v1.5.0 - grouped chains and DevOps proof
v1.5.0 is where grouped chains gets a lot more usable live, and where devops / chains deployment-path starts pulling real Azure Repos pipeline evidence into the picture instead of leaving that whole story trapped in YAML.
What shipped:
- YAML-backed Azure DevOps pipeline evidence, so
devopsandchains deployment-pathcan now surface repo-backed Azure service connections and variable groups from real pipeline definitions and same-repo local templates instead of making you go prove that by hand - strict grouped
chainsartifact reuse for compatible local source JSON, so repeat family reruns can reuse evidence that already exists instead of recollecting the same backing commands every time - batched
role-trustsGraph fanout, which speeds up trust-edge collection and carries forward into groupedchainsfamilies that depend on the same trust reads
In testing, the same trust-edge collection dropped from around 342 seconds to as low as 24 seconds depending on the environment, which worked out to roughly a 78.6% to 93% reduction in time.
That carried forward into groupedchainsruns too:
escalation-pathdropped from 26 seconds to 2 seconds, about 16x faster and roughly 93% less time.
deployment-pathdropped from 38 seconds to 1.62 seconds, about 23x faster and roughly 95% less time.
compute-controldropped from 19 seconds to 1.6 seconds, about 11.8x faster and roughly 91.6% less time. - tighter reduced-view and maintenance-mode truthfulness across
permissions,tokens-credentials,credential-path,deployment-path,functions,arm-deployments, andresource-trusts, so partial visibility reads as partial visibility instead of sounding like stronger proof than the run actually earned
Project note:
AzureFox is moving into maintenance mode from here. If people find issues that are real blockers for usage or that break the tool against its current expectations, those will still get fixed and patched.
The bigger push from here is going into the Go rewrite in HarrierOps Azure.