criss717
f05a75d360
Merge remote-tracking branch 'upstream/main' into feat/i18n-spanish
...
# Conflicts:
# strix/agents/prompt.py
# strix/agents/prompts/system_prompt.jinja
# strix/interface/main.py
2026-08-24 17:11:22 +02:00
devin-ai-integration[bot]
391d81bea7
feat(agents): evidence discipline, and coverage as a first-class artifact ( #961 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-08-24 03:34:09 -07:00
devin-ai-integration[bot]
1c499c5b2d
perf: bootstrap Caido concurrently with the scan start ( #1143 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-08-21 12:09:59 -07:00
devin-ai-integration[bot]
1ce43d1b94
perf: take heavy imports off the startup path and pre-warm them in the background ( #1141 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-08-20 20:24:08 -07:00
Alex Schapiro
2cc8167814
docs(skills): correct gRPC guidance, a .proto is not a spec target
2026-08-20 19:27:04 -04:00
Alex Schapiro
d6a3ca7e58
docs(skills): document --workspace-file for supporting files
2026-08-20 19:27:04 -04:00
Alex Schapiro
9099710cef
docs(skills): fix nonexistent --mount flag, document real targeting flags, add application-security-testing skill
...
- Remove --mount from two skills: the flag does not exist in the CLI. Local
paths are mounted writable when passed with -t.
- Document --target-list, --scope-mode, --diff-base, and OpenAPI/Postman
targets, so agents stop putting spec URLs in --instruction prose.
- Add the application-security-testing skill as the entry point for
whole-product AppSec requests, routing each asset to the right workflow.
- Drop contractions and Latin abbreviations across the skill prose.
2026-08-20 19:27:04 -04:00
Alex Schapiro
634cb98241
docs(skills): use current OWASP editions (Top 10:2025, API Top 10 2023)
2026-08-20 19:27:04 -04:00
Alex Schapiro
1b36343eea
fix(skills): avoid unquoted colon in api-security-testing description
2026-08-20 19:27:04 -04:00
Alex Schapiro
b5ef93e744
feat(skills): add target-specific security testing skills (web app, API, OWASP Top 10, code review)
2026-08-20 19:27:04 -04:00
RAJVARDHAN PATIL
e152c4c7c0
fix(report): raise RuntimeError on non-object run.json ( fixes #1109 ) ( #1116 )
2026-08-20 13:41:04 -07:00
OpenPay
fe758af4fc
fix(tui): use single space after ordered-list marker ( #1043 )
2026-08-20 13:40:12 -07:00
oyasumi
deb2057e20
fix(tui): preserve cost when state is truncated ( #1086 )
...
Co-authored-by: oyasumi <oyasumi@kantilabs.xyz>
2026-08-20 13:36:01 -07:00
Alex Schapiro
d6f2218756
Drop strict tool schemas on Claude routes
2026-08-20 23:12:23 +03:00
oyasumi
6f88b7d7d5
Require viewer session for run data
2026-08-19 15:25:57 -04:00
oyasumi
8d3693df8c
Expose viewer host option
2026-08-19 15:25:57 -04:00
bearsyankees
9cd81e5c76
Add semantic browser and Electron security skills
2026-08-19 12:05:47 -04:00
bearsyankees
e8272c6a21
Add HTTP differential testing tools
2026-08-19 12:04:43 -04:00
bearsyankees
aa5867f5df
Add ecosystem supply-chain security skills
2026-08-19 12:03:45 -04:00
bearsyankees
7b8f9cb160
Add argument injection security skill
2026-08-19 12:02:45 -04:00
bearsyankees
2d944a9bcc
Add Azure and Entra security skill
2026-08-19 12:01:21 -04:00
alex s
0478a69ab0
feat(skills): cover OWASP LLM Top 10 2026 ( #1115 )
2026-08-18 18:40:27 -04:00
alex s
8ede419dcc
handle resume tokens gracefully ( #1097 )
...
* Fix telemetry deltas for resumed runs
* Fix resumed telemetry duration
2026-08-17 16:55:27 -04:00
criss717
8e7973c73a
test(i18n): clean up canonical config test
...
- Simplify test to avoid import inside function
- Remove unused lambda arguments
- All 35 tests passing, ruff clean
2026-08-17 17:59:12 +02:00
criss717
8b4ed4f081
merge: resolve conflicts with upstream/main
...
- writer.py: Keep i18n translations + add contextual CVSS fields
- cli_args.py: Keep i18n + add --workspace-file argument
- cli.py: Keep i18n translations + add workspace_files support
- All 35 tests passing
2026-08-17 17:49:11 +02:00
Ahmed Allam
a46a60cf6a
feat(reporting): require contextual CVSS and usage evidence on dependency reports
2026-08-17 14:35:21 +03:00
Ahmed Allam
918442dbc8
cli: render contextual CVSS vector, advisory score, and reasoning for dependency findings
2026-08-17 13:03:41 +03:00
Ahmed Allam
e442db9c93
Contextual CVSS as a full 8-metric breakdown, computed like a normal finding
2026-08-17 13:03:41 +03:00
Ahmed Allam
9c0d30a0d0
reporting: require the source-to-sink trace in reachability evidence, not just CVSS reasoning
2026-08-17 13:03:41 +03:00
Ahmed Allam
55e6e66030
reporting: surface contextual CVSS in the markdown report; require reasoning only for surviving metrics
2026-08-17 13:03:41 +03:00
Ahmed Allam
99e2d5d826
reporting: drop per-metric contextual CVSS reasoning, keep the summary
2026-08-17 13:03:41 +03:00
Ahmed Allam
310f310e28
feat(reporting): contextual CVSS environmental metrics on dependency reports
2026-08-17 13:03:41 +03:00
yoni-at-strix
8551339130
feat: place caller-provided files into the sandbox workspace (extra_files, --workspace-file) ( #1085 )
...
