Aray v0.10.0 expands deterministic YARA handling, corpus evaluation, and constructibility diagnostics.
Highlights
- Added deterministic evidence extraction with LLM fallback only for unsupported syntax.
- Added standalone ruleset selection and dependency inlining before model calls.
- Added capability preflight, evaluation dispositions, provenance, and upstream-original-rule validation.
- Added signed integer, big-endian, PE32, compact layout, modifier, count, and placement support.
- Hardened normalization validation for retained values, regex and hex witnesses, and count expansions.
- Added automatic batch configuration for
aray-evalandaray-normalize. - Published the 416-rule staged evaluation, machine-readable evidence, diagrams, and research paper.
- Fixed CI to clone the pinned Yara-Rules corpus only inside test jobs and made generated normalization fixtures self-contained.
The deterministic suite passes on Python 3.12 and 3.13, with package build, documentation, and CodeQL checks passing.
See CHANGELOG.md for the complete change history.