Scan v2.10.0: less output spam, better build-time detection

This release focuses on end-user usability and improved XCSSET detection. We removed nearly all of the output spam related to dependency fetching and analysis, and we added better support for detecting build-time infections. We hope you enjoy it!

  • Scan v2.10.0
    • States each distinct dependency outcome once, so a dependency named by forty manifests no longer fails forty identical times.
    • Renders each package's top trait findings inline for nested hostile archives, so you can see why without re-running cleave.
    • ?full=1 returns the complete report from the analyze endpoints, and ?refresh=1 replaces a standing local verdict.
  • cleave v2.10.0
    • Trait rules follow nested encoding chains, so base64 wrapped in base64 no longer hides what's inside it.
    • Xcode .pbxproj and CMake files are parsed and usable as rule targets, which is where XCSSET-style build-time infections live.
  • filefacts v1.6.0
    • Identifies SquashFS images, Snap packages, Flatpak bundles, OpenPGP signatures and YAML, so they get analyzed instead of skipped.
    • npm lockfile aliases (alias@npm:real@^1) resolve to the real package instead of looking up the alias name, so the right code gets analyzed.
  • stng v1.11.0
    • Decodes hex runs embedded inside larger strings — the echo <hex> | xxd -r -p | sh dropper shape.
  • fletch v1.2.1
    • Verifies legacy SHA-1 and Go h1: pins against fetched bytes instead of reporting them as unverifiable.

Release notes: scan v2.10.0 · cleave v2.10.0 · stng v1.11.0 · filefacts v1.6.0 · fletch v1.2.1

brew upgrade atomdrift-project/tap/cleave atomdrift-project/tap/scan atomdrift-project/tap/stng

← All news