Commit Graph
324 Commits
Author SHA1 Message Date
ajmallesh 954ad242dd docs: restore the Acknowledgements section in the README 2026-09-02 13:26:09 -07:00
ezl-keygraph 4fbad2fde9 feat!: trigger the Shannon 3.0 major release 2026-09-02 14:31:09 +05:30
ezl-keygraph f649aa249a fix(readme): restore theme-aware banner, badge, and buttons 2026-09-02 14:15:09 +05:30
ajmallesh 5e9bcb7aff docs: link the benchmark announcement discussion from the README 2026-09-02 01:43:09 -07:00
ajmallesh d544bb9bd6 docs: add the Shannon vs XBOW/Aikido Photoview benchmark writeup
- Add docs/shannon-xbow-aikido-benchmark.md with methodology, per-model
  cost/coverage tables, and links to each model's report and SARIF
- Link the writeup from the README "Shannon in Action" section
2026-09-02 01:40:37 -07:00
ajmallesh 343ce7b2c7 docs: add the Photoview benchmark across three models
- Add a "Shannon in Action" table for Photoview 2.4.0 runs on
  DeepSeek v4 Flash, Grok 4.6, and Claude Opus 5, each linking its
  PDF report and SARIF output
- Store the per-model reports under benchmark/
- Link the (forthcoming) benchmark writeup from the section intro
2026-09-02 01:27:07 -07:00
ajmallesh 81aa81c590 docs: document CI/CD integrations and the reconciled analysis pipeline
- add a CI/CD Integrations section covering the official GitHub Action and
  GitLab component, pipeline artifacts, and exploit-only severity gates
- redraw the architecture section as a Mermaid flow: agentic code analysis
  and recon feed finding reconciliation, then exploitation and reporting
- describe open-source code analysis as a multi-stage agentic workflow and
  reserve parsed-code CPGs and exhaustive verification for Enterprise
- sharpen the privacy wording: results stay local, but model requests carry
  source context to whichever endpoint you configure
- drop the "not recommended" framing on local models and add a section on
  why Shannon complements rather than replaces human pentesters
- regenerate llms-full.txt from the updated README and docs
2026-09-02 00:17:21 -07:00
ajmallesh 3bbd030fde docs: add the Shannon naming section and swap in the 3.0 demo GIF
- explain the Claude Shannon information-theory origin under "What is Shannon?"
- point "Shannon in Action" at the 3.0 recording in assets/Shannon3GIF.gif

Both taken from the README half of #438.
2026-09-01 21:43:36 -07:00
ajmallesh 4dee532437 docs: refresh README and platform overview for Shannon 3.0
- lead with the 3.0 launch note and rewrite key capabilities around security
  code analysis, the rebuilt terminal experience, native CI/CD, and PDF/SARIF
- recast the editions table as Shannon Open Source against the Keygraph
  Enterprise Platform, stating open source is not a trial edition
- rewrite the platform overview around exhaustive agentic SAST, canonical
  findings, automated remediation, targeted verification, and governance
- add five product screenshots under assets/keygraph-platform/, referenced
  relative to docs/
2026-09-01 21:38:00 -07:00
ezl-keygraph 492a38bb9a feat(cli): show a 'start your first scan' box in help on a TTY 2026-09-02 03:07:24 +05:30
ezl-keygraph 55a5881fe8 chore(release): bump beta base version to 3.0.0 2026-09-02 00:34:24 +05:30
ezl-keygraph d7b9e6813c fix(cli): don't blame anthropic when no credentials are configured at all 2026-09-01 23:45:29 +05:30
ezl-keygraph 840fabf030 feat(cli): prompt for setup on a bare npx invocation with no credentials 2026-09-01 23:37:24 +05:30
ajmallesh 7b67302a39 fix(cli): make scan shutdown verifiable
- preselect and persist workflow identity before worker launch
- cancel first, then verify bounded Temporal termination
- reconcile Docker workers with Temporal open workflows
- fail closed on stale images and unavailable lifecycle state
- mark cancellation only after confirmed shutdown
2026-08-31 16:16:14 -07:00
ezl-keygraph 1b440c853c fix(cli): reject a shell credential that shadows a gateway config.toml key 2026-09-01 03:06:18 +05:30
ezl-keygraph d8a10963a8 fix(prompts): scope exploit agents to in-band proof, mark OOB-only findings blocked 2026-09-01 01:45:46 +05:30
ezl-keygraph 4e145a0f3f fix(pi): give each task sub-session its own resource loader to prevent stale extension ctx 2026-09-01 01:45:46 +05:30
ajmallesh e9cf782081 fix: attribute a reconciliation failure to exploitation only
- Stop marking a class's vulnerability-analysis agent failed when that agent
  succeeded and only reconciliation failed; the status tree now renders the
  analysis row completed and the exploitation row failed
- Consume the worker's failedReconciliations signal in the CLI, which the
  mirrored PipelineState already declared but never read
- Correct the class_reconciliation_failed message, which claimed the class's
  analysis results were still in the report when the class is excluded from it
2026-08-30 18:51:23 -07:00
ajmallesh ddfd026f93 fix(worker): correct PDF finding reporting
- Render OWASP category, authentication state, and remediation
- Omit the redundant per-finding exploited status
- Preserve canonical category and field ordering across report modes
- Continue Proof of Impact numbering across embedded code blocks
- Wrap long PDF code lines without changing canonical report content
2026-08-30 14:08:32 -07:00
ajmallesh 602bc27bbc fix(cli): keep shannon logs tailing through a Temporal blip
- End the interactive tail on the log's own terminal marker or Ctrl-C, so a
  transient Temporal outage no longer aborts the command with exit 1.
- Rebuild the memoized Temporal client after a failed poll: a wedged gRPC
  channel was cached forever, so "retrying…" could never reconnect.
- Keep start --follow (CI) bounded — a genuinely dead Temporal still fails
  the run instead of hanging.
2026-08-30 10:48:45 -07:00
ajmallesh 0fe0c67ca5 feat(logging): record the provider reason for a failed agent turn
A failed provider turn collapsed to AGENT_EXECUTION_FAILED/unknown with the
underlying reason discarded, so a model-side rejection or safeguard was
indistinguishable from a transport fault in the error log.

- add safeProviderTurnDetails: write bounded, non-sensitive fields (provider,
  model, responseId, stop reason, tool-in-flight, category, retryable) to error.log
- gate a sanitized errorMessage snippet behind SHANNON_DEBUG_PROVIDER_ERRORS, off by default
- forward SHANNON_DEBUG_PROVIDER_ERRORS from the CLI into the worker container
2026-08-28 12:18:51 -07:00
ajmallesh 8df9eb3db4 merge: integrate xAI subscription auth from main
Both conflicts were adjacency rather than intent. Main rewrote only the Pi
Credential Reuse bullet while Capella rewrote the Audit System bullet beside it,
and the two branches added grok-mermaid and handlebars at the same alphabetical
slot in the lockfile. The pi bump to 0.84.2 also widened StopReason with two
states the Capella structured-generation port could not compile against.

- keep main's Pi bullet and Capella's Audit bullet, whose prose matches the code
- keep both lockfile entries; pnpm install --lockfile-only reproduces the result
- classify the new pending and deferred stop reasons as a rejected request
2026-08-28 09:23:43 -07:00
ezl-keygraph 6108de3cfc feat: bump pi harness to 0.84.2 to enable xAI subscription auth (#435) v2.7.0 2026-08-28 21:20:13 +05:30
ezl-keygraph 7e0464bf79 feat: support pentests with xAI (Grok) subscription auth (#434) 2026-08-28 21:11:24 +05:30
ajmallesh 8bab4ccb1b feat(sast): tolerate hygiene-only Capella reductions instead of going partial
A reduction only makes a run partial when it loses real coverage or a whole
finding. Malformed model output, salvaged turn-limit work, and rejected duplicate
verdicts are recorded as evidence but no longer flip the run to partial.

- add reductionIsTolerable: partial only when genuine-loss counts are nonzero
- drive runCapella's partial reasons and display coverage off non-tolerable ones
- keep every reduction in agenticSast.reductions so nothing is lost as evidence
2026-08-27 18:40:36 -07:00
ajmallesh 098bf4be05 fix(sast): align Capella export with the submit-time code-path contract
The export gate required every code_paths entry to be file:line, but submit only
requires the primary sink to be file:line and accepts bare trace steps. A single
malformed trace step therefore dropped an otherwise-valid finding at export.

