Skip to content

Releases: chasebryan/snoot

Snoot v0.1.0 — cryptography inventory

Choose a tag to compare

@github-actions github-actions released this 01 Oct 04:03
177e0c6

Snoot v0.1.0

First public GitHub Action and CLI release for classical cryptography inventory.
Snoot finds API calls, supported key material, direct dependency declarations,
and TLS configuration indicators, then produces SARIF, JSON, and CycloneDX 1.6
CBOM evidence. This release is experimental: findings need review, and a clean
scan does not establish inventory completeness or quantum safety.

Use the action

- uses: chasebryan/snoot@v0.1.0
  with:
    path: .
    fail-on: high

Check out the repository first. SARIF upload requires contents: read,
actions: read, security-events: write, and GitHub code-scanning access.
Set upload-sarif: 'false' for a report and severity gate without code scanning.
See the README for full workflows, inputs, outputs, baselines, and fork handling.

The composite action compiles this exact revision with Rust 1.90 and locked
Cargo dependencies. It supports GitHub-hosted Linux, macOS, and Windows runners.
Source builds need network access to Rust distribution and Cargo registries;
scanning itself makes no network requests. GitHub Enterprise installations need
runners able to execute the pinned CodeQL upload action, or upload disabled.

Release behavior

  • 22 detection rules across eight source languages and four detection engines.
  • Version-2 portable baselines, explicit overwrite protection, and atomic reports.
  • Incomplete scans and invalid inputs fail instead of appearing clean.
  • Reports remain available when the severity gate fails. The action uploads SARIF
    before enforcing the gate, and translates subdirectory locations to repository paths.
  • All action inputs are passed as literal arguments. Baselines and exclusions are
    tested end to end, with completed-report and finding-count outputs.
  • Five native archives: Linux x64/ARM64 (glibc 2.35+), macOS Intel/Apple Silicon
    (macOS 11+), Windows x64. Every archive is extracted and its CLI, finding gate,
    baseline, and error exits exercised on the corresponding runner.
  • Each archive has a SHA-256 sidecar; SHA256SUMS covers all five archives.
    The action builds from source rather than downloading mutable release assets.
  • Archives include upstream dependency and Rust runtime notices as well as the
    project license; packaging checks the notices against the locked dependencies.

Known limits

Detection is heuristic, recall is unmeasured, and imports/types, indirect calls,
transitive dependencies, TLS includes/inheritance, and several encrypted or
unsupported key formats remain outside complete coverage. Files above 4 MiB and
unsupported binary sources are skipped. Review README and docs/accuracy.md
before making migration or compliance decisions. This release provides inventory
evidence; it does not certify compliance or a complete cryptographic inventory.

License: AGPL-3.0-only. No crates.io publication is part of this release.