Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
340 commits
Select commit Hold shift + click to select a range
ff92864
chore(arch): hardening batch from 2026-06 architecture audit (#154)
0xmanhnv Jun 6, 2026
6360102
ops(migrate): preflight-migrate.sh — block deploy on data that would …
0xmanhnv Jun 6, 2026
54672fe
feat(scancoverage): coverage observability API (RFC-007 Phase 4) (#156)
0xmanhnv Jun 6, 2026
f973d35
fix(integration): tenant-scoped fetch on mutating paths (defense-in-d…
0xmanhnv Jun 6, 2026
3c043b2
feat(outbox): alert when a notification is dead-lettered (#158)
0xmanhnv Jun 6, 2026
bc600fd
docs(rfc-008): native shift-left CI scanning — plan + architecture di…
0xmanhnv Jun 6, 2026
af87422
feat(ingest): baseline-diff (new-vs-target) for PR scans (RFC-008 Pha…
0xmanhnv Jun 6, 2026
82335b0
docs(rfc-008): mark Phase 3 (PR new-vs-base) shipped end-to-end (#161)
0xmanhnv Jun 6, 2026
c3acac3
feat(pentest): XLSX export for campaign findings (RFC-008 Phase 6) (#…
0xmanhnv Jun 8, 2026
d287bfd
docs(rfc-006): detailed Phase 3 — bidirectional Jira status sync (#163)
0xmanhnv Jun 8, 2026
05c1948
feat(jira): client transition + comment support (RFC-006 Phase 3a) (#…
0xmanhnv Jun 8, 2026
f744156
feat(jira): complete + correct status maps, add outbound direction (R…
0xmanhnv Jun 8, 2026
3f68a72
ci(dependabot): target develop, not the default branch (main) (#169)
0xmanhnv Jun 8, 2026
6d71445
feat(jira): bidirectional sync — outbound status push (RFC-006 Phase …
0xmanhnv Jun 8, 2026
5afc564
docs(ticketing): document bidirectional sync (outbound) + config.tick…
0xmanhnv Jun 12, 2026
d97e22d
fix: hidden bugs from deep-dive (jira url-escape, bulk Jira sync, rat…
0xmanhnv Jun 12, 2026
7637c0e
fix(websocket): send-on-closed-channel panic race in Client (#174)
0xmanhnv Jun 12, 2026
5143a3f
feat(report): generic findings executive-summary generator (#175)
0xmanhnv Jun 12, 2026
faef2a3
docs: project assessment & prioritized roadmap (#176)
0xmanhnv Jun 12, 2026
4d01a57
feat(report): scheduler controller — run due schedules + email delive…
0xmanhnv Jun 13, 2026
d270463
docs(roadmap): mark Tier-1 #1 (report scheduler) + #3 (risk trending)…
0xmanhnv Jun 13, 2026
fc35c16
feat(remediation): compute live campaign progress + auto-complete (#179)
0xmanhnv Jun 13, 2026
2f8b9a8
docs: feature-ideas backlog — full-surface audit + 40 grounded propos…
0xmanhnv Jun 13, 2026
e074fa0
fix(priority): derive reachability from asset exposure (#181)
0xmanhnv Jun 13, 2026
ae63831
feat(sso): platform-wide Entra ID env fallback when tenant has none (…
0xmanhnv Jun 13, 2026
ef6a298
feat(priority): risk-score explainability endpoint (#183)
0xmanhnv Jun 13, 2026
ef47327
feat(remediation): create Jira epic from a campaign (#184)
0xmanhnv Jun 13, 2026
d9f5331
feat(remediation): campaign↔Jira-epic bidirectional sync (outbound + …
0xmanhnv Jun 13, 2026
e98b12a
feat(report): enrich scheduled digest — KEV/EPSS/SLA risk posture + n…
0xmanhnv Jun 13, 2026
899c8a9
feat(remediation): include linked Jira epic in campaign responses (#188)
0xmanhnv Jun 13, 2026
3334138
feat(ticketing): add GitHub Issues as a finding ticket provider (#189)
0xmanhnv Jun 13, 2026
18e2e53
feat(ticketing): inbound GitHub issue → finding status sync (#190)
0xmanhnv Jun 13, 2026
5c7baa5
fix: hidden-bug deep-dive — lifecycle, async resilience, tenant DiD, …
0xmanhnv Jun 14, 2026
b520d26
feat(ticketing): outbound GitHub issue status sync (#193)
0xmanhnv Jun 15, 2026
269ddd4
feat(auth): verify SSO id_token signature, nonce, issuer & audience (…
0xmanhnv Jun 15, 2026
ffc73c1
feat(validation): evidence ingestion MVP — record proof-of-fix, recon…
0xmanhnv Jun 15, 2026
1c7d89c
feat(reports): pentest report PDF export (pure Go, no headless browse…
0xmanhnv Jun 15, 2026
c53aab7
docs(rfc): RFC-009 enterprise SSO — SAML 2.0 + SCIM 2.0 provisioning …
0xmanhnv Jun 15, 2026
dd9f02a
feat(scim): SCIM 2.0 provisioning core — tokens + Users (RFC-009 9a/9…
0xmanhnv Jun 15, 2026
98a68e7
fix(scim): three hidden bugs in SCIM provisioning (#199)
0xmanhnv Jun 18, 2026
1414c40
fix(scim): system deprovisioning fails (no actor) + real-DB integrati…
0xmanhnv Jun 18, 2026
99a2249
test(validation): real-DB integration coverage for evidence ingest (#…
0xmanhnv Jun 18, 2026
bd3c744
feat(scim): SCIM 2.0 Groups → role mapping (RFC-009 Phase 9c) (#202)
0xmanhnv Jun 18, 2026
2c3c279
feat(scim): configurable group -> role mapping (RFC-009 9c refinement…
0xmanhnv Jun 19, 2026
72e3ddf
feat(saml): SAML 2.0 SP config + metadata + federated-login seam (RFC…
0xmanhnv Jun 19, 2026
dbb05f7
feat(ticketing): default Jira project + project picker + wire mapping…
0xmanhnv Jun 22, 2026
c2641bc
docs(rfc): RFC-010 Jira Assets / JSM CMDB integration (enrich + recon…
0xmanhnv Jun 22, 2026
bef9efb
Merge remote-tracking branch 'origin/main' into tmp-210-dev
Jun 22, 2026
1771252
chore: stop tracking .claude/settings.local.json (per-developer local…
Jun 22, 2026
01a75f6
deps(go): bump github.com/redis/go-redis/v9 in the go-minor-patch gro…
dependabot[bot] Jun 22, 2026
3a440b0
feat(ticketing): routing rules — route findings to projects by severi…
0xmanhnv Jun 22, 2026
3c2fffd
ci: drop Dependabot docker ecosystem (ECR Public not queryable → alwa…
0xmanhnv Jun 24, 2026
e77e008
docs(ticketing): reflect shipped operator UI (picker, create-ticket, …
0xmanhnv Jun 29, 2026
fa4f42c
deps(actions): bump imjasonh/setup-crane from 0.5 to 0.7 (#215)
dependabot[bot] Jun 29, 2026
6a00695
deps(go): bump golang.org/x/tools in the go-minor-patch group (#216)
dependabot[bot] Jun 29, 2026
c5bbdb5
fix(jira): case-insensitive idempotency marker + robust ticket-key ex…
0xmanhnv Jun 29, 2026
f7aa078
fix(auth): block cross-IdP account takeover in OAuth/SSO find-or-crea…
0xmanhnv Jun 29, 2026
a0092af
fix(security): scope credential-bearing repo Updates by tenant_id (de…
0xmanhnv Jun 29, 2026
a8bc1ff
fix(reports): validate report-schedule cron + report_type at creation…
0xmanhnv Jun 29, 2026
752d605
fix(core): reject empty-tenant on delete (IDOR) + align AutoReopen st…
0xmanhnv Jun 29, 2026
9c90001
fix(auth): bind SSO/OAuth sessions to their JWT so they are revocable…
0xmanhnv Jun 29, 2026
630fcff
chore(security): delete dead unscoped repo + handler (landmines) (#223)
0xmanhnv Jun 29, 2026
7ab59db
fix(security): enforce agent ingest/telemetry rate limits (DoS bypass…
0xmanhnv Jun 29, 2026
0e24a2e
fix(security): gate workflow action nodes by per-resource permission …
0xmanhnv Jun 29, 2026
10baa3a
fix(workflow): unimplemented action handlers fail loudly (no false su…
0xmanhnv Jun 29, 2026
e626fc2
fix(security): guard agent handlers against nil-tenant platform agent…
0xmanhnv Jul 1, 2026
97f6d13
fix(security): bind federated accounts to their IdP issuer (cross-IdP…
0xmanhnv Jul 1, 2026
82b363e
fix(pentest): UpdateRoleSafely referenced non-existent updated_at col…
0xmanhnv Jul 1, 2026
7459588
fix(compliance): live control total in score (was >100% / negative) (…
0xmanhnv Jul 1, 2026
77a3c16
fix(postgres): correct latent batch-upsert landmines (asset_services,…
0xmanhnv Jul 1, 2026
20b4ffb
fix(postgres): correct finding open-count status set + dataflow pagin…
0xmanhnv Jul 1, 2026
