Releases: secureCodeBox/secureCodeBox
Release list
v5.9.0
What's Changed
🦺Important Notices
- Minio has unpublished their previous still available official docker images. secureCodeBox 5.9.0 switches the default S3 bucket for the quick start setups to garage for a quick, self hosted S3 bucket in Kubernetes. Setups using a external S3 Buckets e.g. AWS S3, Google Storage, Hetzner Buckets, etc. are unaffected. If you upgrade a instance using the included Minio instance it will be switched to Garage. Any in-progress scans will fail and have to be restarted. Any scans created after the upgrade will then use the new garage bucket. See #3835
- The legacy helm chart registry at charts.securecodebox.io has now been finally shutdown, see #3800
- Telemetry collection was removed from the secureCodeBox Operator in release 5.9.0. The limited use of the collected data did not justify continued data collection or the effort of maintaining the telemetry backend. The telemetry backend is being shut down and the DNS record for telemetry.securecodebox.io will be removed. secureCodeBox operators older than 5.9.0 with telemetry enabled will continue attempting to submit telemetry every 24 hours and log a failed submission after the DNS record is removed. This does not affect scans or the operator's normal operation. Upgrade to 5.9.0 or later to prevent the attempted requests. #3798
The remaining content on this page is retained temporarily as historical documentation and will be removed in a future release.
🚀 Features
- Remove daily telemetry pings from the secureCodeBox operator by @J12934 in #3798
- Add golang based hook-sdk by @J12934 in #3786
- Add retries for the raw result upload from the lurker sidecar by @J12934 in #3785
🚓 Security Scanner
- Upgraded ffuf from v2.1.0 to v2.3.0 @secureCodeBoxBot (#3729, #3829)
- Upgraded nuclei from v3.11.0 to v3.11.1 @secureCodeBoxBot (#3810)
- Upgraded semgrep from 1.168.0 to 1.177.0 @secureCodeBoxBot (#3723, #3732, #3739, #3747, #3808, #3830)
- Upgraded ssh-audit from v3.3.0 to v3.9.0 @secureCodeBoxBot (#3715)
- Upgraded subfinder from v2.14.0 to v2.16.0 @secureCodeBoxBot (#3809)
- Upgraded trivy from 0.72.0 to 0.74.0 @secureCodeBoxBot (#3750, #3806)
- Upgraded trivy-sbom from 0.72.0 to 0.74.0 @secureCodeBoxBot (#3749, #3807)
- Upgraded wpscan from v4.0.0 to v4.1.0 @secureCodeBoxBot (#3722, #3740)
🔧 Maintenance
- Remove publishing to charts.securecodebox.io and remove leftover docs references to it by @J12934 in #3801
- Switch from minio to garage by @J12934 in #3835
- Increase default cpu & memory limits for the operator to 100Mi RAM and 250 milli cores CPU by @J12934 in #3831
- Golang Version Updates and go mod tidies by @J12934 in #3816
- Fix golang renovate dependency updates by @J12934 in #3827
📚 Documentation
- Remove broken star history chart by @J12934 in #3776
- Add documentation for github secrets by @Reet00 in #3796
📌 Dependencies
Minor dependency updates (67 pull requests). Click to expand.
- Bump webpack-dev-server from 5.2.4 to 5.2.6 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3710
- Bump @types/node from 26.0.1 to 26.1.0 in /parser-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3718
- Bump the github-actions-version-updates group across 1 directory with 10 updates by @dependabot[bot] in #3719
- Update dependency helm/helm to v4.2.3 by @renovate[bot] in #3721
- Update golang Docker tag to v1.26.5 by @renovate[bot] in #3720
- Bump websocket-driver from 0.7.4 to 0.7.5 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3731
- Bump the go-version-updates group across 3 directories with 2 updates by @dependabot[bot] in #3735
- Bump the npm-version-updates group in /documentation with 8 updates by @dependabot[bot] in #3733
- Bump the npm-security-updates group across 1 directory with 5 updates by @dependabot[bot] in #3738
- Bump fast-uri from 3.1.2 to 3.1.4 in /parser-sdk/nodejs in the npm-security-updates group across 1 directory by @dependabot[bot] in #3737
- Bump @types/node from 26.1.0 to 26.1.1 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3727
- Bump the gradle-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3726
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3734
- Update debian Docker tag to v13.6 by @renovate[bot] in #3725
- Bump the go-version-updates group across 4 directories with 5 updates by @dependabot[bot] in #3746
- Bump @types/node from 26.1.1 to 26.1.2 in /parser-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3744
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3745
- Update dependency helm-unittest/helm-unittest to v1.1.2 by @renovate[bot] in #3741
- Update dependency kubernetes/kubernetes to v1.36.3 by @renovate[bot] in #3736
- Bump com.github.ben-manes.versions from 0.54.0 to 0.56.0 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot[bot] in #3743
- Bump postcss from 8.5.15 to 8.5.25 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3748
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3756
- Bump the npm-security-updates group across 3 directories with 1 update by @dependabot[bot] in #3753
- Bump ip-address from 10.2.0 to 10.4.0 in /hooks/cascading-scans/hook by @dependabot[bot] in #3752
- Bump the npm-version-updates group in /documentation with 3 updates by @dependabot[bot] in #3755
- Bump brace-expansion from 1.1.13 to 1.1.18 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3751
- Bump fast-uri from 3.1.4 to 3.1.5 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3758
- Bump fast-uri from 3.1.4 to 3.1.5 in /parser-sdk/nodejs in the npm-security-updates group across 1 directory by @dependabot[bot] in #3757
- Bump @types/node from 26.1.2 to 26.2.0 in /parser-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3765
- Bump @types/react from 19.2.17 to 19.2.18 in /documentation in the npm-version-updates group by @dependabot[bot] in #3764
- Bump js-yaml from 4.2.0 to 4.3.1 in /hooks/cascading-scans/hook by @dependabot[bot] in #3762
- Update docker.io/bkimminich/juice-shop Docker tag to v20.2.0 by @renovate[bot] in #3761
- Bump the npm-security-updates group...
