Skip to content

Releases: secureCodeBox/secureCodeBox

v4.0.1

Choose a tag to compare

@release-drafter release-drafter released this 07 Jun 09:58

v4.0.1

This is a follow up release to fix issues in the v4.0.0 builds.

GitHub commits since tagged version GitHub Repo stars Twitter URL

🐛 Bug Fixes

  • Fixes issues in release builds causing some components not being build correctly in the v4.0.0 release @J12934 (#1752)

Distribution

Artifact HUB
Docker Hub

v4.0.0

Choose a tag to compare

@J12934 J12934 released this 07 Jun 08:41
c96a4cb

v4.0.0

This release has been a long time in the making and brings some awesome improvements to the system as a whole and the auto-discovery in general. Some of these changes required some minor breaking changes, you can find a sumamry of the most important breaking changes in the "💣 Breaking Changes" section below and a complete and detailed list in the Upgrading from 3.x - 4.x notes.

GitHub commits since tagged version GitHub Repo stars Twitter URL

🚀 Features

  • Allow multiple scanTypes to be used in the Service and Container AutoDiscovery @Ilyesbdlala (#1447)
  • Add Cluster Wide Custom Resources (ClusterScanType, ClusterParseDefinition & ClusterScanCompletionHook) @J12934 (#1662): See more in ADR-12
  • Enable Container AutoDiscovery to scan images from private repos @the-simmon (#1374, #1557): See more in ADR-17
  • Added new references attribute to the finding format with unified references to CVEs, CWEs and other external references @Ilyesbdlala (#1676)
  • Added optional identified at parameter to findings (for all scanners which include this info in their results) @Ilyesbdlala (#1434)
  • Added new DNS Scanner: Doggo @rseedorff (#1446)
  • Added option to specify a go template to configure where in the s3 bucket the result files (raw scanner results and findings.json) should be stored. @the-simmon & @J12934 (#1389, #1734)

💣 Breaking Changes

You can find detailed upgrade notes on these braking changes in the upgrading documentation: Upgrading from 3.x - 4.x

Note some breaking changes are missing here and are only referenced in the linked upgrading notes.

  • AutoDiscovery takes a list of scans in config file, allowing it to start more than one scan for a identified resource @the-simmon (#1447)
  • Container AutoDiscovery enabled by default and more consistent behavior compared to Service AutoDiscovery @the-simmon (#1112)
  • SSH-Scan (Mozilla ssh_scan) is now considered deprecated as the tool is no longer maintained by mozilla. As a replacement we've added integration for ssh-audit as a replacement. The ssh-scan integration is still in this release but will be removed in a upcoming release. @Reet00 & @sofi0071 (#1713)
  • Improve Nmap Parser to handle multiple / ipv6 addresses and verbose output @J12934 (#1679)
  • Findings Format: inconsistent ip address fields removed, replaced with standardized ip_addresses @J12934 (#1701, #1748)
  • Allow multiple scanTypes to be used in the Service and Container AutoDiscovery @Ilyesbdlala (#1447)
  • Added optional mitigation attribute to findings @Ilyesbdlala (#1639)
  • Remove AngularCSTI Integration @J12934 (#1649)
  • Renamed Amass attributes.name to attributes.hostname @Ilyesbdlala (#1605)

🚓 Security Scanner

⚓️ Hooks

🐛 Bug Fixes

📚 Documentation

  • Add missing supported platforms (CPU Architectures, e.g. amd64 or arm64) for Scanners to their helm charts and their documentation pages. @snoopy-cat(#1739)

📌 Dependencies

Distribution

Artifact HUB
Docker Hub

Contributors

Thanks to all our contributors supporting this project 🤗
@Ilyesbdlala, @the-simmon, @Reet00, @sofi0071, @ManuelNeuer, @Weltraumschaf, @fphoer, @malexmave, @srburton, @snoopy-cat, @rseedorff and @J12934

v4.0.0-rc.1

v4.0.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@release-drafter release-drafter released this 18 Apr 20:14

Changes

This is the very first release candidate for the upcoming v4 release. All of the features should already be in it but we are still working on some documentation improvements. Any feedback or bugs found are as always very much appreciated 🙌

This release contains breaking changes. The changes are listed in the "💣 Breaking Changes" section below and in the Upgrading from 3.x - 4.x notes.

