mirror of
https://github.com/KeygraphHQ/shannon.git
synced 2026-10-08 09:11:13 +02:00
Drop "Shannon Open Source" and "the Keygraph platform" as product names. The open-source project is Shannon (Shannon OSS where a contrast helps), and the commercial editions are Keygraph Pro and Keygraph Enterprise, plus the Community Program. The one retired-names line now maps Shannon Lite to Shannon and Shannon Pro to Keygraph Pro. Also covers the npm README, the coverage and safety docs, llms.txt and the regenerated llms-full.txt. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
24 lines
1.0 KiB
Markdown
24 lines
1.0 KiB
Markdown
# Coverage and Roadmap
|
|
|
|
Shannon focuses on exploitable findings that can be validated against a running application.
|
|
|
|
## Current Shannon Coverage
|
|
|
|
- Broken Authentication
|
|
- Broken Authorization
|
|
- Injection
|
|
- Cross-Site Scripting
|
|
- Server-Side Request Forgery
|
|
|
|
## Reporting Philosophy
|
|
|
|
Shannon follows a proof-by-exploitation model. Findings that cannot be demonstrated with a working proof of concept are not included in the final report.
|
|
|
|
This reduces speculative noise, but it also means Shannon does not aim to report every possible security issue in a repository. In particular, many dependency, policy, configuration, and broad static-analysis findings are outside the core Shannon workflow.
|
|
|
|
## Roadmap Direction
|
|
|
|
Planned coverage areas should continue to live in the repository's canonical roadmap document if one exists. The README should link to that document rather than carrying detailed roadmap history inline.
|
|
|
|
For organizations that need broader static and organizational coverage now, see [Keygraph Pro and Enterprise](keygraph-platform.md).
|