This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+10 more
Affected surfaces
Summary
AI summaryFixes a critical crash in small repositories, expands test suite coverage, and improves IR validation and resilience defenses.
Full changelog
🥇 Community Spotlight & Hotfixes
First and foremost, a massive thank you to @Abramel for an incredibly detailed and well-researched bug report regarding the FATAL_SYSTEM_COLLAPSE on small/sparse Python repositories (#19).
The issue tracked back to the central physics processor where net.get() failed to guard against NoneType edge cases on graphs with low edge-density. We wanted to get this fix shipped immediately to ensure the community remains unblocked when scanning smaller repositories.
Fix: Applied strict or 0.0 fallbacks to betweenness_score, closeness_score, and normalized_blast_radius during forensic report generation. Small repositories will now accurately process and persist to SQLite without crashing.
🛡️ The Zero-Trust Test Suite Expansion
While pushing the community hotfix, we took the opportunity to completely overhaul the structural integrity of the GitGalaxy engine.
We have expanded from a single Golden Image test to a 16-file, 31-invariant test suite. This ensures the absolute stability of the translation pipelines and security spokes. We plan to add more but wanted the hotfix pushed live quickly.
New Test Coverage Includes:
Security & Compliance Spokes: Full @ patch integration testing for the Supply Chain Firewall, Vault Sentinel, X-Ray Inspector, and SBOM generator.
COBOL-to-Java Forge: Golden Image byte-for-byte verification for Mainframe decoders, Spring Boot Entities, Controllers, and DAG-resolved Services.
AI Hallucination Guards: Mathematical verification that our intermediate representation (IR) strictly forces non-deterministic LLM agents to obey architectural constraints.
Resilience: Verified defense against ReDoS (Regular Expression Denial of Service) poisoning and Zombie Process OS-level timeouts.
🏗️ Architectural Rollup (Since v2.x)
For users upgrading from older versions, GitGalaxy has undergone a massive evolution. The engine now operates as a multi-phase, AST-free analytical platform. Key pillars introduced in recent cycles include:
The Java Forge: A fully automated pipeline capable of translating legacy mainframe architectures into modernized, dependency-injected Java Spring environments.
The API Network Mapper: Auto-discovery of Swagger/OpenAPI documentation matched against physical codebase routers to detect undocumented "Shadow APIs."
Zero-Dependency Mode Fallbacks: Ensuring the Cartographer and Signal Processor gracefully degrade without crashing if third-party binaries are missing.
Run pip install --upgrade gitgalaxy to pull the latest version!
Security Fixes
- Defended against ReDoS (Regular Expression Denial of Service) poisoning and Zombie Process OS-level timeouts in the Resilience layer
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About squid-protocol/gitgalaxy](https:
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]