Commit graph

762 commits

Author SHA1 Message Date
criss717
b7a4a29264 fix(i18n): resolve --config language, translate argparse built-ins and example titles 2026-08-24 23:05:53 +02:00
criss717
27cf85f849 feat(i18n): translate --workspace-file help, Examples header, and model warnings 2026-08-24 18:23:24 +02:00
criss717
fbf94387b9 add specs updates 2026-08-24 17:13:38 +02:00
criss717
f05a75d360 Merge remote-tracking branch 'upstream/main' into feat/i18n-spanish
# Conflicts:
#	strix/agents/prompt.py
#	strix/agents/prompts/system_prompt.jinja
#	strix/interface/main.py
2026-08-24 17:11:22 +02:00
devin-ai-integration[bot]
391d81bea7
feat(agents): evidence discipline, and coverage as a first-class artifact (#961)
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-08-24 03:34:09 -07:00
devin-ai-integration[bot]
1c499c5b2d
perf: bootstrap Caido concurrently with the scan start (#1143)
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-08-21 12:09:59 -07:00
devin-ai-integration[bot]
1ce43d1b94
perf: take heavy imports off the startup path and pre-warm them in the background (#1141)
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-08-20 20:24:08 -07:00
Alex Schapiro
2cc8167814 docs(skills): correct gRPC guidance, a .proto is not a spec target 2026-08-20 19:27:04 -04:00
Alex Schapiro
d6a3ca7e58 docs(skills): document --workspace-file for supporting files 2026-08-20 19:27:04 -04:00
Alex Schapiro
9099710cef docs(skills): fix nonexistent --mount flag, document real targeting flags, add application-security-testing skill
- Remove --mount from two skills: the flag does not exist in the CLI. Local
  paths are mounted writable when passed with -t.
- Document --target-list, --scope-mode, --diff-base, and OpenAPI/Postman
  targets, so agents stop putting spec URLs in --instruction prose.
- Add the application-security-testing skill as the entry point for
  whole-product AppSec requests, routing each asset to the right workflow.
- Drop contractions and Latin abbreviations across the skill prose.
2026-08-20 19:27:04 -04:00
Alex Schapiro
634cb98241 docs(skills): use current OWASP editions (Top 10:2025, API Top 10 2023) 2026-08-20 19:27:04 -04:00
Alex Schapiro
1b36343eea fix(skills): avoid unquoted colon in api-security-testing description 2026-08-20 19:27:04 -04:00
Alex Schapiro
b5ef93e744 feat(skills): add target-specific security testing skills (web app, API, OWASP Top 10, code review) 2026-08-20 19:27:04 -04:00
RAJVARDHAN PATIL
e152c4c7c0
fix(report): raise RuntimeError on non-object run.json (fixes #1109) (#1116) 2026-08-20 13:41:04 -07:00
OpenPay
fe758af4fc
fix(tui): use single space after ordered-list marker (#1043) 2026-08-20 13:40:12 -07:00
oyasumi
deb2057e20
fix(tui): preserve cost when state is truncated (#1086)
Co-authored-by: oyasumi <oyasumi@kantilabs.xyz>
2026-08-20 13:36:01 -07:00
Alex Schapiro
d6f2218756 Drop strict tool schemas on Claude routes 2026-08-20 23:12:23 +03:00
oyasumi
6f88b7d7d5 Require viewer session for run data 2026-08-19 15:25:57 -04:00
oyasumi
8d3693df8c Expose viewer host option 2026-08-19 15:25:57 -04:00
bearsyankees
9cd81e5c76 Add semantic browser and Electron security skills 2026-08-19 12:05:47 -04:00
bearsyankees
e8272c6a21 Add HTTP differential testing tools 2026-08-19 12:04:43 -04:00
bearsyankees
aa5867f5df Add ecosystem supply-chain security skills 2026-08-19 12:03:45 -04:00
bearsyankees
7b8f9cb160 Add argument injection security skill 2026-08-19 12:02:45 -04:00
bearsyankees
2d944a9bcc Add Azure and Entra security skill 2026-08-19 12:01:21 -04:00
alex s
0478a69ab0
feat(skills): cover OWASP LLM Top 10 2026 (#1115) 2026-08-18 18:40:27 -04:00
alex s
8ede419dcc
handle resume tokens gracefully (#1097)
* Fix telemetry deltas for resumed runs

* Fix resumed telemetry duration
2026-08-17 16:55:27 -04:00
criss717
8e7973c73a test(i18n): clean up canonical config test
- Simplify test to avoid import inside function
- Remove unused lambda arguments
- All 35 tests passing, ruff clean
2026-08-17 17:59:12 +02:00
criss717
8b4ed4f081 merge: resolve conflicts with upstream/main
- writer.py: Keep i18n translations + add contextual CVSS fields
- cli_args.py: Keep i18n + add --workspace-file argument
- cli.py: Keep i18n translations + add workspace_files support
- All 35 tests passing
2026-08-17 17:49:11 +02:00
Ahmed Allam
a46a60cf6a feat(reporting): require contextual CVSS and usage evidence on dependency reports 2026-08-17 14:35:21 +03:00
Ahmed Allam
918442dbc8 cli: render contextual CVSS vector, advisory score, and reasoning for dependency findings 2026-08-17 13:03:41 +03:00
Ahmed Allam
e442db9c93 Contextual CVSS as a full 8-metric breakdown, computed like a normal finding 2026-08-17 13:03:41 +03:00
Ahmed Allam
9c0d30a0d0 reporting: require the source-to-sink trace in reachability evidence, not just CVSS reasoning 2026-08-17 13:03:41 +03:00
Ahmed Allam
55e6e66030 reporting: surface contextual CVSS in the markdown report; require reasoning only for surviving metrics 2026-08-17 13:03:41 +03:00
Ahmed Allam
99e2d5d826 reporting: drop per-metric contextual CVSS reasoning, keep the summary 2026-08-17 13:03:41 +03:00
Ahmed Allam
310f310e28 feat(reporting): contextual CVSS environmental metrics on dependency reports 2026-08-17 13:03:41 +03:00
yoni-at-strix
8551339130
feat: place caller-provided files into the sandbox workspace (extra_files, --workspace-file) (#1085)
* add extra-files plumbing so orchestrators can drop single files into the sandbox workspace

* reject extra-file paths that collide with a local source tree

* add --workspace-file so CLI users can place files in the sandbox workspace

* reject repeated and control-character workspace paths

* revalidate persisted workspace files when resuming a run

* drop the workspace-file size limit
2026-08-14 16:43:08 -04:00
Alex Schapiro
8ca0c4a9b8 Fix LiteLLM cost model resolution 2026-08-12 17:26:00 +03:00
criss717
e4a0d42ecc test(i18n): add test for canonical config format
- Add test_canonical_config_format to verify {env: {STRIX_LANGUAGE: es}} format
- Tests now: 35/35 passing
2026-08-10 21:08:26 +02:00
criss717
446de76816 feat(cli): translate --help text to Spanish
- Replace all hardcoded argparse help strings with t() calls
- Help text now displays in Spanish when --language es is used
- Works because _pre_resolve_language() runs before argparse
- Description, all argument help, epilog examples remain English (code examples)
2026-08-10 21:05:23 +02:00
criss717
b76a5b7b88 fix(i18n): resolve config format and argparse language pre-scan
- Fix config file reading to use canonical format {env: {STRIX_LANGUAGE: es}}
- Pre-scan sys.argv for --language/-l before argparse runs
- This allows --help to display translated text when language is set
- Addresses review feedback from greptile-apps[bot]
2026-08-10 20:58:39 +02:00
criss717
6bb9dda3ea docs(spec): update spec with Phase 2 report keys
- Add 18 report translation keys to spec
- Update locale key structure examples
- Total keys: 83 (65 CLI + 18 Report)
2026-08-10 20:30:57 +02:00
Ahmed Allam
7cc9fa9faa chore: release v1.5.3 2026-08-10 21:28:52 +03:00
devin-ai-integration[bot]
174c16fa26
fix(llm): send OpenRouter app attribution on the request itself (#1045) 2026-08-10 11:24:02 -07:00
criss717
fc554a8973 feat(report): translate report headings and metadata labels
- Add 18 report translation keys to en.json and es.json
- Translate section headings: Description, Evidence, Impact, etc.
- Translate metadata labels: Severity, Target, Package, etc.
- Translate executive report title and timestamp label
- All report sections now respect language setting
2026-08-10 19:50:44 +02:00
criss717
06bf0cf844 feat(cli): translate progress and status messages to i18n
- Replace hardcoded strings in cli.py with t() calls
- Add translation keys: test_initiated, test_in_progress, test_summary
- Add translation keys: vulnerabilities_realtime, starting_up, error_during_test
- All CLI progress panels now respect language setting
2026-08-10 19:18:17 +02:00
criss717
ee7013b219 change gitignore 2026-08-10 19:08:57 +02:00
criss717
2ed1a69672 test(i18n): add comprehensive i18n tests
- 34 tests covering all i18n functionality
- Test set_language(), get_language(), _detect_language()
- Test t() translation, fallback, interpolation
- Test get_language_directive() for English and Spanish
- Test locale key consistency between en.json and es.json
- Test Settings.language field with env var
2026-08-10 17:56:53 +02:00
criss717
0fd997613b feat(cli): integrate t() into main UI messages
- Replace hardcoded strings with t() calls in display_completion_message()
- Translate completion title, session ended, target label, output/view/resume
- Translate error panels: LLM connection failed, model not available
- Translate interactive setup unavailable, scan preparation failed
2026-08-10 17:56:25 +02:00
criss717
12d76f2527 feat(agents): inject language directive into system prompt
- Pass language_directive to Jinja template in render_system_prompt()
- Add {% if language_directive %} block to system_prompt.jinja
- Directive instructs LLM to write findings in target language
- Preserves CVE, CWE, CVSS, code, commands unchanged
2026-08-10 17:56:11 +02:00
criss717
a1f109c748 feat(cli): add language configuration
- Add language field to Settings with STRIX_LANGUAGE env var alias
- Add --language/-l CLI flag to argparse
- Call set_language() after argument parsing
- Language persists to ~/.strix/cli-config.json
2026-08-10 17:55:58 +02:00