{"id":50953644,"url":"https://github.com/batu3384/ironsentinel","last_synced_at":"2026-06-18T04:02:37.695Z","repository":{"id":348587958,"uuid":"1198826797","full_name":"batu3384/ironsentinel","owner":"batu3384","description":"Local-first AppSec CLI for guided scans, runtime trust checks, and evidence-rich reporting.","archived":false,"fork":false,"pushed_at":"2026-04-27T22:45:50.000Z","size":2713,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-04-28T00:24:40.992Z","etag":null,"topics":["appsec","bubbletea","cli","go","sarif","security"],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/batu3384.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-04-01T19:50:34.000Z","updated_at":"2026-04-27T22:45:54.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/batu3384/ironsentinel","commit_stats":null,"previous_names":["batu3384/ironsentinel"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/batu3384/ironsentinel","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/batu3384%2Fironsentinel","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/batu3384%2Fironsentinel/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/batu3384%2Fironsentinel/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/batu3384%2Fironsentinel/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/batu3384","download_url":"https://codeload.github.com/batu3384/ironsentinel/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/batu3384%2Fironsentinel/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34475375,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-18T02:00:06.871Z","response_time":128,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["appsec","bubbletea","cli","go","sarif","security"],"created_at":"2026-06-18T04:02:36.686Z","updated_at":"2026-06-18T04:02:37.687Z","avatar_url":"https://github.com/batu3384.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# IronSentinel\n\n\u003cp align=\"center\"\u003e\n  \u003cstrong\u003eLocal-first AppSec command center for scanning source trees, verifying runtime trust, reviewing findings, and exporting evidence-rich reports.\u003c/strong\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg alt=\"Go 1.25+\" src=\"https://img.shields.io/badge/Go-1.25%2B-00ADD8?style=flat-square\u0026logo=go\u0026logoColor=white\"\u003e\n  \u003cimg alt=\"Interface\" src=\"https://img.shields.io/badge/Interface-CLI%20%2B%20TUI-0f172a?style=flat-square\"\u003e\n  \u003cimg alt=\"Reports\" src=\"https://img.shields.io/badge/Reports-SARIF%20%7C%20CSV%20%7C%20HTML-0b7285?style=flat-square\"\u003e\n  \u003cimg alt=\"Language\" src=\"https://img.shields.io/badge/Language-EN%20%2F%20TR-1d4ed8?style=flat-square\"\u003e\n  \u003cimg alt=\"Mode\" src=\"https://img.shields.io/badge/Workflow-Local--first-111827?style=flat-square\"\u003e\n  \u003cimg alt=\"License\" src=\"https://img.shields.io/badge/License-MIT-166534?style=flat-square\"\u003e\n\u003c/p\u003e\n\n`IronSentinel` is the primary product and `ironsentinel` is the primary binary.\n\nWhen you run `ironsentinel` in an interactive terminal, it opens the primary single-console operator surface by default. That surface stays in one continuous `Launch -\u003e Mission -\u003e Debrief` flow, with drawers for findings, runtime trust, and run evidence instead of bouncing operators across separate top-level routes. The platform keeps project history locally, runs guided security missions, normalizes findings into one model, and exports shareable reports without requiring a hosted control plane.\n\n## Why IronSentinel\n\n- local-first security workflow with data stored under `runtime/data/state.db`\n- fullscreen single-console operator flow for launch, mission execution, debrief, and evidence review\n- built-in heuristic coverage plus external scanner orchestration when trusted tools are available\n- evidence-aware runs with artifacts, execution journals, retry state, and exportable reports\n- bilingual operator experience with `English` and `Turkish`\n- shell-safe fallbacks for `NO_COLOR`, non-interactive output, and reduced motion\n\n## Product Surfaces\n\nThe screenshots below show the primary single-console workflow and its debrief-oriented evidence drawers. Route-based compatibility surfaces still exist for migration, but they are no longer the product model to learn first.\n\nThe screenshots below are generated from the real product UI against this repository using a core scan, so the findings queue intentionally shows seeded test fixtures.\n\n| Command center | Guided scan review |\n| --- | --- |\n| ![IronSentinel command center](docs/assets/readme/home.png) | ![IronSentinel scan review](docs/assets/readme/review.png) |\n| Run ledger | Analyst queue |\n| ![IronSentinel runs view](docs/assets/readme/runs.png) | ![IronSentinel findings view](docs/assets/readme/findings.png) |\n\n## Core Workflow\n\n1. Prepare the trusted runtime.\n\n   ```bash\n   ironsentinel setup --target auto --coverage premium\n   ironsentinel runtime doctor --mode safe --require-integrity\n   ```\n\n2. Open the single-console operator surface.\n\n   ```bash\n   ironsentinel --lang en\n   ```\n\n3. Launch a scan from the single-console launch stage or directly from the CLI.\n\n   ```bash\n   ironsentinel scan /absolute/path --coverage core\n   ironsentinel scan /absolute/path --coverage premium\n   ironsentinel scan /absolute/path --coverage full\n   ```\n\n4. Review findings, compare runs, and export reports.\n\n   ```bash\n   ironsentinel findings --run \u003crun-id\u003e\n   ironsentinel runs show \u003crun-id\u003e\n   ironsentinel export \u003crun-id\u003e --format html --output runtime/output/report.html\n   ironsentinel runs gate \u003crun-id\u003e --vex-file ./triage.openvex.json\n   ```\n\n## Authenticated DAST Profiles\n\nReusable DAST auth profiles let you keep target selection separate from credential wiring.\n\nGenerate canonical templates directly from the CLI:\n\n```bash\nironsentinel dast auth-template\nironsentinel dast auth-template form\n```\n\nExample `dast-auth.json`:\n\n```json\n{\n  \"profiles\": [\n    {\n      \"name\": \"staging-bearer\",\n      \"type\": \"bearer\",\n      \"secretEnv\": \"STAGING_API_TOKEN\",\n      \"sessionCheckUrl\": \"https://api.example.test/me\",\n      \"sessionCheckPattern\": \"200 OK\"\n    }\n  ]\n}\n```\n\nUse the profile file together with explicit target-to-profile bindings:\n\n```bash\nironsentinel dast plan \u003cproject-id\u003e \\\n  --target api=https://api.example.test \\\n  --target-auth api=staging-bearer \\\n  --dast-auth-file ./dast-auth.json\n```\n\nThe same flags work on `scan`, so authenticated API validation can flow through the normal review, run, and export pipeline without changing the rest of the command surface.\n\n## Coverage Model\n\nIronSentinel ships with always-on heuristics and then expands into deeper coverage when pinned tools are available on `PATH` or through the managed runtime bundle.\n\n| Lane | Built-in coverage | External adapters |\n| --- | --- | --- |\n| Surface \u0026 repo exposure | stack detection, surface inventory, script audit, runtime config audit | semgrep, staticcheck |\n| Code \u0026 secrets | secret heuristics, evidence capture, execution journals | gitleaks, govulncheck, knip, vulture, codeql |\n| Dependencies \u0026 supply chain | dependency confusion checks, normalized supply-chain findings | syft, trivy, osv-scanner, grype |\n| Infrastructure \u0026 config | runtime and IaC heuristics | checkov |\n| Malware \u0026 suspicious payloads | malware signatures, EICAR validation, binary entropy checks | clamscan |\n| Active validation | launch planning and trust gating | nuclei, OWASP ZAP Automation Framework |\n\nDefault scans use `premium` coverage. For a portable built-in-only pass on a fresh machine, use `--coverage core`.\n\n## Environment Precedence\n\nIronSentinel uses the `IRONSENTINEL_*` product namespace.\n\n- preferred: `IRONSENTINEL_*`\n- compatibility during migration: `APPSEC_*`\n- precedence: canonical `IRONSENTINEL_*` values win when multiple aliases are set\n\nExamples:\n\n```bash\nIRONSENTINEL_LANG=tr\nIRONSENTINEL_TOOLS_DIR=/opt/ironsentinel/tools\nIRONSENTINEL_CONTAINER_IMAGE=ghcr.io/batu3384/ironsentinel-scanner-bundle:latest\n```\n\n## Reporting And Evidence\n\nEvery scan can persist:\n\n- normalized findings with severity, triage state, and review metadata\n- module manifests with command, working directory, environment allowlist, and exit code\n- execution journals including retry, timeout, and failure taxonomy\n- local evidence files for heuristic detections\n- raw scanner outputs when external tools emit structured results\n\nExport formats:\n\n- `HTML` for human-readable review\n- `SARIF` for code scanning and CI integrations\n- `CSV` for operational handoff and spreadsheet workflows\n- `OpenVEX` for package-level vulnerability status exchange\n- `SBOM attestation` for signed or auditable