Skip to content

Tags: csnp/cryptoscan

Tags

v1.4.0

Toggle v1.4.0's commit message
cryptoscan v1.4.0

Report cryptographic usage that the noise filter was silently dropping.

Seven idiomatic forms that reported zero findings in 1.3.0 now report one each:
a.md5(b), hashlib.md5(data).hexdigest(), cipher = md5(b"a"), des.NewCipher(key),
crypto.createHash('md5') behind const, CryptoJS.RC4.encrypt, and
Cipher.getInstance("DES").

Withheld findings are counted and recoverable with --include-narrative. Every
output surface reports the same version. Finding order is deterministic.

Known limitations are recorded in the changelog rather than left for users to
discover.

v1.3.0

Toggle v1.3.0's commit message
Release v1.3.0 - CI/CD Flexibility Features

New Features:
- CI/CD integration with --ignore, --ignore-category, --fail-on, --baseline flags
- Configuration file support (.cryptoscan.yaml) with auto-detection
- Pattern-specific inline suppression (cryptoscan:ignore RSA-001)
- Baseline comparison to only report new findings
- Configurable exit codes for CI pipelines
- Wildcard pattern matching (e.g., RSA-*, CERT-*)

Improvements:
- MigrationScore correctly recalculated after baseline filtering
- Enhanced documentation with CI/CD workflow examples
- New pkg/config package for configuration management

This release enables enterprise-grade CI/CD integration with flexible
ignore mechanisms, baseline tracking, and exit code control.

v1.2.1

Toggle v1.2.1's commit message
Release v1.2.1 - Improved UX with actionable guidance

UX Improvements:
- Certificate findings now show specific Impact statements
- Each finding includes clear "Next Steps" in Effort field
- Actionable remediation guidance (e.g., "URGENT: Remove InsecureSkipVerify")
- Specific recommendations for each certificate pattern type

This release focuses on user experience, ensuring users know exactly
what to do after running a scan.

v1.2.0

Toggle v1.2.0's commit message
Release v1.2.0 - Certificate Detection & False Positive Reduction

New Features:
- 20 new certificate patterns (X.509, CSR, PKCS#12, chains, mTLS, JWK)
- Certificate validation bypass detection (CRITICAL severity)
- Weak signature detection (SHA-1/MD5 certificates)
- Enhanced false positive filtering

Improvements:
- Smarter context analysis (URLs, test data, config keys, UI labels)
- Fixed debug output that corrupted JSON format
- Fixed Go version consistency (go.mod matches docs)
- Applied gofmt to all files
- Updated README and PATTERNS.md documentation

Total patterns: 90
All tests pass (including 75 new certificate tests)

v1.1.1

Toggle v1.1.1's commit message
Release v1.1.1 - QA fixes and repo rename

v1.1.0

Toggle v1.1.0's commit message
Release v1.1.0 - Automatic version detection and visibility improvements

v1.0.3

Toggle v1.0.3's commit message
v1.0.3 - Complete Documentation Update

README Improvements:
- Added Prerequisites section (Go 1.21+, Git)
- Expanded CBOM documentation with compliance context (OMB M-23-02)
- Added detailed explanations for all 10 comparison capabilities
- Full CLI reference with all flags
- CI/CD integration examples (GitHub Actions, GitLab CI, pre-commit)
- Architecture overview and CSNP mission context
- References to NIST FIPS 203/204/205 PQC standards

No code changes from v1.0.1

v1.0.0

Toggle v1.0.0's commit message
v1.0.0 - Initial stable release

CryptoScan: Cryptographic discovery tool for the post-quantum era

Features:
- Scan local directories and remote Git repositories
- Detect 50+ cryptographic patterns (RSA, ECDSA, AES, MD5, SHA-1, etc.)
- Quantum risk classification (Vulnerable, Partial, Safe)
- Multiple output formats: text, JSON, CSV, SARIF, CBOM
- Source code context for verification
- Inline ignore comments for false positive suppression
- Real-time streaming output during scans

Part of the QRAMM Toolkit by CSNP (https://csnp.org)