fix(deps): pin bbot to v3.0.2 tag instead of dev branch - #165
Merged
Merged
Conversation
pyproject.toml pinned bbot to rev = "dev", so uv.lock resolved whatever dev commit was last locked (83a809a, reporting 3.0.0). Stable shipped an unpinned moving target and builds were not reproducible. Pin the tag so intent lives in pyproject.toml and the resolved commit lives in uv.lock. Relocked: bbot 3.0.0 (83a809a) to 3.0.2 (a6fb827). Declare omegaconf explicitly. bbot_server/applets/base.py imports OmegaConf but never listed it; the dependency arrived transitively from bbot, which dropped it in 3.0.2. The import was always under-declared, the bump only exposed it. Transitive changes from the bbot bump: blasthttp 0.10.0 and zstandard 0.25.0 added, cloudcheck 9.3.0 to 11.1.0, asndb 1.0.4 to 1.1.0, yara-python 4.5.2 to 4.5.4. Closes #164
singlerider
force-pushed
the
pin-bbot-v3.0.2
branch
from
August 24, 2026 15:00
75cc482 to
4a5c7bf
Compare
en0f
approved these changes
Aug 24, 2026
gen_scan_data poked speculate.portscanner_enabled and set emit_open_ports. Both names existed only on the old dev commit the lock was pinned to (83a809a); every 3.0.x tag renamed them to portscanner (the module or None) and _always_emit_open_ports. Unpinning surfaced the drift as AttributeError at fixture setup, erroring 50 tests.
Three separate breakages surfaced by the v3.0.2 pin, all landed in bbot commit 5ce0e18b and its neighbors. Output module rename. bbot renamed output/http.py to output/webhook.py and added a new active scan module named http (blasthttp web visiting) whose config schema is threads/in_scope_only/max_response_size, with no url or headers. The agent preset still requested output_modules=["http"] with modules.http.url and .headers, so every server-driven scan died in preset validation with 'Could not find config option "modules.http.url"'. Point the agent preset and the README example at webhook, which carries the url/headers schema the server needs. Event minimization. bbot now lazy-allocates dns_children and clears it in _minimize() once an event's module consumers finish. gen_scan_data collected events off the live async_start stream, so by assertion time every event had an empty dns_children, zeroing dns_links and cloud_providers in the stats applet. Read the events back from the scan's output.json instead, which is what a real deployment ingests and retains the full payload. Ingest progress assertions. The event counts per scan shifted with the dnsresolve child-emission rework, so hardcoded "Ingested 30 events" milestones no longer matched. Derive the expected milestones from the actual event count.
The events applet asserted 30 <= len(events) <= 40 after scan 1 and 60 <= len(events) <= 80 after scan 2, with a TODO asking why the count drifts. bbot 3.0.2's dnsresolve child-emission rework moved scan 1 to 29 events and scan 2 to 25, so the lower bound tripped. The fixture already carries the exact counts. Assert against len(scan1_events) and len(scan1_events) + len(scan2_events) instead of a hand-tuned window, which removes the drift and the TODO along with it.
liquidsec
approved these changes
Aug 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
pyproject.tomlpinned bbot torev = "dev", souv.lockresolved whatever dev commit was last locked (blacklanternsecurity/bbot@83a809a, reporting 3.0.0). Builds were not reproducible.Pin the tag so intent lives in
pyproject.tomland the resolved commit lives inuv.lock.Verified with
uv lockthenuv sync --frozen --dry-run(exit 0).Closes #164