Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -295,6 +295,7 @@ See [SCAN_COVERAGE.md](SCAN_COVERAGE.md) for the full catalog of supported detec
| Python Packages | pip, poetry, pipenv, uv, conda, rye (opt-in) |
| System Packages | rpm, dpkg, pacman, apk, snap, flatpak (Linux) |
| Go Modules | `go.mod`/`go.work` declarations, vendored modules, module cache, `GOBIN` tools, recorded checksums (enterprise) |
| Rust Packages | `Cargo.toml` declarations, `Cargo.lock`, registry cache, Git checkouts, vendored sources, `cargo install` receipts (enterprise) |
| Package Configs | npm (`.npmrc`), pnpm, bun (`bunfig.toml`), yarn classic & berry (`.yarnrc`/`.yarnrc.yml`), pip (`pip.conf`) — effective registry, cooldown policy, and auth surface across every scope |
| Suspicious Files | Malicious-file IOCs from StepSecurity-maintained rules — e.g. `binding.gyp` that runs during `npm install`, and editor/AI-tool config files that auto-execute on project open |

Expand All @@ -310,7 +311,7 @@ Compromised packages most often reach a machine because that machine resolves di
- **Cooldown policy** — whether a cooldown window against newly published packages is in effect.
- **Authentication surface** — what credentials are configured against the registry.

Configuration is read from `.npmrc` (npm), pnpm config, `bunfig.toml` (bun), `.yarnrc` / `.yarnrc.yml` (yarn classic and berry), `pip.conf` (pip), and Go's `go/env` and process environment (proxy, checksum database, private-module and auth settings, redacted on the device). In enterprise mode this rolls up into the **Package Configs** view in the dashboard, where you can spot machines that are unprotected or pointed at the wrong registry.
Configuration is read from `.npmrc` (npm), pnpm config, `bunfig.toml` (bun), `.yarnrc` / `.yarnrc.yml` (yarn classic and berry), `pip.conf` (pip), Go's `go/env` and process environment (proxy, checksum database, private-module and auth settings, redacted on the device), and Cargo's `.cargo/config.toml` files and process environment (registries, source replacement, proxy and TLS settings, redacted on the device). In enterprise mode this rolls up into the **Package Configs** view in the dashboard, where you can spot machines that are unprotected or pointed at the wrong registry.

Enterprise Device Policy can also set StepSecurity Secure Registry as the sole user-level Python index for pip and uv. It manages only the resolved developer's user configuration and shared StepSecurity `.netrc` entry, keeps pip and uv results independent, and restores owned settings on an explicit policy clear. Project files, virtual environments, system configuration, environment variables, direct URLs, and Poetry are not modified.

Expand Down
24 changes: 24 additions & 0 deletions SCAN_COVERAGE.md
Original file line number Diff line number Diff line change
Expand Up @@ -280,6 +280,30 @@ Enterprise telemetry reports Go module evidence for the logged-in developer as t

**Privacy: URL credentials, query strings, and fragments are removed from proxy and checksum-database URLs on the device, `GOAUTH` arguments and non-module `GOFLAGS` are dropped, and non-allowlisted environment values, `.netrc` content, and build settings are never collected.**

## Rust Packages

Enterprise telemetry reports Rust package evidence managed by Cargo for the logged-in developer as two sections, `cargo_inventory` and `cargo_config_audit`. Everything is read statically: **no `cargo`, `rustc` or `git` command, shell, or network call is ever run**, and a root or service account is never scanned in the developer's place. Each evidence kind is reported separately; none of them means a package was compiled or executed.

| Evidence | Source |
|----------|--------|
| Declared requirements | `Cargo.toml` files found under the search directories: normal, dev, build and target-specific dependencies with aliases, requirement text, features, optional and explicit `default-features`, and registry, Git or path selectors. Workspace inheritance is applied; unused `workspace.dependencies` entries are not reported. |
| Workspaces | `[workspace]` members (literal paths and single-level globs), `exclude`, in-root path dependencies and explicit `package.workspace`. Membership that cannot be established is reported as `workspace_unresolved`. |
| Locked packages | `Cargo.lock` formats 3 and 4, once per workspace root, including a custom `resolver.lockfile-path`. Other formats are `unsupported_format`. Unused patches are not reported. |
| Cached packages | Every `registry/cache/<id>/*.crate` and `registry/src/<id>/<name>-<version>/` in the default `~/.cargo` and an effective `CARGO_HOME`, merged into one record per registry ID, name and version. Archives are never unpacked; only their `Cargo.toml` member is read when no extracted copy establishes the identity. |
| Git checkouts | Package manifests in `git/checkouts/<repo>/<rev>/`, with the full commit from the checkout's `.git/HEAD` when recorded. |
| Vendored packages | Packages in directories holding `.cargo-checksum.json`, found by the walk or configured as `source.<name>.directory`, and `.crate` archives in a configured `local-registry`. |
| Installed tools | `.crates.toml` receipts (enriched by `.crates2.json`) in each Cargo home, `install.root` and `CARGO_INSTALL_ROOT`, with each recorded bin checked by presence alone. |
| Recorded checksums | Lockfile and `.cargo-checksum.json` package SHA-256 values, marked `not_verified`. |
| Cargo configuration | `.cargo/config` and `.cargo/config.toml` of each project and its ancestors inside the search directories, the Cargo home config, included files, and the verified process environment: an allowlist of registry, source-replacement, network, install-root and lockfile-path settings, per invocation context, with findings `cargo-001`…`cargo-004`. Credentials files are checked for presence only. |

**Scope.** The home and configured search directories are walked; `.git`, `.hg`, `.svn`, `node_modules`, `target`, `.rustup` and Cargo's own `registry` and `git` directories are not walked as projects, and directory symlinks are not followed. Paths a manifest or config names exactly (workspace members, path dependencies, includes, lockfile paths, Cargo homes, install roots, configured source directories) are read as targeted files, one level deep for source directories. `.cargo` configs above the search directories are not probed, and a workspace root above them is not found. TCC-protected directories and skipped network volumes stay excluded even when `include_tcc_protected` is set. The process environment counts only when the agent runs as the developer.

**Origins.** Registry cache directory names are opaque, so cached packages carry `cache_unknown` origin scoped to their Cargo home and cache ID. Git checkouts carry `git_unknown`, vendored and local-registry packages `vendor_unknown`, and a lockfile entry without a source that matches no single known manifest `local_unknown`, scoped to its lockfile.

**Bounded.** Reads, directory listings, walk depth, archive headers and decompressed bytes, config includes, record count and output size are capped. Any cap, refusal, or failure makes the affected source and section `partial` with a reason code, never silently incomplete.

**Privacy: URL credentials, query strings, and fragments are removed on the device, registry tokens are reported only as configured, custom credential providers are shown as `custom` with their arguments dropped, and non-allowlisted settings, credentials-file contents, and binary contents are never collected.**

## System Package Scanning (Linux)

System package scanning is **automatic on Linux** — no opt-in flag required. Multiple package managers can coexist.
Expand Down
2 changes: 1 addition & 1 deletion go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ require golang.org/x/sys v0.33.0
require (
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510
github.com/google/uuid v1.6.0
github.com/pelletier/go-toml/v2 v2.3.1
github.com/pelletier/go-toml/v2 v2.4.3
github.com/tailscale/hujson v0.0.0-20260302212456-ecc657c15afd
github.com/tidwall/gjson v1.18.0
github.com/tidwall/pretty v1.2.1
Expand Down
4 changes: 2 additions & 2 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,8 @@ github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510/go.mod h1:pupxD2MaaD3
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
github.com/jessevdk/go-flags v1.4.0/go.mod h1:4FA24M0QyGHXBuZZK/XkWh8h0e1EYbRYJSGM75WSRxI=
github.com/pelletier/go-toml/v2 v2.3.1 h1:MYEvvGnQjeNkRF1qUuGolNtNExTDwct51yp7olPtrEc=
github.com/pelletier/go-toml/v2 v2.3.1/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY=
github.com/pelletier/go-toml/v2 v2.4.3 h1:GTRvJQutkOSftxIFD5xw9aepkYNuPWmVJpffdDPYVpY=
github.com/pelletier/go-toml/v2 v2.4.3/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY=
github.com/tailscale/hujson v0.0.0-20260302212456-ecc657c15afd h1:Rf9uhF1+VJ7ZHqxrG8pJ6YacmHvVCmByDmGbAWCc/gA=
github.com/tailscale/hujson v0.0.0-20260302212456-ecc657c15afd/go.mod h1:EbW0wDK/qEUYI0A5bqq0C2kF8JTQwWONmGDBbzsxxHo=
github.com/tidwall/gjson v1.14.2/go.mod h1:/wbyibRr2FHMks5tjHJ5F8dMZh3AcwJEMf5vlfC0lxk=
Expand Down
Loading
Loading