Skip to content

v0.1.0 — AutoCyberGraph MVP

Latest

Choose a tag to compare

@nirjharb nirjharb released this 28 Sep 20:21
· 10 commits to main since this release

AutoCyberGraph — Release Notes

v0.1.0 — MVP (2026-09-28)

Connect Automotive Cybersecurity Risk to Reality.

What was built

AutoCyberGraph — an open-source automotive cybersecurity digital thread /
evidence graph platform. Full-stack monorepo: React + Vite frontend, FastAPI +
SQLAlchemy backend, SQLite/PostgreSQL, JWT + RBAC, Docker + CI, documentation
and a realistic demo dataset.

Major features

  • Traceability spine — Vehicle → ECU → Software → Asset → Threat → TARA →
    Goal → Requirement → Control → AUTOSAR Mechanism → Test → Evidence → Release
    → standards mappings (18 entity types, typed graph edges)
  • Change Impact Engine (core differentiator) — graph traversal from any
    change; every affected artifact carries the relationship path that made it
    affected; impact levels + recommended actions
  • Cybersecurity Release Gate — 8 deterministic checks → PASS / REVIEW /
    HOLD with reasons (no vanity scores)
  • TARA workflow — configurable risk matrix (documented as an application
    implementation, not a certification methodology)
  • Requirement traceability — checklist with missing-link detection
  • Evidence graph — interactive Cytoscape visualization with click-through
  • SBOM & vulnerability engine — CycloneDX + SPDX import, CVE → Component →
    ECU → Vehicle traceability
  • Standards mapping layers — ISO/SAE 21434, UNECE R155, R156, NIST SP 800-53
    (representative controls), AUTOSAR security mechanism catalog
  • Supplier portal — submissions + OEM review workflow with org-scoped
    authorization
  • CyberAdvisor — DB-grounded Q&A; replies "Insufficient evidence in the
    project database."
    when the data cannot answer; never invents compliance
    conclusions
  • Security — bcrypt + JWT, 7-role RBAC, audit logging, rate limiting,
    security headers, threat model (docs/security.md)
  • Demo dataset — Demo EV Platform (5 ECUs, 12 assets, 10 threats, 12 TARA,
    16 requirements, 12 tests, 4 CVEs, 3 releases) including the flagship
    Gateway ECU crypto library v2.4 → v2.5 change scenario

Testing

  • 34 backend tests (auth, RBAC, risk calculation, traceability, impact engine,
    vulnerability mapping, release gate, SBOM, CyberAdvisor, security baselines)
    including the flagship Change → Impact → Release Gate integration test
  • 8 frontend tests (login, dashboard, traceability display, change-impact
    display, release-gate display)
  • CI: lint + tests + build + dependency audit + Docker build (Python 3.11–3.13)

Demo instructions

bash scripts/dev.sh     # http://localhost:8000
# sign in: engineer@autocybergraph.io / ChangeMe123!

Follow the 3-minute demo flow in the README.

Known limitations

  • Graph traversal computed in the service layer (Neo4j adapter is a roadmap
    item; the protocol is already defined)
  • SPDX parsing is document/package level (CycloneDX is the robust path)
  • Evidence stores file references, not blobs (storage backend is pluggable)
  • CyberAdvisor MVP is a deterministic query engine (LLM adapter interface exists)
  • Refresh-token rotation and multi-tenant row isolation are roadmap items
  • Risk matrix is an application method — configurable, not normative

Roadmap (v0.2.0)

Neo4j backend · NIST OSCAL catalog import · object-storage evidence backends ·
refresh-token rotation · LLM CyberAdvisor adapter · richer R156 update workflow.


Disclaimer: AutoCyberGraph is an engineering and evidence-management
platform. It does not provide legal, regulatory, certification, or compliance
advice. ISO/SAE 21434, UNECE R155, UNECE R156, NIST SP 800-53 and AUTOSAR
security are represented as reference/mapping concepts only.