What's Changed fix(scan): read the lockfiles the scanner already claimed to support by @ralyodio in #143 fix(security): remediate GHSA-6562-32wq-j8hx audit findings by @ralyodio in #144 fix(security): resolve CodeQL alerts introduced by #144 by @ralyodio in #145 fix(store): authenticate module publishing by @rissrice2105-agent in #146 fix(security): close the last SSRF rebinding window in…
What's Changed fix(scan): exempt the metasyntactic credential pair in a DSN by @ralyodio in #107 fix(scan): take notice of a gosec G101 annotation already on the line by @ralyodio in #108 Add tcfeed: a ranked shortlist of repositories worth scanning by @ralyodio in #109 feat(tcfeed): add tcfeed pr , which installs the scan workflow by @ralyodio in #110 fix(tcfeed): make tcfeed pr actually fork,…
What's Changed ci: build the self-scan from source instead of installing @latest by @ralyodio in #100 feat(scan): path exclusion via --exclude and .threatcrushignore (v0.8.0) by @ralyodio in #101 Full Changelog : v0.7.2...v0.8.0
What's Changed fix: repair npm install (workspace: protocol) and the SQL verb false positive (v0.7.2) by @ralyodio in #99 Full Changelog : v0.7.1...v0.7.2
What's Changed Fix scanning for env split-string shebangs by @rissrice2105-agent in #93 refactor(scan): extract the scan engine into @threatcrush/scan by @ralyodio in #94 feat(web): scan code with the shared package, and drop .js from its imports by @ralyodio in #95 fix(scan): stop letting neighbouring code decide a finding's severity (v0.7.1) by @ralyodio in #97 feat(modules): add Feodo Tracker…
What's Changed feat(scan): command injection, SSRF and traversal for Java; traversal and template escaping for Go (v0.7.0) by @ralyodio in #91 Full Changelog : v0.6.2...v0.7.0