2026-05-21 - 2026-08-21

Overview

78 Active Pull Requests
88 Active Issues
Excluding merges, 2 authors have pushed 78 commits to main and 163 commits to all branches. On main, 188 files have changed and there have been 27327 additions and 4179 deletions.

1 Release published by 1 user

Published v0.3.0 2026-07-22 17:06:22 +00:00

78 Pull requests merged by 1 user

Merged #231 chore(ci): repoint registry/git/cargo meghsakha.com -> breakpilot.com 2026-08-06 08:42:48 +00:00

Merged #230 fix(orchestrator): refresh control_refs on PLC re-scans 2026-07-22 17:06:09 +00:00

Merged #229 fix(orchestrator): run semantic control mapping on PLC findings 2026-07-22 13:16:53 +00:00

Merged #228 fix(orchestrator): refresh control_refs on existing findings during re-scan 2026-07-22 12:24:37 +00:00

Merged #227 docs(control-mapping): MCP emission loop + default-on flags 2026-07-22 11:23:52 +00:00

Merged #226 fix(mcp): bind tenant to session — bearer context was lost over HTTP 2026-07-22 09:30:07 +00:00

Merged #224 feat(controls): promote grounded controls to covered + enable LLM passes by default 2026-07-22 07:48:52 +00:00

Merged #225 ci: fix cosign signing (install fallback, env-style login, portal sign step) 2026-07-22 07:46:34 +00:00

Merged #223 docs(features): compliance control-mapping pipeline 2026-07-22 07:30:11 +00:00

Merged #222 feat(controls): enrich semantic retrieval query with finding intent + C5 live test 2026-07-22 07:14:49 +00:00

Merged #221 fix(llm): chunk embed() requests under the backend batch cap 2026-07-21 15:41:07 +00:00

Merged #220 feat(controls): B3 — categorize the rest of needs_tooling (architectural + RBAC) 2026-07-21 13:15:27 +00:00

Merged #219 feat(controls): B2 — grounded surface checks for absence-based CRA controls 2026-07-21 12:48:13 +00:00

Merged #218 feat(controls): B1 — custom semgrep detectors for 4 CRA controls 2026-07-21 12:31:20 +00:00

Merged #216 ci: push images to Harbor (repo.meghsakha.com) + cosign 2026-07-21 12:08:05 +00:00

Merged #217 feat(agent): cache control embedding index + auto-wire semantic pass (gated) 2026-07-21 11:29:17 +00:00

Merged #215 feat(agent): semantic control mapping — embedding index + region->control retrieval 2026-07-21 10:50:22 +00:00

Merged #214 feat(oscal): emit unmapped findings as-is + MCP oscal_assessment tool 2026-07-21 09:48:38 +00:00

Merged #213 feat: control-driven SAST — LUT + grounded LLM triage over tool findings 2026-07-21 09:01:52 +00:00

Merged #212 feat(oscal): live assessment endpoint POST /api/v1/oscal/assess 2026-07-20 19:13:47 +00:00

Merged #211 feat(oscal): assessment-results emitter + finding->control linker 2026-07-20 16:53:40 +00:00

Merged #210 feat(oscal): ingest breakpilot OSCAL catalog via OscalControlsProvider 2026-07-20 16:19:09 +00:00

Merged #209 feat(werkbank): make the loop runnable — enqueue + artifact serve/fetch (WB-05b) 2026-07-17 14:34:01 +00:00

Merged #208 refactor(werkbank): extract soft-PLC provisioning + ICS probe into werkbank-exec (WB-04a) 2026-07-17 12:56:16 +00:00

Merged #207 feat(werkbank): runner queue endpoints + result persistence (WB-05) 2026-07-17 11:42:30 +00:00

Merged #206 feat(werkbank): Mongo-backed job queue with lease + visibility timeout (WB-02) 2026-07-17 09:15:24 +00:00

Merged #205 feat(werkbank): job/result contract in compliance-core (WB-01) 2026-07-17 08:54:12 +00:00

Merged #193 feat(plc): ephemeral soft-PLC provisioning + program load (#183) 2026-07-17 07:47:44 +00:00

Merged #185 docs(plc): PLC Runtime Landscape reference + support watch-list 2026-07-16 22:05:40 +00:00

Merged #184 docs(plc): soft-PLC architecture + CODESYS/Yocto lifecycle diagram 2026-07-16 22:00:18 +00:00

Merged #182 fix(matrix): DAST needs an http(s) endpoint; don't offer/run it on modbus:// 2026-07-16 21:28:48 +00:00

Merged #181 feat(onboarding): enable opt-in scans from the wizard success step 2026-07-16 20:52:51 +00:00

Merged #180 feat(cve): match the CODESYS runtime against NVD by CPE 2026-07-16 20:10:20 +00:00

Merged #179 feat(onboarding): Project-archive PLC format + auto-detect from extension 2026-07-16 20:05:06 +00:00

Merged #178 fix(plc): scan every PLC-source artifact, not just the first 2026-07-16 19:59:59 +00:00

Merged #177 fix(upload): raise body-size limit to 512 MiB + surface upload errors 2026-07-16 18:03:41 +00:00

Merged #176 fix(dashboard): preselect saved type/kind in edit-target form 2026-07-16 17:52:28 +00:00

Merged #175 feat(ics): EtherNet/IP probe + OT service-discovery port scan [#148] 2026-07-16 16:48:23 +00:00

Merged #174 feat(ics): OPC UA reachability probe [#148] 2026-07-16 16:35:55 +00:00

Merged #173 feat(cve): notifications for the PLC control-app SBOM (shared helper) [#166] 2026-07-16 16:30:20 +00:00

Merged #172 feat(ics): dynamic Modbus/TCP probe for PLC/SPS devices [#148] 2026-07-16 16:25:05 +00:00

Merged #171 feat(plc): ingest CODESYS projects from a git repo (SAST + SBOM) + docs/UI 2026-07-16 15:47:05 +00:00

Merged #170 feat(plc): control-application SBOM from CODESYS .projectarchive (+CVE) [#166] 2026-07-16 15:28:43 +00:00

Merged #169 feat(plc): analyse graphical logic (FBD/LD) from PLCopen XML [#165] 2026-07-16 11:43:50 +00:00

Merged #168 feat(matrix): PlcSps as a composite device target (SBOM/CVE/DAST/pentest) [#164] 2026-07-16 10:56:36 +00:00

Merged #163 feat(onboarding): PLC/blob file upload (multipart) + single-file ingest fix 2026-07-16 09:41:13 +00:00

Merged #162 feat(pipeline): PLC/SPS control-logic security scanner (IEC 61131-3) 2026-07-16 08:31:44 +00:00

Merged #161 refactor: rip out the legacy TrackedRepository / repositories path 2026-07-16 07:25:46 +00:00

Merged #160 feat(onboarding): input validation + editable targets 2026-07-13 17:57:49 +00:00

Merged #159 feat(agent): real nix (sandbox=false) for firmware SBOM, replacing nix-portable 2026-07-13 16:01:10 +00:00

Merged #158 fix(deps): bump tramiton to v0.4.1 (proot-safe firmware build) 2026-07-13 11:21:44 +00:00

Merged #157 feat(pipeline): firmware SBOM via tramiton reproducible build (phase 2) 2026-07-13 10:15:07 +00:00

Merged #156 feat(pipeline): analysis-based firmware SBOM from tramiton 2026-07-13 08:31:34 +00:00

Merged #155 fix(dashboard): Findings/SBOM filter by targets + accurate target findings_count 2026-07-13 07:59:46 +00:00

Merged #154 fix(onboarding): targets visibility + unified pipeline by default 2026-07-13 07:29:05 +00:00

Merged #153 feat(onboarding): scan-trigger endpoint + wizard Run-Scan button 2026-07-12 22:19:32 +00:00

Merged #152 ci: don't cancel-in-progress for main-branch runs (only pull_request) 2026-07-12 22:08:59 +00:00

Merged #147 fix(ci): authenticate tramiton fetch in dashboard + mcp image builds 2026-07-12 21:52:39 +00:00

Merged #146 feat(pipeline): run tramiton classification + provision DAST in run_target 2026-07-12 21:49:23 +00:00

Merged #145 feat(pipeline): unified run_target execution behind UNIFIED_PIPELINE 2026-07-12 21:31:22 +00:00

Merged #144 feat(dashboard): onboarding wizard UI 2026-07-12 21:28:53 +00:00

Merged #143 fix(ci): authenticate tramiton-core fetch in the agent image build (main deploys) 2026-07-12 20:25:40 +00:00

Merged #142 feat(api): onboarding endpoints for unified targets 2026-07-12 20:15:22 +00:00

Merged #141 feat(migrate): onboarding backfill (repositories + dast_targets -> onboarded_targets) 2026-07-12 20:11:17 +00:00

Merged #140 ci: Kellnr crates.io mirror + persistent S3-backed sccache 2026-07-10 16:30:51 +00:00

Merged #138 feat(onboarding): artifact ingest + classifier + suite-integration seams 2026-07-10 16:00:51 +00:00

Merged #134 feat(onboarding): unified multi-target model + scan matrix foundation 2026-07-10 13:41:26 +00:00

Merged #94 feat(dashboard): UI for managing MCP tokens 2026-06-30 16:32:56 +00:00

Merged #96 feat(m7.3): scheduler pulls tenants from registry, env as fallback 2026-06-30 16:32:36 +00:00

Merged #97 fix(audit): bump quinn-proto + ignore rmcp DNS-rebinding advisory 2026-06-30 16:07:01 +00:00

Merged #92 feat(m7.3): MCP tenant-scoped bearer tokens 2026-06-30 15:27:24 +00:00

Merged #95 feat(m7.3): cross-tenant admin HTTP endpoints 2026-06-30 15:23:41 +00:00

Merged #93 chore(agent): remove stale unscoped webhook routes from API router 2026-06-30 15:18:31 +00:00

Merged #91 feat(dashboard): proactively refresh expired Keycloak tokens 2026-06-17 20:01:43 +00:00

Merged #90 fix(dashboard): attach Keycloak token on agent API calls 2026-06-17 18:36:06 +00:00

Merged #85 feat(m7.1): wire compliance-agent to compliance-core auth + status gate 2026-06-17 09:36:52 +00:00

Merged #84 fix(m7.1): JWKS refresh-on-failure in auth middleware 2026-06-04 14:46:15 +00:00

Merged #83 M7.1 smoke harness: lift auth to compliance-core + compliance-smoke service 2026-06-04 14:38:36 +00:00

39 Issues closed from 1 user

Closed #198 WB-04 · Docker executor + plc-provision job (THIN SLICE) 2026-07-17 08:19:33 +00:00

Closed #204 WB-10 · Observability & security hardening 2026-07-17 08:19:33 +00:00

Closed #203 WB-09 · Runner registration, labels & capability-matched routing 2026-07-17 08:19:33 +00:00

Closed #202 WB-08 · K8s executor, then Shell executor 2026-07-17 08:19:33 +00:00

Closed #201 WB-07 · On-prem runner mode 2026-07-17 08:19:33 +00:00

Closed #199 WB-05 · Control-plane cut-over to enqueue plc-provision 2026-07-17 08:19:33 +00:00

Closed #200 WB-06 · qemu-boot job (firmware dynamic) 2026-07-17 08:19:33 +00:00

Closed #196 WB-02 · DB-table job queue (control plane) 2026-07-17 08:19:32 +00:00

Closed #197 WB-03 · Werkbank runner skeleton 2026-07-17 08:19:32 +00:00

Closed #195 WB-01 · Job + result contract in compliance-core 2026-07-17 08:19:32 +00:00

Closed #194 Epic · Werkbank — dynamic-execution runner (pull queue, pluggable executors, on-prem) 2026-07-17 08:19:26 +00:00

Closed #126 ONB-08 · Wizard screen 3 — scan selection + scope/auth 2026-07-12 22:19:32 +00:00

Closed #133 ONB-15 · Unified scan-pipeline rewrite (feature-flagged run_target path) 2026-07-12 21:31:22 +00:00

Closed #123 ONB-05 · Onboarding wizard shell — multi-step flow, state, navigation 2026-07-12 21:28:53 +00:00

Closed #131 ONB-13 · Onboarding API endpoints (target CRUD, artifact upload, detection) 2026-07-12 20:15:23 +00:00

Closed #132 ONB-14 · Migration + back-compat (fold TrackedRepository / DastTarget in) 2026-07-12 20:11:17 +00:00

Closed #139 CI: use crates.meghsakha.com (Kellnr) mirror + persistent sccache (Hetzner S3), matching werkpilot 2026-07-10 16:30:51 +00:00

Closed #32 [medium] gdpr-patterns: Missing data deletion capability 2026-07-10 07:52:41 +00:00

Closed #31 [medium] gdpr-patterns: Missing data deletion capability 2026-07-10 07:52:40 +00:00

Closed #29 [medium] semgrep: Service 'mailserver' is running with a writable root filesystem. This may allow malicious applications to download and run additional payloads, or modify container files. If an application inside a container has to save something temp… 2026-07-10 07:52:39 +00:00

Closed #54 [medium] semgrep: Service 'mailserver' is running with a writable root filesystem. This may allow malicious applications to download and run additional payloads, or modify container files. If an application inside a container has to save something temp… 2026-07-10 07:52:39 +00:00

Closed #27 [medium] semgrep: Dangerously accepting invalid TLS information 2026-07-10 07:52:26 +00:00

Closed #25 [high] semgrep: Insecure WebSocket Detected. WebSocket Secure (wss) should be used for all WebSocket connections. 2026-07-10 07:52:25 +00:00

Closed #26 [medium] semgrep: Dangerously accepting invalid TLS information 2026-07-10 07:52:25 +00:00

Closed #24 [high] semgrep: Insecure WebSocket Detected. WebSocket Secure (wss) should be used for all WebSocket connections. 2026-07-10 07:52:24 +00:00

Closed #46 [high] gitleaks: Secret detected: Detected a Generic API Key, potentially exposing access to various services and sensitive operations. 2026-07-10 07:52:12 +00:00

Closed #45 [high] gitleaks: Secret detected: Detected a Generic API Key, potentially exposing access to various services and sensitive operations. 2026-07-10 07:52:11 +00:00

Closed #44 [high] gitleaks: Secret detected: Detected a Generic API Key, potentially exposing access to various services and sensitive operations. 2026-07-10 07:52:11 +00:00

Closed #43 [high] gitleaks: Secret detected: Detected a Generic API Key, potentially exposing access to various services and sensitive operations. 2026-07-10 07:52:10 +00:00

Closed #41 [high] oauth-patterns: OAuth implicit grant flow detected 2026-07-10 07:52:00 +00:00

Closed #42 [high] oauth-patterns: OAuth implicit grant flow detected 2026-07-10 07:52:00 +00:00

Closed #38 [medium] gdpr-patterns: Data collection without apparent consent mechanism 2026-07-10 07:51:59 +00:00

Closed #39 [medium] gdpr-patterns: Data collection without apparent consent mechanism 2026-07-10 07:51:59 +00:00

Closed #37 [medium] gdpr-patterns: Data collection without apparent consent mechanism 2026-07-10 07:51:58 +00:00

Closed #36 [medium] gdpr-patterns: Data collection without apparent consent mechanism 2026-07-10 07:51:58 +00:00

Closed #35 [high] gdpr-patterns: PII data potentially logged 2026-07-10 07:51:57 +00:00

Closed #33 [high] gdpr-patterns: PII data potentially logged 2026-07-10 07:51:56 +00:00

Closed #34 [high] gdpr-patterns: PII data potentially logged 2026-07-10 07:51:56 +00:00

Closed #106 CS-C1 · Encode CRA→62443-4-2 crosswalk as OSCAL catalog 2026-07-03 08:04:14 +00:00

67 Issues created by 1 user

Opened #99 CS-A2 · Firmware ingest (EMBA + cve-bin-tool + binwalk) 2026-07-03 08:03:56 +00:00

Opened #98 CS-A1 · Syft/Trivy runner → CycloneDX SBOM 2026-07-03 08:03:56 +00:00

Opened #100 CS-A3 · SBOM data model + Mongo repo 2026-07-03 08:03:56 +00:00

Opened #103 CS-B2 · ICS advisory ingest (CISA ICS-CERT CSAF) 2026-07-03 08:03:57 +00:00

