Skip to content

v1.1.0 — 2026-standard workspace (AI/LLM, new vuln classes, recon depth, hardening) - #2

Merged
DevCop95 merged 1 commit into
mainfrom
feature/v1.1.0-standard-workspace
Oct 6, 2026
Merged

DevCop95 merged 1 commit into
mainfrom
feature/v1.1.0-standard-workspace

Conversation

@DevCop95

@DevCop95 DevCop95 commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Implements the roadmap in #1.

Highlights

  • AI/LLM security reference (docs/ai-llm-security.md, OWASP LLM Top 10) — the biggest 2026 gap.
  • 14 vulnerability-class deep-dives added to QUICK-REFERENCE.md (ATO/password-reset, access-control/IDOR, mass assignment, race conditions, JWT/OAuth, GraphQL, prototype pollution, cache poisoning, CORS, subdomain takeover, CSV injection, path traversal + encoding bypass, NoSQL/Elasticsearch Painless injection, cloud secrets in JS bundles).
  • scripts/duplicate_check.py — pre-submission self-duplicate check.
  • auto-scanner/kev-correlate.sh — CISA KEV correlation + webhook.
  • Recon depth: crt.sh + certspotter CT sources, enriched httpx, JS/secret/source-map analysis, API-spec discovery, paramspider/arjun, --passive-only.
  • CVE watchlist: NVD Source column + Ivanti/Citrix/Fortinet/Jenkins/GitLab.
  • report-template: per-metric CVSS justification, attack scenario, privileges + affected-scope, PoC video slot.

Hardening / fixes

  • Portable resolve_ip() (no hard dig dependency); unblocks the CDN scope guard.
  • scope_filter_file: no longer errors on missing input; logs discards + candidates-pending-scope.txt.
  • crt.sh JSON-validate + retry; recon now probes the target host itself.
  • HTTP-probe stage detects the wrong (Python) httpx and skips cleanly.
  • pentest-express reflected-XSS grep -c double-zero bug fixed.

Validation

  • shellcheck -x -S warning clean on all scripts (Windows + WSL/Linux).
  • Repo tests (test-shell-scope.sh, check-sensitive-files.sh) pass; both .py compile.
  • Phase-by-phase QA run in real Linux (WSL); CDN guard, certspotter fallback and passive-only verified live.

Closes #1

…, hardening (v1.1.0)

Implements the roadmap in issue #1.

Added:
- docs/ai-llm-security.md (OWASP LLM Top 10 reference)
- QUICK-REFERENCE deep-dives: ATO/password-reset, access-control/IDOR, mass
  assignment, race conditions, JWT/OAuth, GraphQL, prototype pollution, cache
  poisoning, CORS, subdomain takeover, CSV injection, path traversal + encoding
  bypass, NoSQL/Elasticsearch Painless injection, cloud secrets in JS bundles
- scripts/duplicate_check.py (pre-submission self-duplicate check)
- auto-scanner/kev-correlate.sh (CISA KEV correlation + webhook)
- recon depth: crt.sh + certspotter CT sources, enriched httpx, JS/secret/
  source-map analysis, API-spec discovery, paramspider/arjun, --passive-only
- CVE watchlist: NVD Source column + Ivanti/Citrix/Fortinet/Jenkins/GitLab

Changed:
- report-template.md: per-metric CVSS justification, attack scenario, privileges
  and affected-scope fields, PoC video slot
- scope_filter_file logs discards + candidates-pending-scope.txt

Fixed:
- portable resolve_ip() (no hard dig dependency); unblocks the CDN guard
- scope_filter_file no longer errors on missing input
- crt.sh JSON validation + retry; recon probes the target host itself
- httpx stage detects the wrong (Python) httpx and skips cleanly
- pentest-express reflected-XSS grep -c double-zero bug

Closes #1
@DevCop95
DevCop95 merged commit 20e6d96 into main Oct 6, 2026
2 checks passed
@DevCop95
DevCop95 deleted the feature/v1.1.0-standard-workspace branch October 6, 2026 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Roadmap to a 2026-standard workspace: coverage gaps, hardening, and traceability (→ v1.1.0)

1 participant