v5.9.0-rc.0
v5.9.0-rc.0
Incomplete release candidate for 5.9.0 to test some changes to the release & build automation since the 5.8.0 release.
Actual release notes will come with the 5.9.0 release.
v5.8.0
What's Changed
🚀 Features
- Make minio endpoint cluster domain configurable by @amitmishra11 in #3702
🚓 Security Scanner
- Upgraded nuclei from v3.8.0 to v3.11.0 @secureCodeBoxBot (#3672, #3716)
- Upgraded semgrep from 1.162.0 to 1.168.0 @secureCodeBoxBot (#3645, #3658, #3666, #3673, #3690, #3701)
- Upgraded trivy from 0.70.0 to 0.72.0 @secureCodeBoxBot (#3660, #3678, #3691, #3708)
- Upgraded trivy-sbom from 0.70.0 to 0.72.0 @secureCodeBoxBot (#3659, #3677, #3692, #3707)
- Upgraded wpscan from v3.8.28 to v4.0.0 @secureCodeBoxBot (#3655)
📌 Dependencies
Minor dependency updates (53 pull requests). Click to expand.
- Bump the npm-security-updates group across 2 directories with 2 updates by @dependabot[bot] in #3648
- Bump ws from 8.18.3 to 8.20.1 in /hooks/cascading-scans/hook by @dependabot[bot] in #3647
- Update dependency go-task/task to v3.51.1 by @renovate[bot] in #3646
- Update dependency helm/helm to v4.2.0 by @renovate[bot] in #3643
- Update nginx Docker tag to v1.31 by @renovate[bot] in #3642
- Update docker.io/bkimminich/juice-shop Docker tag to v20 by @renovate[bot] in #3641
- Update dependency kubernetes/kubernetes to v1.36.1 by @renovate[bot] in #3640
- Bump github/codeql-action from 4.35.3 to 4.35.4 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3639
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in #3638
- Bump the npm-version-updates group in /documentation with 4 updates by @dependabot[bot] in #3637
- Update dependency helm-unittest/helm-unittest to v1.1.0 by @renovate[bot] in #3633
- Bump the go-version-updates group across 4 directories with 8 updates by @dependabot[bot] in #3627
- Update debian Docker tag to v13.5 by @renovate[bot] in #3654
- Bump the go-version-updates group across 4 directories with 7 updates by @dependabot[bot] in #3653
- Update golang Docker tag to v1.26.4 by @renovate[bot] in #3662
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in #3656
- Update dependency kubernetes-sigs/kind to v0.32.0 by @renovate[bot] in #3661
- Bump the github-actions-version-updates group across 1 directory with 7 updates by @dependabot[bot] in #3657
- Bump the gradle-version-updates group across 1 directory with 7 updates by @dependabot[bot] in #3650
- Bump @babel/plugin-transform-modules-systemjs from 7.25.9 to 7.29.4 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3635
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 2 updates by @dependabot[bot] in #3663
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3664
- Bump github.com/minio/minio-go/v7 from 7.1.0 to 7.2.0 in /operator in the go-version-updates group across 1 directory by @dependabot[bot] in #3665
- Update dependency helm-unittest/helm-unittest to v1.1.1 by @renovate[bot] in #3667
- Bump the github-actions-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3669
- Update alpine Docker tag to v3.24 by @renovate[bot] in #3671
- Bump the npm-security-updates group across 1 directory with 4 updates by @dependabot[bot] in #3670
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in #3668
- Bump esbuild from 0.25.5 to 0.28.1 in /hooks/cascading-scans/hook by @dependabot[bot] in #3676
- Update dependency kubernetes/kubernetes to v1.36.2 by @renovate[bot] in #3675
- Update dependency helm/helm to v4.2.1 by @renovate[bot] in #3674
- Bump ws from 8.20.1 to 8.21.0 in /hooks/cascading-scans/hook by @dependabot[bot] in #3682
- Bump form-data from 4.0.4 to 4.0.6 in /hooks/cascading-scans/hook by @dependabot[bot] in #3680
- Bump the npm-security-updates group across 1 directory with 2 updates by @dependabot[bot] in #3684
- Bump the go-version-updates group across 4 directories with 6 updates by @dependabot[bot] in #3688
- Bump the npm-security-updates group across 3 directories with 3 updates by @dependabot[bot] in #3687
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in #3686
- Bump the npm-version-updates group in /documentation with 4 updates by @dependabot[bot] in #3685
- Bump the github-actions-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3698
- Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0 in /auto-discovery/cloud-aws in the go-version-updates group across 1 directory by @dependabot[bot] in #3697
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in #3696
- Bump sass from 1.99.0 to 1.101.0 in /documentation in the npm-version-updates group by @dependabot[bot] in #3695
- Update dependency helm/helm to v4.2.2 by @renovate[bot] in #3689
- Bump js-yaml from 4.1.1 to 4.2.0 in /hooks/cascading-scans/hook by @dependabot[bot] in #3681
- Bump gradle-wrapper from 9.5.1 to 9.6.0 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot[bot] in #3694
- Update docker.io/bkimminich/juice-shop Docker tag to v20.1.0 by @renovate[bot] in #3699
- Update docker.io/bkimminich/juice-shop Docker tag to v20.1.1 by @renovate[bot] in #3700
- Bump the go-version-updates group across 3 directories with 2 updates by @dependabot[bot] in #3705
- Bump @types/node from 26.0.0 to 26.0.1 in /parser-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3704
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 2 updates by @dependabot[bot] in #3703
- Bump js-yaml from 4.1.1 to 4.3.0 in /hooks/notification/hook by @dependabot[bot] in #3709
- Update dependency go-task/task to v3.52.0 by @renovate[bot] in #3714
- Bump golang.org/x/net from 0.52.0 to 0.55.0 in /lurker in the go-security-updates group across 1 directory by @dependabot[bot] in #3713
- Bump golang.org/x/net from 0.52.0 to 0.55.0 in /auto-discovery/kubernetes/pull-secret-extractor by @dependabot[bot] in #3712
New C...
v5.7.0
What's Changed
🚓 Security Scanner
- Upgraded gitleaks from v8.30.0 to v8.30.1 @secureCodeBoxBot (#3568)
- Upgraded nuclei from v3.7.0 to v3.8.0 @secureCodeBoxBot (#3546, #3612)
- Upgraded nikto to 2.6.0 by @J12934 in #3521
- Upgraded semgrep from 1.151.0 to 1.162.0 @secureCodeBoxBot (#3519, #3528, #3543, #3557, #3566, #3580, #3598, #3599, #3611, #3619, #3631)
- Upgraded sslyze from 6.3.0 to 6.3.1 @secureCodeBoxBot (#3577)
- Upgraded subfinder from v2.12.0 to v2.14.0 @secureCodeBoxBot (#3556, #3621)
- Upgraded trivy from 0.69.1 to 0.70.0 @secureCodeBoxBot (#3533, #3541, #3609)
- Upgraded trivy-sbom from 0.69.1 to 0.70.0 @secureCodeBoxBot (#3532, #3540, #3610)
- Upgraded whatweb from v0.6.3 to v0.6.4 @secureCodeBoxBot (#3583)
🐛 Bug Fixes
- Fix Pipeline failures due to oudated dependencies in Makefile by @J12934 in #3520
- Fix cascading-hooks labels by @aveyrenc in #3573
- Update test assertions for nikto by @Reet00 in #3544
📚 Documentation
- Document Domain Setup by @Weltraumschaf in #3592
- Add netlify config by @Weltraumschaf in #3594
- #3499 Add Fossa to PM Docs by @Weltraumschaf in #3617
🔧 Maintenance
- Fix Sandboxing Issues and ARM Builds for Screenshooter by @J12934 in #3600
- Migrate make to task by @p4trickweiss in #3539
📌 Dependencies
Minor dependency updates (68 pull requests). Click to expand.
