Skip to content

Commit 69dcdfb

Browse files
Merge pull request #511 from NVIDIA/codex/release-2.11.2
release: SkillSpector 2.11.2
2 parents a7dfab7 + 4b0573c commit 69dcdfb

4 files changed

Lines changed: 71 additions & 2 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,9 @@
1+
### 2.11.2 (Thursday, September 10, 2026)
2+
### Features/Bug Fixes
3+
* fix: prevent duplicate reference coverage from causing fatal scan-accounting errors (#507)
4+
* fix: avoid false shell-parser limits on ordinary documentation (#507)
5+
* fix: preserve partial coverage for runtime-selected printf and wrapper paths (#508)
6+
---
17
### 2.11.1 (Monday, September 07, 2026)
28
### Features/Bug Fixes
39
* fix: parse space-separated allowed-tools strings (fixes #327) (#330)
Lines changed: 63 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,63 @@
1+
# SkillSpector v2.11.2
2+
3+
Released: 2026-09-10
4+
5+
## Summary
6+
7+
SkillSpector 2.11.2 fixes fatal reference-accounting errors and several false static-parser limits triggered by ordinary documentation. This patch also preserves incomplete-analysis reporting when a runtime-selected executable prevents exact command reconstruction.
8+
9+
## Highlights
10+
11+
- Complete reference accounting when Markdown labels and destinations identify the same artifact, or when several referenced artifacts appear on one source line.
12+
- Avoid false parser limits for simple runtime parameters, inline skill invocations, PowerShell member access, and long quoted prose.
13+
- Keep runtime-selected `printf` and wrapper paths marked as partially inspected.
14+
15+
## Added
16+
17+
- None.
18+
19+
## Changed
20+
21+
- Record reference-coverage completion once per source line.
22+
23+
## Fixed
24+
25+
- Deduplicate reference-coverage records for the same source file, line, and target, preventing fatal `unaccounted_work` errors from duplicate Markdown references.
26+
- Account for distinct reference targets on the same source line without creating conflicting completion records.
27+
- Distinguish simple runtime parameters from command substitutions and complex parameter expansions in bounded shell reconstruction, including inline `$ARGUMENTS` documentation ([#464](https://github.com/NVIDIA/SkillSpector/issues/464)).
28+
- Count unquoted characters separately from already-consumed quoted spans so long quoted prose does not cause a false command-word span limit.
29+
- Preserve partial coverage when runtime parameters select a `printf`, `command`, `builtin`, or `env` executable path; a recognized basename alone cannot establish which executable will run.
30+
31+
## Security
32+
33+
- Fixed security findings.
34+
35+
## Breaking Changes and Migration
36+
37+
- None. No new configuration is required.
38+
39+
## Deprecations
40+
41+
- None.
42+
43+
## Validation
44+
45+
Validated locally with Python 3.12 and uv 0.10.10:
46+
47+
- `uv lock --check` — passed; third-party dependency versions are unchanged.
48+
- `uv run --no-sync make test-ci` — 4,013 passed, 14 skipped, 38 deselected, and 4 expected failures.
49+
- `uv run --no-sync make lint` and `uv run --no-sync make format-check` — passed.
50+
- Built wheel and source distributions; `twine check` passed for both artifacts.
51+
- `skillspector --version` — reported `SkillSpector v2.11.2`.
52+
- The GitHub release helper dry run resolved `v2.11.2` and the matching versioned release notes.
53+
- Docker image build and repository smoke tests passed on Linux/arm64, including the local safe fixture and public GitHub repository scans.
54+
- `git diff --check` — passed.
55+
56+
## Known Limitations
57+
58+
- Full LLM analysis and downstream CI behavior require validation in the deployment that uses the release.
59+
60+
## References
61+
62+
- [GitHub PR #507](https://github.com/NVIDIA/SkillSpector/pull/507)
63+
- [GitHub PR #508](https://github.com/NVIDIA/SkillSpector/pull/508)

‎pyproject.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ build-backend = "hatchling.build"
44

55
[project]
66
name = "skillspector"
7-
version = "2.11.1"
7+
version = "2.11.2"
88
description = "SkillSpector: Security scanner for AI agent skills (Claude Code, Cursor, and similar). Scans skills for vulnerabilities, malicious patterns, and security risks before installation. Supports Git repos, URLs, zips, and local directories; runs static pattern checks and optional LLM semantic analysis; outputs terminal, JSON, and Markdown reports with risk scoring."
99
readme = "README.md"
1010
license = "Apache-2.0"

‎uv.lock‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)