<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
  <title>Broly changelog</title>
  <link>https://shasheen8.github.io/Broly</link>
  <description>Release notes and changes for Broly</description>
  <item>
    <title>v1.66.0: Routes subcommand and keyword matching fix</title>
    <link>https://shasheen8.github.io/Broly#v1-66-0</link>
    <guid>https://shasheen8.github.io/Broly#v1-66-0</guid>
    <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
    <description>This release introduces a new routes subcommand that extracts declared HTTP routes and their reachable dangerous sinks, giving users a way to map attack surface without running a full vulnerability scan. It also fixes multi-word keyword matching in vulnerability classification so phrases like &quot;access control&quot; no longer match unrelated substrings such as &quot;access controller&quot;.</description>
  </item>
  <item>
    <title>v1.63.0: Bug fixes and expanded help docs</title>
    <link>https://shasheen8.github.io/Broly#v1-63-0</link>
    <guid>https://shasheen8.github.io/Broly#v1-63-0</guid>
    <pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
    <description>This release fixes several bugs that caused findings to be dropped or hidden from output, and improves reliability of AI-backed scans. It also expands the CLI help text with vulnerability class listings and CWE references so users can quickly find the right scanner flags.</description>
  </item>
  <item>
    <title>v1.58.0: IaC triage and exploit chain updates</title>
    <link>https://shasheen8.github.io/Broly#v1-58-0</link>
    <guid>https://shasheen8.github.io/Broly#v1-58-0</guid>
    <pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
    <description>This release extends AI triage and exploit chain analysis to infrastructure-as-code findings, narrows exploit chains to critical-severity issues only, and fixes workflow path parsing for zizmor 1.29+. Help text now includes comprehensive examples, configuration options, and exit codes.</description>
  </item>
  <item>
    <title>v1.52.0: Diff scoping, vuln-class hunting, faster scans</title>
    <link>https://shasheen8.github.io/Broly#v1-52-0</link>
    <guid>https://shasheen8.github.io/Broly#v1-52-0</guid>
    <pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
    <description>This release adds line-level diff scoping for PR scans, vulnerability class focus flags for targeted bug hunting, and a standalone container auto-discovery mode. It also significantly reduces scan timeouts and sorts findings critical-first, plus fixes version detection in the update command.</description>
  </item>
  <item>
    <title>v1.0.40: Update command and GLM-5.2 model</title>
    <link>https://shasheen8.github.io/Broly#v1-0-40</link>
    <guid>https://shasheen8.github.io/Broly#v1-0-40</guid>
    <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
    <description>This release adds a self-update command, upgrades the default SAST model to GLM-5.2, and fixes container scanning to only run when SCA is enabled. Users can now update broly in place and will see the active model name in the startup banner.</description>
  </item>
  <item>
    <title>v1.0.36: Auto-installing tools and clearer CLI help</title>
    <link>https://shasheen8.github.io/Broly#v1-0-36</link>
    <guid>https://shasheen8.github.io/Broly#v1-0-36</guid>
    <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
    <description>This release removes the manual pip install step for zizmor and checkov by auto-installing them into a managed venv on first use. It also overhauls the CLI banner and help text so users can see every scanner and AI flag at a glance.</description>
  </item>
  <item>
    <title>v1.0.28: Agentic triage and new scanners</title>
    <link>https://shasheen8.github.io/Broly#v1-0-28</link>
    <guid>https://shasheen8.github.io/Broly#v1-0-28</guid>
    <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
    <description>This release adds agentic AI triage that uses repo search tools to verify SAST findings, along with opt-in adversarial verification and exploit chain synthesis for high-confidence true positives. It also introduces three new scanner types: GitHub Actions workflows, infrastructure-as-code, and malicious-package supply chain audits, each requiring an external binary that is auto-detected at runtime.</description>
  </item>
  <item>
    <title>v1.0.20: Code-first remediation and scan polish</title>
    <link>https://shasheen8.github.io/Broly#v1-0-20</link>
    <guid>https://shasheen8.github.io/Broly#v1-0-20</guid>
    <pubDate>Sat, 23 May 2026 00:00:00 +0000</pubDate>
    <description>This release redesigns SAST output to include concrete fix code alongside remediation guidance, and polishes scan output formatting and container behavior across all scanners. It also introduces baseline finding enforcement, new exit codes for missing required findings, and broader language and scanner coverage.</description>
  </item>
</channel></rss>
