Repository navigation
v0.1.9
v0.1.9
Fixed
- Reduce false positives in CORS, open redirects, CSTI, JSONP, WebSocket, prototype pollution, parser differential and route authentication checks by requiring evidence of the claimed security effect.
- Validate actual redirect destinations instead of attacker URLs embedded in nested query parameters.
- Repair stored-XSS tracking and raw HTTP smuggling verification; preserve raw request and response evidence.
- Include response status and security-relevant headers in finding replay comparisons.
- Correct coverage accounting, persistent learning outcome counts, response similarity and cache-hit detection.
- Share request budgets across HTTP, browser HTTP and raw protocol probe paths.
- Restore Copy Response, Copy Request and Copy cURL in HTML reports, including a clipboard fallback.
- Isolate the CLI integration test from the user's data directory.
Added
- Private-canary proof policies and browser cross-origin read observations.
- Regression tests for the reported false positives, raw protocol replay, clipboard behavior and shared budgets.
- Audit and validation reports documenting remaining verification limits.
Validation
- The preceding changes passed tests in 80 Go packages and
go vet. - The strict observed benchmark passed for the existing corpus.
- Live third-party/browser coverage is not inferred from fixture tests; local race testing required an unavailable GCC toolchain.