ShipProof v0.5.0
Pre-release
Pre-release
ShipProof v0.5.0 — Deep Production Defense & Multi-Framework Engine
ShipProof v0.5.0 expands framework-aware detection across 30+ ecosystems and adds deep-dive production readiness and scale defense rules.
Highlights
- Multi-Framework Auto-Detection: Automatic framework-tailored scanning for Next.js, Nuxt, SvelteKit, Remix, Astro, React, Vue, Angular, SolidJS, Express, Fastify, NestJS, Koa, Hono, Elysia, Prisma, Drizzle, TypeORM, Mongoose, Supabase, FastAPI, Django, Flask, Starlette, Litestar, Sanic, Go (Gin, Echo, Fiber, Chi), Rust (Actix-web, Axum, Rocket), PHP (Laravel, Symfony), Ruby (Rails, Sinatra), Java/Kotlin (Spring Boot, Quarkus, Micronaut), Docker, Serverless, and GitHub Actions.
- Deep-Dive Production Rules: Added
SP113(PHP unserialize injection),SP114(ReDoS nested quantifiers),SP314(Committed SQLite file),SP315(Go response body close leak),SP316(Outbound HTTP inside database transaction), andSP317(Blocking calls inside Pythonasync def). - Comprehensive Explain Catalog: Detailed why/fix/attack scenario/FP-analysis/testing guidance for all rules via
shipproof explain <rule>. - GitHub Packages Publishing: Official
@kingggg5/shipproofnpm package distribution on GitHub Packages. - Bilingual Documentation: Full English and Thai documentation with responsive full-width visual terminal and capacity flow architecture diagrams.
Compatibility
- Node.js 20 or newer for the CLI.
- Python 3.10 or newer for scan, policy, budget, capacity, and MCP evidence tools.
- Config schema version
1and evidence envelope1.0.