Skip to content

Releases: parousia8888/web-app-security-skill

v0.7.2

Choose a tag to compare

@github-actions github-actions released this 25 Aug 11:54
v0.7.2

v0.7.2 release evidence

Status: published and promoted. The signed tag, GitHub Release, npm package, provenance, immutable
verified-installer/bootstrap chain and signed v1 alias are publicly retrievable. Immutable and
post-promotion Action consumers passed.

Outcome

Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.

v0.7.2 closes three reproduced false-clean or destructive paths and strengthens independently
executable evidence contracts without adding a detector family or framework claim.

  • Demo reruns may clean only a marker-owned output directory and fixed generated children.
    Pre-existing unowned directories, symlinks and protected paths are refused.
  • Technical evidence redaction recognizes normalized singular/plural credential containers and
    bounded high-confidence token formats across every report-bundle renderer. It remains leak
    prevention for known output shapes, not a general secret scanner.
  • Direct CommonJS Express routers and exact local CommonJS mounts are inventoried. A structurally
    observed imported local registration function that cannot be resolved produces
    express_registration_function_unresolved, partial coverage, unknown evidence and exit 3.
    Exit 3 means the tool refused a clean result because evidence is incomplete; it is not a
    vulnerability count.
  • Thirteen shipped JSON Schemas compile offline under Ajv Draft 2020-12 and share a curated
    agreement corpus with handwritten validators.
  • The fixed-commit v0.7.0 ordinary-project access review derives all aggregate totals from complete,
    digest-bound project records and has an explicit network-only refresh path.
  • Release documentation separates repository-local signer consistency, GitHub verification,
    release-asset attestation, npm OIDC provenance and checksum/SBOM integrity.

Stable scope remains 25 built-in risk rules, three evidence-integrity rules, 16 opt-in external
adapter risk rules and the existing bounded Express, NestJS and Next.js App Router inventory.

Regression evidence

  • test/demo-output-safety.test.mjs proves an unowned sentinel and owner-created extra child survive
    the demo path while a marked rerun succeeds.
  • test/evidence-writer.test.mjs asserts a unique credential sentinel is absent from JSON,
    Markdown, HTML, SARIF, JUnit and additional bundle artifacts while allowed evidence remains.
  • Express extractor and CLI integration fixtures cover direct CommonJS routers, exact mounts,
    unresolved imported registration functions and a valid route-free worker neighbour.
  • scripts/check-json-schema-contracts.mjs compiles every schema offline and checks Ajv/manual
    agreement for curated positive and negative documents.
  • test/v070-access-review-provenance.test.mjs rejects aggregate drift and project-record digest
    tampering while preserving deterministic semantic route hashes.
  • test/release-trust-boundaries.test.mjs rejects stale verification examples and language that
    conflates repository-local signer consistency with GitHub account ownership.

Each silently reversible P0 branch has a machine assertion that was confirmed to fail when the old
behavior was planted. Focused Phase 1-7 checks passed before candidate freeze.

Published verification

The bounded candidate tree passed:

npm run check
npm pack --dry-run --json
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
git diff --check
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.7.2

npm run check completed all generated-contract checks, local Node tests and the Bash 3.2 smoke
suite. Skill validation returned Skill is valid!. npm pack --dry-run --json reported 183 files,
552,526 packed bytes and 2,218,387 unpacked bytes. Real external-adapter tests remain opt-in and
were not downloaded for the local gate.

The first candidate-gate attempt exposed an integration regression: three repository generators
passed a pre-existing mkdtemp root to the newly ownership-aware demo. The generators now use a
new child output path; their existing deterministic --check gates caught the planted old behavior
and passed after the correction.

One final-tree full local gate, one package inspection and bounded channel consumers are enough
unless a channel-specific failure appears.

Public release facts

  • The SSH-signed annotated v0.7.2 tag object
    ecfa779d317c09d5f0948df880762a914d6f4abc peels to source commit
    30402c866b86d78b66d0d4b495fee40ff6a6f160. Final-tree CI run
    32844389181
    and CodeQL run
    32844389183
    passed before tagging. GitHub reports the tag signature as verified: true, reason: valid, and
    repository-local .github/release-signers verification also passes.
  • GitHub Release workflow
    32844662253
    published the reproducible source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-25.
    Tag CI run
    32844662312
    also passed. Public SHA-256 values are
    340413987722874ac2b2cac58d09f45e44b7f541dc06045e191a54654bc125fb (archive),
    0e7702487a71ea601385be1adb10cb6c8aa75775aa3c63146c228fb82f23fc5f (SBOM),
    642f59261ce225ca06d836d95c2046e29654447af18aee27cc352d5b49615207 (manifest) and
    6300c2822286bfc9913ee694f5daa629572a9a1367029684f5d54db931969552
    (SHA256SUMS). Fresh downloads passed checksums, the 473-entry manifest, archive lifecycle,
    GitHub asset-digest comparison and GitHub release-asset attestation.
  • npm workflow
    32845017547
    published web-app-security-skill@0.7.2 at 2026-08-25T11:58:03.569Z through GitHub OIDC trusted
    publishing. npm records source 30402c866b86d78b66d0d4b495fee40ff6a6f160, shasum
    4b57df8c5c1f60317ffbb1dc54302cd86884eb88, integrity
    sha512-KftiDW+ABghvOlH38KU9GumhtL8NC+8Xkw6PmL/sptKvS/9xOsRPNjj6CJBMETwutADXIe09ea9iXAgFXfwRdQ==
    and SLSA provenance.
    Its 183 files matched corresponding files in the signed source byte for byte.
  • The four observed release digests are recorded in the verifier trust map, whose default is
    0.7.2. The stable Action remains recorded at v0.7.1 until guarded v1 promotion and its
    post-promotion consumer pass.
  • Public-state commit 87326f11c0aab3901ac5cb0783d9452e607e83c5 passed CI
    32845505985
    and CodeQL
    32845505857.
    Its scripts/install-verified.mjs SHA-256 is
    662b7de3d596bb6faf8fac4bf69f325f44c1152c99cbbea5fc25184863b1c6d5.
  • scripts/bootstrap-install.sh, the release contract and English/Chinese verified-installation
    paths now pin that immutable verifier and explicit v0.7.2 assets. The README-facing bootstrap
    source commit 3f42fb70f99f6ccb3c8e8449b2c06749c3b53148 passed CI
    32845795654
    and CodeQL
    32845795620.
    Its scripts/bootstrap-install.sh SHA-256 is
    193ece72d2c7d2c4220a6164a4bb280853ffca1e8de5217535fe95010c146e8a.
  • The README bootstrap and immutable Action examples now select those public v0.7.2 identities.
    Publication commit 68cb7fb24e40e4bbd75b13e469a7f57e4412714f passed CI
    32846176471
    and CodeQL
    32846176455.
  • A clean-room public bootstrap downloaded the script from immutable commit
    3f42fb70f99f6ccb3c8e8449b2c06749c3b53148, matched SHA-256
    193ece72d2c7d2c4220a6164a4bb280853ffca1e8de5217535fe95010c146e8a, installed all three
    surfaces into an isolated temporary home and returned Web App Security Skill 0.7.2. It
    verified source commit 30402c866b86d78b66d0d4b495fee40ff6a6f160, archive, manifest,
    checksums and SBOM. Because the isolated home could not access the macOS keyring, the bootstrap
    accurately reported its optional GitHub attestation check as not run; a separate authenticated
    gh attestation verify passed the same public archive with SHA-256
    340413987722874ac2b2cac58d09f45e44b7f541dc06045e191a54654bc125fb.
  • Pre-promotion Action consumer
    32846524348
    passed. Its immutable job consumed full commit
    30402c866b86d78b66d0d4b495fee40ff6a6f160 and verified route-security v2 control separation;
    its stable job independently proved that the existing v0.7.1 @v1 alias still passed passive
    crawl and authorization-refusal checks before movement.
  • Pre-promotion evidence commit cfdad9bcd49396071b1e19510d7471d625e6dcc3 passed CI
    32846724386
    and CodeQL
    32846724421.
  • The SSH-signed annotated v1 tag moved with an exact guarded lease from tag object
    b0df7d0c6bd2a9a596d591bb63cff6e6bc8471ff to
    758036ee84ad2bc2f31a8ba08969acd2a6b87de6, which peels to
    30402c866b86d78b66d0d4b495fee40ff6a6f160. GitHub reports verified: true and
    reason: valid; repository-local .github/release-signers verification passed with ED25519
    fingerprint SHA256:DmZYVL1dLhUmgaJnfZKpZIexgzMv5jk9+YCoBT3zRIg.
  • Post-promotion public @v1 consumer
    [`...
Read more

