Repository navigation
FEAT Add runtime Techniques registry to the GUI - #3047
Merged
Richard Lundeen (richlundeen) merged 19 commits intoOct 10, 2026
Merged
Richard Lundeen (richlundeen) merged 19 commits into
Richard Lundeen (richlundeen) merged 19 commits into
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove TechniqueDefinition and the parallel structured-input resolver. Keep REST creation to basic attack parameters, converter references, and inline adversarial settings. Advanced seeds and conversation settings remain Python-only. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Restore the registry resolver contract to main. Limit REST input checks to the technique service and remove duplicate runtime technique documentation from the registry guide. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject inherited scenario enum names before runtime registration, keep structured forms within shared resolver capabilities, and reuse complete-list pagination. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep both imports required by the fixed-catalog regression and current scenario run-plan tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve compatible resolved selections across factory additions. Validate candidates against scenario-local pools before registration, and reuse attack-owned configuration checks for deferred construction. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Roman Lutz (romanlutz)
approved these changes
Oct 10, 2026
Preserve revision-aware technique catalogs with explicit dataset sources and limits. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Richard Lundeen (richlundeen)
enabled auto-merge
October 10, 2026 22:49
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 10, 2026
Richard Lundeen (richlundeen)
deleted the
richlundeen-techniques-registry-ui
branch
October 10, 2026 23:53
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds Techniques beside Targets and Converters in the GUI Registry. Users can search and filter the active technique catalog, inspect a short factory creation call, and add named configurations of registered attack classes. This is the follow-up to #2952.
AttackTechniqueFactoryinstances and the existingAttackRegistry; there is no second attack catalog or live attack-instance registry.Additions are runtime-only. A restart or reinitialization removes them. This feature does not change dependencies or database schemas. Current
mainis merged, and its conflicts are resolved.Screenshots
Technique list — Search and filter the active factory catalog.
Technique details — Show the supplied factory creation call without identifiers or expanded internal settings.
Add a technique — Configure an existing attack with a name, tags, supported parameters, and converter references.
Tests and Documentation
Updated the backend API documentation and added backend, registry, GUI, API-client, and real-backend browser coverage. The regressions cover atomic admission, cache refresh, old snapshots, creation-call display, reference order, false/zero/empty values, nested form capabilities, pagination, and stale runtime responses.
All commands below passed after merging current
main. Commands ran from the repository root, except the frontend commands, which ran fromfrontend:uv run --no-sync pytest tests\unit\registry\test_attack_technique_registry.py tests\unit\registry\test_attack_technique_construction.py tests\unit\backend\test_technique_service.py tests\unit\backend\test_scenario_service.py tests\unit\scenario\core\test_attack_technique_factory.py tests\unit\scenario\airt\test_leakage.py tests\unit\scenario\airt\test_multilingual.py tests\unit\scenario\scenarios\adaptive\test_text_adaptive.py -quv run --no-sync pytest tests\unit\backend\test_scenario_run_service.py -qnpm test -- --watch=false --runInBand TechniqueRegistry.test.tsx fetchAllPages.test.ts api.test.ts RegistryLayout.test.tsx parameterForm.test.ts ParameterField.test.tsxnpm run buildnpx eslint src\components\Registry\CreateTechniqueDialog.tsx src\components\Registry\TechniqueRegistry.test.tsx src\utils\fetchAllPages.ts src\utils\fetchAllPages.test.tsuv run --no-sync pre-commit run --all-fileswithUV_NO_SYNC=1npm run test:e2e -- 'registry\.spec\.ts' --project seeded --grep 'creates and selects a runtime technique' --retries 0 --reporter listwith dedicated seeded serversThe browser check verifies runtime registration and scenario selection without prompt sends. It ran with
CI=true,E2E_SEEDED_MODE=true,E2E_FRONTEND_PORT=18843, andPYRIT_E2E_BACKEND_PORT=18842. Build identities were stamped before starting both servers.JupyText was not run: no paired Python/notebook documentation changed. The full unit suite was not run; the scoped commands above cover the affected behavior.