تخطٍّ إلى المحتوى

ما الجديد

سجل إصدارًا بإصدار لتطوير Fendix. صدر الإصدار v3.4.1 في سبتمبر 2026 — تُبنى صور المحرك الآن بلغة Go 1.27 وتشحن بها، فيرتفع سقف الوحدات المدعومة في govulncheck من 1.25؛ ولا تغييرات في الفاحصات أو البصمات أو رموز الخروج، ويبقى الحد الأدنى لإصدار وحدات Go عند 1.25. وفي v3.4.0 — لم يعد بالإمكان أن يبدو المسح مكتملًا وهو ليس كذلك: يسجّل كل محلل ما إذا كان قد عمل ولماذا لم يعمل، ويحمل التقرير كتلة تغطية تسمّي الفجوات، ويكتب مسح URL الذي لا يجد نقاط نهاية تقريره بدل أن يختفي، وتحوّل رايتان اختياريتان فجوة التغطية إلى بناء مُخفق. وفي v3.3.0 — لم تعد الترقية تقسم النتيجة التي تتابعها إلى مغلقة وجديدة، وصارت قائمة الفحوص تُبنى مما اكتمل لا مما جرى إعداده. وفي v3.2.0 — وفيه صار كل قرار حظر يشرح نفسه. تحمل نتيجة BLOCK الآن السياسة التي اتُّخذت بموجبها وصنف الدليل الذي برّرها، عبر تخزين Fendix نفسه وحتى ملف SARIF الذي تصدّره، فيصير خط الإنتاج المخفق قابلًا للتفسير من التقرير وحده. وتذكر النتائج المحجوزة سبب حجزها، وتأتي درجات الثقة مصحوبة بالقواعد التي أنتجتها، ويُوسم صراحةً أي بناء حُظر لمجرد أن فرض الثقة كان مُعطَّلًا. وأوقف الإصدار v3.1.0 ادعاء النتائج بأكثر مما أثبتته — من CORS بحرف بدل مع بيانات الاعتماد، إلى ترتيب أولويات تحديد المعدّل، وتقييم الترويسات بحسب نوع الاستجابة، وصياغة اجتياز المسارات، وبيانات الاعتماد الاختبارية، وقابلية تطبيق الاعتماديات. ومنح الإصدار v3.0 النتائج هوية مستقرة مبنية على القاعدة والملف والرمز والعملية بدل رقم السطر؛ أعد حفظ خطوط الأساس مرة واحدة بعد الترقية من إصدار أقدم منه.

v0.6.0 مكتمل

First Stable Signed Release

April 30, 2026

  • First stable signed release. Every binary, .deb, .rpm, and Docker manifest ships with .crt + .sig cosign sidecars verifiable against the build's GitHub Actions OIDC identity — no static public key, no rotation surface, no key-loss recovery story
  • Cosign keyless signing fully active on the release pipeline (Sigstore Fulcio + GitHub Actions OIDC). COSIGN_ENABLED=true flipped on the engine repo on 2026-04-30T14:07Z; rc2 was the first tag to exercise the full signed-release path end-to-end, then promoted to v0.6.0 final after pipeline validation. Cosign steps hard-fail the release job, so a broken signing path can't silently ship unsigned artifacts
  • https://get.fendix.dev/install.sh is live — DNS CNAME at the registrar, GitHub Pages on the homebrew-fendix mirror, auto-provisioned Let's Encrypt cert. End-to-end smoke test verified the install pipe end-to-end. Mirror URL retained as a documented fallback. Engine repo is now the single source of truth for everything served at get.fendix.dev — auto-synced by release.yml on every v* tag
  • Linux arm64 release binary added — brew install fendix and curl -fsSL https://get.fendix.dev/install.sh | sh now serve native ARM builds for Graviton, Ampere, Raspberry Pi, and ARM Linux laptops
  • Multi-arch Docker image at ghcr.io/abdel-rahmansaied/fendix:vX.Y.Z — manifest list covers linux/amd64 + linux/arm64; docker pull picks the right arch automatically
  • Linux .deb and .rpm packages built via nfpm — install with sudo dpkg -i fendix-*.deb && sudo apt-get install -f or sudo dnf install ./fendix-*.rpm. Declares python3 as required and semgrep as recommended
  • Documentation pass for external evaluators: 5-minute juice-shop walkthrough (docs/walkthrough-juice-shop.md), Semgrep rule-author guide (docs/semgrep-rules.md), triage workflow (docs/triage-workflow.md), JSON schema reference (docs/schema.md), all cross-linked from a top-level Documentation index in the README
  • New --debug-bundle <path> flag writes a redacted diagnostic .tar.gz for attaching to bug reports — auth values masked as [REDACTED], full DEBUG slog stream tee'd into the bundle, probe audit log on --enable-active. Auth credentials never leak (e2e regression locks this in)
  • SECURITY.md + active-scanner threat model (docs/threat-model.md): vulnerability disclosure policy, supported-versions, cosign verification instructions, and the 7-threat safety envelope every active probe must maintain
  • Performance benchmark suite: scan time vs endpoint count, peak goroutine count, allocation profile — published in README. Reference: 1000 endpoints in 31.7 ms / 24.7 MB / 166 peak goroutines (Apple M1, Go 1.21)
v0.6.0-rc1RC مكتمل

