Releases: thedatakey/apollyon
Releases · thedatakey/apollyon
Release list
Apollyon v0.2.0 — public pre-alpha
Immutable
release. Only release title and notes can be modified.
Apollyon 0.2.0 is the first public pre-alpha release of the evidence-first source-security scanner.
Findings are review candidates, not vulnerability verdicts. A complete scan is not proof that a project is secure.
Added
- Portable
AGENTS.mdworkflow with Claude Code, Cursor, Hermes, Gemini CLI,
GitHub Copilot, Windsurf, Cline, OpenCode, and Aider integration surfaces. - Repository-scoped
apollyon-scanAgent Skill and Claude Code plugin manifest. - C#, Go, Java, Kotlin, JavaScript, TypeScript, PHP, Python, Ruby, and Swift
discovery alongside the existing C, C++, header, and Rust support. - Dynamic-execution, operating-system-command, and unsafe-deserialization rules.
- SARIF 2.1.0 output, safe create-new report files, repeated path exclusions,
expanded default dependency/build exclusions, and arulescommand. - Machine-readable excluded-file/directory coverage accounting and stable
incomplete-scan semantics for empty or unsupported targets. - Mixed handwritten-project fixtures and machine-output contract validation.
- Public GitHub launch materials, installation and checksum-verification guide,
social preview artwork, citation metadata, and security-report routing. - Tag-gated release automation for Linux x86-64, macOS Apple Silicon, macOS
Intel, and Windows x86-64 archives with SHA-256 checksums and GitHub build
attestations.
Changed
- Made coding-agent orchestration optional and platform-neutral.
- Expanded CI validation for portable integrations and output contracts.
- Reworked the README around the current CLI, honest pre-alpha positioning,
copy-paste installation, real output, narrow rule coverage, and download UX. - Disabled accidental crates.io publication until a deliberate package release
process exists.
Downloads
Choose the archive matching your platform. Each archive contains the executable, README, and MIT license.
These binaries are currently unsigned. Verify the archive against SHA256SUMS. Build provenance is attached through GitHub artifact attestations and can be checked with gh attestation verify.