Skip to content

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 09 Sep 04:42
· 48 commits to main since this release
Immutable release. Only release title and notes can be modified.
5717e06

Ten PHI-handling rules for HIPAA technical safeguards in healthcare, per-language anomaly baselines, and a configurable anomaly layer (--no-anomalies, --anomaly-detectors, config profiles). checksums.txt is now a verifiable sha256sum -c manifest of the published archives.

Changelog

Added

  • Ten PHI-handling rules in healthcare, which previously only held
    identifier-format detectors: three more provider identifiers (NPI,
    DEA registration, Medicare MBI/HICN) plus seven HIPAA
    technical-safeguard hazards — PHI in log or print output, hard-coded
    patient-identifier literals, patient resources referenced over
    plaintext HTTP, PHI routed through email, SELECT * over PHI tables
    (the minimum-necessary standard), patient identifiers in URL query
    strings, and encryption explicitly disabled next to patient data.
    660 → 670 patterns.

Changed

  • Statistical anomaly z-scores are now computed per language group —
    the eligible files sharing an extension — instead of across the whole
    repository. Comment conventions differ too much between languages for
    a mixed baseline to mean anything: a narrated Python file judged
    against terse Rust siblings was a false outlier waiting to happen. A
    group smaller than eight files supports no z-score, so files in
    minority languages are not judged rather than judged against someone
    else's norm; the Pareto comment-concentration detector remains
    repository-total by definition.
  • The statistical anomaly layer is configurable:
    ScanOptions::anomaly_detectors in the core API, --no-anomalies and
    --anomaly-detectors <list> on the CLI (unknown names fail loudly
    with the valid list), and an anomaly_detectors field in
    -c/--config profile JSON. null/unset runs all four detectors, an
    empty allow-list disables the layer entirely, and a non-empty list
    runs exactly the named detectors. A disabled layer also skips metric
    collection during the walk.

Fixed

  • Release pipeline checksums.txt is now a usable verification file: it
    lists every published archive (platform tarballs, WASM, source) in
    standard sha256sum -c format, computed from the final assembled
    assets. Previously each platform job hashed its unpacked binaries, the
    Windows job stripped filenames from its lines, and artifact merging
    let the Windows file silently overwrite all the others — so v0.5.0
    shipped four bare Windows binary hashes that matched nothing
    downloadable (release assets are immutable once published, so that
    file cannot be corrected in place; it is superseded from the next
    release on).