Repository navigation
🔧 chore(deps): bump rsigma from 0.22 to 0.23 - #100
Merged
Merged
Conversation
0.23.0 is API-compatible for sigmacatch: set_cross_rule_ac, explain_rule, save_hir/load_hir and the parser surface are unchanged. HIR cache schema moves 1 -> 2; the existing load fallback (warn + recompile) covers the one-time cold start. The |neq semantic fix affects zero rules in the SigmaHQ corpus.
Includes yoke-derive 0.8.3 -> 0.8.4, resolving the yanked-version warning from cargo audit. No direct dependency pins changed; ssh-key 0.7 is RC-only and skipped. Remaining audit warning is encoding 0.2.33 (unmaintained, transitive via evtx — upstream).
- runner: drop the BUILD_TIME build-date stamp (never set by build.rs or CI, always logged as 'unknown') - build.rs: drop the always-on ebpf_script_trace.txt / ebpf_build_failure.txt OUT_DIR traces (read by nothing) and a duplicated comment - detection: delete the three debug_* registry tests left from the hidden-user bloom/pruning isolation; the real matching test stays
- repo/plumbing: remove two no-op #[allow(unused_imports)] on pub(crate) re-exports; import setup_sparse_checkout via the facade in porcelain.rs like every other plumbing call - fixtures READMEs: point at sigmacatch/src/regression/evtx_writer.rs (crates/sigmacatch-regression no longer exists since the workspace merge), drop dangling .agents/skills/sigmacatch-reggen/ pointer, rename sigmacatch-linux to sigmacatch in the .log regen recipe
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
Bump
rsigmafrom 0.22 to 0.23 (HIR cache schema 1→2,|neqsemantics,daachorse-indexfeature) and clean up the tree around it: the lockfile is brought fully up to date within semver ranges, and debug leftovers from the bloom/pruning session are removed. No behavioral change for sigmacatch: zero SigmaHQ rules use|neq, and the HIR cache version bump is handled by the existingload_hirfallback (warn + recompile on first run).What's new
sigmacatch— dependenciesrsigma+rsigma-parser0.22 → 0.23 (sigmacatch/Cargo.toml)Cargo.lock: 12 patches within semver ranges (tokio 1.53.2, libc 0.2.190, cc 1.6.0, uuid 1.27.0, serde_with 3.24.0, yoke-derive 0.8.4 unyanked, quinn-proto/udp, mio, lazy_static, tokio-rustls)cargo audit: 0 vulnerabilities (residual:encoding 0.2.33unmaintained, transitive viaevtx— upstream)sigmacatch— debug cleanuprunner.rs: dropBUILD_TIMEstamp (never set bybuild.rsor CI — always logged "unknown")build.rs: drop always-onebpf_script_trace.txt/ebpf_build_failure.txtdebug writes, dedupe commentdetection/mod.rs: remove 3 debug tests from the bloom/pruning session (−200 lines); the real Sysmon EventID 13 matching test is keptsigmacatch— repoplumbing/mod.rs: remove two no-op#[allow(unused_imports)]onpub(crate)re-exports;porcelain.rsnow importssetup_sparse_checkoutvia the facade like every other plumbing callDocs
sigmacatch/src/regression/evtx_writer.rs(thecrates/sigmacatch-regressionpath predates the workspace merge), drop danglingsigmacatch-reggenskill pointer, renamesigmacatch-linux→sigmacatchin the.logregen recipeCHANGELOG.md:[Unreleased]sectionChanged files (10)
sigmacatch/Cargo.toml,Cargo.lock— rsigma 0.23 + lockfile patchessigmacatch/src/runner.rs,sigmacatch/build.rs,sigmacatch/src/detection/mod.rs— debug leftoverssigmacatch/src/repo/plumbing/mod.rs,sigmacatch/src/repo/porcelain.rs— dead allows, facade consistencysigmacatch/tests/fixtures/README.md,sigmacatch/tests/fixtures/sigma/README.md— stale post-refactor referencesCHANGELOG.md—[Unreleased]Full list:
git diff --stat main...HEAD(53 insertions, 260 deletions)Testing
cargo fmt --check— passedcargo clippy --all-targets -- -W warnings— passedcargo clippy --no-default-features --features auditd,builtin,sysmon --all-targets— passed (no dead code in the Linux combo)cargo clippy --no-default-features --features evtx --all-targets— passedcargo test --locked— passed (380 tests, 0 failures; 3 debug tests removed)cargo xwin build --release --target x86_64-pc-windows-msvc— deferred to CI (Linux host)regressiondata-checkagainstsigma/regression_data— deferred to CI (rules clone not present on this host)How to build / run
First run after the upgrade recompiles the HIR cache (schema 2) — expected one-time cold start, logged as a warning.