High-speed file integrity scanner for attested vs unattested data using .f33 sidecars.
2.8K
High-speed file integrity and baseline scanner. Walks one or more roots, measures data gravity (bytes), and classifies large files as attested or unattested based on sibling sidecar presence (.f33, .sig, .asc, .sha256, .sha512, .blake3, .md5, .pem). Emits checksum baselines (Hash Filename format), CSV, or JSON for use with fors33-verifier.
Trust model: The scanner is an O(1) discovery and liability mapping tool based on sidecar presence only. It does not validate Ed25519 signatures or cryptographic proof of baselines. For full cryptographic verification, use fors33-verifier.
Legal: Fors33 Scanner quantifies attestation coverage only. It does not establish, guarantee, or certify regulatory compliance. See DISCLAIMER.md and full legal terms at fors33.com/legal.
For structured package context, see LLM_CONTEXT.md.
hash_file_algos: one disk pass for multiple algorithms; hash_file stays the public single-algo wrapper.execute_scan(..., include_sha256=False): optional SHA-256 companion digest on baseline records when algo is not sha256. Default CLI output is unchanged.Fors33 Scanner with GHCR pin ghcr.io/fors33-official/fors33-scanner:v0.9.1. No file uploads to Fors33.should_cancel= on scan_roots / execute_scan (raises ScanCancelled).has_sidecar on walks: unverified samples record a skip-ext sibling that did not confer attestation; execute_scan keeps the flag.--tsa-url: sets FORS33_TSA_URL for downstream seal tooling; the scanner does not request timestamps.execute_scan(..., wants_baseline=True) on a file path now emits baseline records (previously returned zero candidates).workflow_dispatch version, and Docker images all use vX.Y.Z (e.g. v0.8.3, :v0.8.3).manifest_core helpers; payload members under BagIt data/ count as attested during directory walks.is_epoch_upload_companion_basename in hash_core (epoch bundle companion skips).--legacy-scanner-stats or FORS33_SCANNER_LEGACY_STATS=1 restores single-file below-threshold skipped_files counting and treats .blake3 siblings as not conferring external attestation coverage (library: legacy_scanner_stats bundles both; below_threshold_single_file_counts_skipped and recognize_blake3_sidecar remain available separately on scan_roots / execute_scan)._scan_single_file uses stat(..., follow_symlinks=False), os.scandir sibling discovery with is_file(follow_symlinks=False), skips when the root basename is itself a recognized sidecar suffix, and applies to scan_roots as well as execute_scan..blake3 is part of _ATT_EXTS so BLAKE3 companions classify as external attestation coverage.skipped_files (silent skip, extension-style).has_sidecar on unverified samples: ScanStats.add_unverified_sample(..., *, has_sidecar=False) records "has_sidecar": "true" or "false" on each sampled unattested path (same shape as the L3dgr extension) for downstream re-seal UX.publish-fors33-scanner attach SBOM and SLSA provenance (sbom: true, provenance: mode=max). Pin by digest for regulated deployments..f33, .sig, .asc, checksum sidecars, etc.), baseline/JSON/JSONL on single-file paths, stricter --strict-audit and zero-byte threshold behavior.hash_core mmap ceilings, cgroup alignment, worker cap 64, default_dpk_worker_count() / FORS33_DPK_MAX_WORKERS.--strict-audit, unverified_paths_sample, --tsa-url, JSONL multi-root metadata, --max-exposure, --emit-jsonl, --max-depth. Full text: CHANGELOG.md.workflow_dispatch with explicit version = vX.Y.Z (e.g. v0.8.3) and push_latest; bare X.Y.Z is rejected. It does not run automatically on git tags alone. PyPI releases use the same vX.Y.Z string in pyproject.toml (python -m build, twine upload).pip install fors33-scanner
Scan the current directory (default root) with a 1 MB threshold:
fors33-scanner --threshold-mb 1.0
Scan multiple roots:
fors33-scanner --root /var/log --root /data/telemetry --threshold-mb 10
Emit JSON instead of human output (for CI, pipelines):
fors33-scanner --root /data --json
Fail CI/CD when exposure breaches policy threshold:
fors33-scanner --root /data --max-exposure 5.0 --json
Throttle hashing workers for shared runners:
fors33-scanner --root /data --workers 2
Stream SIEM-ready JSONL events (records + summary):
fors33-scanner --root /data --emit-jsonl -
Depth-limit traversal (0=root only, 1=root + direct children):
fors33-scanner --root /data --max-depth 1
Strict audit (fail on permission or file-lock errors instead of skipping):
fors33-scanner --root /data --strict-audit
Single-file scanning:
# Scan a single file
fors33-scanner --root /path/to/file.csv
# Scan a single file with baseline generation
fors33-scanner --root /path/to/file.csv --emit-checksums baseline.txt
# Scan a single file with JSON manifest
fors33-scanner --root /path/to/file.csv --emit-json manifest.json
Single-file mode accepts individual file paths in addition to directories, enabling direct scanning of specific files without directory traversal. By default it recognizes all attestation sidecar extensions (.f33, .sig, .asc, .sha256, .sha512, .blake3, .md5, .pem) for parity with directory scanning.
Pre-0.8.0 stats (below-threshold single-file roots bump skipped_files, and .blake3 siblings are not counted as external attestation):
fors33-scanner --root /data --legacy-scanner-stats
Equivalent: set FORS33_SCANNER_LEGACY_STATS=1.
Record TSA endpoint for tooling that reads FORS33_TSA_URL:
fors33-scanner --tsa-url https://tsa.example.com/rfc3161
Worker count: positive --workers wins; otherwise a positive FORS33_WORKERS; otherwise default_dpk_worker_count() (uses cpu_count and optional FORS33_DPK_MAX_WORKERS). Non-positive values mean auto. Hard cap 64.
Large-file hashing uses FORS33_MMAP_MIN_MB / FORS33_MMAP_MAX_MB (defaults 500 / 4000), clamped to cgroup/RAM ceiling on Linux; optional FORS33_MMAP_PSI_SOME_AVG10_MAX disables mmap under memory pressure.
For production Docker or CI, pin a semver image tag or immutable digest instead of relying on :latest alone.
Use Fors33 Scanner on the runner. No file uploads to Fors33. Inputs match action.yml: root (default workspace), threshold-mb, json (true for JSON summary). Pin a digest for regulated CI.
- name: Scan coverage
uses: fors33-official/[email protected]
with:
root: .
json: 'true'
Optional policy fail: pass --max-exposure via a follow-on docker run of the same pinned image. Directory/sidecar verify belongs to Fors33 Verifier, not this Action.
Generate checksum baseline (sha256, sha512, or blake3 per --algo):
fors33-scanner --root /data --emit-checksums fors33_baseline.sha256
fors33-scanner --root /data --algo sha512 --emit-checksums fors33_baseline.sha512
Emit CSV or JSON baseline (compatible with fors33-verifier):
fors33-scanner --root /data --emit-csv fors33_baseline.csv
fors33-scanner --root /data --emit-json fors33_baseline.json
Add compliance exposure text to human output (default is strictly mathematical):
fors33-scanner --root /data --compliance-report
0: successful scan / threshold not breached1: exposure threshold breach (--max-exposure)2: invocation/parameter misuse, or --strict-audit I/O access failure130: user interrupted scan (Ctrl+C)Default human output (mathematical only):
[FILE COUNT] : 14,205
[TOTAL BYTES] : 2.1 TB
[ATTESTED] : 48 files, 4.1 GB
[UNATTESTED] : 264 files, 2.1 TB
[ELAPSED] : 4.20s
stderr on startup so data/JSON streams on stdout remain parse-safe.Published images:
docker.io/fors33/fors33-scannerghcr.io/fors33-official/fors33-scannerdocker run --rm ghcr.io/fors33-official/fors33-scanner:v0.10.0 --root /data --threshold-mb 1.0
# or
docker run --rm docker.io/fors33/fors33-scanner:v0.10.0 --root /data --json
Published images include SBOM and build provenance metadata (expand Release notes & version history near the top of this README). Pin a version tag or immutable digest in production pipelines.
--emit-jsonl PATH emits one flat JSON object per line.root_index and root_path in each scan_record.timestamp represents hash completion time.scan_summary with aggregate stats and scan parameters.--emit-jsonl - and --json are both requested, JSONL takes precedence on stdout.unverified_paths_sample entries (JSON/JSONL consumers): each row includes path, status, and has_sidecar ("true" / "false") since 0.7.1 for integration with seal/re-seal workflows.Python 3.9+. Optional blake3 for BLAKE3 hashing. Linux, macOS, Windows.
MIT License. Copyright (c) 2026 Fors33, Inc. See LICENSE. Legal and regulatory boundaries: DISCLAIMER.md and fors33.com/legal.
Content type
Image
Digest
sha256:98e2d3a43…
Size
21.2 MB
Last updated
14 days ago
docker pull fors33/fors33-scanner