v0.4.0
·
64 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Configuration presets on every scan invocation (-c/--config), a rule-liveness harness that proves every bundled pattern can fire, custom user patterns via .aegis.yml, and a round of correctness fixes — baseline rescans stay green, stats now agrees with findings, and the WASM scanner scans again.
Changelog
Added
-c/--configis wired on every scan invocation: a built-in preset
(production,pipeline,development,mcp-integration) or a path to a
JSON profile file supplies defaults for flags the operator did not set
(output format, categories, severity threshold); explicit flags always win.
Unknown names fail with the list of valid presets, and the built-in presets
are tested field-by-field against the shippedconfig/profiles/*.jsonso
they cannot drift.- Rule-liveness harness: 633 provably-firing example matches, one per bundled
pattern, so a pattern that cannot match anything fails CI. - Custom user patterns via
.aegis.ymlin the scan root, merged into the
registry before the walk.
Fixed
- Baseline rescans stay green:
scanno longer scans the baseline file
itself. A baseline records findings verbatim, so a rescan that included it
re-flagged every documented secret and kept the exit code red even when no
new findings existed. The baseline path is now excluded from the walk, and
the exit-code contract is verified end-to-end (0 = no new findings,
1 = new findings only). statsagrees withfindings: stdin (--stdin), env (--env), and
diff (--diff) scans folded findings into ad-hoc counters, so
--format jsoncould emitfinding_count: 0next to a non-empty
findingsarray. All scan paths now aggregate through
ScanStats::add_finding; reports and receipts agree with the finding list.- WASM scanner works:
scan_contentpreviously scanned nothing; the WASM
build now bundles the full pattern set. - Vendor-prefixed secret rules are file-active again after the noise
audit. - Noise audit round two: repaired noisy patterns and deduplicated AST
rules, cutting the project's self-scan from 941 to 817 findings and the
CI-parity self-scan (secrets, security-hardening, web-security at high+) to
0 findings. - Suppression fixtures in the MCP and daemon suites now name the rules that
actually fire and sit on the finding's own line, so inline suppression is
genuinely exercised.
Changed
- Lazy per-extension pattern compilation: patterns are grouped and compiled
once per file extension, so a TypeScript rule never runs against a Rust
file and unreachable regexes are never compiled. - Workspace-wide strict lint enforcement (
clippyall + pedantic,
rust_2018_idioms,unused_qualifications,missing_docs) with
-D warningsin CI; fail-closed scanner initialization. - Test coverage swept to 98% line coverage across the workspace, with a
coverage gate in CI. - Documentation accuracy audit: every user-facing claim re-verified against
the built binaries; public API fully documented (missing_docsenforced).