Repository navigation
Tags: DobermanCore/Doberman-Core
Tags
feat(egress): raise-only static egress classification (EB.1), release… … v0.16.0 EB.1 — the single slice of the egress-breakout defense plan (v4). The MCP proxy now parses the RAW shell/package/git command (a lossless walk_command) and surfaces external_destination, so a network reach hidden inside a shell_exec / package_install / git_op is visible to the guardrails instead of slipping past as an opaque command. - secret + command egress = BLOCK (the existing secret-exfil floor now fires) - command egress + one egress_ambiguous signal (dynamic host, route/proxy override, unbalanced quoting, 256-char cap, multi-host) -> AUTH via ExternalDestinationRule - NormalizationFailureRule turns a parser crash into a fail-closed objective floor - command egress excluded from the subjective baseline (can't be slow-boiled to familiar); secret-shaped host labels HMAC-redacted before the SecurityObject Strictly raise-only: never a new PASS, never a lowered verdict. Release prep: __version__ single-sourced from package metadata (no more drift); version bumped 0.15.0 -> 0.16.0 for the PyPI release. Closes EB.1. EB.2/EB.3 deferred, EB.1b/EB.4 cut (plan v4 / ADR 0039).
PreviousNext