ai-security-scanner 0.1.2
Pre-releaseai-security-scanner 0.1.2
Source: 18ae16ae44fc3c25ed497b0364eef478377013f3
Public testing pre-release. Use this build to exercise the real desktop installer,
one-time scan-tool setup, guided use cases, and end-to-end results flow. It is not the
latest stable release and has not completed the planned formal QC/code review.
This candidate includes the simplified English and Traditional Chinese product flow and
typed immutable snapshots for repository, IaC, OCI image-layout, Kubernetes manifest, and
node-configuration inputs.
Provider discovery stays inside its released AWS Organizations, Azure subscription, or GCP
organization source boundary. Prowler execution is separately bound to one exact AWS account,
Azure subscription, or GCP project with provider-specific identity preflight and endpoint closure.
Other cloud engines retain their narrower released provider scope.
The required 21-engine catalog is bound to immutable image, launcher, adapter, evidence,
coverage, license, and verification contracts. Scanner images remain separate artifacts
and are not bundled in the desktop installers.
Existing local cases, cleanup obligations, evidence snapshots, and provenance remain intact.
Unknown or partial scope remains visibly distinct from a completed or passing result.
These desktop installers are built for Linux x86-64, universal macOS (Intel + Apple silicon),
and Windows x86-64. Verify the selected file against SHA256SUMS.txt and the public GitHub
artifact attestation before installing.
Fresh GitHub-hosted qualification jobs independently installed the Debian package, macOS DMG,
and Windows MSI. All three platforms completed managed-runtime install, start, status, fixed
network-disabled Gitleaks container execution, stop, uninstall with image-cache purge, and
private-state cleanup. The universal macOS artifact was independently exercised on GitHub's
standard Intel macos-15-intel runner. Exact runner-image and operation evidence is published
per platform.
The current installers are not signed with Apple Developer ID or Windows Authenticode and
are not Apple-notarized. Application update payloads are separately signed with the updater
key, but the operating system may still show an unidentified-developer warning. No scanner
engine image is bundled.
The first-party ai-security-scanner-egress-gateway, isolated
ai-security-scanner-bootstrap-broker, and local ai-security-scanner-cli companion
executables are installed beside the desktop executable.
Platform copies and hashes are included as release evidence and SBOM entries.
CycloneDX and SPDX JSON SBOMs, generated third-party notices, engine reference notices, and
machine-readable release metadata accompany the installers.