Skip to content

Releases: rabindra789/periperi

Periperi 0.3.0

Choose a tag to compare

@rabindra789 rabindra789 released this 26 Sep 09:23

Periperi 0.3.0

Local cryptographic discovery, risk diagnostics and CBOM export for VS Code. This release
adds post-quantum algorithm awareness, certificate lifecycle findings and key-strength
validation, and moves the engine source into the repository so it can be built and checked
in place. Source text is passed only to a local Python process and is never sent to an
external service. The underlying rule engine is ECDAT.

Extension ID: thesixbugs.periperi

Highlights

  • Post-quantum algorithms are now first-class — ML-KEM, ML-DSA and SLH-DSA (plus the
    Kyber, Dilithium and SPHINCS+ aliases) are detected in source text and in binaries, are
    reported as not_applicable for quantum risk, and confirm whether the implementation
    matches FIPS 203/204/205. Every quantum-vulnerable family now names its concrete
    migration target.
  • Certificate lifecycle, from the parsed certificate — expired certificates, expiry
    within 30 days, not-yet-valid certificates, self-signed issuing CAs, subject alternative
    names and key usage are read from the real X.509 structure instead of being inferred.
  • Key-strength validation — RSA public exponents below 65537 are reported as high risk,
    and curves below the recommended 128-bit floor (secp192r1, secp224r1, sect curves,
    BrainpoolP256) are flagged. OpenSSH public keys and PKCS#12 key parameters are parsed too.
  • SPKI fingerprints — a SHA-256 SubjectPublicKeyInfo digest is recorded for every parsed
    key and certificate, for inventory and pinning work.
  • Password-based KDF guidance — PBKDF2 configurations with an iteration count below
    600000 are reported as high risk, with Argon2 and scrypt as the recommended alternatives.
  • Unsaved manifests are inventoried — requirements.txt, pyproject.toml,
    Cargo.toml, go.mod and package.json are parsed from the editor buffer, so findings
    appear before the file is saved to disk.
  • Engine capabilities on demand — --version and --capabilities report the engine
    version, CBOM schema, Python version and OpenSSL, Syft and Trivy availability without
    running a scan.

Commands

Command ID
Periperi: Scan Current File ecdat.scanCurrentFile
Periperi: Scan Workspace ecdat.scanWorkspace
Periperi: Scan Binary, Certificate, Key or Container ecdat.scanArtifact
Periperi: Show Cryptographic Report ecdat.showReport
Periperi: Export CBOM ecdat.exportCbom
Periperi: Clear Findings ecdat.clearDiagnostics

Command IDs and the ecdat.* settings namespace are unchanged, so existing settings and
keybindings keep working.

New detection coverage

  • Post-quantum: ML-KEM, ML-DSA, SLH-DSA, and the Kyber, Dilithium and SPHINCS+ aliases.
  • Algorithms: AES-KW, HMAC, SHA-512/256, BLAKE2, plus Google Tink and the AWS Encryption
    SDK as libraries.
  • Key derivation: Argon2, scrypt, PBKDF2, and a low PBKDF2 iteration count as its own
    finding.
  • Tokens and protocols: JOSE algorithm selection (alg, alg=none, RS/PS/ES/EdDSA/HS
    families), cipher-suite names and certificate-pinning configuration.
  • Certificates and keys: expired and expiring-soon certificates, weak RSA public
    exponents, weak elliptic curves, SPKI fingerprints, OpenSSH public keys.

Overlapping matches are suppressed: a line with ML-DSA reports ML-DSA and not DSA, and
SHA-512/256 reports SHA-512/256 and not SHA-512. A bare AES-256-GCM is reported as an
algorithm, not as a cipher suite.

Safety and privacy

  • Key material is redacted from reported evidence, and now on any line containing a PEM
    key header or a long base64 blob, not only on private-key headers.
  • A single artifact that OpenSSL cannot parse no longer aborts the whole scan; the failure is
    contained and the scan continues.
  • Peripheri never executes project code, scanned binaries or container layers, and never
    makes network requests.

Build and development

The engine source now lives in backend/ at the repository root, and
vscode-extension/engine/backend/ is the packaged copy that
vscode-extension/scripts/prepare-engine.mjs fills in. The TypeScript sources and
tsconfig.json are also present, so the checks that could not run in 0.2.0 now do:

Command Purpose
npm run check Type-check the extension without emitting
npm run prepare-engine Copy backend/ into the engine and vendor the platform runtimes
npm run package Build periperi-0.3.0.vsix

out/extension.js, backend/app/scanner.py, backend/app/container_tools.py,
backend/app/dependencies.py and both readme files are unchanged from 0.2.0.

Prototype limits

Detection is pattern- and rule-based and can produce false positives. Validate findings
before making security decisions. Syft and Trivy output depends on those tools' own
vulnerability databases.

The quantum-risk rating applies Mosca's X + Y > Z inequality and is limited to
quantum-vulnerable public-key algorithms; other findings report not_applicable.

Known limitations in this release

  • Because the compiled out/extension.js bundle is unchanged, its status bar, notifications,
    report panel and CBOM output are still labelled "ECDAT". The manifest, the Command Palette
    titles and the package filename use the Periperi name.
  • out/extension.js ends with a //# sourceMappingURL=extension.js.map reference, but that
    map is not shipped, so stack traces from the extension will not map back to original
    TypeScript positions.
  • ecdat.maxWorkspaceFiles is declared but not yet read by the bundle; the engine applies its
    own size and file-count limits.
  • The published .vsix ships without the platform Python runtimes, as in 0.2.0. Run
    npm run prepare-engine before packaging if you want them bundled.
  • No licence file is published, so the package remains unlicensed.

Install

Download periperi-0.3.0.vsix below, then in VS Code run
Extensions: Install from VSIX...

Full changelog

See CHANGELOG.md.

SHA-256 of the attached asset:

0FF563B04BFAC42A5C39B861895E81895BA90EB731B2DADF8665D49CBC2CFC4A

Periperi 0.2.0

Choose a tag to compare

@rabindra789 rabindra789 released this 26 Sep 08:25

Periperi 0.2.0

Local cryptographic discovery, risk diagnostics and CBOM export for VS Code, now with
real OpenSSL-backed artifact parsing, binary fingerprinting and optional Syft/Trivy
container analysis. Source text is passed only to a local Python process and is never
sent to an external service. The underlying rule engine is ECDAT.

Extension ID: thesixbugs.periperi

Highlights

  • New command: Periperi: Scan Binary, Certificate, Key or Container — pick a repository
    archive, container image, binary, certificate or key from disk for a full local scan.
  • Real parsing instead of pattern matching — X.509 certificates, PEM/DER keys and
    PKCS#12 stores are parsed with the cryptography OpenSSL backend, so key size, curve,
    subject, expiry and signature algorithm are reported from the actual structure. Key
    material is never displayed.
  • Binary fingerprinting — .exe, .dll, .so, .dylib, .jar, .wasm, .apk and
    more are fingerprinted from embedded crypto symbols, without being executed.
  • Container images — OCI/Docker archives are detected, their layers expanded, and the
    cryptographic package inventory read through Syft, with Trivy vulnerabilities mapped onto
    crypto packages.
  • Configurable quantum risk — the data-lifetime, migration-time and threat-timeline
    assumptions behind Mosca's inequality are now settings, and every finding reports the
    resulting x, y, z and margin.

Commands

Command ID
Periperi: Scan Current File ecdat.scanCurrentFile
Periperi: Scan Workspace ecdat.scanWorkspace
Periperi: Scan Binary, Certificate, Key or Container ecdat.scanArtifact
Periperi: Show Cryptographic Report ecdat.showReport
Periperi: Export CBOM ecdat.exportCbom
Periperi: Clear Findings ecdat.clearDiagnostics

Command IDs and the ecdat.* settings namespace are unchanged, so existing settings and
keybindings keep working.

Detection coverage

  • Algorithms: AES, AES-GCM, AES-256-GCM, AES-ECB, RSA, RSA-1024, RSA-2048, ECDSA,
    ECDH, ECC, Diffie-Hellman, DSA, SHA-1, SHA-256, SHA-384, SHA-512, MD5, ChaCha20.
  • Libraries: OpenSSL (including libcrypto/libssl and the EVP_* APIs), PyCryptodome,
    Python cryptography, libsodium, Bouncy Castle, Web Crypto API, Node crypto.
  • Key material: PEM private/public key headers, and any key OpenSSL can parse, reported
    without exposing the material.
  • Containers: OCI/Docker archives, plus the Syft package inventory and Trivy
    vulnerabilities for the cryptographic packages inside them.

The most specific match on a line wins: a line containing AES-256-GCM reports
AES-256-GCM, not AES-GCM and not AES.

Settings

Setting Default Purpose
ecdat.scanOnSave true Scan supported files when they are saved
ecdat.pythonPath python Python executable used to run the local engine
ecdat.engineRoot (empty) Engine root, when the extension folder is outside the repository
ecdat.dataSensitivity pii Data-lifetime assumption (X) for the quantum-risk model
ecdat.migrationComplexity standard_application Migration-time assumption (Y) for the quantum-risk model
ecdat.threatTimeline 15 Assumed quantum threat timeline in years (Z)
ecdat.maxWorkspaceFiles 2000 Declared file cap for a manual workspace scan

Requirements

Python 3 must be available locally. Scanning is split by depth:

  • Source scanning (scan on save, Scan Current File) uses the source detector, which is
    Python standard library only and needs no extra packages.
  • Full scanning (Scan Workspace, Scan Binary/Certificate/Key/Container) parses
    certificates, keys and binaries with Python cryptography. Install it from the
    repository root with python -m pip install -r requirements.txt.
  • Container images additionally shell out to Syft and Trivy, which are separate
    command-line tools rather than Python packages. Install them and put them on PATH to
    enable those checks; the scan still runs without them and reports the tools as
    unavailable.

If the extension cannot find the bundled engine, set ecdat.engineRoot to the directory
that contains engine/backend/app/vscode_bridge.py.

On some Windows Python installations a python*._pth file forces isolated mode, which
removes the working directory from sys.path. The engine then fails with
ModuleNotFoundError: No module named 'backend', and pip itself is unavailable.
Remove that file, or point ecdat.pythonPath at an interpreter that does not have one.

Install

Download periperi-0.2.0.vsix below, then in VS Code run
Extensions: Install from VSIX...

Safety and privacy

  • Save-time scanning covers supported text files up to 2 MB; full scanning applies 2 MB per
    text file, 25 MB per binary, 100 MB per upload, 250 MB of expanded archive contents and
    25,000 files per scan.
  • Archive extraction rejects absolute and .. member paths and skips symlinks and hard
    links.
  • Key material is redacted from reported evidence, and any secret/password/token/
    private_key assignment value is stripped.
  • Periperi never executes project code, scanned binaries or container layers, and never
    makes network requests.

Prototype limits

Detection is pattern- and rule-based and can produce false positives. Validate findings
before making security decisions. Syft and Trivy output depends on those tools' own
vulnerability databases.

The quantum-risk rating applies Mosca's X + Y > Z inequality and is limited to
quantum-vulnerable public-key algorithms; other findings report not_applicable.

Known limitations in this release

  • The TypeScript sources (src/) and tsconfig.json are not present in this repository, so
    npm run compile, watch, check and prepare-engine do not run. The compiled
    out/extension.js is committed and npm run package builds the .vsix directly from it.
  • Because the bundle cannot be recompiled, its status bar, notifications, report panel and
    CBOM output are still labelled "ECDAT". The manifest, the Command Palette titles and the
    package filename use the Periperi name. Restoring the TypeScript sources would let the
    remaining strings be renamed at source.
  • out/extension.js ends with a //# sourceMappingURL=extension.js.map reference, but that
    map is not shipped, so stack traces from the extension will not map back to original
    TypeScript positions.
  • ecdat.maxWorkspaceFiles is declared but not yet read by the bundle; the engine applies
    the limits listed above.
  • No licence file is published, so the package remains unlicensed.

Full changelog

See CHANGELOG.md.

SHA-256 of the attached asset:

82C99C20F8DD3DDC13B15B0A5BBBF4E30179850D576164DF9865B914FCEF1487

Periperi 0.1.0

Choose a tag to compare

@rabindra789 rabindra789 released this 26 Sep 06:00

Periperi 0.1.0

First release of Periperi, a VS Code extension for local cryptographic discovery,
risk diagnostics and CBOM export. Source text is passed only to a local Python
process and is never sent to an external service. The underlying rule engine is
ECDAT.

Extension ID: thesixbugs.periperi

Features

  • Scan the active file from the Command Palette or the editor context menu
  • Scan supported files automatically on save
  • Findings on the correct line and in the Problems panel, rated classical and quantum risk
  • Full workspace scan with progress feedback and cancellation
  • Cryptographic report rendered in a webview panel
  • Export current findings as a JSON CBOM

Settings

Setting Default Purpose
ecdat.scanOnSave true Scan supported files when they are saved
ecdat.pythonPath python Python executable used to run the local engine
ecdat.engineRoot (empty) Engine root, when the extension folder sits outside the repository
ecdat.dataSensitivity pii Data-lifetime assumption for the quantum-risk model
ecdat.migrationComplexity standard_application Migration-time assumption for the quantum-risk model
ecdat.threatTimeline 15 Assumed quantum threat timeline in years
ecdat.maxWorkspaceFiles 2000 File cap for a manual workspace scan

Requirements

Python 3 must be available locally. The detector is Python standard library only,
so there are no third-party packages to install. No Periperi server is required.

If the engine cannot be found, set ecdat.engineRoot to the directory containing
engine/backend/app/vscode_bridge.py.

On some Windows Python installations a python*._pth file forces isolated mode,
which drops the working directory from sys.path and makes the engine fail with
ModuleNotFoundError: No module named 'backend'. Remove that file or point
ecdat.pythonPath at an interpreter that does not have one.

Install

Download periperi-0.1.0.vsix below, then in VS Code run
Extensions: Install from VSIX...

Prototype limits

Detection is pattern-based and can produce false positives. Validate findings
before making security decisions. Save-time scanning covers supported text files
up to 2 MB and never executes project code. Key material is redacted from reported
evidence.

The quantum-risk rating applies Mosca's X + Y > Z inequality and is limited to
quantum-vulnerable public-key algorithms; other findings report not_applicable.

Known limitations in this release

  • The TypeScript sources (src/) and tsconfig.json are not present in this
    repository, so npm run compile, watch, check and prepare-engine do not
    run. The compiled out/extension.js is committed, and npm run package builds
    the .vsix directly from it.
  • Because the bundle cannot be recompiled, its status bar, notifications, report
    panel and CBOM output are still labelled "ECDAT". The manifest, the Command
    Palette titles and the package filename use the Periperi name. Restoring the
    TypeScript sources would let the remaining strings be renamed at source.
  • The command IDs and the ecdat.* settings namespace are unchanged, so existing
    settings and keybindings keep working.
  • out/extension.js ends with a //# sourceMappingURL=extension.js.map
    reference, but that map is not shipped, so stack traces from the extension will
    not map back to original TypeScript positions.

SHA-256 of the attached asset:

6ADD1B4CDB19357F5173A1EC529943C5D4357F255BCFE16126F6CEF18C2FAC05