exhaustive host metadata (motherboard/BIOS/GPU/CPU/RAM/storage/network/kernel/processes/services) (19a13eb)
- feat(extractor): LIN-SV services checks; opt-in --elevate privilege model with admin-gated checks (b747a0f)
- feat(extractor): LIN-FS filesystem checks (15) (9055165)
- feat(extractor): shared check helpers + GEN-INV inventory (25 checks) (a4c9777)
- test(extractor): cross-language crypto vector generation (544f720)
- build: cross-compile matrix with size budget gate (2.2-2.6MB per target) (9268991)
- feat(extractor): rich TUI progress with non-TTY fallback (b35947e)
- feat(extractor): UAC self-elevation with graceful decline (cab76a2)
- feat(extractor): end-to-end sealed report from CLI with filters and push (d4ec7a3)
- feat(extractor): system fingerprint both OS (33841f7)
- feat(extractor): binary keyslot with checksum validation and expiry (2ac7d24)
- feat(extractor): sealed envelope X25519+HKDF+AEAD, pinned cross-language HKDF vector (2942064)
- feat(extractor): check registry macro and catalog module pattern (1826c67)
- feat(extractor): engine with panic containment and fallback logging (2b19792)
- feat(extractor): ScanContext with caches, root prefix, injector (05ad419)
- feat(extractor): platform/distro detection and priority lowering (7385916)
- feat(extractor): capped reads and allowlisted command execution (cf2544a)
- feat(extractor): result model with serde report shapes (7b23e98)
- chore: scaffold extractor crate and dashboard package (902e1e5)
- chore: gitignore superpowers workspace (8f9adae)
- Spec+plan: VM-style finding treatment workflow (states, assignment, comments); full implementation plan (9ba8851)
- Spec: per-issuance unique keys, event-driven processing, hostname:machineid display, enterprise report conventions (4ad56ff)
- Spec: add locations, per-location extractor issuance, auto host routing by machine ID (6de838d)
- Add HBS platform design spec: extractor, dashboard, campaigns, threat-informed catalog (2ed288b)
- Initial commit (f8ab797)
Commit: b27baaece99f8384b16292f154284455a6e93ea8
Changes
- docs: operator-first getting started + walkthrough; strip em dashes project-wide (5ce59f8)
Commit: 5ce59f8caa0cf1ace0a9dabc0e3c5f6f4299b615