ai-security-scanner 0.1.4
Pre-releaseai-security-scanner 0.1.4
Source: 0870fd2db59f9d21c69ad9233b331ffba690fea8
Public testing pre-release. This build fixes the empty 0/0 scan and repeated-consent
experience reported during a first home-network test. It is not the latest stable release
and has not completed the planned formal QC/code review.
Choose what you want to check: a home or office network, website, external IP, source code,
infrastructure as code, cloud account, container image, or Kubernetes configuration. Each
choice now opens only the setup it actually needs and preserves that intent through the run.
For a home or office network, the installed app can read local interface and route metadata
to suggest one safe private subnet. It does not probe the network, select the subnet, grant
permission, or start a scan automatically. One explicit click accepts the suggestion, and
the target remains editable before the single scan confirmation.
A scan run is created only when at least one compatible engine has an authorized target,
the required local tools are ready, and every short-lived cloud connection has enough
capacity for the exact execution plan. Cloud capacity and backend-only credentials are
reserved atomically before the run is saved and released if storage or worker startup fails.
A blocked attempt therefore stays in setup instead of creating a 0/0 run or expanding one
setup problem into many failed scanner checks.
The guided network preset checks a useful bounded set of common TCP services. Website checks
preserve the entered URL protocol and port. Advanced controls remain available without
cluttering the first path.
Setup problems now lead to one relevant action: prepare the private scan tools, connect or
reconnect an account, choose between matching connections, review a mismatched target, or
retry a temporarily unavailable check. Failed or partial runs can export a redacted diagnostic containing
statuses, phases, error codes,
versions, and counts without target names, paths, evidence, or raw scanner messages.
The macOS installer, app layout, packaged manifest, CLI, desktop startup, and cleanup are
qualified on a fresh GitHub-hosted Mac. Managed-runtime and container lifecycle operations
are explicitly recorded as not observed because that hosted environment does not provide the
nested virtualization required by AppleHV. This exception is accepted only for a pre-release;
a stable release still fails closed without real Mac runtime evidence.
Existing local cases, cleanup obligations, evidence snapshots, and provenance remain intact.
These desktop installers are built for Linux x86-64, universal macOS (Intel + Apple silicon),
and Windows x86-64. Verify the selected file against SHA256SUMS.txt and the public GitHub
artifact attestation before installing.
Fresh GitHub-hosted qualification jobs independently installed the Debian package, macOS DMG,
and Windows MSI. Linux and Windows completed managed-runtime install, start, status, fixed
network-disabled Gitleaks container execution, stop, uninstall with image-cache purge, and
private-state cleanup. The universal macOS artifact's DMG installation, bundled layout, exact
runtime manifest, CLI, desktop startup, and cleanup passed on GitHub's Intel macos-15-intel
runner. Its managed-runtime and container lifecycle is explicitly recorded as not observed
because GitHub-hosted macOS does not support the nested virtualization required by AppleHV.
This limited macOS evidence is accepted only for a pre-release. Exact evidence is published
per platform.
The current installers are not signed with Apple Developer ID or Windows Authenticode and
are not Apple-notarized. Application update payloads are separately signed with the updater
key, but the operating system may still show an unidentified-developer warning. No scanner
engine image is bundled.
The first-party ai-security-scanner-egress-gateway, isolated
ai-security-scanner-bootstrap-broker, and local ai-security-scanner-cli companion
executables are installed beside the desktop executable.
Platform copies and hashes are included as release evidence and SBOM entries.
CycloneDX and SPDX JSON SBOMs, generated third-party notices, engine reference notices, and
machine-readable release metadata accompany the installers.