release-readiness: go/no-go for the next htpx release — 2026-07-16
Confirmed: 5 new entry files added (2 pairs + 1 recon), asrep-probing-4771.md modified in place — no removed or renamed entry ids, so nothing breaking.
✅ READY to cut v2.4.0
What would ship — the release story
GCP reaches big-three parity (the headline, a feat):
- Persistence (
T1098) — gcp-iam-policy-backdoor ↔ gcp-iam-policy-audit: IAM policy backdoor via setIamPolicy, detected on the SetIamPolicy ADD binding delta.
- Defense Evasion (
T1562.008) — gcp-audit-log-disable ↔ gcp-audit-log-tamper-audit: Cloud Audit log tamper (DeleteSink / auditConfigs strip), detected via self-witnessing Admin Activity events.
- Discovery (
T1580/T1526/T1069.003) — unpaired gcp-enum-recon (projects / Asset Inventory / IAM blast-radius), mirroring the on-prem smb-enum-nxc recon entry.
- Net: +4 paired entries + 1 recon entry, GCP from a single pair to rough parity.
Detection-quality fix (a fix, folded in):
asrep-probing-4771 retargeted to the real AS-REP roast artifact — now keys on a successful 4768 with pre-auth type 0 (the roastable AS-REP its red mate emits), keeping the 4771 0x18 burst as a secondary Kerbrute-enum tell. Previously it only saw the collateral probing, not the roast.
Proposed version + why → v2.4.0 (minor)
- Last tag
v2.3.0 matches the top released heading — version line is coherent.
- The bump is driven by new corpus entries (the two GCP pairs + recon entry = a
feat) → minor.
- Nothing breaking: the
asrep retarget edits the entry in place — same id, same file, no {{slot}} vocabulary change, no removed field. The diff confirms 5 files added, 1 modified, 0 removed/renamed. So this is not a major.
- Patch would undersell it — this adds coverage, not just corrections.
Blockers / pre-flight — maintainer must tick (I run sandboxed; no CI/gh/web access)
Both are confirmations, not checks I performed.
Downstream awareness (context, not a blocker)
Cutting the tag fires auto-tag.yml → GitHub Release, then sync-fanout.yml opens a companion.lock-bump PR against dotfiles-Kali (offensive/companion/). Expect that Kali PR — the two new GCP pairs will fan out there.
Next step (when the two boxes are ticked)
In CHANGELOG.md, add a new heading under [Unreleased]:
Move the current ### Added (GCP parity) and ### Changed (asrep retarget) entries beneath it, leaving [Unreleased] empty, and push to main. auto-tag.yml reads that top heading, tags v2.4.0, and publishes the Release; sync-fanout.yml handles the Kali fan-out.
Report only — I have not edited CHANGELOG.md, tagged, or run auto-tag.sh. The release is yours to drive.
Filed by the claude-routines workflow. Report-first: review and act — nothing was changed.
release-readiness: go/no-go for the next htpx release — 2026-07-16
Confirmed: 5 new entry files added (2 pairs + 1 recon),
asrep-probing-4771.mdmodified in place — no removed or renamed entry ids, so nothing breaking.✅ READY to cut v2.4.0
What would ship — the release story
GCP reaches big-three parity (the headline, a
feat):T1098) —gcp-iam-policy-backdoor↔gcp-iam-policy-audit: IAM policy backdoor viasetIamPolicy, detected on theSetIamPolicyADDbinding delta.T1562.008) —gcp-audit-log-disable↔gcp-audit-log-tamper-audit: Cloud Audit log tamper (DeleteSink/auditConfigsstrip), detected via self-witnessing Admin Activity events.T1580/T1526/T1069.003) — unpairedgcp-enum-recon(projects / Asset Inventory / IAM blast-radius), mirroring the on-premsmb-enum-nxcrecon entry.Detection-quality fix (a
fix, folded in):asrep-probing-4771retargeted to the real AS-REP roast artifact — now keys on a successful4768with pre-auth type 0 (the roastable AS-REP its red mate emits), keeping the4771 0x18burst as a secondary Kerbrute-enum tell. Previously it only saw the collateral probing, not the roast.Proposed version + why → v2.4.0 (minor)
v2.3.0matches the top released heading — version line is coherent.feat) → minor.asrepretarget edits the entry in place — sameid, same file, no{{slot}}vocabulary change, no removed field. The diff confirms 5 files added, 1 modified, 0 removed/renamed. So this is not a major.Blockers / pre-flight — maintainer must tick (I run sandboxed; no CI/gh/web access)
ci.ymlis green onmain— pairing +{{slot}}+ view-drift + shell lint all passing at HEAD (c13b2f0).corpus-reviewissue flags something that should ride with or block this release (e.g. an ATT&CK-ID or pairing finding on the new GCP entries).Both are confirmations, not checks I performed.
Downstream awareness (context, not a blocker)
Cutting the tag fires
auto-tag.yml→ GitHub Release, thensync-fanout.ymlopens acompanion.lock-bump PR againstdotfiles-Kali(offensive/companion/). Expect that Kali PR — the two new GCP pairs will fan out there.Next step (when the two boxes are ticked)
In
CHANGELOG.md, add a new heading under[Unreleased]:Move the current
### Added(GCP parity) and### Changed(asrep retarget) entries beneath it, leaving[Unreleased]empty, and push tomain.auto-tag.ymlreads that top heading, tagsv2.4.0, and publishes the Release;sync-fanout.ymlhandles the Kali fan-out.Report only — I have not edited
CHANGELOG.md, tagged, or runauto-tag.sh. The release is yours to drive.Filed by the claude-routines workflow. Report-first: review and act — nothing was changed.