Skip to content

Releases: thedatakey/apollyon

Apollyon v0.2.0 — public pre-alpha

Pre-release

Choose a tag to compare

@github-actions github-actions released this 15 Aug 15:26
Immutable release. Only release title and notes can be modified.

Apollyon 0.2.0 is the first public pre-alpha release of the evidence-first source-security scanner.

Findings are review candidates, not vulnerability verdicts. A complete scan is not proof that a project is secure.

Added

  • Portable AGENTS.md workflow with Claude Code, Cursor, Hermes, Gemini CLI,
    GitHub Copilot, Windsurf, Cline, OpenCode, and Aider integration surfaces.
  • Repository-scoped apollyon-scan Agent Skill and Claude Code plugin manifest.
  • C#, Go, Java, Kotlin, JavaScript, TypeScript, PHP, Python, Ruby, and Swift
    discovery alongside the existing C, C++, header, and Rust support.
  • Dynamic-execution, operating-system-command, and unsafe-deserialization rules.
  • SARIF 2.1.0 output, safe create-new report files, repeated path exclusions,
    expanded default dependency/build exclusions, and a rules command.
  • Machine-readable excluded-file/directory coverage accounting and stable
    incomplete-scan semantics for empty or unsupported targets.
  • Mixed handwritten-project fixtures and machine-output contract validation.
  • Public GitHub launch materials, installation and checksum-verification guide,
    social preview artwork, citation metadata, and security-report routing.
  • Tag-gated release automation for Linux x86-64, macOS Apple Silicon, macOS
    Intel, and Windows x86-64 archives with SHA-256 checksums and GitHub build
    attestations.

Changed

  • Made coding-agent orchestration optional and platform-neutral.
  • Expanded CI validation for portable integrations and output contracts.
  • Reworked the README around the current CLI, honest pre-alpha positioning,
    copy-paste installation, real output, narrow rule coverage, and download UX.
  • Disabled accidental crates.io publication until a deliberate package release
    process exists.

Downloads

Choose the archive matching your platform. Each archive contains the executable, README, and MIT license.

These binaries are currently unsigned. Verify the archive against SHA256SUMS. Build provenance is attached through GitHub artifact attestations and can be checked with gh attestation verify.