Pulling#788
Open
LordPhenixDeNetra wants to merge 532 commits into
Open
Conversation
Bumps [protobuf](https://github.com/protocolbuffers/protobuf) from 6.33.4 to 6.33.5. - [Release notes](https://github.com/protocolbuffers/protobuf/releases) - [Commits](https://github.com/protocolbuffers/protobuf/commits) --- updated-dependencies: - dependency-name: protobuf dependency-version: 6.33.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
… and CVSS Replace 12 flat parameters (code_file, code_before, code_after, code_diff, and 8 CVSS fields) with structured nested XML fields: code_locations with co-located fix_before/fix_after per location, cvss_breakdown, and cwe. This enables multi-file vulnerability locations, per-location fixes with precise line numbers, data flow representation (source/sink), CWE classification, and compatibility with GitHub/GitLab PR review APIs.
- Specify encoding="utf-8" in registry.py _load_xml_schema() - Specify encoding="utf-8" in skills/__init__.py load_skills() - Prevents cp949/shift_jis/cp1252 decoding errors on non-English Windows
… multi-part suggestions Rewrote the code_locations parameter description to make fix_before/fix_after semantics explicit: they are literal block-level replacements mapped directly to GitHub/GitLab PR suggestion blocks. Added guidance for multi-part fixes (separate locations for non-contiguous changes like imports + code), common mistakes to avoid, and updated all examples to demonstrate multi-line ranges.
* feat: add to readme new keys * feat: shoutout strix models, docs * fix: mypy error * fix: base api * docs: update quickstart and models * fixes: changes to docs uniform api_key variable naming * test: git commit hook * nevermind it was nothing * docs: Update default model to claude-sonnet-4.6 and improve Strix Router docs - Replace gpt-5 and opus-4.6 defaults with claude-sonnet-4.6 across all docs and code - Rewrite Strix Router (models.mdx) page with clearer structure and messaging - Add Strix Router as recommended option in overview.mdx and quickstart prerequisites - Update stale Claude 4.5 references to 4.6 in anthropic.mdx, openrouter.mdx, bug_report.md - Fix install.sh links to point to models.strix.ai and correct docs URLs - Update error message examples in main.py to use claude-sonnet-4-6 --------- Co-authored-by: 0xallam <ahmed39652003@gmail.com>
Bumps [pypdf](https://github.com/py-pdf/pypdf) from 6.6.2 to 6.7.1. - [Release notes](https://github.com/py-pdf/pypdf/releases) - [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md) - [Commits](py-pdf/pypdf@6.6.2...6.7.1) --- updated-dependencies: - dependency-name: pypdf dependency-version: 6.7.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
…ability names - Replace fragile prefix matching with explicit STRIX_MODEL_MAP - Add resolve_strix_model() returning (api_model, canonical_model) - api_model (openai/ prefix) for API calls to OpenAI-compatible Strix API - canonical_model (actual provider name) for litellm capability lookups - Centralize resolution in LLMConfig instead of scattered call sites
Removed pipx installation instructions for strix-agent.
Bumps [google-cloud-aiplatform](https://github.com/googleapis/python-aiplatform) from 1.129.0 to 1.133.0. - [Release notes](https://github.com/googleapis/python-aiplatform/releases) - [Changelog](https://github.com/googleapis/python-aiplatform/blob/main/CHANGELOG.md) - [Commits](googleapis/python-aiplatform@v1.129.0...v1.133.0) --- updated-dependencies: - dependency-name: google-cloud-aiplatform dependency-version: 1.133.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
The badge image URL used invite code which is expired, causing the badge to render 'Invalid invite' instead of the server info. Updated to use the vanity URL which resolves correctly. Fixes usestrix#313
…sestrix#637) Line 72 was over-indented, causing an IndentationError on import of strix/report/writer.py and breaking main. Also bump the mirrors-mypy pre-commit hook to v1.17.1 to avoid the mypy 1.16.0 internal crash (python/mypy#19412) on openai/_client.py.
