Skip to content

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai-security security auditing cli cobol code-bioinformatics
+10 more
codebase-analysis deep-tech incident-response legacy-modernization python sbom software-architecture static-analysis supply-chain-security zero-trust

Affected surfaces

breaking_upgrade rce_ssrf

Summary

AI summary

Fixes a critical crash in small repositories, expands test suite coverage, and improves IR validation and resilience defenses.

Full changelog

🥇 Community Spotlight & Hotfixes
First and foremost, a massive thank you to @Abramel for an incredibly detailed and well-researched bug report regarding the FATAL_SYSTEM_COLLAPSE on small/sparse Python repositories (#19).

The issue tracked back to the central physics processor where net.get() failed to guard against NoneType edge cases on graphs with low edge-density. We wanted to get this fix shipped immediately to ensure the community remains unblocked when scanning smaller repositories.

Fix: Applied strict or 0.0 fallbacks to betweenness_score, closeness_score, and normalized_blast_radius during forensic report generation. Small repositories will now accurately process and persist to SQLite without crashing.

🛡️ The Zero-Trust Test Suite Expansion
While pushing the community hotfix, we took the opportunity to completely overhaul the structural integrity of the GitGalaxy engine.

We have expanded from a single Golden Image test to a 16-file, 31-invariant test suite. This ensures the absolute stability of the translation pipelines and security spokes. We plan to add more but wanted the hotfix pushed live quickly.

New Test Coverage Includes:

Security & Compliance Spokes: Full @ patch integration testing for the Supply Chain Firewall, Vault Sentinel, X-Ray Inspector, and SBOM generator.

COBOL-to-Java Forge: Golden Image byte-for-byte verification for Mainframe decoders, Spring Boot Entities, Controllers, and DAG-resolved Services.

AI Hallucination Guards: Mathematical verification that our intermediate representation (IR) strictly forces non-deterministic LLM agents to obey architectural constraints.

Resilience: Verified defense against ReDoS (Regular Expression Denial of Service) poisoning and Zombie Process OS-level timeouts.

🏗️ Architectural Rollup (Since v2.x)
For users upgrading from older versions, GitGalaxy has undergone a massive evolution. The engine now operates as a multi-phase, AST-free analytical platform. Key pillars introduced in recent cycles include:

The Java Forge: A fully automated pipeline capable of translating legacy mainframe architectures into modernized, dependency-injected Java Spring environments.

The API Network Mapper: Auto-discovery of Swagger/OpenAPI documentation matched against physical codebase routers to detect undocumented "Shadow APIs."

Zero-Dependency Mode Fallbacks: Ensuring the Cartographer and Signal Processor gracefully degrade without crashing if third-party binaries are missing.

Run pip install --upgrade gitgalaxy to pull the latest version!

Security Fixes

  • Defended against ReDoS (Regular Expression Denial of Service) poisoning and Zombie Process OS-level timeouts in the Resilience layer

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track squid-protocol/gitgalaxy](https:

Get notified when new releases ship.

Sign up free

About squid-protocol/gitgalaxy](https:

All releases →

Related context

Beta — feedback welcome: [email protected]