-
0.1.5
Stablereleased this
2026-09-22 00:43:29 -05:00 | 0 commits to main since this releasePackaging
- Require Poetry >=2.2,<3 for development; migrate metadata, dependencies and CLI entry points to standard
[project]tables, use the supported dev dependency group and Poetry Core >=2.2,<3 backend, and regenerate the lockfile with Poetry 2.5.1 without changing locked package versions. - Pin Forgejo CI to Poetry 2.5.1; validate the lockfile and synchronise dependencies with
poetry sync --with dev.
Security
- Enable Chromium process sandboxing by default. Add an explicit
--no-sandboxoverride for isolated, trusted environments; never automatically retry without sandboxing. Clarify that this is independent of--bypass-csp. - Validate and canonicalise HTTP(S)/WebSocket origins and validate generated CSP tokens to prevent source-map metadata injecting directives.
- Report source-map locations as metadata instead of automatically authorising them in
connect-src. - Replace the predictable cache write probe, reject unsafe/symlink cache paths, remove the shared temporary-directory fallback, and use an OS installation lock released after process death.
- Abort failed document interception instead of silently replaying an uninstrumented request. Enforce top-level crawl scope, follow same-origin GET redirect hops explicitly at their real URLs, and reject unsafe/non-GET redirect replay.
- Disable accepted downloads and block service workers for deterministic interception. Add scan/request/observation budgets and disclose incomplete coverage.
Fixed
-
Fix a Chromium error-page navigation race when following same-origin redirects: finish intercepted redirect hops with empty, locked-down documents before navigating to validated destinations; preserve scope checks, redirect limits and final-document policy injection.
-
Fix CI browser tests failing before launch when the runner cache is writable by others: use a private temporary browser directory by default in
tests.sh, validate before installation, preserve explicit safe cache overrides and clean temporary files even on test failure. -
Invoke the report-only violation listener correctly, attribute records to the candidate policy/document, preserve distinct findings and stop trusting page-authored console strings as violations.
-
Return exit 2 for incomplete/error scans, invalid arguments, unconfirmed injection and remaining enforcing policies; retain exit 1 for completed scans with violations.
-
Resolve links through browser
a.href, respecting nested paths, query/fragment links and<base>. Canonicalise equivalent origins/root URLs and record final navigation URLs. -
Separate third-party iframe subresources from parent policy permissions; include same-origin/inherited-policy frames and explicitly observe WebSockets where attribution is unambiguous.
-
Detect external script/stylesheet nonce attributes and emit script/style nonce requirements separately. Skip data-only script blocks and disclose inline collection truncation.
-
Honour explicit browser paths with
--no-install, preservePLAYWRIGHT_BROWSERS_PATH=0, use a consistent CI cache, and avoid reinstalling an existing browser after a sandbox/library launch failure. -
Keep installer output off JSON stdout, skip non-HTML hashing and report page errors/status explicitly.
Added and changed
- JSON schema v2 with complete serialised directives, permission observations, per-page status/injection confirmation, errors/completeness, source-map metadata and header byte size.
- Add
--evaluate-file,--header-only, repeatable--exclude,--scan-timeout,--max-requests,--max-observationsand--header-budget. - Add deterministic unit/control-flow regressions and loopback Chromium integration fixtures; make public-site smoke tests opt-in and remove the brittle live-site policy snapshot.
- Update README with output/exit-code migration notes, sandbox/CSP distinction and remaining coverage limits; add a realistic
SECURITY.mdthreat model.
Downloads
- Require Poetry >=2.2,<3 for development; migrate metadata, dependencies and CLI entry points to standard