Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
624 commits
Select commit Hold shift + click to select a range
1670bbd
MAINT: Deleting Legacy Scenario Scaffolding (#2123)
rlundeen2 Jul 3, 2026
9e4549c
FEAT capability-aware multimodal feedback loop for Crescendo/RedTeami…
fitzpr Jul 3, 2026
4593d99
MAINT: Updating Backend to use Target Registry (#2124)
rlundeen2 Jul 3, 2026
8be27c9
MAINT: Initializers Cleanup (#2100)
rlundeen2 Jul 3, 2026
233fb3b
MAINT: Production schema migration guard + add deliberate migration s…
jsong468 Jul 6, 2026
eac19f7
MAINT: Standardize garak Doctor default strategy to DEFAULT (#2128)
varunj-msft Jul 7, 2026
0594f68
FIX ModuleNotFoundError in Azure SQL memory integration test (#2130)
behnam-o Jul 7, 2026
088ca50
FIX outdated default initializers in CoPyRIT (#2129)
behnam-o Jul 7, 2026
71d5e8a
FEAT Allow dataset parameters on dataset configuration when loading f…
behnam-o Jul 7, 2026
edb684f
MAINT: Add DEFAULT strategy alias to airt.cyber scenario (#2061)
varunj-msft Jul 7, 2026
7ab40cb
FIX: Curate Scam scenario DEFAULT strategy (#2127)
varunj-msft Jul 7, 2026
4aea051
fix(converter): Æ morse key has a stray leading space (KeyError) (#2137)
WatchTree-19 Jul 8, 2026
e50bba8
MAINT: Bump opencv-python from 4.13.0.92 to 5.0.0.93 (#2136)
dependabot[bot] Jul 8, 2026
0db5bc6
MAINT: Bump the minor-and-patch group with 5 updates (#2135)
dependabot[bot] Jul 8, 2026
3dd5806
MAINT: Bump the minor-and-patch group in /frontend with 10 updates (#…
dependabot[bot] Jul 8, 2026
0bbeb71
FIX parse likert raw score via float before int (#2133)
WatchTree-19 Jul 8, 2026
946b674
FEAT: Wire GCG extension protocol implementations (#2070)
romanlutz Jul 8, 2026
aaff32c
Remove all pre-1.0.0 PyRIT-internal deprecations (0.16.0/0.17.0) (#2111)
romanlutz Jul 8, 2026
7d828ed
MAINT: Unify scenario initialize_async's into common parameter bag (#…
rlundeen2 Jul 9, 2026
107810f
FIX: Fixing Myst ToC (#2144)
rlundeen2 Jul 9, 2026
a28ab44
MAINT: Detangle scorer LLM round-trip — ResponseHandler + internal he…
romanlutz Jul 9, 2026
8aa5a9c
Pin GitHub Actions to full-length commit SHAs (#2147)
OssSecurityBot Jul 9, 2026
2f7760d
MAINT: Bump vite from 8.1.2 to 8.1.3 in /frontend in the minor-and-pa…
dependabot[bot] Jul 9, 2026
e6b1368
TEST/FIX/DOC: Adding tests to ensure docs include scorers, scenarios,…
rlundeen2 Jul 9, 2026
066fa47
MAINT: Bump soupsieve from 2.8.1 to 2.8.4 in the security-minor-and-p…
dependabot[bot] Jul 9, 2026
2a768fd
MAINT: Bump torch from 2.12.1 to 2.13.0 in the minor-and-patch group …
dependabot[bot] Jul 9, 2026
67f9d38
FIX: Render full error content in GUI instead of generic 500 (#2145)
jsong468 Jul 9, 2026
1875275
Scorer composition (PR B): TrueFalse pure-composition API + CallableR…
romanlutz Jul 9, 2026
a355575
MAINT: Bump astral-sh/setup-uv from 7.6.0 to 8.2.0 (#2150)
dependabot[bot] Jul 9, 2026
e151cce
MAINT Breaking: Rename Scenario Strategies to Techniques (#2153)
rlundeen2 Jul 9, 2026
d7b9576
FIX: Adaptive Scenario bugs (#2152)
rlundeen2 Jul 9, 2026
40cecc7
MAINT: Technique Organization (#2155)
rlundeen2 Jul 10, 2026
a6d52ab
DOC Add paper affiliations to decomposition converter YAML files (#2139)
romanlutz Jul 10, 2026
9716aee
DOC add scenario update blog (#1940)
hannahwestra25 Jul 10, 2026
3acaaa6
MAINT BREAKING: Rename PromptConverter to Converter (#2161)
jsong468 Jul 10, 2026
b6b8dd6
MAINT: Bump mistune from 3.2.1 to 3.3.0 in the security-minor-and-pat…
dependabot[bot] Jul 10, 2026
fcea078
Fix crash when scorer LLM response is blocked by content filter (#2072)
hannahwestra25 Jul 11, 2026
55e5ebb
DOC: Updating technique docs (#2159)
rlundeen2 Jul 11, 2026
c6a0440
MAINT: AdversarialConversationManager - unify adversarial-chat contex…
rlundeen2 Jul 11, 2026
5aa08a8
PR Breaking MAINT: Moving Role Play Attack to Technique (#2160)
rlundeen2 Jul 11, 2026
566d4a3
Scorer composition (PR C, 3/3): complete LLM rollout with typed rubri…
romanlutz Jul 12, 2026
34f444f
MAINT Rename attack-related seed groups (#2165)
behnam-o Jul 13, 2026
99a638e
FIX: Fix possible SSRF bypass in `_is_azure_blob_url` host parsing (#…
jsong468 Jul 13, 2026
4b45c01
FIX: Fix config notebook (#2181)
jsong468 Jul 13, 2026
3ce657b
FIX: Fixing 4 broken notebooks (#2182)
rlundeen2 Jul 13, 2026
b988707
Fix frontend E2E coverage and gate seeded tests (#2179)
romanlutz Jul 14, 2026
d62f01e
FEAT: add LiteLLMChatTarget for multi-provider access via LiteLLM (#2…
RheagalFire Jul 14, 2026
ec6a939
FEAT: set the objective target's system prompt from the CoPyRIT GUI (…
adrian-gavrila Jul 14, 2026
3b7af75
MAINT: Migrate FlipAttack to a core 'flip' attack technique (#2178)
rlundeen2 Jul 14, 2026
c8fb10c
FEAT Overlay harm-category standardization across dataset loaders (#2…
romanlutz Jul 14, 2026
db81eec
MAINT: Migrating context compliance to technique (#2177)
rlundeen2 Jul 14, 2026
4634610
FIX: Add destination allowlist before forwarding Bearer credential to…
jsong468 Jul 14, 2026
1434fe4
FEAT: Adding descriptions to Techniques (#2167)
rlundeen2 Jul 14, 2026
158a748
FIX: Preserve iterative image state in Crescendo (#2188)
romanlutz Jul 15, 2026
94c9544
MAINT: Bump pyarrow from 24.0.0 to 25.0.0 (#2203)
dependabot[bot] Jul 15, 2026
9a07cbf
MAINT: Bump astral-sh/setup-uv from 8.2.0 to 8.3.2 in the minor-and-p…
dependabot[bot] Jul 15, 2026
b1f243d
MAINT: Bump the minor-and-patch group in /frontend with 6 updates (#2…
dependabot[bot] Jul 15, 2026
dce0f0b
MAINT: Bump https://github.com/astral-sh/ruff-pre-commit from v0.15.2…
dependabot[bot] Jul 15, 2026
f8f6cd7
MAINT: Standardize garak.encoding defaults and fix atomic-attack name…
varunj-msft Jul 15, 2026
629362e
MAINT: Bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 (#…
dependabot[bot] Jul 15, 2026
6d3442b
FIX: CLI Usability Updates (#2194)
rlundeen2 Jul 15, 2026
bae493e
MAINT: Bump the minor-and-patch group across 1 directory with 8 updat…
dependabot[bot] Jul 15, 2026
0ed915a
FIX: sanitize metadata file name in `azure_blob_storage_target` (#2193)
jsong468 Jul 15, 2026
0eb5364
FEAT Persist component identifiers as normalized, content-addressed g…
behnam-o Jul 15, 2026
9a954d4
MAINT: Consolidating Target Metadata (#2185)
rlundeen2 Jul 15, 2026
233b400
FIX: Fixing json retry (#2184)
rlundeen2 Jul 15, 2026
0770376
MAINT: Fold GCG into pyrit/executor/promptgen, remove auxiliary_attac…
romanlutz Jul 16, 2026
f3ce601
DOC: Asset cleanup and notebook-local scorer YAML relocation (#2176)
romanlutz Jul 16, 2026
acc2a77
[BREAKING] MAINT Remove v1 deprecated compatibility paths (#2195)
romanlutz Jul 16, 2026
339a28f
FEAT Add dedicated LlamaGuard scorer (#1867)
immu4989 Jul 16, 2026
10a4923
[BREAKING] MAINT: Standardize Jailbreak scenario around dataset × tec…
varunj-msft Jul 16, 2026
c58f663
FIX old reference in notebook SeedAttackGroup -> AttackSeedGroup (#2…
behnam-o Jul 16, 2026
0bf64b5
MAINT Consolidate memory operations (#2207)
behnam-o Jul 16, 2026
36a92b8
DOC: Delete numbers from notebook headers (#2206)
jsong468 Jul 16, 2026
cb5055f
FIX: eliminate KV public-access window for policy compliance (#2049)
hannahwestra25 Jul 16, 2026
ea3588a
FIX: Tighten CLI backend health-check validation (#2209)
romanlutz Jul 17, 2026
7c7a373
FIX: Propagate dataset_name to jailbreak template seeds (#2208)
romanlutz Jul 17, 2026
27d20ee
FIX: Load HuggingFace models without blocking the event loop (#2211)
romanlutz Jul 17, 2026
ef01772
FIX: CLI display underlying model (#2215)
rlundeen2 Jul 17, 2026
96796c6
FIX: Make CLI/output encoding safe on Windows consoles (#2213)
romanlutz Jul 17, 2026
f5659ce
FIX: Prune emptied atomic attacks on scenario resume (#2210)
romanlutz Jul 17, 2026
7bd8f62
FIX: Accept local HTTP URLs for CLI --start-server (#2212)
romanlutz Jul 17, 2026
79f10ba
[BREAKING] MAINT: Re-migrate Psychosocial scenario to per-subharm cro…
varunj-msft Jul 17, 2026
8af0e02
MAINT: Bring GCG under Ruff and ty checks (#2218)
romanlutz Jul 17, 2026
14de64c
FIX Coerce enum parameters for direct target creation (#2196)
romanlutz Jul 17, 2026
8a91d7d
FEAT: Add remote WildGuardMix dataset loader (#1827)
romanlutz Jul 18, 2026
5b0b3f8
FIX adaptive scenario: normalize seed sequences to fix technique role…
romanlutz Jul 18, 2026
90fa2f8
FIX: Aligning Scenarios with Technique Registry (#2186)
rlundeen2 Jul 18, 2026
0b122fa
FIX Clamp ImageResizingConverter output dimensions (#2169)
ThryLox Jul 19, 2026
fb99324
DOC: Add scanner walkthrough to scenarios blog (#2221)
hannahwestra25 Jul 20, 2026
be4c90e
FIX: Entra ID auth fallback for Azure endpoints in OpenAITextEmbeddin…
romanlutz Jul 20, 2026
9b7db68
FIX Stabilize Playwright frontend host resolution (#2222)
romanlutz Jul 20, 2026
5a4d899
FIX Restore focus after closing Feedback dialog (#2223)
romanlutz Jul 20, 2026
2cf35a0
FIX: Repair responsive target configuration (#2224)
romanlutz Jul 20, 2026
1391f5f
FIX: Repair mobile chat responsiveness (#2226)
romanlutz Jul 20, 2026
b70c840
FIX Correct Round Robin target identity matching (#2225)
romanlutz Jul 20, 2026
8bae485
Add XL-SafetyBench datasets (#1791)
romanlutz Jul 20, 2026
fe7f563
FIX: Repair XPIA ai_recruiter workflow (HTTP modalities, PDF stem, Me…
romanlutz Jul 20, 2026
1f46f7c
TEST: skip Azure key-auth-disabled integration tests (#2229)
romanlutz Jul 21, 2026
5531da0
FIX: Standardize image-text converter font default to None (#2232)
romanlutz Jul 21, 2026
77a738b