- add isValidPrimaryCodePath as the one shared primary-sink contract
- validate only the primary at export; buildResult already drops unusable steps
- route the submit-time validator through the same helper so the two cannot drift
2026-08-27 18:40:31 -07:00
ajmallesh 162db4be29 fix(report): drop the empty Critical Findings section from the PDF summary 2026-08-27 17:16:31 -07:00
ajmallesh d71e550b56 merge: integrate Shannon 3.0 with public v2.6.0
- preserve the versioned and non-TTY banners from public main
- keep workspace launch classification ahead of shared infrastructure setup
- carry the eleven-commit Agentic SAST feature history unchanged
- normalize Capella prompt endings to the accepted candidate tree
2026-08-27 14:30:16 -07:00
ajmallesh 321f441f4b feat(cli)!: rebuild scan status around model work
- show Capella stages beneath the concurrent Agentic SAST phase
- attach reconciliation time to the class row it feeds
- hide completed bookkeeping and the duplicate miscellaneous wrapper
- carry validated child-workflow progress into durable parent state
- derive the terminal tree and status JSON from the same phase shape

BREAKING CHANGE: `status --json` replaces phase `parallel` with `children` and `meta`, adds phase summaries and notes plus agent attachment fields, and removes the `analysis-engines` and `operational-work` phases.
2026-08-27 14:28:15 -07:00
ajmallesh e3c6e8df16 fix(logging): treat a slash as a word separator in agent labels 2026-08-27 10:40:49 -07:00
ezl-keygraph dc2a4fe4e8 feat: brand the npm page, CLI output, and reports (#432)
* docs: rebuild the npm package README on the main README's identity

* docs: point the README banner fallback at an asset that exists

* docs: declare the npm package author, homepage, and issue tracker

* docs(cli): retire "Framework" and settle on the canonical product line

* docs: describe the banner image in alt text instead of repeating the lockup

* feat(cli): print a plain-text banner when stdout is not a terminal

* feat(report): attribute the markdown report from a shared brand constant

* feat(cli): frame the plain-text banner with rules and split the version line

* docs: drop the URL from the npm author field
v2.6.0
2026-08-27 18:53:56 +05:30
ajmallesh 2469e6deac chore(license): attribute Mantis and Pi and refresh the docs
Add the final Mantis and Pi notices, license copies, acknowledgements, and residual copyright updates.

Update the README, maintained documentation, contributor guidance, and hand-maintained mirrors to describe Agentic
SAST, reconciliation, the Miscellaneous lane, current CLI behavior, and the final release contract. Correct stale
workspace and container guidance and annotate long-standing internals for maintainers.
2026-08-26 20:19:41 -07:00
ajmallesh 85d5cbd657 feat(worker): disclose scan coverage and make reporting auditable
Build on the retry-safe finalization foundation to preserve correct identities, source locations, scan dates,
partial-coverage limitations, and consistent report JSON, Markdown, SARIF, and PDF output.

Report Agentic SAST, reconciliation wall-clock time, stage usage, retry spend, and background work without duplicate
or hardcoded totals. Keep report findings canonical, drop cross-class restatements, name enrichment losses, and render
the executive-summary narrative in the PDF.
2026-08-26 20:18:44 -07:00
ajmallesh c3864c9785 feat(worker): standardize severity and reporting guidance in exploit prompts
Give every exploit agent the same status, confidence, severity-reasoning, report-writing, credential-handling, and
scope contract.

Apply the same task-formation and SAST-enrichment procedure to the Miscellaneous lane.
2026-08-26 20:17:25 -07:00
ajmallesh f5e7143619 feat(logging): trace tool calls and write a log per agent
Record complete tool-call arguments in the workflow log and project each agent's events into its own durable log.

Add agent listing and agent-specific log tailing while preserving byte-exact output and draining log handles before
activities return.
2026-08-26 20:13:03 -07:00
ajmallesh 242f85f158 feat(cli)!: default the scan target and add a JSON error contract
List local scans, resolve the active or most recent workspace automatically, and make logs, status, and stop use one canonical scan identity.

Add stable machine-readable failures, richer status output, explicit help errors, and seven-day Temporal retention. Treat absent Temporal pending-activity failures as absent whether the decoder represents them as `null` or missing.

BREAKING CHANGE: `status --json` now returns a fixed `failureMessage`. Read `partialReasons`, `agenticSast`, and `workflow.log` for diagnostic detail.
2026-08-26 20:00:11 -07:00
ajmallesh 3bdcfac85d perf: overlap static analysis and the Miscellaneous lane with the pentest
Run Agentic SAST alongside vulnerability analysis and run Miscellaneous exploitation alongside the specialist exploitation lanes.

Keep reconciliation dependent on the completed static-analysis result while preserving parallel work everywhere that has no data dependency.
2026-08-26 19:57:07 -07:00
ajmallesh 98c66e051d feat(config)!: replace vuln_classes with agentic_sast
Wire Agentic SAST and reconciliation into the main pipeline, persist their durable state, and add the Miscellaneous finding and exploitation lane.

