Releases: secureCodeBox/secureCodeBox
Releases · secureCodeBox/secureCodeBox
Release list
v1.2.0
Note: This Release pins the version of all the secureCodeBox Services. This is meant to help users pin a stable version and prevent accidental upgrades to incompatible versions. You can pin to this release by checking out the git tag via
git checkout v1.2.0
🕷 Security Scanner
- Add Ncrack Scanner for Identifying Services with weak default Credentials. @jorgestiga (#103)
- Add WPScan Scanner to Scan WordPress Instances for Vulnerabilities @dpatanin (#87)
🚀 Features
- Pin Service Versions in
docker-compose@J12934 (#123) - Add Vagrant Config to provide a Reproducible Docker Environment @rseedorff (#110)
📚 Documentation
- Fix Typo in Readme @sa7mon (#124)
- Update OWASP Project Reference @wurstbrot (#92)
- Adding ADRs Directory @Weltraumschaf (#113)
- Write ADR001 for Combined Scanner @dpatanin (#116)
- Rework the ADR001 @Weltraumschaf (#119)
- Use new Invite Link for Slack @Weltraumschaf (#106, #107)
- Update Documentation for Adding new Scanner @jorgestiga (#105)
- Add Multi Tenancy Docs @J12934 (#100)
- Use the new URI for the OWASP Page @Weltraumschaf (#104)
🐛 Bug Fixes
🔧 Maintenance
- Pin Service Versions in
docker-compose@J12934 (#123) - Stabilize SSH Integration Tests @fuhrmeistery (#101)
- Adjust SSH Target @J12934 (#98)
- Fixed Combined Nmap-Nikto Integration Tests @fuhrmeistery (#112)
- Update Expected SSH Scanner Findings for SCB SSH Finding Format 1.1.0 @J12934 (#97)
- Better Debugging with HTTP Status Codes for the
run-scannerScript @Weltraumschaf (#118)
v1.1.0 SSH Scanner
🔍 Scanner Changes
- Added Mozilla SSH Scanner, to check ssh services for miss-configurations and known vulnerabilities
📚 Documentation
- Clarified documentations on different ways on how securityTests can be started
- Moved documentation on Meta Field further down in the documentation
🧪 Tests
- Added integration test for SSH Scanner
v1.0.2 Doc Fixes and new Issue Template
- Fixed dead links in docs
- Expanded documentation on how to configure the defect-dojo integration
- Added issue template to easily create tickets to integrate new scanner
v1.0.1 CLI and Doc fixes
- Fixed Bug which prevented the CLI from checking the engine status, as it was using a deprecated api which has been removed in
v1.0.0 - Fixed open TODO sections in the user guide, and replaced outdated instructions.
v1.0.0 First Stable Release
secureCodeBox 🔒 v1.0.0 🎉
This is our first non beta release!
This release added a bunch of stuff and we have done a lot to improve the general stability.
Mayor Changes
- DefectDojo persistence provider allowing you to import your findings into DefectDojo. See the persistence provider docs for setup instructions.
- Updated Camunda from 7.8 to 7.10
- Note this requires database upgrades. SQL migration files are provided directly by camunda see:
- Updated the API
- Introduced new securityTest Concept abstracting from the camunda processes, with all related information attached to it.
- Removed the "start process" endpoint and replaced it with the securityTest endpoint enabling you to start securityTest and retrieve their status and results without worrying about the concrete camunda processes.
- Introduced a concept for adding some additional meta-data informations to securityTest
- helpful if you automate the securityTest execution with your buildserver (e.g. Jenkins) and add the build-reference as meta data to your securityTest
- Added BasicAuth for engine to scanner communication
- Added engine health endpoint
- Direct HTTPS support without a separate proxy server
- Introduced Docker Healthchecks for engine and scanner container
Note: You can find the changelogs of the minor changes and fixes in the release notes of the individual repositories.