Version History and Changelog
The practical release summary for WSHawk v4.0.4, including the separate Electron + Go desktop and authorization workspace.
Version History and Changelog
WSHawk v4.0.4
- publishes the Classic release at
v4.0.4 - publishes Electron + Go separately at
electron-go-v4.0.4 - fixes headless Linux Electron startup for CI test and audit harnesses
- adds useful first-window diagnostics and fatal startup handling
- synchronizes Python, desktop, extension, Docker, citation, validation, evidence, and documentation version surfaces
WSHawk v4.0.3 Features Included in v4.0.4
- separate bridge-free Electron + Go desktop
- anonymous and multi-identity HTTP, GraphQL, and WebSocket authorization matrices
- explicit IDOR/BOLA, vertical escalation, missing-authentication, BFLA, admin-only, tenant-isolation, and ownership-transfer policies
- path, query, JSON, GraphQL, UUID, numeric-neighbor, and captured-traffic object discovery
- dry-run and rollback-controlled safe write testing
- encrypted projects, redaction, hash-only evidence, retention controls, and reproducible evidence
- findings lifecycle, duplicate consolidation, selected export, and automated retesting
- scored 34-scenario authorization lab
WSHawk v4.0.0
The v4.0.0 release is the major platform shift.
Main Changes
- project-backed local workflow model
- desktop-first operator surface
- HTTP and WebSocket replay services
- AuthZ diff workflows
- race testing workflows
- browser companion pairing with scoped capture
- evidence bundles with integrity metadata
- local validation labs for realtime application scenarios
What Stayed
The compatibility CLI still exists and remains useful for quick scans and scripting.
What Changed in Positioning
WSHawk should now be understood as a local offensive web and realtime application platform, not just a WebSocket scanner with a large payload list.