Skip to content

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 08 Sep 12:24
· 54 commits to main since this release
Immutable release. Only release title and notes can be modified.
07e37f0

A statistical anomaly layer for directory scans — comment-ratio, comment-concentration, identifier-diversity, and file-size outliers reported through a new Severity::Info tier that can never fail a CI run — plus seven money-correctness rules in finance.

Changelog

Added

  • Statistical anomaly layer in the engine: directory scans now collect
    per-file metrics (line counts, comment share under a line-prefix
    heuristic, identifier diversity) and emit Severity::Info findings in
    the new statistical-anomaly category for files far outside their own
    repository's baseline — comment-ratio-outlier (z > 2.5), Pareto-style
    comment-concentration (one file holding ≥ 60% of repo commentary),
    identifier-diversity-outlier (heavy token reuse below 0.2 diversity),
    and file-size-outlier (z > 2.5). Each detector reports only its most
    extreme file; prose, dotfiles, lockfiles, and minified bundles are
    excluded. Grounded in the detection-brittleness literature, the
    observations are triage signals, not verdicts.
  • Severity::Info across the engine: weight 0 in risk scoring, info
    accepted by Severity::parse and custom .aegis.yml patterns, an INFO
    label in text output, SARIF note level, and exclusion from the exit
    code — informational findings are reported in every format but can
    never fail a CI run. They also respect category, severity-threshold,
    and baseline filters like every other finding.
  • Seven money-correctness rules in finance, which previously only held
    PII/credential detectors: money in binary floating-point fields,
    toFixed currency rounding, Math.round on money, exact-equality
    money comparisons, parseFloat money parsing, unsynchronized
    read-modify-write balance updates, and wall-clock settlement/expiry
    timestamps. Counting-shaped identifiers (total_findings == 0) are
    excluded from the equality rule. 653 → 660 patterns.
  • New cryptography category with ten primitive-misuse rules: MD5/SHA-1
    password hashing, weak HMACs, ECB mode, legacy ciphers (DES/3DES/RC4/
    Blowfish), sub-15000-iteration PBKDF2, RSA without OAEP, key material
    derived from non-cryptographic PRNGs (including Go := assignments),
    all-zero IVs/nonces, hard-coded salts, and timing-unsafe MAC
    comparisons. 644 → 653 patterns.
  • Removed the byte-identical duplicate of jwt-none-algorithm that also
    shipped as security-hardening-jwt-none-algorithm (same regex,
    severity, and confidence in two categories); the web-security rule
    remains.
  • Five hallucination-artifact markers in ai-detection: retired OpenAI
    /v1/engines endpoint, doc-example placeholder credential assignments,
    placeholder environment variable reads, imports of placeholder package
    names, and comment-marked stub implementations — the shapes left behind
    when generated code is pasted in unverified, each a silent-failure risk.
    639 → 644 patterns.
  • Six research-grounded AI-writing markers in ai-detection (assistant-conversation
    remnants, formulaic verbs, marketing vocabulary, hedging boilerplate, academic
    phrasing, emoji-led Markdown headings), informed by the detector-ablation
    literature; the category page now states explicitly that these are triage
    signals rather than verdicts, since formulaic human writing triggers them and
    paraphrasing defeats them. 633 → 639 patterns.
  • scripts/generate_examples.py now emits the lint attributes on the generated
    example_for lookup, so regenerating liveness examples no longer produces a
    file that fails clippy -D warnings.
  • Hierarchical pattern catalog under docs/patterns/: a high-level index
    (scoring, scoping, severity distribution) linking one generated page per
    category with every pattern's regex, metadata, and liveness-verified
    example. Regenerated by cargo run -p aegis-patterns --example generate_docs; a freshness test fails CI when the pages drift. Long
    credential-shaped runs in rendered examples are elided so the catalog can
    live in the repository without tripping secret scanners; the exact inputs
    stay compiled in crates/aegis-patterns/src/examples.rs.

Changed

  • Documentation count refresh: the README category table now lists all 34
    categories with per-category counts (the previous 15-row table predates
    ai-detection, cryptography, and the finance expansion), and the wiki
    mirror, docs/README.md, docs/PLAN.md, and the quick-start guide carry
    the 660/34 totals with the current severity distribution.
  • Wiki and documentation audit: replaced stale references (invented install
    paths, flags, config formats, release asset names) with the real CLI/MCP
    surface, corrected pattern counts, and rewrote the six wiki pages to match
    v0.4.0 behavior.