v0.7.1

Choose a tag to compare

@github-actions github-actions released this 24 Aug 16:31
v0.7.1

v0.7.1 release evidence

Status: published and promoted. The signed tag, GitHub Release, npm package, provenance, immutable
verified-installer/bootstrap chain and signed v1 alias are publicly retrievable. Immutable and
post-promotion Action consumers passed.

Outcome

Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.

v0.7.1 closes execution-boundary gaps found by external review without expanding detector or
framework scope. Crawl requests now use one bounded destination/DNS/redirect/size/timeout policy.
Default HIGH gating includes actionable suspected source leads without promoting their evidence
state. Evidence sanitization propagates through nested credential containers. JavaScript,
TypeScript and Python analysis has deterministic per-file and run-wide budgets that fail closed,
and route coverage reflects source inputs stopped by those budgets.

The release also replaces dynamic robots wildcard regexes with a literal matcher and makes the
installed payload include the Claude plugin metadata, bundled rules and v0.7 review evidence. The
stable inventory remains 25 built-in risk rules, three evidence-integrity rules and 16 opt-in
external-adapter risk rules.

Regression evidence

  • 60427ac binds crawl HTTP requests to the tested network boundary.
  • 1affcc8 adds actionable-gate, recursive-redaction, installer, robots and source-budget fixes.
  • The default-gate regression proves a suspected HIGH can block without becoming confirmed.
  • Redaction regressions exercise nested authorization/cookie/token wrappers, private paths and all
    report formats while preserving documented authorization evidence models.
  • Hostile repeated-wildcard and repeated-source-token fixtures exercise bounded work and explicit
    incomplete evidence.
  • A planted rollback of the source operation checks makes the hostile-source regression fail,
    proving that the budget test is an effective gate.

Published verification

The bounded candidate tree passed:

npm run check
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
npm pack --dry-run --json
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.7.1

npm run check completed syntax/generated-contract checks, every local Node test and the Bash 3.2
smoke suite. Skill validation returned Skill is valid!. npm pack --dry-run --json reported 179
files, 538,302 packed bytes and 2,173,845 unpacked bytes. Real external-adapter tests remain
deliberately opt-in and were not downloaded or run by the local gate.

One final-tree full local gate, one package inspection and bounded channel consumers are enough
unless a channel-specific failure appears.