* add extra-files plumbing so orchestrators can drop single files into the sandbox workspace
* reject extra-file paths that collide with a local source tree
* add --workspace-file so CLI users can place files in the sandbox workspace
* reject repeated and control-character workspace paths
* revalidate persisted workspace files when resuming a run
* drop the workspace-file size limit
2026-08-14 16:43:08 -04:00
Alex Schapiro
8ca0c4a9b8
Fix LiteLLM cost model resolution
2026-08-12 17:26:00 +03:00
criss717
e4a0d42ecc
test(i18n): add test for canonical config format
...
- Add test_canonical_config_format to verify {env: {STRIX_LANGUAGE: es}} format
- Tests now: 35/35 passing
2026-08-10 21:08:26 +02:00
criss717
446de76816
feat(cli): translate --help text to Spanish
...
- Replace all hardcoded argparse help strings with t() calls
- Help text now displays in Spanish when --language es is used
- Works because _pre_resolve_language() runs before argparse
- Description, all argument help, epilog examples remain English (code examples)
2026-08-10 21:05:23 +02:00
criss717
b76a5b7b88
fix(i18n): resolve config format and argparse language pre-scan
...
- Fix config file reading to use canonical format {env: {STRIX_LANGUAGE: es}}
- Pre-scan sys.argv for --language/-l before argparse runs
- This allows --help to display translated text when language is set
- Addresses review feedback from greptile-apps[bot]
2026-08-10 20:58:39 +02:00
criss717
6bb9dda3ea
docs(spec): update spec with Phase 2 report keys
...
- Add 18 report translation keys to spec
- Update locale key structure examples
- Total keys: 83 (65 CLI + 18 Report)
2026-08-10 20:30:57 +02:00
Ahmed Allam
7cc9fa9faa
chore: release v1.5.3
2026-08-10 21:28:52 +03:00
devin-ai-integration[bot]
174c16fa26
fix(llm): send OpenRouter app attribution on the request itself ( #1045 )
2026-08-10 11:24:02 -07:00
criss717
fc554a8973
feat(report): translate report headings and metadata labels
...
- Add 18 report translation keys to en.json and es.json
- Translate section headings: Description, Evidence, Impact, etc.
- Translate metadata labels: Severity, Target, Package, etc.
- Translate executive report title and timestamp label
- All report sections now respect language setting
2026-08-10 19:50:44 +02:00
criss717
06bf0cf844
feat(cli): translate progress and status messages to i18n
...
- Replace hardcoded strings in cli.py with t() calls
- Add translation keys: test_initiated, test_in_progress, test_summary
- Add translation keys: vulnerabilities_realtime, starting_up, error_during_test
- All CLI progress panels now respect language setting
2026-08-10 19:18:17 +02:00
criss717
ee7013b219
change gitignore
2026-08-10 19:08:57 +02:00
criss717
2ed1a69672
test(i18n): add comprehensive i18n tests
...
- 34 tests covering all i18n functionality
- Test set_language(), get_language(), _detect_language()
- Test t() translation, fallback, interpolation
- Test get_language_directive() for English and Spanish
- Test locale key consistency between en.json and es.json
- Test Settings.language field with env var
2026-08-10 17:56:53 +02:00
criss717
0fd997613b
feat(cli): integrate t() into main UI messages
...
- Replace hardcoded strings with t() calls in display_completion_message()
- Translate completion title, session ended, target label, output/view/resume
- Translate error panels: LLM connection failed, model not available
- Translate interactive setup unavailable, scan preparation failed
2026-08-10 17:56:25 +02:00
criss717
12d76f2527
feat(agents): inject language directive into system prompt
...
- Pass language_directive to Jinja template in render_system_prompt()
- Add {% if language_directive %} block to system_prompt.jinja
- Directive instructs LLM to write findings in target language
- Preserves CVE, CWE, CVSS, code, commands unchanged
2026-08-10 17:56:11 +02:00
criss717
a1f109c748
feat(cli): add language configuration
...
- Add language field to Settings with STRIX_LANGUAGE env var alias
- Add --language/-l CLI flag to argparse
- Call set_language() after argument parsing
- Language persists to ~/.strix/cli-config.json
2026-08-10 17:55:58 +02:00
criss717
4f964d7472
feat(i18n): add localization infrastructure
...
- Add strix/i18n.py module with t(), set_language(), get_language()
- Add get_language_directive() for agent prompt injection
- Add strix/locales/en.json with 60+ English translation keys
- Add strix/locales/es.json with 60+ Spanish translation keys
- Support language resolution chain: --language > STRIX_LANGUAGE > config > LANG > en
- Thread-safe locale loading with caching
- Graceful fallback: missing key -> English -> key itself
2026-08-10 17:55:27 +02:00
Ahmed Allam
94a2586aaa
fix(container): write the browser profile as root
2026-08-10 10:08:17 +03:00
Ahmed Allam
372e27fa17
chore(container): drop explanatory comment
2026-08-10 09:54:49 +03:00