Releases: secureCodeBox/secureCodeBox
v5.5.0
What's Changed
🚓 Security Scanner
- Upgraded nuclei from v3.6.1 to v3.6.2 @secureCodeBoxBot (#3447)
- Upgraded semgrep from 1.146.0 to 1.147.0 @secureCodeBoxBot (#3453)
- Upgraded sslyze from 6.2.0 to 6.3.0 @secureCodeBoxBot (#3446)
- Upgraded subfinder from v2.10.1 to v2.12.0 @secureCodeBoxBot (#3440, #3454)
🚀 Features
- Add option to include target domain in subfinder findings by @p4trickweiss in #3452
🐛 Bug Fixes
📌 Dependencies
Minor dependency updates (15 pull requests). Click to expand.
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 3 updates by @dependabot[bot] in #3432
- Update dependency go-task/task to v3.46.2 by @renovate[bot] in #3437
- Bump @types/node from 25.0.2 to 25.0.3 in /parser-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3433
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3434
- Bump @types/node from 25.0.2 to 25.0.3 in /parser-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3441
- Bump qs from 6.13.0 to 6.14.1 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3448
- Bump sass from 1.97.1 to 1.97.2 in /documentation in the npm-version-updates group by @dependabot[bot] in #3449
- Update dependency go-task/task to v3.46.4 by @renovate[bot] in #3444
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3450
- Bump org.junit:junit-bom from 6.0.1 to 6.0.2 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot[bot] in #3456
- Bump the go-version-updates group across 4 directories with 7 updates by @dependabot[bot] in #3460
- Update debian Docker tag to v13.3 by @renovate[bot] in #3455
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3457
- Bump @types/node from 25.0.3 to 25.0.7 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3458
- Bump the github-actions-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3459
Full Changelog: v5.4.0...v5.5.0
v5.4.0
What's Changed
🚀 Features
- Rewrite git-repo-scanner in Go, optimizing rate-limits to fetch repo data much faster than before by @p4trickweiss in #3392
🐛 Bug Fixes
🚓 Security Scanner
- Upgraded nuclei from v3.6.0 to v3.6.1 @secureCodeBoxBot (#3425)
- Upgraded semgrep from 1.145.0 to 1.146.0 @secureCodeBoxBot (#3430)
- Upgraded trivy from 0.68.1 to 0.68.2 @secureCodeBoxBot (#3427)
- Upgraded trivy-sbom from 0.68.1 to 0.68.2 @secureCodeBoxBot (#3426)
- Upgraded zap-automation-framework from 2.16.1 to 2.17.0 @secureCodeBoxBot (#3424)
📌 Dependencies
Minor dependency updates (9 pull requests). Click to expand.
- Update dependency helm/helm to v4.0.2 by @renovate[bot] in #3415
- Update dependency helm/helm to v4.0.4 by @renovate[bot] in #3416
- Bump the npm-version-updates group in /documentation with 4 updates by @dependabot[bot] in #3417
- Update golang Docker tag to v1.25.5 by @renovate[bot] in #3423
- Bump the go-version-updates group across 4 directories with 6 updates by @dependabot[bot] in #3421
- Bump the github-actions-version-updates group across 1 directory with 6 updates by @dependabot[bot] in #3420
- Bump @types/node from 24.10.1 to 25.0.2 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3419
- Update dependency kubernetes/kubernetes to v1.35.0 by @renovate[bot] in #3428
- Update dependency kubernetes-sigs/kind to v0.31.0 by @renovate[bot] in #3429
Full Changelog: v5.3.0...v5.4.0
v5.3.0
What's Changed
🚓 Security Scanner
- Upgraded gitleaks from v8.29.0 to v8.30.0 @secureCodeBoxBot (#3383, #3394)
- Upgraded nuclei from v3.5.1 to v3.6.0 @secureCodeBoxBot (#3405)
- Upgraded semgrep from 1.143.0 to 1.145.0 @secureCodeBoxBot (#3382, #3404)
- Upgraded subfinder from v2.10.0 to v2.10.1 @secureCodeBoxBot (#3386)
- Upgraded trivy from 0.67.2 to 0.68.1 @secureCodeBoxBot (#3402)
- Upgraded trivy-sbom from 0.67.2 to 0.68.1 @secureCodeBoxBot (#3403)
🐛 Bug Fixes
- Fixes Incompatability with newer Elasticsearch Systems by @conleth in #3391
- Fix secret name in helm template by @yyvfuruta in #3340
📚 Documentation
- Add Link to Blog Post "Automating Penetration Testing with SecureCodeBox on Kubernetes Kind Clusters Using GitHub Actions" by Yasmine Gharbi in #3395
📌 Dependencies
Minor dependency updates (18 pull requests). Click to expand.
- Update dependency helm/helm to v3.19.2 by @renovate[bot] in #3362
- Bump the npm-version-updates group in /documentation with 3 updates by @dependabot[bot] in #3387
- Bump @types/node from 24.10.0 to 24.10.1 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3388
- Bump the github-actions-version-updates group across 1 directory with 5 updates by @dependabot[bot] in #3389
- Bump the gradle-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3390
- Update dependency helm-unittest/helm-unittest to v1.0.3 by @renovate[bot] in #3270
- Bump @types/react from 19.2.6 to 19.2.7 in /documentation in the npm-version-updates group by @dependabot[bot] in #3396
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3397
- Bump nodemailer from 7.0.7 to 7.0.11 in /hooks/notification/hook by @dependabot[bot] in #3399
- Update golang Docker tag to v1.25.5 by @renovate[bot] in #3400
- Update alpine Docker tag to v3.23 by @renovate[bot] in #3401
- Bump node-forge from 1.3.1 to 1.3.2 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3393
- Bump mdast-util-to-hast from 13.2.0 to 13.2.1 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3406
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3407
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3409
- Bump org.sonarqube from 7.1.0.6387 to 7.2.0.6526 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot[bot] in #3408
- Update dependency helm/helm to v4 by @renovate[bot] in #3363
- Update dependency kubernetes/kubernetes to v1.34.3 - autoclosed by @renovate[bot] in #3412
New Contributors
- @yyvfuruta made their first contribution in #3340
- @conleth made their first contribution in #3391
Full Changelog: v5.2.0...v5.3.0
v5.2.0
What's Changed
🚓 Security Scanner
- Upgraded gitleaks from v8.28.0 to v8.29.0 @secureCodeBoxBot (#3349)
- Upgraded nuclei from v3.4.10 to v3.5.1 @secureCodeBoxBot (#3365)
- Upgraded semgrep from 1.138.0 to 1.143.0 @secureCodeBoxBot (#3306, #3331, #3339, #3347, #3364)
- Upgraded subfinder from v2.9.0 to v2.10.0 @secureCodeBoxBot (#3379)
- Upgraded trivy from 0.67.0 to 0.67.2 @secureCodeBoxBot (#3321)
- Upgraded trivy-sbom from 0.67.0 to 0.67.2 @secureCodeBoxBot (#3320)
- Upgraded whatweb from v0.6.2 to v0.6.3 @secureCodeBoxBot (#3332)
- Avoid confusion in cascading scans between http on port 443 by @Reet00 in #3271
🐛 Bug Fixes
📚 Documentation
- Improve AWS Pod Identity / IRSA Docs by @J12934 in #3314
- Add SCBaaS button by @p4trickweiss in #3350
- Add proposed ADR to use CEL in CascadingRules by @J12934 in #3328
🔧 Maintenance
📌 Dependencies
Minor dependency updates (43 pull requests). Click to expand.
- Bump the pip-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3289
- Dependabot/gradle/hooks/persistence defectdojo/hook/gradle version updates 27032e4d85 by @Weltraumschaf in #3281
- Bump github.com/onsi/ginkgo/v2 from 2.25.3 to 2.26.0 in /auto-discovery/cloud-aws in the go-version-updates group across 1 directory by @dependabot[bot] in #3311
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3310
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in #3309
- Bump the npm-version-updates group in /documentation with 5 updates by @dependabot[bot] in #3307
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 5 updates by @dependabot[bot] in #3308
- Update golang Docker tag to v1.25.2 by @renovate[bot] in #3313
- Bump nodemailer from 6.10.1 to 7.0.7 in /hooks/notification/hook by @dependabot[bot] in #3312
- Update oven/bun Docker tag to v1.3 by @renovate[bot] in #3319
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3322
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in #3323
- Bump the go-version-updates group across 3 directories with 1 update by @dependabot[bot] in #3325
- Update golang Docker tag to v1.25.3 by @renovate[bot] in #3326
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3324
- Bump github/codeql-action from 4.30.8 to 4.30.9 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3335
- Bump @types/node from 24.7.2 to 24.8.1 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3336
- Bump python-gitlab from 6.4.0 to 6.5.0 in /scanners/git-repo-scanner/scanner in the pip-version-updates group across 1 directory by @dependabot[bot] in #3337
- Bump the npm-version-updates group in /documentation with 7 updates by @dependabot[bot] in #3334
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 2 updates by @dependabot[bot] in #3333
- Bump the npm-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3348
- Update Node.js to v24 by @renovate[bot] in #3346
- Bump @types/node from 24.8.1 to 24.9.1 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3345
- Bump github.com/onsi/ginkgo/v2 from 2.26.0 to 2.27.1 in /auto-discovery/cloud-aws in the go-version-updates group across 1 directory by @dependabot[bot] in #3344
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3343
- Update golang Docker tag to v1.25.4 by @renovate[bot] in #3352
- Bump the go-version-updates group across 3 directories with 3 updates by @dependabot[bot] in #3357
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in #3353
- Bump @types/node from 24.9.1 to 24.10.0 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3356
- Update dependency helm/helm to v3.19.1 by @renovate[bot] in #3358
- Update dependency go-task/task to v3.45.5 by @renovate[bot] in #3359
- Update dependency kubernetes/kubernetes to v1.34.2 by @renovate[bot] in #3361
- Bump the gradle-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3355
- Bump python-gitlab from 6.5.0 to 7.0.0 in /scanners/git-repo-scanner/scanner in the pip-version-updates group across 1 directory by @dependabot[bot] in #3354
- Bump js-yaml from 4.1.0 to 4.1.1 in /hooks/cascading-scans/hook by @dependabot[bot] in #3366
- Bump the npm-security-updates group across 3 directories with 1 update by @dependabot[bot] in #3368
- Update docker.io/bkimminich/juice-shop Docker tag to v19.1.1 by @renovate[bot] in #3370
- Bump js-yaml from 4.1.0 to 4.1.1 in /hooks/notification/hook by @dependabot[bot] in #3371
- Bump the npm-version-updates group in /documentation with 3 updates by @dependabot[bot] in #3373
- Bump js-yaml from 3.14.1 to 3.14.2 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3375
- Update debian Docker tag to v13.2 by @renovate[bot] in #3376
- Bump glob from 11.0.3 to 11.1.0 in /documentation in the npm-security-updates group across 1 directory by @dependabot[bot] in #3377
- Bump the go-version-updates group across 4 directories with 4 updates by @dependabot[bot] in #3374
- Bump the go-security-updates group across 3 directories with 1 update by @dependabot[bot] in #3380
Full Changelog: v5.1.0...v5.2.0
v5.1.0
🚀 Features
- Make the healthchecks for the operator configurable via helm values by @J12934 in #3223
- Switch ncrack password encryption from RSA to age-encryption by @p4trickweiss in #3247
- Improve operator and auto-discovery log consistency and switch to json logs by @J12934 in #3227
🚓 Security Scanner
- Upgraded nuclei from v3.4.7 to v3.4.10 @secureCodeBoxBot (#3228, #3232)
- Upgraded semgrep from 1.131.0 to 1.138.0 @secureCodeBoxBot (#3211, #3231, #3248, #3258, #3269, #3283, #3296)
- Upgraded subfinder from v2.8.0 to v2.9.0 @secureCodeBoxBot (#3298)
- Upgraded trivy from 0.65.0 to 0.67.0 @secureCodeBoxBot (#3252, #3303)
- Upgraded trivy-sbom from 0.65.0 to 0.67.0 @secureCodeBoxBot (#3253, #3304)
- Upgraded whatweb from v6.0.1 to v0.6.2 @secureCodeBoxBot (#3236)
🐛 Bug Fixes
- Fix Dependency Track Hook by @p4trickweiss in #3290
- Added affinity and tolerations fields to ssh-audit-scan-type.yaml by @DevikHaruko in #3297
- Migrate scan kubernetes finalizers to avoid warnings about non-recommended finalizer url structure by @J12934 in #3226
📚 Documentation
- Fix minor documentation issues by @J12934 in #3221
- Replace Snyk badge with OpenSSF Scorecard Badge by @J12934 in #3233
- Update supported k8s versions to include new Kubernetes 1.34 release. by @J12934 in #3255
- Update Security Policy with new supported Versions and Update Advisory Publishing Process by @J12934 in #3235
🔧 Maintenance
- Automatically set labels for renovate PRs by @J12934 in #3203
- Renovate for ci.yaml dependencies by @J12934 in #3204
- Optimize Go Docker builds with native cross-compilation by @J12934 in #3206
- Migrate docker repository for petstore by @Reet00 in #3213
- Remove unnecessary create-blog-post script by @Weltraumschaf in #3244
- Migrate parser-sdk to typescript by @J12934 in #3254
- Changes the comments behind pinned actions to include their full version by @J12934 in #3264
- Rewrite pull-secret-extractor in Go by @p4trickweiss in #3267
- Pin GitHub Pipeline Action Dependencies and specify reduced pipeline permissions by @J12934 in #3229
📌 Dependencies
Minor dependency updates (41 pull requests). Click to expand.
- Update golang Docker tag by @renovate[bot] in #3207
- Update dependency go-task/task to v3.44.1 by @renovate[bot] in #3208
- Update dependency helm/helm to v3.18.5 by @renovate[bot] in #3209
- Update dependency kubernetes/kubernetes to v1.33.4 by @renovate[bot] in #3210
- Bump the go-version-updates group across 4 directories with 6 updates by @dependabot[bot] in #3217
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3214
- Bump actions/checkout from 4 to 5 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3216
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 3 updates by @dependabot[bot] in #3215
- Update docker.io/swaggerapi/petstore3 Docker tag to v1.0.27 by @renovate[bot] in #3218
- Update dependency helm/helm to v3.18.6 by @renovate[bot] in #3222
- Bump the go-version-updates group across 3 directories with 2 updates by @dependabot[bot] in #3240
- Bump io.freefair.lombok from 8.14 to 8.14.2 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot[bot] in #3237
- Add pip to dependabot by @Reet00 in #3234
- Bump the npm-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3241
- Update dependency kubernetes-sigs/kind to v0.30.0 by @renovate[bot] in #3245
- Update dependency kubernetes/kubernetes to v1.34.0 by @renovate[bot] in #3246
- Dependabot/gradle/hooks/persistence defectdojo/hook/gradle version updates 7f209d1a84 by @Weltraumschaf in #3251
- Update docker.io/bkimminich/juice-shop Docker tag to v19 by @renovate[bot] in #3257
- Update golang Docker tag to v1.25.1 by @renovate[bot] in #3256
- Bump the npm-version-updates group across 2 directories with 1 update by @dependabot[bot] in #3261
- Bump the npm-version-updates group in /documentation with 4 updates by @dependabot[bot] in #3260
- Bump the github-actions-version-updates group across 1 directory with 5 updates by @dependabot[bot] in #3265
- Update debian Docker tag to v13.1 by @renovate[bot] in #3266
- Bump the go-version-updates group across 4 directories with 9 updates by @dependabot[bot] in #3263
- Update dependency kubernetes/kubernetes to v1.34.1 by @renovate[bot] in #3268
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3275
- Bump the npm-version-updates group across 2 directories with 1 update by @dependabot[bot] in #3277
- Update dependency helm/helm to v3.19.0 by @renovate[bot] in #3273
- Bump github/codeql-action from 3.30.1 to 3.30.3 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3274
- Bump the go-version-updates group across 4 directories with 5 updates by @dependabot[bot] in #3278
- Update dependency go-task/task to v3.45.3 by @renovate[bot] in #3280
- Update dependency go-task/task to v3.45.4 by @renovate[bot] in #3282
- Update golang Docker tag to v1.25.1 by @renovate[bot] in #3288
- Bump @types/node from 24.4.0 to 24.5.2 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3287
- Bump oxsecurity/megalinter from 8.8.0 to 9.0.1 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3286
- Bump tar-fs from 3.0.10 to 3.1.1 in /tests/integration in the npm-security-updates group across 1 directory by @dependabot[bot] in #3292
- Bump tar-fs from 3.1.0 to 3.1.1 in /hooks/notification/hook by @dependabot[bot] in #3291
- Bump tar-fs from 3.1.0 to 3.1.1 in /hooks/cascading-scans/hook by @dependabot[bot] in #3293
- Bump the npm-security-updates group across 2 directories with 1 update by @dependabot[bot] in #3294
- Bump the npm-version-updates group across 1 directory with 9 updates by @dependabot[bot] in #3300
- Bump the github-actions-version-updates...
v5.0.0
What's Changed
This release brings some long awaited improvements and optimizations.
Some of this required breaking changes, these are listed below.
💣 Breaking
Removed / Replaced ScanTypes
zap-baseline-scanandzap-advancedin favor of thezap-automation-framework. Thezap-automation-frameworkScanTpye includes all functionalities of the removed ScanTypes and can be customized easily. The default ScanType for the AutoDiscovery has been changed to thezap-automation-frameworkas well. For migrating to thezap-automation-frameworkplease refer to migration to zap-automation framework guide.amasshas been replaced withsubfinder. Amass is still an amzing tool, but with its focus on becoming more of a standalone platform / database for attack surfaces keeping it integrated and updated in the secureCodeBox was getting harder and harder. subfinder is a very good replacement for subdomain discovery, thats also generally quicker and produces a similar result.kubeauditwas removed as the scanner itself isn't maintaned anymore. As a replacement you can use thetrivywith it'sk8sscanning mode, see trivy ScanType k8s example.typo3scanwas removed as the scanner itself isn't maintaned anymore. Most security aspects of typo3 are now hard to verify from the outside as it requires authentication (which is really good). Some typo3 security aspects (e.g. a incomplete installation) can be verified by nuclei.doggowas removed. Doggo was added primarily as an experimentation to be used to deduplicate duplicate scan target from cascading rules based on DNS entries. That approach hasn't worked out unfortunately. The doggo integration has been non-functional for a while (see: #2853). As an alternative, nuclei already includes some DNS record based checks, if checks for specific records are required custom nuclei rules could be used to fulfil those requirements.cmseekwas removed. cmseek has seen little updates in the last years. Our secureCodeBox integration with cmseek was always pretty basic, only supporting joomla (a specfifc CMS) results, which hasn't been a big focus for us. As a replacement we recommend using nuclei which has joomla rules which will likely receive more updates in the future.
Renamed ClusterRole and ClusterRoleBinding
To avoid naming collisions with other cluster‑scoped resources, the operator's ClusterRole formerly called manager-role has been renamed to securecodebox‑manager-role, and the corresponding ClusterRoleBinding manager-rolebinding is now securecodebox‑manager-rolebinding. The official Helm chart will automatically create and reference these new names when you update the operator.
If you maintain a custom deployment that directly references manager-role or manager-rolebinding, be sure to update those references to securecodebox‑manager-role and securecodebox‑manager-rolebinding respectively.
Changes to trivy k8s scope (namespace / cluster)
The kubeauditScope on the trivy ScanType chart was renamed to k8sScanScope Scope. The previous name was used for consistency with the kubeaudit ScanType, but it never really made sense and was confusing.
The default k8sScanScope scope was also changed from cluster to namespace, The cluster mode needs cluster wide permissions, which makes the trivy chart hard to install in properly locked down RBAC setups.
Removed Integrated Elasticsearch and Kibana Helm Charts
The integrated Elasticsearch and Kibana Helm charts have been dropped from the Persistence ElasticSearch Hook. These charts were intended as a quick-start option, but since Elastic no longer provides their own Helm charts, they have been removed. The documentation has been updated with guidance on setting up an Elasticsearch cluster using the ECK operator.
Changed Default Elasticsearch Index
The default Elasticsearch index has been updated from scbv2 to scb. The inclusion of v2 was a confusing oversight that has been outdated since the release of secureCodeBox v3.
If you had previously ingested finding using the scbv2 index prefix you can keep using it by setting the indexPrefix helm value back to scbv2 or by migrating your existing indexes to match the new naming scheme.
Replaced Bitnami MinIO Subchart with Direct MinIO Deployment
Due to upcoming deprecations in Bitnami Helm charts, the operator's MinIO integration has been changed from using the Bitnami MinIO subchart to a direct MinIO deployment using the official docker.io/minio/minio image.
- Data will NOT be migrated automatically from the old Bitnami MinIO deployment to the new direct MinIO deployment
- If you have important scan data stored in the old MinIO instance, you must manually backup and restore it before upgrading
- The new MinIO deployment uses different naming conventions and storage configurations
For Production Environments:
The included MinIO deployment is intended only for quickstart and development setups. For production environments, you should:
- Use an external S3-compatible storage service (AWS S3, Google Cloud Storage, etc.)
- Set
minio.enabled=falseand configure thes3section in your values - Refer to the installation documentation for external storage configuration
If you need to continue using the embedded MinIO for development, the new deployment will create a fresh MinIO instance with the same default bucket configuration.
🚀 Features
- Add subfinder scanner by @joel-sass in #3122
- Speed up parser & hook execution time by up to 2x & reduce cpu load by up to 5x by bundling parser & hook sdk by @J12934 in #3137 & #3141
- Add resource & security context config options for trivy db cache by @J12934 in #3037
- Add default RuntimeDefault SecComp Profile to Luker and change Capability to Uppercase to better match Security Policies by @Reet00 in #3116
- Migrate Kubernetes Service AutoDiscovery to use Zap Automation Framework by default by @Reet00 in #3049
- Improve container security by ensuring that the executed code can't be modified by the container user by @J12934 in #3035
🚓 Security Scanner
- Upgraded gitleaks from v8.24.3 to v8.28.0 @secureCodeBoxBot (#3009, #3012, #3032, #3058, #3068, #3145)
- Upgraded nuclei from v3.4.2 to v3.4.7 @secureCodeBoxBot (#3027, #3041, #3089, #3107, #3109)
- Upgraded semgrep from 1.120.0 to 1.131.0 @secureCodeBoxBot (#3017, #3038, #3054, #3066, #3076, #3094, #3100, #3112, #3158, #3163)
- Upgraded sslyze from 6.1.0 to 6.2.0 @secureCodeBoxBot (#3166)
- Upgraded subfinder from v2.7.0 to v2.8.0 @secureCodeBoxBot (#3155)
- Upgraded trivy from 0.61.1 to 0.65.0 @secureCodeBoxBot (#3011, #3016, #3055, #3108, #3110, #3164)
- Upgraded trivy-sbom from 0.61.1 to 0.65.0 @secureCodeBoxBot (#3010, #3015, #3056, #3106,...
v5.0.0-rc.3
Third Release Candidate of the secureCodeBox v5 release.
This now also includes an alternative minio stack to prepare for the upcoming bitnami depracations.
For a preview of the upcoming changes, see the upgrading notes and/or the v5 milestone
v5.0.0-rc.2
Second Release Candidate of the secureCodeBox v5 release.
Release builds for the rc.1 didn't trigger correctly, so here we go again 🤞
Full release notes will be coming with the proper v5 release.
For a preview of the upcoming changes, see the upgrading notes and/or the v5 milestone
v5.0.0-rc.1
Initial Release Candidate of the secureCodeBox v5 release.
Depending on how this goes there might be more coming before the actual v5.0.0 release. 🤞
Full release notes will be coming with the proper v5 release.
For a preview of the upcoming changes, see the upgrading notes and/or the v5 milestone
v4.16.0
What's Changed
Note: This is planned to be the last planned feature release before secureCodeBox v5.0.0.
In case of important bugs, we will still publish bug fix releases under 4.16.x :)
🚓 Security Scanner
- Upgraded gitleaks from v8.24.2 to v8.24.3 @secureCodeBoxBot (#2981)
- Upgraded kubeaudit from 0.22.1 to 0.22.2 @secureCodeBoxBot (#3001)
- Upgraded semgrep from 1.117.0 to 1.120.0 @secureCodeBoxBot (#2974, #2985, #2994)
- Upgraded trivy from 0.61.0 to 0.61.1 @secureCodeBoxBot (#2988)
- Upgraded trivy-sbom from 0.61.0 to 0.61.1 @secureCodeBoxBot (#2987)
- Add ARM support to Ncrack by @J12934 in #2996
⛩️ DefectDojo
🐛 Bug Fixes
- Fix Issue with nested Kubernetes Native Objects not being properly configurable in the Kubernetes AutoDiscovery Config by @BorisShek in #2982
- Fix Invalid ARM Image for DefectDojo hook by @J12934 in #2993
📚 Documentation
- Reorder sections in upgrading.md to list the newest first by @BorisShek in #3000
- Update supported Kubernetes versions by @J12934 in #3003
- Add Link to OWASP Stammtisch Hamburg Talk by @J12934 in #3005
- Fix ncrack config in network scanning how-to by @J12934 in #2995
🔧 Maintenance
- Update Gradle Version used for DefectDojo Hook by @Weltraumschaf in #2975
📌 Dependencies
- Update to Go to 1.24 & Update Go Libraries by @Weltraumschaf in #2978
- Bump golang.org/x/net from 0.37.0 to 0.38.0 in /auto-discovery/cloud-aws by @dependabot in #2986
- Bump http-proxy-middleware from 2.0.7 to 2.0.9 in /documentation in the npm-security-updates group by @dependabot in #2992
Full Changelog: v4.15.0...v4.16.0