Releases: hedgerow-dev/rowan
Release list
Rowan 0.3.4
Calibrate log-forging claims with bounded values and resolved numeric formatting, while preserving findings for character conversion, reassignment and unknown formats. Sensitive logging remains independent.
Separate object authorization guard gaps from confirmed impact. Unknown access requirements are MEDIUM review leads; pure existence observations are LOW. Add qualified model read/write policies: public reads never authorize writes or opaque object/selector escapes. JSON reports the model identity, object use and access requirement.
Implementation passed all 12 CI jobs. The release wheel passes packaging, clean installation, self-test and packaged log-rendering/access-policy contract checks. The prior comparable ModelForge scan retains all 168 claims and 60/82 recall; no improved benchmark score or full third-party source precision-gate rerun is claimed.
ORM column declarations alone still do not prove bounded runtime log values. Access policies describe intent rather than enforcement; dynamic dispatch and complex helpers remain conservative limits.
Rowan 0.3.3
Require Hayward 1.2.5 for calibrated model archive detection: source presence is LOW inventory; concrete execution operations in packaged Python are reported separately. Inspection is bounded and never executes source, with incomplete-coverage warnings retained. Pickle detections remain independent. Clean-wheel validation passes the pinned 200-artifact PyTorch comparison and real pipeline checks. The comparable ModelForge source run retains all 168 prior findings. The full source precision gate was not rerun. Implementation CI passed; some release-PR jobs failed before tests because their PyPI index did not yet list Hayward 1.2.5. Publishing is guarded by an exact-wheel smoke scan.
v0.3.2 (alpha)
Improve Python detection across helpers, imports, and equivalent API layouts.
- Resolve static XML parser options passed through keyword dictionaries at the
actual parser call, avoiding findings on unused option dictionaries. - Follow request-derived streams through wrappers and repository helpers into
Unpickler.load(). Preserve distinct deserialization sinks when deduplicating. - Infer privilege fields from application guards and follow manually decoded,
unsigned JWT claims into identity and privilege use. - Analyze object reads through repository helpers and returned permission pairs;
report unresolved imported object reads as authorization coverage signals. - Add
request.streamandrequest.get_json()to shared request-source coverage. - Exclude resolved standard-library regex searches from vector-store and LDAP
claims, and keep async log messages out of cross-file SQL sink summaries.
Analysis remains bounded and conservative. Dynamic dispatch, restricted-unpickler
allow-list gadgets, complex authorization protocols, and dynamic XML options
remain coverage limits. Findings remain review leads.
Rowan v0.3.1
Documentation and packaging only; scanning behaviour is unchanged.
- Install docs use pipx or
uv tool; a barepip installfails on
Homebrew and other externally managed Pythons. - Getting started explains how to add an LLM for
rowan hunt(Ollama,
DeepSeek or OpenRouter), and the usage guide lists every backend env var. - The GitHub Action has a fuller description for its Marketplace listing,
and its docs show thesecurity-events: writepermission it needs.
Install: pipx install rowan-sast (see the getting started guide).
Rowan v0.3.0 (alpha)
First public alpha of Rowan: a static security scanner for AI applications. It scans source code, model files, dependencies and agent/MCP configuration, says what evidence backs each finding, and reports what it could not analyse.
Install
pipx install rowan-sast # or: uv tool install rowan-sast (macOS: brew install pipx first)
rowan install-engine # Opengrep v1.29.0, checked against a built-in SHA-256
rowan scan /path/to/your-projectA bare pip install is refused by Homebrew Python; use pipx, uv, or a virtual environment.
Highlights
- Opengrep dataflow within each file, plus cross-file analysis for Python and JS/TS (limited for Go) and stored-then-read flows through ORMs and vector stores.
- AI and agent rules for Python, JS/TS, Java and Go: agent tools, LLM output handling, MCP servers, model loading, guardrails.
- Model-file scanning via Hayward 1.2.4.
- Text, JSON, HTML and SARIF reports; CI exit codes, baselines, a GitHub Action and an MCP server for coding agents.
Measured (details and caveats in the linked write-ups)
- RealVuln, 63 Python apps: F2 33.0 against SonarQube 14.7 and Semgrep CE 7.5 on the same repositories; precision is below Snyk's.
- Model files on quickset: 26/26 malicious files detected, 0/225 false positives, every file read.
Alpha: treat findings as leads to check, not confirmed bugs. A clean report does not prove a project is secure. See capabilities and known limits.
The GitHub Action example in the docs needs permissions: security-events: write to upload SARIF; the usage guide on main has the corrected example.