Repository navigation
v1.0.1
First release since 1.0.0. Binaries for Linux, macOS and Windows, plus SHA256SUMS.txt, which install.sh and install.ps1 verify before installing. 1.0.0 has no checksum file, so the installers refuse it.
Includes the Windows PowerShell installer and the scanner changes listed in CHANGELOG.md under 1.0.1.
What's Changed
- Add reproducible build and accuracy benchmark by @sandeepannandi in #1
- Keep benchmark fixtures out of PR security summary by @sandeepannandi in #2
- Baseline Rust formatting by @sandeepannandi in #4
- Baseline strict Clippy fixes by @sandeepannandi in #5
- Add standard CI quality gate by @sandeepannandi in #3
- Add realistic corpus benchmark baseline and workflow validation by @sandeepannandi in #6
- feat: add stable finding schema and SARIF output by @sandeepannandi in #7
- Add doctor diagnostics and config checks by @sandeepannandi in #8
- Verify fix-loop remediation gates by @sandeepannandi in #9
- Harden live-pentest target scope and network safety by @sandeepannandi in #10
- fix(ci): bound Chrome launch retries and fail fast on early exit by @sandeepannandi in #11
- feat: guided
cipher-ai setupand secret-handling hardening by @sandeepannandi in #12 - feat: checksum-verified installer and release SHA256SUMS by @sandeepannandi in #13
- Fix JWT secret classification precision by @sandeepannandi in #14
- Fix command injection precision and Java coverage by @sandeepannandi in #15
- Detect Java MessageDigest MD5 weak hash by @sandeepannandi in #16
- ci: publish Cipher SARIF to GitHub Code Scanning by @sandeepannandi in #17
- feat: add repository policy controls by @sandeepannandi in #18
- ci: export policy baseline migration artifact by @sandeepannandi in #19
- ci: enforce repository security policy by @sandeepannandi in #20
- Trace local JavaScript path traversal data flow by @sandeepannandi in #21
- benchmark: support project-level accuracy cases by @sandeepannandi in #22
- benchmark: add pinned MIT real-project corpus by @sandeepannandi in #23
- benchmark: add deterministic real-project mutations by @sandeepannandi in #24
- benchmark: report separate accuracy gates by @sandeepannandi in #25
- fix: detect Python MD5 callable aliases by @sandeepannandi in #26
- feat: add narrow Python path data-flow detection by @sandeepannandi in #27
- feat: add narrow Java path data-flow detection by @sandeepannandi in #28
- feat: add narrow Go path data-flow detection by @sandeepannandi in #29
- Make policy fingerprints position-independent by @sandeepannandi in #30
- Add GitHub Actions workflow security checks by @sandeepannandi in #31
- Pin third-party workflow actions to commit SHAs by @sandeepannandi in #32
- Add Dependabot config for GitHub Actions by @sandeepannandi in #33
- ci: bump the github-actions group with 5 updates by @dependabot[bot] in #34
- Add same-file SQL injection data flow (JS/TS, Python, Java, Go) by @sandeepannandi in #35
- Add same-file command injection data flow (JS/TS, Python, Java, Go) by @sandeepannandi in #36
- Add SSRF rule and same-file data flow (JS/TS, Python, Java, Go) by @sandeepannandi in #37
- Follow same-file function calls in request data flow (JS/TS, Python, Java, Go) by @sandeepannandi in #38
- Cross-file data flow for JS/TS and Python (phase 2) by @sandeepannandi in #39
- Cross-file data flow for Java and Go by @sandeepannandi in #40
- Cross-file import resolution for Java and Go by @sandeepannandi in #41
- Add same-file and cross-file data flow for Rust by @sandeepannandi in #42
- Add Spring MVC and Gin/Echo framework sources to data flow by @sandeepannandi in #43
- Parse multi-line Java signatures; seed only annotated Spring params by @sandeepannandi in #44
- Resolve grouped Rust use imports in cross-file data flow by @sandeepannandi in #45
- Resolve JS/TS default exports in cross-file data flow by @sandeepannandi in #46
- Cross-file data flow: resolve JS/TS re-exports through one barrel hop by @sandeepannandi in #47
- Cross-file data flow: resolve Rust pub use re-exports through one hop by @sandeepannandi in #48
- Cross-file data flow: resolve nested Rust module path calls by @sandeepannandi in #49
- Ignore Python benchmark artifacts by @sandeepannandi in #50
- Cross-file data flow: resolve chained re-exports through a bounded fixpoint by @sandeepannandi in #51
- Cross-file data flow: track call chains across two import hops by @sandeepannandi in #52
- Cross-file data flow: converge the import-hop fixpoint by @sandeepannandi in #53
- Cross-file data flow: converge the re-export and summary fixpoints by @sandeepannandi in #54
- Cross-file data flow: resolve nested Rust module paths of any depth by @sandeepannandi in #55
- Cross-file data flow: resolve nested Rust use groups by @sandeepannandi in #56
- Cross-file data flow: resolve JS calls through instance variables by @sandeepannandi in #57
- Cross-file data flow: resolve Python calls through instance variables by @sandeepannandi in #58
- Cross-file data flow: resolve multi-line Rust use trees by @sandeepannandi in #59
- Resolve JS instance-variable calls through ESM class imports by @sandeepannandi in #60
- Resolve multi-line JS import, require, and re-export declarations by @sandeepannandi in #61
- Resolve parenthesized Python from-imports by @sandeepannandi in #62
- Add cross-file resolution cases to the accuracy corpus by @sandeepannandi in #63
- Resolve JS namespace re-exports (export * as ns from './x') by @sandeepannandi in #64
- Fix review panic on Java imports resolving outside the project by @sandeepannandi in #65
- Resolve Python star imports (from .x import *) by @sandeepannandi in #66
- Resolve Go dot imports (import . "pkg") by @sandeepannandi in #67
- Resolve Rust super::super use paths by @sandeepannandi in #68
- Widen taint sources: request headers/cookies/json/data (py, js) and getQueryString (java) by @sandeepannandi in #69
- Recognize more sanitizers: Double/Float.parse, annotated Rust parse, pathlib .name by @sandeepannandi in #70
- See request reads wrapped in calls as taint sources (str/String/valueOf) by @sandeepannandi in #71
- Catch request reads embedded in f-strings, templates, and concatenation by @sandeepannandi in #72
- Seed Flask route captures and Django view kwargs as taint sources by @sandeepannandi in #73
- Catch request reads embedded in Go/Rust format strings and concatenation by @sandeepannandi in #74
- Add release-profile CI tests, portable policy fingerprints, and a local policy-gate precheck by @sandeepannandi in #75
- Resolve node_modules package imports and Go test files in cross-file data flow by @sandeepannandi in #76
- Fix scanner exclusions relative to project root by @sandeepannandi in #77
- Detect NodeGoat eval and Mongo $where injection flows by @sandeepannandi in #78
- Downgrade test and fixture findings without hiding them by @sandeepannandi in #79
- Avoid SQL injection labels on HTTP route calls by @sandeepannandi in #80
- Limit SSTI findings to request-controlled template sources by @sandeepannandi in #81
- Require request-controlled unguarded access for IDOR findings by @sandeepannandi in #82
- Surface verified source-to-sink paths in review output by @sandeepannandi in #83
- Attach proven source-to-sink paths in real scans by @sandeepannandi in #84
- Detect production signing-secret fallbacks by @sandeepannandi in #85
- Detect request-controlled Needle URLs and Express redirects by @sandeepannandi in #86
- Detect request-driven ReDoS and plaintext password handling by @sandeepannandi in #87
- Detect linked privileged routes and unguarded account access by @sandeepannandi in #88
- Detect scoped template XSS and CSRF gaps by @sandeepannandi in #89
- Detect login session fixation with cookie-session context by @sandeepannandi in #90
- Detect raw login names in line-oriented logs by @sandeepannandi in #91
- Detect distinct public login errors for username enumeration by @sandeepannandi in #92
- Detect raw sensitive profile fields persisted without encryption by @sandeepannandi in #93
- Clarify pilot review findings in source and deployment contexts by @sandeepannandi in #94
- Detect scoped Ruby and PHP SQL and shell injection by @sandeepannandi in #95
- Detect scoped Go web injection flows by @sandeepannandi in #96
- Detect scoped PHP and Rails file and XSS flows by @sandeepannandi in #97
- Detect scoped crypto, TLS, and session-cookie flaws in pilot by @sandeepannandi in #98
- Detect scoped Rails mass assignment at model writes by @sandeepannandi in #99
- Detect Rails CSRF gap from effective legacy configuration by @sandeepannandi in #100
- Detect source-linked Rails work-info IDOR by @sandeepannandi in #101
- Detect Rails login redirect under unsafe host default by @sandeepannandi in #102
- Detect Rails credential enumeration in public login errors by @sandeepannandi in #103
- Detect conditional Rails admin gate bypass by @sandeepannandi in #104
- Detect full SSN rendered before client masking by @sandeepannandi in #105
- Detect unguarded PHP GET password change by @sandeepannandi in #106
- Detect unvalidated PHP GET redirect by @sandeepannandi in #107
- Detect request-controlled Go redirect targets by @sandeepannandi in #108
- Detect Go credential logging via log.Printf family by @sandeepannandi in #109
- Detect Go hardcoded JWT signing secrets by @sandeepannandi in #110
- Suppress asset-pipeline debug flag in Debug Mode rule by @sandeepannandi in #111
- Suppress Google JS loader placeholder in Hardcoded Credentials by @sandeepannandi in #112
- Suppress ZAP dev-tool credential in Hardcoded Credentials by @sandeepannandi in #113
- Suppress DEBUG=True scoped to dev/test Python config classes by @sandeepannandi in #114
- Suppress PHP SQLi finding behind a digits-only request guard by @sandeepannandi in #115
- Detect Go JWT parsing without signing-method pinning by @sandeepannandi in #116
- Detect Django MD5 hasher, cookie sessions, and Pickle serializer by @sandeepannandi in #117
- Detect Django csrf_exempt views by @sandeepannandi in #118
- Detect Django ORM lookups by URL parameter without ownership checks by @sandeepannandi in #119
- Detect Django redirect to request-controlled target by @sandeepannandi in #120
- Read sink-call arguments across continuation lines by @sandeepannandi in #121
- Detect Django template output rendered through the safe filter by @sandeepannandi in #122
- Detect Django ModelForm exclude blacklists missing privilege flags by @sandeepannandi in #123
- Detect Django privilege mutation without a preceding role check by @sandeepannandi in #124
- Require a word boundary before raw( in the ORM raw-query pattern by @sandeepannandi in #125
- Detect level-conditional authorization checks on user endpoints by @sandeepannandi in #126
- Detect unquoted interpolation of escaped values in numeric SQL contexts by @sandeepannandi in #127
- Detect single-pass path traversal filters on include targets by @sandeepannandi in #128
- Detect WebGoat.NET lesson SQL injection in DB providers by @sandeepannandi in #129
- Detect WebGoat.NET file-download path manipulation by @sandeepannandi in #130
- Detect WebGoat.NET lesson XSS in the vulnerable method bodies by @sandeepannandi in #131
- Detect WebGoat.NET unrestricted file upload by @sandeepannandi in #132
- Detect WebGoat.NET debug information disclosure in Web.config by @sandeepannandi in #133
- Detect WebGoat.NET custom weak message digest by @sandeepannandi in #134
- Detect WebGoat.NET predictable random generator by @sandeepannandi in #135
- Detect WebGoat.NET unbounded unsafe pointer write by @sandeepannandi in #136
- Detect DVGA command injection through run_cmd os.popen wrapper by @sandeepannandi in #137
- Detect DVGA arbitrary file write through UploadPaste save_file by @sandeepannandi in #138
- Detect DVGA SQL injection in resolve_pastes raw text filter by @sandeepannandi in #139
- Detect DVGA JWT signature verification disabled in get_identity by @sandeepannandi in #140
- Detect DVGA stored XSS through paste.html template interpolation by @sandeepannandi in #141
- review: exclude test/example/fixture paths from findings by @sandeepannandi in #142
- review: tighten identifier-collision patterns to real sink shapes by @sandeepannandi in #143
- review: suppress documented-design deserialization on trusted stores by @sandeepannandi in #144
- Fix env race in groq missing-key test by @sandeepannandi in #146
- Suppress protocol-mandated and non-security weak-hash findings by @sandeepannandi in #145
- Suppress four small FP classes: config-read debug, OpenSSL '!DES' exclusions, Algolia DocSearch keys, fully-quoted SQL interpolation by @sandeepannandi in #147
- Downgrade unpinned third-party action findings to low severity by @sandeepannandi in #148
- review: index Java package and class lookups in cross-file flow (fixes #149 quadratic scan) by @sandeepannandi in #150
- review: report MongoDB $where injection as NoSQL injection (CWE-943) by @sandeepannandi in #151
- review: skip fixed-string log calls and CLI-flag credential map entries by @sandeepannandi in #152
- CI: pinned-repo exact-key gate + production baseline (plan item 1) by @sandeepannandi in #153
- review: evaluate path-context rules relative to the scan root by @sandeepannandi in #154
- benchmarks: advisory recall on pinned pre-fix commits (3/21 today) by @sandeepannandi in #155
- feat: flag shell-string sinks built from public function parameters by @sandeepannandi in #156
- feat: flag file-based pickle.load; fix superset recall label path by @sandeepannandi in #157
- feat: flag Go archive entry names joined onto a destination without a containment check by @sandeepannandi in #158
- feat: carry request taint through Python call tuple-unpack; flag HTTPConnection as an SSRF sink by @sandeepannandi in #159
- feat: flag Kernel.open on a public Ruby method parameter by @sandeepannandi in #160
- Ruby: shell-string sinks from public-method parameters (PR 2 of 2) by @sandeepannandi in #161
- Python: git argument injection from a constructor or public-method parameter by @sandeepannandi in #162
- CI: fail pull requests that lose a recorded advisory hit by @sandeepannandi in #163
- Recall gate: fail on a stale results.json, add --write by @sandeepannandi in #164
- Recall benchmark: widen to 30 labels (22 advisories), record honest results by @sandeepannandi in #165
- Java: SQL injection from a public-method String parameter appended into a StringBuilder by @sandeepannandi in #166
- Recall benchmark: widen to 34 labels (26 advisories), all four new ones are misses by @sandeepannandi in #167
- bench: production precision ledger (86 findings triaged) by @sandeepannandi in #168
- Weak Hash: skip non-security uses (13 production FPs removed) by @sandeepannandi in #169
- ORM Raw Queries: skip Python docstring prose (1 production FP removed) by @sandeepannandi in #170
- ORM Raw Queries: skip empty and wrapped-constant execute_sql (2 django FPs) by @sandeepannandi in #171
- Debug Mode: skip debug=True inside Django template Engine() (1 production FP) by @sandeepannandi in #172
- SSRF: report Python HTTPConnection flow at the request call (graphite NEAR to HIT) by @sandeepannandi in #173
- Join wrapped same-file and imported call arguments so taint reaches the callee by @sandeepannandi in #174
- Weak Hash: apply non-security cues to the enclosing function declaration by @sandeepannandi in #175
- README: measured results and known limits by @sandeepannandi in #176
- Add install.ps1: Windows installer with checksum verification, tested in CI by @sandeepannandi in #177
- README: add Demo section with real captured output by @sandeepannandi in #178
- Release 1.0.1: version bump and changelog by @sandeepannandi in #179
- Release workflow: add the target to the pinned toolchain by @sandeepannandi in #180
New Contributors
- @sandeepannandi made their first contribution in #1
- @dependabot[bot] made their first contribution in #34
Full Changelog: v1.0.0...v1.0.1