All notable changes to BugScanner are documented here. Format follows Keep a Changelog.
- Structured logging via
structlog(core/logger.py) - Retry logic with exponential backoff (
tenacity) inHttpClient - HTTP response caching — 30–40% fewer requests on re-scans
- Scan diff engine (
core/differ.py) — compare two scans and highlight deltas - SARIF 2.1.0 export (
core/sarif_reporter.py) — GitHub Security tab integration - API key authentication for FastAPI backend (
BUGSCANNER_API_KEY) - CLI
diffcommand —python cli.py diff old.json new.json - Test suite with
pytest,pytest-asyncio,respx— 40+ tests - Dockerfile and docker-compose.yml
- GitHub Actions CI workflow
pyproject.tomlfor modern packaging andpip install -e ..env.examplefor environment configuration
- Rate limiter double-refill bug — actual RPS was ~20% higher than configured
- Nuclei template path — now reads from
settings.yamlinstead of ignored - WAF evasion now uses public API instead of mutating private state
- False positives — SPA fallback detection, body similarity, fake-404 baseline
- IDOR HTTP method scanning — now SPA-aware with 4-layer verification
HttpClientretries transient 5xx/429 responses automaticallyBugScanneracceptsenable_cacheparameter- Report now includes SARIF alongside JSON/HTML
- Modern report UI (dark/light theme, sidebar, bento grid)
- Chunked port scanning for full 1–65535 range
- Isolated subdomain HTTP client
- Multi-DB SQLi time-based verification (
WAITFOR,pg_sleep,BENCHMARK) - Business logic scanner (mass assignment, price manipulation, rate-limit bypass)
--cookie,--header,--proxy,--business-logicCLI flagsfalse_positives_filteredfield in ScanResult
- Initial public release
- Recon, vulnerability scanning, reporting