Releases: rabindra789/periperi
Release list
Periperi 0.3.0
Periperi 0.3.0
Local cryptographic discovery, risk diagnostics and CBOM export for VS Code. This release
adds post-quantum algorithm awareness, certificate lifecycle findings and key-strength
validation, and moves the engine source into the repository so it can be built and checked
in place. Source text is passed only to a local Python process and is never sent to an
external service. The underlying rule engine is ECDAT.
Extension ID: thesixbugs.periperi
Highlights
- Post-quantum algorithms are now first-class — ML-KEM, ML-DSA and SLH-DSA (plus the
Kyber, Dilithium and SPHINCS+ aliases) are detected in source text and in binaries, are
reported asnot_applicablefor quantum risk, and confirm whether the implementation
matches FIPS 203/204/205. Every quantum-vulnerable family now names its concrete
migration target. - Certificate lifecycle, from the parsed certificate — expired certificates, expiry
within 30 days, not-yet-valid certificates, self-signed issuing CAs, subject alternative
names and key usage are read from the real X.509 structure instead of being inferred. - Key-strength validation — RSA public exponents below 65537 are reported as high risk,
and curves below the recommended 128-bit floor (secp192r1, secp224r1, sect curves,
BrainpoolP256) are flagged. OpenSSH public keys and PKCS#12 key parameters are parsed too. - SPKI fingerprints — a SHA-256 SubjectPublicKeyInfo digest is recorded for every parsed
key and certificate, for inventory and pinning work. - Password-based KDF guidance — PBKDF2 configurations with an iteration count below
600000 are reported as high risk, with Argon2 and scrypt as the recommended alternatives. - Unsaved manifests are inventoried —
requirements.txt,pyproject.toml,
Cargo.toml,go.modandpackage.jsonare parsed from the editor buffer, so findings
appear before the file is saved to disk. - Engine capabilities on demand —
--versionand--capabilitiesreport the engine
version, CBOM schema, Python version and OpenSSL, Syft and Trivy availability without
running a scan.
Commands
| Command | ID |
|---|---|
| Periperi: Scan Current File | ecdat.scanCurrentFile |
| Periperi: Scan Workspace | ecdat.scanWorkspace |
| Periperi: Scan Binary, Certificate, Key or Container | ecdat.scanArtifact |
| Periperi: Show Cryptographic Report | ecdat.showReport |
| Periperi: Export CBOM | ecdat.exportCbom |
| Periperi: Clear Findings | ecdat.clearDiagnostics |
Command IDs and the ecdat.* settings namespace are unchanged, so existing settings and
keybindings keep working.
New detection coverage
- Post-quantum: ML-KEM, ML-DSA, SLH-DSA, and the Kyber, Dilithium and SPHINCS+ aliases.
- Algorithms: AES-KW, HMAC, SHA-512/256, BLAKE2, plus Google Tink and the AWS Encryption
SDK as libraries. - Key derivation: Argon2, scrypt, PBKDF2, and a low PBKDF2 iteration count as its own
finding. - Tokens and protocols: JOSE algorithm selection (
alg,alg=none, RS/PS/ES/EdDSA/HS
families), cipher-suite names and certificate-pinning configuration. - Certificates and keys: expired and expiring-soon certificates, weak RSA public
exponents, weak elliptic curves, SPKI fingerprints, OpenSSH public keys.
Overlapping matches are suppressed: a line with ML-DSA reports ML-DSA and not DSA, and
SHA-512/256 reports SHA-512/256 and not SHA-512. A bare AES-256-GCM is reported as an
algorithm, not as a cipher suite.
Safety and privacy
- Key material is redacted from reported evidence, and now on any line containing a PEM
key header or a long base64 blob, not only on private-key headers. - A single artifact that OpenSSL cannot parse no longer aborts the whole scan; the failure is
contained and the scan continues. - Peripheri never executes project code, scanned binaries or container layers, and never
makes network requests.
Build and development
The engine source now lives in backend/ at the repository root, and
vscode-extension/engine/backend/ is the packaged copy that
vscode-extension/scripts/prepare-engine.mjs fills in. The TypeScript sources and
tsconfig.json are also present, so the checks that could not run in 0.2.0 now do:
| Command | Purpose |
|---|---|
npm run check |
Type-check the extension without emitting |
npm run prepare-engine |
Copy backend/ into the engine and vendor the platform runtimes |
npm run package |
Build periperi-0.3.0.vsix |
out/extension.js, backend/app/scanner.py, backend/app/container_tools.py,
backend/app/dependencies.py and both readme files are unchanged from 0.2.0.
Prototype limits
Detection is pattern- and rule-based and can produce false positives. Validate findings
before making security decisions. Syft and Trivy output depends on those tools' own
vulnerability databases.
The quantum-risk rating applies Mosca's X + Y > Z inequality and is limited to
quantum-vulnerable public-key algorithms; other findings report not_applicable.
Known limitations in this release
- Because the compiled
out/extension.jsbundle is unchanged, its status bar, notifications,
report panel and CBOM output are still labelled "ECDAT". The manifest, the Command Palette
titles and the package filename use the Periperi name. out/extension.jsends with a//# sourceMappingURL=extension.js.mapreference, but that
map is not shipped, so stack traces from the extension will not map back to original
TypeScript positions.ecdat.maxWorkspaceFilesis declared but not yet read by the bundle; the engine applies its
own size and file-count limits.- The published
.vsixships without the platform Python runtimes, as in 0.2.0. Run
npm run prepare-enginebefore packaging if you want them bundled. - No licence file is published, so the package remains unlicensed.
Install
Download periperi-0.3.0.vsix below, then in VS Code run
Extensions: Install from VSIX...
Full changelog
See CHANGELOG.md.
SHA-256 of the attached asset:
0FF563B04BFAC42A5C39B861895E81895BA90EB731B2DADF8665D49CBC2CFC4A
Periperi 0.2.0
Periperi 0.2.0
Local cryptographic discovery, risk diagnostics and CBOM export for VS Code, now with
real OpenSSL-backed artifact parsing, binary fingerprinting and optional Syft/Trivy
container analysis. Source text is passed only to a local Python process and is never
sent to an external service. The underlying rule engine is ECDAT.
Extension ID: thesixbugs.periperi
Highlights
- New command: Periperi: Scan Binary, Certificate, Key or Container — pick a repository
archive, container image, binary, certificate or key from disk for a full local scan. - Real parsing instead of pattern matching — X.509 certificates, PEM/DER keys and
PKCS#12 stores are parsed with thecryptographyOpenSSL backend, so key size, curve,
subject, expiry and signature algorithm are reported from the actual structure. Key
material is never displayed. - Binary fingerprinting —
.exe,.dll,.so,.dylib,.jar,.wasm,.apkand
more are fingerprinted from embedded crypto symbols, without being executed. - Container images — OCI/Docker archives are detected, their layers expanded, and the
cryptographic package inventory read through Syft, with Trivy vulnerabilities mapped onto
crypto packages. - Configurable quantum risk — the data-lifetime, migration-time and threat-timeline
assumptions behind Mosca's inequality are now settings, and every finding reports the
resultingx,y,zandmargin.
Commands
| Command | ID |
|---|---|
| Periperi: Scan Current File | ecdat.scanCurrentFile |
| Periperi: Scan Workspace | ecdat.scanWorkspace |
| Periperi: Scan Binary, Certificate, Key or Container | ecdat.scanArtifact |
| Periperi: Show Cryptographic Report | ecdat.showReport |
| Periperi: Export CBOM | ecdat.exportCbom |
| Periperi: Clear Findings | ecdat.clearDiagnostics |
Command IDs and the ecdat.* settings namespace are unchanged, so existing settings and
keybindings keep working.
Detection coverage
- Algorithms: AES, AES-GCM, AES-256-GCM, AES-ECB, RSA, RSA-1024, RSA-2048, ECDSA,
ECDH, ECC, Diffie-Hellman, DSA, SHA-1, SHA-256, SHA-384, SHA-512, MD5, ChaCha20. - Libraries: OpenSSL (including
libcrypto/libssland theEVP_*APIs), PyCryptodome,
Pythoncryptography, libsodium, Bouncy Castle, Web Crypto API, Nodecrypto. - Key material: PEM private/public key headers, and any key OpenSSL can parse, reported
without exposing the material. - Containers: OCI/Docker archives, plus the Syft package inventory and Trivy
vulnerabilities for the cryptographic packages inside them.
The most specific match on a line wins: a line containing AES-256-GCM reports
AES-256-GCM, not AES-GCM and not AES.
Settings
| Setting | Default | Purpose |
|---|---|---|
ecdat.scanOnSave |
true |
Scan supported files when they are saved |
ecdat.pythonPath |
python |
Python executable used to run the local engine |
ecdat.engineRoot |
(empty) | Engine root, when the extension folder is outside the repository |
ecdat.dataSensitivity |
pii |
Data-lifetime assumption (X) for the quantum-risk model |
ecdat.migrationComplexity |
standard_application |
Migration-time assumption (Y) for the quantum-risk model |
ecdat.threatTimeline |
15 |
Assumed quantum threat timeline in years (Z) |
ecdat.maxWorkspaceFiles |
2000 |
Declared file cap for a manual workspace scan |
Requirements
Python 3 must be available locally. Scanning is split by depth:
- Source scanning (scan on save, Scan Current File) uses the source detector, which is
Python standard library only and needs no extra packages. - Full scanning (Scan Workspace, Scan Binary/Certificate/Key/Container) parses
certificates, keys and binaries with Pythoncryptography. Install it from the
repository root withpython -m pip install -r requirements.txt. - Container images additionally shell out to Syft and Trivy, which are separate
command-line tools rather than Python packages. Install them and put them onPATHto
enable those checks; the scan still runs without them and reports the tools as
unavailable.
If the extension cannot find the bundled engine, set ecdat.engineRoot to the directory
that contains engine/backend/app/vscode_bridge.py.
On some Windows Python installations a
python*._pthfile forces isolated mode, which
removes the working directory fromsys.path. The engine then fails with
ModuleNotFoundError: No module named 'backend', andpipitself is unavailable.
Remove that file, or pointecdat.pythonPathat an interpreter that does not have one.
Install
Download periperi-0.2.0.vsix below, then in VS Code run
Extensions: Install from VSIX...
Safety and privacy
- Save-time scanning covers supported text files up to 2 MB; full scanning applies 2 MB per
text file, 25 MB per binary, 100 MB per upload, 250 MB of expanded archive contents and
25,000 files per scan. - Archive extraction rejects absolute and
..member paths and skips symlinks and hard
links. - Key material is redacted from reported evidence, and any
secret/password/token/
private_keyassignment value is stripped. - Periperi never executes project code, scanned binaries or container layers, and never
makes network requests.
Prototype limits
Detection is pattern- and rule-based and can produce false positives. Validate findings
before making security decisions. Syft and Trivy output depends on those tools' own
vulnerability databases.
The quantum-risk rating applies Mosca's X + Y > Z inequality and is limited to
quantum-vulnerable public-key algorithms; other findings report not_applicable.
Known limitations in this release
- The TypeScript sources (
src/) andtsconfig.jsonare not present in this repository, so
npm run compile,watch,checkandprepare-enginedo not run. The compiled
out/extension.jsis committed andnpm run packagebuilds the.vsixdirectly from it. - Because the bundle cannot be recompiled, its status bar, notifications, report panel and
CBOM output are still labelled "ECDAT". The manifest, the Command Palette titles and the
package filename use the Periperi name. Restoring the TypeScript sources would let the
remaining strings be renamed at source. out/extension.jsends with a//# sourceMappingURL=extension.js.mapreference, but that
map is not shipped, so stack traces from the extension will not map back to original
TypeScript positions.ecdat.maxWorkspaceFilesis declared but not yet read by the bundle; the engine applies
the limits listed above.- No licence file is published, so the package remains unlicensed.
Full changelog
See CHANGELOG.md.
SHA-256 of the attached asset:
82C99C20F8DD3DDC13B15B0A5BBBF4E30179850D576164DF9865B914FCEF1487
Periperi 0.1.0
Periperi 0.1.0
First release of Periperi, a VS Code extension for local cryptographic discovery,
risk diagnostics and CBOM export. Source text is passed only to a local Python
process and is never sent to an external service. The underlying rule engine is
ECDAT.
Extension ID: thesixbugs.periperi
Features
- Scan the active file from the Command Palette or the editor context menu
- Scan supported files automatically on save
- Findings on the correct line and in the Problems panel, rated classical and quantum risk
- Full workspace scan with progress feedback and cancellation
- Cryptographic report rendered in a webview panel
- Export current findings as a JSON CBOM
Settings
| Setting | Default | Purpose |
|---|---|---|
ecdat.scanOnSave |
true |
Scan supported files when they are saved |
ecdat.pythonPath |
python |
Python executable used to run the local engine |
ecdat.engineRoot |
(empty) | Engine root, when the extension folder sits outside the repository |
ecdat.dataSensitivity |
pii |
Data-lifetime assumption for the quantum-risk model |
ecdat.migrationComplexity |
standard_application |
Migration-time assumption for the quantum-risk model |
ecdat.threatTimeline |
15 |
Assumed quantum threat timeline in years |
ecdat.maxWorkspaceFiles |
2000 |
File cap for a manual workspace scan |
Requirements
Python 3 must be available locally. The detector is Python standard library only,
so there are no third-party packages to install. No Periperi server is required.
If the engine cannot be found, set ecdat.engineRoot to the directory containing
engine/backend/app/vscode_bridge.py.
On some Windows Python installations a
python*._pthfile forces isolated mode,
which drops the working directory fromsys.pathand makes the engine fail with
ModuleNotFoundError: No module named 'backend'. Remove that file or point
ecdat.pythonPathat an interpreter that does not have one.
Install
Download periperi-0.1.0.vsix below, then in VS Code run
Extensions: Install from VSIX...
Prototype limits
Detection is pattern-based and can produce false positives. Validate findings
before making security decisions. Save-time scanning covers supported text files
up to 2 MB and never executes project code. Key material is redacted from reported
evidence.
The quantum-risk rating applies Mosca's X + Y > Z inequality and is limited to
quantum-vulnerable public-key algorithms; other findings report not_applicable.
Known limitations in this release
- The TypeScript sources (
src/) andtsconfig.jsonare not present in this
repository, sonpm run compile,watch,checkandprepare-enginedo not
run. The compiledout/extension.jsis committed, andnpm run packagebuilds
the.vsixdirectly from it. - Because the bundle cannot be recompiled, its status bar, notifications, report
panel and CBOM output are still labelled "ECDAT". The manifest, the Command
Palette titles and the package filename use the Periperi name. Restoring the
TypeScript sources would let the remaining strings be renamed at source. - The command IDs and the
ecdat.*settings namespace are unchanged, so existing
settings and keybindings keep working. out/extension.jsends with a//# sourceMappingURL=extension.js.map
reference, but that map is not shipped, so stack traces from the extension will
not map back to original TypeScript positions.
SHA-256 of the attached asset:
6ADD1B4CDB19357F5173A1EC529943C5D4357F255BCFE16126F6CEF18C2FAC05