AuthZest v0.1.0-alpha.1
Pre-releaseAuthZest v0.1.0-alpha.1 is the first public preview of the source-aware authorization security testing tool for FastAPI projects.
Included in this preview
- Typer CLI commands for diagnostics, repository scans, JSON output, and the optional local dashboard.
- Deterministic discovery of FastAPI-style route decorators.
- A FastAPI local API and React/Vite dashboard.
- A separated Codex adapter interface; no source is sent to an AI service in this release.
- Linux x64, macOS ARM64, and Windows x64 standalone executables with SHA-256 manifests.
- CI, CodeQL scanning, contribution guidance, and a documented security policy.
Security boundary
Direct CLI scans accept paths chosen by the local user. The HTTP API cannot accept a caller-controlled filesystem path and scans only the workspace selected when the local process starts.
Try it
Download the executable and matching .sha256 file for your operating system, verify the checksum from their containing directory, and then run:
authzest --version
authzest doctor
authzest scan /path/to/fastapi-project
Linux and macOS users may need to make the file executable with chmod +x. These preview binaries are not notarized or signed for public distribution, so the operating system may display an unverified-publisher warning.
Current limitations
This is an executable scaffold, not a complete vulnerability scanner. Authorization classification, security findings, active HTTP testing, and live Codex-backed analysis remain planned work.
See CHANGELOG.md for the release contents.