Tags: csnp/cryptoscan
Tags
cryptoscan v1.4.0
Report cryptographic usage that the noise filter was silently dropping.
Seven idiomatic forms that reported zero findings in 1.3.0 now report one each:
a.md5(b), hashlib.md5(data).hexdigest(), cipher = md5(b"a"), des.NewCipher(key),
crypto.createHash('md5') behind const, CryptoJS.RC4.encrypt, and
Cipher.getInstance("DES").
Withheld findings are counted and recoverable with --include-narrative. Every
output surface reports the same version. Finding order is deterministic.
Known limitations are recorded in the changelog rather than left for users to
discover.
Release v1.3.0 - CI/CD Flexibility Features New Features: - CI/CD integration with --ignore, --ignore-category, --fail-on, --baseline flags - Configuration file support (.cryptoscan.yaml) with auto-detection - Pattern-specific inline suppression (cryptoscan:ignore RSA-001) - Baseline comparison to only report new findings - Configurable exit codes for CI pipelines - Wildcard pattern matching (e.g., RSA-*, CERT-*) Improvements: - MigrationScore correctly recalculated after baseline filtering - Enhanced documentation with CI/CD workflow examples - New pkg/config package for configuration management This release enables enterprise-grade CI/CD integration with flexible ignore mechanisms, baseline tracking, and exit code control.
Release v1.2.1 - Improved UX with actionable guidance UX Improvements: - Certificate findings now show specific Impact statements - Each finding includes clear "Next Steps" in Effort field - Actionable remediation guidance (e.g., "URGENT: Remove InsecureSkipVerify") - Specific recommendations for each certificate pattern type This release focuses on user experience, ensuring users know exactly what to do after running a scan.
Release v1.2.0 - Certificate Detection & False Positive Reduction New Features: - 20 new certificate patterns (X.509, CSR, PKCS#12, chains, mTLS, JWK) - Certificate validation bypass detection (CRITICAL severity) - Weak signature detection (SHA-1/MD5 certificates) - Enhanced false positive filtering Improvements: - Smarter context analysis (URLs, test data, config keys, UI labels) - Fixed debug output that corrupted JSON format - Fixed Go version consistency (go.mod matches docs) - Applied gofmt to all files - Updated README and PATTERNS.md documentation Total patterns: 90 All tests pass (including 75 new certificate tests)
v1.0.3 - Complete Documentation Update README Improvements: - Added Prerequisites section (Go 1.21+, Git) - Expanded CBOM documentation with compliance context (OMB M-23-02) - Added detailed explanations for all 10 comparison capabilities - Full CLI reference with all flags - CI/CD integration examples (GitHub Actions, GitLab CI, pre-commit) - Architecture overview and CSNP mission context - References to NIST FIPS 203/204/205 PQC standards No code changes from v1.0.1
v1.0.0 - Initial stable release CryptoScan: Cryptographic discovery tool for the post-quantum era Features: - Scan local directories and remote Git repositories - Detect 50+ cryptographic patterns (RSA, ECDSA, AES, MD5, SHA-1, etc.) - Quantum risk classification (Vulnerable, Partial, Safe) - Multiple output formats: text, JSON, CSV, SARIF, CBOM - Source code context for verification - Inline ignore comments for false positive suppression - Real-time streaming output during scans Part of the QRAMM Toolkit by CSNP (https://csnp.org)