Releases: teddashh/ai-security-scanner
Release list
ai-security-scanner 0.1.9
ai-security-scanner 0.1.9
Source: 5c95572f54220adbd170d9bfb5af3159c56708ef
Windows pre-release testing notice
This is a public testing pre-release, not a stable deployment. The Windows installers
are intentionally available so this build can be tested now. Windows may show an
Unknown publisher warning.
- MSI: Authenticode not verified; exact-candidate beginner path not observed; installed-app lifecycle not observed; data-preservation path not observed.
- NSIS: Authenticode not verified; exact-candidate beginner path not observed; installed-app lifecycle not observed; data-preservation path not observed.
A clearer, safer public testing build. This prerelease improves automatic runtime
recovery, evidence-backed finding explanations, and honest incomplete-coverage reporting.
Findings now retain the engine facts used to compose their summary, impact, priority, and
next step. English and Traditional Chinese reports explain tested dimensions, limitations,
warnings, control relationships, and verification outcomes without turning unknown or failed
work into a clean result.
Related observations from different engines are grouped reversibly, source attribution stays
visible, and identifiers that could not be attributed are withheld from redacted exports.
The interface also improves responsive layout, keyboard focus, readable text, and motion
preferences.
Verified product-owned runtime material can recover from its digest-anchored packaged cache.
Ambiguous or unrelated state remains untouched, and optional engine failures remain scoped to
their affected tasks. Existing projects, evidence, cleanup obligations, and signer history are
preserved.
For Windows installed-app testing, use the exact published installer bytes and follow the
external qualification plan.
Artifacts offered by this finalized set:
- linux-x86_64 / deb: ai-security-scanner_0.1.9_amd64.deb; technical qualification passed; beginner human path not-observed.
- macos-universal / dmg: ai-security-scanner_0.1.9_universal.dmg; technical qualification installer-passed-runtime-not-observed; beginner human path not-observed.
- windows-x86_64 / msi: ai-security-scanner_0.1.9_x64_en-US.msi; technical qualification passed; beginner human path not-observed.
- windows-x86_64 / nsis: ai-security-scanner_0.1.9_x64-setup.exe; technical qualification passed; beginner human path not-observed.
Not offered in this finalized set:
- linux-x86_64 / appimage: not offered (technical-qualification-not-observed).
- linux-x86_64 / rpm: not offered (technical-qualification-not-observed).
Verify the selected file against SHA256SUMS.txt and its artifact-specific public provenance before installing.
Qualification, human-path observation, OS signing, notarization, updater availability,
provenance requirements, and known limitations are recorded independently for every offered artifact
in release-metadata.json. An absent platform never implies that it passed.
ai-security-scanner 0.1.8
ai-security-scanner 0.1.8
Source: fa1fa9d401995de45080fbfaffc6b39d99955387
Windows pre-release testing notice
This is a public testing pre-release, not a stable deployment. The Windows installers
are intentionally available so this build can be tested now. Windows may show an
Unknown publisher warning.
- MSI: Authenticode not verified; exact-candidate beginner path not observed; installed-app lifecycle not observed; data-preservation path not observed.
- NSIS: Authenticode not verified; exact-candidate beginner path not observed; installed-app lifecycle not observed; data-preservation path not observed.
Faster first scan, safer automatic recovery. This build keeps internal runtime details
out of the beginner path and favors an isolated, reversible recovery when old state is unclear.
On first launch, product-owned disposable state is reconciled automatically. Old state whose
ownership is uncertain is left untouched while the app creates a uniquely named isolated
workspace and continues. Nothing unfamiliar is deleted just to make the scanner start.
The app opens the selected task immediately, keeps recovery in the background, and reports
tested, not tested, failed, and incomplete coverage separately instead of turning one optional
component failure into an all-or-nothing result.
Existing local cases, cleanup obligations, evidence snapshots, and provenance remain intact.
The app still waits for an explicit Start action before contacting a scan target.
Artifacts offered by this finalized set:
- linux-x86_64 / deb: ai-security-scanner_0.1.8_amd64.deb; technical qualification passed; beginner human path not-observed.
- macos-universal / dmg: ai-security-scanner_0.1.8_universal.dmg; technical qualification installer-passed-runtime-not-observed; beginner human path not-observed.
- windows-x86_64 / msi: ai-security-scanner_0.1.8_x64_en-US.msi; technical qualification passed; beginner human path not-observed.
- windows-x86_64 / nsis: ai-security-scanner_0.1.8_x64-setup.exe; technical qualification passed; beginner human path not-observed.
Not offered in this finalized set:
- linux-x86_64 / appimage: not offered (technical-qualification-not-observed).
- linux-x86_64 / rpm: not offered (technical-qualification-not-observed).
Verify the selected file against SHA256SUMS.txt and its artifact-specific public provenance before installing.
Qualification, human-path observation, OS signing, notarization, updater availability,
provenance requirements, and known limitations are recorded independently for every offered artifact
in release-metadata.json. An absent platform never implies that it passed.
ai-security-scanner 0.1.7
ai-security-scanner 0.1.7
Source: 2e25a8fab7a5663d7143c6ba5a2cdaa139688dca
Hands-on Windows testing pre-release. This build carries the Candidate 11 product
repairs produced by operating the real app end to end, then extends those repairs across
the shared scan lifecycle.
First launch recognizes prerequisites that are already available and prepares the private
scan tools before presenting a scan as ready. A scan starts from the action the user chose,
and startup listeners are attached early enough to preserve fast progress and failure events.
Public and internal network checks accept an IP address or domain. Domain resolution is
frozen into the exact run, and the guided common-port inventory remains bounded. If a check
stops, the app preserves saved evidence, shows a useful next step, and offers a redacted
technical log without targets, paths, secrets, or raw scanner messages.
When trusted ignore-rule evaluation is unavailable, files are retained rather than silently omitted.
Windows runtime recovery also treats initialization
proof as one-shot state; a stale journal is never permission to delete WSL state.
AI app and agent checks reuse the existing code, secret, package, and deployment routes.
Applicable findings can carry AIDEFEND references beside NIST CSF and ISO 27001 references.
The managed Gitleaks path remains network-disabled and fully redacts detected secret values.
Existing local cases, cleanup obligations, evidence snapshots, and provenance remain intact.
These desktop installers are built for Linux x86-64, universal macOS (Intel + Apple silicon),
and Windows x86-64. Verify the selected file against SHA256SUMS.txt and the public GitHub
artifact attestation before installing.
Fresh GitHub-hosted qualification jobs independently installed the Debian package, macOS DMG,
Windows MSI, and Windows NSIS Setup executable. Linux and both Windows installers completed
managed-runtime install, start, status, fixed no-upstream managed egress gateway readiness,
network-disabled Gitleaks container execution, stop, uninstall with image-cache purge, and
private-state cleanup. The universal macOS artifact's DMG installation, bundled layout, exact
runtime manifest, CLI, desktop startup, and cleanup passed on GitHub's Intel macos-15-intel
runner. Its managed-runtime, egress gateway, and container lifecycle is explicitly recorded as not observed
because GitHub-hosted macOS does not support the nested virtualization required by AppleHV.
This limited macOS evidence is accepted only for a pre-release. Exact evidence is published
per installer.
The current installers are not signed with Apple Developer ID or Windows Authenticode and
are not Apple-notarized. Application update payloads are separately signed with the updater
key, but the operating system may still show an unidentified-developer warning. No scanner
engine image is bundled.
The first-party ai-security-scanner-egress-gateway, isolated
ai-security-scanner-bootstrap-broker, and local ai-security-scanner-cli companion
executables are installed beside the desktop executable.
Platform copies and hashes are included as release evidence and SBOM entries.
CycloneDX and SPDX JSON SBOMs, generated third-party notices, engine reference notices, and
machine-readable release metadata accompany the installers.
Known Linux pre-release dependency risk
The Linux desktop bundle includes glib 0.18.5 transitively through Tauri’s GTK3/WebKitGTK stack. This version is covered by RUSTSEC-2024-0429, an unsoundness in VariantStrIter. Static review found no product or downloaded production-dependency call to the affected iterator API; the Windows and macOS dependency trees do not contain this crate. The Dependabot alert remains open and this risk is not presented as fixed. A reviewed backport or upstream stack migration remains follow-up work.
ai-security-scanner 0.1.6
ai-security-scanner 0.1.6
Source: 61ed54ef4fb0c9f5fd3c13b2feb7f1c23daad4ca
Public testing pre-release. This build repairs the private connection used by local
network scanners. It has not completed the planned formal QC/code review.
Local network scans no longer depend on a Windows process listening on an address that
exists only inside WSL. The gateway now runs beside the scanners in the private managed
runtime, with separate scanner and uplink networks.
Gateway readiness comes from the running gateway itself. If setup fails, the scan preserves
the concrete failure and cleanup result instead of returning to an unexplained Ready/Repair
loop. Existing event logs and redacted technical downloads remain available for diagnosis.
The downloadable Windows Setup executable and MSI are now installed and exercised in
separate fresh qualification jobs. Each one must prove the gateway is ready and reachable
from the scanner side without making an upstream connection, then remove every exact test
resource before the release can continue.
Existing local cases, cleanup obligations, evidence snapshots, and provenance remain intact.
These desktop installers are built for Linux x86-64, universal macOS (Intel + Apple silicon),
and Windows x86-64. Verify the selected file against SHA256SUMS.txt and the public GitHub
artifact attestation before installing.
Fresh GitHub-hosted qualification jobs independently installed the Debian package, macOS DMG,
Windows MSI, and Windows NSIS Setup executable. Linux and both Windows installers completed
managed-runtime install, start, status, fixed no-upstream managed egress gateway readiness,
network-disabled Gitleaks container execution, stop, uninstall with image-cache purge, and
private-state cleanup. The universal macOS artifact's DMG installation, bundled layout, exact
runtime manifest, CLI, desktop startup, and cleanup passed on GitHub's Intel macos-15-intel
runner. Its managed-runtime, egress gateway, and container lifecycle is explicitly recorded as not observed
because GitHub-hosted macOS does not support the nested virtualization required by AppleHV.
This limited macOS evidence is accepted only for a pre-release. Exact evidence is published
per installer.
The current installers are not signed with Apple Developer ID or Windows Authenticode and
are not Apple-notarized. Application update payloads are separately signed with the updater
key, but the operating system may still show an unidentified-developer warning. No scanner
engine image is bundled.
The first-party ai-security-scanner-egress-gateway, isolated
ai-security-scanner-bootstrap-broker, and local ai-security-scanner-cli companion
executables are installed beside the desktop executable.
Platform copies and hashes are included as release evidence and SBOM entries.
CycloneDX and SPDX JSON SBOMs, generated third-party notices, engine reference notices, and
machine-readable release metadata accompany the installers.
ai-security-scanner 0.1.5
ai-security-scanner 0.1.5
Source: 3e073900ade1b1b863d4f0a3576c0a19d1461ee6
Public testing pre-release. This build makes Windows startup and live scan progress
easier to understand. It has not completed the planned formal QC/code review.
On first launch, the app checks installed Windows prerequisites before showing the normal
workspace. It recognizes components that are already available and automatically prepares
the private local scan tools when needed. A standard Windows approval dialog appears only
when Windows itself needs a change; an explicit restart remains under the user's control.
The Ready/Repair loop is removed. A temporary local-tool connection issue can still be
retried, but a missing or invalid component from the installed package is no longer
presented as something the same broken installation can repair. The app explains the
problem and links to the latest installer while preserving existing local cases.
Before a scan starts, the activity view records when readiness was checked and explains any
blocker in plain language. During a scan, the same timeline shows the active and next scanner,
the current wait reason, the last durable progress, and a delayed-update notice without
mistaking a paused scan for a stalled one. This behavior is shared by every supported scan route.
When technical detail is useful, the app can download a redacted diagnostic containing safe
timestamps, statuses, phases, blocker codes, versions, and counts. It excludes target names,
local paths, raw evidence, credentials, and raw scanner output.
Preparation never starts a scan or widens its scope. The app still waits for the user's
explicit Start action before contacting an approved target.
Existing local cases, cleanup obligations, evidence snapshots, and provenance remain intact.
These desktop installers are built for Linux x86-64, universal macOS (Intel + Apple silicon),
and Windows x86-64. Verify the selected file against SHA256SUMS.txt and the public GitHub
artifact attestation before installing.
Fresh GitHub-hosted qualification jobs independently installed the Debian package, macOS DMG,
and Windows MSI. Linux and Windows completed managed-runtime install, start, status, fixed
network-disabled Gitleaks container execution, stop, uninstall with image-cache purge, and
private-state cleanup. The universal macOS artifact's DMG installation, bundled layout, exact
runtime manifest, CLI, desktop startup, and cleanup passed on GitHub's Intel macos-15-intel
runner. Its managed-runtime and container lifecycle is explicitly recorded as not observed
because GitHub-hosted macOS does not support the nested virtualization required by AppleHV.
This limited macOS evidence is accepted only for a pre-release. Exact evidence is published
per platform.
The current installers are not signed with Apple Developer ID or Windows Authenticode and
are not Apple-notarized. Application update payloads are separately signed with the updater
key, but the operating system may still show an unidentified-developer warning. No scanner
engine image is bundled.
The first-party ai-security-scanner-egress-gateway, isolated
ai-security-scanner-bootstrap-broker, and local ai-security-scanner-cli companion
executables are installed beside the desktop executable.
Platform copies and hashes are included as release evidence and SBOM entries.
CycloneDX and SPDX JSON SBOMs, generated third-party notices, engine reference notices, and
machine-readable release metadata accompany the installers.
ai-security-scanner 0.1.4
ai-security-scanner 0.1.4
Source: 0870fd2db59f9d21c69ad9233b331ffba690fea8
Public testing pre-release. This build fixes the empty 0/0 scan and repeated-consent
experience reported during a first home-network test. It is not the latest stable release
and has not completed the planned formal QC/code review.
Choose what you want to check: a home or office network, website, external IP, source code,
infrastructure as code, cloud account, container image, or Kubernetes configuration. Each
choice now opens only the setup it actually needs and preserves that intent through the run.
For a home or office network, the installed app can read local interface and route metadata
to suggest one safe private subnet. It does not probe the network, select the subnet, grant
permission, or start a scan automatically. One explicit click accepts the suggestion, and
the target remains editable before the single scan confirmation.
A scan run is created only when at least one compatible engine has an authorized target,
the required local tools are ready, and every short-lived cloud connection has enough
capacity for the exact execution plan. Cloud capacity and backend-only credentials are
reserved atomically before the run is saved and released if storage or worker startup fails.
A blocked attempt therefore stays in setup instead of creating a 0/0 run or expanding one
setup problem into many failed scanner checks.
The guided network preset checks a useful bounded set of common TCP services. Website checks
preserve the entered URL protocol and port. Advanced controls remain available without
cluttering the first path.
Setup problems now lead to one relevant action: prepare the private scan tools, connect or
reconnect an account, choose between matching connections, review a mismatched target, or
retry a temporarily unavailable check. Failed or partial runs can export a redacted diagnostic containing
statuses, phases, error codes,
versions, and counts without target names, paths, evidence, or raw scanner messages.
The macOS installer, app layout, packaged manifest, CLI, desktop startup, and cleanup are
qualified on a fresh GitHub-hosted Mac. Managed-runtime and container lifecycle operations
are explicitly recorded as not observed because that hosted environment does not provide the
nested virtualization required by AppleHV. This exception is accepted only for a pre-release;
a stable release still fails closed without real Mac runtime evidence.
Existing local cases, cleanup obligations, evidence snapshots, and provenance remain intact.
These desktop installers are built for Linux x86-64, universal macOS (Intel + Apple silicon),
and Windows x86-64. Verify the selected file against SHA256SUMS.txt and the public GitHub
artifact attestation before installing.
Fresh GitHub-hosted qualification jobs independently installed the Debian package, macOS DMG,
and Windows MSI. Linux and Windows completed managed-runtime install, start, status, fixed
network-disabled Gitleaks container execution, stop, uninstall with image-cache purge, and
private-state cleanup. The universal macOS artifact's DMG installation, bundled layout, exact
runtime manifest, CLI, desktop startup, and cleanup passed on GitHub's Intel macos-15-intel
runner. Its managed-runtime and container lifecycle is explicitly recorded as not observed
because GitHub-hosted macOS does not support the nested virtualization required by AppleHV.
This limited macOS evidence is accepted only for a pre-release. Exact evidence is published
per platform.
The current installers are not signed with Apple Developer ID or Windows Authenticode and
are not Apple-notarized. Application update payloads are separately signed with the updater
key, but the operating system may still show an unidentified-developer warning. No scanner
engine image is bundled.
The first-party ai-security-scanner-egress-gateway, isolated
ai-security-scanner-bootstrap-broker, and local ai-security-scanner-cli companion
executables are installed beside the desktop executable.
Platform copies and hashes are included as release evidence and SBOM entries.
CycloneDX and SPDX JSON SBOMs, generated third-party notices, engine reference notices, and
machine-readable release metadata accompany the installers.
ai-security-scanner 0.1.2
ai-security-scanner 0.1.2
Source: 18ae16ae44fc3c25ed497b0364eef478377013f3
Public testing pre-release. Use this build to exercise the real desktop installer,
one-time scan-tool setup, guided use cases, and end-to-end results flow. It is not the
latest stable release and has not completed the planned formal QC/code review.
