release: v4.1.0 — assurance layer, TypeSafe, hardening + benchmark

Version bumped to 4.1.0 across the workspace, binaries, web console and Typst
template.

README: new "New in v4.1.0" summary; trimmed the verbose highlight bullets and
the TypeSafe section; removed the anti-plagiarism/provenance section (provenance
stays in the code, just not front-and-centre in the README); TypeSafe promoted
to its own top-level section; agent count 446.

TUTORIAL: new section 17 "Assurance & authorization" covering the target gate,
--scope-file, evidence-graded CVSS, audit anchoring + assurance bundle, sandbox,
intercept proxy, PoC re-validation, compliance mapping, TypeSafe, and the
internal/AD graph + budget governor.

benchmarks/typesafe-2026-09-20/: the with/without TypeSafe measurement —
report.html, scorer, both runs' findings/assurance/meta/logs, and a README.
No secrets committed (env-only during the runs, verified clean).

381 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUP
2026-09-20 12:25:23 -03:00
co-authored by Claude Opus 5
parent d2ec0a112d
commit 088d133c80
28 changed files with 4292 additions and 126 deletions
+1 -1
View File
@@ -22,7 +22,7 @@ run this only on a trusted machine/network, same trust model as the CLI itself.
Server/version info.
```json
{ "version": "4.0.0", "binary": "/opt/neurosploit-rs/neurosploit-rs/target/release/neurosploit", "root": "/opt/neurosploit-rs" }
{ "version": "4.1.0", "binary": "/opt/neurosploit-rs/neurosploit-rs/target/release/neurosploit", "root": "/opt/neurosploit-rs" }
```
---
+1 -1
View File
@@ -1,4 +1,4 @@
# NeuroSploit v4.0.0 — web console
# NeuroSploit v4.1.0 — web console
A browser UI for the `neurosploit` CLI harness: a 5-step engagement wizard (Asset → Scope & Auth
→ Leads → Model & Run → Review), a live structured findings view with a generative attack-path
+2 -2
View File
@@ -1,8 +1,8 @@
{
"name": "neurosploit-web",
"version": "4.0.0",
"version": "4.1.0",
"private": true,
"description": "NeuroSploit v4.0.0 web console — lead board + REPL, backed by the neurosploit CLI harness.",
"description": "NeuroSploit v4.1.0 web console — lead board + REPL, backed by the neurosploit CLI harness.",
"main": "server.js",
"scripts": {
"start": "node server.js"
+1 -1
View File
@@ -1,5 +1,5 @@
'use strict';
/* NeuroSploit v4.0.0 — web console frontend. Vanilla JS, no build step. */
/* NeuroSploit v4.1.0 — web console frontend. Vanilla JS, no build step. */
const $ = (sel, root = document) => root.querySelector(sel);
const $$ = (sel, root = document) => Array.from(root.querySelectorAll(sel));
+2 -2
View File
@@ -3,7 +3,7 @@
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<title>NeuroSploit v4.0.0 — Console</title>
<title>NeuroSploit v4.1.0 — Console</title>
<link rel="icon" href="data:image/svg+xml,<svg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 100 100%22><text y=%22.9em%22 font-size=%2290%22>🧠</text></svg>">
<link rel="stylesheet" href="/vendor/xterm.css" />
<link rel="stylesheet" href="/style.css" />
@@ -33,7 +33,7 @@
<div class="sb-groups" id="sbGroups"><!-- populated by app.js --></div>
<div class="sb-bottom">
<span class="sb-version" id="sbVersion">v4.0.0</span>
<span class="sb-version" id="sbVersion">v4.1.0</span>
<div class="sb-bottom-actions">
<button class="icon-btn" id="btnOpenAuth" title="Auth &amp; API keys">🔑</button>
<button class="icon-btn" id="btnOpenRepl" title="Open terminal (Ctrl+`)">❭_</button>
+1 -1
View File
@@ -1,4 +1,4 @@
/* NeuroSploit v4.0.0 — web console.
/* NeuroSploit v4.1.0 — web console.
Visual direction: dense security-operations console (not a marketing SaaS
page). Borders over shadows, typography over color, two radii, one accent.
*/
+2 -2
View File
@@ -1,7 +1,7 @@
#!/usr/bin/env node
'use strict';
/**
* NeuroSploit v4.0.0 — web console backend.
* NeuroSploit v4.1.0 — web console backend.
*
* Zero-dependency Node HTTP server that:
* - serves the static SPA in ./public
@@ -1223,7 +1223,7 @@ const server = http.createServer(async (req, res) => {
});
server.listen(PORT, () => {
console.log(`NeuroSploit v4.0.0 web console → http://localhost:${PORT}`);
console.log(`NeuroSploit v4.1.0 web console → http://localhost:${PORT}`);
console.log(` binary : ${BIN || '(not found — build neurosploit-rs first)'}`);
console.log(` agents : ${AGENTS_DIR}`);
console.log(` runs : ${RUNS_DIR}`);