feat(report): SARIF 2.1.0 export + stronger cross-object reference mining (v4.2.1)

- new sarif module: projects findings to SARIF 2.1.0 (rules deduped by CWE,
  security-severity from graded CVSS, endpoint locations, OWASP/MITRE tags)
- report::write_all/rebuild now emit report.sarif alongside md/json/html/pdf
- `neurosploit sarif <run> [--out]` re-emits on demand; exposed over MCP
- assurance: report.sarif added to the known-artifacts manifest
- chaining doctrine: harvest every object identifier (ids/UUIDs/tokens/emails)
  into a reference pool and substitute across identities/endpoints — the core
  of reliable BOLA/IDOR/mass-assignment discovery
- version 4.2.1; 389 tests passing

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-09-24 12:14:49 -03:00
1 parent e49595b8bf
commit 5ab6451c15
10 files changed
+304 -8

No files matched your search

+2 -2
View File
@@ -929,7 +929,7 @@ dependencies = [
[[package]]
name = "neurosploit"
version = "4.2.0"
version = "4.2.1"
dependencies = [
"anyhow",
"clap",
@@ -946,7 +946,7 @@ dependencies = [
[[package]]
name = "neurosploit-harness"
version = "4.2.0"
version = "4.2.1"
dependencies = [
"anyhow",
"base64",