Repository navigation
NexusShadowScan 0.1.2 (Alpha)
Pre-releaseNexusShadowScan 0.1.2 is the initial PyPI alpha, with 38 connectors across nine discovery surfaces and 220 signatures / 1,018 signals. It discovers evidence of AI agents and integrations and reconciles findings against an approved inventory.
Install using Python 3.11–3.13 in a fresh virtual environment:
python -m pip install NexusShadowScan
shadowscan --helpFor cloud SDKs, use python -m pip install "NexusShadowScan[cloud]". The command and Python imports remain shadowscan; the unrelated PyPI package named shadowscan is a different project. Avoid combining earlier project-nexus-shadowscan candidates with this distribution in one environment.
Version 0.1.1 reached TestPyPI and the immutable v0.1.1 tag. Its production preflight stopped before any PyPI upload. Version 0.1.2 corrects the GitHub tag lookup to use the fully qualified refs/tags/v<version> reference; scanner behavior is unchanged. The original tag remains on its original commit.
Compatibility notes:
- Rebuild comparison baselines for v2 finding identities and regenerate inventory stubs or add
discovery.discriminators. - Handle exit 1 for invalid usage/setup, exit 2 for a completed scan reaching its threshold, and exit 3 for incomplete coverage.
- SARIF carries heuristic
risk_levelvalues; it no longer setssecurity-severity. Gateway comparisons require a consistentSHADOWSCAN_IDENTITY_KEY.
Read the full release notes and deployment guide.
PR #160 received approval for commit 5bfd0742f8d4e22f56131f8dc0e0c0a05a5205d9. The release source, 35b7aed413d74799f8a878f13764e51c5b8f1c70, has the same Git tree, c10aaccef11e09ba4c54915a7b412154a53846f4.
Verify the downloaded wheel:
python -m pip download --no-deps --dest wheels NexusShadowScan==0.1.2
gh attestation verify wheels/nexusshadowscan-0.1.2-py3-none-any.whl --repo aisecnomad/Project-NexusCompare its SHA-256 with the retained candidate's SHA256SUMS. PyPI provenance should identify this repository, release.yml and the pypi environment.
Verified publication evidence:
- Production publication workflow
- Published wheel SHA-256:
e074a37cc8ca16e9967108e54c0c623bccdc6b82173368b414e8fd2057dabde1 - PyPI provenance
This remains Alpha software. Confidence is heuristic, and bundled regression results do not establish field accuracy. Deployment requires acceptance evidence for the intended tenant and scope. Treat reports as confidential. Linux and macOS are supported; Linux x86_64 is the validated deployment target.
A fresh installation from production PyPI passed dependency checks, CLI help, signature validation and an outside-checkout sample scan. The attached evidence archive includes candidate hashes, SBOM and attestation bundles.