v1.1.1
Release v1.1.0
🎉 Major Update
This is the biggest GESF release yet. We added 7 new CLI commands, 3 new packages, 3 new policy packs, a VS Code extension, an ESLint plugin, a web dashboard, infrastructure scanning, dependency analysis, multi-language support, and comprehensive documentation with exercises.
By the numbers:
| Metric | v1.0.1 | v1.1.0 |
|---|---|---|
| Packages | 13 | 16 |
| Policy Packs | 7 | 10 |
| Compliance Controls | 67 | 88 |
| CLI Commands | 14 | 18 |
| Audit Scanners | 6 | 8 |
| Languages Scanned | 4 | 7 |
| MCP Tools | 6 | 17 |
| Unit Tests | 120 | 656 |
🆕 New Features
Auto-Fix Engine (ges fix)
Automatically fixes security and compliance findings detected by the audit engine.
ges fix # Apply all auto-fixable issues
ges fix --dry-run # Preview without making changes
ges fix --rules CONFIG-001 # Fix only specific rules
ges fix --ci # Exit non-zero if findings remainHandles 15 rule types across 7 languages including adding security headers, creating .gitignore entries, generating missing compliance documents, replacing MD5 with SHA-256, extracting hardcoded secrets to environment variables, and adding rate limiting.
Git Hooks (ges hooks)
Pre-commit enforcement that blocks commits containing security findings.
ges hooks install # Install pre-commit hook
ges hooks uninstall # Remove the hookThe installed hook runs ges audit --ci before every git commit. If critical findings exist, the commit is blocked. Bypass with git commit --no-verify.
Web Dashboard (ges dashboard)
A local web server displaying real-time compliance posture in your browser.
ges dashboard # http://localhost:3001
ges dashboard --port 8080 # Custom portFeatures a live HTML dashboard with scores, findings, control status, and policy pack coverage. Includes a JSON API (/api/data, /health) for integration with monitoring tools.
Infrastructure-as-Code Scanner
New scanner analyzing Terraform and CloudFormation for 15 infrastructure misconfigurations:
- S3 buckets with public-read ACLs
- S3 buckets without encryption or versioning
- Security groups open to
0.0.0.0/0 - SSH (port 22), MySQL (3306), PostgreSQL (5432) exposed to the internet
- RDS instances publicly accessible or without encryption
- IAM policies with wildcard actions or resources
- KMS keys without rotation
- SSL/TLS disabled on resources
force_destroyenabled on buckets
Dependency Analysis
Multi-language dependency analysis detecting vulnerabilities, deprecated packages, license issues, and outdated versions:
| Ecosystem | Scanner |
|---|---|
| Node.js | npm audit |
| Python | pip-audit |
| Rust | cargo audit |
| Go | govulncheck |
Identifies deprecated packages with recommended alternatives and flags copyleft licenses (GPL, AGPL).
ESLint Plugin (@greenarmor/eslint-plugin-ges)
Real-time linting rules that catch security issues directly in your editor before you even run ges audit.
Three rules included:
no-hardcoded-secrets— Detects passwords, API keys, tokens, private keysno-weak-crypto— Detects MD5, SHA1, DES, ECB mode, disabled TLSno-injection— Detects SQL injection, command injection,eval()
{
"extends": ["plugin:@greenarmor/ges/recommended"]
}VS Code Extension (gesf-vscode)
Real-time compliance warnings, inline diagnostics, and one-click commands in VS Code.
- Red squiggly underlines for security issues as you type
- Status bar showing live compliance score
- Command palette: Run Audit, Show Score, Generate Report
- JSON schema validation for
.ges/config.json - Auto-activates when
.ges/config.jsonis present
Manual Control Overrides (ges control)
Mark compliance controls as pass, fail, not-applicable, or warning for controls that cannot be detected by source code scanning.
ges control GDPR-ART32-001 pass -r "Implemented with AWS KMS"
ges control GDPR-ART32-003 not-applicable -r "Not using AWS"Overrides are saved to .ges/control-overrides.json and affect the compliance score.
📋 New Policy Packs
ISO 27001 Information Security (11 controls)
Based on ISO/IEC 27001 Annex A. Covers information security policies (A5), organization (A6), asset management (A8), access control (A9), cryptography (A10), operations security (A12), communications security (A13), system acquisition and development (A14), incident management (A16), business continuity (A17), and compliance (A18).
ISO 27701 Privacy Information Management (11 controls)
Based on ISO/IEC 27701:2019. Extends ISO 27001 with privacy and PII protection covering privacy policies (5.2), roles and responsibilities (5.3), privacy risk assessment (5.4), PII identification and classification (6.2), de-identification and anonymization (6.4), PII segregation (6.5), retention and disposal (6.7), transfer controls (6.9), controller obligations (7.3), processor obligations (7.5), and privacy by design (8.4).
HIPAA Healthcare (10 controls)
Based on the HIPAA Security Rule and Privacy Rule (45 CFR 164). Covers administrative safeguards (164.308), physical safeguards (164.310), access control (164.312a), audit controls (164.312b), integrity controls (164.312c), authentication (164.312d), transmission security (164.312e), business associate contracts (164.314), minimum necessary standard (164.502), and administrative requirements (164.530).
🌍 Multi-Language Scanning
The crypto and code security scanners now detect vulnerabilities across 7 languages:
Crypto Scanner (weak algorithms)
| Language | Patterns Added |
|---|---|
| Python | hashlib.md5(), hashlib.sha1(), Crypto.Cipher.DES |
| Go | md5.New(), sha1.New(), crypto/des.NewCipher() |
| Java | MessageDigest.getInstance("MD5"), Cipher.getInstance("DES") |
| Rust | md5::compute(), sha1::Sha1, des::new() |
Also added: TLS verification disabled detection for Python (verify_mode = ssl.CERT_NONE), Go (InsecureSkipVerify), Java (TrustAllCerts), and Rust (danger_accept_invalid_certs).
Code Security Scanner (injection)
| Language | Patterns Added |
|---|---|
| Python | f-string SQL injection from request input |
| Go | SQL injection via fmt.Sprintf with request data |
| Rust | Command injection via Command::new().arg(user_input) |
📄 PDF Reports
ges report now generates PDF reports with zero external dependencies (no Puppeteer, no wkhtmltopdf). The PDF writer uses the raw PDF spec directly.
ges report --format pdf
ges report --format pdf --output reports/compliance.pdf⚡ Incremental Audit and .gesignore
Incremental Auditing
For large projects, the audit engine now caches file hashes and only re-scans files that have changed since the last run. This is used internally by git hooks and auto-fix for faster feedback.
.gesignore
Exclude files and directories from the audit using gitignore-style patterns:
# .gesignore
test/fixtures/
vendor/
*.generated.js🤖 MCP Server: 17 Tools
The MCP AI Compliance Assistant expanded from 6 to 17 tools:
Compliance Assessment:
check_compliance— Compliance scores per frameworkcheck_project_status— Real-time project statuslist_missing_controls— Missing controls per frameworklist_framework_controls— All controls for a frameworkrun_audit— Execute auditgenerate_compliance_report— Full compliance reportgenerate_audit_report— Audit findings report
Fix and Implement:
auto_fix— Automatically fix findings (dry-run supported)implement_control— Generate implementation files for a controlapply_control_override— Override control statusfix_recommendation— Detailed remediation guidance
Document Generation:
generate_retention_policy— Data retention policygenerate_incident_response— Incident response plangenerate_risk_assessment— Risk assessment templategenerate_dpa— Data Processing Agreementgenerate_data_inventory— Data inventory (Article 30)generate_processing_records— Records of processing activities
📚 Documentation
Comprehensive mkdocs documentation with hands-on exercises for every feature:
7 new pages:
- Auto-Fix guide with exercises
- Git Hooks guide with exercises
- Web Dashboard guide with exercises
- IaC Scanner reference (all 15 rules with Terraform examples)
- Dependency Analysis reference
- ESLint Plugin integration guide
- VS Code Extension integration guide
6 updated pages:
- Command Reference (4 new commands documented)
- Audit Scanners (expanded to 8 scanners with multi-language patterns)
- Policy Packs (expanded to 10 packs with full control tables)
- Running an Audit (added
.gesignoreand incremental audit) - Generating Reports (added PDF format)
- Quick Start (added auto-fix, hooks, and dashboard steps)
🐛 Fixes
- Fixed score calculation so clean code scores non-zero
- Fixed
.ges/exclusion from audit scanning - Fixed
generatecommand path resolution - Fixed
initinstalling extra policy packs beyond selected frameworks - Fixed version alignment across all packages
- Fixed
.npmignoreto exclude test artifacts from all packages - Removed duplicate control IDs across packs
- Standardized on
config.json(removedconfig.yamlgeneration)
📦 Packages
New Packages
| Package | Description |
|---|---|
@greenarmor/ges-git-hooks |
Git pre-commit hook enforcement |
@greenarmor/ges-web-dashboard |
Local web dashboard server |
@greenarmor/eslint-plugin-ges |
ESLint security rules |
Updated Packages
All 13 existing packages updated with new features, bug fixes, and expanded test coverage.
📊 Final Stats
| Metric | Count |
|---|---|
| Total packages | 16 |
| Policy packs | 10 |
| Compliance controls | 88 |
| CLI commands | 18 |
| Audit scanners | 8 |
| Languages scanned | 7 |
| MCP tools | 17 |
| Unit tests | 656 |
| IaC rules | 15 |
| Auto-fix rule types | 15 |
🚀 Install
npx @greenarmor/ges initOr install globally:
npm install -g @greenarmor/ges
ges init