Releases: styayur/developer-security-workspace
Release list
v1.0.0
Developer Security Workspace v1.0.0
This update introduces Security IR v1, identity-based triage, explainable layered matching, Changed/Reopened comparisons and thread-aware trace navigation. Findings are queried in bounded SQLite pages and raw results load by artifact reference. The synthetic tutorial includes two scans, fixes, cross-file traces, secrets, dependencies and IaC.
Existing Preview databases migrate transactionally to schema 2; projects, occurrences and notes are preserved. Ambiguous legacy collisions are kept separate. Keep a backup before upgrading important local databases; do not downgrade a migrated database to an older Preview.
Declarative runtime v1 executes only the reviewed Gitleaks profile after the user approves the manifest and installed binary. It is not a sandbox for malicious native executables. Other manifests remain metadata. No scanner, CodeQL engine, account system or telemetry is bundled.
SARIF import now streams through bounded disk-backed staging with progress and cancellation. A 100,000-result double import/diff passes a hard 512 MiB process-memory limit.
Windows MSVC installers use a self-signed Authenticode certificate. This verifies integrity against the included public certificate, but does not provide public-CA publisher trust or remove SmartScreen. The certificate is not automatically trusted and signatures are not timestamped. Release artifacts include the public certificate and SHA256SUMS. See release operations and known limits.
Full Changelog: v0.1.0-preview...v1.0.0
Developer Security Workspace v0.1.0-preview
Developer Security Workspace v0.1.0-preview
Local-first SARIF desktop client, vulnerability debugger, and scanner runtime.
Highlights
- Rust SARIF 2.1.0 parser and unified Security IR
- SQLite scan history, findings, triage, and workspace fingerprints
- Monaco source debugger with SARIF code-flow Trace Player
- New / Existing / Fixed scan diff
- Local-first SARIF import and export
- Secret redaction in findings, raw SARIF, and scanner logs
- Structured scanner process execution with cancellation and log bounds
- Semgrep, Trivy, TruffleHog, and Bandit providers
- Optional user-selected CodeQL runtime
- Metadata-only extension manifest foundation
- Dark, light, and system themes
- No account, telemetry, analytics, or cloud upload
Real scanner verification
| Scanner | Version | Provider result |
|---|---|---|
| Semgrep | 1.178.0 | Passed, 1 smoke finding |
| Trivy | 0.74.0 | Passed, 12 smoke findings |
| TruffleHog | 3.97.9 | Passed, 2 smoke findings after redaction |
| Bandit | 1.9.4 | Passed, 2 smoke findings |
CodeQL CLI is intentionally not bundled. Users can select and verify their own separately licensed runtime.
Build verification
- Frontend tests: passed
- Rust tests: passed
- Real scanner provider integration: passed
- Strict Clippy: passed
- Windows NSIS production build: passed
- Release executable smoke launch: passed
Scope
This is preview software. It does not provide complete protection, certification, zero false positives, or automated remediation. Scanner results must be reviewed in context.
See README.md, SECURITY.md, and docs/ for architecture, privacy, scanner configuration, and licensing details.