detdrift 1.0.0
Stable 1.0 release. Phase 4 dialects (KQL + SPL) are in, and the JSON report / exit-code contract is frozen.
Why 1.0 now
- Second dialect works behind the same CLI (KQL and SPL, in addition to Sigma)
schema_version1 is the stable 1.0 report contract (see docs/json-report.md)- Exit codes
0/1/2remain part of the interface
Install (GitHub; no PyPI in this release)
pip install git+https://github.com/chriswayneh/detdrift.git@v1.0.0
Action pin
- uses: chriswayneh/detdrift@v1.0.0
with:
before: samples/before.jsonl
after: samples/after.jsonl
rules: detections/
# dialect: kql # optional: sigma | kql | spl | autoHighlights since 0.1
- Impact reports for Sigma field drift (CI-friendly exit codes)
- Fail-on severity/tag filters; reusable GitHub Action
- propose-patch helper + agent skill
- Sample importers, SARIF output, empty-after warnings
- Optional KQL/SPL field extractors (
--dialect); Actiondialectinput
Not in this release
- PyPI publish (optional / later)
- Portfolio GIFs
Verify
pip install -e ".[dev]"
pytest -q
python -m detdrift diff -b fixtures/before -a fixtures/after -r rules
python -m detdrift diff -b fixtures/kql/before -a fixtures/kql/after -r examples/kql/rules --dialect kql
python -m detdrift diff -b fixtures/spl/before -a fixtures/spl/after -r examples/spl/rules --dialect spl
See CHANGELOG.md for the full 0.1 → 1.0 summary.