DOC: initializer-rename doc updates and notebook/test fixes (post #21…
romanlutz Jul 21, 2026
a00a23e
MAINT: Make technique prompt placement explicit (#2236)
hannahwestra25 Jul 21, 2026
d23086d
MAINT: Standardize system prompts on prepended_conversation (#2040)
adrian-gavrila Jul 21, 2026
264611c
[BREAKING] MAINT: Remove expired single-turn system prompt (#2245)
romanlutz Jul 22, 2026
403ce70
FIX: Retry adversarial replies with non-object JSON roots (#2247)
romanlutz Jul 22, 2026
151a599
MAINT: Bump https://github.com/astral-sh/ruff-pre-commit from v0.15.2…
dependabot[bot] Jul 22, 2026
623f294
FIX: Correct invalid target initializer guidance (#2248)
romanlutz Jul 22, 2026
9b0da71
TEST: Restore renamed notebook exclusion (#2254)
romanlutz Jul 22, 2026
f43c82b
MAINT: Bump actions/setup-node from 6.4.0 to 7.0.0 (#2252)
dependabot[bot] Jul 22, 2026
11b0057
MAINT: Bump the minor-and-patch group in /frontend with 6 updates (#2…
dependabot[bot] Jul 22, 2026
c8ce56b
DATA Add 488 TrustAIRLab in-the-wild jailbreak templates (#2228)
romanlutz Jul 22, 2026
4fb8dd9
DOC Add scorer composition diagram (#2238)
romanlutz Jul 22, 2026
88db920
MAINT: Bump jupyterlab from 4.5.9 to 4.5.10 in the security-minor-and…
dependabot[bot] Jul 23, 2026
77b90e4
MAINT: Bump the minor-and-patch group with 12 updates (#2253)
dependabot[bot] Jul 23, 2026
481ce17
FIX Batch v1.0 conversation migration backfills (#2266)
romanlutz Jul 23, 2026
2aac5fc
FIX: Correct dataset reference metadata (#2262)
romanlutz Jul 23, 2026
b2ba7fd
FEAT: Add IPA transcription converter (#2264)
romanlutz Jul 23, 2026
c82f683
FIX: improve frontend accessibility and mobile responsiveness (#2240)
romanlutz Jul 23, 2026
bad686a
DOCS: Add v1.0.0 documentation version (#2257)
romanlutz Jul 24, 2026
c8a696e
FIX: Prevent GCG model gradient accumulation (#2244)
romanlutz Jul 24, 2026
b82a615
TEST: unify Entra and API-key integration tests (#2263)
romanlutz Jul 24, 2026
31c460c
MAINT post-1.0.0 release update to 1.1.0.dev0 (#2270)
romanlutz Jul 24, 2026
9c37ff9
FEAT: Add RefreshDatasets initializer to refresh stored datasets (#2268)
varunj-msft Jul 24, 2026
59f2280
DOC: combine steps 6 and 11 in `10_release_process.md` (#2272)
jsong468 Jul 25, 2026
944a551
FIX GCG: forward hf_token as None instead of an empty string (#2275)
immu4989 Jul 26, 2026
262e291
MAINT: Attribute in-the-wild jailbreak templates to paper author affi…
romanlutz Jul 27, 2026
3da58f8
DOC Add security release review process (#2216)
hannahwestra25 Jul 27, 2026
0cec479
FIX: Paginate attack results in the database to keep the GUI responsi…
varunj-msft Jul 28, 2026
06f3506
FIX Improve mobile touch targets (#2258)
romanlutz Jul 28, 2026
1f37a59
FIX BrailleConverter: semicolon mapped to the wrong braille cell (#2278)
WatchTree-19 Jul 28, 2026
5b205e2
FIX SuperscriptConverter: uppercase 'B' mapped to superscript AE liga…
WatchTree-19 Jul 28, 2026
0d23952
FEAT: Chain-of-Thought Rendering for Attack Results (#2269)
ValbuenaVC Jul 28, 2026
b8a81fd
MAINT: Bump types-pyyaml from 6.0.12.20260518 to 6.0.12.20260724 (#2293)
dependabot[bot] Jul 29, 2026
1020d0d
MAINT: Bump @testing-library/jest-dom from 6.9.1 to 7.0.0 in /fronten…
dependabot[bot] Jul 29, 2026
a546f18
MAINT: Bump the minor-and-patch group in /frontend with 10 updates (#…
dependabot[bot] Jul 29, 2026
ee7b6b7
MAINT: Bump astral-sh/setup-uv from 8.3.2 to 9.0.0 (#2289)
dependabot[bot] Jul 29, 2026
17a71e2
MAINT: Bump actions/setup-python from 6.3.0 to 7.0.0 (#2288)
dependabot[bot] Jul 29, 2026
0249520
MAINT: Bump actions/checkout from 7.0.0 to 7.0.1 in the minor-and-pat…
dependabot[bot] Jul 29, 2026
7ab182f
MAINT: Bump https://github.com/astral-sh/ruff-pre-commit from v0.15.2…
dependabot[bot] Jul 29, 2026
dcb7c5a
FEAT: Add markdown toggle to chat window (#2284)
jsong468 Jul 29, 2026
630061a
FIX Handle structured refusals and scenario partial failures (#2283)
romanlutz Jul 29, 2026
991f9a4
FEAT: Add conversation export button to the GUI chat view (#2259)
varunj-msft Jul 30, 2026
2ee237d
FEAT: add AcrosticConverter (#2280)
Ivanodib Jul 30, 2026
5ae9825
FIX Bind doc notebook execution to the invoking checkout's Jupyter ke…
romanlutz Jul 31, 2026
a726d31
MAINT: Post-v1.0.1 release follow-ups for main (#2298)
romanlutz Jul 31, 2026
c7b5ff9
FIX Select GPT-5 response piece by data type instead of position (#2297)
romanlutz Jul 31, 2026
f280151
FIX Use Microsoft Graph for GUI authentication and group authorizatio…
behnam-o Jul 31, 2026
60d8abc
MAINT: Ordering AttackResults by timestamp for perf (#2295)
rlundeen2 Jul 31, 2026
446e47b
FIX: preserve unknown characters in BrailleConverter (#2309)
feiiiiii5 Aug 2, 2026
264d2d3
DOC Document attack outcomes and scenario resiliency (#2296)
romanlutz Aug 2, 2026
3911980
FIX: `pyrit_shell run` fails for every scenario with a flag-collision…
jsong468 Aug 3, 2026
06aa27a
DOC Correct scenario baseline parameter guidance (#2313)
romanlutz Aug 3, 2026
b7bea2d
FEAT Add GUI initializers (#2271)
hannahwestra25 Aug 3, 2026
0cad68d
FIX Persist Chat Markdown display preference (#2311)
romanlutz Aug 3, 2026
cab4ba5
FIX: Keep mobile tour tooltips within the viewport (#2294)
romanlutz Aug 4, 2026
b6e479c
FIX: bound attack conversation IDs before indexing (#2317)
behnam-o Aug 4, 2026
101b139
Improve empty Attack History guidance (#2312)
romanlutz Aug 4, 2026
53073e5
MAINT: Unify OpenAI realtime event routing (#2319)
romanlutz Aug 4, 2026
faeed9f
MAINT Deduplicate pretty output color formatting (#2318)
romanlutz Aug 4, 2026
b0fbc5b
FIX Clarify target choices in the Add Target picker (#2316)
romanlutz Aug 4, 2026
6a92b29
MAINT: Bump brace-expansion, js-yaml, postcss, and setuptools for Dep…
romanlutz Aug 4, 2026
78efa6b
MAINT Simplify attack result queries (#2321)
romanlutz Aug 4, 2026
981e6cd
MAINT: Bump aiohttp from 3.14.1 to 3.14.3 in the security-minor-and-p…
dependabot[bot] Aug 4, 2026
660be89
MAINT: Bump cryptography from 48.0.1 to 50.0.0 (#2325)
dependabot[bot] Aug 5, 2026
f24921d
FIX Avoid blocking WAV reads in realtime target (#2305)
romanlutz Aug 5, 2026
4cde1cd
FIX: warn instead of raising on reasoning-model token truncation (Cha…
romanlutz Aug 5, 2026
a00952d
MAINT: Bump react-markdown from 9.0.1 to 10.1.0 in /frontend (#2330)
dependabot[bot] Aug 5, 2026
13e89da
MAINT: Bump https://github.com/astral-sh/ruff-pre-commit from v0.16.0…
dependabot[bot] Aug 5, 2026
3fa1bbf
MAINT: Bump the minor-and-patch group across 1 directory with 10 upda…
dependabot[bot] Aug 5, 2026
f5ecae5
FEAT: print full scenario result ID in pyrit_scan and pyrit_shell (#2…
jsong468 Aug 6, 2026
8029968
DOC: Replace landing page Roakey peeks with animated spritesheets (#2…
romanlutz Aug 6, 2026
1058258
MAINT: Bump the minor-and-patch group across 1 directory with 10 upda…
dependabot[bot] Aug 6, 2026
6280700
FIX: Make onboarding tour target-state aware (#2310)
romanlutz Aug 6, 2026
c0745e5
MAINT Simplify OpenAI Responses input serialization (#2339)
romanlutz Aug 7, 2026
baf0855
TEST Add Crescendo mixed-failure resilience coverage (#2337)
romanlutz Aug 7, 2026
ff1fa6b
MAINT Simplify Foundry technique mapping (#2336)
romanlutz Aug 7, 2026
66690ee
TEST: fix flaky CreateTargetDialog accessibility test (#2335)
romanlutz Aug 7, 2026
2d11455
FIX Correlate multi-turn attack error results (#2322)
romanlutz Aug 7, 2026
3dd9946
FIX isolate TAP configuration and per-run state (#2338)
romanlutz Aug 7, 2026
c6060d9
Add remove_seeds_from_memory and remove_seed_groups_from_memory
Aug 7, 2026
f823656
TEST Add Crescendo scenario resume coverage (#2343)
romanlutz Aug 7, 2026
692afd4
FIX Handle attack parameter construction failures (#2344)
romanlutz Aug 7, 2026
625a7db
FIX Avoid poisoned dataset ZIP caches (#2345)
romanlutz Aug 7, 2026
1f5cebf
FIX Persist direct scenario cancellation (#2342)
romanlutz Aug 7, 2026
1916eaf
MAINT: Bump the security-minor-and-patch group across 1 directory wit…
dependabot[bot] Aug 9, 2026
efca15b
FEAT Add ShieldGemma scorer following the LlamaGuard scorer pattern (…
immu4989 Aug 10, 2026
e0104c5
Merge branch 'main' into blahdeblahde-remove-seeds-from-memory-api
hannahwestra25 Aug 10, 2026
6d8fd7a
MAINT: Upgrade frontend to react-router 8.3.0 (#2327)
romanlutz Aug 10, 2026
378c2d7
TEST Strengthen Crescendo concurrent context isolation (#2353)
romanlutz Aug 10, 2026
f2c60da
FIX: support stereo audio frequency conversion (#2356)
Vaishnavi220506 Aug 10, 2026
ed76713
FIX: Harden scanner server lifecycle (#2239)
romanlutz Aug 11, 2026
5a6aa3c
FEAT: Add VigenereConverter (#2333)
diamond8658 Aug 11, 2026
34c6937
FIX: require objective_target_identifier on ScenarioResultEntry (#2341)
romanlutz Aug 11, 2026
f57a3bc
MAINT: Consolidate regex scorer defaults (#2351)
romanlutz Aug 11, 2026
8df2cff
DOC Add API example backlinks (#2282)
hugosmoreira Aug 11, 2026
def4ec0
FIX: Correct prompt dataset role semantics (#2358)
romanlutz Aug 11, 2026
668f011
FIX Infer Azure Blob MIME types from file extensions (#2315)
romanlutz Aug 11, 2026
a933993
FEAT: `scenario-results` command and `--view` flag for past scenario …
jsong468 Aug 12, 2026
e77d8a7
FEAT: Capture API response stop reason on MessagePiece metadata (#2340)
varunj-msft Aug 12, 2026
96730ae
Add confirmation dialog before removing an initializer (#2380)
hannahwestra25 Aug 12, 2026
ff634db
FIX Restore targets for deep-linked conversations (#2362)
romanlutz Aug 12, 2026
5475895
FIX: Update supported image formats for GPT vision models (#2386)
fdubut Aug 13, 2026
72cac36
MAINT: Bump the minor-and-patch group with 8 updates (#2369)
dependabot[bot] Aug 13, 2026
924a12e
MAINT: Bump https://github.com/astral-sh/ruff-pre-commit from v0.16.1…
dependabot[bot] Aug 13, 2026
62a7413
MAINT: Bump the minor-and-patch group in /frontend with 12 updates (#…
dependabot[bot] Aug 13, 2026
de76ac7
FIX Prevent stale server PID records on cancellation (#2361)
romanlutz Aug 13, 2026
3c3929b
MAINT: Consolidate GCG attack manager logging (#2364)
romanlutz Aug 13, 2026
850d92c
FIX: Preserve all AcrosticConverter input characters (#2384)
Boulea7 Aug 13, 2026
388fe25
FIX: keep saved initializer settings visible when catalog loading fai…
hannahwestra25 Aug 13, 2026
e507156
FIX: show initializer create errors inside the open dialog (#2370)
hannahwestra25 Aug 13, 2026
47956e9
FIX: Support empty template list in Encoding scenario (#2394)
fdubut Aug 13, 2026
375838d
FIX: Keep cold target catalog responsive (#2360)
romanlutz Aug 13, 2026
49c81a8
FEAT: adding Garak audio achilles scenario (#2138)
rlundeen2 Aug 13, 2026
d1f7306
FEAT: Adding Garak package hallucination scenario (#2141)
rlundeen2 Aug 14, 2026
fa8bffd
TEST Cover Crescendo refusal scorer failures (#2395)
romanlutz Aug 14, 2026
c3fce59
FEAT: Garak sysprompt extraction scenario (#2142)
rlundeen2 Aug 14, 2026
1d88748
FIX: meet 44px touch-target minimum for Initializers controls (#2391)
hannahwestra25 Aug 14, 2026
cfa1770
FIX initializer edit save failures (#2393)
hannahwestra25 Aug 14, 2026
2249d2a
MAINT: Split TAP node execution scheduling (#2382)
romanlutz Aug 14, 2026
f049e1a
FIX PlagiarismScorer: verbatim fast path matched sub-word substrings …
WatchTree-19 Aug 14, 2026
fd65996
MAINT: Remove sys.path mutations from build_scripts (#2368)
romanlutz Aug 14, 2026
3b068a4
FIX: preserve content and word boundaries in NatoConverter (#2399)
feiiiiii5 Aug 14, 2026
e1107cc
FIX TrueFalseResponseHandler: strip whitespace before validating verd…
WatchTree-19 Aug 14, 2026
4d856f4
MAINT: Consolidate OpenAI response handling (#2381)
romanlutz Aug 14, 2026
d323c25
FEAT: Split-payload multi-turn attack strategy (#1733)
ek0212 Aug 14, 2026
f618c27
FEAT add Jailbreak datasets from Menz et al. publication (#1189)
MenzBD Aug 14, 2026
a75e851
FEAT add AgentThreatRulesScorer (ATR taxonomy scorer) (#1893)
eeee2345 Aug 17, 2026
1270f26
FIX: Offload local dataset file reads (#2402)
biefan Aug 17, 2026
414938c
REVERT: Remove AgentThreatRulesScorer (#2410)
adrian-gavrila Aug 18, 2026
7791b49
DOC: Update bibliography publication metadata (#2409)
romanlutz Aug 18, 2026
4598a40
FEAT: Adding general websocket target class and accompanying unit tes…
kmarsh77 Aug 18, 2026
78739f0
FEAT: Adding Garak Figsafe Scenario (#2406)
rlundeen2 Aug 18, 2026
94e5a2f
DOC: correct the .python-version claim in the contributor install gui…
VishnuR23 Aug 18, 2026
626df98
FIX Honor score feedback and handle zero-vector similarity (#2403)
romanlutz Aug 18, 2026
1bb3a47
TEST Add concurrent partial failure resume coverage (#2411)
romanlutz Aug 19, 2026
048c635
MAINT: Bump the minor-and-patch group in /frontend with 12 updates (#…
dependabot[bot] Aug 19, 2026
10bae4a
MAINT: Bump astral-sh/setup-uv from 9.0.0 to 10.0.0 (#2422)
dependabot[bot] Aug 19, 2026
9eda5af
MAINT: Bump https://github.com/astral-sh/ruff-pre-commit from v0.16.2…
dependabot[bot] Aug 19, 2026
201bb0a
MAINT: Bump types-pyyaml from 6.0.12.20260724 to 6.0.12.20260815 (#2425)
dependabot[bot] Aug 19, 2026
662ddc4
MAINT: Bump openai from 2.53.0 to 3.1.0 (#2426)
dependabot[bot] Aug 19, 2026
b99d9ec
MAINT: Bump the minor-and-patch group with 8 updates (#2424)
dependabot[bot] Aug 19, 2026
a3f5f3c
TEST Cover attack executor cancellation (#2430)
romanlutz Aug 19, 2026
90cc959
FIX: size Initializer selector touch target (#2429)
romanlutz Aug 19, 2026
43e520a
FEAT: Convert pyrit_scan mode-flags to subcommands + stale docs corre…
jsong468 Aug 19, 2026
460b9ff
FEAT: Add multilingual scenario (#2392)
fdubut Aug 19, 2026
37bb737
MAINT consolidate remote datetime parsing (#2412)
romanlutz Aug 20, 2026
d65ed40
FEAT: Adding Scorables as an entry point (#2400)
rlundeen2 Aug 20, 2026
d857ac4
DOC: Guidance for serializing model metadata (#2435)
rlundeen2 Aug 20, 2026
cf03df2
Merge branch 'main' into blahdeblahde-remove-seeds-from-memory-api
hannahwestra25 Aug 20, 2026
e2b9889
DOC: address review - execute seed notebook and drop non-error bullet
Aug 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
10 changes: 5 additions & 5 deletions .azuredevops/end-to-end-tests.yml
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
# Runs end-to-end scenario tests using pyrit_scan CLI

trigger: none # Disable automatic CI triggers
trigger: none

schedules:
- cron: "0 7 * * *" # 7 AM UTC = 11 PM PST (UTC-8) / Midnight PDT (UTC-7)
displayName: Nightly E2E Tests at 11 PM PST
- cron: "0 7 * * *" # 7 AM UTC = 11 PM PST (UTC-8)
displayName: E2E Tests Daily at 07:00 AM UTC (11:00 PM PST)
branches:
include:
- main
always: true # Run even if there are no code changes
- main
always: true

jobs:
- template: test-job-template.yml
Expand Down
9 changes: 6 additions & 3 deletions .azuredevops/integration-tests.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,15 @@

# Builds the pyrit environment and runs integration tests

trigger:
trigger: none

schedules:
- cron: "0 */3 * * *" # Every 3 hours
displayName: Integration Tests Every 3 Hours
branches:
include:
- main

# There are additional PR triggers for this that are configurable in ADO.
always: true

jobs:
- template: test-job-template.yml
Expand Down
11 changes: 6 additions & 5 deletions .azuredevops/partner-integration-tests.yml
Original file line number Diff line number Diff line change
@@ -1,14 +1,15 @@
# Builds the pyrit environment and runs partner integration tests. Partner integration tests are to ensure that we
# are not breaking any contract between PyRIT and its partners.
trigger: none # Disable automatic CI triggers

trigger: none

schedules:
- cron: "0 6 * * *" # 6 AM UTC = 10 PM PST (UTC-8) / 11PM PDT (UTC-6)
displayName: Nightly Partner Integration Tests at 10 PM PST
- cron: "0 6 * * *" # 6 AM UTC = 10 PM PST (UTC-8)
displayName: Partner Integration Tests Daily at 06:00 AM UTC (10:00 PM PST)
branches:
include:
- main
always: true # Run even if there are no code changes
- main
always: true

jobs:
- template: test-job-template.yml
Expand Down
2 changes: 1 addition & 1 deletion .azuredevops/test-job-template.yml
Original file line number Diff line number Diff line change
Expand Up @@ -79,7 +79,7 @@ jobs:

echo "Microsoft ODBC Driver 18 installed successfully."
displayName: 'Install ODBC Driver 18 for SQL Server'
- bash: uv sync --extra dev --extra all
- bash: uv sync --extra all
name: install_PyRIT
- bash: df -all -h
name: disk_space_check
Expand Down
2 changes: 1 addition & 1 deletion .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# syntax=docker/dockerfile:1
FROM mcr.microsoft.com/devcontainers/python:3.11-bookworm
FROM mcr.microsoft.com/devcontainers/python:3.14-bookworm

# Makes installation faster
ENV UV_COMPILE_BYTECODE=1
Expand Down
7 changes: 2 additions & 5 deletions .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -16,9 +16,6 @@
"python.analysis.extraPaths": [
"/workspace"
],
"python.linting.mypyArgs": [
"--cache-dir=.mypy_cache"
],
"python.analysis.typeCheckingMode": "basic",
"python.analysis.diagnosticMode": "openFilesOnly",
"python.analysis.autoSearchPaths": false,
Expand Down Expand Up @@ -50,9 +47,9 @@
"**/.pytest_cache/**": true,
"**/build/**": true,
"**/dist/**": true,
"**/pyrit/auxiliary_attacks/gcg/attack/**": true,
"**/pyrit/executor/promptgen/gcg/attack/**": true,
"**/doc/**": true,
"**/.mypy_cache/**": true,
"**/.ty_cache/**": true,
"**/frontend/node_modules/**": true,
"**/frontend/dist/**": true,
"**/dbdata/**": true
Expand Down
26 changes: 1 addition & 25 deletions .devcontainer/devcontainer_setup.sh
Original file line number Diff line number Diff line change
@@ -1,31 +1,7 @@
#!/bin/bash
set -e

MYPY_CACHE="/workspace/.mypy_cache"
VIRTUAL_ENV="/opt/venv"
# Create the mypy cache directory if it doesn't exist
if [ ! -d "$MYPY_CACHE" ]; then
echo "Creating mypy cache directory..."
sudo mkdir -p $MYPY_CACHE
sudo chown vscode:vscode $MYPY_CACHE
sudo chmod 755 $MYPY_CACHE
else
# Check ownership
OWNER=$(stat -c '%U:%G' $MYPY_CACHE)

if [ "$OWNER" != "vscode:vscode" ]; then
echo "Fixing mypy cache directory ownership..."
sudo chown -R vscode:vscode $MYPY_CACHE
fi

