Skip to content

Releases: casing1/authzest

v0.1.0-alpha.3

v0.1.0-alpha.3 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 12 Sep 09:00
99be6f5

AuthZest 0.1.0-alpha.3

An alpha checkpoint for the bounded, user-approved Codex fixture workflow—not a general vulnerability scanner or automatic repair tool.

English

  • Adds offline AI review/proposal contracts, explicit sharing and exact-diff decisions, and application/restoration in a fresh owned-fixture copy. Existing checkouts are not edited.
  • Adds codex-fixture with the version-pinned Codex App Server 0.153.0 adapter. Install and authenticate Codex separately; ordinary scan remains offline and requires no account. Source sharing can consume Codex usage.
  • Keeps the separately approved AST configuration check as the default. --runtime-check selects—but does not approve—a different fixed check: execute only the byte-identical bundled fixture, observe app.debug, and check in-memory ASGI GET /health for HTTP 200 and {"status":"ok"}. Verification and restoration still require separate exact confirmations.
  • Records scoped results, source/checker identities, dependency observations and conflict-aware restoration. Scan report schema stays 1.2; runtime-session journal schema 1.2 is a separate contract.

Limits: the only supported change is the maintained fixture's debug=True → debug=False. No arbitrary repository execution, generated test/command execution, exploit reproduction, or automatic dependency installation. The fixture workflow requires supported POSIX operations; Windows scan support remains, but the fixture runtime workflow is unsupported. The fixed worker keeps a 5-second startup/I/O deadline plus separate 1-second cleanup bound. Process separation is not an OS/network sandbox. Codex transport recovery is not a hard token, provider-attempt, or monetary cap.

One earlier, explicitly authorized source-CLI live run completed draft/apply/runtime-check/restore on ce2834c; the assistant entered the exact phrases, not an independent human reviewer. Native packaging checks and fake-transport tests are separate offline evidence, not additional live-model validation. Neither proves authorization correctness or a verified security fix; broader #35 acceptance remains open.

Standalone executables are unsigned/not notarized, with matching SHA-256 manifests. CI and relocation smoke do not establish clean consumer installation or upgrades. This release does not publish to PyPI or npm.

한국어

일반 취약점 스캐너나 자동 수정 완성본이 아닌, 범위를 제한한 사용자 승인형 Codex fixture 흐름의 알파 중간 버전입니다.

  • 오프라인 AI 검토·제안 계약, 명시적 공유·정확한 diff 결정, 새 소유 fixture 복사본의 적용·복구를 추가합니다. 기존 checkout은 수정하지 않습니다.
  • codex-fixture는 Codex App Server 0.153.0을 고정 사용합니다. Codex는 별도로 설치·로그인해야 하며 공유 시 사용량이 소비될 수 있습니다. 일반 scan은 계정 없이 오프라인으로 동작합니다.
  • 별도 승인 AST 설정 검사가 기본값입니다. --runtime-check는 실행 승인이 아니라 다른 고정 검사 계획의 선택입니다. 바이트가 동일한 번들 fixture만 실행하여 app.debug와 메모리 내 ASGI GET /health의 HTTP 200·{"status":"ok"}를 확인합니다. 검사·복구는 각각 정확한 확인 문구가 필요합니다.
  • 범위를 명시한 결과, 소스·검사 식별값, 의존성 관찰값과 충돌을 고려한 복구를 기록합니다. 스캔 리포트 스키마는 1.2를 유지하며 런타임 세션 journal 1.2와는 별개입니다.

지원 변경은 관리하는 fixture의 debug=True → debug=False뿐입니다. 임의 저장소·생성 테스트/명령 실행, 악용 재현, 의존성 자동 설치는 지원하지 않습니다. fixture 흐름은 지원 POSIX 연산이 필요하며 Windows 스캔은 유지하지만 fixture 런타임 흐름은 지원하지 않습니다. worker의 시작·입출력 5초와 별도 정리 1초 제한을 유지합니다. 프로세스 분리는 OS/네트워크 sandbox가 아니며 Codex 복구 알림 제한은 토큰·제공자 시도·금액 상한이 아닙니다.

앞서 별도 승인받은 ce2834c 소스 CLI 실제 연동에서 초안·적용·런타임 검사·복구가 한 번 완료됐습니다. 확인 문구는 assistant가 입력했으며 독립적인 인간 검토 증거가 아닙니다. native 패키징·가짜 transport 검사는 별도의 오프라인 근거이지 추가 실제 모델 검증이 아닙니다. 인가 정확성이나 보안 수정 효과를 입증하지 않으며 더 넓은 #35 완료 조건은 남아 있습니다.

독립 실행 파일은 서명·공증되지 않았으며 대응 SHA-256 파일을 제공합니다. CI·이동 복사본 smoke는 새 소비자 환경 설치나 업그레이드 검증을 대신하지 않습니다. PyPI·npm 발행은 하지 않습니다.