SBOM provenance handoff\n\nExamples:\n\n```bash\nironsentinel export \u003crun-id\u003e --format html --output runtime/output/report.html\nironsentinel export \u003crun-id\u003e --format sarif --baseline \u003cbaseline-run-id\u003e\nironsentinel export \u003crun-id\u003e --format csv --output runtime/output/findings.csv\nironsentinel export \u003crun-id\u003e --format openvex --vex-file ./triage.openvex.json\nironsentinel export \u003crun-id\u003e --format sbom-attestation \u003e runtime/output/sbom-attestation.json\nironsentinel runs verify-sbom-attestation \u003crun-id\u003e --file runtime/output/sbom-attestation.json\nironsentinel runs policy \u003crun-id\u003e --policy premium-default --vex-file ./triage.openvex.json\n```\n\n## GitHub Publishing\n\nIronSentinel includes a GitHub publishing flow for pushing scan evidence into GitHub-native security surfaces.\n\n```bash\nironsentinel github export-custom-patterns\nironsentinel github upload-sarif \u003crun-id\u003e --repo owner/repo\nironsentinel github submit-deps \u003cproject-id\u003e --repo owner/repo\nironsentinel setup install-pre-push\n```\n\n`export-custom-patterns` emits IronSentinel's high-confidence secret rules in a GitHub custom-pattern-friendly JSON manifest so operators can mirror the same token coverage inside GitHub secret scanning. `upload-sarif` exports the selected run as SARIF and uploads it to GitHub code scanning. `submit-deps` builds a dependency snapshot from the most recent usable inventory for the selected project and submits it to the GitHub dependency graph.\n\n`setup install-pre-push` installs a local git hook that runs `ironsentinel github push-protect` before every push. The guard scans the outgoing commit set and blocks the push only when it finds high-confidence secrets such as GitHub personal access tokens or AWS access keys.\n\nAuthentication is resolved in this order:\n\n- `GITHUB_TOKEN`\n- `GH_TOKEN`\n- `gh auth token`\n\nBoth commands resolve repository, ref, and commit metadata from the project workspace when available, and accept `--repo`, `--ref`, `--sha`, and command-specific selectors such as `--baseline` or `--run` when you need to override the inferred context.\n\n## Remediation Campaigns\n\nCampaigns group selected findings into a local remediation work item before they are published to GitHub Issues. The workflow stays local-first until you explicitly publish it.\n\n```bash\nironsentinel campaigns create --project \u003cproject-id\u003e --run \u003crun-id\u003e --finding \u003cfingerprint\u003e\nironsentinel campaigns list --project \u003cproject-id\u003e\nironsentinel campaigns show \u003ccampaign-id\u003e\nironsentinel campaigns publish-github \u003ccampaign-id\u003e --repo owner/repo\n```\n\nThe fullscreen command center surfaces campaign hints in the run and finding detail panes so operators can jump from triage to campaign creation without leaving the existing workflow.\n\n## Command Map\n\n| Job | Command |\n| --- | --- |\n| Open the fullscreen command center | `ironsentinel` |\n| Open the static posture overview | `ironsentinel overview` |\n| Run a guided scan mission | `ironsentinel scan /absolute/path --coverage premium` |\n| Register the current project | `ironsentinel init` |\n| Pick a folder and start scanning | `ironsentinel scan --picker` |\n| Inspect findings | `ironsentinel findings --run \u003crun-id\u003e` |\n| Review a single finding interactively | `ironsentinel review \u003cfingerprint\u003e --run \u003crun-id\u003e` |\n| Inspect recent runs | `ironsentinel runs list` / `ironsentinel runs show \u003crun-id\u003e` |\n| Watch the queue or a specific run | `ironsentinel runs watch \u003crun-id\u003e` |\n| Apply OpenVEX to gates and policy | `ironsentinel runs gate \u003crun-id\u003e --vex-file triage.openvex.json` / `ironsentinel runs policy \u003crun-id\u003e --vex-file triage.openvex.json` |\n| Verify exported SBOM provenance | `ironsentinel runs verify-sbom-attestation \u003crun-id\u003e --file sbom-attestation.json` |\n| Manage remediation campaigns | `ironsentinel campaigns list|show|create|add-findings|publish-github` |\n| Validate runtime trust | `ironsentinel runtime doctor --mode safe --require-integrity` |\n| Run the queue worker once or continuously | `ironsentinel daemon --once` / `ironsentinel daemon` |\n| Export reports and evidence | `ironsentinel export \u003crun-id\u003e --format html|sarif|csv|openvex|sbom-attestation` |\n| Export GitHub secret scanning patterns | `ironsentinel github export-custom-patterns` |\n| Publish scan evidence to GitHub | `ironsentinel github upload-sarif \u003crun-id\u003e` / `ironsentinel github submit-deps \u003cproject-id\u003e` |\n| Install local push protection | `ironsentinel setup install-pre-push` |\n\nCompatibility commands such as `console`, `open`, `pick`, and `tui` remain callable for migration, but they are hidden from primary help and redirect operators toward the canonical single-console workflow above.