Skip to content

v1.1.1

Choose a tag to compare

@greenarmor greenarmor released this 07 Jun 06:48
· 126 commits to master since this release

Release v1.1.0

🎉 Major Update

This is the biggest GESF release yet. We added 7 new CLI commands, 3 new packages, 3 new policy packs, a VS Code extension, an ESLint plugin, a web dashboard, infrastructure scanning, dependency analysis, multi-language support, and comprehensive documentation with exercises.

By the numbers:

Metric v1.0.1 v1.1.0
Packages 13 16
Policy Packs 7 10
Compliance Controls 67 88
CLI Commands 14 18
Audit Scanners 6 8
Languages Scanned 4 7
MCP Tools 6 17
Unit Tests 120 656

🆕 New Features

Auto-Fix Engine (ges fix)

Automatically fixes security and compliance findings detected by the audit engine.

ges fix                    # Apply all auto-fixable issues
ges fix --dry-run          # Preview without making changes
ges fix --rules CONFIG-001 # Fix only specific rules
ges fix --ci               # Exit non-zero if findings remain

Handles 15 rule types across 7 languages including adding security headers, creating .gitignore entries, generating missing compliance documents, replacing MD5 with SHA-256, extracting hardcoded secrets to environment variables, and adding rate limiting.

Git Hooks (ges hooks)

Pre-commit enforcement that blocks commits containing security findings.

ges hooks install     # Install pre-commit hook
ges hooks uninstall   # Remove the hook

The installed hook runs ges audit --ci before every git commit. If critical findings exist, the commit is blocked. Bypass with git commit --no-verify.

Web Dashboard (ges dashboard)

A local web server displaying real-time compliance posture in your browser.

ges dashboard              # http://localhost:3001
ges dashboard --port 8080  # Custom port

Features a live HTML dashboard with scores, findings, control status, and policy pack coverage. Includes a JSON API (/api/data, /health) for integration with monitoring tools.

Infrastructure-as-Code Scanner

New scanner analyzing Terraform and CloudFormation for 15 infrastructure misconfigurations:

  • S3 buckets with public-read ACLs
  • S3 buckets without encryption or versioning
  • Security groups open to 0.0.0.0/0
  • SSH (port 22), MySQL (3306), PostgreSQL (5432) exposed to the internet
  • RDS instances publicly accessible or without encryption
  • IAM policies with wildcard actions or resources
  • KMS keys without rotation
  • SSL/TLS disabled on resources
  • force_destroy enabled on buckets

Dependency Analysis

Multi-language dependency analysis detecting vulnerabilities, deprecated packages, license issues, and outdated versions:

Ecosystem Scanner
Node.js npm audit
Python pip-audit
Rust cargo audit
Go govulncheck

Identifies deprecated packages with recommended alternatives and flags copyleft licenses (GPL, AGPL).

ESLint Plugin (@greenarmor/eslint-plugin-ges)

Real-time linting rules that catch security issues directly in your editor before you even run ges audit.

Three rules included:

  • no-hardcoded-secrets — Detects passwords, API keys, tokens, private keys
  • no-weak-crypto — Detects MD5, SHA1, DES, ECB mode, disabled TLS
  • no-injection — Detects SQL injection, command injection, eval()
{
  "extends": ["plugin:@greenarmor/ges/recommended"]
}

VS Code Extension (gesf-vscode)

Real-time compliance warnings, inline diagnostics, and one-click commands in VS Code.

  • Red squiggly underlines for security issues as you type
  • Status bar showing live compliance score
  • Command palette: Run Audit, Show Score, Generate Report
  • JSON schema validation for .ges/config.json
  • Auto-activates when .ges/config.json is present

Manual Control Overrides (ges control)

Mark compliance controls as pass, fail, not-applicable, or warning for controls that cannot be detected by source code scanning.

ges control GDPR-ART32-001 pass -r "Implemented with AWS KMS"
ges control GDPR-ART32-003 not-applicable -r "Not using AWS"

Overrides are saved to .ges/control-overrides.json and affect the compliance score.


📋 New Policy Packs

ISO 27001 Information Security (11 controls)

Based on ISO/IEC 27001 Annex A. Covers information security policies (A5), organization (A6), asset management (A8), access control (A9), cryptography (A10), operations security (A12), communications security (A13), system acquisition and development (A14), incident management (A16), business continuity (A17), and compliance (A18).

ISO 27701 Privacy Information Management (11 controls)

Based on ISO/IEC 27701:2019. Extends ISO 27001 with privacy and PII protection covering privacy policies (5.2), roles and responsibilities (5.3), privacy risk assessment (5.4), PII identification and classification (6.2), de-identification and anonymization (6.4), PII segregation (6.5), retention and disposal (6.7), transfer controls (6.9), controller obligations (7.3), processor obligations (7.5), and privacy by design (8.4).