- Bump qs from 6.14.1 to 6.14.2 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3511
- Bump lodash-es from 4.17.21 to 4.17.23 in /hooks/finding-post-processing/hook by @dependabot[bot] in #3523
- Update dependency kubernetes/kubernetes to v1.35.1 by @renovate[bot] in #3509
- chore(deps): update golang docker tag by @renovate[bot] in #3510
- Bump ajv from 6.12.6 to 6.14.0 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3524
- Bump the gradle-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3525
- Bump the npm-version-updates group across 2 directories with 3 updates by @dependabot[bot] in #3526
- Bump the go-version-updates group across 4 directories with 4 updates by @dependabot[bot] in #3518
- Bump the npm-version-updates group in /documentation with 3 updates by @dependabot[bot] in #3514
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3517
- Bump lodash-es from 4.17.21 to 4.17.23 in /hooks/notification/hook by @dependabot[bot] in #3527
- Bump the go-version-updates group across 4 directories with 4 updates by @dependabot[bot] in #3538
- Bump the github-actions-version-updates group across 1 directory with 6 updates by @dependabot[bot] in #3537
- Bump @types/node from 25.3.0 to 25.3.3 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3536
- Bump @types/node from 25.2.3 to 25.3.3 in /documentation in the npm-version-updates group by @dependabot[bot] in #3535
- chore(deps): update dependency kubernetes/kubernetes to v1.35.2 by @renovate[bot] in #3531
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 2 updates by @dependabot[bot] in #3534
- Bump the npm-security-updates group across 1 directory with 2 updates by @dependabot[bot] in #3542
- Bump svgo from 3.3.2 to 3.3.3 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3547
- chore(deps): update docker.io/bkimminich/juice-shop docker tag to v19.2.0 by @renovate[bot] in #3548
- chore(deps): update golang docker tag to v1.26.1 by @renovate[bot] in #3545
- chore(deps): update docker.io/bkimminich/juice-shop docker tag to v19.2.1 by @renovate[bot] in #3549
- Bump the go-version-updates group across 3 directories with 3 updates by @dependabot[bot] in #3555
- chore(deps): update debian docker tag to v13.4 by @renovate[bot] in #3561
- Bump the github-actions-version-updates group across 1 directory with 8 updates by @dependabot[bot] in #3565
- Bump @types/node from 25.3.3 to 25.5.0 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3564
- Bump the npm-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3563
- Bump the gradle-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3562
- chore(deps): update dependency go-task/task to v3.49.1 by @renovate[bot] in #3550
- Bump undici from 6.23.0 to 6.24.1 in /hooks/persistence-elastic/hook by @dependabot[bot] in #3559
- chore(deps): update dependency kubernetes/kubernetes to v1.35.3 by @renovate[bot] in #3567
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 2 updates by @dependabot[bot] in #3570
- Bump picomatch from 2.3.1 to 2.3.2 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3574
- Bump the go-version-updates group across 4 directories with 4 updates by @dependabot[bot] in #3572
- Npmrc by @Weltraumschaf in #3579
- Bump lodash-es from 4.17.23 to 4.18.1 in /hooks/cascading-scans/hook by @dependabot[bot] in #3582
- Bump nodemailer from 7.0.11 to 8.0.4 in /hooks/notification/hook by @dependabot[bot] in #3575
- Bump @types/node from 25.5.0 to 25.5.2 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3585
- Bump the npm-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3584
- Bump brace-expansion from 1.1.12 to 1.1.13 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3576
- Bump lodash-es from 4.17.23 to 4.18.1 in /hooks/finding-post-processing/hook by @dependabot[bot] in #3588
- Bump the github-actions-version-updates group across 1 directory with 6 updates by @dependabot[bot] in #3586
- Bump github.com/minio/minio-go/v7 from 7.0.99 to 7.0.100 in /operator in the go-version-updates group across 1 directory by @dependabot[bot] in #3587
- chore(deps): update golang docker tag to v1.26.2 b...
v5.6.0
What's Changed
⚠️ Upgrade Notes
This release contains a minor addition (suspend field) to the Custom Resource Definitions (CRDs), Helm does not update CRDs after the initial installation. If you are planning on using the suspend field make sure that your CRDs are up to date.
To upgrade the CRDs you can run the following script or grab the latest CRDs from the git repo at the v5.6.0 tag:
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v5.6.0/operator/crds/execution.securecodebox.io_scans.yaml
kubectl apply -f https://raw.githubusercontent.com/secureCodeBox/secureCodeBox/v5.6.0/operator/crds/execution.securecodebox.io_scheduledscans.yaml🚀 Features
- Add suspend functionality to Scan and ScheduledScan resources by @J12934 in #3504
- Allow extra volumes and volume mounts for CSI secrets and other volumes by @mazmar in #3485
🚓 Security Scanner
- Upgraded nuclei from v3.6.2 to v3.7.0 @secureCodeBoxBot (#3486)
- Upgraded semgrep from 1.147.0 to 1.151.0 @secureCodeBoxBot (#3465, #3477, #3498)
- Upgraded trivy from 0.68.2 to 0.69.1 @secureCodeBoxBot (#3501)
- Upgraded trivy-sbom from 0.68.2 to 0.69.1 @secureCodeBoxBot (#3502)
🐛 Bug Fixes
📌 Dependencies
Minor dependency updates (28 pull requests). Click to expand.