This candidate includes the simplified English and Traditional Chinese product flow and
typed immutable snapshots for repository, IaC, OCI image-layout, Kubernetes manifest, and
node-configuration inputs.
Provider discovery stays inside its released AWS Organizations, Azure subscription, or GCP
organization source boundary. Prowler execution is separately bound to one exact AWS account,
Azure subscription, or GCP project with provider-specific identity preflight and endpoint closure.
Other cloud engines retain their narrower released provider scope.
The required 21-engine catalog is bound to immutable image, launcher, adapter, evidence,
coverage, license, and verification contracts. Scanner images remain separate artifacts
and are not bundled in the desktop installers.
Existing local cases, cleanup obligations, evidence snapshots, and provenance remain intact.
Unknown or partial scope remains visibly distinct from a completed or passing result.
These desktop installers are built for Linux x86-64, universal macOS (Intel + Apple silicon),
and Windows x86-64. Verify the selected file against SHA256SUMS.txt and the public GitHub
artifact attestation before installing.
Fresh GitHub-hosted qualification jobs independently installed the Debian package, macOS DMG,
and Windows MSI. All three platforms completed managed-runtime install, start, status, fixed
network-disabled Gitleaks container execution, stop, uninstall with image-cache purge, and
private-state cleanup. The universal macOS artifact was independently exercised on GitHub's
standard Intel macos-15-intel runner. Exact runner-image and operation evidence is published
per platform.
The current installers are not signed with Apple Developer ID or Windows Authenticode and
are not Apple-notarized. Application update payloads are separately signed with the updater
key, but the operating system may still show an unidentified-developer warning. No scanner
engine image is bundled.
The first-party ai-security-scanner-egress-gateway, isolated
ai-security-scanner-bootstrap-broker, and local ai-security-scanner-cli companion
executables are installed beside the desktop executable.
Platform copies and hashes are included as release evidence and SBOM entries.
CycloneDX and SPDX JSON SBOMs, generated third-party notices, engine reference notices, and
machine-readable release metadata accompany the installers.
ai-security-scanner 0.1.1
ai-security-scanner 0.1.1
Source: 42b117a727531977337cb75d77b07db2e9668cb5
This patch release hardens container ownership controls, provider bootstrap recovery,
case revision concurrency, managed-runtime repair, historical evidence validation,
incomplete-result reporting, and exact artifact cleanup migration from v0.1.0.
These desktop installers are built for Linux x86-64, universal macOS (Intel + Apple silicon),
and Windows x86-64. Verify the selected file against SHA256SUMS.txt and the public GitHub
artifact attestation before installing.
The current installers are not signed with Apple Developer ID or Windows Authenticode and
are not Apple-notarized. Application update payloads are separately signed with the updater
key, but the operating system may still show an unidentified-developer warning. No scanner
engine image is bundled.
The first-party ai-security-scanner-egress-gateway, isolated
ai-security-scanner-bootstrap-broker, and local ai-security-scanner-cli companion
executables are installed beside the desktop executable.
Platform copies and hashes are included as release evidence and SBOM entries.
CycloneDX and SPDX JSON SBOMs, generated third-party notices, engine reference notices, and
machine-readable release metadata accompany the installers.
ai-security-scanner 0.1.0
ai-security-scanner 0.1.0
Source: 7f26f7b5de646433a4d00161fc5ffaec0ec8ac32
These desktop installers are built for Linux x86-64, universal macOS (Intel + Apple silicon),
and Windows x86-64. Verify the selected file against SHA256SUMS.txt and the public GitHub
artifact attestation before installing.
The current installers are not signed with Apple Developer ID or Windows Authenticode and
are not Apple-notarized. Application update payloads are separately signed with the updater
key, but the operating system may still show an unidentified-developer warning. No scanner
engine image is bundled.
The first-party ai-security-scanner-egress-gateway, isolated
ai-security-scanner-bootstrap-broker, and local ai-security-scanner-cli companion
executables are installed beside the desktop executable.
Platform copies and hashes are included as release evidence and SBOM entries.
CycloneDX and SPDX JSON SBOMs, generated third-party notices, engine reference notices, and
machine-readable release metadata accompany the installers.