Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Releases: secureCodeBox/secureCodeBox

v4.16.0

29 Apr 12:47
Compare
Choose a tag to compare

What's Changed

Note: This is planned to be the last planned feature release before secureCodeBox v5.0.0.
In case of important bugs, we will still publish bug fix releases under 4.16.x :)

πŸš“ Security Scanner

⛩️ DefectDojo

  • Use native DefectDojo Importer for SSH Audit results by @J12934 in #3004

πŸ› Bug Fixes

  • Fix Issue with nested Kubernetes Native Objects not being properly configurable in the Kubernetes AutoDiscovery Config by @BorisShek in #2982
  • Fix Invalid ARM Image for DefectDojo hook by @J12934 in #2993

πŸ“š Documentation

  • Reorder sections in upgrading.md to list the newest first by @BorisShek in #3000
  • Update supported Kubernetes versions by @J12934 in #3003
  • Add Link to OWASP Stammtisch Hamburg Talk by @J12934 in #3005
  • Fix ncrack config in network scanning how-to by @J12934 in #2995

πŸ”§ Maintenance

πŸ“Œ Dependencies

  • Update to Go to 1.24 & Update Go Libraries by @Weltraumschaf in #2978
  • Bump golang.org/x/net from 0.37.0 to 0.38.0 in /auto-discovery/cloud-aws by @dependabot in #2986
  • Bump http-proxy-middleware from 2.0.7 to 2.0.9 in /documentation in the npm-security-updates group by @dependabot in #2992

Full Changelog: v4.15.0...v4.16.0

v4.15.0

08 Apr 11:53
Compare
Choose a tag to compare

What's Changed

πŸš“ Security Scanner

πŸ“Œ Dependencies

  • Bump @types/node from 22.13.8 to 22.13.10 in /documentation in the npm-version-updates group by @dependabot in #2934
  • Bump the npm-version-updates group in /documentation with 3 updates by @dependabot in #2952
  • Bump the npm-version-updates group in /documentation with 3 updates by @dependabot in #2962
  • Bump image-size from 1.2.0 to 1.2.1 in /documentation in the npm-security-updates group by @dependabot in #2966
  • Bump the npm-version-updates group in /documentation with 4 updates by @dependabot in #2969
  • Bump estree-util-value-to-estree from 3.2.1 to 3.3.3 in /documentation in the npm-security-updates group by @dependabot in #2971

πŸ“š Documentation

Full Changelog: v4.14.0...v4.15.0

v4.14.0

18 Mar 12:24
Compare
Choose a tag to compare

What's Changed

πŸš€ Features

πŸš“ Security Scanner

βš“οΈ Hooks

πŸ› Bug Fixes

πŸ“š Documentation

  • Clarify Container AutoDiscovery being disable by default @BorisShek in #2924

πŸ”§ Maintenance

πŸ“Œ Dependencies

  • Update version of minio chart used by default operator install by @J12934 in #2891
  • Bump the gradle-version-updates group across 1 directory with 3 updates by @dependabot in #2868
  • Update operators to latest kubebuilder versions by @J12934 in #2890
  • Bump the npm-version-updates group in /documentation with 2 updates by @dependabot in #2899
  • Bump io.freefair.lombok from 8.12 to 8.12.1 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot in #2898
  • Bump the npm-version-updates group in /documentation with 4 updates by @dependabot in #2907
  • Bump org.springframework:spring-web from 6.2.2 to 6.2.3 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot in #2906
  • Bump serialize-javascript from 6.0.1 to 6.0.2 in /documentation in the npm-security-updates group by @dependabot in #2908
  • Bump jsonpath-plus from 10.2.0 to 10.3.0 in /hooks by @dependabot in #2912
  • Bump @types/node from 22.13.4 to 22.13.5 in /documentation in the npm-version-updates group by @dependabot in #2917
  • Bump the npm-version-updates group in /documentation with 3 updates by @dependabot in #2925
  • Bump prismjs from 1.29.0 to 1.30.0 in /documentation in the npm-security-updates group by @dependabot in #2937
  • Bump golang.org/x/net from 0.30.0 to 0.36.0 in /lurker by @dependabot in #2941
  • Bump @babel/helpers from 7.26.0 to 7.26.10 in /hooks by @dependabot in #2943
  • Bump the npm-security-updates group in /documentation with 2 updates by @dependabot in #2944

New Contributors

Full Changelog: v4.13.0...v4.14.0

v4.13.0

04 Feb 13:23
Compare
Choose a tag to compare

πŸš€ Features

  • Add ARM support for SSH-Audit and SSLyze by @J12934 in #2884

πŸ› Bug Fixes

  • Grant delete permissions for ScheduledScans in AutoDiscovery by @BorisShek in #2871