- Update golang Docker tag to v1.25.6 by @renovate[bot] in #3468
- Update dependency helm/helm to v4.0.5 by @renovate[bot] in #3464
- Bump qs from 6.13.0 to 6.14.1 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3463
- Bump @types/node from 25.0.7 to 25.0.9 in /documentation in the npm-version-updates group by @dependabot[bot] in #3470
- Bump undici from 6.21.3 to 6.23.0 in /hooks/persistence-elastic/hook by @dependabot[bot] in #3462
- Bump @types/node from 25.0.7 to 25.0.9 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3471
- Bump the go-version-updates group across 3 directories with 2 updates by @dependabot[bot] in #3473
- Bump the github-actions-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3472
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 2 updates by @dependabot[bot] in #3469
- Bump lodash from 4.17.21 to 4.17.23 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3476
- Update dependency helm/helm to v4.1.0 by @renovate[bot] in #3475
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3483
- Bump the go-version-updates group across 3 directories with 1 update by @dependabot[bot] in #3484
- Update dependency go-task/task to v3.48.0 by @renovate[bot] in #3479
- Bump lodash-es from 4.17.21 to 4.17.23 in /hooks/cascading-scans/hook by @dependabot[bot] in #3474
- Bump @types/node from 25.0.9 to 25.0.10 in /parser-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3482
- Bump the npm-version-updates group in /documentation with 5 updates by @dependabot[bot] in #3481
- chore(deps): update golang docker tag to v1.25.7 by @renovate[bot] in #3497
- Bump @isaacs/brace-expansion from 5.0.0 to 5.0.1 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3496
- Bump the go-version-updates group across 3 directories with 2 updates by @dependabot[bot] in #3495
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3494
- Bump webpack from 5.96.1 to 5.105.0 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3503
- Bump @types/node from 25.0.10 to 25.2.0 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3493
- Bump github/codeql-action from 4.32.1 to 4.32.2 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3508
- Bump the npm-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3507
- Bump gradle-wrapper from 8.13 to 9.3.0 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot[bot] in #3480
Other Changes
New Contributors
Full Changelog: v5.5.0...v5.6.0
v5.5.0
What's Changed
🚓 Security Scanner
- Upgraded nuclei from v3.6.1 to v3.6.2 @secureCodeBoxBot (#3447)
- Upgraded semgrep from 1.146.0 to 1.147.0 @secureCodeBoxBot (#3453)
- Upgraded sslyze from 6.2.0 to 6.3.0 @secureCodeBoxBot (#3446)
- Upgraded subfinder from v2.10.1 to v2.12.0 @secureCodeBoxBot (#3440, #3454)
🚀 Features
- Add option to include target domain in subfinder findings by @p4trickweiss in #3452
🐛 Bug Fixes
📌 Dependencies
Minor dependency updates (15 pull requests). Click to expand.
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 3 updates by @dependabot[bot] in #3432
- Update dependency go-task/task to v3.46.2 by @renovate[bot] in #3437
- Bump @types/node from 25.0.2 to 25.0.3 in /parser-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3433
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3434
- Bump @types/node from 25.0.2 to 25.0.3 in /parser-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3441
- Bump qs from 6.13.0 to 6.14.1 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3448
- Bump sass from 1.97.1 to 1.97.2 in /documentation in the npm-version-updates group by @dependabot[bot] in #3449
- Update dependency go-task/task to v3.46.4 by @renovate[bot] in #3444
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3450
- Bump org.junit:junit-bom from 6.0.1 to 6.0.2 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot[bot] in #3456
- Bump the go-version-updates group across 4 directories with 7 updates by @dependabot[bot] in #3460
- Update debian Docker tag to v13.3 by @renovate[bot] in #3455
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3457
- Bump @types/node from 25.0.3 to 25.0.7 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3458
- Bump the github-actions-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3459
Full Changelog: v5.4.0...v5.5.0
v5.4.0
What's Changed
🚀 Features
- Rewrite git-repo-scanner in Go, optimizing rate-limits to fetch repo data much faster than before by @p4trickweiss in #3392
🐛 Bug Fixes
🚓 Security Scanner
- Upgraded nuclei from v3.6.0 to v3.6.1 @secureCodeBoxBot (#3425)
- Upgraded semgrep from 1.145.0 to 1.146.0 @secureCodeBoxBot (#3430)
- Upgraded trivy from 0.68.1 to 0.68.2 @secureCodeBoxBot (#3427)
- Upgraded trivy-sbom from 0.68.1 to 0.68.2 @secureCodeBoxBot (#3426)
- Upgraded zap-automation-framework from 2.16.1 to 2.17.0 @secureCodeBoxBot (#3424)
📌 Dependencies
Minor dependency updates (9 pull requests). Click to expand.
