ExploitSpec v0.2.0 adds a bounded, local-only path from a HAR 1.2 capture to a
reviewable version 1 security regression spec.
HAR import
exploitspec import har --list first prints value-free request summaries. An
explicit one-based --entry is then required to create a spec; no request is
selected implicitly and no captured traffic is replayed.
The generated YAML replaces the captured origin, path segments, query and form
names and values, supported header values, JSON object keys, and JSON string
leaves with positional EXPLOITSPEC_HAR_* environment placeholders. Importing
a capture never authorizes its target: non-loopback execution still requires an
explicit run --allow-host decision.
The importer accepts at most 8 MiB and 256 entries, caps generated placeholders
at 4,096, and keeps the ordinary 1 MiB spec limit. Ambiguous JSON members,
custom header names, encoded or binary bodies, multipart data, opaque media
types, and JSON numbers, booleans, or null values fail closed. The documented
format remains version 1.
Distribution integrity
The release contains Linux, macOS, and Windows archives plus SHA256SUMS.
GitHub build-provenance attestations cover every archive and the checksum
manifest and can be checked with gh attestation verify.
Full comparison: v0.1.0...v0.2.0