Merge pull request #47 from SquidSec/docs/finalize-status

docs: release notes 0.1.107 and plan status
This commit is contained in:
☣️ Mr. The Plague ☣️
2026-08-01 12:09:14 -05:00
committed by GitHub
2 changed files with 25 additions and 29 deletions
+16 -20
View File
@@ -4,31 +4,27 @@ All notable changes to SquidC5 are documented here.
Format inspired by [Keep a Changelog](https://keepachangelog.com/).
**OPSEC notes** call out changes that affect detection surface or defaults.
## [Unreleased]
## [0.1.107] - 2026-08-01
### Added
- Server-side HITL approval queue (`sc5 policy hitl …`); client `hitl_approved` ignored
- Listener restore on boot; clean shutdown keeps `running` for restart recovery
- DB schema migrations (`schema_version`)
- LLM API keys encrypted at rest
- API rate limit + max body size enforcement
- Deep health endpoint (`/api/v1/health/deep`)
- `sc5 backup` / `sc5 restore`
- Optional JSON logging (`SQUIDC5_LOG_JSON`)
- Implant AEAD (ChaCha20-Poly1305) check-in auth (`implant_psk`, require auth default on)
- HTTPS-default HTTP beacon templates (system CA verify; lab uses redirector or `scheme=http`)
- Beacon `kill_date` enforcement
- Audit integrity chain (`chain_hash` / `prev_hash`, migration v3)
- Native Linux Go beacon scaffold (`agents/linux`)
- Listener crash supervision + audit retention purge
- Team RBAC on shell when session metadata has `team_id`
- Server-side HITL approval queue with command binding
- Listener restore on boot; `sc5 backup` / `restore`
- Deep health, rate limits, body limits, JSON logging
- SquidGate PR security gate
- Startup config validation
- Plugin signing secret hardening (no legacy default in prod)
- Admin token file mode 0600; admin.js admin-only gate
- SquidSec branding (logo), expanded threat model, systemd unit
### Security / OPSEC
- TLS-by-default docs and examples (`https://`, `sc5 --insecure` for lab)
- Docker compose healthcheck uses HTTPS
- CI `pip-audit` fails the build
- Rate limit defaults may need raising for chatty ops UIs (prod often 600/min)
### Docs
- SquidSec branding and logo on README
- Expanded threat model, systemd unit, CONTRIBUTING, this changelog
- Client `hitl_approved` ignored; admin.js admin-only
- LLM keys encrypted at rest; plugin signing secret hardened
- TLS-by-default docs; binary-only prod deploy path
- Rate limit may need 600/min for ops UI
## [0.1.x] - 2026
+9 -9
View File
@@ -567,32 +567,32 @@ For **each** Change ID:
| A08 | A | done | merged |
| A09 | A | done | merged |
| A10 | A | done | merged |
| A11 | A | pending | |
| A11 | A | done | merged |
| A11b | A | pending/optional | |
| B01 | B | done | merged |
| B02 | B | done | merged |
| B03 | B | pending | |
| B03 | B | done | merged |
| B04 | B | done | merged |
| B05 | B | done | merged |
| B06 | B | done | merged |
| B07 | B | pending | |
| B07 | B | done | merged |
| B08 | B | done | merged |
| B09 | B | done | merged |
| B10 | B | pending | |
| B11 | B | pending | |
| B12 | B | pending | |
| B13 | B | pending | |
| B14 | B | pending | |
| B14 | B | done | merged |
| B15 | B | done | merged |
| B16 | B | done | merged |
| C01 | C | pending | |
| C02 | C | pending | |
| C01 | C | done | merged |
| C02 | C | done | merged |
| C03 | C | pending | |
| C04 | C | pending | |
| C05 | C | pending | |
| C06 | C | pending | |
| C06 | C | done | merged |
| C07 | C | pending | |
| C08 | C | pending | |
| C08 | C | done | merged |
| C09 | C | pending | |
| C10 | C | pending | |
| C11 | C | pending | |
@@ -601,7 +601,7 @@ For **each** Change ID:
| D03 | D | pending | |
| D04 | D | pending | |
| D05 | D | pending | |
| D06 | D | pending | |
| D06 | D | done | merged |
| D07 | D | pending | |
| D08 | D | pending | |