- Update dependency helm/helm to v4.0.2 by @renovate[bot] in #3415
- Update dependency helm/helm to v4.0.4 by @renovate[bot] in #3416
- Bump the npm-version-updates group in /documentation with 4 updates by @dependabot[bot] in #3417
- Update golang Docker tag to v1.25.5 by @renovate[bot] in #3423
- Bump the go-version-updates group across 4 directories with 6 updates by @dependabot[bot] in #3421
- Bump the github-actions-version-updates group across 1 directory with 6 updates by @dependabot[bot] in #3420
- Bump @types/node from 24.10.1 to 25.0.2 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3419
- Update dependency kubernetes/kubernetes to v1.35.0 by @renovate[bot] in #3428
- Update dependency kubernetes-sigs/kind to v0.31.0 by @renovate[bot] in #3429
Full Changelog: v5.3.0...v5.4.0
v5.3.0
What's Changed
🚓 Security Scanner
- Upgraded gitleaks from v8.29.0 to v8.30.0 @secureCodeBoxBot (#3383, #3394)
- Upgraded nuclei from v3.5.1 to v3.6.0 @secureCodeBoxBot (#3405)
- Upgraded semgrep from 1.143.0 to 1.145.0 @secureCodeBoxBot (#3382, #3404)
- Upgraded subfinder from v2.10.0 to v2.10.1 @secureCodeBoxBot (#3386)
- Upgraded trivy from 0.67.2 to 0.68.1 @secureCodeBoxBot (#3402)
- Upgraded trivy-sbom from 0.67.2 to 0.68.1 @secureCodeBoxBot (#3403)
🐛 Bug Fixes
- Fixes Incompatability with newer Elasticsearch Systems by @conleth in #3391
- Fix secret name in helm template by @yyvfuruta in #3340
📚 Documentation
- Add Link to Blog Post "Automating Penetration Testing with SecureCodeBox on Kubernetes Kind Clusters Using GitHub Actions" by Yasmine Gharbi in #3395
📌 Dependencies
Minor dependency updates (18 pull requests). Click to expand.
- Update dependency helm/helm to v3.19.2 by @renovate[bot] in #3362
- Bump the npm-version-updates group in /documentation with 3 updates by @dependabot[bot] in #3387
- Bump @types/node from 24.10.0 to 24.10.1 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3388
- Bump the github-actions-version-updates group across 1 directory with 5 updates by @dependabot[bot] in #3389
- Bump the gradle-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3390
- Update dependency helm-unittest/helm-unittest to v1.0.3 by @renovate[bot] in #3270
- Bump @types/react from 19.2.6 to 19.2.7 in /documentation in the npm-version-updates group by @dependabot[bot] in #3396
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3397
- Bump nodemailer from 7.0.7 to 7.0.11 in /hooks/notification/hook by @dependabot[bot] in #3399
- Update golang Docker tag to v1.25.5 by @renovate[bot] in #3400
- Update alpine Docker tag to v3.23 by @renovate[bot] in #3401
- Bump node-forge from 1.3.1 to 1.3.2 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3393
- Bump mdast-util-to-hast from 13.2.0 to 13.2.1 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3406
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3407
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3409
- Bump org.sonarqube from 7.1.0.6387 to 7.2.0.6526 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot[bot] in #3408
- Update dependency helm/helm to v4 by @renovate[bot] in #3363
- Update dependency kubernetes/kubernetes to v1.34.3 - autoclosed by @renovate[bot] in #3412
New Contributors
- @yyvfuruta made their first contribution in #3340
- @conleth made their first contribution in #3391
Full Changelog: v5.2.0...v5.3.0
v5.2.0
What's Changed
🚓 Security Scanner
- Upgraded gitleaks from v8.28.0 to v8.29.0 @secureCodeBoxBot (#3349)
- Upgraded nuclei from v3.4.10 to v3.5.1 @secureCodeBoxBot (#3365)
- Upgraded semgrep from 1.138.0 to 1.143.0 @secureCodeBoxBot (#3306, #3331, #3339, #3347, #3364)
- Upgraded subfinder from v2.9.0 to v2.10.0 @secureCodeBoxBot (#3379)
- Upgraded trivy from 0.67.0 to 0.67.2 @secureCodeBoxBot (#3321)
- Upgraded trivy-sbom from 0.67.0 to 0.67.2 @secureCodeBoxBot (#3320)
- Upgraded whatweb from v0.6.2 to v0.6.3 @secureCodeBoxBot (#3332)
- Avoid confusion in cascading scans between http on port 443 by @Reet00 in #3271
🐛 Bug Fixes
📚 Documentation
- Improve AWS Pod Identity / IRSA Docs by @J12934 in #3314
- Add SCBaaS button by @p4trickweiss in #3350
- Add proposed ADR to use CEL in CascadingRules by @J12934 in #3328
🔧 Maintenance
📌 Dependencies
Minor dependency updates (43 pull requests). Click to expand.
- Bump the pip-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3289
- Dependabot/gradle/hooks/persistence defectdojo/hook/gradle version updates 27032e4d85 by @Weltraumschaf in #3281
- Bump github.com/onsi/ginkgo/v2 from 2.25.3 to 2.26.0 in /auto-discovery/cloud-aws in the go-version-updates group across 1 directory by @dependabot[bot] in #3311
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3310
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in #3309
- Bump the npm-version-updates group in /documentation with 5 updates by @dependabot[bot] in #3307
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 5 updates by @dependabot[bot] in #3308
- Update golang Docker tag to v1.25.2 by @renovate[bot] in #3313
- Bump nodemailer from 6.10.1 to 7.0.7 in /hooks/notification/hook by @dependabot[bot] in #3312
- Update oven/bun Docker tag to v1.3 by @renovate[bot] in #3319
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3322
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in #3323
- Bump the go-version-updates group across 3 directories with 1 update by @dependabot[bot] in #3325
- Update golang Docker tag to v1.25.3 by @renovate[bot] in #3326
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3324
- Bump github/codeql-action from 4.30.8 to 4.30.9 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3335
- Bump @types/node from 24.7.2 to 24.8.1 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3336
- Bump python-gitlab from 6.4.0 to 6.5.0 in /scanners/git-repo-scanner/scanner in the pip-version-updates group across 1 directory by @dependabot[bot] in #3337
- Bump the npm-version-updates group in /documentation with 7 updates by @dependabot[bot] in #3334
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 2 updates by @dependabot[bot] in #3333
- Bump the npm-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3348
- Update Node.js to v24 by @renovate[bot] in #3346
- Bump @types/node from 24.8.1 to 24.9.1 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3345
- Bump github.com/onsi/ginkgo/v2 from 2.26.0 to 2.27.1 in /auto-discovery/cloud-aws in the go-version-updates group across 1 directory by @dependabot[bot] in #3344
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3343
- Update golang Docker tag to v1.25.4 by @renovate[bot] in #3352
- Bump the go-version-updates group across 3 directories with 3 updates by @dependabot[bot] in #3357
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3353
- Bump @types/node from 24.9.1 to 24.10.0 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3356
- Update dependency helm/helm to v3.19.1 by @renovate[bot] in #3358
- Update dependency go-task/task to v3.45.5 by @renovate[bot] in #3359
- Update dependency kubernetes/kubernetes to v1.34.2 by @renovate[bot] in #3361
- Bump the gradle-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3355
- Bump python-gitlab from 6.5.0 to 7.0.0 in /scanners/git-repo-scanner/scanner in the pip-version-updates group across 1 directory by @dependabot[bot] in #3354
- Bump js-yaml from 4.1.0 to 4.1.1 in /hooks/cascading-scans/hook by @dependabot[bot] in #3366
- Bump the npm-security-updates group across 3 directories with 1 update by @dependabot[bot] in #3368
- Update docker.io/bkimminich/juice-shop Docker tag to v19.1.1 by @renovate[bot] in #3370
- Bump js-yaml from 4.1.0 to 4.1.1 in /hooks/notification/hook by @dependabot[bot] in #3371
- Bump the npm-version-updates group in /documentation with 3 updates by @dependabot[bot] in #3373
- Bump js-yaml from 3.14.1 to 3.14.2 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3375
- Update debian Docker tag to v13.2 by @renovate[bot] in #3376
- Bump glob from 11.0.3 to 11.1.0 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3377
- Bump the go-version-updates group across 4 directories with 4 updates by @dependabot[bot] in #3374
- Bump the go-security-updates group across 3 directories with 1 update by @dependabot[bot] in #3380
Full Changelog: v5.1.0...v5.2.0
v5.1.0
🚀 Features
- Make the healthchecks for the operator configurable via helm values by @J12934 in #3223
- Switch ncrack password encryption from RSA to age-encryption by @p4trickweiss in #3247
- Improve operator and auto-discovery log consistency and switch to json logs by @J12934 in #3227
🚓 Security Scanner
- Upgraded nuclei from v3.4.7 to v3.4.10 @secureCodeBoxBot (#3228, #3232)
- Upgraded semgrep from 1.131.0 to 1.138.0 @secureCodeBoxBot (#3211, #3231, #3248, #3258, #3269, #3283, #3296)
- Upgraded subfinder from v2.8.0 to v2.9.0 @secureCodeBoxBot (#3298)
- Upgraded trivy from 0.65.0 to 0.67.0 @secureCodeBoxBot (#3252, #3303)
- Upgraded trivy-sbom from 0.65.0 to 0.67.0 @secureCodeBoxBot (#3253, #3304)
- Upgraded whatweb from v6.0.1 to v0.6.2 @secureCodeBoxBot (#3236)
🐛 Bug Fixes
- Fix Dependency Track Hook by @p4trickweiss in #3290
- Added affinity and tolerations fields to ssh-audit-scan-type.yaml by @DevikHaruko in #3297
- Migrate scan kubernetes finalizers to avoid warnings about non-recommended finalizer url structure by @J12934 in #3226
📚 Documentation
- Fix minor documentation issues by @J12934 in #3221
- Replace Snyk badge with OpenSSF Scorecard Badge by @J12934 in #3233
- Update supported k8s versions to include new Kubernetes 1.34 release. by @J12934 in #3255
- Update Security Policy with new supported Versions and Update Advisory Publishing Process by @J12934 in #3235
🔧 Maintenance
- Automatically set labels for renovate PRs by @J12934 in #3203
- Renovate for ci.yaml dependencies by @J12934 in #3204
- Optimize Go Docker builds with native cross-compilation by @J12934 in #3206
- Migrate docker repository for petstore by @Reet00 in #3213
- Remove unnecessary create-blog-post script by @Weltraumschaf in #3244
- Migrate parser-sdk to typescript by @J12934 in #3254
- Changes the comments behind pinned actions to include their full version by @J12934 in #3264
- Rewrite pull-secret-extractor in Go by @p4trickweiss in #3267
- Pin GitHub Pipeline Action Dependencies and specify reduced pipeline permissions by @J12934 in #3229
📌 Dependencies
Minor dependency updates (41 pull requests). Click to expand.
- Update golang Docker tag by @renovate[bot] in #3207
- Update dependency go-task/task to v3.44.1 by @renovate[bot] in #3208
- Update dependency helm/helm to v3.18.5 by @renovate[bot] in #3209
- Update dependency kubernetes/kubernetes to v1.33.4 by @renovate[bot] in #3210
- Bump the go-version-updates group across 4 directories with 6 updates by @dependabot[bot] in #3217
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3214
- Bump actions/checkout from 4 to 5 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3216
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 3 updates by @dependabot[bot] in #3215
- Update docker.io/swaggerapi/petstore3 Docker tag to v1.0.27 by @renovate[bot] in #3218
- Update dependency helm/helm to v3.18.6 by @renovate[bot] in #3222
- Bump the go-version-updates group across 3 directories with 2 updates by @dependabot[bot] in #3240
- Bump io.freefair.lombok from 8.14 to 8.14.2 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot[bot] in #3237
- Add pip to dependabot by @Reet00 in #3234
- Bump the npm-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3241
- Update dependency kubernetes-sigs/kind to v0.30.0 by @renovate[bot] in #3245
- Update dependency kubernetes/kubernetes to v1.34.0 by @renovate[bot] in #3246
- Dependabot/gradle/hooks/persistence defectdojo/hook/gradle version updates 7f209d1a84 by @Weltraumschaf in #3251
- Update docker.io/bkimminich/juice-shop Docker tag to v19 by @renovate[bot] in #3257
- Update golang Docker tag to v1.25.1 by @renovate[bot] in #3256
- Bump the npm-version-updates group across 2 directories with 1 update by @dependabot[bot] in #3261
- Bump the npm-version-updates group in /documentation with 4 updates by @dependabot[bot] in #3260
- Bump the github-actions-version-updates group across 1 directory with 5 updates by @dependabot[bot] in #3265
- Update debian Docker tag to v13.1 by @renovate[bot] in #3266
- Bump the go-version-updates group across 4 directories with 9 updates by @dependabot[bot] in #3263
- Update dependency kubernetes/kubernetes to v1.34.1 by @renovate[bot] in #3268
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3275
- Bump the npm-version-updates group across 2 directories with 1 update by @dependabot[bot] in #3277
- Update dependency helm/helm to v3.19.0 by @renovate[bot] in #3273
- Bump github/codeql-action from 3.30.1 to 3.30.3 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3274
- Bump the go-version-updates group across 4 directories with 5 updates by @dependabot[bot] in #3278
- Update dependency go-task/task to v3.45.3 by @renovate[bot] in #3280
- Update dependency go-task/task to v3.45.4 by @renovate[bot] in #3282
- Update golang Docker tag to v1.25.1 by @renovate[bot] in #3288
- Bump @types/node from 24.4.0 to 24.5.2 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3287
- Bump oxsecurity/megalinter from 8.8.0 to 9.0.1 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3286
- Bump tar-fs from 3.0.10 to 3.1.1 in /tests/integration in the npm-security-updates group across 1 directory by @dependabot[bot] in #3292
- Bump tar-fs from 3.1.0 to 3.1.1 in /hooks/notification/hook by @dependabot[bot] in #3291
- Bump tar-fs from 3.1.0 to 3.1.1 in /hooks/cascading-scans/hook by @dependabot[bot] in #3293
- Bump the npm-security-updates group across 2 directories with 1 update by @dependabot[bot] in #3294
- Bump the npm-version-updates group across 1 directory with 9 updates by @dependabot[bot] in #3300
- Bump the github-actions-version-updates...