Skip to content

Support pySigma 2.0 - #40

Draft
cristianchiriac wants to merge 1 commit into
logpoint:mainfrom
cristianchiriac:support-pysigma-2
Draft

cristianchiriac wants to merge 1 commit into
logpoint:mainfrom
cristianchiriac:support-pysigma-2

Conversation

@cristianchiriac

Copy link
Copy Markdown
Contributor

pySigma 2.0.0 was released on 2026-10-04. This backend currently requires pysigma = "^1.4.0", so it can't be installed alongside 2.0.

Changes

  • pyproject.toml: pysigma = "^2.0.0". poetry.lock was regenerated with poetry lock. The resolved changes are pysigma 1.4.0 → 2.0.0, the new google-re2 dependency, packaging 26.2 → 26.3, and removal of the 3.10-only exceptiongroup/tomli.
  • pySigma 2.0 requires Python ≥ 3.11, so python = "^3.11". 3.10 is removed from the test matrix and the README.
  • test_logpoint_windows_hashes_duplicates: HashesFieldsDetectionItemTransformation now strips wildcards from hash values (SigmaHQ/pySigma@44d9ba0). Hashes|contains: 'MD5=…' therefore converts to hash="…" instead of hash="…*". The test expected the old trailing *; it now expects exact hash matches, the same as the md5:/sha1: selection in the same rule.

Testing: after poetry install from the new lock (pySigma 2.0.0, Python 3.11), pytest gives 54 passed. Without the test change, only test_logpoint_windows_hashes_duplicates fails. It also fails on pySigma 1.5.1, so any version newer than the current lock needs this update.

pySigma 2.0.0 was released on 2026-10-04. Require pysigma ^2.0.0 and refresh
poetry.lock.

pySigma 2.0 requires Python 3.11, so raise the Python requirement and drop 3.10
from the test matrix and the README.

HashesFieldsDetectionItemTransformation now strips wildcards from hash values
(SigmaHQ/pySigma 44d9ba0), so a Hashes|contains value converts to an exact
hash match. Update the expected query in test_logpoint_windows_hashes_duplicates.
@cristianchiriac

Copy link
Copy Markdown
Contributor Author

Update: the red CI here is not caused by this change. pySigma 2.0.0 turned sigma into a regular package (it added sigma/__init__.py), so a plugin installed in editable mode, which is what poetry install does, can no longer be imported: ModuleNotFoundError: No module named 'sigma.backends...'. I reported and proposed a fix upstream in SigmaHQ/pySigma#584.

Correction to the description above: my local runs that passed used a non-editable install of this backend (pip install .), not plain poetry install. Sorry for the imprecise wording. I'm marking this as a draft until a pySigma release contains the fix, and will then refresh the lock file.

@cristianchiriac
cristianchiriac marked this pull request as draft October 5, 2026 16:31

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant