Skip to content

Observer v0.7.0 — scans that don't hang, and honest comparison

Choose a tag to compare

@sanks205 sanks205 released this 23 Sep 11:06
· 36 commits to main since this release
fa345e5

Observer v0.7.0 — scans that don't hang, and honest comparison

This release fixes the most common pain point: deep scans over large codebases used to get killed by a fixed 5-minute budget. Timeouts now scale with file count, and you can set your own.

✨ Highlights

  • Dynamic scan timeouts. Each engine (Semgrep, PHPStan, Bandit, gosec, ESLint) gets a per-file estimate with a +50% buffer, minimum 5 minutes, hard cap 60 minutes. A WordPress-sized repo (~4,600 files) now gets ~7–9 minutes instead of being cut off at 5.
  • Override anytime. Set OBSERVER_SCAN_TIMEOUT=30m (or any Go duration) to take full control; the env var wins.
  • Estimate printed up front. After file discovery, Observer prints "Est. 7m45s for 4613 files (built-in ~1m32s + Semgrep ~7m42s) — auto timeout 11m38s" so you know what you're in for.
  • Semgrep now matches Observer's own file set. Standard excludes (vendor, node_modules, dist, build, *.min.js, etc.) are passed through so Semgrep and the built-in scanner count the same source files — no more apples-to-oranges finding counts.
  • Honest comparison page. The README and landing page now include a "Code leaves your machine?" row (Observer: never — 100% local) and an "Engine transparency" row (built-in + Semgrep/PHPStan labeled per finding), and compare against Snyk rather than Sentry.

🔒 Still true

Single self-contained binary. Fully offline (--assert-offline enforces it). No account, no telemetry. Multi-language native rules (PHP, JS/TS, Python, Java, Ruby) + optional Semgrep / PHPStan / Bandit / gosec / ESLint. Dependency CVEs via OSV.dev. --diff changed-code scanning, pre-commit gate, --attest. Free & MIT.

📦 Install

scoop install https://raw.githubusercontent.com/sanks205/getobserver/main/packaging/scoop/observer.json
brew install https://raw.githubusercontent.com/sanks205/getobserver/main/packaging/homebrew/observer.rb

Binaries are unsigned — verify against SHA256SUMS.txt.

OS File
Windows x64 / ARM observer_windows_amd64.exe / observer_windows_arm64.exe
macOS Apple / Intel observer_darwin_arm64 / observer_darwin_amd64
Linux x64 / ARM observer_linux_amd64 / observer_linux_arm64