v1.3.0
Noir v1.3.0 adds first-class support for the HTTP QUERY method (RFC 10008), 11 new framework analyzers, and scan-integrity reporting, on top of a large internal consolidation and bug sweep.
Added
- HTTP QUERY method (RFC 10008): end-to-end support from the core endpoint model through detection in ~24 frameworks (Express, Fastify, Hono, Node
http/https, NestJS, Flask,aiohttp, Rails, Laravel, Phoenix/Plug, Echo, Fiber, Gonet/http, axum, Ktor, http4k, Micronaut, Vert.x, JAX-RS/Quarkus/Dropwizard, ASP.NET Core, Kemal), plus OAS3 serialization and HTML report rendering. - New framework analyzers: Oak (Deno), Feathers.js, Sails.js, LoopBack 4, CherryPy, Masonite, Padrino, Phalcon, Helidon, ServiceStack, and Kratos.
- Scan-integrity reporting: failed analyzers and skipped files are now reported instead of silently dropped, with
--strictto exit non-zero when any occur. - Recovered iOS deep-link routes that config-only scanning missed.
Changed
- Consolidated 44 duplicated top-level splitters into a shared
Noir::TopLevelSplit, derived the analyzer/detector/tagger/format/tech registries from their classes, and split the largest monolithic extractors by concern.
Performance
- Detector and tagger sweeps now run one PCRE2 pass per marker instead of N substring walks, read through the content cache, and split each file into lines once.
- Go files are parsed once for their declaration tables; JS/TS route pre-filters collapse into precompiled unions; already-valid UTF-8 files skip the iconv decode; failed parses arememoized so N analyzers don't each pay the timeout.
Fixed
- Multi-agent bug sweep across analyzer, detector, scan, output, and CLI layers: a single line of source (fat literals, unterminated strings, column-0 comments, escaped quotes) no longer erases a file's routes; scans no longer hang or lose coverage silently; OpenAPI documents are valid and stop dropping parameters; unprotected routes are no longer tagged authenticated.
- Security fixes: ACP tool-permission auto-approval, AI agent symlink escape from the scan base,
--probe-headersecret leakage to cross-host targets, and world-readable AI cache. - Deliver/probe fixes for proxy bypass, credential forwarding, and missing timeouts.
- Bounded AST walk depth and parse time so one file can't kill a scan.
New Contributors
- @ccyyy1023 made their first contribution in #2454
- @Vam-si-krish made their first contribution in #2453
- @tomatotomata made their first contribution in #2456
- @Guflly made their first contribution in #2479
Full Changelog: v1.2.1...v1.3.0