Hammerhead

Released v0.1.0

Audit potentially untrusted software repositories on your own machine.

Hammerhead is a defensive security tool from Talarurus: a local-first command-line tool written in Go. Hammerhead is built around a security-focused SafeWalker architecture.

Release details

Current version
0.1.0
Status
Released
Category
Defensive security tooling
Language
Go
Interface
Command line
Model
Local-first
Findings
Security, Hygiene, Info
Reports
Terminal, JSON

Approach

How Hammerhead approaches repository auditing

Hammerhead is made for the moment before you trust a repository: when you have the code but have not yet decided to depend on it.

  1. Run it locally

    Use the Hammerhead CLI on your own machine, against a repository you want to examine.

  2. Audit the repository

    Hammerhead audits the potentially untrusted repository. Hammerhead is built around a security-focused SafeWalker architecture.

  3. Classify findings

    Each finding is reported as Security, Hygiene, or Info.

  4. Read the report

    Review results in the terminal, or take the JSON output into your own tools.

Architecture

SafeWalker

Hammerhead is built around a security-focused SafeWalker architecture.

Hammerhead is defensive security tooling for auditing potentially untrusted software repositories. It is local-first, written in Go, and reports Security, Hygiene, and Info findings in the terminal or as JSON.

Hammerhead Audit model Runs locally
Hammerhead audits a potentially untrusted repository on your machine, sorts findings into Security, Hygiene, and Info, and reports them in the terminal or as JSON.

Findings

Three finding classes

Hammerhead separates its findings into three classes. Each class is reported separately from the other two.

Security

Findings Hammerhead reports in the Security class, kept separate from Hygiene and Info findings.

Hygiene

Findings Hammerhead reports in the Hygiene class, kept separate from Security and Info findings.

Info

Findings Hammerhead reports in the Info class, kept separate from Security and Hygiene findings.

Reports

Terminal and JSON reports

The same findings, in the format that suits the job.

Terminal

A human-readable report for reviewing results directly in your shell.

JSON

Machine-readable output for scripts, pipelines, and other tools.

Model

Local-first, written in Go

Local-first

Hammerhead is local-first. Audits run on your own machine, where the repository already is.

Go command-line tool

Hammerhead is written in Go and used from the command line, so it fits manual review and scripted workflows alike.

Hammerhead v0.1.0 is released.

Follow Talarurus on GitHub for project updates. Found a vulnerability in Hammerhead? Report it privately.