Niro v0.1.80
Summary
Third-party component testing now prioritizes live exploitation of applicable security advisories.
Changes
- Pentests analyze third-party components at scale, validate applicable advisories against the running target, and create test cases only from reproducible live behavior.
Security
- Advisory candidates are not treated as clean unless the affected behavior was reached and did not reproduce the vulnerability.
- Test cases can reuse credentials created during advisory probing for independent verification.
Compatibility and upgrade
No action required.
Known issues
checksums.txtdoes not coverniro.mcpb.- Release artifacts have no detached signatures, provenance attestation, or SBOM.