Feature availability¶
The first attackmap CLI release that has each feature. An older CLI rejects
a flag it doesn't know with a usage error, so if a flag fails, compare against
this table and upgrade (brew upgrade attackmap, or
pipx upgrade attackmap). Check your version with attackmap --version
(0.4.30+); on older releases use pip show attackmap.
Versions come from the core
CHANGELOG. The
macOS app column marks features the macOS app uses: it detects
them from attackmap analyze --help and hides or drops what your CLI lacks.
Released¶
| Feature | Command / flag | Minimum CLI | macOS app |
|---|---|---|---|
| AI narrative review | --llm |
0.1.0 | ✓ |
| SARIF output | attackmap-report.sarif (always written) |
0.2.0 | |
| Dependency CVE lookup (OSV.dev) | --cve |
0.2.0 | ✓ |
| Baseline diff and PR gate | --baseline, --diff-output, --fail-on-new-high |
0.2.0 | |
| Plugin recommendations | attackmap suggest [--install] [--yes] [--show-installed] |
0.2.0 | |
| Vulnerability-hypothesis hunt | --hunt |
0.3.0 | ✓ |
| Hunt verification | --hunt --verify |
0.4.0 | ✓ |
| Remediation suggestions | --remediate |
0.4.0 | ✓ |
| PR summary comment | --pr-comment |
0.4.0 | |
| NDJSON progress stream | --progress-format json |
0.4.1 | ✓ |
| OpenAI / Codex provider | --llm-provider openai |
0.4.3 | ✓ |
| Fast mode | --llm-speed fast |
0.4.3 | ✓ |
| Installed modules as JSON | attackmap modules --json |
0.4.4 | ✓ |
Suppressions (baseline file, inline attackmap:ignore) |
--no-suppress, --suppress-file |
0.4.7 | ✓ |
| Triage | --triage |
0.4.15 | ✓ |
| Verify jury: skeptic votes | --verify-votes |
0.4.16 | ✓ |
| Verify jury: failure-mode lenses | --hunt-lenses |
0.4.17 | ✓ |
| Verify jury: multi-round hunt and token budget | --hunt-rounds, --hunt-budget |
0.4.18 | ✓ |
| Recall mode | --recall |
0.4.20 | ✓ |
| Cross-repo / fleet scan | attackmap analyze <repoA> <repoB> … |
0.4.22 | ✓ |
| Detection benchmark | attackmap bench |
0.4.28 | |
| Version flag | attackmap --version |
0.4.30 | |
| Output filtering | --format {all,json,markdown} (accepted but ignored before 0.4.30) |
0.4.30 | ✓ |
| Pinned plugin auto-install | --install-missing |
0.4.31 | |
| Official plugins only | --trusted-analyzers-only |
0.4.31 |
The macOS app treats the whole verify jury as one capability and enables it
when the CLI has --verify-votes (0.4.16). --hunt-lenses, --hunt-rounds
and --hunt-budget need 0.4.17 and 0.4.18, so on a 0.4.16 CLI leave those
at their defaults.
Unreleased (on main, after 0.4.31)¶
These are in the changelog's [Unreleased] section and ship in the first
release after 0.4.31.
| Feature | Command / flag |
|---|---|
| Analyzer failure isolation; fail fast on request | scan.analyzer_errors; --strict-analyzers |
Analyzer run order by priority; opt-in analyzers and the "Opt-in analyzers match this repo but were not run" hint |
enabled_by_default=False, -m |
| Shared plugin walker | attackmap.sdk.fs (see Analyzer SDK) |
| Stable rule ids | attackmap rules [--json] |
| Trusted suppressions | --suppress-from-ref, --allow-pr-suppressions |
| Suppression expiry gate | --strict-suppressions |
| Newly-suppressed gate | --fail-on-new-suppression |