whitebox-secure-scan
whitebox-secure-scan is an offline, read-only white-box secure-code triage tool for penetration testers. It identifies high-signal security review leads, records precise file and line evidence, groups related instances into root causes, and provides reviewer guidance.
It is designed to accelerate source-code review not to replace a penetration tester, confirm exploitability automatically, or generate a final pentest report. Every candidate requires independent verification by an authorized security engineer.
It scans Python 3.11+, JavaScript/TypeScript, Java, and Go locally. It does not import, execute, upload, or modify target code and does not contact package registries or external AI services during scans.
Install and run
python3 -m venv .venv && . .venv/bin/activate
python -m pip install -e ".[dev]"
whitebox-secure-scan review /path/to/repository --output ./whitebox-results
The normal review workflow keeps only the useful review outputs: SUMMARY.md, report.md, findings.json, root-causes.json, and review-points.json. Detailed inventory, routes, metadata, SARIF, and handoff packaging remain available through advanced compatibility commands. Results are review leads, not automatic vulnerability confirmations.
Scope
The engine combines Python AST parsing, structured lexical analysis for the other supported languages, framework evidence detection, conservative source/sink heuristics, secret redaction, confidence scoring, duplicate suppression, route inventory, normalized reporting, safety-bounded walking, and local adapter interfaces. Findings are review leads or review points, not confirmed vulnerabilities.
Java uses a structured lexical fallback that removes comments/Javadocs, masks string literals for API matching, and requires observable method or constructor invocation. It distinguishes code surfaces such as production, test, utility, demo, generated, and configuration. Findings include verdict_candidate, code_surface, proof_gaps, counterevidence, parser metadata, and source/sink diagnostics.
JavaScript and TypeScript use the same conservative structured-lexical approach when an optional AST parser is unavailable. Upload findings require both an uploaded-file source and a write/storage sink; blob responses, report downloads, browser exports, API wrappers, identifiers, comments, and UI labels are not upload or execution evidence. Dynamic execution requires an invocation of eval, Function, vm, or a child_process API. Literal-secret findings require a credential-shaped value, while environment-variable lookups and labels such as Change Password are excluded.
The normal command is whitebox-secure-scan review /path/to/repository. Other commands are advanced support utilities. See the compact technical reference.
Triage commands are sample-unreported for deterministic negative-review candidates and compare for old/new result comparison. Use --production-only for production results, --include-test-code to inspect ordinary test code, --include-test-secrets to retain test-source secrets, and --root-causes-only when consuming grouped results.
The operational workflow is: scan to an output directory outside the target, inspect the concise summary and evidence, optionally send the bounded handoff package to an approved internal verifier, then manually validate candidates. Default controls are offline operation, redaction, no repository execution, no external tools, bounded file reads, no symlink following, and no writes to the target repository.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file whitebox_secure_scan-1.0.1.tar.gz.
File metadata
- Download URL: whitebox_secure_scan-1.0.1.tar.gz
- Upload date:
- Size: 42.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8a3fbfe101d9124e1cc8947d5679dac4017d1978a9e8a34097d3df39ceeb12af
|
|
| MD5 |
692964c555f6adeac18c650c690df195
|
|
| BLAKE2b-256 |
442b5e8207fa4f97358d658be1bb719130b8d3ae3bbb536c8b245c7871315550
|
Provenance
The following attestation bundles were made for whitebox_secure_scan-1.0.1.tar.gz:
Publisher:
publish.yml on Waariss/whitebox-secure-scan
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
whitebox_secure_scan-1.0.1.tar.gz -
Subject digest:
8a3fbfe101d9124e1cc8947d5679dac4017d1978a9e8a34097d3df39ceeb12af - Sigstore transparency entry: 2205247423
- Sigstore integration time:
-
Permalink:
Waariss/whitebox-secure-scan@b2c1860f69335e9f3342b128e5813fa835b73d6b -
Branch / Tag:
refs/tags/v1.0.1 - Owner: https://github.com/Waariss
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@b2c1860f69335e9f3342b128e5813fa835b73d6b -
Trigger Event:
release
-
Statement type:
File details
Details for the file whitebox_secure_scan-1.0.1-py3-none-any.whl.
File metadata
- Download URL: whitebox_secure_scan-1.0.1-py3-none-any.whl
- Upload date:
- Size: 44.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8f30455d002ff290e9af1552f3f726378aa533a0a44e2bb9b0f175605eea59ad
|
|
| MD5 |
351c2c84691b63d173d36c7cd8f108d8
|
|
| BLAKE2b-256 |
0a619ab98ceea008154a6150cd7dca2ec6e6485ca40b4e268a939e27e97ecb17
|
Provenance
The following attestation bundles were made for whitebox_secure_scan-1.0.1-py3-none-any.whl:
Publisher:
publish.yml on Waariss/whitebox-secure-scan
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
whitebox_secure_scan-1.0.1-py3-none-any.whl -
Subject digest:
8f30455d002ff290e9af1552f3f726378aa533a0a44e2bb9b0f175605eea59ad - Sigstore transparency entry: 2205247450
- Sigstore integration time:
-
Permalink:
Waariss/whitebox-secure-scan@b2c1860f69335e9f3342b128e5813fa835b73d6b -
Branch / Tag:
refs/tags/v1.0.1 - Owner: https://github.com/Waariss
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@b2c1860f69335e9f3342b128e5813fa835b73d6b -
Trigger Event:
release
-
Statement type: