mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-05 07:27:18 +02:00
Field feedback: real, reproducible findings (missing HSTS, insecure cookie flags, internal IP leaked in a header) were being down-rated/dropped by the adversarial opinion-vote. The user's rule: never discard something real; another person must be able to reproduce the same finding. Validation: - has_http_receipt(): a finding whose proof is a captured HTTP response (status line / security headers / Set-Cookie / a header the class is proven by) or a file:line citation is REPRODUCIBLE by definition. - validate(): a finding unanimously rejected by the vote but carrying such a receipt is NO LONGER dropped — it is kept as needs-review (capped to what the receipt alone proves), because "the response lacks HSTS" is a fact, not a story. grounded_receipt() now also recognizes an in-prose HTTP receipt. - reproducibility: a kept finding at a URL with no explicit repro steps gets a minimal pasteable `curl -i` so anyone can reproduce the exact finding. Also: - /pocs (aliases /poc /evidence /artifacts): list a run's synthesized/written PoC + evidence files with their paths (was: "unknown command /pocs"). - version bumped to 4.2.2 across CLI/clap/web; stale v4.2.1/v4.1.0 labels fixed. 423 tests passing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
22 lines
499 B
TOML
22 lines
499 B
TOML
[workspace]
|
|
members = ["crates/harness", "app"]
|
|
resolver = "2"
|
|
|
|
[workspace.package]
|
|
version = "4.2.2"
|
|
edition = "2021"
|
|
license = "MIT"
|
|
repository = "https://github.com/JoasASantos/NeuroSploit"
|
|
|
|
[workspace.dependencies]
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
tokio = { version = "1", features = ["full"] }
|
|
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls"] }
|
|
anyhow = "1"
|
|
futures = "0.3"
|
|
|
|
[profile.release]
|
|
opt-level = 2
|
|
lto = "thin"
|