<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Fimil Changelog</title><description>What has shipped in Fimil: scanners, the AI pentest engine, auto-remediation, and platform updates.</description><link>https://fimil.dev</link><language>en-us</language><item><title>Platform-wide dependency and code audit sweep</title><link>https://fimil.dev/changelog#2026-06-platform-audit-sweep</link><guid isPermaLink="true">https://fimil.dev/changelog#2026-06-platform-audit-sweep</guid><description>Resolved every open dependency alert across the API, web app, worker, and MCP server, alongside a hardening pass on session timeouts and billing webhook deduplication.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>AI Pentest: in-browser testing, TOTP MFA login, and advisory fix PRs</title><link>https://fimil.dev/changelog#2026-05-pentest-browser-mfa</link><guid isPermaLink="true">https://fimil.dev/changelog#2026-05-pentest-browser-mfa</guid><description>The agent can now drive a real headless browser during discovery and exploitation, log in through TOTP multi-factor auth before testing, and open an advisory fix PR for every confirmed finding.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>feature</category></item><item><title>AI Pentest: IDOR detection, PoC export, and pay-per-confirmed-finding billing</title><link>https://fimil.dev/changelog#2026-05-pentest-idor-poc-billing</link><guid isPermaLink="true">https://fimil.dev/changelog#2026-05-pentest-idor-poc-billing</guid><description>Cross-account session pairs catch insecure direct object references; every confirmed finding exports a PoC with a copy-paste curl reproduction; billing meters only confirmed findings, with automatic credit on false-positive reversal.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>feature</category></item><item><title>MCP server: run security operations from your AI assistant</title><link>https://fimil.dev/changelog#2026-03-mcp-server</link><guid isPermaLink="true">https://fimil.dev/changelog#2026-03-mcp-server</guid><description>Model Context Protocol tools covering scans, findings, triage, remediation, reports, and webhooks — so an AI assistant can drive Fimil end to end. Pentest tools joined the set alongside the pentest engine.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate><category>feature</category></item><item><title>AI Pentest: vector breadth, API-aware discovery, and audit-ready reports</title><link>https://fimil.dev/changelog#2026-03-pentest-vectors-discovery</link><guid isPermaLink="true">https://fimil.dev/changelog#2026-03-pentest-vectors-discovery</guid><description>SQL injection, SSRF, broken authorization, mass assignment, and prompt injection validators with curated payload libraries; BFS crawling plus OpenAPI and GraphQL schema ingest for discovery; PDF reports with SOC 2 and PCI-DSS finding mappings.</description><pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate><category>feature</category></item><item><title>Intelligence layer: one signal from many scanners</title><link>https://fimil.dev/changelog#2026-02-intelligence-layer</link><guid isPermaLink="true">https://fimil.dev/changelog#2026-02-intelligence-layer</guid><description>Cross-scanner deduplication via fingerprints, finding groups with four correlation types, composite priority scoring (severity, age, reachability, EPSS), call-graph reachability with call chains, and auto-triage rules with a full audit trail.</description><pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate><category>feature</category></item><item><title>Auto-remediation: the finding is the pull request</title><link>https://fimil.dev/changelog#2026-01-auto-remediation</link><guid isPermaLink="true">https://fimil.dev/changelog#2026-01-auto-remediation</guid><description>Semver-aware dependency bumps across 7+ package ecosystems, IaC fixes for Terraform, CloudFormation, and Kubernetes, code fixes from 75+ CWE-specific handlers in eight languages, and secrets rotation guidance — all delivered as ready-to-merge PRs.</description><pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate><category>feature</category></item><item><title>Core platform: scanner orchestration behind one dashboard</title><link>https://fimil.dev/changelog#2025-12-core-platform</link><guid isPermaLink="true">https://fimil.dev/changelog#2025-12-core-platform</guid><description>Isolated scanner execution with normalized output across SAST, SCA, secrets, IaC, containers, and SBOM; GitHub, GitLab, and Bitbucket integrations with PR checks; CLI pre-commit gate; Kubernetes operator for self-hosted installs.</description><pubDate>Mon, 01 Dec 2025 00:00:00 GMT</pubDate><category>feature</category></item></channel></rss>