Co-authored-by: Alex Schapiro <46074070+bearsyankees@users.noreply.github.com>
* fix: capture cost for streamed LiteLLM responses * docs: note LiteLLM streaming metadata callbacks
…ation, Django (usestrix#617) * Add five community security skills for agent specialization Expand coverage with OAuth flow testing, AWS misconfigurations, prototype pollution, insecure deserialization, and Django framework playbooks. * Address Greptile review feedback on AWS and deserialization skills - Use head-bucket for S3 existence checks instead of duplicating s3 ls - Add Node.js to insecure_deserialization frontmatter description * Clarify S3 existence vs public listing checks in aws skill Split unauthenticated enumeration into separate head-bucket/HTTP and s3 ls steps with interpretation guidance per review. * some tools ads --------- Co-authored-by: bearsyankees <bearsyankees@gmail.com>
…sestrix#626) * feat(report): SARIF 2.1.0 emitter for CI / code-scanning integration Strix emits CSV + markdown + JSON but no SARIF, so findings can't feed GitHub code-scanning, an ASPM, or any SARIF-consuming CI gate. Add a stdlib-only emitter (strix/report/sarif.py) and always write findings.sarif from ReportState._save_artifacts, beside the existing artifacts. Design invariants (learned from running this in production): - Stable partialFingerprints.primaryLocationLineHash per finding, so a re-scan that re-words a title doesn't churn code-scanning alert IDs. - Class/category hashing so the same vuln class maps to a stable ruleId across scans rather than drifting. - Findings with no code location anchor to SECURITY.md with a synthetic location marker instead of being silently dropped. - Always emit (even with zero findings) so a clean re-scan overwrites a stale findings.sarif and code-scanning auto-resolves fixed alerts. - tool.driver.version reports the strix package version. - Fully isolated in its own try/except: a SARIF build error must never break the CSV/MD/run-record path. Verified end-to-end on v1.0.4 against a SQLi/cmd-inj/weak-hash fixture: 3 findings -> valid SARIF 2.1.0, 3 results, real code locations, distinct per-finding fingerprints. * fix(report): complete SARIF code scanning metadata --------- Co-authored-by: bearsyankees <bearsyankees@gmail.com>
…usestrix#689) _read_json_overrides is documented to let env vars outrank the persisted cli-config.json, but it decided per-alias and broke on the first alias found in either env or the file. When a multi-alias field (e.g. api_key via LLM_API_KEY/OPENAI_API_KEY) was set in the env under one alias but stored in the file under another, the stale file value was surfaced as an init kwarg and overrode the live env var. A lowercase env var was also missed (settings use case_sensitive=False). Decide whether a field is already set in the environment by checking all of its aliases case-insensitively before consulting the file. Add regression tests for the cross-alias and case-insensitive cases. Closes usestrix#688
Cover run record I/O, vulnerability markdown rendering, CSV severity ordering, and executive report output.
…trix#708) Builds on the SARIF 2.1.0 emitter (usestrix#626): give each SARIF rule one or more `stride:<leg>` tags (Spoofing / Tampering / Repudiation / Information disclosure / Denial of service / Elevation of privilege) derived from the finding's CWE, so consumers — the GitHub code-scanning Security tab, ASPM dashboards, coverage reports — can group and filter findings by threat-model leg. SARIF results inherit their rule's tags via ruleId, so tagging the rule is sufficient. - _CWE_TO_STRIDE maps common CWEs to legs (dominant leg first where a CWE spans several); unmapped / no-CWE findings fall back to a default (tampering + information-disclosure) so every finding carries >=1 leg and downstream reports have no coverage gaps. - Includes mappings for CWEs surfaced by real scans: 798 (hardcoded creds), 862 (missing authz), 259 (hardcoded password), 1391 (weak credential). Tests: tests/report/test_sarif_stride.py (14 cases — mapping, normalization of CWE-306/306/"cwe: 306" forms, default fallback, rule-tag emission).
* Add target list CLI option * Handle target list comments and encoding errors
…rt-error hints (usestrix#588) * feat: add bedrock + vertex optional extras with install docs and import hints (usestrix#574) Declare [project.optional-dependencies] with vertex (google-auth) and bedrock (boto3) extras so "strix-agent[vertex]" / "strix-agent[bedrock]" install the provider SDKs. Add an Installation section to the Bedrock docs mirroring Vertex, and a _provider_import_hint helper in warm_up_llm that surfaces a pip-install hint when a provider dependency is missing. Fixes usestrix#574, usestrix#573 * fix(providers): use pipx in install hint to match docs A pipx-installed strix can't add an extra with 'pip install' (wrong env); mirror the documented 'pipx install "strix-agent[...]"' command. Addresses Greptile review.
…estrix#721) StrixDockerSandboxClient.delete() best-effort-kills the sandbox container via containers.get(id).kill() before delegating to the SDK's delete(), suppressing docker NotFound/APIError. But when the docker daemon socket is already going away — the normal case on a host/CI teardown — containers.get() -> inspect_container raises requests' ConnectionError, which is a *sibling* of docker.errors.APIError under requests.RequestException, not a subclass. So it escapes the APIError-only suppress and surfaces a full traceback on teardown even though the kill is meant to be best-effort. Add RequestException to the suppress so the best-effort kill is genuinely best-effort regardless of daemon reachability. Test: tests/test_docker_client_delete.py — the kill raising ConnectionError (and NotFound/APIError) is swallowed and delete() still delegates; unrelated errors still propagate; no-container_id is a no-op. The ConnectionError case fails against the pre-fix APIError-only suppress.
…estrix#704) Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: Ahmed Allam <49919286+0xallam@users.noreply.github.com>
…renders - Increased UI update interval from 350ms to 500ms - Reduced dot animation frequency from 60ms to 250ms - Reduced splash animation frequency from 50ms to 100ms - Added content hash cache for rendered agent messages to avoid re-parsing markdown and re-running Pygments on every tick - Added guard to prevent redundant scroll_end callbacks from queuing during rapid updates Closes usestrix#581
Co-Authored-By: Ahmed Allam <ahmed39652003@gmail.com>
…n chain Co-Authored-By: Ahmed Allam <ahmed39652003@gmail.com>
Expand cloud and technology coverage for GCP IAM/storage and Auth0 tenant/API misconfiguration testing.
- Use curl instead of gsutil for anonymous GCS checks - Document userinfo requires bearer access token
…ix#730) feat(inputs): implement logic for required tool choice based on model test(inputs): add tests for force_required_tool_choice behavior test(runner): update tests to include force_required_tool_choice in settings
Contributor
|
Too many files changed for review. ( Bypass the limit by tagging |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pulling