Skip to content

APSA v1.0.4

Choose a tag to compare

@github-actions github-actions released this 06 Oct 12:26
· 37 commits to main since this release

APSA 1.0.4 hardens local audit boundaries and preserves complete advisory evidence.

  • Isolate parser and background worker imports from the current directory and PYTHONPATH.
  • Keep MCP-authorized file paths bound through sidecar, policy, scenario and source reads; carry validated scenarios into execution.
  • Mark truncated source enumeration as partial coverage, including skipped entries.
  • Create the audit database privately and repair WAL/SHM permissions before opening SQLite.
  • Reject malformed KEV vendor/product fields without replacing cached intelligence.
  • Apply the configured intelligence freshness window independently of the health display threshold.
  • Preserve every CVE component, release, patch and snapshot branch in advisories and affected OS findings, with stable finding IDs and baselines.

Install examples and packaged skills are updated. The three CLI aliases and existing audit data remain compatible; customized skills are preserved.

Validation: 590 tests, Ruff, Pyright and the existing 31-case corpus passed. The final commit passed the four CI combinations on Ubuntu 24.04/macOS 15 and CPython 3.11.15/3.12.13. Wheel/sdist builds were repeated and installed in a clean environment for source/APK, MCP and skill checks. These are bounded regression checks; no new device or commercial-app detection-rate validation was performed.

Install or replace an existing tool installation:

uv tool install --python 3.12 --force apsa==1.0.4
apsa --version
apsa doctor --json

The wheel and source distribution are published on PyPI. The downloads include checksums, the build manifest and the verified dependency/attribution bundle. The manifest's published: false describes the local build stage; the publishing workflow records the upload result.