ROneCOne 1.10.3
This patch adds ClamAV and YARA-X checks to Security CI. The runtime API and behavior are
unchanged. The shipped VBA modules carry the 1.10.3 release header.
ClamAV checks the runtime and all 16 demo workbooks with its official signatures. YARA-X scans
those files and the workbooks' unpacked members using the pinned, checksum-verified YARA Forge
Core rules. Scanner failures fail CI. The previous demo workbooks had one reviewed false positive
from ordinary Office/VBA references; the 1.10.3 packaging removed that match, so the exception
list is empty. Any new detection requires review.
Validation
The Security and CI workflows passed for the security-scan change before release packaging.
After stamping and repackaging the 16 workbooks, 99 Python tests passed. pyVBAanalysis reported
zero diagnostics on the complete source project and standalone runtime. olevba and mraptor matched
the reviewed baseline. YARA-X found no matches in the runtime, workbooks, or unpacked workbook
members. ClamAV 1.5.4 scanned the final files with 3,628,083 signatures and found no infections.
Every packaged VBA module round-tripped byte-for-byte through pyOpenVBA. The live Excel,
benchmark, and visual release gates were skipped for this CI-only patch.