Skip to content

Releases: c2dc/aray

Aray v0.10.0

Choose a tag to compare

@e-valente e-valente released this 17 Aug 14:25

Aray v0.10.0 expands deterministic YARA handling, corpus evaluation, and constructibility diagnostics.

Highlights

  • Added deterministic evidence extraction with LLM fallback only for unsupported syntax.
  • Added standalone ruleset selection and dependency inlining before model calls.
  • Added capability preflight, evaluation dispositions, provenance, and upstream-original-rule validation.
  • Added signed integer, big-endian, PE32, compact layout, modifier, count, and placement support.
  • Hardened normalization validation for retained values, regex and hex witnesses, and count expansions.
  • Added automatic batch configuration for aray-eval and aray-normalize.
  • Published the 416-rule staged evaluation, machine-readable evidence, diagrams, and research paper.
  • Fixed CI to clone the pinned Yara-Rules corpus only inside test jobs and made generated normalization fixtures self-contained.

The deterministic suite passes on Python 3.12 and 3.13, with package build, documentation, and CodeQL checks passing.

See CHANGELOG.md for the complete change history.

Aray v0.9.0

Choose a tag to compare

@e-valente e-valente released this 05 Aug 18:21

Aray v0.9.0 expands benign YARA-matching artifact generation across Linux ELF, Windows PE, and generic file formats.

Highlights

  • Added deterministic normalization checks, judge retries, regex witness validation, and safe failure handling.
  • Added scan-only ELF and PE artifact generation without external compilers.
  • Added generic byte-blob generation for non-executable formats and exact offset placement.
  • Added role-specific LLM models, endpoints, API keys, streaming controls, and automatic structured-output fallback.
  • Added batch evaluation and normalization commands with file and directory input support.
  • Added filesize constraints, wide strings, multi-rule handling, and hardened PE/ELF code generation.
  • Added comprehensive CI, CodeQL, dependency review, coverage, packaging, and GitHub Pages documentation.
  • Adopted the Apache License 2.0.

See CHANGELOG.md for the complete change history.