πŸš“ Security Scanner

πŸ“š Documentation

πŸ“Œ Dependencies

  • Bump mikefarah/yq from 4.44.6 to 4.45.1 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot in #2841
  • Bump the npm-version-updates group across 1 directory with 12 updates by @dependabot in #2842
  • Bump the npm-version-updates group across 1 directory with 3 updates by @dependabot in #2880
  • Bump golang.org/x/net from 0.25.0 to 0.33.0 in /auto-discovery/cloud-aws by @dependabot in #2879
  • Bump @types/node from 22.12.0 to 22.13.0 in /documentation in the npm-version-updates group by @dependabot in #2881
  • Bump golang.org/x/net from 0.23.0 to 0.33.0 in /auto-discovery/kubernetes by @dependabot in #2883

πŸ”§ Maintanance

  • Revert "Replace SCB-token with github token" by @Reet00 in #2856

Full Changelog: v4.12.0...v4.13.0

v4.12.0

09 Jan 10:38
Compare
Choose a tag to compare

πŸš“ Security Scanner

πŸ“š Documentation

  • Add Talk From Bulat Gafurov from Ufadevconf #2810
  • Add Sergios talk at Ekoparty 2024 #2818
  • Add Blog Post announcing OWASP secureCodeBox and Friends Assembly at 38C3 by @Weltraumschaf in #2820
  • Restructure and Cleanup DefectDojo Hook Docs by @J12934 in #2822
  • Fix Markdown Causing a Broken Link On The Nmap Docs Page by @Weltraumschaf in #2821

πŸ”§ Maintenance

  • Adjust release note grouper for release notes generated by the native github feature by @J12934 in #2795
  • Fix Docker Build Warnings by @J12934 in #2824
  • Remove Comment to Prevent REUSE Check Failing to interpret License Tags by @Weltraumschaf in #2812
  • Bugfix Corrected branches keyword trigger workflow correctly by @Reet00 in #2794
  • Avoid run fail for dependabot PRs by @Reet00 in #2827

πŸ“Œ Dependencies

  • Bump the npm-security-updates group in /documentation with 2 updates by @dependabot in #2796
  • Bump the npm-version-updates group in /documentation with 5 updates by @dependabot in #2807
  • Bump the npm-version-updates group across 5 directories with 3 updates by @dependabot in #2806
  • Bump golang.org/x/crypto from 0.21.0 to 0.31.0 in /auto-discovery/cloud-aws by @dependabot in #2808
  • Bump nanoid from 3.3.7 to 3.3.8 in /documentation in the npm-security-updates group by @dependabot in #2803
  • Bump org.springframework:spring-web from 6.2.0 to 6.2.1 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot in #2805
  • Bump org.junit:junit-bom from 5.11.3 to 5.11.4 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot in #2814
  • Bump the github-actions-version-updates group across 1 directory with 2 updates by @dependabot in #2800
  • Use Latest Temurin 17.0.13 in SDKMAN Config by @Weltraumschaf in #2823
  • Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 2 updates by @dependabot in #2832

Full Changelog: v4.11.0...v4.12.0

v4.11.0

04 Dec 15:06
Compare
Choose a tag to compare

What's Changed

πŸš“ Security Scanner

πŸ› Bug Fixes

  • Handle 'Packages' attribute in Trivy parser by @BorisShek in #2727
  • Fix Duplicate Env Vars Added To Hook Kubernetes Job by @J12934 in #2779

πŸ“š Documentation

πŸ”§ Maintenance

  • Replace release drafter config with build in github config by @J12934 in #2792
  • Added workflow that adds bot PRs directly into To Review column by @Reet00 in #2758

πŸ“Œ Dependencies

Minor dependency updates (16 pull requests). Click to expand.
  • Bump cross-spawn from 7.0.3 to 7.0.6 in /auto-discovery/kubernetes/pull-secret-extractor/integration-test by @dependabot in #2763
  • Bump jsonpath-plus from 10.0.1 to 10.2.0 in the npm-security-updates group across 1 directory by @dependabot in #2762
  • Temporary Ignore Broken Defect Dojo Client Lib by @Weltraumschaf in #2746
  • Bump jsonpath-plus from 10.0.6 to 10.2.0 in /auto-discovery/kubernetes/pull-secret-extractor/integration-test by @dependabot in #2767
  • Bump @types/node from 22.8.7 to 22.9.0 in the npm-version-updates group by @dependabot in #2751
  • Bump the npm-version-updates group in /documentation with 18 updates by @dependabot in #2771
  • Bump the npm-version-updates group across 7 directories with 12 updates by @dependabot in #2772
  • Bump cross-spawn from 7.0.3 to 7.0.6 in the npm-security-updates group by @dependabot in #2768
  • Bump the gradle-version-updates group across 1 directory with 10 updates by @dependabot in #2770
  • Bump cross-spawn from 7.0.3 to 7.0.6 in /documentation in the npm-security-updates group by @dependabot in #2775
  • Bump the npm-security-updates group across 2 directories with 2 updates by @dependabot in #2777
  • Bump cross-spawn from 7.0.3 to 7.0.6 in /hooks by @dependabot in #2774
  • Bump the npm-version-updates group across 7 directories with 3 updates by @dependabot in #2781
  • Bump the npm-version-updates group in /documentation with 8 updates by @dependabot in #2780
  • Bump @types/node from 22.9.3 to 22.10.1 in /documentation in the npm-version-updates group by @dependabot in #2782
  • Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 5 updates by @dependabot in #2783
  • Bump the npm-version-updates group across 7 directories with 3 updates by @dependabot in #2784

Full Changelog: v4.10.0...v4.11.0

v4.10.0

15 Nov 10:52
Compare
Choose a tag to compare

Changes

This release contains the following changes πŸŽ‰. Help spread the word or leave a GitHub star if you like it πŸ˜‰

GitHub commits since tagged version GitHub Repo stars Mastodon URL

πŸš€ Features

πŸš“ Security Scanner

πŸ› Bug Fixes

πŸ“š Documentation

βš™οΈ Maintanance

πŸ“Œ Dependencies

  • Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 4 updates @dependabot (#2696)
  • Bump jest-runner-eslint from 2.2.0 to 2.2.1 in the npm-version-updates group @dependabot (#2697)
  • Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 8 updates @dependabot (#2686)
  • Bump @types/node from 22.5.5 to 22.7.4 in the npm-version-updates group @dependabot (#2687)

Distribution

Artifact HUB
Docker Hub

Contributors

Thank you to all our contributors supporting this project πŸ€—
@Freedisch, @J12934, @Michael-Kruggel, @Reet00, @Weltraumschaf, @ddddddO and Vanessa Hermann

v4.9.0

27 Sep 14:14
Compare
Choose a tag to compare

Changes

This release contains the following changes πŸŽ‰. Help spread the word or leave a GitHub star if you like it πŸ˜‰

GitHub commits since tagged version GitHub Repo stars Mastodon URL

πŸš€ Features

πŸš“ Security Scanner

πŸ› Bug Fixes

  • Fix Issue MS Teams Notification Hook Not Being Able To Deliver Messages @J12934 (#2666)

πŸ“š Documentation

  • Add link to secureCodeBox Talk at the ContainerDays 2024 @J12934 (#2663)

πŸ“Œ Dependencies

Minor dependency updates (4 pull requests). Click to expand.
  • Bump org.springframework:spring-web from 6.1.12 to 6.1.13 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group @dependabot (#2658)
  • Bump peter-evans/create-pull-request from 6 to 7 in /.github/workflows in the github-actions-version-updates group @dependabot (#2650)
  • Bump the npm-version-updates group with 4 updates @dependabot (#2659)
  • Bump @types/node from 22.5.2 to 22.5.4 in the npm-version-updates group @dependabot (#2649)

Distribution

Artifact HUB
Docker Hub

Contributors

Thanks to all our contributors supporting this project πŸ€—
@J12934 and @Michael-Kruggel

v4.8.0

06 Sep 14:08
Compare
Choose a tag to compare

Changes

This release contains the following changes πŸŽ‰. Help spread the word or leave a GitHub star if you like it πŸ˜‰

GitHub commits since tagged version GitHub Repo stars Mastodon URL

⚠️ Upgrade Notes

This release contains a fix in the Custom Resource Definitions (CRDs), Helm does not update CRDs after the initial installation.
To upgrade the CRDs you can run the following script or grab the latest CRDs from the git repo at the v4.8.0 tag:

kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v4.8.0/operator/crds/cascading.securecodebox.io_cascadingrules.yaml	
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v4.8.0/operator/crds/execution.securecodebox.io_clusterparsedefinitions.yaml	
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v4.8.0/operator/crds/execution.securecodebox.io_clusterscancompletionhooks.yaml	
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v4.8.0/operator/crds/execution.securecodebox.io_clusterscantypes.yaml	
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v4.8.0/operator/crds/execution.securecodebox.io_parsedefinitions.yaml	
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v4.8.0/operator/crds/execution.securecodebox.io_scancompletionhooks.yaml	
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v4.8.0/operator/crds/execution.securecodebox.io_scans.yaml	
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v4.8.0/operator/crds/execution.securecodebox.io_scantypes.yaml	
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v4.8.0/operator/crds/execution.securecodebox.io_scheduledscans.yaml

πŸš€ Features

  • Add a optional ttlSecondsAfterFinished field to scans to cleanup finished scans #2293 @Reet00 (#2631)
  • Support setting env variables for Scans generated by the Kubernetes AutoDiscovery @J12934 (#2628)
  • Add cascade CLI Command To Visualize Cascaded Scans Hierarchy @Freedisch (#2608)
  • Add option to disable tls connection between the operator and the s3 endpoint @Michael-Kruggel (#2637)

πŸš“ Security Scanner

πŸ› Bug Fixes

  • Add a custom entry script for ZAP Automation Framework to ensure that scans are compelting even when they have warning @J12934 (#2627)

πŸ“š Documentation

πŸ“Œ Dependencies

Minor dependency updates (11 pull requests). Click to expand.
  • Bump @types/node from 22.5.0 to 22.5.2 in the npm-version-updates group @dependabot (#2641)
  • Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 2 updates @dependabot (#2640)
  • Bump the gradle-version-updates group across 1 directory with 3 updates @dependabot (#2633)
  • Bump oxsecurity/megalinter from 7 to 8 in /.github/workflows in the github-actions-version-updates group @dependabot (#2632)
  • Bump the npm-version-updates group with 2 updates @dependabot (#2634)
  • Bump micromatch from 4.0.5 to 4.0.8 in /auto-discovery/kubernetes/pull-secret-extractor/integration-test @dependabot (#2635)
  • Bump @types/node from 22.2.0 to 22.4.1 in the npm-version-updates group @dependabot (#2623)
  • Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 3 updates @dependabot (#2617)
  • Bump @types/node from 22.1.0 to 22.2.0 in the npm-version-updates group @dependabot (#2616)
  • Bump the npm-version-updates group with 2 updates @dependabot (#2610)
  • Bump mikefarah/yq from 4.44.2 to 4.44.3 in /.github/workflows in the github-actions-version-updates group @dependabot (#2611)

Distribution

Artifact HUB
Docker Hub

Contributors

Thanks to all our contributors supporting this project πŸ€—
@Freedisch, @J12934, @Michael-Kruggel and @Reet00

v4.7.0

31 Jul 15:57
Compare
Choose a tag to compare

Changes

This release contains the following changes πŸŽ‰. Help spread the word or leave a GitHub star if you like it πŸ˜‰

GitHub commits since tagged version GitHub Repo stars Mastodon URL

πŸš€ Features

πŸš“ Security Scanner

πŸ› Bug Fixes

  • Fixed Scan not marked as Errored when exceeding the Job BackoffLimit @Ilyesbdlala (#2568)
  • Fix nodeSelectors not working properly @J12934 (#2582)
  • Fix Health/Readyness Check Issues with Kubernetes AutoDiscovery @J12934 (#2578)

πŸ“š Documentation

  • Add docs and cli completion for trigger and scan command @Freedisch (#2587)

πŸ”§ Maintenance

πŸ“Œ Dependencies

Minor dependency updates (50 pull requests). Click to expand.
  • Use Latest DefectDojo Client Lib @Weltraumschaf (#2599)
  • Bump braces from 3.0.2 to 3.0.3 in /hooks/notification/hook @dependabot (#2600)
  • Bump the npm-version-updates group with 2 updates @dependabot (#2598)
  • Bump braces from 3.0.2 to 3.0.3 in /hooks/generic-webhook/hook @dependabot (#2596)
  • Bump ws from 8.13.0 to 8.18.0 in /hooks/cascading-scans/hook @dependabot (#2597)
  • Bump braces from 3.0.2 to 3.0.3 in /hooks/finding-post-processing/hook @dependabot (#2592)
  • Bump braces from 3.0.2 to 3.0.3 in /hooks/cascading-scans/hook @dependabot (#2590)
  • Bump ws from 8.12.0 to 8.18.0 in /hooks @dependabot (#2591)
  • Bump the npm-version-updates group with 2 updates @dependabot (#2588)
  • Bump ws from 8.12.0 to 8.18.0 in /auto-discovery/kubernetes/pull-secret-extractor/integration-test @dependabot (#2577)
  • Bump org.springframework:spring-web from 6.1.10 to 6.1.11 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group @dependabot (#2572)
  • Bump the npm-version-updates group with 2 updates @dependabot (#2571)
  • Bump certifi from 2023.7.22 to 2024.7.4 in /auto-discovery/kubernetes/pull-secret-extractor @dependabot (#2564)
  • Bump fsfe/reuse-action from 3 to 4 in /.github/workflows in the github-actions-version-updates group @dependabot (#2567)
  • Bump the npm-version-updates group with 2 updates @dependabot (#2565)
  • Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 5 updates @dependabot (#2566)
  • Bump the gradle-version-updates group across 1 directory with 8 updates @dependabot (#2556)
  • Bump @types/node from 20.14.8 to 20.14.9 in the npm-version-updates group @dependabot (#2550)

Distribution

Artifact HUB
Docker Hub

Contributors

Thanks to all our contributors supporting this project πŸ€—
@Freedisch, @Ilyesbdlala, @J12934, @Weltraumschaf, and @eliihen