Changelog

v0.2.3 5 commits

Vigilance checked this release against the one before it. See what it gained.

  • e3085a8 vigi reads compiled Python files and static libraries
  • 567eb81 vigi reads Chromium resource packs
  • 862eb36 vigi shows a popup when software gains a new capability
  • b51b103 vigi reads Bun programs and packed files
  • 89ddd30 Faster scans of large installers and data files

v0.2.2

Vigilance checked this release against the one before it. See what it gained.

v0.2.1 1 commit

Vigilance checked this release against the one before it. See what it gained.

  • e138821 Vigilance has a Windows app window. Run vigi ui to set up a machine, review changes and manage a fleet without the command line

v0.2.0 7 commits

Vigilance checked this release against the one before it. See what it gained.

  • 2fb06c9 A silent install runs start to finish without asking anything
  • 15c3e8e vigi fleet count reports how many machines your fleet runs
  • 51317c0 The installer finishes on its own, and the first check runs after it
  • 7e51a10 An install that stops says which step stopped
  • 8cdd810 The Windows installer asks what to watch and how often, and shows the plan before it writes anything
  • ee78697 vigi reads binary property lists, and reports how much of a folder it covered
  • 7fe960a A report shows the file name, never the folder it sits in

v0.1.52 1 commit

Vigilance checked this release against the one before it. See what it gained.

  • d474927 The word is capability now, in what you read, in the JSON keys and in the SARIF rule ids

v0.1.51 1 commit

Vigilance checked this release against the one before it. See what it gained.

  • 14627cd Cosmetic improvements

v0.1.50 2 commits

Vigilance checked this release against the one before it. See what it gained.

  • b451c12 Every finding leads with the installed program or package it belongs to, and the fleet page can report one to us in a form already filled in
  • 2c19d86 The fleet page opens with how many machines need you, and puts the machines in a band per state

v0.1.49 2 commits

Vigilance checked this release against the one before it. See what it gained.

  • 9a663e6 The Windows downloads are signed. Windows shows Marcello Delcaro as the publisher
  • 12d31b2 Fewer false alarms on developer tools

v0.1.48 1 commit

Vigilance checked this release against the one before it. See what it gained.

  • 824d457 Every power Vigilance reports is written in plain words, and every destination it reports is a place a file really talks to

v0.1.47 1 commit

Vigilance checked this release against the one before it. See what it gained.

  • abc085f Every destination Vigilance reports is a real address

v0.1.46 2 commits

  • 1a885e1 Detection algorithm tuning
  • 8be7c8e Help goes to support@vigihq.com, licences to licensing@vigihq.com

v0.1.45

v0.1.44

v0.1.43

v0.1.42

v0.1.41

v0.1.40 12 commits

  • b358d5d Vigilance reports how many times a program uses each power it asks for, not only that it asked
  • b4e8763 vigi --gate answers a CI pipeline with a pass or a fail
  • c3399db Vigilance runs as an ordinary account, and keeps its licence in that account's own folder
  • b33afc5 The fleet page has a search box and a dark theme
  • 64ca758 The fleet page carries hundreds of machines
  • c3f0865 The fleet page opens on the machines that have not reported, and exports the list for an audit
  • 2e4da86 A machine can join a fleet, and every run files a receipt against it
  • 7368997 Install Vigilance from an apt or an rpm repository
  • 0de63ac Install Vigilance with npm or pip
  • 3c76b12 Install Vigilance with scoop on Windows
  • 5a3155e Every address a customer is given is a vigihq.com one
  • 3e1ac66 Vigilance reports more kinds of power a file gains between versions

v0.1.38 4 commits

  • cb10ba3 Show how to check a build against its inputs, near the top of the help
  • 407a92e Vigilance reports a build file that runs a data file
  • b3ffe6e Vigilance reports a package that starts fetching a dependency from outside the registry
  • 418eb3f Vigilance reports a file that hides the name of what it loads inside an encoding

v0.1.37 2 commits

  • b30c2c5 The free tier says when a newer version is out, on the report it already sends, with no new connection
  • 53d304d A scheduled check watches the whole folder tree, so a change in any subfolder starts a run

v0.1.36 1 commit

  • 33591a8 The scan writes its findings as SARIF for CI

v0.1.35 1 commit

  • b78772a Your own deny-list, and a release feed you can poll

v0.1.34 2 commits

  • d71c860 --report writes one plain HTML page of any check, with the machine-readable record in the same file, and the scheduled run, the git hooks and fleet all take it
  • 6394e76 vigi hook git checks every commit and merge, diff --sarif writes SARIF 2.1.0 for security tooling, and Vigilance reports a change to a container image's start-up settings

v0.1.33 9 commits

  • e7eeb47 Clearer help, split into everyday and pipeline commands, plus a tidier first run.
  • aea2409 check --opaque lists files that are not readable text (the old opaque command, folded in).
  • de36386 Vigilance suggests the closest command when you mistype one
  • aad36ae vigi profile now takes a path directly, like the main scan.
  • fbd0708 The most important finding now sorts to the top of the list.
  • 90578a1 Vigilance reads inside .Z files, the output of Unix compress
  • 4a390d1 Vigilance reads inside Electron app archives (.asar)
  • d087cd5 Pro is its own binary with no network code, so it opens no connection at all.
  • c4341c0 vigi upgrade switches a Free install to Pro from the command line.

v0.1.32 1 commit

  • 4a28623 A Pro license keeps running for a few days after its renewal date

v0.1.31 1 commit

  • f72ac4e Read every architecture in a macOS universal binary

v0.1.30 2 commits

  • aaa73f3 Vigilance reads PDFs and .gmo message catalogs
  • 668c0fe vigi status says whether the scheduled check is still running

v0.1.29 2 commits

  • 8913c30 Open CRX, Ruby gem, ar/.a, AppImage and RAR archives
  • 8298250 Open APPX, MSIX, EAR and snap packages

v0.1.27

v0.1.26 9 commits

  • 0910025 Route standalone compressed tars and modern rpm payloads to the decoders
  • 3ec5f48 Read inside zstd and squashfs
  • 5a50656 Read inside 7z archives
  • 8bb2dd2 Expose the LZMA core to the 7z and squashfs readers
  • e967dd2 Read inside MSI, CFB and MSP compound files
  • 53928c0 Read inside xz, lzma, lz4, ISO9660, xar and CAB
  • 86ec290 Catch more code that hides what it runs
  • 01c6abb Widen what counts as a new power on Windows
  • b14b9dc Name more cloud secrets, and tighten shell-pipe detection

v0.1.25 1 commit

  • 0682715 Vigilance shows the exact administrator command when a licence install needs one

v0.1.24 4 commits

  • 0ea2bd8 vigi snapshots shows the copies your machine already keeps, and the path to compare them
  • 7b20bbb vigi fleet merge builds one page for every machine you watch
  • 3fcd020 vigi timeline --dir reads a folder of old versions in order
  • 53a92ef vigi whatis, vigi diff --json, and wider coverage in vigi profile

v0.1.23 1 commit

  • 90a8217 vigi activate gets a licence with no network call

v0.1.22

v0.1.21

v0.1.20 1 commit

  • 37d7407 schedule: offer 15 and 30 minute checks

v0.1.19

v0.1.18 1 commit

  • 06ee322 Vigilance renews its licence and updates itself from a signed file

v0.1.17

v0.1.16

v0.1.15

v0.1.14 1 commit

  • ac4106e Scan files across the machine's cores

v0.1.13 1 commit

  • 97399a1 Licensing: offline signed files that expire on schedule

v0.1.12 4 commits

  • bd58cb7 vigi runs on OpenBSD
  • 2997a4b On Windows, vigi notices what came and went between checks
  • 459d900 Run on change as well as on the clock, and never two runs at once
  • e384014 Catch more tampering that tries to hide a change

v0.1.11

v0.1.10 1 commit

  • 758eb22 Read container images, pair versioned archives, and make the first look fast

v0.1.9 1 commit

  • 75419db Handle a Windows disk cleanly

v0.1.8 1 commit

  • d3a583f Windows notices what came and went between checks

v0.1.7 2 commits

  • ccb9f64 The come-and-went rule is a macOS and Linux signal
  • e91448d State the starting position, and notice what came and went

v0.1.6

v0.1.5

v0.1.4

v0.1.3 1 commit

  • b7c4344 Install into the administrator's folder by default

v0.1.2

v0.1.1 1 commit

  • efc3004 Count the calls, not just the powers

v0.1.0 6 commits

  • 2a2a165 The scheduled job says which folders it can reach
  • 487a264 The wizard installs the schedule instead of printing a command
  • ca97980 vigi reads WebAssembly, including files built to be awkward
  • 3c944b3 Add an installer for every platform, and a wizard that says where to run it
  • 0152457 The tool now says what it is, and ships as a binary
  • a1e92d7 Read Java, .NET and WebAssembly binaries