RSSAmplifier

Blog

Release notes from threatcrush

github.comRSS feed ↗10 posts

Latest posts

ThreatCrush 0.11.2

What's Changed fix(scan): read the lockfiles the scanner already claimed to support by @ralyodio in #143 fix(security): remediate GHSA-6562-32wq-j8hx audit findings by @ralyodio in #144 fix(security): resolve CodeQL alerts introduced by #144 by @ralyodio in #145 fix(store): authenticate module publishing by @rissrice2105-agent in #146 fix(security): close the last SSRF rebinding window in…

ThreatCrush 0.11.1

What's Changed fix(scan): exempt the metasyntactic credential pair in a DSN by @ralyodio in #107 fix(scan): take notice of a gosec G101 annotation already on the line by @ralyodio in #108 Add tcfeed: a ranked shortlist of repositories worth scanning by @ralyodio in #109 feat(tcfeed): add tcfeed pr , which installs the scan workflow by @ralyodio in #110 fix(tcfeed): make tcfeed pr actually fork,…

ThreatCrush 0.11.0

What's Changed feat(scan): LDAP/XPath/NoSQL/host-header rules — coverage 79.8% → 83.0% (v0.11.0) by @ralyodio in #104 Full Changelog : v0.10.0...v0.11.0

ThreatCrush 0.10.0

What's Changed feat(scan): misconfiguration, weak-crypto & injection rules — coverage 71.3% → 79.8% (v0.10.0) by @ralyodio in #103 Full Changelog : v0.9.0...v0.10.0

ThreatCrush 0.9.0

What's Changed feat(scan): weak-crypto rules for Python — coverage 65.9% → 71.3% (v0.9.0) by @ralyodio in #102 Full Changelog : v0.8.0...v0.9.0

ThreatCrush 0.8.0

What's Changed ci: build the self-scan from source instead of installing @latest by @ralyodio in #100 feat(scan): path exclusion via --exclude and .threatcrushignore (v0.8.0) by @ralyodio in #101 Full Changelog : v0.7.2...v0.8.0

ThreatCrush 0.7.2

What's Changed fix: repair npm install (workspace: protocol) and the SQL verb false positive (v0.7.2) by @ralyodio in #99 Full Changelog : v0.7.1...v0.7.2

ThreatCrush 0.7.1

What's Changed Fix scanning for env split-string shebangs by @rissrice2105-agent in #93 refactor(scan): extract the scan engine into @threatcrush/scan by @ralyodio in #94 feat(web): scan code with the shared package, and drop .js from its imports by @ralyodio in #95 fix(scan): stop letting neighbouring code decide a finding's severity (v0.7.1) by @ralyodio in #97 feat(modules): add Feodo Tracker…

ThreatCrush 0.7.0

What's Changed feat(scan): command injection, SSRF and traversal for Java; traversal and template escaping for Go (v0.7.0) by @ralyodio in #91 Full Changelog : v0.6.2...v0.7.0

ThreatCrush 0.6.2

What's Changed fix(sarif): publish the fingerprint under a namespaced key (v0.6.2) by @ralyodio in #90 Full Changelog : v0.6.1...v0.6.2