- preselect and persist workflow identity before worker launch
- cancel first, then verify bounded Temporal termination
- reconcile Docker workers with Temporal open workflows
- fail closed on stale images and unavailable lifecycle state
- mark cancellation only after confirmed shutdown
- Stop marking a class's vulnerability-analysis agent failed when that agent
succeeded and only reconciliation failed; the status tree now renders the
analysis row completed and the exploitation row failed
- Consume the worker's failedReconciliations signal in the CLI, which the
mirrored PipelineState already declared but never read
- Correct the class_reconciliation_failed message, which claimed the class's
analysis results were still in the report when the class is excluded from it
- Render OWASP category, authentication state, and remediation
- Omit the redundant per-finding exploited status
- Preserve canonical category and field ordering across report modes
- Continue Proof of Impact numbering across embedded code blocks
- Wrap long PDF code lines without changing canonical report content
A failed provider turn collapsed to AGENT_EXECUTION_FAILED/unknown with the
underlying reason discarded, so a model-side rejection or safeguard was
indistinguishable from a transport fault in the error log.
- add safeProviderTurnDetails: write bounded, non-sensitive fields (provider,
model, responseId, stop reason, tool-in-flight, category, retryable) to error.log
- gate a sanitized errorMessage snippet behind SHANNON_DEBUG_PROVIDER_ERRORS, off by default
- forward SHANNON_DEBUG_PROVIDER_ERRORS from the CLI into the worker container
Both conflicts were adjacency rather than intent. Main rewrote only the Pi
Credential Reuse bullet while Capella rewrote the Audit System bullet beside it,
and the two branches added grok-mermaid and handlebars at the same alphabetical
slot in the lockfile. The pi bump to 0.84.2 also widened StopReason with two
states the Capella structured-generation port could not compile against.
- keep main's Pi bullet and Capella's Audit bullet, whose prose matches the code
- keep both lockfile entries; pnpm install --lockfile-only reproduces the result
- classify the new pending and deferred stop reasons as a rejected request
A reduction only makes a run partial when it loses real coverage or a whole
finding. Malformed model output, salvaged turn-limit work, and rejected duplicate
verdicts are recorded as evidence but no longer flip the run to partial.
- add reductionIsTolerable: partial only when genuine-loss counts are nonzero
- drive runCapella's partial reasons and display coverage off non-tolerable ones
- keep every reduction in agenticSast.reductions so nothing is lost as evidence
The export gate required every code_paths entry to be file:line, but submit only
requires the primary sink to be file:line and accepts bare trace steps. A single
malformed trace step therefore dropped an otherwise-valid finding at export.
- add isValidPrimaryCodePath as the one shared primary-sink contract
- validate only the primary at export; buildResult already drops unusable steps
- route the submit-time validator through the same helper so the two cannot drift
- preserve the versioned and non-TTY banners from public main
- keep workspace launch classification ahead of shared infrastructure setup
- carry the eleven-commit Agentic SAST feature history unchanged
- normalize Capella prompt endings to the accepted candidate tree
- show Capella stages beneath the concurrent Agentic SAST phase
- attach reconciliation time to the class row it feeds
- hide completed bookkeeping and the duplicate miscellaneous wrapper
- carry validated child-workflow progress into durable parent state
- derive the terminal tree and status JSON from the same phase shape
BREAKING CHANGE: `status --json` replaces phase `parallel` with `children` and `meta`, adds phase summaries and notes plus agent attachment fields, and removes the `analysis-engines` and `operational-work` phases.
* docs: rebuild the npm package README on the main README's identity
* docs: point the README banner fallback at an asset that exists
* docs: declare the npm package author, homepage, and issue tracker
* docs(cli): retire "Framework" and settle on the canonical product line
* docs: describe the banner image in alt text instead of repeating the lockup
* feat(cli): print a plain-text banner when stdout is not a terminal
* feat(report): attribute the markdown report from a shared brand constant
* feat(cli): frame the plain-text banner with rules and split the version line
* docs: drop the URL from the npm author field
Add the final Mantis and Pi notices, license copies, acknowledgements, and residual copyright updates.
Update the README, maintained documentation, contributor guidance, and hand-maintained mirrors to describe Agentic
SAST, reconciliation, the Miscellaneous lane, current CLI behavior, and the final release contract. Correct stale
workspace and container guidance and annotate long-standing internals for maintainers.
Build on the retry-safe finalization foundation to preserve correct identities, source locations, scan dates,
partial-coverage limitations, and consistent report JSON, Markdown, SARIF, and PDF output.
Report Agentic SAST, reconciliation wall-clock time, stage usage, retry spend, and background work without duplicate
or hardcoded totals. Keep report findings canonical, drop cross-class restatements, name enrichment losses, and render
the executive-summary narrative in the PDF.
Give every exploit agent the same status, confidence, severity-reasoning, report-writing, credential-handling, and
scope contract.
Apply the same task-formation and SAST-enrichment procedure to the Miscellaneous lane.
Record complete tool-call arguments in the workflow log and project each agent's events into its own durable log.
Add agent listing and agent-specific log tailing while preserving byte-exact output and draining log handles before
activities return.
Run Agentic SAST alongside vulnerability analysis and run Miscellaneous exploitation alongside the specialist exploitation lanes.
Keep reconciliation dependent on the completed static-analysis result while preserving parallel work everywhere that has no data dependency.
Wire Agentic SAST and reconciliation into the main pipeline, persist their durable state, and add the Miscellaneous finding and exploitation lane.
Make scan completion, cancellation, partial outcomes, resume identity, and report recovery use the integrated final workflow contract. Introduce the atomic finalization, ordering, renumbering, compaction, and output services that workflow calls. Keep completed Miscellaneous work and report drafts idempotent across resume, preserve public main's default-on exploit SARIF behavior, and describe stage-fallback candidates without claiming they were exported.
BREAKING CHANGE: `vuln_classes` has been removed. Configs containing it now fail validation, and all five core pentest classes run on every scan.
Workspaces created by Shannon 2.x cannot be resumed. Finish or discard in-flight scans before upgrading, then start a new workspace name.
Parse Agentic SAST SARIF into typed observations, enrich and route those observations, and reconcile them with pentest findings before exploitation.
Publish deterministic exploitation queues with stable lineage, exact-path Git commits, retry-safe manifests, named drop reasons, and confined task formation. Reject duplicate producer IDs before commit and adopt either legal provenance shape after a lost acknowledgement.
Add the ten-stage Agentic SAST pipeline, confined repository tools, model runtime, prompt templates, and SARIF export.
Make retries, repair sessions, reduced coverage, usage accounting, and model-output drift durable across Temporal replay and resume. Keep retry diagnostics in their actionable closed vocabulary. Package the Mantis-derived license material with the prompts that require it.
* fix(cli): skip splash screen off a TTY (e.g. CI)
* fix: terminate failed scans in Temporal and surface the reason when following
* fix(cli): indent embedded newlines within failure-error segments
* fix(worker): omit the Agent Breakdown section when no agents completed
* fix(cli): don't reprint the failure reason when the log already showed it
* fix(worker): indent embedded newlines within the workflow.log error block
Documentation pass over the README and supporting docs, incorporating the
Aug 19 review with Parathan.
README:
- Dark/light banner and Discord/Keygraph buttons via <picture>
- Add a Common Questions section at the bottom of the page
- State one consistent position on model support and provider breadth
- Name the OpenAI Responses API alongside Chat Completions
- Frame local and self-hosted models as technically supported but not
recommended, since capability varies once the harness opens every
provider and model
- Describe SARIF as machine-readable output rather than a CI feature
Docs:
- ai-providers: drop the Claude-preference claim; explain that capability
varies and the model should be evaluated against your own targets
- configuration: correct rating semantics stale since v2.2.0, since
severity is now recorded in both exploitative and analysis-only runs
- safety: reframe the model-support caveat in the same terms
- worker: correct the stale rationale on the SARIF analysis-mode gate
CI/CD documentation is intentionally omitted until the GitHub Marketplace
action lands, so the README does not ship a hand-rolled npx wrapper that
is about to be replaced.
llms.txt and llms-full.txt regenerated from source, with one deliberate
exception: the "Is Shannon free?" and "Is Shannon free for startups and
nonprofits?" questions are kept in the llms-full.txt copy of the README
but not in the README itself. That section exists for agents, so a naive
regeneration of llms-full.txt would drop them; re-add them if you rebuild
the file from source.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* refactor(cli): list workspaces natively instead of via the worker image
* feat(cli): preflight that Docker is installed and running
* feat(cli): stop scans by workspace or --all, terminating their Temporal workflows
* fix(worker): abort the running agent on cancellation so Temporal cancel takes effect
* refactor(cli): split destructive teardown out of stop into a reset command
* refactor(cli): centralise flag parsing and confirmation across commands
* fix(cli): pass provider credentials to docker by name to keep secrets out of argv
* feat(cli): add per-command help via <command> --help/-h and help <command>
* feat(cli): replace raw docker output with clack spinners for infra and scan teardown
* fix(cli): verify scan stop by re-querying container and workflow state instead of assuming success
* fix(cli): resolve running state before prompting on stop and report no-op stops honestly
* refactor(cli): show splash first and drive start with one spinner resolving to a clean line
* fix(cli): validate --url up front so a bad value fails cleanly instead of a late crash
* refactor(cli): centralize error reporting with fail() for expected errors and a crash handler that logs the stack and links the issue tracker
* feat(cli): add --json/--plain machine-readable output to workspaces and status
* refactor(cli): remove the workspaces command
* refactor(cli): remove the status command
* feat(cli): add 'progress <workspace>' — live scan progress from Temporal
* fix(cli): mark metric-less agents as skipped in progress, not done
* feat(cli): animate running agents in progress with a clack-style spinner
* feat(cli): rename progress->status, reveal agents as they run, show live per-agent elapsed
* fix(cli): mark passed-over phases as skipped live, not pending
* style(cli): rename status footer 'Wall-clock' to 'Time Taken', drop the parenthetical
* style(cli): drop '(sum of agents)' from status total cost line
* style(cli): green filled circle for completed, Shannon gold for running
* style(cli): use Shannon gold in place of green in status
* feat(cli): suggest closest command or flag on typo
* refactor(cli): single-source start help and drop ./repos bare-name shortcut
* feat(cli): name providers and fix in multi-provider credential error
* feat(cli): support --flag=value syntax and expand leading ~ in paths
* refactor(cli): centralize ANSI color codes in colors.ts
* feat(cli): add scans command listing completed scans with cost and duration
* fix(cli): keep stdout clean off-TTY for logs and start
* feat(cli): add repo link to top-level help
* feat(worker): record auth-validation metrics and register resume attempts early
* refactor(cli): share resume-aware workflow-id resolution and surface root-cause failures
* feat(cli): add status --json, auth phase, dashboard link, and stable live redraw
* refactor(cli): drop cost from status and scans output
* feat(worker): surface both PDF and markdown report at run root
* refactor(cli): normalize error/warning prefixing through fail and warn
* feat(cli): add version --json for machine-readable output
* refactor(cli): rename start --debug to --keep-container
* refactor(cli): point start's progress hint at status instead of the Temporal dashboard
* refactor(cli): centralize the mode-aware command prefix
* refactor(cli): trim start and logs output to durable facts off-TTY
* feat(cli): require typed confirmation for reset instead of --yes
reset permanently wipes all Temporal data and volumes — a severe,
irreversible action. Replace its default y/N confirm (bypassable with
--yes) with a typed-word confirmation that has no bypass, so the wipe
can only be triggered by a deliberate interactive answer.
* feat(cli): surface logs and status hints after start on a TTY
* feat(cli): exit 2 on usage errors, distinct from operational failures
* feat(cli): add start --follow to stream logs and exit on scan outcome
* refactor(cli): redesign splash with sunset-gradient wordmark and truecolor
* refactor(cli): remove the uninstall command
* docs: sync CLI docs with removed uninstall/workspaces, new scans and --follow
* docs: fix reset confirmation — typed confirm, not --yes/-y
* style(cli): restructure status footer with divider, aligned Logs/Temporal rows
* feat(cli): show splash in the status command
* fix(worker): validate auth-state shape, not entry count
* docs: correct reset confirmation and add markdown report to run-root docs
* feat(cli): support any Pi provider via generic SHANNON_AI_API_KEY
* docs(cli): point users to pi.dev/models for provider and model ids
* docs: document generic provider path and pi.dev catalogue
* feat(worker): record severity in analysis mode alongside confidence
* fix(worker): align add_finding severity with the exploit collector's four levels
* refactor(worker): drop the dead REPORT_VULN_HEADING substitution
No prompt in the tree uses the placeholder, so the replacement was a no-op
on every render.
* fix(worker): strip all whitespace from TOTP secrets, not just the ends
* fix(worker): render rule type and value in the agent prompt
* refactor(worker): drop the dead vuln-summary subsection substitution
* feat(worker): record token, cache, and turn usage per agent
* feat: replace model tiers with a single SHANNON_AI_MODEL across five providers
* feat(cli): rebuild the setup wizard for provider and model selection
* docs: document single-model selection and supported providers
* feat(worker): use chat completions for OpenAI behind a custom base URL
* feat: add SHANNON_AI_OPENAI_FORMAT to pick the wire API for OpenAI gateways
* refactor(cli): drop endpoint path hints from the gateway format picker
* feat(worker): enable pi in-session provider retry with retry-after backoff
* refactor(worker): hand provider error classification to pi and drop the Anthropic ladders
* refactor: remove the subscription retry preset and pipeline config section
* fix(worker): validate Bedrock credentials with the same live probe as other providers
* feat(worker): render the report from structured findings instead of agent-written markdown
* fix(worker): dispose the credential probe session on every path
* fix(worker): refuse to replace the assembled report with an empty one
* refactor(worker): catch post-processing throws across the whole finalization block
* revert(worker): drop the report zero-findings guard
* docs(worker): correct the retry split and Bedrock credential claims
* docs: regenerate llms-full.txt from current sources
* feat(cli): build and run the npx flow from a clone
* refactor(cli): flatten the setup summary output
* feat(cli): reject runs with more than one provider configured
* fix(worker): say a rejected bash call never ran
* chore(cli): drop grok-4.3 and gpt-5.6-luna from the setup suggestions
* feat(worker): capture structured finding locations for SARIF output
* fix(worker): enumerate queue confidence so the report inherits it verbatim
* feat(worker): give the reporting phase a mode-specific output schema
* feat(worker): emit a SARIF 2.1.0 log for exploitative runs
* fix(worker): correct SARIF locations and defer fingerprinting to the upload action
* fix(worker): drop the confidence suffix from the analysis-mode summary list
* feat(worker): give exploit findings a dedicated code location field
* feat(worker): carry structured code locations from the vuln queue to the report
* fix(worker): join code locations from the vuln queue instead of re-asking agents
* fix(worker): spell out the finding_id to category mapping in the tool schema
* feat: drop Google/Gemini as a supported AI provider
* fix(worker): stop asking the report agent for code locations
* docs: correct the provider list and drop the removed rate-limit settings
* docs: add provider cyber safeguards and suggested models per provider
* docs: document the SARIF output and the report rating thresholds
* feat(worker): migrate agent runtime from Claude Agent SDK to pi harness
* feat: remove Google Vertex AI provider support
* fix(worker): route Bedrock and custom-base-URL providers from env
* feat(prompts): instruct agents to call submit_exploitation_queue and submit_auth_result
* fix(worker): count sub-agent cost and surface compaction failures
* refactor(worker): rename claude-executor to pi-executor
* feat(worker): pi-event-driven output formatting
* fix(worker): gate adaptive thinking to Opus models, drop CLAUDE_THINKING_LEVEL
* fix(worker): restore minLength/minItems on vuln-collector schemas
* feat(worker): give task sub-agent write+bash, align tool descriptions
* feat(worker): add glob custom tool and route code_path globs to it
* refactor(prompts): use pi tool names (task, todo_write, read, bash, glob)
* refactor(prompts): drop stale MCP terminology for collector tools
* refactor(prompts): drop collector server names from deliverable instructions
* fix(worker): restore minLength/minItems on pre-recon and exploit collector schemas
* feat(worker): load playwright-cli skill via pi resource loader
* refactor(cli): remove CLAUDE_CODE_MAX_OUTPUT_TOKENS config
* build: drop @anthropic-ai/claude-code from worker image
* docs: remove vertex references from llms context
* docs(worker): update stale sdk comments
* refactor(worker): unify provider precedence between preflight and executor
* feat(worker): enforce bounded bash timeouts via pi extension
* ci: bump the beta release line to 2.0.0 (#356)
* fix(cli): pin npx command hints to beta tag
* fix: render agent deliverables before the success commit so resume preserves them (#377)
* feat(cli): restructure run folder and improve terminal UX (#383)
* feat: surface report at run root and nest run internals under .shannon
* feat: use plain-language wording in user-facing terminal messages
* feat(cli): guide users to watch scan progress and surface report path on start
* docs: sync run-folder layout and CLI wording across docs and comments
* feat(cli): add version command reporting package version or git SHA
* feat(cli): detect TTY for interactive prompts, color, and progress output
* docs: document --yes flag, version command, and tty module
* fix(cli): FORCE_COLOR precedence and plain uninstall --yes output
* fix(cli): respect empty NO_COLOR
* fix(cli): let NO_COLOR take precedence over FORCE_COLOR
* docs: mark claude-code-router integration as removed
* refactor(worker): converge shared core with shannon-oss (#388)
* fix(worker): port keygraph shared-core correctness fixes
* refactor(worker): adopt collectors/ and ai/pi/ layout; add task budget cap and cancellation
* refactor(worker): drop inconsistent Collector "Server" suffix
* refactor(worker): drop unused providerConfig/apiKey seams, resolve credentials from env only
* refactor(worker): port oss code_path pattern expansion + external_directory allow
* fix(worker): preserve dotfile paths in code_path avoid patterns (.env no longer stripped to env)
* feat(worker): render Unprocessed Vulnerabilities section in exploit deliverable (align with oss)
* feat(worker): request set_blind_spots for all vuln classes (align auth/ssrf with production prompts)
* refactor(worker): adopt unified permissionSystem* naming and helper layout
* refactor(worker): inline blind_spots into vuln deliverable section array
* chore(worker): drop unused zod dependency (tree is typebox-native)
* fix(worker): normalize base32 TOTP secret to accept padding and whitespace
* refactor(worker): adopt shared toolResult helper and flatSchema naming in collectors
* refactor(worker): use undefined over null in queue-schema builders
* docs(worker): converge renderer/collector doc comments to current pi terminology
* refactor(worker): adopt schema.ts cleanInput/stringEnum helpers in collectors
* feat(worker): converge exploit-collector/renderer with vendored; capture and render overview for blocked findings
* refactor(worker): converge session-tools/pipeline/exploitation-checker with vendored
* refactor(worker): converge task-tool usage reporting with vendored onUsage callback
* refactor(worker): converge structured output onto a submitTool executor channel
* docs(worker): expand exploit-renderer docstring to match shannon-oss
* docs(worker): adopt richer vuln-renderer docstring from shannon-oss
* docs(worker): neutralize billing-detection wording for shannon-oss parity
* fix(worker): verify checkpoint hash in the deliverables clone being reset
* fix(worker): fail fast on malformed exploitation queue JSON
* fix(worker): honor retryable flag when classifying exploitation-queue check failures
* fix(worker): fail fast on corrupted session.json in run-scope validation
* feat(worker): propagate Temporal cancellation signal into agent and auth pi sessions
* fix(worker): mark exploit agent complete when exploitation is skipped so resume skips it
* prompts: drop scan description from executive report prompt
* refactor(worker): add createGenericSubmitTool for raw JSON-schema submit tools
* refactor(worker): gate playwright-cli skill to browser agents via skillsOverride (adopt shannon-oss mechanism)
* docs(worker): correct formatLogTime comment to UTC to match toISOString
* refactor(worker): converge queue-schemas with shannon-oss (guarded count, decl order)
* refactor(worker): converge task-tool with shannon-oss (byte-identical; modelRegistry optional)
* fix(worker): use replaceLiteral for all prompt value insertions to prevent $-mangling
* fix(worker): classify agent execution failures by error type instead of hardcoding validation
* fix(worker): cap auth-failure detail at 250 chars to match shannon-oss
* style(worker): apply biome formatting
* refactor(worker): remove per-session task delegation cap from task tool
* style(cli): collapse usage hint now that the beta tag is gone
* chore: mark the pi harness migration as a breaking change
BREAKING CHANGE: Google Vertex AI is no longer a supported provider. The
CLAUDE_CODE_USE_VERTEX, ANTHROPIC_VERTEX_PROJECT, CLOUD_ML_REGION, and
GOOGLE_APPLICATION_CREDENTIALS environment variables, along with the
use_vertex, vertex_project, and cloud_ml_region config.toml keys, are
removed. Vertex users must switch to Anthropic, AWS Bedrock, or a custom
Anthropic-compatible base URL.