GitHub commits since tagged version GitHub Repo stars Twitter URL

🚀 Features

  • Add Cluster Wide Custom Resources (ClusterScanType, ClusterParseDefinition & ClusterScanCompletionHook) @J12934 (#1662): See more in ADR-12
  • Enable Container AutoDiscovery to scan images from private repos @the-simmon (#1374, #1557): See more in ADR-17
  • Allow multiple scanTypes to be used in the Service and Container AutoDiscovery @Ilyesbdlala (#1447)
  • Added new references attribute to the finding format with unified references to CVEs, CWEs and other external references @Ilyesbdlala (#1676)
  • Added optional identified at parameter to findings (for all scanners which include this info in their results) @Ilyesbdlala (#1434)
  • Added new DNS Scanner: Doggo @rseedorff (#1446)

💣 Breaking Changes

You can find detailed upgrade notes on these braking changes in the upgrading documentation: Upgrading from 3.x - 4.x

Note some breaking changes are missing here and are only referenced in the linked upgrading notes.

  • Improve Nmap Parser to handle multiple / ipv6 addresses and verbose output @J12934 (#1679)
  • Allow multiple scanTypes to be used in the Service and Container AutoDiscovery @Ilyesbdlala (#1447)
  • Added optional mitigation attribute to findings @Ilyesbdlala (#1639)
  • Remove AngularCSTI Integration @J12934 (#1649)
  • Renamed Amass attributes.name to attributes.hostname @Ilyesbdlala (#1605)

🚓 Security Scanner

⚓️ Hooks

🐛 Bug Fixes

📚 Documentation

📌 Dependencies

Distribution

Artifact HUB
Docker Hub

Contributors

Thanks to all our contributors supporting this project 🤗
@Ilyesbdlala, @J12934, @Weltraumschaf, @fphoer, @malexmave, @srburton, @the-simmon and @rseedorff

v3.16-alpha3

v3.16-alpha3 Pre-release
Pre-release

Choose a tag to compare

@the-simmon the-simmon released this 08 Feb 15:16
1be050a

This is a test release for the upcoming feature described in ADR17 (#1557).

v3.16-alpha2

v3.16-alpha2 Pre-release
Pre-release

Choose a tag to compare

@the-simmon the-simmon released this 08 Feb 14:47
718356d

This is a test release for the upcoming feature described in ADR17 (#1557). This time with the prereleased trigger in release-build.yaml.

v3.16-alpha1

v3.16-alpha1 Pre-release
Pre-release

Choose a tag to compare

@the-simmon the-simmon released this 08 Feb 14:17
3949390

This is a test release for the upcoming feature described in ADR17 (#1557)

v3.15.2

Choose a tag to compare

@J12934 J12934 released this 13 Dec 12:46
ee3f399

Changes

This release is a security release and is highly recommended for all users of the zap-advanced ScanType.

Big thanks to @patrykzzz for pointing out the issue and providing a fix 🙌

GitHub commits since tagged version GitHub Repo stars Twitter URL

🔒 Security

When using the JSON authentication method in the ZAP Advanced scanner the python script configuring the ZAP was logging the credentials (username & password) used. The vulnerability is present in our secureCodeBox scripts, not in ZAP itself. Only the zap-advanced ScanType is affected, zap-baseline-scan, zap-api-scanand zap-full-scan are not affected.

Distribution

Artifact HUB
Docker Hub

Contributors

Thanks to all our contributors supporting this project 🤗
@patrykzzz

v3.15.1

Choose a tag to compare

@Weltraumschaf Weltraumschaf released this 18 Nov 11:55

Changes

This release contains the following changes 🎉. Help spread the word or leave a GitHub star if you like it 😉

GitHub commits since tagged version GitHub Repo stars Twitter URL

🐛 Bug Fixes

  • Fix formaterrors in helm templates:
  • fix(jest): Combines both the config files for jest and sets it to 27.0.6 (workaround #1425) @Ilyesbdlala (#1415)
  • Use specific rule in semgrep integration-test instead of ruleset (fixes #1399) @RamiSouai (#1400)
  • fix zap integration-test (no issue to link) @rebeccan (#1393)

Distribution

Artifact HUB
Docker Hub

Contributors

Thanks to all our contributors supporting this project 🤗
@Ilyesbdlala, @ldimitrov, @RamiSouai, @rebeccan, and @the-simmon

v3.15.0

Choose a tag to compare

@release-drafter release-drafter released this 15 Sep 15:07
fd62b19

Changes

This release contains the following changes 🎉. Help spread the word or leave a GitHub star if you like it 😉

GitHub commits since tagged version GitHub Repo stars Twitter URL

⚠️ Upgrade Notes

This update adds new fields to the Custom Resource Definitions (CRDs), Helm does not update CRDs after the initial installation.
To upgrade the CRDs you can run the following script or grab the latest CRDs from the git repo at the v3.15.0 tag:

kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v3.15.0/operator/crds/cascading.securecodebox.io_cascadingrules.yaml
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v3.15.0/operator/crds/execution.securecodebox.io_parsedefinitions.yaml
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v3.15.0/operator/crds/execution.securecodebox.io_scancompletionhooks.yaml
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v3.15.0/operator/crds/execution.securecodebox.io_scans.yaml
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v3.15.0/operator/crds/execution.securecodebox.io_scantypes.yaml
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v3.15.0/operator/crds/execution.securecodebox.io_scheduledscans.yaml

🚀 Features

  • Add Resources to Scan, ParseDefinition & ScanCompletionHook CRDs @J12934 (#1342)
  • Added podSecurityContext to all scanTypes @rseedorff (#1330, #1339)
  • ZAP Advanced: Add support for additional report types @malexmave (#1320)

🚓 Security Scanner

⚓️ Hooks

  • Added a configuration to disable the automatic dashboard import @rseedorff (#1332, #1338)

📚 Documentation

  • ADR-0012: Initial Proposal for Cluster Wide Custom Resources (e.g. ClusterScanType) @J12934 (#1270)
  • Update Juice Shop URL in documentation example scans @malexmave (#1333)

🔧 Maintenance

  • Fix create-new-scanner Make target @malexmave (#1354)
  • Improved Megalint Config and applied auto fixes @Ilyesbdlala (#1302)
  • Added a configuration to disable the automatic dashboard import (closes #1332) @rseedorff (#1338)
  • Updating amass config due to recent config changes @rseedorff (#1337)
  • Run Helm docs generation only on main branch @Ilyesbdlala (#1291)
  • Add Megalinter output to Gitignore file @malexmave (#1334)
  • Added missing podSecurityContext to scanner template @rseedorff (#1358)

📌 Dependencies

Distribution

Artifact HUB
Docker Hub

Contributors

Thanks to all our contributors supporting this project 🤗
@Ilyesbdlala, @J12934, @Weltraumschaf, @malexmave and @rseedorff

v3.14.3

Choose a tag to compare

@release-drafter release-drafter released this 17 Aug 10:49
e737a3e

Changes

This release contains the following changes 🎉. Help spread the word or leave a GitHub star if you like it 😉

GitHub commits since tagged version GitHub Repo stars Twitter URL

🐛 Bug Fixes

🚓 Security Scanner

📌 Dependencies

  • Upgrade @kubernetes/client-node from 0.16.3 to 0.17.0 @snyk-bot (#1276)

Distribution

Artifact HUB
Docker Hub

Contributors

Thanks to all our contributors supporting this project 🤗
@J12934, @malexmave and @the-simmon