Opened #101 CS-A4 · Dashboard SBOM view 2026-07-03 08:03:57 +00:00

Opened #102 CS-B1 · CVE matcher (OSV.dev + NVD) 2026-07-03 08:03:57 +00:00

Opened #104 CS-B3 · LLM VEX triage → OpenVEX 2026-07-03 08:03:57 +00:00

Opened #105 CS-B4 · VEX review UX (approve/override) 2026-07-03 08:03:58 +00:00

Opened #107 CS-C2 · Mapping engine (findings → controls → status) 2026-07-03 08:03:58 +00:00

Opened #106 CS-C1 · Encode CRA→62443-4-2 crosswalk as OSCAL catalog 2026-07-03 08:03:58 +00:00

Opened #108 CS-C3 · Compliance dashboard (requirement → status → evidence) 2026-07-03 08:03:59 +00:00

Opened #109 CS-D1 · Evidence aggregator 2026-07-03 08:03:59 +00:00

Opened #110 CS-D2 · LLM narrative → conformity DRAFT (Pandoc/Typst) 2026-07-03 08:03:59 +00:00

Opened #111 CS-D3 · Human sign-off gate 2026-07-03 08:04:00 +00:00

Opened #112 CS-E1 · PLCopen XML / ST parser (eval RuSTy) 2026-07-03 08:04:00 +00:00

Opened #113 CS-E2 · 3 control-logic security rules 2026-07-03 08:04:00 +00:00

Opened #114 CS-E3 · LLM remediation hints for lint findings 2026-07-03 08:04:01 +00:00

Opened #117 CS-F3 · Machine-overview landing 2026-07-03 08:04:01 +00:00

Opened #115 CS-F1 · Seed demo dataset (one fictional machine) 2026-07-03 08:04:01 +00:00

Opened #116 CS-F2 · Demo narrative script + reset 2026-07-03 08:04:01 +00:00

Opened #118 ONB-Epic · Multi-target artifact-aware onboarding wizard 2026-07-10 08:32:57 +00:00

Opened #119 ONB-01 · Target taxonomy + unified data model (OnboardedTarget/TargetType/Artifact) 2026-07-10 08:34:41 +00:00

Opened #121 ONB-03 · Artifact-aware classifier / auto-detection (Tramiton detect handoff) 2026-07-10 08:34:42 +00:00

Opened #120 ONB-02 · Artifact ingest layer (git/zip/firmware/mobile/container/URL/plaintext) 2026-07-10 08:34:42 +00:00

Opened #123 ONB-05 · Onboarding wizard shell — multi-step flow, state, navigation 2026-07-10 08:34:43 +00:00

Opened #122 ONB-04 · Scan-applicability matrix (target type × artifacts → SAST/DAST/pentest) 2026-07-10 08:34:43 +00:00

Opened #125 ONB-07 · Wizard screen 2 — artifact upload/link (type-aware inputs) 2026-07-10 08:34:44 +00:00

Opened #124 ONB-06 · Wizard screen 1 — target type selection (card grid + auto-detect) 2026-07-10 08:34:44 +00:00

Opened #126 ONB-08 · Wizard screen 3 — scan selection + scope/auth 2026-07-10 08:34:45 +00:00

Opened #127 ONB-09 · Wizard screen 4 — review & launch 2026-07-10 08:34:45 +00:00

Opened #129 ONB-11 · Mobile (Android/iOS) onboarding specifics (APK/AAB/IPA) 2026-07-10 08:34:46 +00:00

Opened #128 ONB-10 · Firmware / Yocto onboarding specifics (Tramiton + EMBA/binwalk) 2026-07-10 08:34:46 +00:00

Opened #131 ONB-13 · Onboarding API endpoints (target CRUD, artifact upload, detection) 2026-07-10 08:34:47 +00:00

Opened #130 ONB-12 · PLC / SPS onboarding specifics (PLCopen XML / ST) 2026-07-10 08:34:47 +00:00

Opened #132 ONB-14 · Migration + back-compat (fold TrackedRepository / DastTarget in) 2026-07-10 08:34:48 +00:00

Opened #133 ONB-15 · Unified scan-pipeline rewrite (feature-flagged run_target path) 2026-07-10 09:02:05 +00:00

Opened #136 ONB-17 · Compliance-scope capture + pluggable ControlsProvider (OSCAL vs breakpilot RAG) 2026-07-10 10:32:30 +00:00

Opened #135 ONB-16 · Tramiton evidence reconciliation (detect handoff + local evidence + entitlement) 2026-07-10 10:32:30 +00:00

Opened #137 ONB-18 · Werkpilot remediation hook (downstream consumer) 2026-07-10 10:32:31 +00:00

Opened #139 CI: use crates.meghsakha.com (Kellnr) mirror + persistent sccache (Hetzner S3), matching werkpilot 2026-07-10 13:32:21 +00:00

Opened #148 ONB · PLC/SPS dynamic testing — soft-PLC (OpenPLC) + industrial-protocol probing 2026-07-12 21:56:19 +00:00

Opened #149 ONB · Embedded Linux/Yocto dynamic path — QEMU boot (runqemu/FirmAE) → DAST + pentest 2026-07-12 21:56:20 +00:00

Opened #150 ONB · Bitbake/Yocto detection (our classifier) + Yocto-native SPDX/cve-check ingest (no tramiton dep) 2026-07-12 21:56:20 +00:00

Opened #151 ONB · FirmwareStatic scanner: EMBA + binwalk + cve-bin-tool (firmware image analysis) 2026-07-12 21:56:21 +00:00

Opened #164 ONB · Composite PLC-on-Yocto target: PlcSps offers SBOM/CVE + DAST + pentest (matrix) 2026-07-16 10:40:46 +00:00

Opened #165 ONB · SAST: CODESYS native project (.project/.projectarchive) + graphical languages (LD/FBD/SFC/CFC) 2026-07-16 10:40:47 +00:00

Opened #166 ONB · SBOM: control-application dependency SBOM (CODESYS libraries + runtime version) -> CVE 2026-07-16 10:40:47 +00:00

Opened #167 ONB · CODESYS-on-Yocto customer: end-to-end SBOM/SAST/DAST/pentest coverage tracker 2026-07-16 10:40:57 +00:00

Opened #183 Epic: Dynamic PLC testing via ephemeral soft-PLC (deploy control logic → ICS + DAST) 2026-07-16 21:23:22 +00:00

Opened #186 Epic · Certifai → breakpilot-platform integration (post-#183) 2026-07-16 22:16:32 +00:00

Opened #187 STORY · Demo target fixtures — curated representative targets 2026-07-16 22:16:32 +00:00

Opened #192 STORY · breakpilot-compliance Qdrant RAG controls as ControlsProvider tools 2026-07-16 22:16:33 +00:00

Opened #189 STORY · Next.js onboarding app in breakpilot-platform (replace Dioxus) 2026-07-16 22:16:33 +00:00

Opened #190 STORY · RBAC for onboarding + scanner data (breakpilot-platform RBAC) 2026-07-16 22:16:33 +00:00

Opened #191 STORY · Externalize findings/SBOM/CVE as API + MCP to platform services 2026-07-16 22:16:33 +00:00

Opened #188 STORY · Nightly agent regression against the demo targets 2026-07-16 22:16:33 +00:00

Opened #194 Epic · Werkbank — dynamic-execution runner (pull queue, pluggable executors, on-prem) 2026-07-17 08:14:30 +00:00

Opened #195 WB-01 · Job + result contract in compliance-core 2026-07-17 08:15:05 +00:00

Opened #196 WB-02 · DB-table job queue (control plane) 2026-07-17 08:15:05 +00:00

Opened #197 WB-03 · Werkbank runner skeleton 2026-07-17 08:15:06 +00:00

Opened #198 WB-04 · Docker executor + plc-provision job (THIN SLICE) 2026-07-17 08:15:06 +00:00

Opened #199 WB-05 · Control-plane cut-over to enqueue plc-provision 2026-07-17 08:15:07 +00:00

Opened #200 WB-06 · qemu-boot job (firmware dynamic) 2026-07-17 08:15:07 +00:00

Opened #202 WB-08 · K8s executor, then Shell executor 2026-07-17 08:15:08 +00:00

Opened #203 WB-09 · Runner registration, labels & capability-matched routing 2026-07-17 08:15:08 +00:00

Opened #201 WB-07 · On-prem runner mode 2026-07-17 08:15:08 +00:00

Opened #204 WB-10 · Observability & security hardening 2026-07-17 08:15:09 +00:00

3 Unresolved Conversations