Public release facts

  • The SSH-signed annotated v0.7.1 tag object
    0e0b150162379105227faa81f8489add5b05a04a peels to source commit
    2b746b168d767c9b2225a273474e561650b2b6f8. Final-tree CI run
    32750844326
    and CodeQL run
    32750844327
    passed before tagging.
  • GitHub Release workflow
    32751168775
    published the reproducible source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-25
    Japan time. Public SHA-256 values are
    8df18745da238a418539d153d68c4fc395cd86c2e9131abbbd2fb9bf0cdfe381 (archive),
    a97313fbf775f08cddef608b15743d26ea1255e44b192a184a677d8cc0f38725 (SBOM),
    59ef38bbb6d00873f2c57211db36dd3c2a128c80295c024ff988d2fee67f40a0 (manifest) and
    4fd672781c26a9f39c67a0c3c9576e83d25a6032ba01b1ad6dbd8f2a6f8bafde
    (SHA256SUMS). Fresh downloads passed checksums, manifest validation, archive lifecycle checks,
    public-asset digest comparison and GitHub provenance verification.
  • npm workflow
    32751396849
    published web-app-security-skill@0.7.1 at 2026-08-24T16:32:26.236Z through GitHub OIDC trusted
    publishing. npm records shasum 3f062a645458618597219a3c87d3287011ea91bd, integrity
    sha512-miQTWXA5cFtPbRmfi2STyiqLago3Z8bjfl9oFCPt8ENw4w3tH4X4ZMw0cJDvqpKiakGOmGQWNhS0avu0/+JG6A==
    and SLSA provenance.
    Its 179 files matched corresponding files in the signed source archive byte for byte.
  • The four observed release digests are recorded in the verifier trust map, whose default is
    0.7.1.
  • Public-state commit 7f84917f5014b4f0f2eb532b7007394ad3123615 passed CI
    32751921925
    and CodeQL
    32751921825.
    Its scripts/install-verified.mjs SHA-256 is
    38d40a706fc4e0c377657d5b49a4a8980811a2518104ac95c762278b87d7b804.
  • scripts/bootstrap-install.sh, the release contract and English/Chinese verified-installation
    paths now pin that immutable verifier and explicit v0.7.1 assets. The README-facing bootstrap
    source commit 25a37e476720ad8ef221e38c0e2842abf928a1db passed CI
    32752244215
    and CodeQL
    32752244217.
    Its scripts/bootstrap-install.sh SHA-256 is
    ce37908a73bd9ffd004ec3c0a4d36dc88e3baa6187bd17df816a454a940bfe63.
  • The README bootstrap and immutable Action examples now select those public v0.7.1 identities.
    Publication commit 4977ae24dfb145d2c24db102aa779875bf76f29d passed CI
    32752898885
    and CodeQL
    32752898896.
  • A clean-room public bootstrap downloaded the script from immutable commit
    25a37e476720ad8ef221e38c0e2842abf928a1db, matched SHA-256
    ce37908a73bd9ffd004ec3c0a4d36dc88e3baa6187bd17df816a454a940bfe63, installed into an isolated
    temporary home and returned Web App Security Skill 0.7.1. It verified source commit
    2b746b168d767c9b2225a273474e561650b2b6f8, archive, manifest, checksums, SBOM and GitHub
    attestation.
  • Immutable Action consumer
    32753098586
    passed against full commit 2b746b168d767c9b2225a273474e561650b2b6f8. Its NestJS fixture
    verified one-time application controls, separate authentication/authorization,
    no_route_scoped_control_observed review state and no fabricated confirmed vulnerability.
  • The SSH-signed annotated v1 tag moved with an exact guarded lease from tag object
    b04630846eeb621fd40397f78b28ad92c4c4e6bc to
    b0df7d0c6bd2a9a596d591bb63cff6e6bc8471ff, which peels to
    2b746b168d767c9b2225a273474e561650b2b6f8. GitHub and .github/release-signers verify its
    ED25519 signature with fingerprint
    SHA256:DmZYVL1dLhUmgaJnfZKpZIexgzMv5jk9+YCoBT3zRIg.
  • Post-promotion public @v1 consumer
    32753263317
    passed passive crawl, authorization-refusal and immutable route-security checks.

Artifact identity, consumer success and provenance do not prove every detector conclusion correct
or an audited project secure. v1 is intentionally movable; consumers requiring an immutable
workflow must use the full source commit.

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 24 Aug 01:47
v0.7.0

v0.7.0 release evidence

Status: published and promoted. The signed tag, GitHub Release, npm package, provenance, immutable
verified-installer/bootstrap chain and signed v1 alias are publicly retrievable. Immutable and
post-promotion Action consumers passed.

Outcome

Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.

v0.7.0 corrects route-control aggregation and extends route-security into a bounded
access-control-chain review. Application controls are listed once; authentication, route
authorization and unclassified route controls are separate; and routes with no observed
route-scoped control form a human-review queue without becoming vulnerability findings.

For supported syntax, the analyzer records identity evidence and a caller-selected object reaching
a Prisma, Drizzle or experimental Supabase operation in the same entry or through one exact local
call. It stops before a second local call. Next.js Server Actions are represented separately from
HTTP routes. Missing visible controls or query constraints do not prove BOLA/IDOR, and every
Supabase chain retains an external RLS-policy dependency.

Evidence sets

  • v0.7.0 access-control review: four fixed public
    commits, 173 HTTP routes, 23 Server Actions and 32 manually reviewed entries. All 12 observed
    ordinary-project chains are partial and zero are completed.
  • v0.7.0 access-control regressions:
    four minimized correctness failures covering application-guard aggregation, chain fingerprinting,
    Next monorepo roots and exact tsconfig alias resolution.
  • v0.6.0 rule-contract conformance: the
    unchanged 25 built-in risk and three evidence-integrity source-rule contracts.
  • Known limitations: exact route, Server Action, identity,
    data-operation, module-resolution, one-hop and external-policy boundaries.

The ordinary-project review is purposive source-only evidence. It is not representative production
precision/recall, whole-program data flow, runtime reachability, exploitability, DAST or proof that
an audited project is secure.

Published verification

The bounded local gate included:

npm run check
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
npm pack --dry-run --json
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.7.0

One final-tree full local gate, one package inspection and bounded clean-room consumers are enough
unless a channel-specific failure appears.

Public release facts

  • The SSH-signed annotated v0.7.0 tag object
    b0de94c044082d951c12d95950360d4250e12d31 peels to source commit
    bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a. Final-tree CI run
    32680695072
    and CodeQL run
    32680695073
    passed before tagging.
  • GitHub Release workflow
    32680851023
    published the reproducible source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-24.
    Public SHA-256 values are c5fa68b48e3c4a00ccc9c55fbd7a375eb1adddf9e7e8b7398f5e14a93974aa78
    (archive), 3e0c80aee8a093a3d04fa950d6e78a604c81958a4b7f984ab78cbd97276f0bf4
    (SBOM), f707c4cceafc4864917fd47de525c522117b53c9a5724eb6a4e80e57cbbe5e37
    (manifest) and f40a58952a221f677c9bc76b923b0f4ebd3a3dfe34b16bfb8ced885cb46aaa47
    (SHA256SUMS). Fresh downloads passed checksums, manifest validation, archive lifecycle checks and
    GitHub provenance verification for all four assets.
  • npm workflow
    32680989366
    published web-app-security-skill@0.7.0 at 2026-08-24T01:49:15.577Z through GitHub OIDC
    trusted publishing. npm records shasum a46d7ab62f577dfc21998ba3350d74c7d256d86d, integrity
    sha512-GhVvvQIDb2ahF1aiRzKD2ilszykYY8X2b6i3RAlJ0TJu7o6KjhVK09edqlAG8IRRVD/MU3Z5Q5+8m4ZMw6HFpw==
    and SLSA provenance.
    Its 177 files matched the corresponding signed source-archive files byte for byte.
  • A clean-room exact-version npx --yes web-app-security-skill@0.7.0 demo run produced the expected
    suspected HIGH lead, review proposal, fixed security retest and passing functional retest.
  • Public-state commit b3e77a87cc5ee16195c0965012217416ee3a935d passed CI
    32681514684
    and CodeQL
    32681514679.
    Its scripts/install-verified.mjs SHA-256 is
    4e3c6ce6c8c3ec0cfa7972edbc85b93885bae64cb714a87c926e81fc49410422.
  • Verifier-pin commit cb36196fb438fb0ad0e5b5a6a27043bf48ffb018 passed CI
    32681707779
    and CodeQL
    32681707703.
    Its scripts/bootstrap-install.sh SHA-256 is
    544d0ded89ed98467c275c838f033148d944668b0b56842d849ff8ae4abc63d2.
  • A clean-room public bootstrap downloaded that exact script, verified its SHA-256, installed into
    an isolated temporary home and returned Web App Security Skill 0.7.0. It verified source commit
    bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a, archive, manifest, checksums and SBOM. Optional GitHub
    attestation was explicitly reported as not run because the isolated home had no authenticated
    gh session; checksum and manifest verification still ran.
  • Immutable Action consumer
    32682001909
    passed against full commit bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a. Its NestJS fixture
    confirmed that the application rate-limit guard is listed once, authentication and authorization
    remain separate, an unprotected state-changing object route is review evidence, and no confirmed
    vulnerability is fabricated.
  • The SSH-signed annotated v1 tag object
    b04630846eeb621fd40397f78b28ad92c4c4e6bc was moved with a guarded lease and peels to
    bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a. Its signature verifies against
    .github/release-signers with fingerprint
    SHA256:DmZYVL1dLhUmgaJnfZKpZIexgzMv5jk9+YCoBT3zRIg.
  • Post-promotion public @v1 consumer
    32682179514
    passed the passive crawl, authorization-refusal and immutable NestJS route-security v2 checks.

