Skip to content

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 10 Jul 14:28
· 5 commits to main since this release
  • Added: an often-forbidden tag for clients the server keeps refusing (403) (#123)
  • Added: cache-busting version token on inspect-data URLs (#119)
  • Added: detect www-Referer browser spoofing as spoofed_browser (#96) (#101)
  • Changed: a browser that never caches at volume is spoofed, not automation (#130)
  • Changed: all-cold-at-volume is a spoofed_browser tell (#103) (#129)
  • Changed: a sustained 403 rate corroborates vuln_scanner (#128)
  • Changed: a probing client is a vuln_scanner, even under a browser costume (#122)
  • Changed: measure request cadence over navigations, not asset bursts (#121)
  • Changed: asset co-load counts only referer-linked page cascades (#109) (#116)
  • Fixed: "polls a few URLs repeatedly" counts targets, not query-stripped paths (#126)
  • Fixed: lead the inspect rationale with the chosen classification (#125)
  • Fixed: count query-string enumeration in the 404-storm signal (#124)
  • Fixed: feed-polling spoofers no longer excused as feed readers; add polls-feeds tag (#120)
  • Fixed: inspect trace nests an asset's own sub-resources (multi-level cascades) (#118)
  • Fixed: require enough HTML pages before co-load scores a browser (#115)