v0.5.0
·
54 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
A statistical anomaly layer for directory scans — comment-ratio, comment-concentration, identifier-diversity, and file-size outliers reported through a new Severity::Info tier that can never fail a CI run — plus seven money-correctness rules in finance.
Changelog
Added
- Statistical anomaly layer in the engine: directory scans now collect
per-file metrics (line counts, comment share under a line-prefix
heuristic, identifier diversity) and emitSeverity::Infofindings in
the newstatistical-anomalycategory for files far outside their own
repository's baseline —comment-ratio-outlier(z > 2.5), Pareto-style
comment-concentration(one file holding ≥ 60% of repo commentary),
identifier-diversity-outlier(heavy token reuse below 0.2 diversity),
andfile-size-outlier(z > 2.5). Each detector reports only its most
extreme file; prose, dotfiles, lockfiles, and minified bundles are
excluded. Grounded in the detection-brittleness literature, the
observations are triage signals, not verdicts. Severity::Infoacross the engine: weight 0 in risk scoring,info
accepted bySeverity::parseand custom.aegis.ymlpatterns, an INFO
label in text output, SARIFnotelevel, and exclusion from the exit
code — informational findings are reported in every format but can
never fail a CI run. They also respect category, severity-threshold,
and baseline filters like every other finding.- Seven money-correctness rules in
finance, which previously only held
PII/credential detectors: money in binary floating-point fields,
toFixedcurrency rounding,Math.roundon money, exact-equality
money comparisons,parseFloatmoney parsing, unsynchronized
read-modify-write balance updates, and wall-clock settlement/expiry
timestamps. Counting-shaped identifiers (total_findings == 0) are
excluded from the equality rule. 653 → 660 patterns. - New
cryptographycategory with ten primitive-misuse rules: MD5/SHA-1
password hashing, weak HMACs, ECB mode, legacy ciphers (DES/3DES/RC4/
Blowfish), sub-15000-iteration PBKDF2, RSA without OAEP, key material
derived from non-cryptographic PRNGs (including Go:=assignments),
all-zero IVs/nonces, hard-coded salts, and timing-unsafe MAC
comparisons. 644 → 653 patterns. - Removed the byte-identical duplicate of
jwt-none-algorithmthat also
shipped assecurity-hardening-jwt-none-algorithm(same regex,
severity, and confidence in two categories); the web-security rule
remains. - Five hallucination-artifact markers in
ai-detection: retired OpenAI
/v1/enginesendpoint, doc-example placeholder credential assignments,
placeholder environment variable reads, imports of placeholder package
names, and comment-marked stub implementations — the shapes left behind
when generated code is pasted in unverified, each a silent-failure risk.
639 → 644 patterns. - Six research-grounded AI-writing markers in
ai-detection(assistant-conversation
remnants, formulaic verbs, marketing vocabulary, hedging boilerplate, academic
phrasing, emoji-led Markdown headings), informed by the detector-ablation
literature; the category page now states explicitly that these are triage
signals rather than verdicts, since formulaic human writing triggers them and
paraphrasing defeats them. 633 → 639 patterns. scripts/generate_examples.pynow emits the lint attributes on the generated
example_forlookup, so regenerating liveness examples no longer produces a
file that failsclippy -D warnings.- Hierarchical pattern catalog under
docs/patterns/: a high-level index
(scoring, scoping, severity distribution) linking one generated page per
category with every pattern's regex, metadata, and liveness-verified
example. Regenerated bycargo run -p aegis-patterns --example generate_docs; a freshness test fails CI when the pages drift. Long
credential-shaped runs in rendered examples are elided so the catalog can
live in the repository without tripping secret scanners; the exact inputs
stay compiled incrates/aegis-patterns/src/examples.rs.
Changed
- Documentation count refresh: the README category table now lists all 34
categories with per-category counts (the previous 15-row table predates
ai-detection,cryptography, and the finance expansion), and the wiki
mirror,docs/README.md,docs/PLAN.md, and the quick-start guide carry
the 660/34 totals with the current severity distribution. - Wiki and documentation audit: replaced stale references (invented install
paths, flags, config formats, release asset names) with the real CLI/MCP
surface, corrected pattern counts, and rewrote the six wiki pages to match
v0.4.0 behavior.