HeaderProof separates input, orchestration, transport, detection, evidence gating, and output.
cli.pyowns the stable command surface and process exit contract.input.pynormalizes target, list, and stdin streams.engine.pyschedules bounded detector work per URL.transport.pyperforms HTTP exchanges and enforces request pacing.detectors.pyderives bounded probe context; template matchers/extractors decide which candidate signals exist.templates.pyvalidates declarative request primitives, matchers, extractors, and evidence-gate definitions.evidence.pyapplies the template evidence gate before a candidate can become a finding.output.pypersists append-only evidence and exports findings.
The primary invariant is that a console finding is never emitted before its detector-specific technical gate passes. Lower-confidence observations stay in the evidence bundle rather than being promoted to findings.
input -> baseline/probes -> detector candidate -> evidence gate -> finding -> stdout/export
Every attempted probe is recorded independently of whether a finding is produced. This keeps false-positive suppression auditable and makes missing proof distinguishable from a clean result.
- Detector updates:
TayfurYldz/headerproof-templates;headerproof -update-templatesdownloads its validated manifest without replacing the binary. - CI wrapper:
TayfurYldz/headerproof-action; the action preserves HeaderProof's0/1/2exit semantics and can export SARIF.