You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 63b47c1
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: CHANGELOG.md
+38-8Lines changed: 38 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,22 +13,52 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
13
13
### Changed
14
14
- Threat-modeling phase disabled by default (`enable_threat_modeling = false`) — it generated a static STRIDE template rather than code-derived analysis
-`baco doctor` pre-flight checks: config parse, per-phase LLM slot validation (warns on phases without `api_key` that will be skipped), semgrep/python3 presence, output dir writability, disk space
22
+
-`baco eval` detection-regression suite: 10 labeled targets with ground-truth oracles, precision/recall/F1, CI gate on pass-rate (`BACO_EVAL_FLOOR`, default 0.70)
23
+
-`baco init [PATH]` config scaffolding with language detection and preset suggestions
24
+
- Scan-health report (console + JSON section): per-phase run/skipped-with-reason, file counters (indexed/analyzed/dropped/chunked), LLM call outcomes by error class, token and cost totals per phase, blind-scan warning when all LLM phases are skipped
- Per-language default Semgrep rulesets derived from `project.languages`
28
+
- Environment-variable bridges for all six LLM phase slots (`LLM_DISCOVERY_KEY`, `LLM_VERIFICATION_KEY`, `LLM_AGGREGATION_KEY`, `LLM_STATIC_ANALYSIS_KEY`, `LLM_SECURITY_AGENT_VERIFICATION_KEY`, `LLM_THREAT_MODELING_KEY`)
29
+
- LLM cost transparency: optional `[llm.pricing]` table, token counts per phase and model surfaced in the health report
|`knowledge`|`fp_patterns` (map of CWE → list of false-positive indicator strings), `required_security_primitives` (map of language → list of required primitives), `hook_registry` (map of language → HookRegistryLanguageConfig with `hook_label`, `registrations` regexes with optional `(?P<hook>)` capture, `handler_patterns` override) |
777
777
778
-
Unset fields keep the base `ScannerConfig` default; CLI flags still override the preset.
778
+
Unset fields keep the base `ScannerConfig` default; CLI flags still override the preset.
779
+
780
+
## Eval suite
781
+
782
+
The `[eval]` section configures the detection-regression suite run by `baco eval`.
|`floor`| f32 |`0.70`| Minimum aggregate pass-rate (0.0-1.0). The suite fails when the aggregate does not strictly exceed it. `BACO_EVAL_FLOOR` overrides it per invocation. |
787
+
788
+
```toml
789
+
[eval]
790
+
floor = 0.9
791
+
```
792
+
793
+
794
+
## Agent scaffold
795
+
796
+
The `[agent_scaffold]` section configures the call-graph-guided agent scaffold used during security-agent verification.
|`enabled`| bool |`false`| Enables the agent scaffold modules |
801
+
|`max_rounds`| u8 | built-in | Maximum interaction rounds per target function |
802
+
|`paths_per_target`| u8 | built-in | Number of call-graph paths to sample per target |
803
+
804
+
```toml
805
+
[agent_scaffold]
806
+
enabled = false
807
+
```
808
+
809
+
## Citation verification
810
+
811
+
The `[citation_verification]` section controls verification that finding citations (file + line) actually resolve in the target source, downgrading unverifiable findings.
0 commit comments