# Check permissions
PERMS=$(stat -c '%a' $MYPY_CACHE)

if [ "$PERMS" != "755" ]; then
echo "Fixing mypy cache directory permissions..."
sudo chmod -R 755 $MYPY_CACHE
fi
fi

# cleanup old extensions
sudo rm -rf /vscode/vscode-server/extensionsCache/github.copilot-*
Expand All @@ -46,7 +22,7 @@ if [ ! -f "$HASH_FILE" ] || [ "$(cat $HASH_FILE)" != "$CURRENT_HASH" ]; then

# Install dependencies
uv pip install ipykernel
uv pip install -e ".[dev,all]"
uv sync --extra all
# Register the kernel with Jupyter
python -m ipykernel install --user --name=pyrit-dev --display-name="Python (pyrit-dev)"

Expand Down
4 changes: 2 additions & 2 deletions .devcontainer/docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ services:
- pip-cache:/home/vscode/.cache/pip:cached
- uv-cache:/home/vscode/.cache/uv:cached
- precommit-cache:/home/vscode/.cache/pre-commit:cached
- mypy-cache:/workspace/.mypy_cache:cached
- ty-cache:/workspace/.ty_cache:cached
- pylance-cache:/home/vscode/.cache/pylance:cached
- node-modules:/workspace/frontend/node_modules:cached
- ~/.pyrit:/home/vscode/.pyrit:cached
Expand All @@ -27,6 +27,6 @@ volumes:
pip-cache:
uv-cache:
precommit-cache:
mypy-cache:
ty-cache:
pylance-cache:
node-modules:
2 changes: 1 addition & 1 deletion .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ build/
**/*.py[cod]
**/*$py.class
**/.pytest_cache/
**/.mypy_cache/
**/.ty_cache/

# Environment files with secrets
.env
Expand Down
35 changes: 32 additions & 3 deletions .env_example
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@

PLATFORM_OPENAI_CHAT_ENDPOINT="https://api.openai.com/v1"
PLATFORM_OPENAI_CHAT_KEY="sk-xxxxx"
PLATFORM_OPENAI_CHAT_GPT4O_MODEL="gpt-4o"
PLATFORM_OPENAI_CHAT_MODEL="gpt-4o"

# Note: For Azure OpenAI endpoints, use the new format with /openai/v1 and specify the model separately
# Example: https://xxxx.openai.azure.com/openai/v1
Expand All @@ -42,6 +42,15 @@ AZURE_OPENAI_GPT4O_MODEL="deployment-name"
# identifiers will default to the value of the standard MODEL environment variable.
AZURE_OPENAI_GPT4O_UNDERLYING_MODEL="gpt-4o"

# Optional second GPT-4o endpoint (that can be used for round-robin distribution).
# TargetInitializer creates RoundRobinTargets that automatically group together
# targets with identical underlying model names and behavioral params, allowing
# for distribution of requests across them for rate-limit relief.
AZURE_OPENAI_GPT4O_ENDPOINT2="https://xxxx.openai.azure.com/openai/v1"
AZURE_OPENAI_GPT4O_KEY2="xxxxx"
AZURE_OPENAI_GPT4O_MODEL2="deployment-name"
AZURE_OPENAI_GPT4O_UNDERLYING_MODEL2="gpt-4o"

AZURE_OPENAI_INTEGRATION_TEST_ENDPOINT="https://xxxxx.openai.azure.com/openai/v1"
AZURE_OPENAI_INTEGRATION_TEST_KEY="xxxxx"
AZURE_OPENAI_INTEGRATION_TEST_MODEL="deployment-name"
Expand Down Expand Up @@ -75,17 +84,36 @@ AZURE_OPENAI_GPT4O_UNSAFE_CHAT_MODEL2="deployment-name"
AZURE_OPENAI_GPT4O_UNSAFE_CHAT_UNDERLYING_MODEL2=""

# Adversarial chat target (used by scenario attack techniques, e.g. role-play, TAP)
# Default endpoint goes here; specialized ones below
ADVERSARIAL_CHAT_ENDPOINT="https://xxxxx.openai.azure.com/openai/v1"
ADVERSARIAL_CHAT_KEY="xxxxx"
ADVERSARIAL_CHAT_MODEL="deployment-name"

ADVERSARIAL_CHAT_SINGLETURN_ENDPOINT="https://xxxxxx.westus3.inference.ml.azure.com/score"
ADVERSARIAL_CHAT_SINGLETURN_KEY="xxxxx"
ADVERSARIAL_CHAT_SINGLETURN_MODEL="deployment-name"

ADVERSARIAL_CHAT_MULTITURN_ENDPOINT="https://xxxxxx.westus3.inference.ml.azure.com/score"
ADVERSARIAL_CHAT_MULTITURN_KEY="xxxxx"
ADVERSARIAL_CHAT_MULTITURN_MODEL="deployment-name"

ADVERSARIAL_CHAT_REASONING_ENDPOINT="https://xxxxxx.westus3.inference.ml.azure.com/score"
ADVERSARIAL_CHAT_REASONING_KEY="xxxxx"
ADVERSARIAL_CHAT_REASONING_MODEL="deployment-name"


# Objective Scorer chat target (used in scorers in scenarios)
OBJECTIVE_SCORER_CHAT_ENDPOINT="https://xxxxx.openai.azure.com/openai/v1"
OBJECTIVE_SCORER_CHAT_KEY="xxxxx"
OBJECTIVE_SCORER_CHAT_MODEL="deployment-name"

AZURE_FOUNDRY_DEEPSEEK_ENDPOINT="https://xxxxx.eastus2.models.ai.azure.com"
AZURE_FOUNDRY_DEEPSEEK_KEY="xxxxx"
AZURE_FOUNDRY_DEEPSEEK_MODEL=""

AZURE_FOUNDRY_PHI4_ENDPOINT="https://xxxxx.models.ai.azure.com"
AZURE_CHAT_PHI4_KEY="xxxxx"
AZURE_FOUNDRY_PHI4_MODEL=""
AZURE_CHAT_PHI4_MODEL=""

AZURE_FOUNDRY_MISTRAL_LARGE_ENDPOINT="https://xxxxx.services.ai.azure.com/openai/v1/"
AZURE_FOUNDRY_MISTRAL_LARGE_KEY="xxxxx"
Expand Down Expand Up @@ -113,7 +141,7 @@ DEFAULT_OPENAI_FRONTEND_MODEL = "gpt-4o"

OPENAI_CHAT_ENDPOINT=${PLATFORM_OPENAI_CHAT_ENDPOINT}
OPENAI_CHAT_KEY=${PLATFORM_OPENAI_CHAT_KEY}
OPENAI_CHAT_MODEL=${PLATFORM_OPENAI_CHAT_GPT4O_MODEL}
OPENAI_CHAT_MODEL=${PLATFORM_OPENAI_CHAT_MODEL}
# The following line can be populated if using an Azure OpenAI deployment
# where the deployment name differs from the actual underlying model
OPENAI_CHAT_UNDERLYING_MODEL=""
Expand Down Expand Up @@ -267,6 +295,7 @@ AZURE_CONTENT_SAFETY_API_KEY="xxxxx"
AZURE_CONTENT_SAFETY_API_ENDPOINT="https://xxxxx.cognitiveservices.azure.com/"

HUGGINGFACE_TOKEN="hf_xxxxxxx"
HUGGINGFACE_ENDPOINT="https://router.huggingface.co/v1"

GOOGLE_GEMINI_ENDPOINT = "https://generativelanguage.googleapis.com/v1beta/openai"
GOOGLE_GEMINI_API_KEY = "xxxxx"
Expand Down
21 changes: 21 additions & 0 deletions .github/ISSUE_TEMPLATE/praise.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
---
name: Praise
about: Tell us something you love about PyRIT or the Co-PyRIT GUI
title: ''
labels: 'praise'
assignees: ''

---

<!--
Thanks for taking the time to share something positive! Pure praise issues
are auto-acknowledged and closed by our triage bot so the team can see them
quickly without cluttering the open-issue backlog.

If you'd also like to report a bug or request a feature, please open a
separate issue using the corresponding template.
-->

#### What do you love?
<!-- Tell us what's working well, what you find useful, or any moment that made
your day easier. -->
15 changes: 7 additions & 8 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,19 +4,16 @@ PyRIT (Python Risk Identification Tool for generative AI) is an open-source fram

## Architecture

PyRIT uses a modular "Lego brick" design. The main extensibility points are:
PyRIT uses a modular pluggable-brick design.

- **Prompt Converters** (`pyrit/prompt_converter/`) — Transform prompts (70+ implementations). Base: `PromptConverter`.
- **Scorers** (`pyrit/score/`) — Evaluate responses. Base: `Scorer`.
- **Prompt Targets** (`pyrit/prompt_target/`) — Send prompts to LLMs/APIs. Base: `PromptTarget`.
- **Executors / Scenarios** (`pyrit/executor/`, `pyrit/scenario/`) — Orchestrate multi-turn attacks.
- **Memory** (`pyrit/memory/`) — `CentralMemory` for prompt/response persistence.
**[`doc/code/framework.md`](../doc/code/framework.md) is the canonical reference for how these pieces fit together.** It defines each component's responsibilities — what it owns and, critically, what it *does not* own — and how scenarios, attack techniques, executors, and the core/shared layers relate. Read it before adding or reviewing components so new code lands in the right place.

## Code Review Guidelines

When performing a code review, be selective. Only leave comments for issues that genuinely matter:

- Bugs, logic errors, or security concerns
- Bugs, correctness, logic errors, or security concerns
- **Component responsibilities** — Each component should do its job and *only* its job, per [`doc/code/framework.md`](../doc/code/framework.md). Flag responsibility bleed: e.g. an executor assembling prepended/system prompts or role-play framing (that's an attack technique), a converter or target making branching decisions (that's an attack/scorer), a scorer acting on its own result (the attack branches), or business logic living in memory/output. If logic belongs in a different brick, say so.
- Unclear code that would benefit from refactoring for readability
- Violations of the critical coding conventions above (async suffix, keyword-only args, type annotations)

Expand All @@ -32,8 +29,10 @@ Aim for fewer, higher-signal comments. A review with 2-3 important comments is b

BEFORE editing or code-reviewing any file, you MUST read the `.github/instructions/` files whose `applyTo` patterns match the files you are about to edit. For example:
- Editing/code-reviewing `pyrit/**/*.py` → read `style-guide.instructions.md` and `user-custom.instructions.md`
- Editing/code-reviewing database models, Alembic migrations, or memory migration tests → also read `database.instructions.md`
- Editing/code-reviewing `pyrit/scenario/**` → also read `scenarios.instructions.md`
- Editing/code-reviewing `pyrit/prompt_converter/**` → also read `converters.instructions.md`
- Editing/code-reviewing `pyrit/setup/initializers/techniques/**` → also read `setup-techniques.instructions.md`
- Editing/code-reviewing `pyrit/converter/**` → also read `converters.instructions.md`
- Editing/code-reviewing `tests/**` → also read `test.instructions.md`
- Editing/code-reviewing `doc/**/*.py` or `doc/**/*.ipynb` → also read `docs.instructions.md`
- Editing/code-reviewing `frontend/**/*.{ts,tsx}` → also read `frontend-style-guide.instructions.md`
Expand Down
Loading
Loading