You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CHANGELOG.md
+34Lines changed: 34 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,6 +4,40 @@ All notable changes to ghostscan are documented here.
4
4
5
5
---
6
6
7
+
## v0.3.0 - 2026-04-12
8
+
9
+
### New Features
10
+
11
+
-**JSON output** — added `--format json` for structured reports containing tool metadata, scan timing, summary counts, findings, skipped files, and recoverable errors. Fatal execution errors in JSON mode are emitted as structured reports and still exit with code `2`.
12
+
-**Configurable excludes** — added repeatable `--exclude` globs and `--no-default-excludes`. Exclude matching uses normalized relative paths with `/` separators, supports `**` across path segments, and reports matched excludes in verbose human output.
13
+
-**Emoji-aware Unicode handling** — valid emoji variation selectors, keycap sequences, regional indicator flags, skin-tone modifiers, and ZWJ emoji sequences are recognized to reduce false positives while preserving detection for fake or suspicious emoji-like content.
14
+
-**Binary magic detection** — discovery now skips files with recognized binary signatures in addition to files containing NUL bytes.
15
+
16
+
### Changes
17
+
18
+
-**Decoder findings are internal by default** — decoder and dynamic-execution markers now act as correlation context instead of standalone findings; hidden payloads near those markers are reported as correlated findings.
19
+
-**Font asset noise reduced** — private-use-only findings are suppressed in conservative font-like SVG and icon font contexts.
20
+
-**Human reporting streamlined** — non-verbose output now stays summary-focused, verbose output retains detailed finding blocks, and runtime summaries include pruned excluded directories.
21
+
-**Finding ordering stabilized** — sorting now prioritizes higher-signal Unicode rules before lower-signal rule IDs when location fields are equal.
22
+
-**Payload density detection optimized** — payload window analysis now uses sliding state and fixed class aggregation to reduce allocations while preserving deterministic messages.
23
+
-**Scan path simplified** — files that pass discovery are scanned through a trusted text path so binary checks are not repeated.
24
+
25
+
### Documentation
26
+
27
+
- README updated for JSON output, exclude flags, current CLI help text, decoder correlation behavior, font asset noise reduction, and Go `1.26.2` source-build requirements.
28
+
29
+
### Tests and Benchmarks
30
+
31
+
- Added coverage across CLI, app, detector, filesystem, finding, report, scan, and Unicode helper behavior.
32
+
- Added benchmarks for CLI execution, discovery, payload detection, and file scanning paths.
33
+
- Added fixtures for font private-use SVG content, benign emoji sequences, fake emoji content, and binary PDF detection.
34
+
35
+
### Maintenance
36
+
37
+
- Bumped Go from `1.26.1` to `1.26.2`.
38
+
- Bumped `actions/setup-go` from `6.3.0` to `6.4.0`.
39
+
- Updated runtime dependencies for binary type detection and existing transitive dependency versions.
-**Payload-aware heuristics**: Flags long hidden sequences, dense suspicious regions, and explicit payload-plus-decoder correlations while keeping standalone decoder noise out of default results.
49
49
-**Noise reduction for asset contexts**: Suppresses obvious private-use glyph mappings in font-like SVG assets so icon fonts do not dominate the report.
50
-
-**Safe repository traversal**: Skips symlinks, NUL-containing files, oversize files, and common dependency or build directories.
50
+
-**Safe repository traversal**: Skips symlinks, binary files, oversize files, and common dependency or build directories.
51
51
-**CI-friendly behavior**: Uses deterministic ordering, human or JSON output, and exit codes `0`, `1`, and `2`.
52
52
53
53
## Installation
@@ -166,7 +166,7 @@ The current scanner behavior is intentionally narrow and real:
166
166
- Recursively scans a file or directory path.
167
167
- Parses flags only before the optional file or directory path.
168
168
- Does not follow symlinks.
169
-
- Treats files containing a NUL byte as binary and skips them.
169
+
- Treats files containing a NUL byte or recognized binary magic signature as binary and skips them.
170
170
- Uses a default max file size of `5 MiB`.
171
171
- Matches excludes against the full normalized relative path with `/` separators.
172
172
- Supports repeatable `--exclude` globs with `**` matching zero or more path segments and `filepath.Match` semantics for other segments.
0 commit comments