Artifact identity, consumer success and provenance do not prove every detector conclusion correct
or an audited project secure. v1 is intentionally movable; consumers requiring an immutable
workflow must use the full source commit.

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 23 Aug 19:15
v0.6.0

v0.6.0 release evidence

Status: published and promoted. The signed tag, GitHub Release, npm package/provenance, immutable
verified-installer/bootstrap chain, immutable Action consumer and signed v1 consumer are publicly
retrievable and verified.

Outcome

Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.

v0.6.0 adds a framework-aware route-security review beside the existing finding report. It extracts
bounded Express, NestJS and Next.js App Router syntax into separate JSON and Markdown artifacts,
maps supported authentication and route-authorization signals, keeps object authorization distinct,
and orders human review work without turning review priority into vulnerability severity.

The release does not infer that a missing visible control is a confirmed vulnerability. Custom or
unresolved controls remain review candidates, and the direct Prisma object-authorization lead stays
experimental because the bounded ordinary-project review produced no ordinary-project matches.

Evidence sets

  • v0.6.0 route review: 57 manually reviewed routes at three
    immutable public commits, with 51 detected routes and six explicit misses.
  • v0.6.0 route regressions: six minimized
    route-extraction and classification failures retained as deterministic regressions.
  • v0.6.0 rule-contract conformance: 25
    built-in risk and three evidence-integrity planted positive/negative/state contracts.
  • Known limitations: exact supported syntax, parser, incremental,
    evidence-state and object-authorization boundaries.

The route review is purposive source-only evidence, and the planted suite is author-maintained rule
contract evidence. Neither is a representative production-vulnerability benchmark or a claim of
whole-program data flow, reachability, exploitability, precision, recall, DAST or project safety.

Published verification

The bounded local gate included:

npm run check
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
npm pack --dry-run --json
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.6.0

Package and verified-Skill clean-room runs produced equivalent route artifacts on the same owned
fixture before publication.

Public release facts

  • The SSH-signed v0.6.0 tag peels to source commit
    7521e0699eefe26d23a7972fbee6fb37b46fdfe2. Candidate CI run
    32660512207
    and CodeQL run
    32660512188
    passed before publication.
  • GitHub Release workflow
    32660619413
    published the reproducible source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-23.
    Public SHA-256 values are 65da7ce8f88f7ece030e671973235e1ae3c318c2b49cb8d1f53382714191a26c
    (archive), 092fa41f2af42a3da5cdb88769c0d101fb659e3eb080de61351630594ad57a9b
    (SBOM), 0e89c158688e3211eb02fb9fa54c7d7f452300f30b5906c4fe44f7d46e4a2140
    (manifest) and 40daac6af415136e37e28aa15724bdfb8dd3fc3050691c3a66dbeba7b2e2093d
    (SHA256SUMS). Fresh downloads passed checksums and GitHub attestation verification.
  • npm workflow
    32660739200
    published web-app-security-skill@0.6.0 at 2026-08-23T19:17:13.071Z through GitHub OIDC
    trusted publishing. npm records shasum 6d83dba33b0d1349873e9b77ffd73da6f88b7396, integrity
    sha512-oe0uooh3BWRiHAsmUk9/JIJoFac7pK/2Ey4SEalos2a7Q1JGBoiDfj8FujlveMkXdBxrF4MpwflqlRwaLkiSJg==
    and SLSA provenance.
    The fresh registry tarball is byte-identical to a package built at the signed source commit.
  • Published-state commit a9afb943298d70f1d5a2d8005a4d0a928acb3de8 contains the v0.6.0
    verifier trust entry; scripts/install-verified.mjs at that commit has SHA-256
    1bcc929e7b939c6f5b300d91b928467be4ad809856611bfb53c96e1c39f60e5c. Bootstrap commit
    3fa12244dfb70e0588ccf0e645bf5c75b6148b01 pins that verifier and has bootstrap SHA-256
    22df4c865d01f51b64066c8e53beaa9bb3cb3c29ef431c6b8a3aa56074dab65c.
  • Final pinning CI run
    32661555145
    passed all four Node 22/24 by Ubuntu/macOS jobs; CodeQL run
    32661555143
    passed. Immutable Action run
    32661706137
    reproduced one owned GET /api/orders/[id] route with authentication and authorization both
    not_observed, priority review_next, and no confirmed vulnerability created from those states.
  • A fresh exact-version npx run and a fresh public-bootstrap CLI install both returned v0.6.0 and
    produced the same route semantics and parser identity: @babel/parser 7.28.4 with bundle SHA-256
    f8d700c78a6d0a50513a672b419074a87597093733d2d69ecee92675d8139698. The isolated installer
    explicitly reported that GitHub attestation verification did not run because gh was not
    authenticated there; fixed checksums, manifest, SBOM, tag and source identity still verified,
    while public release attestations had already been verified separately.
  • Signed movable tag v1 has tag object 1ec4442b72a8d36ba9765d88f7d63108e91d6d02
    and peels to the immutable v0.6.0 source commit
    7521e0699eefe26d23a7972fbee6fb37b46fdfe2. Public consumer run
    32661836371
    passed the passive-crawl, authorization-rejection and immutable route jobs after promotion.

Artifact identity, provenance and passing consumers do not prove every detector conclusion correct
or an audited project secure. v1 is intentionally movable; use the full source commit when a
workflow must remain immutable.

v0.5.4

Choose a tag to compare

@github-actions github-actions released this 23 Aug 15:33
v0.5.4

v0.5.4 release evidence

Status: published. The signed tag, GitHub Release, npm package with provenance, verified installer
trust entry and signed v1 promotion are publicly verifiable.

Outcome

Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.

v0.5.4 expands the bounded automatic first pass. Five built-in rules cover exact Git tracking of
sensitive .env names, JavaScript session-secret/cookie settings and Python session-cookie/CSRF
settings. Eight project-owned Opengrep rules add same-file request-to-SQL, outbound-URL, file-path
and redirect flows across JavaScript/TypeScript and Python. --profile deep selects the built-in
detector plus the four existing external adapters without downloading them.

The release retains the corrected evidence claim: the self-authored planted suite is named
rule-contract conformance and reports literal positive/negative/state contract results. A separate
historical real-world regression corpus executes four minimized correctness failures and one
review-visible expected benign DOM-sink match against product code.

The main-branch try-now command follows npm latest. Reusable CI, signed release verification and the
trusted installer remain pinned to an immutable version or source commit.

Evidence sets

Neither evidence set is a representative production-vulnerability benchmark. Stable detector reach
is 25 built-in risk rules, 2 evidence-integrity rules and 16 opt-in external-adapter rules: 43 total.
Opengrep matches remain same-file suspected leads. A missing deep-profile prerequisite is explicit
unknown evidence and exit 3, never a clean result.

Published verification

The local release gates include:

npm run conformance:rules
npm run regressions:real-world
npm run check
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .

The release procedure additionally verifies the signed tag after it exists:

git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.5.4

Public release facts

  • The SSH-signed v0.5.4 tag peels to source commit
    d9ee538089ac813dcd454d10b45f14b958c1ec19. Candidate CI run
    32648619071
    and CodeQL run
    32648619088
    passed before publication.
  • GitHub Release workflow
    32648846862
    published the source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-23. The public
    asset SHA-256 values are 00742dfe4d0118e8361380314c4fe01ed4e3924db1015d080b882bd3841431a5
    (archive), cfa209b59004ce29bbf808eadc37b1fbb8bfd8eb162e462c29661e8d18a592e1
    (SBOM), f50d8b974666694ccaebdb583127cc62471536943b028f7057919cf47b4529c1
    (manifest) and cbd7d771f81cee065989dc386fef239fc65d2d0966b1ca23fb5c8b9f94bdce12
    (SHA256SUMS).
  • npm workflow
    32650181341
    published web-app-security-skill@0.5.4 at 2026-08-23T15:58:01.250Z through the configured
    GitHub OIDC trusted publisher. npm records shasum
    1fb71399684025257e069a63b46eb058cca590d1, integrity
    sha512-N9UlD9l05Mmm1El7VFf1CGR6nSSG8msea+JjwlN/uwv7rV8gUbGp3DZlEKO8yFMWw+uqLFyYYBocCD8PTRPUdA==
    and SLSA provenance.
    A fresh public tarball contained 140 files and matched the signed tag package payload file by file.
  • The signed movable v1 tag object is
    464ba64a4d256dbf3b26f78101730b24a4337bc4 and peels to the same immutable source commit.
    Public consumer run
    32650353548
    passed both the passive path and expected authorization rejection.

Artifact identity, signatures and provenance establish origin and byte identity. They do not prove
that every detector conclusion is correct or that a scanned project is secure.

v0.5.3

Choose a tag to compare

@github-actions github-actions released this 16 Aug 10:02
v0.5.3

Web App Security Skill v0.5.3

Web App Security Skill gives Web builders using AI coding agents a reviewable local security first pass. Run it without installing:

npx --yes web-app-security-skill@0.5.3 audit . --fail-on never

The report explains each lead in security terms and ordinary language, states what the evidence
does not prove, proposes a change for review, names likely product side effects, and separates
security retesting from normal-behavior testing. The command does not edit the project or contact
a deployment.

v0.5.3 also includes the Claude repository plugin, diff-scoped review, the planted pattern
benchmark and public known limitations. These are bounded first-pass capabilities; they do not
prove that a project is secure or establish production-vulnerability precision or recall.


Release identity

  • Version/tag: v0.5.3
  • Source identity: the commit peeled from the SSH-signed annotated tag; the exact commit is recorded
    in web-app-security-skill-0.5.3.release.json and the provenance attestation.
  • Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.
  • Stable corpus: 20 built-in risk rules, two evidence-integrity rules and eight opt-in external
    adapter rules, unchanged from v0.5.2.

This file is part of the source commit it describes and therefore does not embed a fabricated self-
referential source SHA. The signed tag, manifest and provenance establish the published source
identity.

Distribution

The package named web-app-security-skill publishes the real zero-dependency CLI with both
web-app-security-skill and webapp-security bin names. Its explicit file allowlist contains the
runtime, skill instructions, rules, schemas, references, current limitations and benchmark evidence
while excluding repository tests, launch/adoption notes and engineering plans. An isolated packed
artifact runs version and a real source audit through offline npx.

Claude Code can add this repository as marketplace web-app-security and install plugin
web-app-security-skill. The plugin uses the repository-root SKILL.md; no copied detector or
second skill body exists. Both manifests validate with Claude Code 2.1.284, and an isolated Claude
configuration completes marketplace add, plugin install and plugin listing.

Git diff source selection

audit <project> --since <ref> resolves the ref to an immutable commit, scans current tracked source
with full file context and retains exact-location findings on added lines. It records but excludes
untracked files. audit <project> --staged exports and scans the Git index, excluding unstaged
working-tree content.

Path-level findings follow materially changed files. Missing-lockfile conclusions remain visible
when a relevant manifest, workspace file or ancestor lockfile changes. Changed-file parse failures
and global traversal incompleteness remain explicit unknown evidence. Pure content-identical renames
do not replay findings.

Diff modes use the built-in adapter only and cannot use baseline/retest comparison. A clean diff
report does not establish whole-repository safety.

Ground-truth pattern benchmark

npm run benchmark:ground-truth regenerates exact JSON and Markdown results from the stable corpus.
The 20 risk contracts produce TP=20, FN=0, TN=20 and FP=0; the two evidence-integrity contracts
produce TP=2, FN=0, TN=2 and FP=0, with no expected-state mismatch. Tests prove that deleting a
positive observation produces an FN and that a safe-neighbour match produces an FP.

These are synthetic planted pattern-contract results. They do not measure production-vulnerability
precision, recall, language coverage, reachability or exploitability. The five-project ordinary-code
review remains separate evidence.

