-
v7.8.3 Stable
released this | 45 commits to main since this release
Security and correctness patch. 47 verified fixes from the v7.8.1/v7.8.2
completion-review MEDIUM tier (52 findings triaged: 48 confirmed defects, with
3 feature-requests and 1 non-defect scoped out; capability work — the #11
persistence detector and #27 AST-taint f-string recall — deferred to v8). No
new features, and no CRITICAL/HIGH: every review-claimed HIGH downgraded to
MEDIUM on re-verification. 2013 tests, 0 fail.Fixed
- Supply-chain gate bypasses. The offline npm blocklist was skipped for
bare/range/tag installs (resolved version never re-checked); non-hoisted
nested lockfile keys derived the wrong package name; the yarn.lock matcher
both false-BLOCKed a legitimate package (unassociated substrings + unanchored
pkg@) and missed Yarn Berry'sversion:format;pip audit(no such
subcommand) made Python CVE detection a permanent silent no-op and, once
corrected topip-audit, audited the target instead of the scanner host. - Hook coverage. pathguard registered
Writeonly, so an Edit to an
existing protected file (settings,.env,.ssh, the hooks themselves)
bypassed it — nowEdit|Write. The trifecta window counted marker lines and
could scroll a real leg out. The remote-pipe-to-shell block missed
xargs/sudo/tee/env interposition. pre-edit-secrets missed bare provider keys
(Anthropic, OpenAI, fine-grained GitHub PAT, Google, JWT). - Scanner robustness / DoS. Quadratic ReDoS in the HTML-obfuscation
injection patterns (~28s to 4ms); unbounded readline on MCP-server stdout
(memory exhaustion / uncaught RangeError); an uncapped same-host redirect loop
in the VSIX fetcher; a scalarpolicy.jsonsection override threw an uncaught
TypeError; non-atomic writes to the MCP-description and skill-registry caches. - False positives / negatives. toxic-flow fabricated CRITICAL trifectas from
substring keyword matches (urlincurl); TRG-broad/-baiting fired on scoped
phrasing and substrings; a legitimate leading UTF-8 BOM was flagged HIGH; the
workflow actor-auth-bypass detector missed the bareif:form (Dependabot
spoof); the git reflog force-push detector tripped on anyresetin a commit
subject; the diff engine mislabeled unchanged findings on duplicate
fingerprints; memory-poisoning double-reported a hex token as base64 + hex. - Parser divergence / evasion. YAML block-scalar bodies were re-parsed as
top-level keys (name/allowed_tools override) and indented/chomped block-scalar
headers (|2,>-) were unrecognized; the bash normalizer decoded only
\xHH, not ANSI-C octal/\u/\U; embedded base64 (opt-in) now reaches the
SIG decode pipeline;.env.local/.env.examplewere silently skipped by
discovery;collapseLetterSpacing(multi-space/tab) andredact(_, _, 0)
(full-URL leak) were fixed; the SIG scanner now honours the documented
custom_rules_pathpolicy option. - Docs / version consistency. Orchestrated scanner count corrected to 14,
posture categories to 16, red-team scenarios to 72, tests badge to 2013; SARIF
driver.versionnow reflects the real plugin version; the pathguard matcher
and persistence-detection documentation were corrected; danglingROADMAP.md
references removed. - MCP output-injection scan was inert in live sessions
(hooks/scripts/post-mcp-verify.mjs). The hook read the PostToolUse
tool_outputfield, but live Claude Code delivers the tool result as
tool_response, so the indirect-injection scan on MCP output never ran
outside the test harness; it now readstool_responseand falls back to
tool_output. Found via a live-session check during the sweep, not part of
the MEDIUM-tier triage.
Deferred (to v8)
- Persistence-command detection (cron/launchctl/rc-files/plist) and the
AST-taint f-string/concat/alias recall gap — capability enhancements, not
defects in shipped code. - Deterministic detectors for AST09 (bulk knowledge load), AST10/LLM10
(unbounded consumption), and MCP05 (path-traversal read sink) — each already
covered by the LLM-agent layer.
Downloads
-
Source code (ZIP)
1 download
-
Source code (TAR.GZ)
0 downloads
- Supply-chain gate bypasses. The offline npm blocklist was skipped for