Skip to content

Commit 7e283af

Browse files
authored
Release v0.3.0 (#17)
* docs: update binary detection wording * chore: release v0.3.0
1 parent 4d36188 commit 7e283af

2 files changed

Lines changed: 36 additions & 2 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,40 @@ All notable changes to ghostscan are documented here.
44

55
---
66

7+
## v0.3.0 - 2026-04-12
8+
9+
### New Features
10+
11+
- **JSON output** — added `--format json` for structured reports containing tool metadata, scan timing, summary counts, findings, skipped files, and recoverable errors. Fatal execution errors in JSON mode are emitted as structured reports and still exit with code `2`.
12+
- **Configurable excludes** — added repeatable `--exclude` globs and `--no-default-excludes`. Exclude matching uses normalized relative paths with `/` separators, supports `**` across path segments, and reports matched excludes in verbose human output.
13+
- **Emoji-aware Unicode handling** — valid emoji variation selectors, keycap sequences, regional indicator flags, skin-tone modifiers, and ZWJ emoji sequences are recognized to reduce false positives while preserving detection for fake or suspicious emoji-like content.
14+
- **Binary magic detection** — discovery now skips files with recognized binary signatures in addition to files containing NUL bytes.
15+
16+
### Changes
17+
18+
- **Decoder findings are internal by default** — decoder and dynamic-execution markers now act as correlation context instead of standalone findings; hidden payloads near those markers are reported as correlated findings.
19+
- **Font asset noise reduced** — private-use-only findings are suppressed in conservative font-like SVG and icon font contexts.
20+
- **Human reporting streamlined** — non-verbose output now stays summary-focused, verbose output retains detailed finding blocks, and runtime summaries include pruned excluded directories.
21+
- **Finding ordering stabilized** — sorting now prioritizes higher-signal Unicode rules before lower-signal rule IDs when location fields are equal.
22+
- **Payload density detection optimized** — payload window analysis now uses sliding state and fixed class aggregation to reduce allocations while preserving deterministic messages.
23+
- **Scan path simplified** — files that pass discovery are scanned through a trusted text path so binary checks are not repeated.
24+
25+
### Documentation
26+
27+
- README updated for JSON output, exclude flags, current CLI help text, decoder correlation behavior, font asset noise reduction, and Go `1.26.2` source-build requirements.
28+
29+
### Tests and Benchmarks
30+
31+
- Added coverage across CLI, app, detector, filesystem, finding, report, scan, and Unicode helper behavior.
32+
- Added benchmarks for CLI execution, discovery, payload detection, and file scanning paths.
33+
- Added fixtures for font private-use SVG content, benign emoji sequences, fake emoji content, and binary PDF detection.
34+
35+
### Maintenance
36+
37+
- Bumped Go from `1.26.1` to `1.26.2`.
38+
- Bumped `actions/setup-go` from `6.3.0` to `6.4.0`.
39+
- Updated runtime dependencies for binary type detection and existing transitive dependency versions.
40+
741
## v0.2.0 - 2026-03-24
842

943
### New Features

‎README.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ Fingerprint: /Users/johnsmith/ghostscan/testdata/invisible/single.txt:unicode/in
4747
- **Focused Unicode threat coverage**: Detects invisible characters, private-use Unicode, bidi controls, directional marks, mixed-script tokens, and combining marks.
4848
- **Payload-aware heuristics**: Flags long hidden sequences, dense suspicious regions, and explicit payload-plus-decoder correlations while keeping standalone decoder noise out of default results.
4949
- **Noise reduction for asset contexts**: Suppresses obvious private-use glyph mappings in font-like SVG assets so icon fonts do not dominate the report.
50-
- **Safe repository traversal**: Skips symlinks, NUL-containing files, oversize files, and common dependency or build directories.
50+
- **Safe repository traversal**: Skips symlinks, binary files, oversize files, and common dependency or build directories.
5151
- **CI-friendly behavior**: Uses deterministic ordering, human or JSON output, and exit codes `0`, `1`, and `2`.
5252

5353
## Installation
@@ -166,7 +166,7 @@ The current scanner behavior is intentionally narrow and real:
166166
- Recursively scans a file or directory path.
167167
- Parses flags only before the optional file or directory path.
168168
- Does not follow symlinks.
169-
- Treats files containing a NUL byte as binary and skips them.
169+
- Treats files containing a NUL byte or recognized binary magic signature as binary and skips them.
170170
- Uses a default max file size of `5 MiB`.
171171
- Matches excludes against the full normalized relative path with `/` separators.
172172
- Supports repeatable `--exclude` globs with `**` matching zero or more path segments and `filepath.Match` semantics for other segments.

0 commit comments

Comments
 (0)