v0.6.0
·
48 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Ten PHI-handling rules for HIPAA technical safeguards in healthcare, per-language anomaly baselines, and a configurable anomaly layer (--no-anomalies, --anomaly-detectors, config profiles). checksums.txt is now a verifiable sha256sum -c manifest of the published archives.
Changelog
Added
- Ten PHI-handling rules in
healthcare, which previously only held
identifier-format detectors: three more provider identifiers (NPI,
DEA registration, Medicare MBI/HICN) plus seven HIPAA
technical-safeguard hazards — PHI in log or print output, hard-coded
patient-identifier literals, patient resources referenced over
plaintext HTTP, PHI routed through email,SELECT *over PHI tables
(the minimum-necessary standard), patient identifiers in URL query
strings, and encryption explicitly disabled next to patient data.
660 → 670 patterns.
Changed
- Statistical anomaly z-scores are now computed per language group —
the eligible files sharing an extension — instead of across the whole
repository. Comment conventions differ too much between languages for
a mixed baseline to mean anything: a narrated Python file judged
against terse Rust siblings was a false outlier waiting to happen. A
group smaller than eight files supports no z-score, so files in
minority languages are not judged rather than judged against someone
else's norm; the Pareto comment-concentration detector remains
repository-total by definition. - The statistical anomaly layer is configurable:
ScanOptions::anomaly_detectorsin the core API,--no-anomaliesand
--anomaly-detectors <list>on the CLI (unknown names fail loudly
with the valid list), and ananomaly_detectorsfield in
-c/--configprofile JSON.null/unset runs all four detectors, an
empty allow-list disables the layer entirely, and a non-empty list
runs exactly the named detectors. A disabled layer also skips metric
collection during the walk.
Fixed
- Release pipeline
checksums.txtis now a usable verification file: it
lists every published archive (platform tarballs, WASM, source) in
standardsha256sum -cformat, computed from the final assembled
assets. Previously each platform job hashed its unpacked binaries, the
Windows job stripped filenames from its lines, and artifact merging
let the Windows file silently overwrite all the others — so v0.5.0
shipped four bare Windows binary hashes that matched nothing
downloadable (release assets are immutable once published, so that
file cannot be corrected in place; it is superseded from the next
release on).