39 Commits
Author SHA1 Message Date
NotoriousRebel 50669f2704 docs: align fail-closed proxy contract 2026-08-25 23:11:03 -04:00
NotoriousRebel 414276e330 fix: fail closed when required proxies are unavailable 2026-08-25 22:59:06 -04:00
L1ghtn1ng 86c2c5f979 fix: enforce discovery security boundaries
Keep proxy identities stable across provider conversations, preserve exact target scope, canonicalize evidence, secure first-run config creation, and retain legacy source-name compatibility.
2026-08-25 01:29:05 +01:00
NotoriousRebel 9b982db7b6 fix: report provider collection outcomes truthfully 2026-08-16 21:31:08 -04:00
NotoriousRebel 6e0e761661 fix: close provider contract review gaps 2026-08-15 22:28:14 -04:00
NotoriousRebel df1933b345 fix: preserve provider sessions across pagination 2026-08-15 13:20:26 -04:00
NotoriousRebel bbc7832c8f fix: reuse bounded takeover transport 2026-08-15 11:44:18 -04:00
NotoriousRebel ea9dab4b87 feat: replace takeover fingerprints with typed evidence 2026-08-15 03:30:33 -04:00
MattandGitHub f44807a046 refactor: run discovery sources with TaskGroup (#2544)
* refactor: run discovery sources with TaskGroup

* fix: preserve source runner compatibility diagnostics

* feat: add configurable source workers
2026-08-15 01:48:33 -04:00
MattandGitHub 38e32de023 fix: complete API endpoint scans by default (#2539)
* fix: complete API endpoint scans by default

* refactor: reuse shared cancellation cleanup
2026-08-14 23:03:28 -04:00
MattandGitHub bb77613a05 fix: call Censys Platform API directly (#2537)
* fix: call Censys Platform API directly (#295)

(cherry picked from commit 7ce361413ad35471ab0b6878382f3548b0918dbe)

* docs: clarify Censys global search entitlement
2026-08-14 22:44:45 -04:00
MattandGitHub 259455f1c1 fix: remove Windvane DNS guessing fallback (#2541) 2026-08-14 15:14:53 -04:00
MattandGitHub 624066a3e8 Add RouteViews enrichment and sourced ASN organization attribution (#2528)
* Add RouteViews network enrichment

* Add authenticated RouteViews API access

* Restrict RouteViews to explicit network pivots

* Restore discovered ASN RouteViews enrichment

* Retain sourced ASN organization attribution

* Avoid dangling and repeated ASN attributions

* Keep automatic RouteViews evidence target-relevant

* Complete target-relevant RouteViews enrichment

* Clarify automatic RouteViews IP pivots
2026-08-13 10:46:54 -04:00
MattandGitHub aed50e0b0d Add crt.name composite hostname discovery (#2531) 2026-08-12 17:05:12 -04:00
MattandGitHub 4643f6f0f9 fix: use explicit provider and browser user agents (#2530) 2026-08-12 17:01:57 -04:00
MattandGitHub 91ed6c1d9f Add APIs.guru hostname, email, and URL discovery (#2525)
* feat: add bounded APIs.guru discovery

* docs: clarify APIs.guru result boundaries
2026-08-12 12:06:04 -04:00
MattandGitHub ac3c543768 Add bounded provider response streaming (#2526)
* Add bounded provider response streaming

* Add bounded provider JSON fetching
2026-08-12 09:41:13 -04:00
MattandGitHub fa8afa5e46 Add bounded virtual-host discovery (#2517)
* Add bounded virtual-host discovery

* Document virtual host probe boundary
2026-08-11 00:43:04 -04:00
MattandGitHub 1fd5749e52 Add an authenticated durable run API v1 (#2511)
* Model active evidence in result persistence

* Expose active action diagnostics

* Persist truthful DNS action evidence

* Persist direct action evidence

* feat: add authenticated durable run API v1

* Make API file interchange JSONL-only

* Harden API evidence boundaries

* Remove API rate limiter

* Unify API runs with result persistence

* Support target action runs

* Keep DNS resolver selection action-neutral

* Add action-neutral CLI resolver selection

* Preserve API evidence across JSONL round trips

* Complete HarvestView API run parity

* Harden HarvestView run API contracts

* Remove obsolete bundled network snapshots

Delete the unused bundled AWS IP-range and resolver snapshots while preserving operator-supplied resolver file input.

* refactor: canonicalize URL results

* docs: define a bounded test budget

* Standardize hostname and IP result names

* fix(api): avoid duplicate evidence conflicts
2026-08-10 00:08:04 -04:00
MattandGitHub 6b02dbddc9 Share safe enumeration execution across transports (#2507)
* feat: share safe enumeration execution across transports

* fix: clarify safe scan contracts

* fix: preserve public screenshot redirects

* fix: restore operator-controlled active requests

* fix: allow operator-selected API scan targets
2026-08-07 16:02:16 -04:00
MattandGitHub 7a854eda95 Contract DeHashed and LeakIX evidence (#2506)
* Contract DeHashed evidence handling

* Align LeakIX with its documented API

* Update provider capability selection

* Require REST auth for DeHashed results
2026-08-07 00:25:54 -04:00
MattandGitHub 30ac342d9d Remove unavailable Venacus source (#2505) 2026-08-07 00:04:47 -04:00
MattandGitHub ce791dcaca Contract Leak-Lookup evidence handling (#2504)
* Contract Leak-Lookup evidence

* Preserve additional API compatibility
2026-08-07 00:01:26 -04:00
MattandGitHub 8d8bbdc060 Preserve POST semantics through proxies (#2498) 2026-08-06 21:32:02 -04:00
MattandGitHub 9ff9115dcf Migrate Pentest-Tools discovery to API v2 (#2497)
* Migrate Pentest-Tools discovery to API v2

* Send Pentest scan payload as JSON
2026-08-06 21:27:30 -04:00
MattandGitHub 4f76b93513 Preserve direct DNS source result contracts (#2494)
* Harden explicit DNS direct source contracts

* Reject mismatched Shodan InternetDB evidence

* Preserve valid direct-source IP evidence

* Avoid ambiguous hostname output assertions

* Reference current Pentest-Tools scan documentation
2026-08-06 20:16:23 -04:00
MattandGitHub d60afe12e1 Retain GitLab evidence URLs (#2492) 2026-08-06 15:39:26 -04:00
MattandGitHub 16c4866b49 fix: drive all from passive source catalog (#2489) 2026-08-06 14:47:33 -04:00
MattandGitHub a7f883e45c feat: add HIBP verified-domain source (#2488) 2026-08-06 14:47:33 -04:00
NotoriousRebel 35b368b705 fix: retain HIBP breach names in completed results 2026-08-05 23:02:36 -04:00
NotoriousRebel e063c42a08 fix: remove invalid Bitbucket domain source (#100) 2026-08-05 21:45:08 -04:00
NotoriousRebel 66e1beee7c feat: preserve shared HTTP response metadata 2026-08-05 18:31:36 -04:00
NotoriousRebel 59311ef7cc test: isolate configuration copy logging 2026-08-04 19:54:57 -04:00
NotoriousRebel 4a69697451 feat: select sources by result capability 2026-07-30 19:47:51 -04:00
NotoriousRebel 677fa512d4 fix: separate diagnostics from operator output 2026-07-20 23:37:09 -04:00
L1ghtn1ng acf099f6ac Bump dependencies, replace UJSONResponse with JSONResponse, and add _API_KEY_FIELDS to Core. 2026-03-07 08:26:21 +00:00
L1ghtn1ng ffe1f3a832 Synchronize api-keys.yaml with Core class API key references and add a test to ensure consistency 2026-01-18 01:15:26 +00:00
L1ghtn1ng bc2fce07cc Update proxy parameter handling in tests: expand default structure to include both "http" and "socks5" fields 2026-01-06 22:14:02 +00:00
Branch VincentandGitHub 4d825aaf33 build: migrate to pep517 backend (#1505)
* build: migrate to pep517 backend

* test loading config files
2023-10-08 19:45:23 +01:00