Repository navigation
Release 1.3.0
New endpoint: MITRE ATT&CK technique classification.
POST /classify/attack-techniquesranks ATT&CK (Enterprise) techniques
for a vulnerability description using
CIRCL/vulnerability-attack-technique-classification-roberta-base
(multi-label; sigmoid scores,top_kselectable, 0.5 prediction
threshold flagged per technique). Each technique is returned with its
ID, official name, score, andpredictedflag, alongside the same
model/model_revisionprovenance fields as/classify/severity.- Technique names are resolved from a bundled
id -> nametable
extracted from the MITRE enterprise ATT&CK STIX data
(api/data/attack_technique_names.json). - The model is preloaded at startup (gunicorn
--preloadcompatible)
and included inml-gw-cli refresh-all. - New test suite (
poetry run pytest) covering both classification
endpoints through the router and service layers with a stubbed model
layer, so it runs without downloading models.pytestandhttpxare
added as adevdependency group. - New CI workflow (GitHub Actions) running mypy and the test suite on
every push tomainand every pull request. - The classification endpoints are now plain (non-async) handlers, so
FastAPI runs them in its threadpool and CPU-bound model inference no
longer blocks the event loop for concurrent requests. mypyandtypes-cachetoolsare now dev dependencies, so
poetry run mypy api/uses the project virtualenv instead of relying
on a system-wide mypy that cannot see the dependencies;
explicit_package_basesis enabled sinceapi/is a namespace
package. Fixed the one strictness error this surfaced
(Tensor.item()is typedint | float; the argmax index is now
wrapped inint()).