External Release Readiness

April 30, 2026

  • Linux arm64 release binary added — brew install fendix and curl -fsSL .../install.sh | sh now serve native ARM builds for Graviton, Ampere, Raspberry Pi, and ARM Linux laptops
  • Multi-arch Docker image at ghcr.io/abdel-rahmansaied/fendix:vX.Y.Z — manifest list covers linux/amd64 + linux/arm64; docker pull picks the right arch automatically
  • Cosign keyless signing wired (Sigstore Fulcio + GitHub Actions OIDC; opt-in via the COSIGN_ENABLED=true repo variable). When enabled, every binary ships with .sig + .crt sidecar files
  • Linux .deb and .rpm packages built via nfpm — install with sudo dpkg -i fendix-*.deb && sudo apt-get install -f or sudo dnf install ./fendix-*.rpm. Declares python3 as required and semgrep as recommended
  • New docs/install.md install reference covers every install path with cosign verification one-liners; get.fendix.dev short-URL installer planned (operator-action: domain registration + GitHub Pages CNAME)
  • Documentation pass for external evaluators: 5-minute juice-shop walkthrough (docs/walkthrough-juice-shop.md), Semgrep rule-author guide (docs/semgrep-rules.md), triage workflow (docs/triage-workflow.md), JSON schema reference (docs/schema.md), all cross-linked from a top-level Documentation index in the README
  • New --debug-bundle <path> flag writes a redacted diagnostic .tar.gz for attaching to bug reports — auth values masked as [REDACTED], full DEBUG slog stream tee'd into the bundle, probe audit log on --enable-active. Auth credentials never leak (e2e regression locks this in)
  • SECURITY.md + active-scanner threat model (docs/threat-model.md): vulnerability disclosure policy, supported-versions, cosign verification instructions, and the 7-threat safety envelope every active probe must maintain
  • Performance benchmark suite: scan time vs endpoint count, peak goroutine count, allocation profile — published in README. Reference: 1000 endpoints in 31.7 ms / 24.7 MB / 166 peak goroutines (Apple M1, Go 1.21)
  • Release-candidate cut to validate the new pipeline (cosign + nfpm + ghcr) end-to-end before tagging clean v0.6.0; signed-release validation pending COSIGN_ENABLED=true
v0.5.0 مكتمل

Quality & Ops

April 30, 2026

  • Public JSON output schema published (docs/schema.md + docs/schema.json draft-07); validator runs in tests against every emitted report; findings: [] instead of null when empty
  • Path-parameter substitution: templated endpoints like /users/{id} now scan against /users/1 (or schema-derived sample). Resolution order: schema.exampleschema.enum[0] → type-driven default → name heuristic → fallback 1. Endpoint.Path stays templated for reports; FullURL is concrete
  • Logging hygiene: aggregated WARN volume — max 3 per check key per scan, rest downgraded to DEBUG. New INFO warning summary line at scan end. Real-world: 30 WARN lines → 9 + 1 summary on a 10-endpoint scan against an unreachable target
  • Scan budgets: new --max-requests (soft cap on total HTTP requests; discovery exempt), --max-duration (Go duration string, e.g. 5m), --respect-robots (treat robots.txt Disallow as hard restriction across all discovery sources)
  • New auth profile: --auth-type apikey-query puts the credential in the URL query string instead of a header — common for legacy/sensor APIs that prefer query placement
  • Auth profiles end-to-end: bearer / apikey-header / apikey-query / basic / cookie all covered by e2e tests that record what reaches the server
  • Concurrency review: race-clean proof at 1000 endpoints × 32 workers under go test -race; new FuzzWorkerPool_CancelTiming fuzzer (4455 execs / zero failures over 15s of fuzzing)
  • Severity↔confidence consistency enforced — LOW confidence caps severity at MEDIUM, MEDIUM caps at HIGH (matches the scoring formula's implicit max). Inconsistent findings get severity downgraded with an aggregated WARN line
  • Drop-in GitHub Actions workflow: examples/github-actions/fendix-scan.yml does scan → actions/cache baseline → SARIF upload → PR summary comment via actions/github-script@v7
v0.4.0 مكتمل

Coverage Parity

April 29, 2026

  • Correlator finalized: HTTP method-prefix stripping + path-suffix matching (handles base-path skew like spec /pet/findByStatus ↔ live /api/v3/pet/findByStatus); debug instrumentation with match_kind=exact|suffix|fuzzy; blackbox findings consumed at most once
  • Real CVE coverage: pip-audit (PyPI) + npm audit (JS) + govulncheck (Go) as primary paths; hardcoded list as offline fallback. Real-world: badcode/requirements.txt = 6 deps findings (offline) → 97 with pip-audit installed (16× coverage)
  • Go module support — go.mod files now scanned by govulncheck; only emits findings on actually-called code paths (vendored-but-uncalled noise dropped)
  • Crawler upgrade: robots.txt + sitemap.xml + HTML link parsing with recursive depth. Real-world: httpbin.org discovery went from 1 endpoint to 3 (Disallow /deny + linked /forms/post + brute-force /robots.txt)
  • New flags: --wordlist, --crawl-depth (default 1), --max-endpoints (default 500); built-in CommonPaths expanded ~50 → 117 with admin/dashboard/source-control/DevOps tooling paths
  • Findings deduplication: identical issues across N endpoints collapse into one finding with affected_endpoints (real-world: petstore 160 → 10, 16× reduction)
  • Static analyzer: 6 new patterns — pickle.load, yaml.load without SafeLoader, MD5/SHA1 for passwords, open redirect, SSRF, auth-header trust
  • Multi-step SQLi detection via intra-function scope tracking (sql = '...' + var; cursor.execute(sql))
  • Active scanner: body & header param probing; error-based + boolean-based SQLi; SQLite + Oracle time-based payloads (5 DB types total)
  • New --max-probes-per-endpoint flag (default 20) for active scan budget control
  • Secrets analyzer: 8 new provider patterns — GitHub, Stripe, Slack, Google, Anthropic, OpenAI, npm, GCP service-account JSON (15 total, was 7)
  • .env file scanning fixed (dotfile walker now yields env-files; unquoted KEY=value pattern gated to .env*)
  • v0.4.0 ships the planned v0.3.0 batch under a single tag
v0.2.0 مكتمل

P0 Flag Wiring

April 29, 2026

  • --save-baseline now actually writes a file (was previously a silent no-op at the CLI)
  • --code-only scans run successfully (orchestrator no longer early-exits when only --code is given)
  • Active scanner now uses spec-defined query/path parameters instead of hardcoded id
  • --spec now accepts https://... URLs in addition to local file paths (fetched with content-type detection, 50 MB cap)
  • SARIF rule IDs are now stable per check type (fendix.<category>.<title-slug>) — breaking change for v0.1 SARIF baseline consumers
  • End-to-end test infrastructure: every CLI flag now has a test that runs the binary and asserts observable effect
v0.1.0 مكتمل

Initial Release

April 2026

  • Initial production release — ~594 tests across the engine
  • MIT License, CHANGELOG, .fendix-ignore.example template
  • Ready for production use with full documentation
Phase 9 مكتمل

Hardening

April 2026

  • Performance benchmark suite across all critical paths
  • Go native fuzz testing (362k+ executions, 0 panics)
  • Python hypothesis fuzz testing — found and fixed 3 real bugs
  • Self-audit: 0 production code vulnerabilities
  • 29 resilience tests: garbage responses, timeouts, crashes, malformed streams
  • Memory profiling: 2.3KB/finding, 15MB/1000 correlations
  • Error message audit — 7 messages improved with actionable guidance
Phase 8 مكتمل

Documentation

April 2026

  • Complete README.md with all 10 required sections
  • CONTRIBUTING.md with development setup and check-writing guides
  • 11 individual check documentation pages in docs/checks/
  • 6 Architecture Decision Records (ADR-001 through ADR-006)
  • CHANGELOG.md following Keep a Changelog format
  • Full godoc (92 Go symbols) and docstring (16 Python symbols) coverage

صدر الإصدار v3.4.1 في سبتمبر 2026 — تُبنى صور المحرك الآن بلغة Go 1.27 وتشحن بها، فيرتفع سقف الوحدات المدعومة في govulncheck من 1.25؛ ولا تغييرات في الفاحصات أو البصمات أو رموز الخروج، ويبقى الحد الأدنى لإصدار وحدات Go عند 1.25. صدر الإصدار v3.4.0 في سبتمبر 2026 — لم يعد بالإمكان أن يبدو المسح مكتملًا وهو ليس كذلك: يسجّل كل محلل ما إذا كان قد عمل ولماذا لم يعمل، ويحمل التقرير كتلة تغطية تسمّي الفجوات، ويكتب مسح URL الذي لا يجد نقاط نهاية تقريره بدل أن يختفي، وتحوّل رايتان اختياريتان فجوة التغطية إلى بناء مُخفق. صدر الإصدار v3.3.0 في سبتمبر 2026 — ولم تعد الترقية تقسم النتيجة التي تتابعها إلى مغلقة وجديدة، وصارت قائمة الفحوص تُبنى مما اكتمل لا مما جرى إعداده. وفي v3.2.0 — وفيه صار كل قرار حظر يشرح نفسه. تحمل نتيجة BLOCK الآن السياسة التي اتُّخذت بموجبها وصنف الدليل الذي برّرها، عبر تخزين Fendix نفسه وحتى ملف SARIF الذي تصدّره، فيصير خط الإنتاج المخفق قابلًا للتفسير من التقرير وحده. وتذكر النتائج المحجوزة سبب حجزها، وتأتي درجات الثقة مصحوبة بالقواعد التي أنتجتها، ويُوسم صراحةً أي بناء حُظر لمجرد أن فرض الثقة كان مُعطَّلًا. وأوقف الإصدار v3.1.0 ادعاء النتائج بأكثر مما أثبتته — من CORS بحرف بدل مع بيانات الاعتماد، إلى ترتيب أولويات تحديد المعدّل، وتقييم الترويسات بحسب نوع الاستجابة، وصياغة اجتياز المسارات، وبيانات الاعتماد الاختبارية، وقابلية تطبيق الاعتماديات. ومنح الإصدار v3.0 النتائج هوية مستقرة مبنية على القاعدة التي أطلقت النتيجة، وفي أي ملف، وداخل أي دالة، وحول أي عملية. أعد حفظ خطوط الأساس مرة واحدة بعد الترقية من إصدار أقدم من v3.0، وأعد كتابة أي قاعدة .fendix-ignore تثبّت قيمة fingerprint: — أما القواعد التي تطابق بالمسار أو الفئة أو معرّف القاعدة فلا تتأثر.