Releases: parousia8888/web-app-security-skill
Release list
v0.7.2
v0.7.2 release evidence
Status: published and promoted. The signed tag, GitHub Release, npm package, provenance, immutable
verified-installer/bootstrap chain and signed v1 alias are publicly retrievable. Immutable and
post-promotion Action consumers passed.
Outcome
Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.
v0.7.2 closes three reproduced false-clean or destructive paths and strengthens independently
executable evidence contracts without adding a detector family or framework claim.
- Demo reruns may clean only a marker-owned output directory and fixed generated children.
Pre-existing unowned directories, symlinks and protected paths are refused. - Technical evidence redaction recognizes normalized singular/plural credential containers and
bounded high-confidence token formats across every report-bundle renderer. It remains leak
prevention for known output shapes, not a general secret scanner. - Direct CommonJS Express routers and exact local CommonJS mounts are inventoried. A structurally
observed imported local registration function that cannot be resolved produces
express_registration_function_unresolved, partial coverage,unknownevidence and exit 3.
Exit 3 means the tool refused a clean result because evidence is incomplete; it is not a
vulnerability count. - Thirteen shipped JSON Schemas compile offline under Ajv Draft 2020-12 and share a curated
agreement corpus with handwritten validators. - The fixed-commit v0.7.0 ordinary-project access review derives all aggregate totals from complete,
digest-bound project records and has an explicit network-only refresh path. - Release documentation separates repository-local signer consistency, GitHub verification,
release-asset attestation, npm OIDC provenance and checksum/SBOM integrity.
Stable scope remains 25 built-in risk rules, three evidence-integrity rules, 16 opt-in external
adapter risk rules and the existing bounded Express, NestJS and Next.js App Router inventory.
Regression evidence
test/demo-output-safety.test.mjsproves an unowned sentinel and owner-created extra child survive
the demo path while a marked rerun succeeds.test/evidence-writer.test.mjsasserts a unique credential sentinel is absent from JSON,
Markdown, HTML, SARIF, JUnit and additional bundle artifacts while allowed evidence remains.- Express extractor and CLI integration fixtures cover direct CommonJS routers, exact mounts,
unresolved imported registration functions and a valid route-free worker neighbour. scripts/check-json-schema-contracts.mjscompiles every schema offline and checks Ajv/manual
agreement for curated positive and negative documents.test/v070-access-review-provenance.test.mjsrejects aggregate drift and project-record digest
tampering while preserving deterministic semantic route hashes.test/release-trust-boundaries.test.mjsrejects stale verification examples and language that
conflates repository-local signer consistency with GitHub account ownership.
Each silently reversible P0 branch has a machine assertion that was confirmed to fail when the old
behavior was planted. Focused Phase 1-7 checks passed before candidate freeze.
Published verification
The bounded candidate tree passed:
npm run check
npm pack --dry-run --json
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
git diff --check
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.7.2npm run check completed all generated-contract checks, local Node tests and the Bash 3.2 smoke
suite. Skill validation returned Skill is valid!. npm pack --dry-run --json reported 183 files,
552,526 packed bytes and 2,218,387 unpacked bytes. Real external-adapter tests remain opt-in and
were not downloaded for the local gate.
The first candidate-gate attempt exposed an integration regression: three repository generators
passed a pre-existing mkdtemp root to the newly ownership-aware demo. The generators now use a
new child output path; their existing deterministic --check gates caught the planted old behavior
and passed after the correction.
One final-tree full local gate, one package inspection and bounded channel consumers are enough
unless a channel-specific failure appears.
Public release facts
- The SSH-signed annotated
v0.7.2tag object
ecfa779d317c09d5f0948df880762a914d6f4abcpeels to source commit
30402c866b86d78b66d0d4b495fee40ff6a6f160. Final-tree CI run
32844389181
and CodeQL run
32844389183
passed before tagging. GitHub reports the tag signature asverified: true,reason: valid, and
repository-local.github/release-signersverification also passes. - GitHub Release workflow
32844662253
published the reproducible source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-25.
Tag CI run
32844662312
also passed. Public SHA-256 values are
340413987722874ac2b2cac58d09f45e44b7f541dc06045e191a54654bc125fb(archive),
0e7702487a71ea601385be1adb10cb6c8aa75775aa3c63146c228fb82f23fc5f(SBOM),
642f59261ce225ca06d836d95c2046e29654447af18aee27cc352d5b49615207(manifest) and
6300c2822286bfc9913ee694f5daa629572a9a1367029684f5d54db931969552
(SHA256SUMS). Fresh downloads passed checksums, the 473-entry manifest, archive lifecycle,
GitHub asset-digest comparison and GitHub release-asset attestation. - npm workflow
32845017547
publishedweb-app-security-skill@0.7.2at2026-08-25T11:58:03.569Zthrough GitHub OIDC trusted
publishing. npm records source30402c866b86d78b66d0d4b495fee40ff6a6f160, shasum
4b57df8c5c1f60317ffbb1dc54302cd86884eb88, integrity
sha512-KftiDW+ABghvOlH38KU9GumhtL8NC+8Xkw6PmL/sptKvS/9xOsRPNjj6CJBMETwutADXIe09ea9iXAgFXfwRdQ==
and SLSA provenance.
Its 183 files matched corresponding files in the signed source byte for byte. - The four observed release digests are recorded in the verifier trust map, whose default is
0.7.2. The stable Action remains recorded at v0.7.1 until guardedv1promotion and its
post-promotion consumer pass. - Public-state commit
87326f11c0aab3901ac5cb0783d9452e607e83c5passed CI
32845505985
and CodeQL
32845505857.
Itsscripts/install-verified.mjsSHA-256 is
662b7de3d596bb6faf8fac4bf69f325f44c1152c99cbbea5fc25184863b1c6d5. scripts/bootstrap-install.sh, the release contract and English/Chinese verified-installation
paths now pin that immutable verifier and explicit v0.7.2 assets. The README-facing bootstrap
source commit3f42fb70f99f6ccb3c8e8449b2c06749c3b53148passed CI
32845795654
and CodeQL
32845795620.
Itsscripts/bootstrap-install.shSHA-256 is
193ece72d2c7d2c4220a6164a4bb280853ffca1e8de5217535fe95010c146e8a.- The README bootstrap and immutable Action examples now select those public v0.7.2 identities.
