Skip to content

release-readiness: go/no-go for the next htpx release #52

Description

@github-actions

release-readiness: go/no-go for the next htpx release — 2026-07-16

Confirmed: 5 new entry files added (2 pairs + 1 recon), asrep-probing-4771.md modified in place — no removed or renamed entry ids, so nothing breaking.


✅ READY to cut v2.4.0

What would ship — the release story

GCP reaches big-three parity (the headline, a feat):

  • Persistence (T1098) — gcp-iam-policy-backdoorgcp-iam-policy-audit: IAM policy backdoor via setIamPolicy, detected on the SetIamPolicy ADD binding delta.
  • Defense Evasion (T1562.008) — gcp-audit-log-disablegcp-audit-log-tamper-audit: Cloud Audit log tamper (DeleteSink / auditConfigs strip), detected via self-witnessing Admin Activity events.
  • Discovery (T1580/T1526/T1069.003) — unpaired gcp-enum-recon (projects / Asset Inventory / IAM blast-radius), mirroring the on-prem smb-enum-nxc recon entry.
  • Net: +4 paired entries + 1 recon entry, GCP from a single pair to rough parity.

Detection-quality fix (a fix, folded in):

  • asrep-probing-4771 retargeted to the real AS-REP roast artifact — now keys on a successful 4768 with pre-auth type 0 (the roastable AS-REP its red mate emits), keeping the 4771 0x18 burst as a secondary Kerbrute-enum tell. Previously it only saw the collateral probing, not the roast.

Proposed version + why → v2.4.0 (minor)

  • Last tag v2.3.0 matches the top released heading — version line is coherent.
  • The bump is driven by new corpus entries (the two GCP pairs + recon entry = a feat) → minor.
  • Nothing breaking: the asrep retarget edits the entry in place — same id, same file, no {{slot}} vocabulary change, no removed field. The diff confirms 5 files added, 1 modified, 0 removed/renamed. So this is not a major.
  • Patch would undersell it — this adds coverage, not just corrections.

Blockers / pre-flight — maintainer must tick (I run sandboxed; no CI/gh/web access)

  • ci.yml is green on main — pairing + {{slot}} + view-drift + shell lint all passing at HEAD (c13b2f0).
  • No open corpus-review issue flags something that should ride with or block this release (e.g. an ATT&CK-ID or pairing finding on the new GCP entries).

Both are confirmations, not checks I performed.

Downstream awareness (context, not a blocker)

Cutting the tag fires auto-tag.yml → GitHub Release, then sync-fanout.yml opens a companion.lock-bump PR against dotfiles-Kali (offensive/companion/). Expect that Kali PR — the two new GCP pairs will fan out there.

Next step (when the two boxes are ticked)

In CHANGELOG.md, add a new heading under [Unreleased]:

## [v2.4.0] - 2026-07-16

Move the current ### Added (GCP parity) and ### Changed (asrep retarget) entries beneath it, leaving [Unreleased] empty, and push to main. auto-tag.yml reads that top heading, tags v2.4.0, and publishes the Release; sync-fanout.yml handles the Kali fan-out.

Report only — I have not edited CHANGELOG.md, tagged, or run auto-tag.sh. The release is yours to drive.

Filed by the claude-routines workflow. Report-first: review and act — nothing was changed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions