Skip to content

fix(deps): pin bbot to v3.0.2 tag instead of dev branch - #165

Merged
singlerider merged 4 commits into
stablefrom
pin-bbot-v3.0.2
Aug 24, 2026
Merged

singlerider merged 4 commits into
stablefrom
pin-bbot-v3.0.2

Conversation

@singlerider

@singlerider singlerider commented Aug 24, 2026 •

Copy link
Copy Markdown
Collaborator

pyproject.toml pinned bbot to rev = "dev", so uv.lock resolved whatever dev commit was last locked (blacklanternsecurity/bbot@83a809a, reporting 3.0.0). Builds were not reproducible.

Pin the tag so intent lives in pyproject.toml and the resolved commit lives in uv.lock.

Verified with uv lock then uv sync --frozen --dry-run (exit 0).

Closes #164

pyproject.toml pinned bbot to rev = "dev", so uv.lock resolved
whatever dev commit was last locked (83a809a, reporting 3.0.0).
Stable shipped an unpinned moving target and builds were not
reproducible.

Pin the tag so intent lives in pyproject.toml and the resolved
commit lives in uv.lock. Relocked: bbot 3.0.0 (83a809a) to
3.0.2 (a6fb827).

Declare omegaconf explicitly. bbot_server/applets/base.py imports
OmegaConf but never listed it; the dependency arrived transitively
from bbot, which dropped it in 3.0.2. The import was always
under-declared, the bump only exposed it.

Transitive changes from the bbot bump: blasthttp 0.10.0 and
zstandard 0.25.0 added, cloudcheck 9.3.0 to 11.1.0, asndb 1.0.4
to 1.1.0, yara-python 4.5.2 to 4.5.4.

Closes #164
gen_scan_data poked speculate.portscanner_enabled and set
emit_open_ports. Both names existed only on the old dev commit the
lock was pinned to (83a809a); every 3.0.x tag renamed them to
portscanner (the module or None) and _always_emit_open_ports.

Unpinning surfaced the drift as AttributeError at fixture setup,
erroring 50 tests.
Three separate breakages surfaced by the v3.0.2 pin, all landed in
bbot commit 5ce0e18b and its neighbors.

Output module rename. bbot renamed output/http.py to output/webhook.py
and added a new active scan module named http (blasthttp web visiting)
whose config schema is threads/in_scope_only/max_response_size, with no
url or headers. The agent preset still requested output_modules=["http"]
with modules.http.url and .headers, so every server-driven scan died in
preset validation with 'Could not find config option "modules.http.url"'.
Point the agent preset and the README example at webhook, which carries
the url/headers schema the server needs.

Event minimization. bbot now lazy-allocates dns_children and clears it in
_minimize() once an event's module consumers finish. gen_scan_data
collected events off the live async_start stream, so by assertion time
every event had an empty dns_children, zeroing dns_links and
cloud_providers in the stats applet. Read the events back from the
scan's output.json instead, which is what a real deployment ingests and
retains the full payload.

Ingest progress assertions. The event counts per scan shifted with the
dnsresolve child-emission rework, so hardcoded "Ingested 30 events"
milestones no longer matched. Derive the expected milestones from the
actual event count.
The events applet asserted 30 <= len(events) <= 40 after scan 1 and
60 <= len(events) <= 80 after scan 2, with a TODO asking why the count
drifts. bbot 3.0.2's dnsresolve child-emission rework moved scan 1 to
29 events and scan 2 to 25, so the lower bound tripped.

The fixture already carries the exact counts. Assert against
len(scan1_events) and len(scan1_events) + len(scan2_events) instead of
a hand-tuned window, which removes the drift and the TODO along with it.
@singlerider
singlerider merged commit c4bf127 into stable Aug 24, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pin bbot dependency to a release tag instead of dev

3 participants