Skip to content

ShipProof v0.5.0

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 16 Aug 11:57
· 63 commits to main since this release

ShipProof v0.5.0 — Deep Production Defense & Multi-Framework Engine

ShipProof v0.5.0 expands framework-aware detection across 30+ ecosystems and adds deep-dive production readiness and scale defense rules.

Highlights

  • Multi-Framework Auto-Detection: Automatic framework-tailored scanning for Next.js, Nuxt, SvelteKit, Remix, Astro, React, Vue, Angular, SolidJS, Express, Fastify, NestJS, Koa, Hono, Elysia, Prisma, Drizzle, TypeORM, Mongoose, Supabase, FastAPI, Django, Flask, Starlette, Litestar, Sanic, Go (Gin, Echo, Fiber, Chi), Rust (Actix-web, Axum, Rocket), PHP (Laravel, Symfony), Ruby (Rails, Sinatra), Java/Kotlin (Spring Boot, Quarkus, Micronaut), Docker, Serverless, and GitHub Actions.
  • Deep-Dive Production Rules: Added SP113 (PHP unserialize injection), SP114 (ReDoS nested quantifiers), SP314 (Committed SQLite file), SP315 (Go response body close leak), SP316 (Outbound HTTP inside database transaction), and SP317 (Blocking calls inside Python async def).
  • Comprehensive Explain Catalog: Detailed why/fix/attack scenario/FP-analysis/testing guidance for all rules via shipproof explain <rule>.
  • GitHub Packages Publishing: Official @kingggg5/shipproof npm package distribution on GitHub Packages.
  • Bilingual Documentation: Full English and Thai documentation with responsive full-width visual terminal and capacity flow architecture diagrams.

Compatibility

  • Node.js 20 or newer for the CLI.
  • Python 3.10 or newer for scan, policy, budget, capacity, and MCP evidence tools.
  • Config schema version 1 and evidence envelope 1.0.