Skip to content

loosens constraints on web security tools - #165

Merged
danielvaughn merged 4 commits into
mainfrom
fix/revert-tool-constraints
Oct 1, 2026
Merged

danielvaughn merged 4 commits into
mainfrom
fix/revert-tool-constraints

Conversation

@danielvaughn

Copy link
Copy Markdown
Contributor

Loosen web-security tool constraints

Optional tools (Caido, Burp, exiftool, agent-browser, wrangler, ast-grep, waymore, pacu, fireprox, archivealchemist) no longer fail sandbox provisioning when they can't install. Only the core required tools remain fatal.

Changes

  • install_tools.sh: optional-tool install failures now warn and continue instead of aborting; added a sealed-mode fast path that validates present
    tools without running any installer.
  • capability.yaml: removed health checks for the optional tools, so a missing optional tool no longer reports a false "error" (there's no warn/yellow
    severity — only ok or error). Bumped to 2.0.2.
  • tests: updated the installer offline suite and the Caido manifest tests to match the required/optional split.

Why

Sealed and offline deployments legitimately ship without the optional tools. They shouldn't block boot or light up the health panel red.

@danielvaughn
danielvaughn merged commit 0dc7aba into main Oct 1, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant