ai-security-scanner 0.1.6
Pre-releaseai-security-scanner 0.1.6
Source: 61ed54ef4fb0c9f5fd3c13b2feb7f1c23daad4ca
Public testing pre-release. This build repairs the private connection used by local
network scanners. It has not completed the planned formal QC/code review.
Local network scans no longer depend on a Windows process listening on an address that
exists only inside WSL. The gateway now runs beside the scanners in the private managed
runtime, with separate scanner and uplink networks.
Gateway readiness comes from the running gateway itself. If setup fails, the scan preserves
the concrete failure and cleanup result instead of returning to an unexplained Ready/Repair
loop. Existing event logs and redacted technical downloads remain available for diagnosis.
The downloadable Windows Setup executable and MSI are now installed and exercised in
separate fresh qualification jobs. Each one must prove the gateway is ready and reachable
from the scanner side without making an upstream connection, then remove every exact test
resource before the release can continue.
Existing local cases, cleanup obligations, evidence snapshots, and provenance remain intact.
These desktop installers are built for Linux x86-64, universal macOS (Intel + Apple silicon),
and Windows x86-64. Verify the selected file against SHA256SUMS.txt and the public GitHub
artifact attestation before installing.
Fresh GitHub-hosted qualification jobs independently installed the Debian package, macOS DMG,
Windows MSI, and Windows NSIS Setup executable. Linux and both Windows installers completed
managed-runtime install, start, status, fixed no-upstream managed egress gateway readiness,
network-disabled Gitleaks container execution, stop, uninstall with image-cache purge, and
private-state cleanup. The universal macOS artifact's DMG installation, bundled layout, exact
runtime manifest, CLI, desktop startup, and cleanup passed on GitHub's Intel macos-15-intel
runner. Its managed-runtime, egress gateway, and container lifecycle is explicitly recorded as not observed
because GitHub-hosted macOS does not support the nested virtualization required by AppleHV.
This limited macOS evidence is accepted only for a pre-release. Exact evidence is published
per installer.
The current installers are not signed with Apple Developer ID or Windows Authenticode and
are not Apple-notarized. Application update payloads are separately signed with the updater
key, but the operating system may still show an unidentified-developer warning. No scanner
engine image is bundled.
The first-party ai-security-scanner-egress-gateway, isolated
ai-security-scanner-bootstrap-broker, and local ai-security-scanner-cli companion
executables are installed beside the desktop executable.
Platform copies and hashes are included as release evidence and SBOM entries.
CycloneDX and SPDX JSON SBOMs, generated third-party notices, engine reference notices, and
machine-readable release metadata accompany the installers.