Skip to content

Release 1.3.0

Choose a tag to compare

@cedricbonhomme cedricbonhomme released this 17 Jul 12:49
· 30 commits to main since this release
v1.3.0
45752c0

New endpoint: MITRE ATT&CK technique classification.

  • POST /classify/attack-techniques ranks ATT&CK (Enterprise) techniques
    for a vulnerability description using
    CIRCL/vulnerability-attack-technique-classification-roberta-base
    (multi-label; sigmoid scores, top_k selectable, 0.5 prediction
    threshold flagged per technique). Each technique is returned with its
    ID, official name, score, and predicted flag, alongside the same
    model / model_revision provenance fields as /classify/severity.
  • Technique names are resolved from a bundled id -> name table
    extracted from the MITRE enterprise ATT&CK STIX data
    (api/data/attack_technique_names.json).
  • The model is preloaded at startup (gunicorn --preload compatible)
    and included in ml-gw-cli refresh-all.
  • New test suite (poetry run pytest) covering both classification
    endpoints through the router and service layers with a stubbed model
    layer, so it runs without downloading models. pytest and httpx are
    added as a dev dependency group.
  • New CI workflow (GitHub Actions) running mypy and the test suite on
    every push to main and every pull request.
  • The classification endpoints are now plain (non-async) handlers, so
    FastAPI runs them in its threadpool and CPU-bound model inference no
    longer blocks the event loop for concurrent requests.
  • mypy and types-cachetools are now dev dependencies, so
    poetry run mypy api/ uses the project virtualenv instead of relying
    on a system-wide mypy that cannot see the dependencies;
    explicit_package_bases is enabled since api/ is a namespace
    package. Fixed the one strictness error this surfaced
    (Tensor.item() is typed int | float; the argmax index is now
    wrapped in int()).