Skip to content

v0.0.22

Choose a tag to compare

@aviggiano aviggiano released this 24 Aug 12:03
87e1682

v0.0.22 brings threat-aware, dynamically planned audits to Ultrafuzz and strengthens the authenticated runtime and cloud lifecycle that keeps long-running campaigns recoverable.

  • Threat-driven audit planning. The default workflow can build a threat model, combine it with a pinned vulnerability database, and expand deterministic goal lanes with attributable findings.
  • Authenticated controller recovery. Operators can refresh controller-only code for an existing compatible run while preserving sealed inputs, durable identities, and fail-closed recovery checks.
  • More dependable cloud execution. Modal handoffs, restored workspaces, runtime-rendered prompts, dependency closures, schema bundles, and retry state remain bound to authenticated release evidence.

New features

  • [runtime] [topology] Adds threat-model and goal-planning workflows, dynamic topology fanout, pinned vulnerability-database inputs, opt-in Pi and OpenCode adapters, expanded artifact provenance, a structural threat-model benchmark lane, and source-release package validation. Thanks @aviggiano! (#744)
  • [runtime] [cli] Adds resume --refresh-controller for compatible controller-only fixes, rebuilding stock controller files from installed packages while authenticating sealed run semantics and retaining the existing run and workflow identities. Thanks @aviggiano! (#726)

Improvements

  • [workflows] Keeps the benchmark-history aggregation gate on main pushes and manual release validation while skipping it on pull requests where its prerequisites do not run. Thanks @aviggiano! (#773)
  • [docs] Refreshes the README's product description, threat-hunting guidance, provider-neutral introduction, VPS recommendation, and getting-started prompt. Thanks @aviggiano! (#790)

Bug fixes

  • [runtime] [modal] Makes authenticated controller refresh durable across cloud continuations, interrupted snapshot publication, dynamic base-task reconstruction, sealed module and schema resolution, missing-run recovery, portable snapshot paths, retry recreation, and trusted CLI rotation. Thanks @aviggiano! (#757, #766, #777, #779, #781, #783, #785, #787, #789)
  • [modal] [runtime] Preserves canonical cloud handoff and publication identity by deduplicating identical authenticated inputs, repairing controller-local Git metadata, limiting static reconstruction to direct dependencies, retaining immutable dependency evidence, and admitting only authenticated runtime-rendered prompts under the run root. Thanks @aviggiano! (#759, #771, #774, #775, #776)

Full changelog: v0.0.21...v0.0.22