Skip to content

Milestones

List view

  • The flaws identified from the keyword-rosetta epic inititative go here - https://github.com/squid-protocol/keyword-rosetta

    No due date
    7/63 issues closed
  • Hardening GitGalaxy's existing COBOL/JCL structural-signature extraction -- especially CICS coverage -- and adding first-class support for the rest of the mainframe language family needed for full CICS-platform visibility (BMS, HLASM, REXX, PL/I, DB2 SQL/SQL PL). Tracked under epic #2516; see the `legacy-modernization` label for the full current set. Scope is deliberately narrow: a structural-extraction bug shared across many languages that happens to touch cobol/jcl incidentally belongs to the general extraction-hardening epic (#813, tracked in v2.4.9) instead, even when the fix ships alongside this work.

    No due date
    9/18 issues closed
  • Next-release grab-bag spanning three independent efforts, not one themed epic like the other milestones: - **5-Tier Knowledge Graph Hierarchy (epic #108):** `SignalProcessor` currently flattens Function -> Class -> File -> Folder -> Repo into a File-level score, skipping the documented Class-level containment boundary. #109 upgrades the risk-aggregation math, #110 expands the SQLite/output recorders to store class-level risk vectors, #111 syncs the docs. - **ML-Ops positive-control malware pipeline (#96):** an immutable, defanged malware sample library wired into CI so a structural-signature change can never silently drift the XGBoost threat classifier's accuracy without a build failure. - **Scanning/UX features:** a full scan mode that ignores the default vendor/generated-code exclusions (#136), a Sankey-diagram visualizer for what was actually scanned (#137), and a fallback warning when uncommitted files fall outside git-based scanning (#138).

    No due date
    0/8 issues closed
  • Evolving GitGalaxy from a structural static analysis tool into a compliance-ready, air-gap-native DevSecOps platform for highly regulated sectors (Aerospace, Defense, FinTech, MedTech) -- tracked under epic #75. Traditional AST-based analysis can't run against decades-old, uncompilable defense/aerospace codebases. This milestone extracts Structural Signatures for legacy and modern safety-critical languages (no working toolchain required) and layers a domain-specific risk ontology on top: - **Phase 1 -- Defense Primitives (language dictionaries):** JOVIAL/CMS-2 (#77), VHDL (#78), Lustre/SCADE (#81), HAL/S (#82), CORAL 66 (#1141), PL/I (#1142), ATLAS (#1143). Ada/SPARK (#76) and AGC Assembly already shipped. - **Phase 2 -- Domain-Specific Ontology Auto-Binning Engine (#84):** classify a file's architectural role (flight software, ground control, avionics bus, ...) instead of treating every repository as generic source code. - **Phase 3 -- MISRA C/C++ Structural Signatures & Liability Floor (#80):** a hard compliance gate for the automotive/aerospace C/C++ safety-critical coding standard. SARIF export, SBOM generation, and CI/CD delta-gating (Phases 4-5) already shipped under v2.4.0 -- see #75's own status note for the current remaining scope. **Note:** #1142's PL/I signatures overlap with #2502 (Legacy Modernization, CICS-driven) -- see #2516 for the open consolidation question before either ships.

    No due date
    1/11 issues closed