#1118151 RFS: sys-scan-graph/0 -- sytem security scanner

#1118151#5
Date:
2025-10-15 12:45:30 UTC
From:
To:
Dear mentors,

I want to submit **sys-scan-graph** for sponsorship:

 * Package name: sys-scan-graph

 * Upstream contact: Joseph Mazzini (joseph@mazzlabs.works)

 * Version: 5.0.3

 * URL: https://GitHub.com/J-mazz/sys-scan-graph

 * License: Apache-License-Version-2.0

See the public repository for comprehensive documentation.

Thank you for any consideration,
Joseph Mazzini | J-mazz

#1118151#14
Date:
2025-10-15 21:25:02 UTC
From:
To:
Please read on how the Debian ITP process works.
You have to file a bug report on wnpp and reference it in your
changelog.

Why are there already several revisions in your debian/changelog?
It should be the latest one only.

It is usually not a good idea to have the debian package in the upstream
source.

#1118151#23
Date:
2025-10-16 02:40:47 UTC
From:
To:
Hi,

Adding to Bastian's comments, you can consider maintaining your Debian
packaging on https://salsa.debian.org/  and remove the debian/ folder in
the github upstream. Salsa also makes it easier for your potential
sponsors to make any changes to your packaging before the upload or
perform Non-Maintainer Uploads in case there are any issues with your
packages while you're away.

#1118151#32
Date:
2025-10-21 08:05:45 UTC
From:
To:
Dear mentors,

Thank you again for the feedback on the RFS for sys-scan-graph (Bug
#1118151).

I have addressed the points previously raised:

1.  **Separate Packaging Repository:** The Debian packaging files have been
moved out of the upstream source repository and are now maintained
separately here:
    * `https://github.com/J-mazz/sys-scan-debian_package`
<https://github.com/J-mazz/sys-scan-debian_package>

2.  **Changelog:** The `debian/changelog` file has been corrected to
contain only the entry for the initial release (`6.0.0-1`), and it now
references the ITP bug #1118151.

For further context on the package:

* **Upstream Source Repository:** The main C++ scanner and Python agent
source code resides at:
    * `https://github.com/J-mazz/sys-scan-graph`
<https://github.com/J-mazz/sys-scan-graph>
* **PyPI Package:** The Python intelligence layer component is also
available on PyPI under the name `sys-scan-agent`. The Debian package will
ensure correct integration and dependency handling within the Debian
ecosystem.
* **User Interface:** The primary user interface is command-line based. The
Python intelligence layer can generate comprehensive, self-contained HTML
reports for visualizing scan results and analysis. There is also a separate
GTKmm-based graphical UI (`sys-scan-ui`) in development:
    * `https://github.com/J-mazz/sys-scan-ui`
<https://github.com/J-mazz/sys-scan-ui>
    * This UI interacts with the `sys-scan-agent` via IPC (multiprocessing
queues) and allows users to view findings and provide feedback.
    * **Packaging Plan:** To keep the core `sys-scan-graph` package focused
and lightweight, the plan is to package `sys-scan-ui` separately *after*
the core package has been accepted into Debian. This current RFS pertains
only to the core `sys-scan-graph` (CLI scanner and Python agent).

I am awaiting approval to salsa.debian.org. Once complete, I will move the
Debian package source there.

Regards,

Joseph Mazzini
<jmazzini541@gmail.com>

#1118151#37
Date:
2025-10-27 07:49:59 UTC
From:
To:
Hello,

This email provides an update for the Intent to Package report,
Bug#1118183, concerning sys-scan-graph.

I have successfully migrated the project's source repository to Debian's
Salsa platform. The new canonical Git repository URL is now:

https://salsa.debian.org/J-mazz/sys-scan-graph.git

Please use this location for all future reference regarding the packaging
of this software.

Thank you,
Joseph Mazzini
<jmazzini541@gmail.com>
<joseph@mazzlabs.works>

#1118151#40
Date:
2025-11-26 16:42:03 UTC
From:
To:
Are you still working on this? The git repo is scheduled for removal...
#1118151#49
Date:
2025-11-27 05:26:13 UTC
From:
To:
Yes, I am still working on this,
I tried to revert the scheduled deletion. It's current on GitHub.
The embedded agent is a work in progress, I originally used a llama-3 model
that did not meet DFSG I have limited compute & time but I will add finish
feature soon.

Regards,
Joseph Mazzin

#1118151#54
Date:
2025-12-25 05:58:33 UTC
From:
To:
Dear Mentors,

I am writing to formally request that my contact email address for this
Intent to Package be updated to joseph@mazzlabs.works; please utilize this
address for all future correspondence regarding this submission and the
associated package maintenance.

I have pushed the latest upstream source code revisions to the primary
repository located at https://salsa.debian.org/J-mazz/sys-scan-graph. This
update notably integrates both a fine-tuned ML feature and a Qt-based
Graphical User Interface; this interface is designed to facilitate
Human-in-the-Loop (HitL) functionality, allowing for interactive user
oversight during the scanning process.

The specific Debian packaging files continue to be maintained in their
dedicated repository at
https://salsa.debian.org/J-mazz/sys-scan-debian_package.

In support of the package's machine learning capabilities, I have also
uploaded the model fine-tuning workflows and synthetic dataset curation
scripts to https://salsa.debian.org/J-mazz/sys-scan-agent_MLops.git. The
specific dataset utilized for this implementation has been published to the
Hugging Face hub at
https://huggingface.co/datasets/jmazz/sys-scan_synthetic_dataset_v2 to
ensure transparency and reproducibility of the model's behavior.

Thank you for your attention to these updates.

Regards,

Joseph Mazzini

joseph@mazzlabs.works

#1118151#59
Date:
2025-12-25 05:48:53 UTC
From:
To:
Dear Mentors,

I am writing to formally request that my contact email address for this
Intent to Package be updated to joseph@mazzlabs.works; please utilize this
address for all future correspondence regarding this submission and the
associated package maintenance.

I have pushed the latest upstream source code revisions to the primary
repository located at https://salsa.debian.org/J-mazz/sys-scan-graph. This
update notably integrates both a fine-tuned ML feature and a Qt-based
Graphical User Interface; this interface is designed to facilitate
Human-in-the-Loop (HitL) functionality, allowing for interactive user
oversight during the scanning process.

The specific Debian packaging files continue to be maintained in their
dedicated repository at
https://salsa.debian.org/J-mazz/sys-scan-debian_package.

In support of the package's machine learning capabilities, I have also
uploaded the model fine-tuning workflows and synthetic dataset curation
scripts to https://salsa.debian.org/J-mazz/sys-scan-agent_MLops.git. The
specific dataset utilized for this implementation has been published to the
Hugging Face hub at
https://huggingface.co/datasets/jmazz/sys-scan_synthetic_dataset_v2 to
ensure transparency and reproducibility of the model's behavior.

Thank you for your attention to these updates.

Regards,

Joseph Mazzini

joseph@mazzlabs.works

#1118151#64
Date:
2025-12-25 05:48:52 UTC
From:
To:
Dear Mentors,

I am writing to formally request that my contact email address for this
Intent to Package be updated to joseph@mazzlabs.works; please utilize this
address for all future correspondence regarding this submission and the
associated package maintenance.

I have pushed the latest upstream source code revisions to the primary
repository located at https://salsa.debian.org/J-mazz/sys-scan-graph. This
update notably integrates both a fine-tuned ML feature and a Qt-based
Graphical User Interface; this interface is designed to facilitate
Human-in-the-Loop (HitL) functionality, allowing for interactive user
oversight during the scanning process.

The specific Debian packaging files continue to be maintained in their
dedicated repository at
https://salsa.debian.org/J-mazz/sys-scan-debian_package.

In support of the package's machine learning capabilities, I have also
uploaded the model fine-tuning workflows and synthetic dataset curation
scripts to https://salsa.debian.org/J-mazz/sys-scan-agent_MLops.git. The
specific dataset utilized for this implementation has been published to the
Hugging Face hub at
https://huggingface.co/datasets/jmazz/sys-scan_synthetic_dataset_v2 to
ensure transparency and reproducibility of the model's behavior.

Thank you for your attention to these updates.

Regards,

Joseph Mazzini

joseph@mazzlabs.works