A local-first security workbench for debugging findings from source to sink.
Detect → Normalize → Understand → Trace → Compare → Triage
Releases · Demo walkthrough · Architecture
No account. No telemetry. No cloud upload by DSW.
Scanners are replaceable producers. Security IR and the investigation workflow are the product.
A finding is a debuggable object: source location, independent data-flow paths, rule/CWE metadata, proposed fixes, provenance and a redacted raw result. DSW keeps that investigation local in a resizable IDE-style workbench.
- Open a repository or import SARIF 2.1.0.
- Filter SQLite-backed finding pages and open a finding in Monaco.
- Choose a trace path, step through source/propagation/sink, and inspect rule, fix and raw evidence.
- Compare scans with explained Native/Exact/Context/Relocated matches.
- Save triage on a stable identity so decisions survive rescanning.
Try Demo Workspace creates two synthetic scans with SQL injection, cross-file trace, a parameterized-query fix, redacted secret, dependency and IaC findings. Follow the interactive tutorial.
The first product screenshot must show the real Finding Debugger, Monaco and Trace together. Capture instructions and asset locations are ready; no generated mock screenshot is presented as a working product.
| Capability | Implementation |
|---|---|
| Stable internal protocol | Security IR v1, versioned provenance and normalization goldens |
| Finding identity | Native, exact, source-context and deterministic semantic evidence; ambiguous collisions stay separate |
| Lifecycle and triage | First/last seen, occurrences, Fixed/Reopened; identity-bound decisions and notes |
| Scan comparison | New, Existing, Fixed, Reopened, Changed; paginated result buckets |
| Trace Debugger | Thread selection, cross-file Monaco ranges, Step n/N, keyboard Previous/Next |
| Large result sets | SQLite filters/counts, 100-row UI pages, bounded IPC, lazy raw-result references |
| Local persistence | Transactional schema migrations preserve Preview projects/history/triage |
| Scanner extensions | Reviewed declarative Gitleaks profile, explicit manifest/binary approval, no plugin scripts |
| Import/export | SARIF 2.1.0 with existing compatibility adapters |
All existing real providers remain available. Scanner binaries are installed separately and never silently downloaded by DSW.
| Producer | Input to DSW | Notes |
|---|---|---|
| Semgrep | Native SARIF | Metrics disabled; user-selected rules/config |
| Trivy | Native SARIF | SCA, secrets, configuration, containers and licenses |
| TruffleHog | Trusted JSON adapter | Raw candidate values removed; verification follows scanner settings |
| Bandit | SARIF / trusted JSON adapter | Formatter fallback retains rule, severity, confidence and CWE |
| Gitleaks extension | Native SARIF file | Explicit approval; reviewed offline/read-only profile |
| CodeQL and other tools | Imported SARIF | CodeQL runtime remains user-provided; no engine bundled |
Provider details and historical verified versions · Extension security boundary
Scanner / SARIF -> normalize + redact -> Security IR v1
-> layered matcher -> identity + occurrence
-> SQLite -> paginated inbox -> Monaco / trace / triage
React/TypeScript + Monaco; Tauri 2; Rust; local SQLite. No localhost backend, database server, Electron, cloud service or AI matching. Protocol, matching and migration policy.
Download the Windows x64 NSIS installer and SHA256SUMS from GitHub Releases. Windows 10/11 and WebView2 are required. v1.0.0 uses a self-signed Authenticode certificate; it does not provide public-CA trust or remove SmartScreen. The public certificate and checksums accompany the release. See signature verification.
pnpm install --frozen-lockfile
pnpm typecheck
pnpm test
pnpm build
cargo fmt --manifest-path src-tauri/Cargo.toml --all -- --check
cargo clippy --manifest-path src-tauri/Cargo.toml --all-targets -- -D warnings
cargo test --manifest-path src-tauri/Cargo.toml
pnpm tauri devWindows desktop validation additionally uses --features desktop. Build an installer with pnpm tauri build (MSVC C++ Build Tools required), or use the existing GNU fallback with an installed GNU/MinGW toolchain. CI and release operations.
Generate performance inputs with node scripts/generate-large-sarif.mjs 50000 work/large-50000.sarif. Benchmarks and limits.
Source reads stay within the canonical workspace. Scanner processes use executable + argv, with bounded logs, deadlines and cancellation. SARIF/log redaction runs before persistence and UI log events. Context fingerprint metadata contains only hashes.
DSW has no account, telemetry, analytics or cloud storage. External scanners may have their own network/database/credential-verification behavior. Extension permission declarations are not an OS sandbox for a malicious native binary. Security model · Private vulnerability reporting.
- SARIF import streams through disk-backed staging with cancellation: 1 GiB input, 2 MiB per result/value, 8 MiB metadata. Scanner machine output remains capped at 128 MiB; full Raw inspection at 8 MiB.
- Duplicate ambiguous findings remain unmatched; v1 does not match across different rules or conflicting symbols.
- Extension execution currently supports the reviewed Gitleaks profile only; arbitrary native commands/custom converters are disabled.
- Full CodeQL database analysis and Authenticode signing are outside this Preview.
- 100k synthetic imports pass locally (about 1.32 GiB peak in a debug test); low-memory profiling and real desktop screenshots remain separate validation work.
Application source: AGPL-3.0-only (LICENSE). Optional scanners retain their own terms and are not bundled. See NOTICE, third-party licenses, and licensing.
This project is not affiliated with or endorsed by any scanner vendor.