This release focuses on end-user usability and improved XCSSET detection. We removed nearly all of the output spam related to dependency fetching and analysis, and we added better support for detecting build-time infections. We hope you enjoy it!
- Scan v2.10.0
- States each distinct dependency outcome once, so a dependency named by forty manifests no longer fails forty identical times.
- Renders each package's top trait findings inline for nested hostile archives, so you can see why without re-running cleave.
?full=1returns the complete report from the analyze endpoints, and?refresh=1replaces a standing local verdict.
- cleave v2.10.0
- Trait rules follow nested encoding chains, so base64 wrapped in base64 no longer hides what's inside it.
- Xcode
.pbxprojand CMake files are parsed and usable as rule targets, which is where XCSSET-style build-time infections live.
- filefacts v1.6.0
- Identifies SquashFS images, Snap packages, Flatpak bundles, OpenPGP signatures and YAML, so they get analyzed instead of skipped.
- npm lockfile aliases (
alias@npm:real@^1) resolve to the real package instead of looking up the alias name, so the right code gets analyzed.
- stng v1.11.0
- Decodes hex runs embedded inside larger strings — the
echo <hex> | xxd -r -p | shdropper shape.
- Decodes hex runs embedded inside larger strings — the
- fletch v1.2.1
- Verifies legacy SHA-1 and Go
h1:pins against fetched bytes instead of reporting them as unverifiable.
- Verifies legacy SHA-1 and Go
Release notes: scan v2.10.0 · cleave v2.10.0 · stng v1.11.0 · filefacts v1.6.0 · fletch v1.2.1
brew upgrade atomdrift-project/tap/cleave atomdrift-project/tap/scan atomdrift-project/tap/stng