v0.6.2
·
34 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Aegis 0.6.2 — honesty pass. Five false-positive-prone detection rules
regex-corrected (hipaa-phi, code-injection-request, mesa-optimization,
executable-file-upload direction, k8s-run-as-non-root inversion), the
repository self-scans clean at high severity, enable/disable now
persist, worker count actually sizes the scan pool, and the never-wired
output pipeline (fake PostgreSQL/MySQL handlers) is gone. The Docker
image builds and was verified end-to-end; Kubernetes usage is a scan
CronJob. CI pins --locked everywhere and the release attestation
records the lockfile SHA-256.
Removed
- The never-wired
output-pipelinefeature ofaegis-core(file,
SQLite, webhook, PostgreSQL, and MySQL outputs plus the parallel YAML
preset configuration world). The PostgreSQL and MySQL implementations
logged what they "would insert" and returned success — fake
implementations — and no binary consumed any of it. Code that needs
database sinks should callserde_jsonand its own client.
Fixed
aegis disable <pattern>/aegis enable <pattern>now persist to
<config dir>/aegis/pattern-state.jsonand are honored by scans and
aegis list; previously both subcommands printed a confirmation and
changed nothing. Unknown pattern names fail loud with the valid-name
hint. Integration tests run against an isolatedXDG_CONFIG_HOME.ScanOptions::workersnow actually sizes the scan thread pool (rayon's
global pool ignored it), pool-build failures warn and fall back once,
andworkers_usedmerges as a maximum across shard stats instead of
being lost.- Silent-failure paths: an unscannable pattern is logged with its name
instead of vanishing from scans; the clone tokenizer advances by
UTF-8 width instead of one byte (panicked on multibyte escapes);
trim_stringtruncates on character boundaries; MCP and daemon
response writes surface transport errors instead of.ok()-ing them.
Security
- Container/deploy hardening: the Docker image now builds (rust 1.88,
--locked, non-root) and the Kubernetes phantom HTTP daemon
(endpoints that never existed) was replaced by a scan CronJob with no
Kubernetes API access.