Publication commit68cb7fb24e40e4bbd75b13e469a7f57e4412714fpassed CI
32846176471
and CodeQL
32846176455. - A clean-room public bootstrap downloaded the script from immutable commit
3f42fb70f99f6ccb3c8e8449b2c06749c3b53148, matched SHA-256
193ece72d2c7d2c4220a6164a4bb280853ffca1e8de5217535fe95010c146e8a, installed all three
surfaces into an isolated temporary home and returnedWeb App Security Skill 0.7.2. It
verified source commit30402c866b86d78b66d0d4b495fee40ff6a6f160, archive, manifest,
checksums and SBOM. Because the isolated home could not access the macOS keyring, the bootstrap
accurately reported its optional GitHub attestation check as not run; a separate authenticated
gh attestation verifypassed the same public archive with SHA-256
340413987722874ac2b2cac58d09f45e44b7f541dc06045e191a54654bc125fb. - Pre-promotion Action consumer
32846524348
passed. Its immutable job consumed full commit
30402c866b86d78b66d0d4b495fee40ff6a6f160and verified route-security v2 control separation;
its stable job independently proved that the existing v0.7.1@v1alias still passed passive
crawl and authorization-refusal checks before movement. - Pre-promotion evidence commit
cfdad9bcd49396071b1e19510d7471d625e6dcc3passed CI
32846724386
and CodeQL
32846724421. - The SSH-signed annotated
v1tag moved with an exact guarded lease from tag object
b0df7d0c6bd2a9a596d591bb63cff6e6bc8471ffto
758036ee84ad2bc2f31a8ba08969acd2a6b87de6, which peels to
30402c866b86d78b66d0d4b495fee40ff6a6f160. GitHub reportsverified: trueand
reason: valid; repository-local.github/release-signersverification passed with ED25519
fingerprintSHA256:DmZYVL1dLhUmgaJnfZKpZIexgzMv5jk9+YCoBT3zRIg. - Post-promotion public
@v1consumer
[`...
v0.7.1
v0.7.1 release evidence
Status: published and promoted. The signed tag, GitHub Release, npm package, provenance, immutable
verified-installer/bootstrap chain and signed v1 alias are publicly retrievable. Immutable and
post-promotion Action consumers passed.
Outcome
Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.
v0.7.1 closes execution-boundary gaps found by external review without expanding detector or
framework scope. Crawl requests now use one bounded destination/DNS/redirect/size/timeout policy.
Default HIGH gating includes actionable suspected source leads without promoting their evidence
state. Evidence sanitization propagates through nested credential containers. JavaScript,
TypeScript and Python analysis has deterministic per-file and run-wide budgets that fail closed,
and route coverage reflects source inputs stopped by those budgets.
The release also replaces dynamic robots wildcard regexes with a literal matcher and makes the
installed payload include the Claude plugin metadata, bundled rules and v0.7 review evidence. The
stable inventory remains 25 built-in risk rules, three evidence-integrity rules and 16 opt-in
external-adapter risk rules.
Regression evidence
60427acbinds crawl HTTP requests to the tested network boundary.1affcc8adds actionable-gate, recursive-redaction, installer, robots and source-budget fixes.- The default-gate regression proves a suspected HIGH can block without becoming confirmed.
- Redaction regressions exercise nested authorization/cookie/token wrappers, private paths and all
report formats while preserving documented authorization evidence models. - Hostile repeated-wildcard and repeated-source-token fixtures exercise bounded work and explicit
incomplete evidence. - A planted rollback of the source operation checks makes the hostile-source regression fail,
proving that the budget test is an effective gate.
Published verification
The bounded candidate tree passed:
npm run check
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
npm pack --dry-run --json
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.7.1npm run check completed syntax/generated-contract checks, every local Node test and the Bash 3.2
smoke suite. Skill validation returned Skill is valid!. npm pack --dry-run --json reported 179
files, 538,302 packed bytes and 2,173,845 unpacked bytes. Real external-adapter tests remain
deliberately opt-in and were not downloaded or run by the local gate.
One final-tree full local gate, one package inspection and bounded channel consumers are enough
unless a channel-specific failure appears.
Public release facts
- The SSH-signed annotated
v0.7.1tag object
0e0b150162379105227faa81f8489add5b05a04apeels to source commit
2b746b168d767c9b2225a273474e561650b2b6f8. Final-tree CI run
32750844326
and CodeQL run
32750844327
passed before tagging. - GitHub Release workflow
32751168775
published the reproducible source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-25
Japan time. Public SHA-256 values are
8df18745da238a418539d153d68c4fc395cd86c2e9131abbbd2fb9bf0cdfe381(archive),
a97313fbf775f08cddef608b15743d26ea1255e44b192a184a677d8cc0f38725(SBOM),
59ef38bbb6d00873f2c57211db36dd3c2a128c80295c024ff988d2fee67f40a0(manifest) and
4fd672781c26a9f39c67a0c3c9576e83d25a6032ba01b1ad6dbd8f2a6f8bafde
(SHA256SUMS). Fresh downloads passed checksums, manifest validation, archive lifecycle checks,
public-asset digest comparison and GitHub provenance verification. - npm workflow
32751396849
publishedweb-app-security-skill@0.7.1at2026-08-24T16:32:26.236Zthrough GitHub OIDC trusted
publishing. npm records shasum3f062a645458618597219a3c87d3287011ea91bd, integrity
sha512-miQTWXA5cFtPbRmfi2STyiqLago3Z8bjfl9oFCPt8ENw4w3tH4X4ZMw0cJDvqpKiakGOmGQWNhS0avu0/+JG6A==
and SLSA provenance.
Its 179 files matched corresponding files in the signed source archive byte for byte. - The four observed release digests are recorded in the verifier trust map, whose default is
0.7.1. - Public-state commit
7f84917f5014b4f0f2eb532b7007394ad3123615passed CI
32751921925
and CodeQL
32751921825.
Itsscripts/install-verified.mjsSHA-256 is
38d40a706fc4e0c377657d5b49a4a8980811a2518104ac95c762278b87d7b804. scripts/bootstrap-install.sh, the release contract and English/Chinese verified-installation
paths now pin that immutable verifier and explicit v0.7.1 assets. The README-facing bootstrap
source commit25a37e476720ad8ef221e38c0e2842abf928a1dbpassed CI
32752244215
and CodeQL
32752244217.
Itsscripts/bootstrap-install.shSHA-256 is
ce37908a73bd9ffd004ec3c0a4d36dc88e3baa6187bd17df816a454a940bfe63.- The README bootstrap and immutable Action examples now select those public v0.7.1 identities.
Publication commit4977ae24dfb145d2c24db102aa779875bf76f29dpassed CI
32752898885
and CodeQL
32752898896. - A clean-room public bootstrap downloaded the script from immutable commit
25a37e476720ad8ef221e38c0e2842abf928a1db, matched SHA-256
ce37908a73bd9ffd004ec3c0a4d36dc88e3baa6187bd17df816a454a940bfe63, installed into an isolated
temporary home and returnedWeb App Security Skill 0.7.1. It verified source commit
2b746b168d767c9b2225a273474e561650b2b6f8, archive, manifest, checksums, SBOM and GitHub
attestation. - Immutable Action consumer
32753098586
passed against full commit2b746b168d767c9b2225a273474e561650b2b6f8. Its NestJS fixture
verified one-time application controls, separate authentication/authorization,
no_route_scoped_control_observedreview state and no fabricated confirmed vulnerability. - The SSH-signed annotated
v1tag moved with an exact guarded lease from tag object
b04630846eeb621fd40397f78b28ad92c4c4e6bcto
b0df7d0c6bd2a9a596d591bb63cff6e6bc8471ff, which peels to
2b746b168d767c9b2225a273474e561650b2b6f8. GitHub and.github/release-signersverify its
ED25519 signature with fingerprint
SHA256:DmZYVL1dLhUmgaJnfZKpZIexgzMv5jk9+YCoBT3zRIg. - Post-promotion public
@v1consumer
32753263317
passed passive crawl, authorization-refusal and immutable route-security checks.
Artifact identity, consumer success and provenance do not prove every detector conclusion correct
or an audited project secure. v1 is intentionally movable; consumers requiring an immutable
workflow must use the full source commit.
v0.7.0
v0.7.0 release evidence
Status: published and promoted. The signed tag, GitHub Release, npm package, provenance, immutable
verified-installer/bootstrap chain and signed v1 alias are publicly retrievable. Immutable and
post-promotion Action consumers passed.
Outcome
Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.
v0.7.0 corrects route-control aggregation and extends route-security into a bounded
access-control-chain review. Application controls are listed once; authentication, route
authorization and unclassified route controls are separate; and routes with no observed
route-scoped control form a human-review queue without becoming vulnerability findings.
For supported syntax, the analyzer records identity evidence and a caller-selected object reaching
a Prisma, Drizzle or experimental Supabase operation in the same entry or through one exact local
call. It stops before a second local call. Next.js Server Actions are represented separately from
HTTP routes. Missing visible controls or query constraints do not prove BOLA/IDOR, and every
Supabase chain retains an external RLS-policy dependency.
Evidence sets
v0.7.0 access-control review: four fixed public
commits, 173 HTTP routes, 23 Server Actions and 32 manually reviewed entries. All 12 observed
ordinary-project chains are partial and zero are completed.v0.7.0 access-control regressions:
four minimized correctness failures covering application-guard aggregation, chain fingerprinting,
Next monorepo roots and exact tsconfig alias resolution.v0.6.0 rule-contract conformance: the
unchanged 25 built-in risk and three evidence-integrity source-rule contracts.Known limitations: exact route, Server Action, identity,
data-operation, module-resolution, one-hop and external-policy boundaries.
The ordinary-project review is purposive source-only evidence. It is not representative production
precision/recall, whole-program data flow, runtime reachability, exploitability, DAST or proof that
an audited project is secure.
Published verification
The bounded local gate included:
npm run check
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
npm pack --dry-run --json
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.7.0One final-tree full local gate, one package inspection and bounded clean-room consumers are enough
unless a channel-specific failure appears.
Public release facts
- The SSH-signed annotated
v0.7.0tag object
b0de94c044082d951c12d95950360d4250e12d31peels to source commit
bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a. Final-tree CI run
32680695072
and CodeQL run
32680695073
passed before tagging. - GitHub Release workflow
32680851023
published the reproducible source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-24.
Public SHA-256 values arec5fa68b48e3c4a00ccc9c55fbd7a375eb1adddf9e7e8b7398f5e14a93974aa78
(archive),3e0c80aee8a093a3d04fa950d6e78a604c81958a4b7f984ab78cbd97276f0bf4
(SBOM),f707c4cceafc4864917fd47de525c522117b53c9a5724eb6a4e80e57cbbe5e37
(manifest) andf40a58952a221f677c9bc76b923b0f4ebd3a3dfe34b16bfb8ced885cb46aaa47
(SHA256SUMS). Fresh downloads passed checksums, manifest validation, archive lifecycle checks and
GitHub provenance verification for all four assets. - npm workflow
32680989366
publishedweb-app-security-skill@0.7.0at2026-08-24T01:49:15.577Zthrough GitHub OIDC
trusted publishing. npm records shasuma46d7ab62f577dfc21998ba3350d74c7d256d86d, integrity
sha512-GhVvvQIDb2ahF1aiRzKD2ilszykYY8X2b6i3RAlJ0TJu7o6KjhVK09edqlAG8IRRVD/MU3Z5Q5+8m4ZMw6HFpw==
and SLSA provenance.
Its 177 files matched the corresponding signed source-archive files byte for byte. - A clean-room exact-version
npx --yes web-app-security-skill@0.7.0 demorun produced the expected
suspected HIGH lead, review proposal, fixed security retest and passing functional retest. - Public-state commit
b3e77a87cc5ee16195c0965012217416ee3a935dpassed CI
32681514684
and CodeQL
32681514679.
Itsscripts/install-verified.mjsSHA-256 is
4e3c6ce6c8c3ec0cfa7972edbc85b93885bae64cb714a87c926e81fc49410422. - Verifier-pin commit
cb36196fb438fb0ad0e5b5a6a27043bf48ffb018passed CI
32681707779
and CodeQL
32681707703.
Itsscripts/bootstrap-install.shSHA-256 is
544d0ded89ed98467c275c838f033148d944668b0b56842d849ff8ae4abc63d2. - A clean-room public bootstrap downloaded that exact script, verified its SHA-256, installed into
an isolated temporary home and returnedWeb App Security Skill 0.7.0. It verified source commit
bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a, archive, manifest, checksums and SBOM. Optional GitHub
attestation was explicitly reported as not run because the isolated home had no authenticated
ghsession; checksum and manifest verification still ran. - Immutable Action consumer
32682001909
passed against full commitbfed608b5d1abe56b6b34b09f0c6ef59f17eab4a. Its NestJS fixture
confirmed that the application rate-limit guard is listed once, authentication and authorization
remain separate, an unprotected state-changing object route is review evidence, and no confirmed
vulnerability is fabricated. - The SSH-signed annotated
v1tag object
b04630846eeb621fd40397f78b28ad92c4c4e6bcwas moved with a guarded lease and peels to
bfed608b5d1abe56b6b34b09f0c6ef59f17eab4a. Its signature verifies against
.github/release-signerswith fingerprint
SHA256:DmZYVL1dLhUmgaJnfZKpZIexgzMv5jk9+YCoBT3zRIg. - Post-promotion public
@v1consumer
32682179514
passed the passive crawl, authorization-refusal and immutable NestJS route-security v2 checks.
Artifact identity, consumer success and provenance do not prove every detector conclusion correct
or an audited project secure. v1 is intentionally movable; consumers requiring an immutable
workflow must use the full source commit.
v0.6.0
v0.6.0 release evidence
Status: published and promoted. The signed tag, GitHub Release, npm package/provenance, immutable
verified-installer/bootstrap chain, immutable Action consumer and signed v1 consumer are publicly
retrievable and verified.
Outcome
Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.
v0.6.0 adds a framework-aware route-security review beside the existing finding report. It extracts
bounded Express, NestJS and Next.js App Router syntax into separate JSON and Markdown artifacts,
maps supported authentication and route-authorization signals, keeps object authorization distinct,
and orders human review work without turning review priority into vulnerability severity.
The release does not infer that a missing visible control is a confirmed vulnerability. Custom or
unresolved controls remain review candidates, and the direct Prisma object-authorization lead stays
experimental because the bounded ordinary-project review produced no ordinary-project matches.
Evidence sets
v0.6.0 route review: 57 manually reviewed routes at three
immutable public commits, with 51 detected routes and six explicit misses.v0.6.0 route regressions: six minimized
route-extraction and classification failures retained as deterministic regressions.v0.6.0 rule-contract conformance: 25
built-in risk and three evidence-integrity planted positive/negative/state contracts.Known limitations: exact supported syntax, parser, incremental,
evidence-state and object-authorization boundaries.
The route review is purposive source-only evidence, and the planted suite is author-maintained rule
contract evidence. Neither is a representative production-vulnerability benchmark or a claim of
whole-program data flow, reachability, exploitability, precision, recall, DAST or project safety.
Published verification
The bounded local gate included:
npm run check
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
npm pack --dry-run --json
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.6.0Package and verified-Skill clean-room runs produced equivalent route artifacts on the same owned
fixture before publication.
Public release facts
- The SSH-signed
v0.6.0tag peels to source commit
7521e0699eefe26d23a7972fbee6fb37b46fdfe2. Candidate CI run
32660512207
and CodeQL run
32660512188
passed before publication. - GitHub Release workflow
32660619413
published the reproducible source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-23.
Public SHA-256 values are65da7ce8f88f7ece030e671973235e1ae3c318c2b49cb8d1f53382714191a26c
(archive),092fa41f2af42a3da5cdb88769c0d101fb659e3eb080de61351630594ad57a9b
(SBOM),0e89c158688e3211eb02fb9fa54c7d7f452300f30b5906c4fe44f7d46e4a2140
(manifest) and40daac6af415136e37e28aa15724bdfb8dd3fc3050691c3a66dbeba7b2e2093d
(SHA256SUMS). Fresh downloads passed checksums and GitHub attestation verification. - npm workflow
32660739200
publishedweb-app-security-skill@0.6.0at2026-08-23T19:17:13.071Zthrough GitHub OIDC
trusted publishing. npm records shasum6d83dba33b0d1349873e9b77ffd73da6f88b7396, integrity
sha512-oe0uooh3BWRiHAsmUk9/JIJoFac7pK/2Ey4SEalos2a7Q1JGBoiDfj8FujlveMkXdBxrF4MpwflqlRwaLkiSJg==
and SLSA provenance.
The fresh registry tarball is byte-identical to a package built at the signed source commit. - Published-state commit
a9afb943298d70f1d5a2d8005a4d0a928acb3de8contains the v0.6.0
verifier trust entry;scripts/install-verified.mjsat that commit has SHA-256
1bcc929e7b939c6f5b300d91b928467be4ad809856611bfb53c96e1c39f60e5c. Bootstrap commit
3fa12244dfb70e0588ccf0e645bf5c75b6148b01pins that verifier and has bootstrap SHA-256
22df4c865d01f51b64066c8e53beaa9bb3cb3c29ef431c6b8a3aa56074dab65c. - Final pinning CI run
32661555145
passed all four Node 22/24 by Ubuntu/macOS jobs; CodeQL run
32661555143
passed. Immutable Action run
32661706137
reproduced one ownedGET /api/orders/[id]route with authentication and authorization both
not_observed, priorityreview_next, and no confirmed vulnerability created from those states. - A fresh exact-version npx run and a fresh public-bootstrap CLI install both returned v0.6.0 and
produced the same route semantics and parser identity:@babel/parser7.28.4 with bundle SHA-256
f8d700c78a6d0a50513a672b419074a87597093733d2d69ecee92675d8139698. The isolated installer
explicitly reported that GitHub attestation verification did not run becauseghwas not
authenticated there; fixed checksums, manifest, SBOM, tag and source identity still verified,
while public release attestations had already been verified separately. - Signed movable tag
v1has tag object1ec4442b72a8d36ba9765d88f7d63108e91d6d02
and peels to the immutable v0.6.0 source commit
7521e0699eefe26d23a7972fbee6fb37b46fdfe2. Public consumer run
32661836371
passed the passive-crawl, authorization-rejection and immutable route jobs after promotion.
Artifact identity, provenance and passing consumers do not prove every detector conclusion correct
or an audited project secure. v1 is intentionally movable; use the full source commit when a
workflow must remain immutable.
v0.5.4
v0.5.4 release evidence
Status: published. The signed tag, GitHub Release, npm package with provenance, verified installer
trust entry and signed v1 promotion are publicly verifiable.
Outcome
Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.
v0.5.4 expands the bounded automatic first pass. Five built-in rules cover exact Git tracking of
sensitive .env names, JavaScript session-secret/cookie settings and Python session-cookie/CSRF
settings. Eight project-owned Opengrep rules add same-file request-to-SQL, outbound-URL, file-path
and redirect flows across JavaScript/TypeScript and Python. --profile deep selects the built-in
detector plus the four existing external adapters without downloading them.
The release retains the corrected evidence claim: the self-authored planted suite is named
rule-contract conformance and reports literal positive/negative/state contract results. A separate
historical real-world regression corpus executes four minimized correctness failures and one
review-visible expected benign DOM-sink match against product code.
The main-branch try-now command follows npm latest. Reusable CI, signed release verification and the
trusted installer remain pinned to an immutable version or source commit.
Evidence sets
v0.5.4 rule-contract conformance: 25
built-in risk and 2 evidence-integrity planted positive/negative/state contracts.v0.5.4 historical real-world regressions:
report-summary rendering, pnpm workspace lock inheritance, nested-template coverage,
path-equivalent retest handling and numeric SVG DOM-sink review.Known limitations: parser, evidence-state, incremental-audit and
claim boundaries.
Neither evidence set is a representative production-vulnerability benchmark. Stable detector reach
is 25 built-in risk rules, 2 evidence-integrity rules and 16 opt-in external-adapter rules: 43 total.
Opengrep matches remain same-file suspected leads. A missing deep-profile prerequisite is explicit
unknown evidence and exit 3, never a clean result.
Published verification
The local release gates include:
npm run conformance:rules
npm run regressions:real-world
npm run check
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .The release procedure additionally verifies the signed tag after it exists:
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.5.4Public release facts
- The SSH-signed
v0.5.4tag peels to source commit
d9ee538089ac813dcd454d10b45f14b958c1ec19. Candidate CI run
32648619071
and CodeQL run
32648619088
passed before publication. - GitHub Release workflow
32648846862
published the source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-23. The public
asset SHA-256 values are00742dfe4d0118e8361380314c4fe01ed4e3924db1015d080b882bd3841431a5
(archive),cfa209b59004ce29bbf808eadc37b1fbb8bfd8eb162e462c29661e8d18a592e1
(SBOM),f50d8b974666694ccaebdb583127cc62471536943b028f7057919cf47b4529c1
(manifest) andcbd7d771f81cee065989dc386fef239fc65d2d0966b1ca23fb5c8b9f94bdce12
(SHA256SUMS). - npm workflow
32650181341
publishedweb-app-security-skill@0.5.4at2026-08-23T15:58:01.250Zthrough the configured
GitHub OIDC trusted publisher. npm records shasum
1fb71399684025257e069a63b46eb058cca590d1, integrity
sha512-N9UlD9l05Mmm1El7VFf1CGR6nSSG8msea+JjwlN/uwv7rV8gUbGp3DZlEKO8yFMWw+uqLFyYYBocCD8PTRPUdA==
and SLSA provenance.
A fresh public tarball contained 140 files and matched the signed tag package payload file by file. - The signed movable
v1tag object is
464ba64a4d256dbf3b26f78101730b24a4337bc4and peels to the same immutable source commit.
Public consumer run
32650353548
passed both the passive path and expected authorization rejection.
Artifact identity, signatures and provenance establish origin and byte identity. They do not prove
that every detector conclusion is correct or that a scanned project is secure.
v0.5.3
Web App Security Skill v0.5.3
Web App Security Skill gives Web builders using AI coding agents a reviewable local security first pass. Run it without installing:
npx --yes web-app-security-skill@0.5.3 audit . --fail-on neverThe report explains each lead in security terms and ordinary language, states what the evidence
does not prove, proposes a change for review, names likely product side effects, and separates
security retesting from normal-behavior testing. The command does not edit the project or contact
a deployment.
v0.5.3 also includes the Claude repository plugin, diff-scoped review, the planted pattern
benchmark and public known limitations. These are bounded first-pass capabilities; they do not
prove that a project is secure or establish production-vulnerability precision or recall.
Release identity
- Version/tag:
v0.5.3 - Source identity: the commit peeled from the SSH-signed annotated tag; the exact commit is recorded
inweb-app-security-skill-0.5.3.release.jsonand the provenance attestation. - Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.
- Stable corpus: 20 built-in risk rules, two evidence-integrity rules and eight opt-in external
adapter rules, unchanged from v0.5.2.
This file is part of the source commit it describes and therefore does not embed a fabricated self-
referential source SHA. The signed tag, manifest and provenance establish the published source
identity.
Distribution
The package named web-app-security-skill publishes the real zero-dependency CLI with both
web-app-security-skill and webapp-security bin names. Its explicit file allowlist contains the
runtime, skill instructions, rules, schemas, references, current limitations and benchmark evidence
while excluding repository tests, launch/adoption notes and engineering plans. An isolated packed
artifact runs version and a real source audit through offline npx.
Claude Code can add this repository as marketplace web-app-security and install plugin
web-app-security-skill. The plugin uses the repository-root SKILL.md; no copied detector or
second skill body exists. Both manifests validate with Claude Code 2.1.284, and an isolated Claude
configuration completes marketplace add, plugin install and plugin listing.
Git diff source selection
audit <project> --since <ref> resolves the ref to an immutable commit, scans current tracked source
with full file context and retains exact-location findings on added lines. It records but excludes
untracked files. audit <project> --staged exports and scans the Git index, excluding unstaged
working-tree content.
Path-level findings follow materially changed files. Missing-lockfile conclusions remain visible
when a relevant manifest, workspace file or ancestor lockfile changes. Changed-file parse failures
and global traversal incompleteness remain explicit unknown evidence. Pure content-identical renames
do not replay findings.
Diff modes use the built-in adapter only and cannot use baseline/retest comparison. A clean diff
report does not establish whole-repository safety.
Ground-truth pattern benchmark
npm run benchmark:ground-truth regenerates exact JSON and Markdown results from the stable corpus.
The 20 risk contracts produce TP=20, FN=0, TN=20 and FP=0; the two evidence-integrity contracts
produce TP=2, FN=0, TN=2 and FP=0, with no expected-state mismatch. Tests prove that deleting a
positive observation produces an FN and that a safe-neighbour match produces an FP.
These are synthetic planted pattern-contract results. They do not measure production-vulnerability
precision, recall, language coverage, reachability or exploitability. The five-project ordinary-code
review remains separate evidence.
Known limitations and deferred expansion
KNOWN_LIMITATIONS.md publishes current parser, evidence-state, external-adapter, incremental and
recurring benign-match boundaries. The v0.5.3 architecture decision defers MCP and additional stable
rules. It defines client demand, permission, schema, local transport, distribution and failure tests
for future MCP work, plus fixture, evidence-boundary, false-positive and fail-closed gates for every
future stable rule.
Compatibility and security boundary
- Finding/report v3, persisted-subject comparison and v2 migration semantics remain compatible.
- Syntax and external scanner matches remain
suspecteduntil independent evidence confirms them. - Missing or failed source evidence remains
unknown; unavailable evidence is never a pass. - Passive network defaults, authorization acknowledgements and review-only repair behavior are
unchanged. - This release is not general SAST/DAST coverage, authenticated testing, an MCP service or proof that
a project is secure.
Release verification
The release workflow runs npm run check, rebuilds all four release assets twice and compares every
byte, verifies archive structure, checksums, manifest and SPDX SBOM, exercises isolated install and
upgrade, then requests GitHub build provenance before publication.
Verify the signed tag:
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.5.3The published SHA256SUMS, manifest source commit, git rev-parse 'v0.5.3^{}', GitHub-recorded asset
digests and provenance are verified before immutable asset digests are added to the installer. npm,
verified installation and the mutable v1 alias are promoted only after their public consumers pass.
v0.5.2
v0.5.2 release evidence
Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.
Web App Security Skill v0.5.2 is a focused correctness patch over v0.5.1. It repairs report
rendering, pnpm workspace lockfile evidence, nested JavaScript/TypeScript template coverage and
path-only retest evasion without expanding the stable rule boundary or changing evidence states.
Release identity
- Version/tag:
v0.5.2 - Source identity: the commit peeled from the SSH-signed annotated tag; the exact commit is recorded
inweb-app-security-skill-0.5.2.release.jsonand the provenance attestation. - Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.
- Stable corpus: 20 built-in risk rules, two evidence-integrity rules and eight opt-in external
adapter rules, unchanged from v0.5.1.
This file is part of the source commit it describes and therefore does not embed a fabricated
self-referential source SHA. The signed tag, manifest and provenance establish the published source
identity.
Correctness fixes
Structured risk summaries
The v3 Markdown and HTML renderers now read each state's structured { total, bySeverity } value.
They omit zero-count states and render both state totals and nonzero severity counts. The report's
first risk summary no longer coerces those objects to [object Object].
pnpm workspace lockfiles
The missing-lockfile rule now reads bounded pnpm-workspace.yaml package patterns and recognizes an
applicable ancestor pnpm-lock.yaml. Positive and negative package patterns form an include/exclude
boundary. Unreadable, oversized or unsupported workspace metadata makes the
check incomplete and emits evidence-integrity coverage; it does not produce a confirmed absence.
This parser supports the ordinary string-list form and JSON-compatible inline arrays. It is not a
general YAML implementation. A package excluded from the workspace still needs its own applicable
lockfile.
Nested template coverage
The bounded JavaScript/TypeScript tokenizer now tracks nested template literals and their
expression depth, including templates inside TSX brace expressions. Template text remains ignored
as data while code inside ${...} remains tokenized and scanned. An unterminated template still
produces partial coverage and explicit unknown evidence.
Rename-aware retesting
Retesting now derives a path-independent movement fingerprint from rule identity, adapter identity
and normalized evidence. A unique one-to-one match across old and new paths is reported as
unchanged with reason condition_moved. Duplicate or otherwise ambiguous matches remain separate
new and fixed observations so the comparison does not guess.
Compatibility and security boundary
- Finding/report v3, persisted-subject comparison and v2 migration semantics remain compatible.
- Syntax and external scanner matches remain
suspecteduntil independent evidence confirms them. - Missing or failed source evidence remains
unknown; no parser fix turns unavailable evidence into
a pass. - Passive network defaults, authorization acknowledgements and review-only repair behavior are
unchanged. - This release is not general SAST/DAST coverage, authenticated testing or proof that a project is
secure.
Release verification
The release workflow runs npm run check, rebuilds all four release assets twice and compares every
byte, verifies archive structure, checksums, manifest and SPDX SBOM, exercises isolated install and
upgrade, then requests GitHub build provenance before publication.
Verify the signed tag:
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.5.2After publication, verify SHA256SUMS, compare the manifest source commit with
git rev-parse 'v0.5.2^{}', verify provenance, and only then add the immutable asset digests to the
verified installer. The mutable v1 alias moves only after the public consumer workflow passes.
v0.5.1
v0.5.1 release evidence
Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.
Web App Security Skill v0.5.1 is a compatibility patch over the v0.5.0 source-detection and
understandable-remediation release. It repairs independently reproduced tokenizer and case-study
reproduction defects without expanding the stable rule boundary or changing evidence states.
Release identity
- Version/tag:
v0.5.1 - Source identity: the commit peeled from the SSH-signed annotated tag; the exact commit is recorded
inweb-app-security-skill-0.5.1.release.jsonand the provenance attestation. - Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.
- Stable corpus: 20 built-in risk rules, two evidence-integrity rules and eight opt-in external
adapter rules, unchanged from v0.5.0.
This file is part of the source commit it describes and therefore does not embed a fabricated
self-referential source SHA. The signed tag, manifest and provenance establish the published source
identity.
Correctness fixes
JSX text boundary
The bounded JS/TS tokenizer now tracks JSX tag, child-text and brace-expression states. Text such as
skills/*.yaml or src/*.tsx no longer opens a JavaScript block comment, while expressions, tag
attributes and nested JSX return to code tokenization. A tokenizer failure still produces partial
coverage and explicit unknown evidence; it is never treated as a clean result.
Python raw-string boundary
The Python tokenizer now consumes backslash-quoted characters in raw as well as non-raw strings for
lexical delimiter handling. The reproduced raw regular expression compiles with CPython and now
completes tokenizer coverage. This remains a bounded tokenizer, not a claim of complete Python
grammar or data-flow analysis.
Reproducible ordinary-project evidence
The v0.5.0 five-project evidence retains each original report.json SHA-256 as an archival byte
identity and adds report.semanticDigest. The stable digest covers report schema, ruleset digest,
state summary and sorted finding ID/state pairs. Third parties can run:
node scripts/check-v050-ordinary-review.mjs \
--report <project-id> /path/to/reproduced/report.jsonDirect audits intentionally receive a random ephemeral subject, so their full report bytes are not
claimed to match the author's original report. The new comparison preserves subject isolation while
making the reviewed finding semantics reproducible.
Local TLS fixture isolation
The HTTPS hardening regression test removes inherited SSL_CERT_FILE before setting its owned
CURL_CA_BUNDLE. The reported enterprise-CA failure was not independently reproduced on the release
host; this change removes an unnecessary host-environment input from the fixture.
Compatibility and security boundary
- Finding/report v3, persisted-subject comparison and v2 migration semantics are unchanged.
- Syntax and external scanner matches remain
suspecteduntil independent evidence confirms them. - Missing or failed source evidence remains
unknown; no parser fix turns unavailable evidence into
a pass. - Passive network defaults, authorization acknowledgements and review-only repair behavior are
unchanged. - This release is not general SAST/DAST coverage, authenticated testing or proof that a project is
secure.
Release verification
The release workflow runs npm run check, rebuilds all four release assets twice and compares every
byte, verifies archive structure, checksums, manifest and SPDX SBOM, exercises isolated install and
upgrade, then requests GitHub build provenance before publication.
Verify the signed tag:
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.5.1After publication, verify SHA256SUMS, compare the manifest source commit with
git rev-parse 'v0.5.1^{}', verify provenance, and only then add the immutable asset digests to the
verified installer. The mutable v1 alias moves only after the public consumer workflow passes.
v0.5.0
v0.5.0 release evidence
Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.
Web App Security Skill v0.5.0 expands narrow automated source detection and makes every actionable
source result understandable before a user approves a change. It keeps the evidence discipline and
passive defaults from v0.4.0; it does not turn syntax matches into confirmed vulnerabilities or let
the CLI edit a project unattended.
Release identity
- Version/tag:
v0.5.0 - Source identity: the commit peeled from the SSH-signed annotated tag; the exact 40-character SHA
is also recorded inweb-app-security-skill-0.5.0.release.jsonand the provenance attestation. - Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.
- External adapters: Gitleaks
8.30.1, Opengrep1.27.0, OSV-Scanner2.5.0and Checkov3.3.9,
installed and version-pinned by the caller.
This Markdown file is part of the source commit it describes, so it does not embed a fabricated
self-referential commit SHA. Verify the exact published identity with the signed tag, release
manifest and provenance.
Stable rule boundary
The v0.5.0 stable source and deployment-policy corpus contains exactly 30 rules:
- 20 built-in risk rules: four shared project/configuration checks, eight bounded
JavaScript/TypeScript checks and eight tokenizer-backed Python checks; - two built-in evidence-integrity rules that expose unreadable/failed source observations as
unknownrather than clean; - eight opt-in external-adapter risk rules: two Gitleaks rules, two Opengrep rules, one
OSV-Scanner rule and three Checkov rules.
The machine-readable source of truth is docs/stable-source-rules.json,
and docs/stable-rule-corpus.json links every stable rule to a positive
fixture, safe near-neighbour, expected state, evidence boundary and test entrypoint. Built-in rules
have 22 real observations and 22 planted missing-observation failures. External rules use pinned
real-tool CI fixtures. This demonstrates the documented observation paths, not population-level
precision, recall or exploitability.
Built-in depth is deliberately limited to direct lexical or tokenizer-backed constructs. It does
not prove whole-program input flow, runtime reachability, sanitizer correctness or deployment
exposure. Source patterns and external scanner rows remain suspected unless rule-specific
independent evidence confirms the conclusion.
Explanation and repair contract
Source findings and reports now use v3. Each actionable result retains the professional term and
standards mapping, then also records:
- a plain-language explanation and conditional consequence;
- the evidence that exists and what it cannot prove;
- one reviewable proposal, alternatives and likely product side effects;
- decisions that must remain with the owner;
- separate security and normal-function retests; and
- rollback criteria.
Persisted v2 source baselines remain readable through the compatibility layer and cannot
manufacture a fixed result. A fix is comparable only when subject, scope, rule identity and current
coverage agree. repair-plan and repair-validate create and validate private, non-overwriting
review records with explicit approval and dual-retest states. The CLI does not apply project edits,
deploy changes or migrations.
Adapter decisions
- Opengrep
1.27.0is the stable bounded SAST adapter for two bundled, digest-pinned same-file
request-to-command rules. It is opt-in, does not fetch rules and does not execute project code. - Checkov
3.3.9is the stable bounded deployment adapter for three fixed root Dockerfile/GitHub
Actions rules. It uses--skip-download; it may query PyPI for version metadata but does not
upload project source. - Gitleaks and OSV-Scanner retain the v0.4.0 contracts. OSV data may change with the public advisory
database. None of the adapters is downloaded automatically, and project dependencies are never
installed or executed.
Exact selection evidence, rejected alternatives and failure behavior are in
docs/sast-adapter-benchmark.md,
docs/iac-adapter-benchmark.md and
docs/adapter-protocol.md.
Ordinary-project and demo evidence
The broader built-in v3 path ran against five existing ordinary Web projects at immutable commits,
without probing hosted services or executing project dependencies. All 43 observed findings were
uniquely reviewed: 11 useful leads, 27 expected benign matches, one unknown tokenizer observation
and four confirmed missing-lockfile facts. These are finding classifications, not 43 vulnerabilities
and not a precision/recall result. A zero-finding project is not evidence that the project is secure.
The local network-free demo uses one intentionally unsafe Node.js child-process call. It reports a
suspected CWE-78-shaped lead, states that input flow and reachability are unproven, proposes
execFile with separate arguments, names quoting and cross-platform behavior as side effects, then
records a compatible security retest and an independent functional retest. The demo proves this
bounded workflow, not automatic safe repair.
Release verification
The release workflow runs the full repository gate, builds every artifact twice and compares bytes,
verifies archive paths, the stable rule manifest, release manifest, SHA-256 list and SPDX 2.3 SBOM,
then exercises clean installation and an isolated v0.4.0-to-v0.5.0 lifecycle upgrade. GitHub build
provenance is requested only after these checks pass. External consumers separately exercise the
exact immutable Action source in backward-compatible crawl mode and v0.5.0 source mode before the
stable v1 alias moves.
Verify the published tag after release:
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.5.0Verify downloaded assets with SHA256SUMS, compare the manifest source commit with
git rev-parse 'v0.5.0^{}', and verify GitHub provenance. The built-in verified-installer trust
anchor is updated only after immutable public asset digests exist; until then, the documented
default installer remains the already trusted v0.4.0 release.
Unsupported and known risks
- This is not a general SAST/DAST scanner, authenticated pentest or proof that a project is secure.
- BOLA/IDOR, business logic, LLM/OAuth, database isolation and most framework-specific paths remain
agent-guided and require project context. - Twenty-seven expected benign matches in the bounded ordinary-project review show that lexical
leads still need human review. No precision or recall percentage is claimed. - Authenticated browser DAST, universal language coverage, automatic exploit generation, unattended
patching, deployment and database migration are not provided. - No authenticated third-party deployment, production cloud account or upstream live system was
actively tested for this release. - Native Windows, PowerShell and WSL2 remain unsupported because no maintained verification
environment exists. Node 20 and earlier are not supported release targets. - Signatures, checksums and attestations establish artifact identity and build origin; they do not
prove that every security conclusion or proposed implementation is correct.
v0.4.0
v0.4.0 release evidence
Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.
Web App Security Skill v0.4.0 is the evidence-integrity and useful-detection release. It keeps the
agent-guided hardening methodology while making narrow automated results harder to overstate.
Release identity
- Version/tag:
v0.4.0 - Source identity: the commit peeled from the SSH-signed annotated tag; the exact 40-character SHA
is also recorded inweb-app-security-skill-0.4.0.release.jsonand the provenance attestation. - Runtime matrix: Node.js 22 and 24 on Ubuntu and macOS; Bash 3.2 remains covered on macOS.
- External adapters: Gitleaks
8.30.1and OSV-Scanner2.5.0, installed and pinned by the caller.
The Markdown file is part of the source commit it describes, so it does not embed a fabricated
self-referential commit SHA. Verify the exact published identity with the signed tag and manifest.
Evidence model and migration
Report v2 binds findings to subject, scope, rule revision, adapter and ruleset identity. Per-rule
coverage records discovered, eligible, scanned, excluded, skipped, truncated and failed work. A
missing or incomplete check is explicit unknown/unavailable evidence and cannot establish fixed.
Historical v1 reports remain readable but are never silently comparable. migrate-report records
their original SHA-256 and explicit user binding as non-comparable lineage; a new persisted v2 audit
is required before a later retest can prove a fix. Moved or cloned projects require explicit
rebind acknowledgement rather than path or repository-name inference. See
docs/report-v2-migration.md.
Detection and reporting changes
- Built-in source checks remain deliberately narrow: lockfile absence, environment-named files,
public Node inspector bindings and common production source-map settings. - Gitleaks checks committed history and the working tree. OSV-Scanner checks supported recorded
lockfiles and may query the public OSV advisory service. Neither adapter is downloaded by the
product and project dependencies are not executed. - Every external scanner match is
suspected. Gitleaks does not prove credential validity or
exposure; OSV does not prove reachability, deployed version or exploitability. - Reports separate
security_exposure,supply_chain,search_discoverability,reliabilityand
evidence_integrity. A HIGH discoverability result is not a HIGH security vulnerability. - JSON, Markdown, HTML, SARIF and JUnit are committed as one private atomic evidence bundle after
sanitization and validation. Existing output is not overwritten. - The composite Action keeps v0.3 crawl behavior and adds source mode. External findings require an
acknowledged alert-owner policy before they can affect the configured gate.
Five-project evidence
The dated 2026-08-14 corpus ran the complete v2 source path at immutable commits without probing a
hosted project or executing project dependencies.
| Project | Confirmed | Suspected | Boundary |
|---|---|---|---|
| Linkwarden | 0 | 270 | OSV advisory rows are mutable suspected leads |
| Healthchecks | 0 | 98 | Gitleaks documentation/test matches suspected; OSV not applicable |
| Open WebUI | 0 | 144 | Source-map and OSV leads suspected; public .map delivery unknown |
| Uptime Kuma | 4 | 93 | Four low-severity missing-lockfile facts in independent extra/ tools; external leads suspected |
| Mealie | 0 | 30 | Gitleaks test-material matches suspected |
These records demonstrate applicability, state discipline and false-positive closure. They are not
labelled benchmark data and do not support a precision/recall score. OSV counts can change as its
public advisory database changes. Reproduction commands and unreached surfaces are in
docs/case-studies/journeys/.
Regressions fixed
- Cross-project, tampered, forged, v1 or incomplete baselines cannot manufacture a fixed result.
- Deep, large, unreadable, malformed and truncated source candidates remain visible in coverage.
- Crawler-range, sitemap and AWS permission failures become unknown evidence, never a clean result.
- Cross-domain severity is no longer combined into one security headline.
- Evidence writes are private, atomic, non-overwriting and rolled back after handled failures.
- External-tool missing/version/timeout/error/malformed paths fail closed; upstream OSV severity
cannot inflate local severity. - Duplicate Gitleaks rows are deduplicated while distinct fingerprints remain distinct; finding IDs
survive sanitizer patterns that resemble numeric account identifiers.
The complete bug-to-test map is docs/regression-inventory.md.
Release verification
The release workflow runs the full gate, builds every artifact twice and compares bytes, verifies
archive paths, manifest, SHA-256 list and SPDX 2.3 SBOM, then exercises an isolated v0.3.0-to-v0.4.0
upgrade plus clean install/version/start/upgrade/uninstall behavior. GitHub provenance is requested
only after those checks pass. A separate consumer repository verifies both backward-compatible crawl
mode and built-in source mode against the exact candidate/release commit.
Verify the published tag after release:
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.4.0Verify downloaded assets with SHA256SUMS, then compare the manifest source commit with
git rev-parse 'v0.4.0^{}' and verify GitHub provenance. The post-publication verifier now trusts
the immutable v0.4.0 asset digests, and the documented bootstrap pins and verifies that verifier
before installation.
Unsupported and unknown
- This is not a general SAST/DAST scanner, authenticated pentest or automatic patching system.
- BOLA/IDOR, business logic, LLM/OAuth, database isolation and most framework-specific sinks remain
agent-guided and require project context. - No authenticated third-party deployment, production cloud account or upstream live system was
actively tested for this release. - Native Windows, PowerShell and WSL2 are unsupported because no maintained verification environment
exists. Node 20 and earlier are not supported release targets. - Release signatures, checksums and attestations establish artifact identity and build origin; they
do not prove every security conclusion is correct or that an installed project is secure.