HIPAA Healthcare (10 controls)

Based on the HIPAA Security Rule and Privacy Rule (45 CFR 164). Covers administrative safeguards (164.308), physical safeguards (164.310), access control (164.312a), audit controls (164.312b), integrity controls (164.312c), authentication (164.312d), transmission security (164.312e), business associate contracts (164.314), minimum necessary standard (164.502), and administrative requirements (164.530).


🌍 Multi-Language Scanning

The crypto and code security scanners now detect vulnerabilities across 7 languages:

Crypto Scanner (weak algorithms)

Language Patterns Added
Python hashlib.md5(), hashlib.sha1(), Crypto.Cipher.DES
Go md5.New(), sha1.New(), crypto/des.NewCipher()
Java MessageDigest.getInstance("MD5"), Cipher.getInstance("DES")
Rust md5::compute(), sha1::Sha1, des::new()

Also added: TLS verification disabled detection for Python (verify_mode = ssl.CERT_NONE), Go (InsecureSkipVerify), Java (TrustAllCerts), and Rust (danger_accept_invalid_certs).

Code Security Scanner (injection)

Language Patterns Added
Python f-string SQL injection from request input
Go SQL injection via fmt.Sprintf with request data
Rust Command injection via Command::new().arg(user_input)

📄 PDF Reports

ges report now generates PDF reports with zero external dependencies (no Puppeteer, no wkhtmltopdf). The PDF writer uses the raw PDF spec directly.

ges report --format pdf
ges report --format pdf --output reports/compliance.pdf

⚡ Incremental Audit and .gesignore

Incremental Auditing

For large projects, the audit engine now caches file hashes and only re-scans files that have changed since the last run. This is used internally by git hooks and auto-fix for faster feedback.

.gesignore

Exclude files and directories from the audit using gitignore-style patterns:

# .gesignore
test/fixtures/
vendor/
*.generated.js

🤖 MCP Server: 17 Tools

The MCP AI Compliance Assistant expanded from 6 to 17 tools:

Compliance Assessment:

  • check_compliance — Compliance scores per framework
  • check_project_status — Real-time project status
  • list_missing_controls — Missing controls per framework
  • list_framework_controls — All controls for a framework
  • run_audit — Execute audit
  • generate_compliance_report — Full compliance report
  • generate_audit_report — Audit findings report

Fix and Implement:

  • auto_fix — Automatically fix findings (dry-run supported)
  • implement_control — Generate implementation files for a control
  • apply_control_override — Override control status
  • fix_recommendation — Detailed remediation guidance

Document Generation:

  • generate_retention_policy — Data retention policy
  • generate_incident_response — Incident response plan
  • generate_risk_assessment — Risk assessment template
  • generate_dpa — Data Processing Agreement
  • generate_data_inventory — Data inventory (Article 30)
  • generate_processing_records — Records of processing activities

📚 Documentation

Comprehensive mkdocs documentation with hands-on exercises for every feature:

7 new pages:

  • Auto-Fix guide with exercises
  • Git Hooks guide with exercises
  • Web Dashboard guide with exercises
  • IaC Scanner reference (all 15 rules with Terraform examples)
  • Dependency Analysis reference
  • ESLint Plugin integration guide
  • VS Code Extension integration guide

6 updated pages:

  • Command Reference (4 new commands documented)
  • Audit Scanners (expanded to 8 scanners with multi-language patterns)
  • Policy Packs (expanded to 10 packs with full control tables)
  • Running an Audit (added .gesignore and incremental audit)
  • Generating Reports (added PDF format)
  • Quick Start (added auto-fix, hooks, and dashboard steps)

🐛 Fixes

  • Fixed score calculation so clean code scores non-zero
  • Fixed .ges/ exclusion from audit scanning
  • Fixed generate command path resolution
  • Fixed init installing extra policy packs beyond selected frameworks
  • Fixed version alignment across all packages
  • Fixed .npmignore to exclude test artifacts from all packages
  • Removed duplicate control IDs across packs
  • Standardized on config.json (removed config.yaml generation)

📦 Packages

New Packages

Package Description
@greenarmor/ges-git-hooks Git pre-commit hook enforcement
@greenarmor/ges-web-dashboard Local web dashboard server
@greenarmor/eslint-plugin-ges ESLint security rules

Updated Packages

All 13 existing packages updated with new features, bug fixes, and expanded test coverage.


📊 Final Stats

Metric Count
Total packages 16
Policy packs 10
Compliance controls 88
CLI commands 18
Audit scanners 8
Languages scanned 7
MCP tools 17
Unit tests 656
IaC rules 15
Auto-fix rule types 15

🚀 Install

npx @greenarmor/ges init

Or install globally:

npm install -g @greenarmor/ges
ges init

🔗 Full Changelog

v1.0.1...v1.1.0