-
0.1.5
Stablereleased this
2026-09-22 00:43:29 -05:00 | 0 commits to main since this releasePackaging
- Require Poetry >=2.2,<3 for development; migrate metadata, dependencies and CLI entry points to standard
[project]tables, use the supported dev dependency group and Poetry Core >=2.2,<3 backend, and regenerate the lockfile with Poetry 2.5.1 without changing locked package versions. - Pin Forgejo CI to Poetry 2.5.1; validate the lockfile and synchronise dependencies with
poetry sync --with dev.
Security
- Enable Chromium process sandboxing by default. Add an explicit
--no-sandboxoverride for isolated, trusted environments; never automatically retry without sandboxing. Clarify that this is independent of--bypass-csp. - Validate and canonicalise HTTP(S)/WebSocket origins and validate generated CSP tokens to prevent source-map metadata injecting directives.
- Report source-map locations as metadata instead of automatically authorising them in
connect-src. - Replace the predictable cache write probe, reject unsafe/symlink cache paths, remove the shared temporary-directory fallback, and use an OS installation lock released after process death.
- Abort failed document interception instead of silently replaying an uninstrumented request. Enforce top-level crawl scope, follow same-origin GET redirect hops explicitly at their real URLs, and reject unsafe/non-GET redirect replay.
- Disable accepted downloads and block service workers for deterministic interception. Add scan/request/observation budgets and disclose incomplete coverage.
Fixed
-
Fix a Chromium error-page navigation race when following same-origin redirects: finish intercepted redirect hops with empty, locked-down documents before navigating to validated destinations; preserve scope checks, redirect limits and final-document policy injection.
-
Fix CI browser tests failing before launch when the runner cache is writable by others: use a private temporary browser directory by default in
tests.sh, validate before installation, preserve explicit safe cache overrides and clean temporary files even on test failure. -
Invoke the report-only violation listener correctly, attribute records to the candidate policy/document, preserve distinct findings and stop trusting page-authored console strings as violations.
-
Return exit 2 for incomplete/error scans, invalid arguments, unconfirmed injection and remaining enforcing policies; retain exit 1 for completed scans with violations.
-
Resolve links through browser
a.href, respecting nested paths, query/fragment links and<base>. Canonicalise equivalent origins/root URLs and record final navigation URLs. -
Separate third-party iframe subresources from parent policy permissions; include same-origin/inherited-policy frames and explicitly observe WebSockets where attribution is unambiguous.
-
Detect external script/stylesheet nonce attributes and emit script/style nonce requirements separately. Skip data-only script blocks and disclose inline collection truncation.
-
Honour explicit browser paths with
--no-install, preservePLAYWRIGHT_BROWSERS_PATH=0, use a consistent CI cache, and avoid reinstalling an existing browser after a sandbox/library launch failure. -
Keep installer output off JSON stdout, skip non-HTML hashing and report page errors/status explicitly.
Added and changed
- JSON schema v2 with complete serialised directives, permission observations, per-page status/injection confirmation, errors/completeness, source-map metadata and header byte size.
- Add
--evaluate-file,--header-only, repeatable--exclude,--scan-timeout,--max-requests,--max-observationsand--header-budget. - Add deterministic unit/control-flow regressions and loopback Chromium integration fixtures; make public-site smoke tests opt-in and remove the brittle live-site policy snapshot.
- Update README with output/exit-code migration notes, sandbox/CSP distinction and remaining coverage limits; add a realistic
SECURITY.mdthreat model.
Downloads
- Require Poetry >=2.2,<3 for development; migrate metadata, dependencies and CLI entry points to standard
-
0.1.4
Stablereleased this
2026-02-03 19:57:16 -06:00 | 9 commits to main since this release- Don't wait for networkidle, if it doesn't get that far but 'load' does
- Dependency updates
Downloads
-
0.1.3
Stablereleased this
2026-01-05 16:21:21 -06:00 | 12 commits to main since this release- Fix bug in --evaluate mode, which would inject the CSP into third party domains, which they would then throw violations for and trip the result
Downloads
-
0.1.2
Stablereleased this
2026-01-01 22:22:26 -06:00 | 14 commits to main since this release- Add
--bypass-cspoption to ignore an existing enforcing CSP to avoid it skewing results - Add
--evaluateoption to test a proposed CSP without needing to install it (best to use in conjunction with --bypass-csp`)
Downloads
- Add
-
0.1.1
Stablereleased this
2026-01-01 17:58:01 -06:00 | 18 commits to main since this release- Fix prog name
- Add --ignore-non-html option to skip pages that weren't HTML (which might trigger Chromium's 'sha256-4Su6mBWzEIFnH4pAGMOuaeBrstwJN4Z3pq/s1Kn4/KQ=' hash)
- Fix detection of Python for AppImage if it needs to install browsers via playwright
Downloads
-
0.1.0
Stablereleased this
2026-01-01 17:19:37 -06:00 | 24 commits to main since this releaseInitial release
Downloads