Skip to content

v1.0.0: stable report contract + dialects

Latest

Choose a tag to compare

@chriswayneh chriswayneh released this 24 Sep 12:26
· 2 commits to main since this release

detdrift 1.0.0

Stable 1.0 release. Phase 4 dialects (KQL + SPL) are in, and the JSON report / exit-code contract is frozen.

Why 1.0 now

  • Second dialect works behind the same CLI (KQL and SPL, in addition to Sigma)
  • schema_version 1 is the stable 1.0 report contract (see docs/json-report.md)
  • Exit codes 0 / 1 / 2 remain part of the interface

Install (GitHub; no PyPI in this release)

pip install git+https://github.com/chriswayneh/detdrift.git@v1.0.0

Action pin

- uses: chriswayneh/detdrift@v1.0.0
  with:
    before: samples/before.jsonl
    after: samples/after.jsonl
    rules: detections/
    # dialect: kql   # optional: sigma | kql | spl | auto

Highlights since 0.1

  • Impact reports for Sigma field drift (CI-friendly exit codes)
  • Fail-on severity/tag filters; reusable GitHub Action
  • propose-patch helper + agent skill
  • Sample importers, SARIF output, empty-after warnings
  • Optional KQL/SPL field extractors (--dialect); Action dialect input

Not in this release

  • PyPI publish (optional / later)
  • Portfolio GIFs

Verify

pip install -e ".[dev]"
pytest -q
python -m detdrift diff -b fixtures/before -a fixtures/after -r rules
python -m detdrift diff -b fixtures/kql/before -a fixtures/kql/after -r examples/kql/rules --dialect kql
python -m detdrift diff -b fixtures/spl/before -a fixtures/spl/after -r examples/spl/rules --dialect spl

See CHANGELOG.md for the full 0.1 → 1.0 summary.