\n\n## Accessibility And Operator Fallbacks\n\n- `NO_COLOR=1` switches styled command surfaces to plain shell-safe output.\n- `IRONSENTINEL_REDUCED_MOTION=1` disables non-essential TUI animation.\n- `ironsentinel config language en|tr` persists the preferred interface language.\n- `ironsentinel config ui-mode standard|plain|compact` stores the preferred TUI density mode.\n\n## Build From Source\n\n```bash\ngo mod tidy\ngo build ./cmd/ironsentinel\n```\n\nThe project targets Go `1.25.x`.\n\n## Local Quality Gate\n\nRun the same local quality gate used by release validation:\n\n```bash\nbash scripts/quality_local.sh\n```\n\nThis executes:\n\n- `go test ./...`\n- `bash scripts/coverage_gate.sh`\n- `go vet ./...`\n- `staticcheck ./...`\n- `golangci-lint run --config .golangci.yml --concurrency 2 ./...`\n- a core self-scan with `ironsentinel`\n\nCoverage artifacts are written to:\n\n- `coverage/internal.out`\n- `coverage/internal-summary.txt`\n- `coverage/internal-packages.txt`\n\nDefault minimum internal coverage is `45.0%` and can be overridden with `COVERAGE_MIN`.\n\n## Repository Layout\n\n| Path | Purpose |\n| --- | --- |\n| `cmd/ironsentinel` | main product binary |\n| `cmd/releasectl` | release verification and lock hydration tooling |\n| `internal/cli` | command center UI, shell-safe surfaces, and command routing |\n| `internal/agent` | scanner orchestration, runtime probing, and module adapters |\n| `internal/core` | stateful workflows, portfolio data, findings, and runtime doctor |\n| `internal/reports` | HTML, SARIF, and CSV export paths |\n| `internal/store` | local SQLite state store |\n| `scripts` | local quality gate, smoke checks, and release automation |\n| `docs` | active architecture and release discipline docs |\n| `docs/archive` | historical audits, reviews, and remediation snapshots |\n\n## Runtime And Release Discipline\n\n- support matrix and capability tiers: [`docs/release-discipline.md`](docs/release-discipline.md)\n- system architecture: [`docs/architecture.md`](docs/architecture.md)\n- setup + runtime smoke check: `bash scripts/smoke_setup_doctor.sh`\n- shell guard smoke check: `bash scripts/smoke_shell_guards.sh`\n- Windows shell guard smoke check: `pwsh scripts/smoke_shell_guards.ps1`\n- release publish preflight: `bash scripts/release_publish_preflight.sh --version vX.Y.Z --require-signing --require-tag`\n- release artifact preflight: `bash scripts/release_artifact_preflight.sh --dir dist/vX.Y.Z --require-signing --require-external-attestation`\n\n## Representative Commands\n\n```bash\ngo run ./cmd/ironsentinel\ngo run ./cmd/ironsentinel overview\ngo run ./cmd/ironsentinel scan /absolute/path --coverage core\ngo run ./cmd/ironsentinel scan /absolute/path --coverage premium --fail-on-new high\ngo run ./cmd/ironsentinel findings --severity high --limit 20\ngo run ./cmd/ironsentinel runs show \u003crun-id\u003e\ngo run ./cmd/ironsentinel runtime doctor --mode safe --require-integrity\ngo run ./cmd/ironsentinel export \u003crun-id\u003e --format html --output runtime/output/report.html\ngo run ./cmd/ironsentinel github export-custom-patterns\ngo run ./cmd/ironsentinel github upload-sarif \u003crun-id\u003e --repo owner/repo\ngo run ./cmd/ironsentinel github submit-deps \u003cproject-id\u003e --repo owner/repo\ngo run ./cmd/ironsentinel setup install-pre-push\ngo run ./cmd/releasectl verify --dir dist/\u003cversion\u003e --lock scanner-bundle.lock.json --require-signature --require-attestation --require-external-attestation\n```\n\nFor the full command surface, run:\n\n```bash\nironsentinel --help\nironsentinel \u003ccommand\u003e --help\n```\n\n## License\n\nIronSentinel is available under the [MIT License](LICENSE).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbatu3384%2Fironsentinel","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbatu3384%2Fironsentinel","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbatu3384%2Fironsentinel/lists"}