# Changelog | Chainsaw

> Notable changes to Chainsaw — supply-chain attack signals, CLI authentication, cross-platform binaries, and more. Keep-a-Changelog format.

Source: https://chain305.com/changelog/

---

Changelog

# What's shipped recently

Notable changes in plain English. Source, issues, and release detail live in the [open-core repository](https://github.com/chain305/chainsaw-core).

1.  Security 2026-07-07 v0.19.3
    
    ## AI model scanning reads inside zip-container checkpoints
    
    PyTorch has saved .pt/.bin as a zip archive since 2020, with the pickle nested at archive/data.pkl — the format ~99% of Hugging Face models ship in. Chainsaw now unwraps the container before the pickle scan, so a malicious os.system buried inside a real checkpoint is caught, not just hand-crafted raw .pkl files. The opcode walker also models the pickle stack and memo, closing STACK\_GLOBAL and byte-encoded-module evasions that dodge a naive text scan.
    
    [Read more →](https://chain305.com/product/policy/)
    
2.  Changed 2026-06-26 v0.18.0
    
    ## One-command guard setup, plus an honest first run and doctor
    
    chainsaw guard init --install writes the guard hook into your shell rc in one command — no copy-paste. guard update now shows live download progress so a slow dataset pull doesn't read as a hang. The first-run telemetry prompt defaults to yes with a plain-language disclaimer of exactly what's shared, and stays silent in CI. doctor's manager table is realigned and now reports a 'shim' state, so a manager protected by the shell guard no longer reads as unprotected.
    
    [Read more →](https://chain305.com/quickstart/)
    
3.  Added 2026-05-24 v0.18.0
    
    ## Linux distro CVE detection — Alpine, Debian, Red Hat, Oracle Linux
    
    Native CVE detectors per distro, with each stream updating on its own cadence — distinct from upstream OSV. A vendor advisory becomes a block-list entry the same hour the distro publishes it. Modular ingest means an Alpine stall doesn't hold up Red Hat coverage.
    
    [Read more →](https://chain305.com/product/policy/)
    
4.  Added 2026-05-22 v0.18.0
    
    ## Bundled Hugging Face malware feed
    
    Native HF coordinate-match feed shipped in-process — closes the gap where public SCA indexes lag on model-repo malware. Lookup is constant-time at resolve; a hit drops trust score to -100.
    
    [Read more →](https://chain305.com/product/policy/)
    
5.  Added 2026-05-21 v0.18.0
    
    ## chainsaw doctor verify-hook and doctor logs
    
    Two new CLI subcommands. verify-hook detects client-side install-hook bypasses — a developer skipping the proxy via .npmrc edits or env overrides now shows up in doctor output. doctor logs surfaces operator-actionable WARN lines from the server so on-call doesn't have to grep raw stdout.
    
6.  Changed 2026-05-20 v0.17.1
    
    ## Docker OCI inspector and Swift git-fallback ON by default
    
    Per-layer image inspection and Swift's git-tag fallback no longer need an opt-in flag. New deployments get container depth and Swift coverage out of the box. Existing installs keep their explicit config; the default only changes when the flag is unset.
    
7.  Added 2026-05-15 v0.17.0
    
    ## Silent-success write telemetry + SQL tripwire
    
    published\_to\_inventory counters, drop counters, and a SQL tripwire fire when a write looks like it succeeded but didn't land. Six operator log lines were promoted DEBUG→WARN so the cases that used to need code-reading now show up in doctor logs.
    
8.  Added 2026-05-10 v0.17.0
    
    ## VEX-aware exception CLI
    
    chainsaw exception create now accepts --cve, --decision, and --vex-note. Exceptions carry VEX semantics — not\_affected, affected, fixed, under\_investigation — so the audit log answers vendor questionnaires directly.
    
9.  Added 2026-05-05 v0.17.0
    
    ## chainsaw cargo-credentials — credential provider for cargo 1.74+
    
    Cargo's native credential-provider protocol now has a first-class Chainsaw integration. No more .cargo/config.toml token-in-plaintext patterns; the provider sources credentials from the OS keyring.
    
10.  Added 2026-04-18 v0.16.0
     
     ## Supply-chain attack signals catalogue
     
     Install-script exfiltration, maintainer takeover, version anomalies, hidden Unicode, publish-velocity bursts, reserved-namespace dependency confusion, Docker malware feed, per-layer image enforcement, APT/Yum/DNF hash-chain provenance, typosquat across 15 ecosystems including Go, CocoaPods, and GitHub Actions, repo liveness plus ownership match, and checksum fail-closed enforcement — 25 signals total, composable in a single policy. Four run on every ecosystem (CVE, license, reserved namespaces, trust score); the rest light up where each registry exposes the metadata we need. See our per-ecosystem coverage matrix for the full grid.
     
     [Read more →](https://chain305.com/product/policy/)
     
11.  Added 2026-04-18 v0.16.0
     
     ## Browser-based CLI login with Turnstile
     
     chainsaw auth login now opens a browser to the dashboard and uses a device-code flow with Cloudflare Turnstile to block automated login attempts. Works on headless shells via a short code; works on desktop via redirect. Tokens land in the OS keyring — macOS Keychain, Windows Credential Manager, Linux secret-service.
     
12.  Added 2026-04-18 v0.16.0
     
     ## Cross-platform CLI binaries
     
     Builds for macOS (Intel and Apple Silicon), Linux (x86\_64, arm64), and Windows (x86\_64), each with a published SHA-256 checksum for download verification. The server URL can be baked into the binary at build time for air-gapped shipping. Sigstore-signed releases follow once the release-signer bot is provisioned.
     
13.  Changed 2026-04-18 v0.16.0
     
     ## Strict JWT mode is now default
     
     Chainsaw refuses to boot without CHAINSAW\_JWT\_SECRET or a persistent store to hold a generated secret. Multi-replica deployments are safer out of the box. Single-process dev still works with CHAINSAW\_STRICT\_JWT=0.
     
14.  Fixed 2026-04-18 v0.16.0
     
     ## FORCE\_HTTPS scheme upgrade for CLI auth
     
     The CLI login URL now honours FORCE\_HTTPS. Reverse-proxied Chainsaw deployments with TLS termination upstream no longer emit http:// redirects.
     
15.  Fixed 2026-04-18 v0.16.0
     
     ## Web UI URLs resolved via NEXT\_APP\_BASEPATH
     
     Dashboard URLs printed by the CLI during auth now respect NEXT\_APP\_BASEPATH and CHAINSAW\_WEB\_UI\_URL, so Chainsaw deployments on a subpath or a custom domain get correct browser links.
     

Want the whole history?

## CHANGELOG.md in the repo

Every release, every PR, every behaviour change — with engineering-level detail. The repo CHANGELOG uses Keep a Changelog format.

[View on GitHub](https://github.com/chain305/chainsaw-core/blob/main/CHANGELOG.md) [Talk to sales](https://cal.com/chain305/30min)