8089d6b
fix(components): return 404 (not 500) for a missing component (#233)
0xmanhnv Jul 1, 2026
9c549da
fix(handlers): finding-groups pagination swap + audit divide-by-zero …
0xmanhnv Jul 1, 2026
4b64a74
fix(ingest): merge component errors into output so audit reflects fai…
0xmanhnv Jul 1, 2026
3bdef46
fix(threat): reject malformed IDs in GetActor/DeleteActor (#236)
0xmanhnv Jul 1, 2026
599977f
fix(aitriage): fail loudly on batch-check error + un-stick triage on …
0xmanhnv Jul 1, 2026
b6fa70f
fix(exposure): reject invalid list-filter values instead of returning…
0xmanhnv Jul 1, 2026
0271831
fix(ingest): CheckFingerprints checks all fingerprints (was truncatin…
0xmanhnv Jul 1, 2026
5951233
fix(asset-dedup): render merge-log text columns as strings, not base6…
0xmanhnv Jul 1, 2026
5579811
fix(findings): distinguish persistence failures from skips in BulkFix…
0xmanhnv Jul 1, 2026
bf741b3
fix(remediation): stable denominator so campaign progress can't excee…
0xmanhnv Jul 1, 2026
aaf333c
test(e2e): full feature-flow suite + checklist (+ migration-drift & C…
0xmanhnv Jul 1, 2026
cc46819
feat(startup): fail fast when the DB schema is behind shipped migrati…
0xmanhnv Jul 2, 2026
986750a
fix(findings): apply status before persisting approval (no permanent …
0xmanhnv Jul 2, 2026
04d2a11
fix(assignment): resolve asset type so AssetTypes rules can match (br…
0xmanhnv Jul 2, 2026
fd4eff4
feat(validation): RFC-011 dispatch — make CTEM Stage-4 executable (#247)
0xmanhnv Jul 2, 2026
9de2d27
fix(validation): read validate outcome from result.metadata (agent pa…
0xmanhnv Jul 2, 2026
f9ccd55
feat(auth): SAML 2.0 SP-initiated login + ACS (RFC-009 9e) (#249)
0xmanhnv Jul 2, 2026
0fbfafb
feat(validation): tenant validation-coverage KPI (RFC-011) (#250)
0xmanhnv Jul 2, 2026
f6589c8
feat(compliance): deterministic finding->OWASP control auto-mapping (…
0xmanhnv Jul 2, 2026
31f0690
fix(validation): coverage total must COUNT(DISTINCT f.id), not COUNT(…
0xmanhnv Jul 2, 2026
0b5291a
fix(auth): block cross-tenant account takeover via federated login (H…
0xmanhnv Jul 2, 2026
3f750b2
fix(dedup): recompute finding fingerprints after asset merge (#255)
0xmanhnv Jul 3, 2026
0d08068
docs(roadmap): mark Validation engine, SSO/SAML/SCIM, and PDF export …
0xmanhnv Jul 3, 2026
2d454fc
feat(attack-surface): exposure chains — shortest attack paths to KEV/…
0xmanhnv Jul 3, 2026
176473f
fix: revert unsafe dedup fingerprint recompute + correct CWE-611 mapp…
0xmanhnv Jul 3, 2026
98f50b2
fix(validation): only auto-resolve findings from the fix_applied (pro…
0xmanhnv Jul 3, 2026
b99cf09
Merge main (squashed release #210) into develop to reconcile history …
Jul 3, 2026
4df37b6
deps(go): bump the go-minor-patch group with 6 updates (#261)
dependabot[bot] Jul 3, 2026
d5e07b8
fix(auth): close nOAuth account-takeover on global "Sign in with Micr…
0xmanhnv Jul 6, 2026
233c322
fix(dedup): correct composite-aware fingerprint recompute after asset…
0xmanhnv Jul 6, 2026
a397a6a
fix: deep-dive follow-ups (dedup base persistence, recompute/chain ro…
0xmanhnv Jul 7, 2026
045e0f0
feat(ctem): infer asset internet-exposure at ingest → unlock reachabi…
0xmanhnv Jul 7, 2026
8c6c84a
feat(ctem): auto-queue proof-of-fix re-check on fix_applied (#266)
0xmanhnv Jul 7, 2026
02f5b93
feat(ctem): auto-route findings to groups on bulk ingest (#267)
0xmanhnv Jul 7, 2026
7320890
feat(ctem): wire workflow ticket actions + register AI-triage action …
0xmanhnv Jul 7, 2026
78dc026
feat(ctem): recompute SLA deadline when a sweep escalates finding pri…
0xmanhnv Jul 7, 2026
8cf27fd
feat(ctem): RFC-012 + stop fabricating BAS detections (Tier-1 Phase 0…
0xmanhnv Jul 7, 2026
695fc41
feat(ctem): persist simulation runs (RFC-012 Phase 1a) (#271)
0xmanhnv Jul 7, 2026
6220df0
feat(ctem): real safe-check dispatch for simulations (RFC-012 Phase 1…
0xmanhnv Jul 7, 2026
7c676c6
feat(integrations): RFC-013 DefectDojo co-existence — DD→CTIS convert…
0xmanhnv Jul 7, 2026
5bad668
feat(integrations): DefectDojo live sync — client + service + endpoin…
0xmanhnv Jul 8, 2026
53bcc7e
feat(analytics): finding source breakdown + DefectDojo-dependency rat…
0xmanhnv Jul 8, 2026
bad582c
fix(assets): stop dropping scanner CTEM signals + sub_type at the ing…
0xmanhnv Jul 8, 2026
4f10c30
fix(assets): wire owner_ref→user auto-resolution (was dead) (#277)
0xmanhnv Jul 8, 2026
3e67be5
perf(assets): scope finding-count aggregate with LATERAL (kill per-re…
0xmanhnv Jul 8, 2026
06748d0
chore(assets): remove dead AssetService methods (SCM-sync cluster + A…
0xmanhnv Jul 8, 2026
ab06f6f
feat(integrations): DefectDojo auto-sync scheduler (RFC-013 Phase 2c)…
0xmanhnv Jul 8, 2026
c1a66d0
docs(rfc): RFC-014 k8s-style agent identity (short-lived, auto-rotati…
0xmanhnv Jul 8, 2026
2eca2ab
feat(agent): self-service API-key renewal endpoint (RFC-014 Phase 1a)…
0xmanhnv Jul 8, 2026
a19541b
feat(agent): API-key expiry + configurable TTL (RFC-014 Phase 1b) (#283)
0xmanhnv Jul 8, 2026
7b4eee9
docs(architecture): agent identity & credentials (shipped-vs-planned)…
0xmanhnv Jul 8, 2026
5f251f1
feat(agent): rotation overlap via multi-key store (RFC-014 Phase 3) (…
0xmanhnv Jul 8, 2026
2cfdcd4
fix(agent): retire inline key once + status-guarded expiry update (RF…
0xmanhnv Jul 8, 2026
1ce3ace
ci: bump Go toolchain 1.26.4 -> 1.26.5 (GO-2026-5856) (#287)
0xmanhnv Jul 10, 2026
3317798
feat(remediation): remediation groups — fix a solution family in one …
0xmanhnv Jul 10, 2026
88cd5ac
fix(remediation): sanitize user-controlled key before logging (CodeQL…
0xmanhnv Jul 10, 2026
18c7c4c
docs(architecture): module coupling & path to feature-toggleable modu…
0xmanhnv Jul 10, 2026
0976c01
feat(remediation): campaign can actively resolve its open findings (R…
0xmanhnv Jul 10, 2026
8035e06
feat(modules): RequireModule route gating middleware (decoupling Phas…
0xmanhnv Jul 10, 2026
e5e9e6b
feat(modules): invalidate module-gate cache on toggle (instant enforc…
0xmanhnv Jul 10, 2026
95a724b
feat(modules): gate simulation, threat-intel, remediation route group…
0xmanhnv Jul 10, 2026
335e705
feat(modules): gate pipelines + workflows route groups (Phase 1 rollo…
0xmanhnv Jul 10, 2026
31b9ae0
chore(lint): depguard rule freezing core-domain isolation (decoupling…
0xmanhnv Jul 10, 2026
194bb27
feat(remediation): spawn a tracked campaign from a solution-family gr…
0xmanhnv Jul 10, 2026
0a567e0
feat: read-only MCP server + tenant-scoped API-key auth (RFC-016) (#299)
0xmanhnv Jul 10, 2026
c1b9487
deps(go): bump the go-minor-patch group with 11 updates (#300)
dependabot[bot] Jul 13, 2026
c6b73b4
feat(modules): persistent, live-resolved product bundles (ASM/ASPM/VM…
0xmanhnv Jul 13, 2026
bd63399
feat(prioritization): feed attack-path reachability into finding prio…
0xmanhnv Jul 13, 2026
b413512
feat(prioritization): raise findings with business impact (close-the-…
0xmanhnv Jul 13, 2026
77f1c16
fix(modules): CTEM Full enables every real module + empty-baseline fa…
0xmanhnv Jul 13, 2026
d1a3e04
fix(modules): concurrency-safe subscribe, curation-aware inheritance,…
0xmanhnv Jul 13, 2026
69144a5
fix(findings): enrich the findings list with asset name (was showing …
0xmanhnv Jul 14, 2026
a4fb9bc
docs(rfc): RFC-017 — CTEM prioritization surfacing & loop closure (#307)
0xmanhnv Jul 14, 2026
6713abe
feat(findings): surface CTEM priority — sort, filter & default P0-fir…
0xmanhnv Jul 14, 2026
771b28f
fix(remediation): unscoped campaign tracks nothing, not the whole ten…
0xmanhnv Jul 14, 2026
fb9a323
feat(remediation): campaign assignment, finding-ids scope, start/due …
0xmanhnv Jul 14, 2026
3eaf577
fix(dashboard): risk-trend 500 — date >= integer type error (#311)
0xmanhnv Jul 16, 2026
1ae83e3
fix(security): pin Go toolchain to 1.26.5 (patch 10 reachable stdlib …
0xmanhnv Jul 16, 2026
ee7c0e6
fix(security): close cross-tenant IDOR in tools, roles, permission-se…
0xmanhnv Jul 16, 2026
6d7c762
fix(security): close SSRF gaps in webhook validation, DefectDojo, git…
0xmanhnv Jul 16, 2026
27721e4
fix(security): hash auth tokens at rest, activate perm-version revoca…
0xmanhnv Jul 16, 2026
e3d2938
fix(security): clamp per_page on all list endpoints (DoS + divide-by-…
0xmanhnv Jul 16, 2026
621d42c
fix(security): validate inline scan-command templates server-side (ag…
0xmanhnv Jul 16, 2026
41b4721
fix: duplicate tool import in tool_handler (merge artifact broke deve…
Jul 16, 2026
2c04aaa
fix(scan): agent-SDK field names in scan command payload (scanner/con…
Jul 16, 2026
7457c1b
fix(dashboard): populate average risk score (was always 0.0) (#318)
0xmanhnv Jul 16, 2026
4570877
fix(risk-score): opt-in amplify_headroom mode to de-saturate top of r…
0xmanhnv Jul 16, 2026
487225a
fix(pentest): correct campaign-type & finding-status validation drift…
0xmanhnv Jul 16, 2026
8680b0c
fix(pentest): make Reports functional — lifecycle, type/format, retes…
0xmanhnv Jul 17, 2026
3076d46
feat(pentest): persist mitre_technique_id/tactic + cvss_version (+ fi…
0xmanhnv Jul 17, 2026
61de2c3
fix(mcp): harden read-only MCP server per adversarial audit (#323)
0xmanhnv Jul 17, 2026
2f5deef
feat(mcp): pentest report-writing tools + prompts (Phase 1, read-only…
0xmanhnv Jul 17, 2026
6d18b8d
deps(actions): bump actions/setup-go from 6 to 7 (#325)
dependabot[bot] Jul 20, 2026
249cc74
deps(go): bump the go-minor-patch group with 4 updates (#326)
dependabot[bot] Jul 20, 2026
72976d6
fix(persistence): stop silently dropping owner_ref, campaign metadata…
0xmanhnv Jul 20, 2026
c845d71
fix(persistence): stop ticketing project_key corruption + asset-lifec…
0xmanhnv Jul 20, 2026
87b917f
fix(settings): partial-merge tenant settings PATCH to stop wiping omi…
0xmanhnv Jul 20, 2026
b475ded
feat(business-unit): persist criticality, risk_tolerance, and parent …
0xmanhnv Jul 20, 2026
e17526c
fix(api): 9 deferred/functional backend bugs — atomic campaign lead, …
0xmanhnv Jul 20, 2026
de578e3
fix(api): remaining LOW bugs — autoassign N+1, fix-applied scoping (+…
0xmanhnv Jul 20, 2026
95d50a6
fix(api): enforce threat-actor + Jira-ticket input validation; report…
0xmanhnv Jul 20, 2026
fc555ee
fix(reports): scan NULL last_status without erroring the list endpoin…
0xmanhnv Jul 21, 2026
a2055de
feat(findings): manual evidence + remediation-step endpoints (generic…
0xmanhnv Jul 21, 2026
6dfe668
feat(finding): delete manual evidence note + enrich list with uploade…
0xmanhnv Jul 21, 2026
4d6cfe3
fix(security): harden new-surface LOW residuals + quick-scan target d…
0xmanhnv Jul 23, 2026
cd7e5fa
feat(threat-model): continuous threat modeling — P1 backend (RFC docs…
0xmanhnv Jul 23, 2026
be882eb
feat(threat-model): add tactic × technique coverage endpoint (#339)
0xmanhnv Jul 23, 2026
112920f
fix(auth): SSO/Entra P0 hardening — close auto-join + nOAuth holes (#…
0xmanhnv Jul 23, 2026
338a726
feat(auth): SSO P1 — DNS domain verification (JIT trust gate) + PKCE …
0xmanhnv Jul 23, 2026
0810275
test(scim): assert deprovision revokes sessions + cross-tenant isolat…
0xmanhnv Jul 23, 2026
902355a
docs: add Microsoft Entra ID (Azure AD) SSO operator how-to (#343)
0xmanhnv Jul 24, 2026
29ae0fd
feat(auth): public GET /api/v1/auth/providers login-capability snapsh…
0xmanhnv Jul 24, 2026
0fe6431
feat(auth): enforce per-tenant SSO with owner break-glass (SSO P2) (#…
0xmanhnv Jul 24, 2026
b251b25
fix(security): harden platform-admin RBAC at the route layer (#346)
0xmanhnv Jul 24, 2026
36194bc
chore(deploy): error-proof migrations around the fail-fast schema che…
0xmanhnv Jul 24, 2026
527f8dd
docs(sso): multi-tenant EntraID model — one platform, many tenants, e…
0xmanhnv Jul 24, 2026
b9bb2b8
feat(auth): SSO fast-revoke — per-request enforce-SSO + OIDC back-cha…
0xmanhnv Jul 24, 2026
08deaee
feat(auth): proof-before-link for SSO/OAuth account adoption (#350)
0xmanhnv Jul 24, 2026
3de96ab
feat(asset-graph): infer Exposes/RunsOn edges beyond DNS (#351)
0xmanhnv Jul 24, 2026
b798da0
feat(priority): wire threat-model + persist is_reachable into CTEM pr…
0xmanhnv Jul 24, 2026
89bcd1e
feat(threatmodel): background controller keeps threat models fresh (#…
0xmanhnv Jul 24, 2026
31b6f1b
fix(threat-intel): repair EPSS CSV parse + add KEV fallback mirror (#…
0xmanhnv Jul 24, 2026
6087898
fix(ingest): give the ingest worker a real per-run timeout (#355)
0xmanhnv Jul 24, 2026
7d54bfa
fix(audit): dedup audit-chain-break alerts so a persisting break page…
0xmanhnv Jul 24, 2026
222c7f4
fix(threat-intel): KEV cwes array + EPSS percentile overflow (follow-…
0xmanhnv Jul 25, 2026
6269321
fix(threat-intel): widen EPSS staging temp-table percentile to match …
0xmanhnv Jul 25, 2026
4e4219d
fix(api): handler panic no longer kills the process; ingest crash vec…
0xmanhnv Jul 26, 2026
bac99db
fix(api): three schema-drift bugs that made whole features silently d…
0xmanhnv Jul 26, 2026
d230042
fix(audit): stop the tamper-evident chain from corrupting itself; sto…
0xmanhnv Jul 27, 2026
eebf48c
fix(semgrep): a partially-parsed file no longer discards the entire s…
0xmanhnv Jul 27, 2026
3b96f81
deps(go): bump the go-minor-patch group with 7 updates (#363)
dependabot[bot] Jul 27, 2026
4a05ea2
ci: gate on Go-vs-database schema drift (+ fix the drift it found) (#…
0xmanhnv Jul 27, 2026
a82082f
docs: OASM competitive comparison + phased adoption plan (#365)
0xmanhnv Jul 27, 2026
d48cb7a
fix(api): GET /scans/{id}/runs returns the API's own JSON shape (#366)
0xmanhnv Jul 27, 2026
f02f130
docs(competitive): re-order the plan around what verification proved …
0xmanhnv Jul 27, 2026
e9257dc
ci: run the integration tests that have been silently skipping (#368)
0xmanhnv Jul 27, 2026
f81104e
deps: bump grpc to v1.82.1 for GO-2026-6061 (#371)
0xmanhnv Jul 28, 2026
fc24eed
ci: actually run golangci-lint on api (#369)
0xmanhnv Jul 28, 2026
48eae09
ci: run the security gates that have never run (#370)
0xmanhnv Jul 28, 2026
86d3034
fix(findings): reconcile the three definitions of a finding source (#…
0xmanhnv Jul 28, 2026
fb050c6
docs(adr): finding provenance belongs to the sighting, not the findin…
0xmanhnv Jul 28, 2026
bdcecaf
fix(ingest): stop recording every unknown scanner as SAST (#373) (#375)
0xmanhnv Jul 28, 2026
74affd0
fix(ingest): capability matching was substring, and mis-routed six re…
0xmanhnv Jul 28, 2026
cf15bd6
feat(findings): record which channel reported a finding (#377)
0xmanhnv Jul 28, 2026
d265cd6
fix(migrations): 000197 failed on the live database, and CI could not…
0xmanhnv Jul 29, 2026
bb7a51c
fix(scan): a single scan could never report success or a real failure…
0xmanhnv Jul 30, 2026
b9f6f9b
ci: the weekly security sweep never scanned the container image (#380)
0xmanhnv Jul 30, 2026
cffec29
tools(audit): prove every chain break before anyone rebaselines (#381)
0xmanhnv Jul 31, 2026
1d0f000
fix(scan): scheduled scans with no next_run_at are invisible, and not…
0xmanhnv Jul 31, 2026
b6c5b8e
test(scan): cover the half of the scan loop that had no test (#383)
0xmanhnv Jul 31, 2026
261f41b
fix(agent): an agent created without a job capacity can never be sche…
0xmanhnv Jul 31, 2026
26d31b1
fix(pipeline): a run reported twice the findings a scan actually prod…
0xmanhnv Jul 31, 2026
273afe6
fix(agents): an agent that never heartbeated wins every dispatch, for…
0xmanhnv Aug 1, 2026
29b1825
Release: develop → main (2026-07-03) (#260) (#393)
0xmanhnv Aug 2, 2026
5d856ad
fix(findings): the regression metric has never had a writer (#388)
0xmanhnv Aug 2, 2026
10e02e2
fix(workers): the async job worker never ran, and the controllers ran…
0xmanhnv Aug 2, 2026
d2044a6
fix(audit): chain ingest audit events into the tamper-evident hash ch…
0xmanhnv Aug 2, 2026
2a85d94
fix(auth): social login buttons 404 — wire the OAuth handler (#391)
0xmanhnv Aug 2, 2026
b990aa3
ci: scan the release-candidate image before the tag, not after (#392)
0xmanhnv Aug 2, 2026
63e20c6
fix(lint): clear the lint debt that only becomes visible at release (…
0xmanhnv Aug 2, 2026
872594a
fix(priority): deliver priority escalations — publisher was never wir…
0xmanhnv Aug 3, 2026
7ace3e8
fix(commands): platform-job recovery could never run, and expiry told…
0xmanhnv Aug 3, 2026
7d4e99d
fix(config): three settings an operator can set that did nothing (#398)
0xmanhnv Aug 3, 2026
9664675
deps(go): bump the go-minor-patch group with 6 updates (#401)
dependabot[bot] Aug 3, 2026
30ff053
fix(notifications): six event types were delivered nowhere, silently …
0xmanhnv Aug 3, 2026
b0096a1
feat(notifications): serve the event-type registry instead of letting…
0xmanhnv Aug 3, 2026
0faf51c
test(module): DB-backed parity guard for the module catalog (#402)
0xmanhnv Aug 3, 2026
686d898
fix(simulation): live safe-check dispatch panics instead of running (…
0xmanhnv Aug 3, 2026
5d9423a
fix(controls): compensating controls were impossible to create and in…
0xmanhnv Aug 3, 2026
9993269
tools: script the release branch instead of rebuilding it by hand eac…
0xmanhnv Aug 3, 2026
807c759
feat(openapi): the spec is generated and CI-enforced, not hand-mainta…
0xmanhnv Aug 3, 2026
c072130
docs(openapi): correct the make swagger comment (#408)
0xmanhnv Aug 3, 2026
c72d191
test: serialize cross-tenant sweep tests, and stop defaulting tests a…
0xmanhnv Aug 3, 2026
789b2b3
feat(validation): answer "did our controls react?" without overloadin…
0xmanhnv Aug 3, 2026
3b8a213
fix(command): give commands a default expiry so the expiry path can s…
0xmanhnv Aug 3, 2026
91e573f
fix(notifications): stop the severity filter from eating approval eve…
0xmanhnv Aug 4, 2026
0a39459
fix(telemetry): report unpaired events, and retract migration 000155'…
0xmanhnv Aug 4, 2026
437e25f
fix(audit): bring authentication events under the tamper-evident chai…
0xmanhnv Aug 4, 2026
f7867d4
chore(release): carry main's ancestry into v0.5.0
Aug 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,47 @@ jobs:
working-directory: api
run: GOWORK=off go test ./tools/lint/getbyid/... -count=1

# ============================================
# OpenAPI contract gate — api/openapi/swagger.yaml is generated by swag from
# the handler // @Router annotations, and until now nothing checked that the
# committed file still matched them. It had drifted to the point of describing
# a different server: 30 documented paths with no route anywhere in the repo
# (a closed-source era leftover), and 40 real endpoints missing, including the
# entire /notifications API.
#
# That is a client bug, not a docs bug — the UI generates its API types from
# this file, so a stale entry ships a request to an endpoint that does not
# exist and a missing entry hides a feature from every client.
#
# This compares SETS of operations (annotations vs spec vs registered routes),
# not the bytes of the generated file. A byte gate was tried first and failed
# here for a reason worth recording: swag is not hermetic. A clean runner
# drops `format: int64` from some map[string]int64 fields that a developer
# machine emits — same pinned swag, same Go, warm module cache. Both documents
# describe the same API, so the gate would have failed on a non-disagreement
# nobody could fix, and would have been deleted. See
# tools/lint/openapicontract.
#
# Deliberately UNCONDITIONAL: no `if:` on event_name, no base-ref lookup, and
# the script fails (rather than skips) when its inputs are missing.
# Conditional gates in this repository have twice turned out never to run.
# ============================================
openapi:
name: OpenAPI Contract
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v7

- name: Setup Go
uses: actions/setup-go@v7
with:
go-version: ${{ env.GO_VERSION }}
cache: true

- name: Spec matches the handler annotations
run: bash scripts/check-openapi.sh

lint:
name: Lint
runs-on: ubuntu-latest
Expand Down
59 changes: 46 additions & 13 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -108,6 +108,14 @@ lint-ci: lint-new
@echo "Running staticcheck..."
@GOWORK=off go run honnef.co/go/tools/cmd/staticcheck@latest ./...

## release-branch: build a release branch that can merge into main (VERSION=v0.5.0)
## Releases are squash-merged, so main ends up single-parent and git stops seeing
## that develop contains it — the next release then reports conflicts that are not
## disagreements. This carries the ancestry inside the branch instead, so it merges
## cleanly regardless of which button is pressed. Add PUSH=--push when ready.
release-branch:
@bash scripts/release-branch.sh $(VERSION) $(PUSH)

## fmt: Format code
fmt:
@echo "Formatting code..."
Expand All @@ -118,21 +126,46 @@ tidy:
@echo "Tidying dependencies..."
$(GOMOD) tidy

## swagger: Generate OpenAPI documentation using swag
swagger:
## swagger: Regenerate api/openapi/swagger.yaml from the handler annotations.
## The spec is a GENERATED artifact — never hand-edit it. The UI generates its
## API types from the committed file, and scripts/check-openapi.sh fails CI when
## the annotations, the spec and the registered routes stop agreeing.
##
## Previously this target printed "swag not installed" and exited 0, so a
## regeneration that never happened looked exactly like one that succeeded.
swagger: swagger-install
@echo "Generating Swagger documentation..."
@if command -v swag >/dev/null 2>&1; then \
GOWORK=off swag init --generalInfo cmd/server/main.go --output api/openapi --outputTypes yaml --parseDependency; \
echo "" >> api/openapi/swagger.yaml; \
echo "Swagger docs generated in api/openapi/"; \
else \
echo "swag not installed. Run: make swagger-install"; \
fi

## swagger-install: Install swag CLI tool
@# --parseDependency walks into dependency packages — the asset-type enum
@# descriptions come from github.com/openctemio/ctis, not from this module,
@# and without the flag swag fails outright on json.RawMessage. Download
@# first so it is reading source rather than guessing.
@#
@# This does NOT make swag reproducible: a clean runner still drops
@# `format: int64` from some map[string]int64 fields that a developer
@# machine emits, with the same swag, the same Go and a warm cache. That is
@# why the gate compares sets of operations rather than bytes. See
@# tools/lint/openapicontract.
@GOWORK=off go mod download
@GOWORK=off $(SWAG) init --generalInfo cmd/server/main.go --output api/openapi --outputTypes yaml --parseDependency
@echo "Swagger docs generated in api/openapi/"

## swagger-check: Fail if the annotations, the spec and the routes disagree.
## Compares SETS of operations, not the bytes of the generated file — swag is
## not reproducible enough across environments for a byte diff to hold. See
## tools/lint/openapicontract for why.
swagger-check:
@bash scripts/check-openapi.sh

## swagger-install: Install the pinned swag CLI (no-op if already present).
## Pinned: an upstream release must not be able to change the committed contract
## or turn every PR red. Bump here and in scripts/check-openapi.sh together.
SWAG_VERSION ?= v1.16.4
SWAG := $(shell command -v swag 2>/dev/null || echo "$$(go env GOPATH)/bin/swag")
swagger-install:
@echo "Installing swag..."
go install github.com/swaggo/swag/cmd/swag@latest
@if ! "$(SWAG)" --version 2>/dev/null | grep -qF "$(SWAG_VERSION)"; then \
echo "Installing swag $(SWAG_VERSION)..."; \
GOWORK=off GOFLAGS=-mod=mod go install github.com/swaggo/swag/cmd/swag@$(SWAG_VERSION); \
fi

## clean: Clean build artifacts
clean:
Expand Down
Loading