Tags: mkarvan/AgentShield
Tags
release: v0.15.0 AgentShield Protect: `agentshield protect` activates enforcement reversibly, `protect verify` proves each layer blocks with sentinel probes and writes a protection receipt, `protect status` re-reads it. Plus the two macOS exec interceptor fixes those probes found (it failed open, and built arm64-only) and the install hints that named the unrelated `agentshield` package on PyPI. Version pins bumped (pyproject, __init__, README badge, AGENT_SETUP expected version, pre-commit revs, GitHub Action default). README gains a `protect` quick-start step and CLI sections; AGENT_SETUP gains the fast path. ROADMAP's release history, which stopped at 0.12.0, now covers 0.13–0.15 and drops the backlog entries that have since shipped.
AgentShield v0.12.0 Added: T6.3 provenance regression tracking, posture audit summary, GitHub Action SARIF upload. Fixed: waiver cache correctness, Action fail-on:NONE, npm scoped provenance encoding, PyPI all-artifact provenance, stable SARIF fingerprints, multi-process-safe audit chaining. Tests: container e2e sections for the new features. See CHANGELOG.md.
AgentShield v0.11.0 - Hash-chained audit log: audit tail/verify/prune/forward, retention, HTTP NDJSON + RFC 5424 syslog forwarding with cursor-tracked delivery - Provenance/attestation checks (T6.x) + pip hash emission - SARIF 2.1.0 output for scan-file / diff-scan / scan-docker - Waivers: time-boxed finding exceptions with mandatory expiry - Webhook/Slack notifications for BLOCK and drift events See CHANGELOG.md.
feat(v0.9.0): CVE scanning for system packages - Add syspkg_cve.py: SysPkgCVEScanner queries OSV (primary) + distro trackers (Ubuntu CVE, Red Hat CVE, Homebrew audit) for system packages - Cache CVE results in SQLite (syspkg_cve_cache table) with 6h TTL - Wire CVE lookup into guard-scan-cmd: findings evaluated against configurable severity policy (critical=BLOCK by default) - Add SysPkgConfig to config.py: [syspkg] TOML section with enabled, cve_scan, and severity_policy fields; rule-level overrides supported - Update shell wrappers (bash/zsh/fish): add || return 1 so blocking actually prevents the install command from running - Manager-to-ecosystem mapping: apt→Debian/Ubuntu, yum/dnf→AlmaLinux/ Rocky Linux, apk→Alpine, zypper→SUSE, snap→Ubuntu - Offline mode and cve_scan=false both skip CVE scanning gracefully - Unit tests (test_syspkg_cve.py) and e2e tests (test_syspkg_cve_e2e.py) - Version bump to 0.9.0, ROADMAP/README/AGENT_SETUP updated
v0.8.0: System package manager detection (warning-only) Add syspkg_detector.py analyzer that detects system package manager commands (apt-get, apt, yum, dnf, brew, apk, pacman, zypper, pkg, emerge, snap, flatpak) in shell strings. Emits SP1.1 warnings at INFO severity — never blocks. - Wire into guard-scan-cmd CLI and shell guard wrappers (bash/zsh/fish) - Handle sudo prefixes, compound commands, flag skipping - Extract package names where parseable - Use -- separator to prevent typer flag conflicts (e.g. pacman -S) - Unit tests (35) and e2e tests (11) - Bump version to 0.8.0 - Update ROADMAP.md, README.md, AGENT_SETUP.md
PreviousNext