strix v1.6.0

v1.6.0Android
Added 14
  • Place caller-provided files into the sandbox workspace via extra_files and --workspace-file
  • Add contextual CVSS breakdown on dependency reports
  • Add OWASP LLM Top 10 2026 skill coverage
  • Add Azure and Entra security skill
  • Add argument injection security skill
  • Add ecosystem supply-chain security skills
Changed 11
  • Require contextual CVSS and usage evidence on dependency reports
  • Drop strict tool schemas on Claude routes
  • Improve skills
  • Take heavy imports off the startup path and pre-warm them in the background
  • Bootstrap Caido concurrently with the scan start
  • Treat literal 'null' and 'none' strings as absent for optional tool arguments
Fixed 13
  • Fix LiteLLM cost model resolution
  • Handle resume tokens gracefully
  • Preserve cost in TUI when state is truncated
  • Use single space after ordered-list marker in TUI
  • Raise RuntimeError on non-object run.json in report
  • Re-exec runs the new binary after self-update to prevent endless update-prompt loop
Security 1
  • Add CSV injection hardening

From strix

What's Changed
New Contributors

Full Changelog: https://github.com/usestrix/strix/compare/v1.5.3...v1.6.0

View original

Upgraded? How did it go?

Discussion