The CLAUDE_CODE_MAX_OUTPUT_TOKENS environment variable and the
max_output_tokens config.toml key are also removed.
* feat: surface report at run root and nest run internals under .shannon
* feat: use plain-language wording in user-facing terminal messages
* feat(cli): guide users to watch scan progress and surface report path on start
* docs: sync run-folder layout and CLI wording across docs and comments
* feat(cli): add version command reporting package version or git SHA
* feat(cli): detect TTY for interactive prompts, color, and progress output
* docs: document --yes flag, version command, and tty module
* fix(cli): FORCE_COLOR precedence and plain uninstall --yes output
* fix(cli): respect empty NO_COLOR
* fix(cli): let NO_COLOR take precedence over FORCE_COLOR
* docs: mark claude-code-router integration as removed
* feat(auth): reuse preflight's authenticated session across agents
* fix(preflight): verify saved auth state parses and has cookies or origins
* fix(prompts): strip shared-session block when no auth is configured
* fix(shannon): store shared auth state in the per-session audit dir
* fix(prompts): write stub auth-state in pipeline-testing preflight
* fix(preflight): clear stale auth-state.json before validate-authentication
* fix(preflight): drop auth-state.json on workflow completion
* docs(claude): refresh auth-state.json description for new layout and cleanup
* refactor(prompts): drop unused PLAYWRIGHT_SESSION resolve in login instructions
* style(prompts): collapse verifySavedAuthState signature per biome
* refactor(prompts): require AUTH_STATE_FILE on authenticated runs
* style(prompts): trim numbered-step comments back to step headers
* feat(steerability): add config-driven profile with code_path avoid enforcement
* fix(steerability): write SDK deny rules once per workflow to avoid parallel-agent race
* fix(steerability): reference guidance by pointer in report DROP rules
* fix(steerability): tighten code_path avoid enforcement
* chore(steerability): use shared ALL_VULN_CLASSES const and tighten RunScope type
* fix(steerability): validate run scope before resume short-circuit
* fix(steerability): emit only documented Read/Edit deny rules for code_path
* fix(steerability): assemble report from analysis deliverables when exploit is disabled
* feat(steerability): preflight check that code_path rules match at least one repo entry
* fix(steerability): tag missing code_path entries with avoid/focus kind
* revert(steerability): assemble report from analysis deliverables when exploit is disabled
* feat(steerability): render per-class findings from queue JSON when exploit is disabled
* refactor(steerability): trim findings renderer to common mappable rows
* feat(steerability): allow report agent to rewrite category-label finding titles
* docs(steerability): document new config fields in README and CLAUDE.md
* docs(steerability): comment out optional config sections in examples
* feat: add ReportOutputProvider for consumer-extended report artifacts
* fix: thread deliverablesSubdir through report assembly
* fix: produce structured report JSON on resume path
* fix: fail loud on structured report output provider errors
* feat: extend checkpoint provider and container DI for consumer-specific backends
* fix: pre-create .shannon overlay mount points on all platforms
* chore: drop claude-code-router mode
* fix: drop 'resets' keyword from spending-cap text patterns
* feat: extract pipeline core for library consumption
* fix: chmod workspace directory for container write access
* fix: resolve playwright output dir relative to deliverables parent
* feat: add multi-provider LLM support via ProviderConfig
* fix: resolve model overrides via options.model, remove unused model env passthrough
* fix: use ANTHROPIC_AUTH_TOKEN for custom base URL and router auth
* fix: skip env-based credential validation when providerConfig is present
* fix: support large UID/GID values for AD/LDAP users in container