Known limitations and deferred expansion

KNOWN_LIMITATIONS.md publishes current parser, evidence-state, external-adapter, incremental and
recurring benign-match boundaries. The v0.5.3 architecture decision defers MCP and additional stable
rules. It defines client demand, permission, schema, local transport, distribution and failure tests
for future MCP work, plus fixture, evidence-boundary, false-positive and fail-closed gates for every
future stable rule.

Compatibility and security boundary

  • Finding/report v3, persisted-subject comparison and v2 migration semantics remain compatible.
  • Syntax and external scanner matches remain suspected until independent evidence confirms them.
  • Missing or failed source evidence remains unknown; unavailable evidence is never a pass.
  • Passive network defaults, authorization acknowledgements and review-only repair behavior are
    unchanged.
  • This release is not general SAST/DAST coverage, authenticated testing, an MCP service or proof that
    a project is secure.

Release verification

The release workflow runs npm run check, rebuilds all four release assets twice and compares every
byte, verifies archive structure, checksums, manifest and SPDX SBOM, exercises isolated install and
upgrade, then requests GitHub build provenance before publication.

Verify the signed tag:

git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.5.3

The published SHA256SUMS, manifest source commit, git rev-parse 'v0.5.3^{}', GitHub-recorded asset
digests and provenance are verified before immutable asset digests are added to the installer. npm,
verified installation and the mutable v1 alias are promoted only after their public consumers pass.

v0.5.2

Choose a tag to compare

@github-actions github-actions released this 15 Aug 15:21
v0.5.2

v0.5.2 release evidence

Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.

Web App Security Skill v0.5.2 is a focused correctness patch over v0.5.1. It repairs report
rendering, pnpm workspace lockfile evidence, nested JavaScript/TypeScript template coverage and
path-only retest evasion without expanding the stable rule boundary or changing evidence states.

Release identity

  • Version/tag: v0.5.2
  • Source identity: the commit peeled from the SSH-signed annotated tag; the exact commit is recorded
    in web-app-security-skill-0.5.2.release.json and the provenance attestation.
  • Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.
  • Stable corpus: 20 built-in risk rules, two evidence-integrity rules and eight opt-in external
    adapter rules, unchanged from v0.5.1.

This file is part of the source commit it describes and therefore does not embed a fabricated
self-referential source SHA. The signed tag, manifest and provenance establish the published source
identity.

Correctness fixes

Structured risk summaries

The v3 Markdown and HTML renderers now read each state's structured { total, bySeverity } value.
They omit zero-count states and render both state totals and nonzero severity counts. The report's
first risk summary no longer coerces those objects to [object Object].

pnpm workspace lockfiles

The missing-lockfile rule now reads bounded pnpm-workspace.yaml package patterns and recognizes an
applicable ancestor pnpm-lock.yaml. Positive and negative package patterns form an include/exclude
boundary. Unreadable, oversized or unsupported workspace metadata makes the
check incomplete and emits evidence-integrity coverage; it does not produce a confirmed absence.

This parser supports the ordinary string-list form and JSON-compatible inline arrays. It is not a
general YAML implementation. A package excluded from the workspace still needs its own applicable
lockfile.

Nested template coverage

The bounded JavaScript/TypeScript tokenizer now tracks nested template literals and their
expression depth, including templates inside TSX brace expressions. Template text remains ignored
as data while code inside ${...} remains tokenized and scanned. An unterminated template still
produces partial coverage and explicit unknown evidence.

Rename-aware retesting

Retesting now derives a path-independent movement fingerprint from rule identity, adapter identity
and normalized evidence. A unique one-to-one match across old and new paths is reported as
unchanged with reason condition_moved. Duplicate or otherwise ambiguous matches remain separate
new and fixed observations so the comparison does not guess.

Compatibility and security boundary

  • Finding/report v3, persisted-subject comparison and v2 migration semantics remain compatible.
  • Syntax and external scanner matches remain suspected until independent evidence confirms them.
  • Missing or failed source evidence remains unknown; no parser fix turns unavailable evidence into
    a pass.
  • Passive network defaults, authorization acknowledgements and review-only repair behavior are
    unchanged.
  • This release is not general SAST/DAST coverage, authenticated testing or proof that a project is
    secure.

Release verification

The release workflow runs npm run check, rebuilds all four release assets twice and compares every
byte, verifies archive structure, checksums, manifest and SPDX SBOM, exercises isolated install and
upgrade, then requests GitHub build provenance before publication.

Verify the signed tag:

git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.5.2

After publication, verify SHA256SUMS, compare the manifest source commit with
git rev-parse 'v0.5.2^{}', verify provenance, and only then add the immutable asset digests to the
verified installer. The mutable v1 alias moves only after the public consumer workflow passes.

v0.5.1

Choose a tag to compare

@github-actions github-actions released this 14 Aug 05:26
v0.5.1

v0.5.1 release evidence

Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.

Web App Security Skill v0.5.1 is a compatibility patch over the v0.5.0 source-detection and
understandable-remediation release. It repairs independently reproduced tokenizer and case-study
reproduction defects without expanding the stable rule boundary or changing evidence states.

Release identity

  • Version/tag: v0.5.1
  • Source identity: the commit peeled from the SSH-signed annotated tag; the exact commit is recorded
    in web-app-security-skill-0.5.1.release.json and the provenance attestation.
  • Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.
  • Stable corpus: 20 built-in risk rules, two evidence-integrity rules and eight opt-in external
    adapter rules, unchanged from v0.5.0.

This file is part of the source commit it describes and therefore does not embed a fabricated
self-referential source SHA. The signed tag, manifest and provenance establish the published source
identity.

Correctness fixes

JSX text boundary

The bounded JS/TS tokenizer now tracks JSX tag, child-text and brace-expression states. Text such as
skills/*.yaml or src/*.tsx no longer opens a JavaScript block comment, while expressions, tag
attributes and nested JSX return to code tokenization. A tokenizer failure still produces partial
coverage and explicit unknown evidence; it is never treated as a clean result.

Python raw-string boundary

The Python tokenizer now consumes backslash-quoted characters in raw as well as non-raw strings for
lexical delimiter handling. The reproduced raw regular expression compiles with CPython and now
completes tokenizer coverage. This remains a bounded tokenizer, not a claim of complete Python
grammar or data-flow analysis.

Reproducible ordinary-project evidence

The v0.5.0 five-project evidence retains each original report.json SHA-256 as an archival byte
identity and adds report.semanticDigest. The stable digest covers report schema, ruleset digest,
state summary and sorted finding ID/state pairs. Third parties can run:

node scripts/check-v050-ordinary-review.mjs \
  --report <project-id> /path/to/reproduced/report.json

Direct audits intentionally receive a random ephemeral subject, so their full report bytes are not
claimed to match the author's original report. The new comparison preserves subject isolation while
making the reviewed finding semantics reproducible.

Local TLS fixture isolation

The HTTPS hardening regression test removes inherited SSL_CERT_FILE before setting its owned
CURL_CA_BUNDLE. The reported enterprise-CA failure was not independently reproduced on the release
host; this change removes an unnecessary host-environment input from the fixture.

Compatibility and security boundary

  • Finding/report v3, persisted-subject comparison and v2 migration semantics are unchanged.
  • Syntax and external scanner matches remain suspected until independent evidence confirms them.
  • Missing or failed source evidence remains unknown; no parser fix turns unavailable evidence into
    a pass.
  • Passive network defaults, authorization acknowledgements and review-only repair behavior are
    unchanged.
  • This release is not general SAST/DAST coverage, authenticated testing or proof that a project is
    secure.

Release verification

The release workflow runs npm run check, rebuilds all four release assets twice and compares every
byte, verifies archive structure, checksums, manifest and SPDX SBOM, exercises isolated install and
upgrade, then requests GitHub build provenance before publication.

Verify the signed tag:

git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.5.1

After publication, verify SHA256SUMS, compare the manifest source commit with
git rev-parse 'v0.5.1^{}', verify provenance, and only then add the immutable asset digests to the
verified installer. The mutable v1 alias moves only after the public consumer workflow passes.

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 13 Aug 21:27
v0.5.0

v0.5.0 release evidence

Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.

Web App Security Skill v0.5.0 expands narrow automated source detection and makes every actionable
source result understandable before a user approves a change. It keeps the evidence discipline and
passive defaults from v0.4.0; it does not turn syntax matches into confirmed vulnerabilities or let
the CLI edit a project unattended.

Release identity

  • Version/tag: v0.5.0
  • Source identity: the commit peeled from the SSH-signed annotated tag; the exact 40-character SHA
    is also recorded in web-app-security-skill-0.5.0.release.json and the provenance attestation.
  • Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.
  • External adapters: Gitleaks 8.30.1, Opengrep 1.27.0, OSV-Scanner 2.5.0 and Checkov 3.3.9,
    installed and version-pinned by the caller.

This Markdown file is part of the source commit it describes, so it does not embed a fabricated
self-referential commit SHA. Verify the exact published identity with the signed tag, release
manifest and provenance.

Stable rule boundary

The v0.5.0 stable source and deployment-policy corpus contains exactly 30 rules:

  • 20 built-in risk rules: four shared project/configuration checks, eight bounded
    JavaScript/TypeScript checks and eight tokenizer-backed Python checks;
  • two built-in evidence-integrity rules that expose unreadable/failed source observations as
    unknown rather than clean;
  • eight opt-in external-adapter risk rules: two Gitleaks rules, two Opengrep rules, one
    OSV-Scanner rule and three Checkov rules.

The machine-readable source of truth is docs/stable-source-rules.json,
and docs/stable-rule-corpus.json links every stable rule to a positive
fixture, safe near-neighbour, expected state, evidence boundary and test entrypoint. Built-in rules
have 22 real observations and 22 planted missing-observation failures. External rules use pinned
real-tool CI fixtures. This demonstrates the documented observation paths, not population-level
precision, recall or exploitability.

Built-in depth is deliberately limited to direct lexical or tokenizer-backed constructs. It does
not prove whole-program input flow, runtime reachability, sanitizer correctness or deployment
exposure. Source patterns and external scanner rows remain suspected unless rule-specific
independent evidence confirms the conclusion.

Explanation and repair contract

Source findings and reports now use v3. Each actionable result retains the professional term and
standards mapping, then also records:

  • a plain-language explanation and conditional consequence;
  • the evidence that exists and what it cannot prove;
  • one reviewable proposal, alternatives and likely product side effects;
  • decisions that must remain with the owner;
  • separate security and normal-function retests; and
  • rollback criteria.

Persisted v2 source baselines remain readable through the compatibility layer and cannot
manufacture a fixed result. A fix is comparable only when subject, scope, rule identity and current
coverage agree. repair-plan and repair-validate create and validate private, non-overwriting
review records with explicit approval and dual-retest states. The CLI does not apply project edits,
deploy changes or migrations.

Adapter decisions

  • Opengrep 1.27.0 is the stable bounded SAST adapter for two bundled, digest-pinned same-file
    request-to-command rules. It is opt-in, does not fetch rules and does not execute project code.
  • Checkov 3.3.9 is the stable bounded deployment adapter for three fixed root Dockerfile/GitHub
    Actions rules. It uses --skip-download; it may query PyPI for version metadata but does not
    upload project source.
  • Gitleaks and OSV-Scanner retain the v0.4.0 contracts. OSV data may change with the public advisory
    database. None of the adapters is downloaded automatically, and project dependencies are never
    installed or executed.

Exact selection evidence, rejected alternatives and failure behavior are in
docs/sast-adapter-benchmark.md,
docs/iac-adapter-benchmark.md and
docs/adapter-protocol.md.

Ordinary-project and demo evidence

The broader built-in v3 path ran against five existing ordinary Web projects at immutable commits,
without probing hosted services or executing project dependencies. All 43 observed findings were
uniquely reviewed: 11 useful leads, 27 expected benign matches, one unknown tokenizer observation
and four confirmed missing-lockfile facts. These are finding classifications, not 43 vulnerabilities
and not a precision/recall result. A zero-finding project is not evidence that the project is secure.

The local network-free demo uses one intentionally unsafe Node.js child-process call. It reports a
suspected CWE-78-shaped lead, states that input flow and reachability are unproven, proposes
execFile with separate arguments, names quoting and cross-platform behavior as side effects, then
records a compatible security retest and an independent functional retest. The demo proves this
bounded workflow, not automatic safe repair.

Release verification

The release workflow runs the full repository gate, builds every artifact twice and compares bytes,
verifies archive paths, the stable rule manifest, release manifest, SHA-256 list and SPDX 2.3 SBOM,
then exercises clean installation and an isolated v0.4.0-to-v0.5.0 lifecycle upgrade. GitHub build
provenance is requested only after these checks pass. External consumers separately exercise the
exact immutable Action source in backward-compatible crawl mode and v0.5.0 source mode before the
stable v1 alias moves.

Verify the published tag after release:

git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.5.0

Verify downloaded assets with SHA256SUMS, compare the manifest source commit with
git rev-parse 'v0.5.0^{}', and verify GitHub provenance. The built-in verified-installer trust
anchor is updated only after immutable public asset digests exist; until then, the documented
default installer remains the already trusted v0.4.0 release.

Unsupported and known risks

  • This is not a general SAST/DAST scanner, authenticated pentest or proof that a project is secure.
  • BOLA/IDOR, business logic, LLM/OAuth, database isolation and most framework-specific paths remain
    agent-guided and require project context.
  • Twenty-seven expected benign matches in the bounded ordinary-project review show that lexical
    leads still need human review. No precision or recall percentage is claimed.
  • Authenticated browser DAST, universal language coverage, automatic exploit generation, unattended
    patching, deployment and database migration are not provided.
  • No authenticated third-party deployment, production cloud account or upstream live system was
    actively tested for this release.
  • Native Windows, PowerShell and WSL2 remain unsupported because no maintained verification
    environment exists. Node 20 and earlier are not supported release targets.
  • Signatures, checksums and attestations establish artifact identity and build origin; they do not
    prove that every security conclusion or proposed implementation is correct.

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 13 Aug 16:06
v0.4.0

v0.4.0 release evidence

Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.

Web App Security Skill v0.4.0 is the evidence-integrity and useful-detection release. It keeps the
agent-guided hardening methodology while making narrow automated results harder to overstate.

Release identity

  • Version/tag: v0.4.0
  • Source identity: the commit peeled from the SSH-signed annotated tag; the exact 40-character SHA
    is also recorded in web-app-security-skill-0.4.0.release.json and the provenance attestation.
  • Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.
  • External adapters: Gitleaks 8.30.1 and OSV-Scanner 2.5.0, installed and pinned by the caller.

The Markdown file is part of the source commit it describes, so it does not embed a fabricated
self-referential commit SHA. Verify the exact published identity with the signed tag and manifest.

Evidence model and migration

Report v2 binds findings to subject, scope, rule revision, adapter and ruleset identity. Per-rule
coverage records discovered, eligible, scanned, excluded, skipped, truncated and failed work. A
missing or incomplete check is explicit unknown/unavailable evidence and cannot establish fixed.

Historical v1 reports remain readable but are never silently comparable. migrate-report records
their original SHA-256 and explicit user binding as non-comparable lineage; a new persisted v2 audit
is required before a later retest can prove a fix. Moved or cloned projects require explicit
rebind acknowledgement rather than path or repository-name inference. See
docs/report-v2-migration.md.

Detection and reporting changes

  • Built-in source checks remain deliberately narrow: lockfile absence, environment-named files,
    public Node inspector bindings and common production source-map settings.
  • Gitleaks checks committed history and the working tree. OSV-Scanner checks supported recorded
    lockfiles and may query the public OSV advisory service. Neither adapter is downloaded by the
    product and project dependencies are not executed.
  • Every external scanner match is suspected. Gitleaks does not prove credential validity or
    exposure; OSV does not prove reachability, deployed version or exploitability.
  • Reports separate security_exposure, supply_chain, search_discoverability, reliability and
    evidence_integrity. A HIGH discoverability result is not a HIGH security vulnerability.
  • JSON, Markdown, HTML, SARIF and JUnit are committed as one private atomic evidence bundle after
    sanitization and validation. Existing output is not overwritten.
  • The composite Action keeps v0.3 crawl behavior and adds source mode. External findings require an
    acknowledged alert-owner policy before they can affect the configured gate.

Five-project evidence

The dated 2026-08-14 corpus ran the complete v2 source path at immutable commits without probing a
hosted project or executing project dependencies.

Project Confirmed Suspected Boundary
Linkwarden 0 270 OSV advisory rows are mutable suspected leads
Healthchecks 0 98 Gitleaks documentation/test matches suspected; OSV not applicable
Open WebUI 0 144 Source-map and OSV leads suspected; public .map delivery unknown
Uptime Kuma 4 93 Four low-severity missing-lockfile facts in independent extra/ tools; external leads suspected
Mealie 0 30 Gitleaks test-material matches suspected

These records demonstrate applicability, state discipline and false-positive closure. They are not
labelled benchmark data and do not support a precision/recall score. OSV counts can change as its
public advisory database changes. Reproduction commands and unreached surfaces are in
docs/case-studies/journeys/.

Regressions fixed

  • Cross-project, tampered, forged, v1 or incomplete baselines cannot manufacture a fixed result.
  • Deep, large, unreadable, malformed and truncated source candidates remain visible in coverage.
  • Crawler-range, sitemap and AWS permission failures become unknown evidence, never a clean result.
  • Cross-domain severity is no longer combined into one security headline.
  • Evidence writes are private, atomic, non-overwriting and rolled back after handled failures.
  • External-tool missing/version/timeout/error/malformed paths fail closed; upstream OSV severity
    cannot inflate local severity.
  • Duplicate Gitleaks rows are deduplicated while distinct fingerprints remain distinct; finding IDs
    survive sanitizer patterns that resemble numeric account identifiers.

The complete bug-to-test map is docs/regression-inventory.md.

Release verification

The release workflow runs the full gate, builds every artifact twice and compares bytes, verifies
archive paths, manifest, SHA-256 list and SPDX 2.3 SBOM, then exercises an isolated v0.3.0-to-v0.4.0
upgrade plus clean install/version/start/upgrade/uninstall behavior. GitHub provenance is requested
only after those checks pass. A separate consumer repository verifies both backward-compatible crawl
mode and built-in source mode against the exact candidate/release commit.

Verify the published tag after release:

git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.4.0

Verify downloaded assets with SHA256SUMS, then compare the manifest source commit with
git rev-parse 'v0.4.0^{}' and verify GitHub provenance. The post-publication verifier now trusts
the immutable v0.4.0 asset digests, and the documented bootstrap pins and verifies that verifier
before installation.

Unsupported and unknown

  • This is not a general SAST/DAST scanner, authenticated pentest or automatic patching system.
  • BOLA/IDOR, business logic, LLM/OAuth, database isolation and most framework-specific sinks remain
    agent-guided and require project context.
  • No authenticated third-party deployment, production cloud account or upstream live system was
    actively tested for this release.
  • Native Windows, PowerShell and WSL2 are unsupported because no maintained verification environment
    exists. Node 20 and earlier are not supported release targets.
  • Release signatures, checksums and attestations establish artifact identity and build origin; they
    do not prove every security conclusion is correct or that an installed project is secure.