v0.6.1: Action dialect input
Action dialect input + CI dialect demos
Callers of the reusable composite Action can pass dialect (sigma|kql|spl|auto) into detdrift diff. CI examples run the bundled Sigma demo plus KQL/SPL fixtures when present.
What'''s new
- �ction.yml input dialect (default sigma) -> detdrift diff --dialect
- .github/workflows/detdrift.yml and docs/ci/detdrift.yml: KQL + SPL demo drift steps (hashFiles gated)
- README: Action dialect one-liner; CLI flag list includes spl
- ROADMAP: Action dialect noted under Phase 4
Not in this release
- PyPI publish
- Portfolio GIFs
Verify
pip install -e .[dev] pytest -q detdrift diff -b fixtures/before -a fixtures/after -r rules detdrift diff -b fixtures/kql/before -a fixtures/kql/after -r examples/kql/rules --dialect kql detdrift diff -b fixtures/spl/before -a fixtures/spl/after -r examples/spl/rules --dialect spl