English changelog · 한국어 변경 이력 · Runtime scope and evidence

Verification / 검증

Published 2026-09-12 from 99be6f5614d283befa2a421b64f84958b680f92f (package 0.1.0a3). Main candidate and tag publishing run passed, including 1,548 Python tests and three-platform fresh artifact checks. All six public files were downloaded again, passed checksums, and matched tag artifacts byte-for-byte. The public macOS binary also passed local relocated scan (7) and fixed runtime (1) checks. Linux/Windows execution evidence is matching-platform CI; Windows runtime checks assert unsupported behavior.

2026-09-12 위 커밋에서 패키지 0.1.0a3로 발행했습니다. main 후보·태그 워크플로, Python 테스트 1,548개와 세 플랫폼 새 다운로드 검사를 통과했습니다. 공개 파일 6개를 다시 내려받아 체크섬과 태그 산출물의 바이트 일치를 확인했고, 공개 macOS 파일은 로컬 이동 scan 7개와 고정 runtime 1개도 통과했습니다. Linux/Windows 실행 근거는 동일 OS CI이며 Windows 런타임 검사는 미지원 동작 확인입니다.

What's Changed

  • docs: align guides with published alpha.2 by @casing1 in #42
  • docs: require issue and PR tracking metadata by @casing1 in #44
  • feat: implement offline AI evidence contracts and evaluation by @casing1 in #45
  • feat: add offline proposal-bound decisions by @casing1 in #47
  • feat: apply approved changes to owned-fixture copies by @casing1 in #49
  • feat(codex): connect the opt-in owned-fixture workflow by @casing1 in #51
  • feat(runner): add approved fixture configuration verification by @casing1 in #53
  • feat(runner): add approved owned-fixture runtime verification by @casing1 in #55
  • chore(release): prepare v0.1.0-alpha.3 by @casing1 in #57

Full Changelog: v0.1.0-alpha.2...v0.1.0-alpha.3

v0.1.0-alpha.2

v0.1.0-alpha.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 10 Sep 05:56
7cc359a

AuthZest v0.1.0-alpha.2

English

This prerelease updates the CLI-first, source-only FastAPI inventory. Python package version: 0.1.0a2; report schema: 1.2. Release commit: 7cc359acbb864ef6d31e3b536787857da4f7e09c.

Changes since alpha.1

  • Recognize supported FastAPI/APIRouter owners, literal prefixes, and repository-local router imports without importing or executing the scanned application.
  • Preserve distinct route registrations and source locations, structured diagnostics, bounded/partial analysis status, and opt-in scan --strict.
  • Record route-local Depends/Security declarations and inherited application/router/include context. dependencies stays local; effective_dependencies includes the supported inherited context.
  • Organize English documentation by topic, with mirrored Korean folders and separate Japanese/Russian README folders. See the documentation index.
  • Gate publishing on version/changelog consistency, fixture-report binary checks, SHA-256 checks, and downloaded-artifact smoke tests in fresh jobs on all three build platforms.

Artifacts and validation

Download the executable for your OS/architecture together with its matching .sha256 file. The provided binaries are Linux x64, macOS arm64, and Windows x64. Verify the checksum before enabling execution; follow the release guide.

Validation covers 451 Python tests, 14 documentation-checker tests, frontend checks/build, and four maintained source-only fixture scans through the built and relocated binaries. Separate CI jobs download and check each artifact without installing AuthZest's Python dependencies. The manual main validation is run 34442310332; the publishing run 34442837616 repeats these gates for the tag.

These are unsigned, unnotarized alpha executables. CI and relocated-copy checks do not establish clean installation or upgrades on consumer devices, nor compatibility with every OS version. No PyPI/npm package is published by this release.

Scope and next work

Dependency declarations are source evidence, not proof of authentication or authorization. Nested callable resolution, security verdicts, live Codex integration, patch application, and verification execution are not implemented. Successful scans are not security passes; unsupported source patterns can produce partial reports.

Next: #33 offline evidence/response contract, followed by #35 user-approved Codex defensive patch and verification workflow.

Read the full English changelog. Compare alpha.1 to alpha.2.

한국어

CLI 중심의 소스 전용 FastAPI 목록 분석을 갱신한 프리릴리스입니다. Python 패키지 버전은 0.1.0a2, 리포트 스키마는 1.2이며 릴리스 커밋은 7cc359acbb864ef6d31e3b536787857da4f7e09c입니다.

alpha.1 이후 변경

  • 스캔 대상 앱을 import하거나 실행하지 않고 지원 범위의 FastAPI/APIRouter 소유자, 리터럴 prefix, 저장소 내부 router import를 인식합니다.
  • 개별 라우트 등록과 원본 소스 위치, 구조화된 진단, bounded/partial 상태, 선택적 scan --strict를 제공합니다.
  • 직접 Depends/Security 선언과 app/router/include 상속 맥락을 기록합니다. dependencies는 직접 선언을 유지하고 effective_dependencies에 지원하는 상속 맥락을 함께 담습니다.
  • 영어 문서를 주제별로 정리하고 한국어는 같은 주제 구조로, 일본어·러시아어 README는 언어별 폴더로 분리했습니다. 한국어 문서 목차를 참고하세요.
  • 버전·변경 기록 일치, 실제 바이너리의 fixture 리포트, SHA-256, 세 빌드 플랫폼의 별도 다운로드 실행 검사가 통과해야 발행하도록 구성했습니다.

