Skip to content

This release adds 2 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai-security security auditing cli cobol code-bioinformatics
+10 more
codebase-analysis deep-tech incident-response legacy-modernization python sbom software-architecture static-analysis supply-chain-security zero-trust

Summary

AI summary

Expanded testing pipeline validates core claims with a 443‑test adversarial matrix executing in ~3.05 seconds.

Full changelog

🚀 v2.2.0: The Enterprise Matrix & Structural Rigor
A Foundation of Absolute Proof
In our v2.1.0 release, we pushed a critical hotfix inspired by an excellent bug report from @Abramel regarding sparse repository collapses. That interaction sparked an internal reckoning. We realized that simply patching edge cases wasn't enough; if GitGalaxy is going to make bold claims about AST-free parsing, deterministic AI guardrails, and legacy mainframe extraction, we needed an undeniable wall of proof to back them up.

This release represents a massive paradigm shift in our engineering rigor. We have expanded the GitGalaxy testing pipeline from 84 baseline tests to a punishing 443-test adversarial matrix, mathematically validating our boldest architectural claims to ensure absolute data integrity for our users.

The most exciting part? The entire 443-test polyglot matrix executes in ~3.05 seconds.

🛡️ The Empirical Validation Suite
We have completely restructured the testing architecture into specialized domain gauntlets, proving the engine’s stability across 30+ programming languages:

AST-Free Precision (The Extraction Gauntlets): We subject the core engine to positive, negative, and pathologically fragmented code payloads. This proves GitGalaxy accurately maps functions, classes, arguments, and dependencies with AST-level precision—without requiring a compiler.

Catastrophic Backtracking (ReDoS) Immunity: We introduced "The Blast Chamber." The engine is now bombarded with isolated, pathological formatting (e.g., C++ Macro Spirals, C# Iron Wall overlaps, C/C++ K&R Ambiguity traps). O(1) boundaries and strict timeouts guarantee the regex engine will never lock the CPU in a death spiral.

Bayesian Refutation & The 50/0 Law: The Spectral Auditor now actively defends against data-dumps and hallucinated code. We empirically prove that massive, inert files are successfully stripped of their execution claims and relegated to "Dark Matter," actively bypassing the Ecosystem Orphan guards via Bayesian Refutation.

Autonomous AI & AppSec Guardrails: Verified the detection of RCE (Remote Code Execution) funnels, God-mode agent prompts, exfiltration camouflage, and hallucination zones to ensure LLM integrations remain bounded.

Legacy Mainframe Hardening: Locked in byte-for-byte verification for the COBOL DAG Architect, EBCDIC/COMP-3 payload unpacker, and the Code Graveyard dead-logic finder.

🧹 Pristine Execution Hygiene
Alongside the test expansion, the core engine Python modules were hardened to achieve a 100% clean CI/CD pipeline.

Resolved all Python 3.12+ SyntaxWarnings (invalid escape sequences) by enforcing strict raw string constraints across the regex pattern dictionaries.

Patched Flake8 static analysis warnings for flawless linter compliance.

GitGalaxy is now strictly deterministic, fully tested, and enterprise-ready.

Run pip install --upgrade gitgalaxy to pull the latest version!

Contributors
@Abramel - For the initial spark that catalyzed this massive architectural hardening.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track squid-protocol/gitgalaxy](https:

Get notified when new releases ship.

Sign up free

About squid-protocol/gitgalaxy](https:

All releases →

Related context

Beta — feedback welcome: [email protected]