Repository navigation
Releases: ryanvmorais/webvigil
Release list
WebVigil 1.1.0
A minor release: new options, detector improvements and hardening, all backward compatible. No exit code, existing check id or JSON report field changes.
- Single-page applications:
--harseeds the crawl and the injection pass from a browser or proxy recording, so an app that builds its pages in JavaScript is no longer one empty page. - Detectors: a
<select>is now fuzzed,--file-uploadreaches servers that filter by part type, blind SQL injection is found when a field ships empty, and aGETform that changes state is flagged. - Targets: a one-label host (
http://app:8000/, a Compose service name) or an IPv6 literal is accepted;[http] total_timeout_sbounds a whole request. - Dashboard and Web API: every page has a nonce-based Content-Security-Policy; the API refuses cross-origin state changes, and reports are served with
nosniffand a sandbox policy. - Upgrade:
pipx upgrade webvigilordocker pull ghcr.io/ryanvmorais/webvigil:1.1.0
Scan only systems you own or have permission to test. What is and is not promised across versions: docs/stability.md.
Full list of what changed in 1.1.0: CHANGELOG
WebVigil 1.0.4
A patch release with one fix: a robots.txt, a sitemap or a page served by the scanned site can no longer keep a scan busy for a long time or make it use a lot of memory.
- The crawl reads at most 20 sitemaps and 10,000 sitemap URLs, 20,000 links per page, 500 forms per page and 1,000 controls per form, and keeps at most 2,000 forms and a bounded set of URLs seen.
- The pages fetched are the same while
max_pagesis within those limits, and a scan warning says when a limit was reached. - A link, a form or a sitemap past a limit is left out.
- Upgrade with
pip install -U webvigilor pullghcr.io/ryanvmorais/webvigil:1.0.4. Nothing in the CLI, the exit codes, the configuration keys, the check ids or the JSON report changes.
Use WebVigil only on systems you own or are authorized in writing to test.
Security advisory: GHSA-63j8-4f3v-r77j
Full list of changes: CHANGELOG.md
WebVigil 1.0.3
A patch release with one fix: a page, a script or an API description served by the scanned site can no longer keep a scan busy for a long time or make it use a lot of memory.
- The patterns of the library fingerprint (which run in the default Safe Mode), of the Active Mode signatures and of the host-header,
TRACEand CSRF-confirmation passes are bounded, and they read the first 256 KiB of a body or script. - The OpenAPI import caps the size of the request bodies it builds from a schema.
- A library marker or a framework message that appears only after the first 256 KiB of a body is no longer recognised; a request body for a very large schema is cut short.
- Upgrade with
pip install -U webvigilor pullghcr.io/ryanvmorais/webvigil:1.0.3. Nothing in the CLI, the exit codes, the configuration keys, the check ids or the JSON report changes.
Use WebVigil only on systems you own or are authorized in writing to test.
Security advisory: GHSA-7cmg-mh2g-8rwv
Full list of changes: CHANGELOG.md
WebVigil 1.0.2
Patch release with one fix, in the error-page signatures of the information-disclosure check. The CLI, the exit codes, the configuration keys, the check ids and the JSON report do not change.
- The patterns that recognise Java, Node.js and Python stack traces and the Django and Rails debug pages are bounded, so a page from the scanned site can no longer keep a scan busy for a long time in them. The signatures now read the first 256 KiB of a body: a framework error that appears only past that point is no longer recognised.
- Upgrade:
pipx upgrade webvigil, ordocker pull ghcr.io/ryanvmorais/webvigil:1.0.2.
Scan only systems you own or have permission to test. The compatibility promise is in docs/stability.md.
Security advisory: GHSA-wxvq-cw49-p7f6
Full list of what changed in 1.0.2: CHANGELOG
WebVigil 1.0.1
Patch release: it hardens the optional Web API and lifts the selectolax cap. The CLI, the exit codes, the configuration keys, the check ids and the JSON report do not change.
- Web API: it refuses at start a pinned
session_secretshorter than 32 characters and a*incors_origins, and an unauthenticated request can no longer make it hold memory in proportion to its size (a body over 1 MiB is answered with413, the login fields are capped). If you pinned a shorter secret, generate a longer one before upgrading. - Login takes the same time for a username that does not exist as for a wrong password, and an out-of-range scan id is a
422, not a500. - HTML is parsed with the Lexbor backend of
selectolax(selectolax>=1.0.0,<2); a full Active scan of the bundled test app gives the same findings. - Windows: a report redirected from stdout is UTF-8, so
webvigil reportcan read it back. - Upgrade:
pipx upgrade webvigil, ordocker pull ghcr.io/ryanvmorais/webvigil:1.0.1.
Scan only systems you own or have permission to test. The compatibility promise is in docs/stability.md.
Security advisory: GHSA-vw64-75mj-x37q
Full list of what changed in 1.0.1: CHANGELOG
WebVigil 1.0.0
First release of WebVigil: an open-source web application vulnerability scanner (DAST) for developers.
- Safe Mode by default (passive, production-safe); Active Mode behind
--mode active --authorized-by. - 50 checks (27 passive, 23 active), every active finding confirmed against a per-request baseline.
- Reports in JSON (with a
schema_version), SARIF 2.1.0, HTML and Markdown;--fail-onfor CI. - Install:
pipx install webvigil, ordocker run --rm ghcr.io/ryanvmorais/webvigil scan <url>.
Scan only systems you own or have permission to test. What WebVigil does not do is in the
README's "Scope and limitations"; the compatibility promise is in docs/stability.md.
Full list of what is in 1.0.0: CHANGELOG