배포 파일과 검증

자신의 OS/아키텍처에 맞는 실행 파일과 대응하는 .sha256 파일을 함께 받으세요. 제공 파일은 Linux x64, macOS arm64, Windows x64입니다. 실행 권한을 부여하기 전에 체크섬을 확인하고 한국어 릴리스 가이드를 따르세요.

Python 테스트 451개, 문서 검사기 테스트 14개, frontend 검사·빌드, 직접 관리하는 소스 전용 fixture 4종의 실제 바이너리·복사본 스캔을 검증했습니다. 별도 CI 작업은 AuthZest의 Python 의존성을 설치하지 않고 배포 파일을 내려받아 검사합니다. main 사전 검증은 실행 34442310332이며, 발행 실행 34442837616에서도 태그에 대해 같은 검증을 반복합니다.

서명·공증되지 않은 알파 실행 파일입니다. CI와 복사본 실행 검사는 일반 사용자 기기의 깨끗한 설치·업그레이드 또는 모든 OS 버전의 호환성을 보장하지 않습니다. 이번 릴리스는 PyPI/npm 패키지를 발행하지 않습니다.

범위와 다음 작업

의존성 선언은 소스 근거이며 인증·인가가 안전하다는 증명이 아닙니다. 중첩 함수 해석, 취약점 판정, 실제 Codex 연동, 패치 적용, 검증 실행은 아직 구현하지 않았습니다. 성공 종료는 보안 통과가 아니며 미지원 구문은 부분 분석으로 남을 수 있습니다.

다음은 #33 오프라인 근거·응답 계약, 이후 #35 사용자 승인형 Codex 방어적 수정·검증 흐름입니다.

전체 한국어 변경 기록 · alpha.1과 alpha.2 비교

Merged pull requests / 병합 PR

The original automatically generated PR history is retained below. / 자동 생성된 원래 PR 이력을 아래에 보존합니다.

What's Changed

  • fix(release): make publishing portable by @casing1 in #16
  • docs(release): record first public preview by @casing1 in #18
  • fix(parser): recognize FastAPI route owners by @casing1 in #20
  • chore(ci): require CodeQL before merging by @casing1 in #23
  • feat(parser): compose same-file router prefixes by @casing1 in #24
  • feat(parser): resolve repository-local router imports by @casing1 in #26
  • docs: align CLI-first roadmap and bilingual project guides by @casing1 in #30
  • fix: strengthen evidence reliability and seven-week delivery plan by @casing1 in #34
  • feat: add versioned report and source registration evidence (#32) by @casing1 in #36
  • feat: collect route-local dependency evidence (#28) by @casing1 in #37
  • feat: propagate inherited dependency evidence per registration by @casing1 in #38
  • build: prepare alpha.2 artifacts and organize docs by @casing1 in #40

Full Changelog: v0.1.0-alpha.1...v0.1.0-alpha.2

AuthZest v0.1.0-alpha.1

Pre-release

Choose a tag to compare

@casing1 casing1 released this 03 Sep 16:52
d1f4213

AuthZest v0.1.0-alpha.1 is the first public preview of the source-aware authorization security testing tool for FastAPI projects.

Included in this preview

  • Typer CLI commands for diagnostics, repository scans, JSON output, and the optional local dashboard.
  • Deterministic discovery of FastAPI-style route decorators.
  • A FastAPI local API and React/Vite dashboard.
  • A separated Codex adapter interface; no source is sent to an AI service in this release.
  • Linux x64, macOS ARM64, and Windows x64 standalone executables with SHA-256 manifests.
  • CI, CodeQL scanning, contribution guidance, and a documented security policy.

Security boundary

Direct CLI scans accept paths chosen by the local user. The HTTP API cannot accept a caller-controlled filesystem path and scans only the workspace selected when the local process starts.

Try it

Download the executable and matching .sha256 file for your operating system, verify the checksum from their containing directory, and then run:

authzest --version
authzest doctor
authzest scan /path/to/fastapi-project

Linux and macOS users may need to make the file executable with chmod +x. These preview binaries are not notarized or signed for public distribution, so the operating system may display an unverified-publisher warning.

Current limitations

This is an executable scaffold, not a complete vulnerability scanner. Authorization classification, security findings, active HTTP testing, and live Codex-backed analysis remain planned work.

See CHANGELOG.md for the release contents.