Make scan completion, cancellation, partial outcomes, resume identity, and report recovery use the integrated final workflow contract. Introduce the atomic finalization, ordering, renumbering, compaction, and output services that workflow calls. Keep completed Miscellaneous work and report drafts idempotent across resume, preserve public main's default-on exploit SARIF behavior, and describe stage-fallback candidates without claiming they were exported.

BREAKING CHANGE: `vuln_classes` has been removed. Configs containing it now fail validation, and all five core pentest classes run on every scan.

Workspaces created by Shannon 2.x cannot be resumed. Finish or discard in-flight scans before upgrading, then start a new workspace name.
2026-08-26 19:55:03 -07:00
ajmallesh c33132b0ab feat(worker): deduplicate static and runtime findings before exploitation
Parse Agentic SAST SARIF into typed observations, enrich and route those observations, and reconcile them with pentest findings before exploitation.

Publish deterministic exploitation queues with stable lineage, exact-path Git commits, retry-safe manifests, named drop reasons, and confined task formation. Reject duplicate producer IDs before commit and adopt either legal provenance shape after a lost acknowledgement.
2026-08-26 19:37:20 -07:00
ajmallesh 980607c602 feat(worker): add agentic static analysis
Add the ten-stage Agentic SAST pipeline, confined repository tools, model runtime, prompt templates, and SARIF export.

Make retries, repair sessions, reduced coverage, usage accounting, and model-output drift durable across Temporal replay and resume. Keep retry diagnostics in their actionable closed vocabulary. Package the Mantis-derived license material with the prompts that require it.
2026-08-26 19:26:36 -07:00
ezl-keygraph ed5659e2e2 fix(report): emit SARIF by default for exploit runs (#431)
* fix(report): emit SARIF by default for exploit runs, opt out with report.sarif: false

* docs: describe SARIF as on-by-default for exploit runs
v2.5.4
2026-08-26 19:25:16 +05:30
ezl-keygraph f64a30040e ci: publish npm and beta via OIDC trusted publishing (#430) v2.5.3 2026-08-25 00:12:58 +05:30
ezl-keygraph b13788d8ef fix: terminate failed scans in Temporal and surface the reason when following (#429)
* fix(cli): skip splash screen off a TTY (e.g. CI)

* fix: terminate failed scans in Temporal and surface the reason when following

* fix(cli): indent embedded newlines within failure-error segments

* fix(worker): omit the Agent Breakdown section when no agents completed

* fix(cli): don't reprint the failure reason when the log already showed it

* fix(worker): indent embedded newlines within the workflow.log error block
2026-08-24 20:04:47 +05:30
George Flores 53118c6203 Merge pull request #427 from KeygraphHQ/docs/ci-sarif-common-questions
README update
2026-08-19 18:33:16 -07:00
George FloresandClaude Opus 5 af1ed2a563 README update
Documentation pass over the README and supporting docs, incorporating the
Aug 19 review with Parathan.

README:
- Dark/light banner and Discord/Keygraph buttons via <picture>
- Add a Common Questions section at the bottom of the page
- State one consistent position on model support and provider breadth
- Name the OpenAI Responses API alongside Chat Completions
- Frame local and self-hosted models as technically supported but not
  recommended, since capability varies once the harness opens every
  provider and model
- Describe SARIF as machine-readable output rather than a CI feature

Docs:
- ai-providers: drop the Claude-preference claim; explain that capability
  varies and the model should be evaluated against your own targets
- configuration: correct rating semantics stale since v2.2.0, since
  severity is now recorded in both exploitative and analysis-only runs
- safety: reframe the model-support caveat in the same terms
- worker: correct the stale rationale on the SARIF analysis-mode gate

CI/CD documentation is intentionally omitted until the GitHub Marketplace
action lands, so the README does not ship a hand-rolled npx wrapper that
is about to be replaced.

llms.txt and llms-full.txt regenerated from source, with one deliberate
exception: the "Is Shannon free?" and "Is Shannon free for startups and
nonprofits?" questions are kept in the llms-full.txt copy of the README
but not in the README itself. That section exists for agents, so a naive
regeneration of llms-full.txt would drop them; re-add them if you rebuild
the file from source.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 18:26:34 -07:00
ezl-keygraph 12d1c48a78 fix(cli): align usage command column in help output (#426) v2.5.2 2026-08-19 20:07:54 +05:30
ezl-keygraph dfb7c69d3b fix(cli): show splash screen on bare invocation and setup (#425) v2.5.1 2026-08-19 19:42:24 +05:30
ezl-keygraph d41ae9c20d feat(cli): overhaul commands and add live scan status (#424)
* refactor(cli): list workspaces natively instead of via the worker image

* feat(cli): preflight that Docker is installed and running

* feat(cli): stop scans by workspace or --all, terminating their Temporal workflows

* fix(worker): abort the running agent on cancellation so Temporal cancel takes effect

* refactor(cli): split destructive teardown out of stop into a reset command

* refactor(cli): centralise flag parsing and confirmation across commands

* fix(cli): pass provider credentials to docker by name to keep secrets out of argv

* feat(cli): add per-command help via <command> --help/-h and help <command>

* feat(cli): replace raw docker output with clack spinners for infra and scan teardown

* fix(cli): verify scan stop by re-querying container and workflow state instead of assuming success

* fix(cli): resolve running state before prompting on stop and report no-op stops honestly

* refactor(cli): show splash first and drive start with one spinner resolving to a clean line

* fix(cli): validate --url up front so a bad value fails cleanly instead of a late crash

* refactor(cli): centralize error reporting with fail() for expected errors and a crash handler that logs the stack and links the issue tracker

* feat(cli): add --json/--plain machine-readable output to workspaces and status

* refactor(cli): remove the workspaces command

* refactor(cli): remove the status command

* feat(cli): add 'progress <workspace>' — live scan progress from Temporal

* fix(cli): mark metric-less agents as skipped in progress, not done

* feat(cli): animate running agents in progress with a clack-style spinner

* feat(cli): rename progress->status, reveal agents as they run, show live per-agent elapsed

* fix(cli): mark passed-over phases as skipped live, not pending

* style(cli): rename status footer 'Wall-clock' to 'Time Taken', drop the parenthetical

* style(cli): drop '(sum of agents)' from status total cost line

* style(cli): green filled circle for completed, Shannon gold for running

* style(cli): use Shannon gold in place of green in status

* feat(cli): suggest closest command or flag on typo

* refactor(cli): single-source start help and drop ./repos bare-name shortcut

* feat(cli): name providers and fix in multi-provider credential error

* feat(cli): support --flag=value syntax and expand leading ~ in paths

* refactor(cli): centralize ANSI color codes in colors.ts

* feat(cli): add scans command listing completed scans with cost and duration

* fix(cli): keep stdout clean off-TTY for logs and start

* feat(cli): add repo link to top-level help

* feat(worker): record auth-validation metrics and register resume attempts early

* refactor(cli): share resume-aware workflow-id resolution and surface root-cause failures

* feat(cli): add status --json, auth phase, dashboard link, and stable live redraw

* refactor(cli): drop cost from status and scans output

* feat(worker): surface both PDF and markdown report at run root

* refactor(cli): normalize error/warning prefixing through fail and warn

* feat(cli): add version --json for machine-readable output

* refactor(cli): rename start --debug to --keep-container

* refactor(cli): point start's progress hint at status instead of the Temporal dashboard

* refactor(cli): centralize the mode-aware command prefix

* refactor(cli): trim start and logs output to durable facts off-TTY

* feat(cli): require typed confirmation for reset instead of --yes

reset permanently wipes all Temporal data and volumes — a severe,
irreversible action. Replace its default y/N confirm (bypassable with
--yes) with a typed-word confirmation that has no bypass, so the wipe
can only be triggered by a deliberate interactive answer.

* feat(cli): surface logs and status hints after start on a TTY

* feat(cli): exit 2 on usage errors, distinct from operational failures

* feat(cli): add start --follow to stream logs and exit on scan outcome

* refactor(cli): redesign splash with sunset-gradient wordmark and truecolor

* refactor(cli): remove the uninstall command

* docs: sync CLI docs with removed uninstall/workspaces, new scans and --follow

* docs: fix reset confirmation — typed confirm, not --yes/-y

* style(cli): restructure status footer with divider, aligned Logs/Temporal rows

* feat(cli): show splash in the status command

* fix(worker): validate auth-state shape, not entry count

* docs: correct reset confirmation and add markdown report to run-root docs
v2.5.0
2026-08-18 15:46:25 +05:30
ezl-keygraph 1ae0a142f8 feat(worker): render PDF security reports via Typst (#421) 2026-08-12 15:06:43 +05:30
ezl-keygraph d4cc2ab974 feat: support pentests with Codex subscription auth (#419) v2.4.0 2026-08-10 15:27:19 +05:30