Skip to content

AuthZest v0.1.0-alpha.1

Pre-release
Pre-release

Choose a tag to compare

@casing1 casing1 released this 03 Sep 16:52
· 87 commits to main since this release
d1f4213

AuthZest v0.1.0-alpha.1 is the first public preview of the source-aware authorization security testing tool for FastAPI projects.

Included in this preview

  • Typer CLI commands for diagnostics, repository scans, JSON output, and the optional local dashboard.
  • Deterministic discovery of FastAPI-style route decorators.
  • A FastAPI local API and React/Vite dashboard.
  • A separated Codex adapter interface; no source is sent to an AI service in this release.
  • Linux x64, macOS ARM64, and Windows x64 standalone executables with SHA-256 manifests.
  • CI, CodeQL scanning, contribution guidance, and a documented security policy.

Security boundary

Direct CLI scans accept paths chosen by the local user. The HTTP API cannot accept a caller-controlled filesystem path and scans only the workspace selected when the local process starts.

Try it

Download the executable and matching .sha256 file for your operating system, verify the checksum from their containing directory, and then run:

authzest --version
authzest doctor
authzest scan /path/to/fastapi-project

Linux and macOS users may need to make the file executable with chmod +x. These preview binaries are not notarized or signed for public distribution, so the operating system may display an unverified-publisher warning.

Current limitations

This is an executable scaffold, not a complete vulnerability scanner. Authorization classification, security findings, active HTTP testing, and live Codex-backed analysis remain planned work.

See CHANGELOG.md for the release contents.