Skip to content

V2.0 - #9

Merged
giveen merged 5 commits into
mainfrom
v2.0
May 5, 2026
Merged

giveen merged 5 commits into
mainfrom
v2.0

Conversation

@giveen

@giveen giveen commented May 5, 2026

Copy link
Copy Markdown
Owner

Description of Changes

Contributor License Agreement (CLA)

To accept your code, we legally need you to agree to our CLA so we can maintain the project's Business Source License (BSL) and future open-source transitions.

  • [ X] By checking this box, I confirm that I have read and agree to the terms of the CLA.md in this repository. (To check the box, put an x between the brackets like this: [x])

giveen added 3 commits May 4, 2026 11:28
- gui: add Rescan button (hidden until report written, wired to rootAgent)
- gui: surface rescan errors in chat as '✗ Rescan failed: <reason>'
- gui: remove HighlightNode exported no-op (no live callers)
- gui: fyne.LogError for allowlist persistence failures (was _ =)
- mcp: nil guard cmd.Process before Kill in context-cancel goroutine
- mcp: log DiscoverBackend probe failures to stderr instead of silently discarding
- cmd/late-sast: delegate cleanupContainer to CleanupScanEnvironmentTool
- cmd/run-tools: fix broken build (AssessDisclosureContextTool{} not NewAssessDisclosureContextTool())
- session/ttystyle: simplify FormatSessionDisplay, remove intermediate var and redundant rune-len check
- tool/subagent: remove stale TODO comment for unimplemented reviewer/committer types
- tool/docs_lookup: clarify docs_* descriptions (named library → ProContext registry)
- tool/context_index: clarify ctx_* descriptions (arbitrary content → in-session BM25 index)
- changelog: add v2.0.1 release notes
Copilot AI review requested due to automatic review settings May 5, 2026 20:06

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR is a broad v2.0 refactor that removes the old TUI/project-map flow, expands the SAST toolchain with deterministic setup/scan/cleanup helpers, adds shared tool-result caching/runtime UI state, and updates prompts/docs to drive the new workflow.

Changes:

  • Adds new scan workflow tools for container setup, readiness probing, exploit replay, secret scanning, and cleanup.
  • Reworks orchestration/agent behavior with shared tool caching, tool runtime events, and stricter subagent middleware.
  • Removes the old TUI/project-map code and updates GUI, prompts, docs, and versioning for the new SAST flow.

Reviewed changes

Copilot reviewed 74 out of 76 changed files in this pull request and generated 7 comments.

Show a summary per file
File Description
Makefile Bumps default release version to v2.0.0.
internal/tui/theme.go Deletes old TUI markdown theme implementation.
internal/tui/styles.go Deletes old TUI style definitions.
internal/tui/state.go Deletes old TUI state/model definitions.
internal/tui/model.go Deletes old TUI model construction/renderer code.
internal/tui/keys.go Deletes old TUI keymap definitions.
internal/tui/interactions.go Deletes old TUI prompt/confirmation middleware.
internal/tui/interactions_test.go Removes tests for deleted TUI middleware.
internal/tool/wait_for_target_ready.go Adds deterministic container readiness probing tool.
internal/tool/wait_for_target_ready_test.go Adds readiness tool tests.
internal/tool/utils.go Adds architecture JSON parsing helper.
internal/tool/subagent.go Adds retry/backoff/telemetry logic for subagents.
internal/tool/setup_container.go Adds container setup/install helper tool.
internal/tool/setup_container_test.go Adds setup_container tests.
internal/tool/sast_tools_test.go Expands SpawnSubagentTool retry coverage.
internal/tool/run_secrets_scanner.go Adds TruffleHog-backed secrets scanning tool.
internal/tool/run_secrets_scanner_test.go Adds secrets scanner tests.
internal/tool/run_exploit_replay.go Adds deterministic exploit replay tool.
internal/tool/run_exploit_replay_test.go Adds exploit replay tests.
internal/tool/resolve_install_strategy_test.go Adds install-strategy test coverage.
internal/tool/docs_lookup.go Clarifies docs tool descriptions and intended usage.
internal/tool/doc.go Adds package-level tool organization docs.
internal/tool/context_index.go Clarifies ctx_* tool descriptions and usage boundaries.
internal/tool/cleanup_scan_environment.go Adds deterministic scan cleanup tool.
internal/tool/cleanup_scan_environment_test.go Adds cleanup tool tests.
internal/tool/bootstrap_scan_toolchain_test.go Adds bootstrap toolchain tests.
internal/tool/assess_disclosure_context_test.go Adds disclosure-context tests.
internal/session/ttystyle.go Minor cleanup/simplification of session display formatting.
internal/session/tool_call_repair_test.go Adds malformed tool-call repair tests.
internal/session/session.go Adds malformed JSON tool-call repair logic.
internal/orchestrator/highlight_middleware.go Removes project-map highlighting middleware.
internal/orchestrator/base.go Adds shared cache + tool runtime event plumbing.
internal/mcp/client.go Minor MCP transport cleanup/safety logging changes.
internal/gui/sast_picker.go Makes setup callback return errors and recover to picker UI.
internal/gui/project_map.go Removes project map GUI panel.
internal/gui/markdown.go Adds HTML stripping in markdown rendering.
internal/gui/events.go Adds live tool runtime status/timer handling; removes old project-map/snapshot events.
internal/gui/confirm.go Logs failures when persisting allow decisions.
internal/gui/app.go Simplifies main GUI layout, removes mission/project-map UI, adds rescan button support.
internal/executor/toolcache.go Adds shared TTL-based tool result cache + tool timeouts.
internal/executor/executor.go Wires cache/tool runtime callbacks into tool execution loop.
internal/executor/executor_test.go Updates executor test signature.
internal/common/version.go Bumps embedded version string to v2.0.0.
internal/common/interfaces.go Replaces old GUI events with ToolRuntimeEvent and expands architecture data.
internal/client/client.go Adds stderr logging for backend discovery probe failures.
internal/assets/sast/references/xss.md Adds XSS false-positive guidance for email templates.
internal/assets/prompts/instruction-sast.md Rewrites SAST flow to use new deterministic tools.
internal/assets/prompts/instruction-sast-setup.md Rewrites setup prompt around new install/launch/readiness tools.
internal/assets/prompts/instruction-sast-scanner.md Rewrites scanner prompt to use structured tools.
internal/assets/prompts/instruction-sast-scanner-binary.md Rewrites binary scanner prompt to use structured tools.
internal/assets/prompts/instruction-sast-retest.md Rewrites retest prompt around disclosure/cleanup tools.
internal/assets/prompts/instruction-sast-auditor.md Adds output-format/context guidance for auditor agent.
internal/agent/agent.go Adds new subagent middleware/enforcement helpers and middleware assembly changes.
internal/agent/agent_test.go Adds coverage for new middleware and nil-parent handling.
go.sum Updates dependency lockfile for removed/downgraded deps.
go.mod Drops old TUI deps from direct requires and adjusts indirect versions.
cmd/run-tools/main.go Adds a hardcoded helper binary to run disclosure/cleanup/report tools manually.
.vscode/settings.json Adds Linux/amd64/gopls build environment settings.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread internal/tool/run_exploit_replay.go
Comment thread internal/tool/run_secrets_scanner.go
Comment thread internal/tool/run_secrets_scanner.go Outdated
Comment thread internal/agent/agent.go Outdated
Comment thread internal/tool/wait_for_target_ready.go
Comment thread internal/tool/cleanup_scan_environment.go Outdated
Comment thread internal/executor/toolcache.go
@giveen

giveen commented May 5, 2026

Copy link
Copy Markdown
Owner Author

Addressed all Copilot reviewer findings in commit b54e212.

Implemented fixes:

  • Cleared stale lastErr after successful retry in run_exploit_replay to prevent false unreachable verdicts.
  • Applied timeout_seconds via per-scan context.WithTimeout in run_secrets_scanner.
  • Shell-quoted scan_path in run_secrets_scanner command construction to prevent command injection via metacharacters.
  • Wired scannerSecretsFirstMiddleware into scanner/binary-scanner subagent middleware chain.
  • Made wait_for_target_ready endpoint selection deterministic by sorting exposed ports before selection.
  • Fixed cleanup_scan_environment workdir cleanup for arbitrary host paths by mounting the workdir parent and deleting absolute target path.
  • Added cache invalidation after workspace-mutating tools (write_file, compose_patch, implementations, bash) to avoid stale read-side cache results.

Validation:

  • go test ./internal/tool/... ./internal/agent/... ./internal/executor/...
  • go build ./...

All pass.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 75 out of 77 changed files in this pull request and generated 5 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread internal/session/session.go
Comment thread internal/tool/setup_container.go Outdated
Comment thread internal/tool/run_exploit_replay.go
Comment thread internal/executor/toolcache.go Outdated
Comment thread cmd/run-tools/main.go Outdated
@giveen

giveen commented May 5, 2026

Copy link
Copy Markdown
Owner Author

Second review pass addressed in commit 3352dc3 and all remaining review threads are now resolved.

Fixes included:

  • toolRequiresArgs updated for current tool names (docs_resolve, ctx_index).
  • setup_container now properly reuses existing containers when recreate=false (and starts stopped existing containers).
  • run_exploit_replay now applies per-attempt timeout via request context even when a custom HTTPClient is injected.
  • Executor timeout for run_secrets_scanner aligned to 10 minutes to match documented max timeout_seconds behavior.
  • cmd/run-tools rewritten to a safe flag-driven utility (--tool, --args) with no hardcoded destructive targets.

Validation:

  • go test ./internal/session/... ./internal/tool/... ./internal/executor/...
  • go build ./...

@giveen
giveen merged commit 007055b into main May 5, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants