Skip to content

v0.3.2 (alpha)

Choose a tag to compare

@hedgerow-dev hedgerow-dev released this 03 Oct 11:03
· 5 commits to main since this release
95c095e

Improve Python detection across helpers, imports, and equivalent API layouts.

  • Resolve static XML parser options passed through keyword dictionaries at the
    actual parser call, avoiding findings on unused option dictionaries.
  • Follow request-derived streams through wrappers and repository helpers into
    Unpickler.load(). Preserve distinct deserialization sinks when deduplicating.
  • Infer privilege fields from application guards and follow manually decoded,
    unsigned JWT claims into identity and privilege use.
  • Analyze object reads through repository helpers and returned permission pairs;
    report unresolved imported object reads as authorization coverage signals.
  • Add request.stream and request.get_json() to shared request-source coverage.
  • Exclude resolved standard-library regex searches from vector-store and LDAP
    claims, and keep async log messages out of cross-file SQL sink summaries.

Analysis remains bounded and conservative. Dynamic dispatch, restricted-unpickler
allow-list gadgets, complex authorization protocols, and dynamic XML options
remain coverage limits. Findings remain review leads.