Skip to content

v0.1.9

Choose a tag to compare

@github-actions github-actions released this 11 Sep 09:14
· 26 commits to main since this release

v0.1.9

Fixed

  • Reduce false positives in CORS, open redirects, CSTI, JSONP, WebSocket, prototype pollution, parser differential and route authentication checks by requiring evidence of the claimed security effect.
  • Validate actual redirect destinations instead of attacker URLs embedded in nested query parameters.
  • Repair stored-XSS tracking and raw HTTP smuggling verification; preserve raw request and response evidence.
  • Include response status and security-relevant headers in finding replay comparisons.
  • Correct coverage accounting, persistent learning outcome counts, response similarity and cache-hit detection.
  • Share request budgets across HTTP, browser HTTP and raw protocol probe paths.
  • Restore Copy Response, Copy Request and Copy cURL in HTML reports, including a clipboard fallback.
  • Isolate the CLI integration test from the user's data directory.

Added

  • Private-canary proof policies and browser cross-origin read observations.
  • Regression tests for the reported false positives, raw protocol replay, clipboard behavior and shared budgets.
  • Audit and validation reports documenting remaining verification limits.

Validation

  • The preceding changes passed tests in 80 Go packages and go vet.
  • The strict observed benchmark passed for the existing corpus.
  • Live third-party/browser coverage is not inferred from fixture tests; local race testing required an unavailable GCC toolchain.