Skip to content

Releases: secureCodeBox/secureCodeBox

v1.2.0

Choose a tag to compare

@J12934 J12934 released this 18 May 13:09
dab9d13

Note: This Release pins the version of all the secureCodeBox Services. This is meant to help users pin a stable version and prevent accidental upgrades to incompatible versions. You can pin to this release by checking out the git tag via git checkout v1.2.0

🕷 Security Scanner

  • Add Ncrack Scanner for Identifying Services with weak default Credentials. @jorgestiga (#103)
  • Add WPScan Scanner to Scan WordPress Instances for Vulnerabilities @dpatanin (#87)

🚀 Features

  • Pin Service Versions in docker-compose @J12934 (#123)
  • Add Vagrant Config to provide a Reproducible Docker Environment @rseedorff (#110)

📚 Documentation

🐛 Bug Fixes

🔧 Maintenance

  • Pin Service Versions in docker-compose @J12934 (#123)
  • Stabilize SSH Integration Tests @fuhrmeistery (#101)
  • Adjust SSH Target @J12934 (#98)
  • Fixed Combined Nmap-Nikto Integration Tests @fuhrmeistery (#112)
  • Update Expected SSH Scanner Findings for SCB SSH Finding Format 1.1.0 @J12934 (#97)
  • Better Debugging with HTTP Status Codes for the run-scanner Script @Weltraumschaf (#118)

v1.1.0 SSH Scanner

Choose a tag to compare

@J12934 J12934 released this 24 Jun 08:59
1729c2a

🔍 Scanner Changes

  • Added Mozilla SSH Scanner, to check ssh services for miss-configurations and known vulnerabilities

📚 Documentation

  • Clarified documentations on different ways on how securityTests can be started
  • Moved documentation on Meta Field further down in the documentation

🧪 Tests

  • Added integration test for SSH Scanner

v1.0.2 Doc Fixes and new Issue Template

Choose a tag to compare

@J12934 J12934 released this 11 Apr 11:32
  • Fixed dead links in docs
  • Expanded documentation on how to configure the defect-dojo integration
  • Added issue template to easily create tickets to integrate new scanner

v1.0.1 CLI and Doc fixes

Choose a tag to compare

@J12934 J12934 released this 20 Mar 16:32
b6440cf
  • Fixed Bug which prevented the CLI from checking the engine status, as it was using a deprecated api which has been removed in v1.0.0
  • Fixed open TODO sections in the user guide, and replaced outdated instructions.

v1.0.0 First Stable Release

Choose a tag to compare

@rfelber rfelber released this 13 Feb 13:18
v1.0.0
ffd3366

secureCodeBox 🔒 v1.0.0 🎉

This is our first non beta release!
This release added a bunch of stuff and we have done a lot to improve the general stability.

Mayor Changes

  • DefectDojo persistence provider allowing you to import your findings into DefectDojo. See the persistence provider docs for setup instructions.
  • Updated Camunda from 7.8 to 7.10
  • Updated the API
    • Introduced new securityTest Concept abstracting from the camunda processes, with all related information attached to it.
    • Removed the "start process" endpoint and replaced it with the securityTest endpoint enabling you to start securityTest and retrieve their status and results without worrying about the concrete camunda processes.
    • Introduced a concept for adding some additional meta-data informations to securityTest
      • helpful if you automate the securityTest execution with your buildserver (e.g. Jenkins) and add the build-reference as meta data to your securityTest
    • Added BasicAuth for engine to scanner communication
    • Added engine health endpoint
  • Direct HTTPS support without a separate proxy server
  • Introduced Docker Healthchecks for engine and scanner container

Note: You can find the changelogs of the minor changes and fixes in the release notes of the individual repositories.