Skip to content

v0.6.1: Action dialect input

Choose a tag to compare

@chriswayneh chriswayneh released this 24 Sep 12:22
· 5 commits to main since this release

Action dialect input + CI dialect demos

Callers of the reusable composite Action can pass dialect (sigma|kql|spl|auto) into detdrift diff. CI examples run the bundled Sigma demo plus KQL/SPL fixtures when present.

What'''s new

  • �ction.yml input dialect (default sigma) -> detdrift diff --dialect
  • .github/workflows/detdrift.yml and docs/ci/detdrift.yml: KQL + SPL demo drift steps (hashFiles gated)
  • README: Action dialect one-liner; CLI flag list includes spl
  • ROADMAP: Action dialect noted under Phase 4

Not in this release

  • PyPI publish
  • Portfolio GIFs

Verify

pip install -e .[dev] pytest -q detdrift diff -b fixtures/before -a fixtures/after -r rules detdrift diff -b fixtures/kql/before -a fixtures/kql/after -r examples/kql/rules --dialect kql detdrift diff -b fixtures/spl/before -a fixtures/spl/after -r examples/spl/rules --dialect spl