Skip to content

Release OSINTai v4 - #2

Merged
gs-ai merged 1 commit into
mainfrom
agent/osintai-v4
Aug 14, 2026
Merged

gs-ai merged 1 commit into
mainfrom
agent/osintai-v4

Conversation

@gs-ai

@gs-ai gs-ai commented Aug 14, 2026

Copy link
Copy Markdown
Owner

Summary

  • release OSINTai 4.0.0 with deterministic post-crawl analysis, correlation, timelines, hypotheses, pivots, evaluation, and local training exports
  • harden crawl scope, redirects, response limits, Ollama endpoints, run paths, and atomic checkpoints
  • add locked dependencies, a release gate, and regression/security coverage

Verification

  • 82 unit tests pass with ResourceWarning failures enabled
  • Python compilation passes
  • Bandit medium/high and Ruff correctness checks pass
  • pip-audit reports no known dependency vulnerabilities
  • Gitleaks reports zero findings in the publishable tree and all reachable history
  • CLI reports OSINTai 4.0.0

@gs-ai
gs-ai marked this pull request as ready for review August 14, 2026 23:18
Copilot AI lite review requested due to automatic review settings August 14, 2026 23:18
@gs-ai
gs-ai merged commit 61e8fe7 into main Aug 14, 2026
1 check passed
@gs-ai
gs-ai deleted the agent/osintai-v4 branch August 14, 2026 23:18

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR cuts the OSINTai v4.0.0 release by adding a post-crawl, deterministic “analysis layer” (provenance-labelled findings/correlation/timeline/hypotheses/leads), tightening crawl/fetch safety policies (scope + redirects + response type/size limits + loopback-only Ollama), and introducing a locked-deps CI release gate.

Changes:

  • Added offline analysis pipeline (deterministic checks, correlation, temporal analysis, optional deep/cross-check, evaluation, and inert training export) plus an analysis report format.
  • Hardened crawl/runtime policies: multi-seed scoping enforcement, redirect validation before follow, HTML/XHTML-only bounded downloads, atomic JSON checkpoints, and loopback-only Ollama client.
  • Added comprehensive regression/capability tests and a CI “release gate” workflow; pinned runtime dependencies.

Reviewed changes

Copilot reviewed 27 out of 29 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
tests/test_seed_and_fetch_policy.py Adds tests for seed parsing/run-id validation, scope enforcement, redirect policy, response limits, and loopback-only Ollama endpoints.
tests/test_analysis_layer.py Adds extensive regression/capability coverage for prompts, provenance, entities, patterns, correlation, temporal, evaluation, and end-to-end analysis pipeline artifacts.
src/osintai/training_export.py Implements portable JSON/JSONL export of evaluation tasks/preferences/scored results and a manifest.
src/osintai/temporal.py Adds timeline event model, timestamp parsing, plausibility filters, and temporal findings (gaps/bursts/trailing gap).
src/osintai/storage.py Adds atomic JSON writes and hardens JSON reads; marks SHA1 as legacy artifact ID (not security).
src/osintai/report.py Keeps existing ranked report stable and adds a separate provenance-aware analysis report writer.
src/osintai/proxy_pool.py Switches proxy selection randomness to secrets.choice.
src/osintai/provenance.py Introduces provenance primitives (Finding/Hypothesis/Lead/Confidence/CheckResult) and confidence kinds.
src/osintai/prompts.py Centralizes prompt profiles, preserving byte-identical “standard” prompt via regression test.
src/osintai/pivots.py Adds deterministic lead generation producing lookup URLs plus false-positive risk notes.
src/osintai/pipeline.py Adds post-crawl analysis orchestrator producing artifacts, optional model stages, and export gating.
src/osintai/patterns.py Adds deterministic checks (homoglyphs, sensitive infra, secret presence/JWT decode, generated text, outliers).
src/osintai/ollama_api.py Enforces loopback-only, credential-free base URLs; disables env proxy usage; adds health/model helpers.
src/osintai/normalize.py Narrows broad exception handling to ValueError.
src/osintai/multimodel.py Adds optional cross-model claim checks that preserve disagreement as findings.
src/osintai/hypotheses.py Adds deterministic hypothesis generation from findings and wraps model hypotheses with provenance.
src/osintai/fetcher.py Adds bounded HTML-only streaming fetch with redirect validation and response size enforcement.
src/osintai/extractor.py Hardens URL extraction by validating/normalizing regex matches and avoiding malformed URL crashes.
src/osintai/evaluation.py Adds deterministic rubric scoring for model output quality and weak-example selection.
src/osintai/entities.py Adds entity typing/normalization/indexing and extended extraction (unicode domains/handles, dates, secrets, etc.).
src/osintai/crawler.py Integrates prompt profiles, seed-host scoping, redirect policy enforcement, trust_env=False, and safer exception handling.
src/osintai/correlation.py Adds evidence-backed candidate-only correlation logic and domain mapping.
src/osintai/cli.py Expands CLI for v4 analysis options, run profiles, seed-file handling, run manifest, and startup Ollama health checks.
src/osintai/init.py Bumps version to 4.0.0 and exports analysis-layer modules.
src/osintai/dedupe.py Marks SHA1 usage as legacy artifact ID with usedforsecurity=False.
requirements.txt Pins runtime dependencies to exact versions.
README.md Updates documentation for v4 features, analysis layer, safety guardrails, and updated usage.
.gitignore Ignores additional generated directories/files.
.github/workflows/release-gate.yml Adds CI release gate: locked deps install, audit, tests, compile, bandit/ruff checks, and version assertion.
Suppressed comments (1)

src/osintai/patterns.py:370

  • The credential-shaped finding uses an evidence key named "values_recorded" while the token finding uses "value_recorded". Using one consistent key name across findings simplifies consumers.
                evidence={"pair_count": len(pairs), "values_recorded": False},

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/osintai/temporal.py
Comment on lines +104 to +108
for record in page_records or []:
url = record.get("url")
fetched_at = record.get("fetched_at")
if not url or not fetched_at:
continue
Comment thread src/osintai/cli.py
Comment on lines +224 to +225
if flag in argv:
continue
Comment thread src/osintai/patterns.py
"issuer": str(claims.get("iss", "")) if claims else "",
"audience": str(claims.get("aud", "")) if claims else "",
"expiry": str(claims.get("exp", "")) if claims else "",
"recorded_value": False,
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants