dependabot[bot]
f31cf230ab
chore(deps): bump github.com/samber/lo from 1.44.0 to 1.46.0 ( #1992 )
...
Bumps [github.com/samber/lo](https://github.com/samber/lo ) from 1.44.0 to 1.46.0.
- [Release notes](https://github.com/samber/lo/releases )
- [Changelog](https://github.com/samber/lo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/samber/lo/compare/v1.44.0...v1.46.0 )
---
updated-dependencies:
- dependency-name: github.com/samber/lo
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-07-16 04:17:22 +09:00
dependabot[bot]
ed0d1b8312
chore(deps): bump github.com/emersion/go-smtp from 0.21.2 to 0.21.3 ( #1991 )
...
Bumps [github.com/emersion/go-smtp](https://github.com/emersion/go-smtp ) from 0.21.2 to 0.21.3.
- [Release notes](https://github.com/emersion/go-smtp/releases )
- [Commits](https://github.com/emersion/go-smtp/compare/v0.21.2...v0.21.3 )
---
updated-dependencies:
- dependency-name: github.com/emersion/go-smtp
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-07-16 04:16:11 +09:00
dependabot[bot]
24ae273f7e
chore(deps): bump the aws group with 5 updates ( #1990 )
...
Bumps the aws group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) | `1.30.1` | `1.30.3` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.27.24` | `1.27.26` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.17.24` | `1.17.26` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2 ) | `1.58.0` | `1.58.2` |
| [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2 ) | `1.30.1` | `1.30.3` |
Updates `github.com/aws/aws-sdk-go-v2` from 1.30.1 to 1.30.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.30.1...v1.30.3 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.27.24 to 1.27.26
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.27.24...config/v1.27.26 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.17.24 to 1.17.26
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.17.24...credentials/v1.17.26 )
Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.58.0 to 1.58.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.58.0...service/s3/v1.58.2 )
Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.30.1 to 1.30.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.30.1...v1.30.3 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-07-16 04:09:05 +09:00
dependabot[bot]
ab624670fb
chore(deps): bump google.golang.org/grpc from 1.64.0 to 1.64.1 ( #1988 )
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.64.0 to 1.64.1.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.64.0...v1.64.1 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-07-11 05:57:48 +09:00
dependabot[bot]
a00fe47e5f
chore(deps): bump the aws group with 3 updates ( #1987 )
...
Bumps the aws group with 3 updates: [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ), [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) and [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2 ).
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.27.23 to 1.27.24
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.27.23...config/v1.27.24 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.17.23 to 1.17.24
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.17.23...credentials/v1.17.24 )
Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.57.1 to 1.58.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.57.1...service/s3/v1.58.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-07-09 23:28:49 +09:00
dependabot[bot]
d4f7550d66
chore(deps): bump github.com/aquasecurity/trivy from 0.52.2 to 0.53.0 ( #1984 )
...
* chore(deps): bump github.com/aquasecurity/trivy from 0.52.2 to 0.53.0
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.52.2 to 0.53.0.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.52.2...v0.53.0 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
* chore(deps): fixed for trivy update
* fix windows
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Shunichi Shinohara <shino.shun@gmail.com >
2024-07-05 09:08:36 +09:00
MaineK00n
1333f3ac94
fix(scanner/suse): skip new line in zyper -q lu ( #1986 )
2024-07-04 16:22:13 +09:00
dependabot[bot]
ac55380bd7
chore(deps): bump github.com/samber/lo from 1.39.0 to 1.44.0 ( #1985 )
...
Bumps [github.com/samber/lo](https://github.com/samber/lo ) from 1.39.0 to 1.44.0.
- [Release notes](https://github.com/samber/lo/releases )
- [Changelog](https://github.com/samber/lo/blob/master/CHANGELOG.md )
- [Commits](https://github.com/samber/lo/compare/v1.39.0...v1.44.0 )
---
updated-dependencies:
- dependency-name: github.com/samber/lo
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-07-04 14:16:22 +09:00
dependabot[bot]
109891e917
chore(deps): bump goreleaser/goreleaser-action from 5 to 6 ( #1981 )
...
* chore(deps): bump goreleaser/goreleaser-action from 5 to 6
Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action ) from 5 to 6.
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases )
- [Commits](https://github.com/goreleaser/goreleaser-action/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: goreleaser/goreleaser-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
* chore: add version header
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2024-07-04 14:12:59 +09:00
dependabot[bot]
4633c04d59
chore(deps): bump the aws group with 5 updates ( #1983 )
...
Bumps the aws group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) | `1.30.0` | `1.30.1` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.27.21` | `1.27.23` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.17.21` | `1.17.23` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2 ) | `1.56.1` | `1.57.1` |
| [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2 ) | `1.29.1` | `1.30.1` |
Updates `github.com/aws/aws-sdk-go-v2` from 1.30.0 to 1.30.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.30.0...v1.30.1 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.27.21 to 1.27.23
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.27.21...config/v1.27.23 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.17.21 to 1.17.23
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.17.21...credentials/v1.17.23 )
Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.56.1 to 1.57.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.56.1...service/s3/v1.57.1 )
Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.29.1 to 1.30.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.29.1...v1.30.1 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-07-04 14:09:29 +09:00
dependabot[bot]
5db0fdb5d8
chore(deps): bump docker/build-push-action from 5 to 6 ( #1982 )
...
Bumps [docker/build-push-action](https://github.com/docker/build-push-action ) from 5 to 6.
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](https://github.com/docker/build-push-action/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: docker/build-push-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-07-04 14:03:22 +09:00
MaineK00n
a76302c111
feat(cve/nvd): support CVSS v4.0 ( #1979 )
...
* feat(cve/nvd): support CVSS v4.0
* fix(ci/build/windows): use libc v1.52.1
2024-07-04 13:39:16 +09:00
MaineK00n
d8173cdd42
feat(cve/mitre): support go-cve-dictionary:mitre ( #1978 )
...
* feat(cve/mitre): support go-cve-dictionary:mitre
* chore: adopt reviewer comment
* refactor(models): refactor CveContents method
2024-06-29 16:35:06 +09:00
dependabot[bot]
9beb5fc9f0
chore(deps): bump github.com/hashicorp/go-getter from 1.7.4 to 1.7.5 ( #1976 )
...
Bumps [github.com/hashicorp/go-getter](https://github.com/hashicorp/go-getter ) from 1.7.4 to 1.7.5.
- [Release notes](https://github.com/hashicorp/go-getter/releases )
- [Changelog](https://github.com/hashicorp/go-getter/blob/main/.goreleaser.yml )
- [Commits](https://github.com/hashicorp/go-getter/compare/v1.7.4...v1.7.5 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/go-getter
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-26 16:01:20 +09:00
dependabot[bot]
0b4dfa0b31
chore(deps): bump the aws group with 5 updates ( #1974 )
...
Bumps the aws group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) | `1.27.2` | `1.30.0` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.27.18` | `1.27.21` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.17.18` | `1.17.21` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2 ) | `1.55.1` | `1.56.1` |
| [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2 ) | `1.28.12` | `1.29.1` |
Updates `github.com/aws/aws-sdk-go-v2` from 1.27.2 to 1.30.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.27.2...v1.30.0 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.27.18 to 1.27.21
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.27.18...config/v1.27.21 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.17.18 to 1.17.21
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.17.18...credentials/v1.17.21 )
Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.55.1 to 1.56.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.55.1...service/s3/v1.56.1 )
Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.28.12 to 1.29.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/fsx/v1.28.12...service/s3/v1.29.1 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-26 16:00:52 +09:00
MaineK00n
0a47a26553
chore(deps): update goval-dictionary ( #1973 )
2024-06-25 17:28:47 +09:00
Shunichi Shinohara
86d3681d8d
fix(config/os): Fix EOL date of ubuntu 23.10 ( #1972 )
...
cf. https://lists.ubuntu.com/archives/ubuntu-announce/2024-June/000302.html
2024-06-18 16:20:48 +09:00
MaineK00n
436341a4a5
feat: update EOL and Windows KB list ( #1971 )
...
* feat(os): update EOL
* feat(scanner/windows): update kb list
2024-06-18 16:13:59 +09:00
dependabot[bot]
2cd2d1a9a2
chore(deps): bump github.com/aquasecurity/trivy from 0.52.1 to 0.52.2 ( #1969 )
...
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.52.1 to 0.52.2.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/v0.52.2/CHANGELOG.md )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.52.1...v0.52.2 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-18 07:08:39 +09:00
dependabot[bot]
3ba0cea6e3
chore(deps): bump github.com/spf13/cobra from 1.8.0 to 1.8.1 ( #1970 )
...
Bumps [github.com/spf13/cobra](https://github.com/spf13/cobra ) from 1.8.0 to 1.8.1.
- [Release notes](https://github.com/spf13/cobra/releases )
- [Commits](https://github.com/spf13/cobra/compare/v1.8.0...v1.8.1 )
---
updated-dependencies:
- dependency-name: github.com/spf13/cobra
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-18 07:06:39 +09:00
MaineK00n
52fa3a0e31
refactor(report/s3): remove deprecated method for s3 endpoint ( #1967 )
2024-06-17 21:43:52 +09:00
future-ryunosuketanai
ad4f66d551
style(log): saas s3 upload error log ( #1966 )
2024-06-17 17:37:49 +09:00
dependabot[bot]
1e82e04991
chore(deps): bump github.com/aquasecurity/trivy from 0.51.4 to 0.52.1 ( #1961 )
...
* chore(deps): bump github.com/aquasecurity/trivy from 0.51.4 to 0.52.1
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.51.4 to 0.52.1.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/v0.52.1/CHANGELOG.md )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.51.4...v0.52.1 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
* test: update integration commit hash
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2024-06-13 17:16:17 +09:00
dependabot[bot]
995f57ec0c
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity ( #1964 )
...
Bumps [github.com/Azure/azure-sdk-for-go/sdk/azidentity](https://github.com/Azure/azure-sdk-for-go ) from 1.5.2 to 1.6.0.
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases )
- [Changelog](https://github.com/Azure/azure-sdk-for-go/blob/main/documentation/release.md )
- [Commits](https://github.com/Azure/azure-sdk-for-go/compare/sdk/internal/v1.5.2...sdk/azcore/v1.6.0 )
---
updated-dependencies:
- dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azidentity
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-12 22:02:50 +09:00
dependabot[bot]
40d2c8ff6a
chore(deps): bump golang.org/x/oauth2 from 0.20.0 to 0.21.0 ( #1962 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.20.0 to 0.21.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.20.0...v0.21.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-12 18:57:52 +09:00
dependabot[bot]
8abed7a43c
chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.8.0 to 0.9.0 ( #1960 )
...
Bumps [github.com/CycloneDX/cyclonedx-go](https://github.com/CycloneDX/cyclonedx-go ) from 0.8.0 to 0.9.0.
- [Release notes](https://github.com/CycloneDX/cyclonedx-go/releases )
- [Changelog](https://github.com/CycloneDX/cyclonedx-go/blob/master/.goreleaser.yml )
- [Commits](https://github.com/CycloneDX/cyclonedx-go/compare/v0.8.0...v0.9.0 )
---
updated-dependencies:
- dependency-name: github.com/CycloneDX/cyclonedx-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-12 17:40:22 +09:00
dependabot[bot]
48949237b8
chore(deps): bump golang.org/x/text from 0.15.0 to 0.16.0 ( #1959 )
...
Bumps [golang.org/x/text](https://github.com/golang/text ) from 0.15.0 to 0.16.0.
- [Release notes](https://github.com/golang/text/releases )
- [Commits](https://github.com/golang/text/compare/v0.15.0...v0.16.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/text
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-12 17:35:42 +09:00
dependabot[bot]
3958dde312
chore(deps): bump the aws group with 5 updates ( #1958 )
...
Bumps the aws group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2 ) | `1.27.0` | `1.27.2` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) | `1.27.16` | `1.27.18` |
| [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) | `1.17.16` | `1.17.18` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2 ) | `1.54.3` | `1.55.1` |
| [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2 ) | `1.28.10` | `1.28.12` |
Updates `github.com/aws/aws-sdk-go-v2` from 1.27.0 to 1.27.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.27.0...v1.27.2 )
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.27.16 to 1.27.18
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.27.16...config/v1.27.18 )
Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.17.16 to 1.17.18
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.17.16...credentials/v1.17.18 )
Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.54.3 to 1.55.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.54.3...service/s3/v1.55.1 )
Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.28.10 to 1.28.12
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/efs/v1.28.10...service/fsx/v1.28.12 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-12 17:31:23 +09:00
MaineK00n
7f79b8eadf
feat(config/os): add alpine 3.19, 3.20 EOL ( #1965 )
2024-06-12 17:18:20 +09:00
Shunichi Shinohara
cb26be180a
fix(ci): Remove unused files to avoid disk full ( #1957 )
...
cf.
- https://zenn.dev/pinto0309/scraps/c6413eb15a1b2a (in Japanese)
- https://github.com/actions/runner-images/issues/709
2024-06-09 12:32:21 +09:00
MaineK00n
e1fab805af
fix(debian,ubuntu): collect running kernel source package ( #1935 )
2024-06-06 21:20:16 +09:00
MaineK00n
5af1a22733
fix(redhat-based): collect running kernel packages ( #1950 )
2024-06-06 10:28:40 +09:00
dependabot[bot]
0533069446
chore(deps): bump docker/setup-buildx-action from 2 to 3 ( #1955 )
...
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) from 2 to 3.
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](https://github.com/docker/setup-buildx-action/compare/v2...v3 )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-03 18:15:00 +09:00
dependabot[bot]
3e1f2bc88b
chore(deps): bump docker/setup-qemu-action from 2 to 3 ( #1954 )
...
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) from 2 to 3.
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](https://github.com/docker/setup-qemu-action/compare/v2...v3 )
---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-03 18:09:09 +09:00
dependabot[bot]
368c496d40
chore(deps): bump docker/metadata-action from 4 to 5 ( #1953 )
...
Bumps [docker/metadata-action](https://github.com/docker/metadata-action ) from 4 to 5.
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Upgrade guide](https://github.com/docker/metadata-action/blob/master/UPGRADE.md )
- [Commits](https://github.com/docker/metadata-action/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: docker/metadata-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-03 18:06:18 +09:00
dependabot[bot]
a99e3af3fe
chore(deps): bump golangci/golangci-lint-action from 3 to 6 ( #1952 )
...
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action ) from 3 to 6.
- [Release notes](https://github.com/golangci/golangci-lint-action/releases )
- [Commits](https://github.com/golangci/golangci-lint-action/compare/v3...v6 )
---
updated-dependencies:
- dependency-name: golangci/golangci-lint-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-03 17:59:19 +09:00
dependabot[bot]
1769107382
chore(deps): bump github/codeql-action from 2 to 3 ( #1951 )
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 2 to 3.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/v2...v3 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-06-03 17:58:27 +09:00
dependabot[bot]
2e5884b9bd
chore(deps): bump github.com/aquasecurity/trivy from 0.51.2 to 0.51.4 ( #1938 )
...
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.51.2 to 0.51.4.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.51.2...v0.51.4 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-29 16:41:11 +09:00
MaineK00n
cc9734d5e4
chore(deps): use github.com/Azure/azure-sdk-for-go/sdk/storage/azblob ( #1661 )
2024-05-28 19:31:21 +09:00
dependabot[bot]
227208b60b
chore(deps): bump github.com/BurntSushi/toml from 1.3.2 to 1.4.0 ( #1949 )
...
Bumps [github.com/BurntSushi/toml](https://github.com/BurntSushi/toml ) from 1.3.2 to 1.4.0.
- [Release notes](https://github.com/BurntSushi/toml/releases )
- [Commits](https://github.com/BurntSushi/toml/compare/v1.3.2...v1.4.0 )
---
updated-dependencies:
- dependency-name: github.com/BurntSushi/toml
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-28 11:24:39 +09:00
dependabot[bot]
949d72d0b7
chore(deps): bump actions/setup-go from 3 to 5 ( #1946 )
...
Bumps [actions/setup-go](https://github.com/actions/setup-go ) from 3 to 5.
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](https://github.com/actions/setup-go/compare/v3...v5 )
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-28 11:24:29 +09:00
dependabot[bot]
2f02918064
chore(deps): bump github.com/hashicorp/go-version from 1.6.0 to 1.7.0 ( #1948 )
...
Bumps [github.com/hashicorp/go-version](https://github.com/hashicorp/go-version ) from 1.6.0 to 1.7.0.
- [Release notes](https://github.com/hashicorp/go-version/releases )
- [Changelog](https://github.com/hashicorp/go-version/blob/main/CHANGELOG.md )
- [Commits](https://github.com/hashicorp/go-version/compare/v1.6.0...v1.7.0 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/go-version
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-28 11:24:10 +09:00
dependabot[bot]
73917188d5
chore(deps): bump the aws group with 2 updates ( #1947 )
...
Bumps the aws group with 2 updates: [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) and [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2 ).
Updates `github.com/aws/aws-sdk-go-v2/config` from 1.27.15 to 1.27.16
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.27.15...config/v1.27.16 )
Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.54.2 to 1.54.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.54.2...service/s3/v1.54.3 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: aws
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-28 11:04:29 +09:00
dependabot[bot]
980c1ff262
chore(deps): bump docker/build-push-action from 2 to 5 ( #1945 )
...
Bumps [docker/build-push-action](https://github.com/docker/build-push-action ) from 2 to 5.
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](https://github.com/docker/build-push-action/compare/v2...v5 )
---
updated-dependencies:
- dependency-name: docker/build-push-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-28 10:59:59 +09:00
dependabot[bot]
58bb6c7e09
chore(deps): bump actions/checkout from 3 to 4 ( #1944 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 3 to 4.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-28 10:59:40 +09:00
dependabot[bot]
977fe0ca49
chore(deps): bump goreleaser/goreleaser-action from 4 to 5 ( #1943 )
...
Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action ) from 4 to 5.
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases )
- [Commits](https://github.com/goreleaser/goreleaser-action/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: goreleaser/goreleaser-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-28 10:53:57 +09:00
dependabot[bot]
474c76e7a7
chore(deps): bump docker/login-action from 2 to 3 ( #1942 )
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 2 to 3.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/v2...v3 )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-28 10:53:23 +09:00
MaineK00n
5116a6a23d
feat(ci): group aws-sdk-go-v2 updates, check github actions update ( #1941 )
...
* feat(ci): group aws-sdk-go-v2 updates
* faet(ci): add github actions update
2024-05-28 10:39:13 +09:00
dependabot[bot]
8449f2e295
chore(deps): bump github.com/aws/aws-sdk-go-v2/credentials ( #1936 )
...
Bumps [github.com/aws/aws-sdk-go-v2/credentials](https://github.com/aws/aws-sdk-go-v2 ) from 1.17.15 to 1.17.16.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/credentials/v1.17.15...credentials/v1.17.16 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-28 10:27:54 +09:00
MaineK00n
db2c502b4a
feat(reporter/s3): support minio ( #1930 )
...
* feat(reporter/s3): support minio
* feat(reporter/s3): disable config/credential: file and some providers
2024-05-28 10:13:39 +09:00
dependabot[bot]
337eb0b281
chore(deps): bump github.com/aws/aws-sdk-go from 1.53.0 to 1.53.9 ( #1934 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.53.0 to 1.53.9.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.53.0...v1.53.9 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: indirect
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-24 19:31:37 +09:00
MaineK00n
d8bce94d8c
chore(deps): use aws-sdk-go-v2 ( #1922 )
2024-05-24 19:08:38 +09:00
dependabot[bot]
9107d1b1bc
chore(deps): bump github.com/aquasecurity/trivy from 0.51.1 to 0.51.2 ( #1928 )
...
* ---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
* chore(deps): go mod tidy
* chore(deps): follow type name change
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Shunichi Shinohara <shino.shun@gmail.com >
2024-05-23 05:13:59 +09:00
MaineK00n
407407d306
fix(contrib/trivy-to-vuls): remove cvss/severity duplicates, list all severities ( #1929 )
2024-05-22 17:16:02 +09:00
dependabot[bot]
dccdd8a091
chore(deps): bump github.com/package-url/packageurl-go from 0.1.2 to 0.1.3 ( #1927 )
...
updated-dependencies:
- dependency-name: github.com/package-url/packageurl-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-21 15:13:50 +09:00
MaineK00n
878c25bf5a
feat(detector, contrib/trivy-to-vuls): collect vendor severity and cvss ( #1921 )
2024-05-17 19:11:51 +09:00
MaineK00n
e4728e3881
fix(gost/debian): show all severities that appeared ( #1914 )
2024-05-16 18:01:01 +09:00
MaineK00n
61c39637f2
feat(scanner/redhat): each package has modularitylabel ( #1381 )
2024-05-16 02:54:02 +09:00
dependabot[bot]
f1c384812a
chore(deps): bump github.com/aquasecurity/trivy from 0.50.1 to 0.51.1 ( #1912 )
...
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.50.1 to 0.51.1.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.50.1...v0.51.1 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-15 22:37:12 +09:00
dependabot[bot]
0fa09e1517
chore(deps): bump github.com/emersion/go-smtp from 0.21.1 to 0.21.2 ( #1918 )
...
Bumps [github.com/emersion/go-smtp](https://github.com/emersion/go-smtp ) from 0.21.1 to 0.21.2.
- [Release notes](https://github.com/emersion/go-smtp/releases )
- [Commits](https://github.com/emersion/go-smtp/compare/v0.21.1...v0.21.2 )
---
updated-dependencies:
- dependency-name: github.com/emersion/go-smtp
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-14 10:51:15 +09:00
MaineK00n
ef2be3d6ea
feat(detect/redhat): detect unpatched vulnerabilities with oval, stop using gost ( #1907 )
...
* feat(oval/redhat): detect not fixed package
* feat(gost/redhat): stop using to detect unpatched vulnerabilities
2024-05-10 17:32:40 +09:00
dependabot[bot]
827f2cb8d8
chore(deps): bump golang.org/x/oauth2 from 0.19.0 to 0.20.0 ( #1910 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.19.0 to 0.20.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.19.0...v0.20.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-08 07:10:05 +09:00
dependabot[bot]
4cb4ec4dda
chore(deps): bump golang.org/x/text from 0.14.0 to 0.15.0 ( #1909 )
...
Bumps [golang.org/x/text](https://github.com/golang/text ) from 0.14.0 to 0.15.0.
- [Release notes](https://github.com/golang/text/releases )
- [Commits](https://github.com/golang/text/compare/v0.14.0...v0.15.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/text
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-08 03:04:23 +09:00
dependabot[bot]
81f3d5f3bd
chore(deps): bump go.etcd.io/bbolt from 1.3.9 to 1.3.10 ( #1908 )
...
Bumps [go.etcd.io/bbolt](https://github.com/etcd-io/bbolt ) from 1.3.9 to 1.3.10.
- [Release notes](https://github.com/etcd-io/bbolt/releases )
- [Commits](https://github.com/etcd-io/bbolt/compare/v1.3.9...v1.3.10 )
---
updated-dependencies:
- dependency-name: go.etcd.io/bbolt
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-08 02:30:02 +09:00
MaineK00n
f3f667138d
feat(ubuntu): add 24.04 noble ( #1878 )
2024-05-02 16:56:42 +09:00
dependabot[bot]
bca59ff85f
chore(deps): bump github.com/hashicorp/go-getter from 1.7.3 to 1.7.4 ( #1903 )
...
Bumps [github.com/hashicorp/go-getter](https://github.com/hashicorp/go-getter ) from 1.7.3 to 1.7.4.
- [Release notes](https://github.com/hashicorp/go-getter/releases )
- [Changelog](https://github.com/hashicorp/go-getter/blob/main/.goreleaser.yml )
- [Commits](https://github.com/hashicorp/go-getter/compare/v1.7.3...v1.7.4 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/go-getter
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-30 15:04:15 +09:00
future-ryunosuketanai
3f98fbc82c
style(log) fix trivy scan page link ( #1902 )
2024-04-25 19:20:42 +09:00
MaineK00n
73dc95f6b9
fix(detector/suse): support when advisory.cves has both NVD and SUSE evaluations ( #1899 )
2024-04-23 16:30:33 +09:00
dependabot[bot]
04bdaabe6b
chore(deps): bump golang.org/x/net from 0.22.0 to 0.23.0 ( #1898 )
...
Bumps [golang.org/x/net](https://github.com/golang/net ) from 0.22.0 to 0.23.0.
- [Commits](https://github.com/golang/net/compare/v0.22.0...v0.23.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-21 22:52:03 +09:00
Shunichi Shinohara
8f4025120d
(fix) Exclude dev dependencies from npm's package-lock.json and Fix Java DB download endpoint ( #1893 )
...
* (fix) Exclude dev dependencies from npm's package-lock.json
* chore(integration) update
* choir(integration) add lib scan names to makefile
* fix(javadb) add schema version only once
2024-04-17 17:23:57 +09:00
deferdeter
cfbe47bd99
chore: fix some typos in comments ( #1897 )
...
Signed-off-by: deferdeter <deferdeter@outlook.com >
2024-04-16 19:14:00 +09:00
future-ryunosuketanai
a6cafabfb8
style(log) config.toml template docs url ( #1894 )
...
* fix: config.toml template url
* applied fixes to other places
2024-04-16 12:11:28 +09:00
dependabot[bot]
d1137ad1ca
chore(deps): bump github.com/emersion/go-smtp from 0.21.0 to 0.21.1 ( #1896 )
...
Bumps [github.com/emersion/go-smtp](https://github.com/emersion/go-smtp ) from 0.21.0 to 0.21.1.
- [Release notes](https://github.com/emersion/go-smtp/releases )
- [Commits](https://github.com/emersion/go-smtp/compare/v0.21.0...v0.21.1 )
---
updated-dependencies:
- dependency-name: github.com/emersion/go-smtp
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-16 10:35:18 +09:00
dependabot[bot]
6181e1c4bb
chore(deps): bump golang.org/x/sync from 0.6.0 to 0.7.0 ( #1890 )
...
Bumps [golang.org/x/sync](https://github.com/golang/sync ) from 0.6.0 to 0.7.0.
- [Commits](https://github.com/golang/sync/compare/v0.6.0...v0.7.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/sync
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-10 18:19:54 +09:00
dependabot[bot]
5f0abc971f
chore(deps): bump golang.org/x/oauth2 from 0.18.0 to 0.19.0 ( #1891 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.18.0 to 0.19.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.18.0...v0.19.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-10 17:56:53 +09:00
dependabot[bot]
3cdd2e10d0
chore(deps): bump github.com/emersion/go-smtp from 0.20.2 to 0.21.0 ( #1888 )
...
* chore(deps): bump github.com/emersion/go-smtp from 0.20.2 to 0.21.0
Bumps [github.com/emersion/go-smtp](https://github.com/emersion/go-smtp ) from 0.20.2 to 0.21.0.
- [Release notes](https://github.com/emersion/go-smtp/releases )
- [Commits](https://github.com/emersion/go-smtp/compare/v0.20.2...v0.21.0 )
---
updated-dependencies:
- dependency-name: github.com/emersion/go-smtp
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
* fix(reporter/email): use DialStartTLS instead of StartTLS
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2024-04-05 17:41:41 +09:00
Konstantin Eremin
867bf63bb2
TLS insecure option adding ( #1220 )
...
* TLS InsecureSkipVerify option added to sendMail
* refactor(reporter/email): remove redundant if statement
---------
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2024-04-05 13:12:47 +09:00
dependabot[bot]
5d5dcd5f41
chore(deps): bump github.com/aquasecurity/trivy from 0.49.1 to 0.50.1 ( #1885 )
...
* chore(deps): bump github.com/aquasecurity/trivy from 0.49.1 to 0.50.1
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.49.1 to 0.50.1.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.49.1...v0.50.1 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
* refactor(cmd/report): use trivy default for trivy-java-db-repository default value
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2024-03-28 13:09:49 +09:00
dependabot[bot]
e25ec99968
chore(deps): bump github.com/aws/aws-sdk-go from 1.49.21 to 1.51.5 ( #1881 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.49.21 to 1.51.5.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.49.21...v1.51.5 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-22 16:27:34 +09:00
future-ryunosuketanai
50580f6e98
feat(wpscan): support enterprise feature ( #1875 )
...
* supported the enterprise version of wpscan
* remove omitempty
* fix struct pointer
* Update detector/wordpress.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* add exploitdb to wpscan ref
* unexport WpCveInfos, WpCveInfo, and References
* unexport some wpscan struct and fix poc, exploit assign
* change OffensiveSecurityType to wpscan
* Update detector/wordpress.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
---------
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2024-03-22 16:17:16 +09:00
MaineK00n
472df0e1b6
chore(deps): update dictionary modules ( #1877 )
2024-03-22 16:10:50 +09:00
dependabot[bot]
7d5a47bc33
chore(deps): bump github.com/docker/docker ( #1880 )
...
Bumps [github.com/docker/docker](https://github.com/docker/docker ) from 25.0.1+incompatible to 25.0.5+incompatible.
- [Release notes](https://github.com/docker/docker/releases )
- [Commits](https://github.com/docker/docker/compare/v25.0.1...v25.0.5 )
---
updated-dependencies:
- dependency-name: github.com/docker/docker
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-21 13:22:24 +09:00
Shunichi Shinohara
99cf9dbccd
feat(detector/library): update JAR-like files' Name/Version in library list ( #1874 )
...
* Update JAR-like files in library list
* Update detector/library.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/library.go
---------
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2024-03-19 15:17:37 +09:00
MaineK00n
e1df74cbc1
fix(amazon): use major version for checking eol, security advisories ( #1873 )
2024-03-18 16:13:54 +09:00
dependabot[bot]
426eb53af5
chore(deps): bump github.com/jackc/pgx/v5 from 5.5.1 to 5.5.4 ( #1872 )
...
Bumps [github.com/jackc/pgx/v5](https://github.com/jackc/pgx ) from 5.5.1 to 5.5.4.
- [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md )
- [Commits](https://github.com/jackc/pgx/compare/v5.5.1...v5.5.4 )
---
updated-dependencies:
- dependency-name: github.com/jackc/pgx/v5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-15 09:49:26 +09:00
dependabot[bot]
bda089b589
chore(deps): bump google.golang.org/protobuf from 1.32.0 to 1.33.0 ( #1871 )
...
Bumps google.golang.org/protobuf from 1.32.0 to 1.33.0.
---
updated-dependencies:
- dependency-name: google.golang.org/protobuf
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-14 15:13:37 +09:00
dependabot[bot]
02d1f6f59e
chore(deps): bump golang.org/x/oauth2 from 0.17.0 to 0.18.0 ( #1868 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.17.0 to 0.18.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.17.0...v0.18.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-12 04:02:19 +09:00
Shunichi Shinohara
75c1956635
fix(build): Change timeout to 60 minutes ( #1867 )
2024-03-11 10:08:51 +09:00
MaineK00n
b8320c05d2
fix(scanner): output all results even if all fail ( #1866 )
2024-03-07 22:07:32 +09:00
tk007
be7b9114cc
feat(PackageURL):add package URL for library scan result ( #1862 )
...
* add: package url in model.Library
* feat(trivy-to-vuls): add purl for library scan result
* feat(scanner/library): add purl for lockfile scan result
* fix: model.Library test
* fix: trivy-to-vuls test data
* fix: panic case to generate purl
* fix: add blank line
* fix: trivy-to-vuls for using Trivy version 0.49.0 or earlier
* fix: remove comment
* fix: remove print
* fix: testcase for Package.Identifier does not exist version
* fix: add blank line
* fix: expected libs
* fix: PackageURL -> PURL
* fix: blank line
2024-03-07 16:21:15 +09:00
MaineK00n
bf14b5f61f
fix(detector): library.Scan move to detector ( #1864 )
2024-03-06 16:59:06 +09:00
MaineK00n
dc496468b9
refactor(config): move syslogconf to config/syslog package ( #1865 )
2024-03-05 18:11:45 +09:00
dependabot[bot]
54dae08f54
chore(deps): bump go.uber.org/zap from 1.26.0 to 1.27.0 ( #1861 )
...
Bumps [go.uber.org/zap](https://github.com/uber-go/zap ) from 1.26.0 to 1.27.0.
- [Release notes](https://github.com/uber-go/zap/releases )
- [Changelog](https://github.com/uber-go/zap/blob/master/CHANGELOG.md )
- [Commits](https://github.com/uber-go/zap/compare/v1.26.0...v1.27.0 )
---
updated-dependencies:
- dependency-name: go.uber.org/zap
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-05 15:45:01 +09:00
Shunichi Shinohara
d1f9233409
Avoid to use sync.Once inside trivy javadb Updater ( #1859 )
...
* Avoid to use once inside trivy javadb Updater
Because detector package may be used as library-like way
* Update detector/javadb/javadb.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/javadb/javadb.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/javadb/javadb.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/javadb/javadb.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/javadb/javadb.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/javadb/javadb.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/javadb/javadb.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/javadb/javadb.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/javadb/javadb.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/javadb/javadb.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Avoid else if, unless necessary
* go mod tidy
* Add package comment
---------
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2024-03-05 15:23:45 +09:00
dependabot[bot]
eed4328e2c
chore(deps): bump helm.sh/helm/v3 from 3.14.0 to 3.14.2 ( #1856 )
...
Bumps [helm.sh/helm/v3](https://github.com/helm/helm ) from 3.14.0 to 3.14.2.
- [Release notes](https://github.com/helm/helm/releases )
- [Commits](https://github.com/helm/helm/compare/v3.14.0...v3.14.2 )
---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-28 16:38:43 +09:00
MaineK00n
05e0f05f5a
fix(ci): use go version of go.mod ( #1858 )
2024-02-28 16:20:55 +09:00
Shunichi Shinohara
351cf4f712
Update trivy from 0.35.0 to 0.49.1 ( #1806 )
...
* Update trivy 0.35.0->0.48.0
- Specify oras-go 1.2.4 in indirect dependencies
docker/docker changes a part of its API at 24.0
- registry: return concrete service type · moby/moby@7b3acdf
- 7b3acdff5d (diff-8325eae896b1149bf92c826d07fc29005b1b102000b766ffa5a238d791e0849bR18-R21)
oras-go 1.2.3 uses 23.0.1 and trivy transitively depends on docker/docker 24.y.z.
There is a build error between oras-go and docker/dockr.
- Update disabled analyzers
- Update language scanners, enable all of them
* move javadb init to scan.go
* Add options for java db init()
* Update scanner/base.go
* Remove unused codes
* Add some lock file names
* Typo fix
* Remove space character (0x20)
* Add java-db options for integration scan
* Minor fomartting fix
* minor fix
* conda is NOT supported by Trivy for library scan
* Configure trivy log in report command too
* Init trivy in scanner
* Use trivy's jar.go and replace client which does almost nothing
* mv jar.go
* Add sha1 hash to result and add filepath for report phase
* Undo added 'vuls scan' options
* Update oras-go to 1.2.4
* Move Java DB related config items to report side
* Add java db search in detect phase
* filter top level jar only
* Update trivy to 0.49.1
* go mod tidy
* Update to newer interface
* Refine lock file list, h/t MaineK00n
* Avoid else clauses if possible, h/t MaineK00n
* Avoid missing word for find and lang types, h/t MaineK00n
* Add missing ecosystems, h/t MaineK00n
* Add comments why to use custom jar analyzer, h/t MaineK00n
* Misc
* Misc
* Misc
* Include go-dep-parser's pares.go for modification
* Move digest field from LibraryScanner to Library
* Use inner jars sha1 for each
* Add Seek to file head before handling zip file entry
* Leave Digest feild empty for entries from pom.xml
* Don't import python/pkg (don't look into package.json)
* Make privete where private is sufficient
* Remove duplicate after Java DB lookup
* misc
* go mod tidy
* Comment out ruby/gemspec
* misc
* Comment out python/packaging
* misc
* Use custom jar
* Update scanner/trivy/jar/parse.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/trivy/jar/parse.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/trivy/jar/parse.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/trivy/jar/parse.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/trivy/jar/parse.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/trivy/jar/jar.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/library.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update models/library.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/base.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/trivy/jar/parse.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/trivy/jar/parse.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Missing changes in name change
* Update models/github.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update models/library.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update models/library.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update models/library.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/base.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/base.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update scanner/trivy/jar/jar.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Don't import fanal/types at github.go
* Rewrite code around java db initialization
* Add comment
* refactor
* Close java db client
* rename
* Let LibraryScanner have java db client
* Update detector/library.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/library.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/library.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* Update detector/library.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
* inline variable
* misc
* Fix typo
---------
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2024-02-28 14:25:58 +09:00
dependabot[bot]
d7e1e82299
chore(deps): bump go.etcd.io/bbolt from 1.3.8 to 1.3.9 ( #1854 )
...
Bumps [go.etcd.io/bbolt](https://github.com/etcd-io/bbolt ) from 1.3.8 to 1.3.9.
- [Release notes](https://github.com/etcd-io/bbolt/releases )
- [Commits](https://github.com/etcd-io/bbolt/compare/v1.3.8...v1.3.9 )
---
updated-dependencies:
- dependency-name: go.etcd.io/bbolt
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-27 09:57:43 +09:00
dependabot[bot]
6f63566b68
chore(deps): bump golang.org/x/oauth2 from 0.16.0 to 0.17.0 ( #1849 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.16.0 to 0.17.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.16.0...v0.17.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-13 03:53:42 +09:00
MaineK00n
b9ebcf351b
fix(scanner/windows): support when default shell is powershell ( #1844 )
2024-02-02 15:42:43 +09:00
MaineK00n
7e91f5ef7e
fix(contrib/trivy): fix convert for src package ( #1842 )
2024-02-02 15:35:05 +09:00
hiroka-wada
76267a54fc
delete: cab validation ( #1843 )
...
Co-authored-by: wadahiroka <wadahiroka@wadahirokanoMBP.AirPort >
2024-02-01 12:58:33 +09:00
MaineK00n
ea84385c42
fix(scanner/macos): remove unnecessary error check ( #1836 )
2024-01-31 05:33:47 +09:00
dependabot[bot]
d6589c2193
chore(deps): bump github.com/google/uuid from 1.5.0 to 1.6.0 ( #1837 )
...
Bumps [github.com/google/uuid](https://github.com/google/uuid ) from 1.5.0 to 1.6.0.
- [Release notes](https://github.com/google/uuid/releases )
- [Changelog](https://github.com/google/uuid/blob/master/CHANGELOG.md )
- [Commits](https://github.com/google/uuid/compare/v1.5.0...v1.6.0 )
---
updated-dependencies:
- dependency-name: github.com/google/uuid
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-31 05:32:51 +09:00
dependabot[bot]
6e07103036
chore(deps): bump github.com/emersion/go-smtp from 0.20.1 to 0.20.2 ( #1838 )
...
Bumps [github.com/emersion/go-smtp](https://github.com/emersion/go-smtp ) from 0.20.1 to 0.20.2.
- [Release notes](https://github.com/emersion/go-smtp/releases )
- [Commits](https://github.com/emersion/go-smtp/compare/v0.20.1...v0.20.2 )
---
updated-dependencies:
- dependency-name: github.com/emersion/go-smtp
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-31 05:32:32 +09:00
dependabot[bot]
b7e5bb2fbb
chore(deps): bump golang.org/x/oauth2 from 0.15.0 to 0.16.0 ( #1831 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.15.0 to 0.16.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.15.0...v0.16.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-16 07:58:40 +09:00
dependabot[bot]
91ed76838e
chore(deps): bump golang.org/x/sync from 0.5.0 to 0.6.0 ( #1833 )
...
Bumps [golang.org/x/sync](https://github.com/golang/sync ) from 0.5.0 to 0.6.0.
- [Commits](https://github.com/golang/sync/compare/v0.5.0...v0.6.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/sync
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-16 07:49:21 +09:00
Sinclair
098f3089dd
chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.7.2 to 0.8.0 ( #1829 )
2024-01-12 14:17:12 +09:00
dependabot[bot]
0e04d21bef
chore(deps): bump github.com/emersion/go-smtp from 0.20.0 to 0.20.1 ( #1826 )
...
Bumps [github.com/emersion/go-smtp](https://github.com/emersion/go-smtp ) from 0.20.0 to 0.20.1.
- [Release notes](https://github.com/emersion/go-smtp/releases )
- [Commits](https://github.com/emersion/go-smtp/compare/v0.20.0...v0.20.1 )
---
updated-dependencies:
- dependency-name: github.com/emersion/go-smtp
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-09 23:40:33 +09:00
dependabot[bot]
f1005e5db3
chore(deps): bump github.com/emersion/go-smtp from 0.19.0 to 0.20.0 ( #1824 )
...
Bumps [github.com/emersion/go-smtp](https://github.com/emersion/go-smtp ) from 0.19.0 to 0.20.0.
- [Release notes](https://github.com/emersion/go-smtp/releases )
- [Commits](https://github.com/emersion/go-smtp/compare/v0.19.0...v0.20.0 )
---
updated-dependencies:
- dependency-name: github.com/emersion/go-smtp
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 15:32:17 +09:00
dependabot[bot]
1acc4d8e04
chore(deps): bump github.com/c-robinson/iplib from 1.0.7 to 1.0.8 ( #1819 )
...
Bumps [github.com/c-robinson/iplib](https://github.com/c-robinson/iplib ) from 1.0.7 to 1.0.8.
- [Release notes](https://github.com/c-robinson/iplib/releases )
- [Commits](https://github.com/c-robinson/iplib/compare/v1.0.7...v1.0.8 )
---
updated-dependencies:
- dependency-name: github.com/c-robinson/iplib
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-26 08:07:08 +09:00
dependabot[bot]
eee6441372
chore(deps): bump golang.org/x/crypto from 0.16.0 to 0.17.0 ( #1818 )
...
Bumps [golang.org/x/crypto](https://github.com/golang/crypto ) from 0.16.0 to 0.17.0.
- [Commits](https://github.com/golang/crypto/compare/v0.16.0...v0.17.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/crypto
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-19 13:51:19 +09:00
MaineK00n
bbf53c7639
chore(deps): bump dictionaries ( #1815 )
2023-12-18 05:41:46 +09:00
MaineK00n
8e497bb938
fix(scanner/redhat): do not make cache when offline of redhat fast ( #1814 )
2023-12-17 05:21:34 +09:00
hiroka-wada
b2c91175b3
fix(scanner/redhat): make cache before detect dnf modules ( #1812 )
...
Co-authored-by: wadahiroka <wadahiroka@192.168 .0.4>
2023-12-15 16:16:13 +09:00
MaineK00n
d1224991a0
feat(models/nvd): group by source ( #1805 )
2023-12-08 19:36:26 +09:00
MaineK00n
7e12e9abc4
chore(deps): bump go-cve-dictionary to 0.10.0 ( #1803 )
2023-12-07 12:48:14 +09:00
dependabot[bot]
df960cc0f5
chore(deps): bump golang.org/x/oauth2 from 0.14.0 to 0.15.0 ( #1799 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.14.0 to 0.15.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.14.0...v0.15.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-29 11:15:40 +09:00
dependabot[bot]
b0489785d0
chore(deps): bump github.com/gosnmp/gosnmp from 1.36.1 to 1.37.0 ( #1798 )
...
Bumps [github.com/gosnmp/gosnmp](https://github.com/gosnmp/gosnmp ) from 1.36.1 to 1.37.0.
- [Release notes](https://github.com/gosnmp/gosnmp/releases )
- [Changelog](https://github.com/gosnmp/gosnmp/blob/master/CHANGELOG.md )
- [Commits](https://github.com/gosnmp/gosnmp/compare/v1.36.1...v1.37.0 )
---
updated-dependencies:
- dependency-name: github.com/gosnmp/gosnmp
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-29 11:14:56 +09:00
MaineK00n
8e9d165e75
feat(os): add FreeBSD 14 ( #1797 )
2023-11-25 08:29:29 +09:00
MaineK00n
ef29afbf94
feat(scanner/windows): remove unnecessary cab ( #1793 )
2023-11-20 12:01:03 +09:00
hiroka-wada
cbece1dce1
add: Setenv HTTPS_PROXY for aws sdk ( #1794 )
...
Co-authored-by: wadahiroka <wadahiroka@192.168 .0.8>
2023-11-20 10:19:18 +09:00
dependabot[bot]
4ffa06770c
chore(deps): bump github.com/emersion/go-smtp from 0.18.1 to 0.19.0 ( #1790 )
...
Bumps [github.com/emersion/go-smtp](https://github.com/emersion/go-smtp ) from 0.18.1 to 0.19.0.
- [Release notes](https://github.com/emersion/go-smtp/releases )
- [Commits](https://github.com/emersion/go-smtp/compare/v0.18.1...v0.19.0 )
---
updated-dependencies:
- dependency-name: github.com/emersion/go-smtp
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-15 23:21:21 +09:00
dependabot[bot]
53317ee49b
chore(deps): bump golang.org/x/sync from 0.4.0 to 0.5.0 ( #1789 )
...
Bumps [golang.org/x/sync](https://github.com/golang/sync ) from 0.4.0 to 0.5.0.
- [Commits](https://github.com/golang/sync/compare/v0.4.0...v0.5.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/sync
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-15 22:16:42 +09:00
dependabot[bot]
fc743569b7
chore(deps): bump golang.org/x/oauth2 from 0.13.0 to 0.14.0 ( #1791 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.13.0 to 0.14.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.13.0...v0.14.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-15 22:09:59 +09:00
Sinclair
bced16fa9c
fix(scanner): parsing apt cache policy for nvidia-container-toolkit ( #1786 )
...
* fix(scanner): parsing apt cache policy for nvidia-container-toolkit
* fix testcase
2023-11-13 13:49:17 +09:00
dependabot[bot]
f3f8e26ba5
chore(deps): bump github.com/emersion/go-smtp from 0.16.0 to 0.18.1 ( #1771 )
...
Bumps [github.com/emersion/go-smtp](https://github.com/emersion/go-smtp ) from 0.16.0 to 0.18.1.
- [Release notes](https://github.com/emersion/go-smtp/releases )
- [Commits](https://github.com/emersion/go-smtp/compare/v0.16.0...v0.18.1 )
---
updated-dependencies:
- dependency-name: github.com/emersion/go-smtp
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-09 05:24:58 +09:00
MaineK00n
cd8f6e1b8f
feat(os): add fedora 39 ( #1788 )
2023-11-08 23:47:46 +09:00
MaineK00n
323f0aea3d
feat(windows): add Windows 11 23H2 ( #1751 )
2023-11-07 09:27:39 +09:00
dependabot[bot]
5d1c365a42
chore(deps): bump golang.org/x/text from 0.13.0 to 0.14.0 ( #1782 )
...
Bumps [golang.org/x/text](https://github.com/golang/text ) from 0.13.0 to 0.14.0.
- [Release notes](https://github.com/golang/text/releases )
- [Commits](https://github.com/golang/text/compare/v0.13.0...v0.14.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/text
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-07 08:14:11 +09:00
dependabot[bot]
d8fa000b01
chore(deps): bump github.com/spf13/cobra from 1.7.0 to 1.8.0 ( #1785 )
...
Bumps [github.com/spf13/cobra](https://github.com/spf13/cobra ) from 1.7.0 to 1.8.0.
- [Release notes](https://github.com/spf13/cobra/releases )
- [Commits](https://github.com/spf13/cobra/compare/v1.7.0...v1.8.0 )
---
updated-dependencies:
- dependency-name: github.com/spf13/cobra
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-07 08:08:56 +09:00
dependabot[bot]
9f1e090597
chore(deps): bump github.com/docker/docker ( #1777 )
...
Bumps [github.com/docker/docker](https://github.com/docker/docker ) from 23.0.4+incompatible to 24.0.7+incompatible.
- [Release notes](https://github.com/docker/docker/releases )
- [Commits](https://github.com/docker/docker/compare/v23.0.4...v24.0.7 )
---
updated-dependencies:
- dependency-name: github.com/docker/docker
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-31 14:30:49 +09:00
dependabot[bot]
8d5765fcb0
chore(deps): bump go.etcd.io/bbolt from 1.3.7 to 1.3.8 ( #1780 )
...
Bumps [go.etcd.io/bbolt](https://github.com/etcd-io/bbolt ) from 1.3.7 to 1.3.8.
- [Release notes](https://github.com/etcd-io/bbolt/releases )
- [Commits](https://github.com/etcd-io/bbolt/compare/v1.3.7...v1.3.8 )
---
updated-dependencies:
- dependency-name: go.etcd.io/bbolt
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-31 14:30:11 +09:00
dependabot[bot]
3a5c3326b2
chore(deps): bump github.com/google/uuid from 1.3.1 to 1.4.0 ( #1781 )
...
Bumps [github.com/google/uuid](https://github.com/google/uuid ) from 1.3.1 to 1.4.0.
- [Release notes](https://github.com/google/uuid/releases )
- [Changelog](https://github.com/google/uuid/blob/master/CHANGELOG.md )
- [Commits](https://github.com/google/uuid/compare/v1.3.1...v1.4.0 )
---
updated-dependencies:
- dependency-name: github.com/google/uuid
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-31 14:29:00 +09:00
hiroka-wada
cef4ce4f9f
chore(config):Modification of AmazonLinux 1 maintenance deadline ( #1776 )
2023-10-27 23:19:16 +09:00
MaineK00n
264a82e2f4
chore(deps): bump github.com/vulsio/gost to v0.4.6-0.20231027050036-c963bd83e7e5 ( #1775 )
2023-10-27 14:26:05 +09:00
dependabot[bot]
fed731b0f2
chore(deps): bump google.golang.org/grpc from 1.58.2 to 1.58.3 ( #1774 )
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.58.2 to 1.58.3.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.58.2...v1.58.3 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-26 08:24:29 +09:00
dependabot[bot]
5e2ac5a0c4
chore(deps): bump golang.org/x/oauth2 from 0.12.0 to 0.13.0 ( #1773 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.12.0 to 0.13.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.12.0...v0.13.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-25 08:20:41 +09:00
MaineK00n
b9db5411cd
feat(scanner): revert lsof command for futurevuls users ( #1770 )
2023-10-20 12:07:20 +09:00
MaineK00n
a1c1f4ce60
fix(scanner): change lsof cmd that should succeed without password ( #1769 )
2023-10-20 11:48:04 +09:00
MaineK00n
75e9883d8a
feat(ubuntu): add ubuntu 23.10(mantic) ( #1750 )
2023-10-19 02:01:18 +09:00
dependabot[bot]
801b968f89
chore(deps): bump github.com/package-url/packageurl-go ( #1754 )
...
Bumps [github.com/package-url/packageurl-go](https://github.com/package-url/packageurl-go ) from 0.1.1-0.20220203205134-d70459300c8a to 0.1.2.
- [Release notes](https://github.com/package-url/packageurl-go/releases )
- [Commits](https://github.com/package-url/packageurl-go/commits/v0.1.2 )
---
updated-dependencies:
- dependency-name: github.com/package-url/packageurl-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-17 23:18:36 +09:00
dependabot[bot]
37175066b1
chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.7.1 to 0.7.2 ( #1733 )
...
Bumps [github.com/CycloneDX/cyclonedx-go](https://github.com/CycloneDX/cyclonedx-go ) from 0.7.1 to 0.7.2.
- [Release notes](https://github.com/CycloneDX/cyclonedx-go/releases )
- [Changelog](https://github.com/CycloneDX/cyclonedx-go/blob/master/.goreleaser.yml )
- [Commits](https://github.com/CycloneDX/cyclonedx-go/compare/v0.7.1...v0.7.2 )
---
updated-dependencies:
- dependency-name: github.com/CycloneDX/cyclonedx-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-17 23:17:30 +09:00
MaineK00n
1a55cafc91
chore(deps): update dictionary ( #1708 )
2023-10-17 23:04:27 +09:00
Kota Kanbe
57264e1765
fix(scan): fix nil poiter in needs-restarting ( #1767 )
2023-10-17 17:58:21 +09:00
dependabot[bot]
48ff5196f4
chore(deps): bump github.com/gosnmp/gosnmp from 1.35.0 to 1.36.1 ( #1763 )
...
Bumps [github.com/gosnmp/gosnmp](https://github.com/gosnmp/gosnmp ) from 1.35.0 to 1.36.1.
- [Release notes](https://github.com/gosnmp/gosnmp/releases )
- [Changelog](https://github.com/gosnmp/gosnmp/blob/master/CHANGELOG.md )
- [Commits](https://github.com/gosnmp/gosnmp/compare/v1.35.0...v1.36.1 )
---
updated-dependencies:
- dependency-name: github.com/gosnmp/gosnmp
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-17 15:25:53 +09:00
hiroka-wada
738f275e50
fix(contrib/fvuls): Add flag to specify snmp community for future-vuls discover ( #1762 )
...
* add: community option for discover command
* fix: README
---------
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.6>
2023-10-12 15:30:27 +09:00
dependabot[bot]
1c79cc5232
chore(deps): bump golang.org/x/net from 0.15.0 to 0.17.0 ( #1761 )
...
Bumps [golang.org/x/net](https://github.com/golang/net ) from 0.15.0 to 0.17.0.
- [Commits](https://github.com/golang/net/compare/v0.15.0...v0.17.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-12 14:23:25 +09:00
orangekame3
73da85210a
chore: remove rand.Seed() ( #1756 )
...
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2023-10-12 14:17:34 +09:00
dependabot[bot]
3de546125f
chore(deps): bump golang.org/x/sync from 0.2.0 to 0.4.0 ( #1757 )
...
Bumps [golang.org/x/sync](https://github.com/golang/sync ) from 0.2.0 to 0.4.0.
- [Commits](https://github.com/golang/sync/compare/v0.2.0...v0.4.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/sync
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-12 14:12:32 +09:00
MaineK00n
d2ca56a515
chore(os): update EOL ( #1749 )
2023-10-03 00:37:16 +09:00
guangwu
27df19f09d
chore: remove refs to deprecated io/ioutil ( #1748 )
...
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
2023-10-01 18:51:53 +09:00
Eng Zer Jun
c1854a3a7b
refactor: remove redundant len check ( #1743 )
...
`len` returns 0 if the slice is nil. From the Go specification [1]:
"1. For a nil slice, the number of iterations is 0."
Therefore, an additional `len(v) != 0` check for before the loop is
unnecessary.
[1]: https://go.dev/ref/spec#For_range
Signed-off-by: Eng Zer Jun <engzerjun@gmail.com >
2023-09-26 18:00:05 +09:00
dependabot[bot]
b43c1b9984
chore(deps): bump github.com/c-robinson/iplib from 1.0.6 to 1.0.7 ( #1745 )
...
Bumps [github.com/c-robinson/iplib](https://github.com/c-robinson/iplib ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/c-robinson/iplib/releases )
- [Commits](https://github.com/c-robinson/iplib/compare/v1.0.6...v1.0.7 )
---
updated-dependencies:
- dependency-name: github.com/c-robinson/iplib
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-26 17:57:16 +09:00
hiroka-wada
9d8e510c0d
add: json tag ( #1746 )
...
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.6>
2023-09-26 15:50:18 +09:00
MaineK00n
1832b4ee3a
feat(macos): support macOS ( #1712 )
2023-09-25 16:51:09 +09:00
MaineK00n
78b52d6a7f
feat(detector/cve): new support for fortinet data feed ( #1736 )
2023-09-25 16:19:10 +09:00
sadayuki-matsuno
048e204b33
fix(contrib/future-vuls) output detail of loading toml error ( #1741 )
2023-09-24 21:45:33 +09:00
MaineK00n
70fd968910
fix(server): add filter cves ( #1707 )
2023-09-22 17:45:45 +09:00
MaineK00n
01441351c3
feat(contrib/snmp2cpe): add other fortinet products ( #1636 )
2023-09-22 17:43:04 +09:00
MaineK00n
4a28722e4a
fix(scanner): fix socket file name length of SSH ControlPath ( #1714 )
2023-09-22 17:31:26 +09:00
hiroka-wada
dea9ed7709
fix: errorlog future-vuls trivy-to-vuls ( #1739 )
...
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.6>
2023-09-22 17:25:57 +09:00
hiroka-wada
f6509a5376
feat(config): Auto-upgrade Windows config.toml from v1 to v2 ( #1726 )
...
* add: README.md
* add: commands(discover,add-server,add-cpe)
* add: implements(discover,add-server,add-cpe)
* fix: changed os.Exit(1) in main.go to return an error
* fix: lint error
* delete: trivy-to-vuls stdIn
* fix: Incomprehesible error logs
* fix: according to review
* add: function converts old config to latest one
* delete: add-server
* fix: lint error
* fix
* fix: remote scan error in Windows
* fix: lint error
* fix
* fix: lint error
* fix: lint error
* add: scanner/scanner.go test normalizeHomeDirForWindows()
* fix
* fix
* fix
* fix: remove pointless assignment
* fix
---------
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.4>
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.10>
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.6>
2023-09-21 16:48:35 +09:00
hiroka-wada
80b48fcbaa
feat(contrib/fvuls) Add commands to obtained CPE information of network devices by executing snmp2cpe and upload to Fvuls server ( #1721 )
...
* add: README.md
* add: commands(discover,add-server,add-cpe)
* add: implements(discover,add-server,add-cpe)
* fix: changed os.Exit(1) in main.go to return an error
* fix: lint error
* delete: trivy-to-vuls stdIn
* fix: Incomprehesible error logs
* fix: according to review
* add: function converts old config to latest one
* delete: add-server
* fix: lint error
* fix
* fix: remote scan error in Windows
* fix: lint error
* fix
* fix: lint error
* fix: lint error
* fix: lint error
* add: scanner/scanner.go test normalizeHomeDirForWindows()
* fix
* fix
* fix
* fix
* fix
* fix
* fix: lint error
* fix: error log
* fix
* refactor(fvuls)
* Refactor (#2 )
refactor
---------
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.6>
* Refactor (#3 )
fix
---------
Co-authored-by: Sadayuki Matsuno <sadayuki.matsuno@gmail.com >
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.6>
* fix
* fix: lint error
* fix
---------
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.4>
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.10>
Co-authored-by: 和田皓翔 <wadahiroka@192.168 .0.6>
Co-authored-by: Sadayuki Matsuno <sadayuki.matsuno@gmail.com >
2023-09-21 15:55:05 +09:00
dependabot[bot]
3f2dbe3b6d
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.300 to 1.45.6 ( #1730 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.44.300 to 1.45.6.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.44.300...v1.45.6 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-12 20:54:00 +09:00
dependabot[bot]
5ffd620868
chore(deps): bump golang.org/x/oauth2 from 0.8.0 to 0.12.0 ( #1731 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.8.0 to 0.12.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.8.0...v0.12.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-12 20:53:43 +09:00
dependabot[bot]
a23abf48fd
chore(deps): bump github.com/sirupsen/logrus from 1.9.0 to 1.9.3 ( #1687 )
...
Bumps [github.com/sirupsen/logrus](https://github.com/sirupsen/logrus ) from 1.9.0 to 1.9.3.
- [Release notes](https://github.com/sirupsen/logrus/releases )
- [Changelog](https://github.com/sirupsen/logrus/blob/master/CHANGELOG.md )
- [Commits](https://github.com/sirupsen/logrus/compare/v1.9.0...v1.9.3 )
---
updated-dependencies:
- dependency-name: github.com/sirupsen/logrus
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-22 21:47:35 +09:00
dependabot[bot]
6e14a2dee6
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.263 to 1.44.300 ( #1706 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.44.263 to 1.44.300.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.44.263...v1.44.300 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-22 21:47:19 +09:00
dependabot[bot]
e12fa0ba64
chore(deps): bump google.golang.org/grpc from 1.52.0 to 1.53.0 ( #1699 )
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.52.0 to 1.53.0.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.52.0...v1.53.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-22 21:42:06 +09:00
dependabot[bot]
fa5b875c34
chore(deps): bump github.com/BurntSushi/toml from 1.2.1 to 1.3.2 ( #1692 )
...
Bumps [github.com/BurntSushi/toml](https://github.com/BurntSushi/toml ) from 1.2.1 to 1.3.2.
- [Release notes](https://github.com/BurntSushi/toml/releases )
- [Commits](https://github.com/BurntSushi/toml/compare/v1.2.1...v1.3.2 )
---
updated-dependencies:
- dependency-name: github.com/BurntSushi/toml
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-22 21:38:04 +09:00
sadayuki-matsuno
f9276a7ea8
feat(windows) export DetectKBsFromKernelVersion ( #1703 )
2023-07-13 10:14:49 +09:00
MaineK00n
457a3a9627
feat(scanner/windows): update release info ( #1696 )
2023-06-29 14:05:10 +09:00
MaineK00n
4253550c99
chore(scanner): do not show logs when lsof: no Internet files located ( #1688 )
2023-06-23 16:08:49 +09:00
Atsushi Watanabe
97cf033ed6
feat(os): add Fedora 38 EOL date ( #1689 )
...
* feat: add Fedora 38 EOL date
* Update EOL date
based on https://fedorapeople.org/groups/schedule/f-38/f-38-key-tasks.html
* Fix test case name
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
---------
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2023-06-13 17:23:11 +09:00
Kota Kanbe
5a6980436a
feat(ubuntu): Support Ubuntu 14.04 and 16.04 ESM ( #1682 )
...
* feat(ubuntu): Support Ubuntu ESM
* Sort PackageFixStatuses to resolve the diff in integrationTest
* go mod update gost
2023-05-31 09:27:43 +09:00
Sinclair
6271ec522e
fix(detector/github): Enhance the dependency graph API call on the big repository ( #1681 )
...
* fix: Reduce the number of data to be fetched per page, when retrying after a timeout failure on Dependency Graph API
* check rate limit on dependency graph API
* comment
2023-05-26 14:39:02 +09:00
dependabot[bot]
83681ad4f0
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.259 to 1.44.263 ( #1677 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.44.259 to 1.44.263.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.44.259...v1.44.263 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-18 10:17:34 +09:00
dependabot[bot]
779833872b
chore(deps): bump golang.org/x/oauth2 from 0.7.0 to 0.8.0 ( #1678 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.7.0 to 0.8.0.
- [Commits](https://github.com/golang/oauth2/compare/v0.7.0...v0.8.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-18 10:16:54 +09:00
Sinclair
5c79720f56
fix(detector/github): Dependency graph API touches fewer data per page than before ( #1654 )
...
* fix: Github dependency graph API touches fewer data per page than before
* fix: logging on Github API access failure
* fix: the previous errors persist upon retrying dependency graph
2023-05-15 19:41:04 +09:00
Wagde Zabit
b2c5b79672
feat(os): support debian 12 ( #1676 )
...
* feat(os): support debian 12
* chore(scanner/debian): remove unneeded warn log
---------
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2023-05-13 01:04:31 +09:00
dependabot[bot]
b0cc908b73
chore(deps): bump github.com/docker/distribution ( #1675 )
...
Bumps [github.com/docker/distribution](https://github.com/docker/distribution ) from 2.8.1+incompatible to 2.8.2+incompatible.
- [Release notes](https://github.com/docker/distribution/releases )
- [Commits](https://github.com/docker/distribution/compare/v2.8.1...v2.8.2 )
---
updated-dependencies:
- dependency-name: github.com/docker/distribution
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-12 08:56:46 +09:00
MaineK00n
ea3d8a6d0b
test: sort []cveContent by CVEID ( #1674 )
2023-05-11 00:53:22 +09:00
MaineK00n
7475b27f6a
chore(deps): update dictionary tools, Vuls is now CGO free ( #1667 )
...
* chore(deps): update dictionary tools, Vuls is now CGO free
* chore(integration): update commit
2023-05-11 00:28:51 +09:00
dependabot[bot]
ef80838ddd
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.254 to 1.44.259 ( #1672 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.44.254 to 1.44.259.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.44.254...v1.44.259 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-09 08:09:49 +09:00
dependabot[bot]
b445b71ca5
chore(deps): bump golang.org/x/sync from 0.1.0 to 0.2.0 ( #1673 )
...
Bumps [golang.org/x/sync](https://github.com/golang/sync ) from 0.1.0 to 0.2.0.
- [Commits](https://github.com/golang/sync/compare/v0.1.0...v0.2.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/sync
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-09 08:09:26 +09:00
dependabot[bot]
1ccc5f031a
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.251 to 1.44.254 ( #1669 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.44.251 to 1.44.254.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.44.251...v1.44.254 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-02 12:17:14 +09:00
MaineK00n
8356e976c4
chore(deps): update goval-dictionary v0.8.3 ( #1671 )
2023-05-02 12:14:43 +09:00
MaineK00n
3cc7e92ce5
fix(saas): remove current directory part ( #1666 )
2023-04-27 12:09:34 +09:00
dependabot[bot]
046a29467b
chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.7.0 to 0.7.1 ( #1663 )
...
Bumps [github.com/CycloneDX/cyclonedx-go](https://github.com/CycloneDX/cyclonedx-go ) from 0.7.0 to 0.7.1.
- [Release notes](https://github.com/CycloneDX/cyclonedx-go/releases )
- [Changelog](https://github.com/CycloneDX/cyclonedx-go/blob/master/.goreleaser.yml )
- [Commits](https://github.com/CycloneDX/cyclonedx-go/compare/v0.7.0...v0.7.1 )
---
updated-dependencies:
- dependency-name: github.com/CycloneDX/cyclonedx-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-27 05:54:41 +09:00
dependabot[bot]
ef5ab8eaf0
chore(deps): bump golang.org/x/oauth2 from 0.1.0 to 0.7.0 ( #1662 )
...
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2 ) from 0.1.0 to 0.7.0.
- [Release notes](https://github.com/golang/oauth2/releases )
- [Commits](https://github.com/golang/oauth2/compare/v0.1.0...v0.7.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-27 05:42:57 +09:00
dependabot[bot]
c8daa5c982
chore(deps): bump github.com/Ullaakut/nmap/v2 ( #1665 )
...
Bumps [github.com/Ullaakut/nmap/v2](https://github.com/Ullaakut/nmap ) from 2.1.2-0.20210406060955-59a52fe80a4f to 2.2.2.
- [Release notes](https://github.com/Ullaakut/nmap/releases )
- [Commits](https://github.com/Ullaakut/nmap/commits/v2.2.2 )
---
updated-dependencies:
- dependency-name: github.com/Ullaakut/nmap/v2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-27 05:41:49 +09:00
dependabot[bot]
9309081b3d
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.249 to 1.44.251 ( #1660 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.44.249 to 1.44.251.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.44.249...v1.44.251 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-27 04:01:42 +09:00
dependabot[bot]
f541c32d1f
chore(deps): bump github.com/c-robinson/iplib from 1.0.3 to 1.0.6 ( #1659 )
...
Bumps [github.com/c-robinson/iplib](https://github.com/c-robinson/iplib ) from 1.0.3 to 1.0.6.
- [Release notes](https://github.com/c-robinson/iplib/releases )
- [Commits](https://github.com/c-robinson/iplib/compare/v1.0.3...v1.0.6 )
---
updated-dependencies:
- dependency-name: github.com/c-robinson/iplib
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-27 03:51:34 +09:00
dependabot[bot]
79a8b62105
chore(deps): bump go.etcd.io/bbolt from 1.3.6 to 1.3.7 ( #1657 )
...
Bumps [go.etcd.io/bbolt](https://github.com/etcd-io/bbolt ) from 1.3.6 to 1.3.7.
- [Release notes](https://github.com/etcd-io/bbolt/releases )
- [Commits](https://github.com/etcd-io/bbolt/compare/v1.3.6...v1.3.7 )
---
updated-dependencies:
- dependency-name: go.etcd.io/bbolt
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-27 03:50:53 +09:00
dependabot[bot]
74c91a5a21
chore(deps): bump github.com/spf13/cobra from 1.6.1 to 1.7.0 ( #1658 )
...
Bumps [github.com/spf13/cobra](https://github.com/spf13/cobra ) from 1.6.1 to 1.7.0.
- [Release notes](https://github.com/spf13/cobra/releases )
- [Commits](https://github.com/spf13/cobra/compare/v1.6.1...v1.7.0 )
---
updated-dependencies:
- dependency-name: github.com/spf13/cobra
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-27 03:36:46 +09:00
MaineK00n
6787ab45c5
feat(ubuntu): add ubuntu 23.04 ( #1647 )
2023-04-27 03:26:59 +09:00
dependabot[bot]
f631e9e603
chore(deps): bump github.com/emersion/go-smtp from 0.14.0 to 0.16.0 ( #1580 )
...
Bumps [github.com/emersion/go-smtp](https://github.com/emersion/go-smtp ) from 0.14.0 to 0.16.0.
- [Release notes](https://github.com/emersion/go-smtp/releases )
- [Commits](https://github.com/emersion/go-smtp/compare/v0.14.0...v0.16.0 )
---
updated-dependencies:
- dependency-name: github.com/emersion/go-smtp
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-27 03:25:41 +09:00
dependabot[bot]
2ab48afe47
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.136 to 1.44.249 ( #1656 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.44.136 to 1.44.249.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.44.136...v1.44.249 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-27 03:24:53 +09:00
dependabot[bot]
53ccd61687
chore(deps): bump github.com/Azure/azure-sdk-for-go ( #1588 )
...
Bumps [github.com/Azure/azure-sdk-for-go](https://github.com/Azure/azure-sdk-for-go ) from 66.0.0+incompatible to 68.0.0+incompatible.
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases )
- [Changelog](https://github.com/Azure/azure-sdk-for-go/blob/main/documentation/release.md )
- [Commits](https://github.com/Azure/azure-sdk-for-go/compare/v66.0.0...v68.0.0 )
---
updated-dependencies:
- dependency-name: github.com/Azure/azure-sdk-for-go
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-27 03:20:58 +09:00
Sinclair
b91a7b75e2
fix(detector/github): Github dependency graph API request will be retried on error ( #1650 )
...
* fix: Github dependency graph API request will be retried on error
* fix: github dependency graph: error handling
* github dependency graph: fix retry max
2023-04-24 12:46:29 +09:00
Wagde Zabit
333eae06ea
fix order in identifying amazon linux version ( #1652 )
2023-04-21 10:35:19 +09:00
MaineK00n
93d401c70c
chore(integration): update commit ( #1649 )
2023-04-20 14:09:21 +09:00
MaineK00n
99dc8e892f
feat(gost/ubuntu): check kernel source package more strictly ( #1599 )
2023-04-20 13:05:41 +09:00
MaineK00n
fb904f0543
refactor(reporter): refactoring TelegramWriter, GoogleChatWriter ( #1628 )
...
* style: remove unnecessary line break
* style: use regexp.MatchString instead of regexp.Match
* refactor(reporter): refactoring TelegramWriter, GoogleChatWriter
2023-04-20 11:53:31 +09:00
MaineK00n
d4d33fc81d
fix(scanner/dpkg): Fix false-negative in Debian and Ubuntu ( #1646 )
...
* fix(scanner/dpkg): fix dpkg-query and not remove src pkgs
* refactor(gost): remove unnecesary field and fix typo
* refactor(detector/debian): detect using only SrcPackage
2023-04-20 11:42:53 +09:00
Kota Kanbe
a1d3fbf66f
fix(scan): false positives in Debian Pkg for CVE-IDs already detected by Trivy ( #1639 )
...
* fix(scan): false positives in Debian Pkg for CVE-IDs already detected by Trivy
* fix
* Add detectionMethod only when detected by gost
2023-04-17 09:21:30 +09:00
Sinclair
2cdfbe3bb4
fix: dependency graph using small query at once to avoid timeout ( #1642 )
2023-04-14 14:46:31 +09:00
MaineK00n
ac8290119d
fix(configtest): amazon linux 2022, 2023 require dnf-utils ( #1635 )
2023-04-10 10:16:03 +09:00
MaineK00n
abdb081af7
feat(scanner): skip ssh config validation if G option is unknown option ( #1632 )
2023-04-04 18:50:17 +09:00
kurita0
e506125017
feat(wp): support csh, no sudo scan ( #1523 )
...
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2023-03-28 21:07:10 +09:00
MaineK00n
8ccaa8c3ef
fix(scanner/windows): support installationType Domain Controller ( #1627 )
2023-03-28 21:04:17 +09:00
MaineK00n
de1ed8ecaa
feat(ci): add windows for snmp2cpe ( #1626 )
2023-03-28 19:20:03 +09:00
MaineK00n
947d668452
feat(windows): support Windows ( #1581 )
...
* chore(deps): mod update
* fix(scanner): do not attach tty because there is no need to enter ssh password
* feat(windows): support Windows
2023-03-28 19:00:33 +09:00
MaineK00n
db21149f00
feat(contrib): add snmp2cpe ( #1625 )
2023-03-28 18:56:28 +09:00
dependabot[bot]
7f35f4e661
chore(deps): bump github.com/hashicorp/go-getter from 1.6.2 to 1.7.0 ( #1606 )
...
Bumps [github.com/hashicorp/go-getter](https://github.com/hashicorp/go-getter ) from 1.6.2 to 1.7.0.
- [Release notes](https://github.com/hashicorp/go-getter/releases )
- [Changelog](https://github.com/hashicorp/go-getter/blob/main/.goreleaser.yml )
- [Commits](https://github.com/hashicorp/go-getter/compare/v1.6.2...v1.7.0 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/go-getter
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-17 05:04:48 +09:00
MaineK00n
6682232b5c
feat(os): support Amazon Linux 2023 ( #1621 )
2023-03-16 17:31:57 +09:00
sadayuki-matsuno
984debe929
fix(detector/github) change timeout 10s to 10m ( #1616 )
2023-03-01 16:58:11 +09:00
Kota Kanbe
a528362663
fix(saas): upload JSON if err occured during scan ( #1615 )
2023-03-01 14:52:03 +09:00
MaineK00n
ee97d98c39
feat: update EOL ( #1598 )
2023-02-22 16:00:05 +09:00
MaineK00n
4e486dae1d
style: fix typo ( #1592 )
...
* style: fix typo
* style: add comment
2023-02-22 15:59:47 +09:00
MaineK00n
897fef24a3
feat(detector/exploitdb): mod update and add more urls ( #1610 )
2023-02-22 15:58:24 +09:00
MaineK00n
73f0adad95
fix: use GetCveContentTypes instead of NewCveContentType ( #1603 )
2023-02-21 11:56:26 +09:00
Sinclair
704492963c
Revert: gost/Ubuntu.ConvertToModel() is public method now ( #1597 )
2023-02-08 11:36:36 +09:00
Sinclair
1927ed344c
fix(report): tidy dependencies for multiple repo on integration with GSA ( #1593 )
...
* initialize dependencyGraphManifests out of loop
* remove GitHubSecurityAlert.PackageName
* tidy dependency map for multi repo
* set repo name into SBOM components & purl for multi repo
2023-02-07 19:47:32 +09:00
MaineK00n
ad2edbb844
fix(ubuntu): vulnerability detection for kernel package ( #1591 )
...
* fix(ubuntu): vulnerability detection for kernel package
* feat(gost/ubuntu): update mod to treat status: deferred as unfixed
* feat(ubuntu): support 22.10
2023-02-03 15:56:58 +09:00
MaineK00n
bfe0db77b4
feat(cwe): add cwe-id for category and view ( #1578 )
2023-01-20 18:02:07 +09:00
MaineK00n
ff3b9cdc16
fix: add comment ( #1585 )
2023-01-20 18:01:10 +09:00
Sinclair
2deb1b9d32
chore: update version for golangci-lint ( #1586 )
2023-01-20 18:00:54 +09:00
kl-sinclair
ca64d7fc31
feat(report): Include dependencies into scan result and cyclondex for supply chain security on Integration with GitHub Security Alerts ( #1584 )
...
* feat(report): Enhance scan result and cyclondex for supply chain security on Integration with GitHub Security Alerts
* derive ecosystem/version from dependency graph
* fix vars name && fetch manifest info on GSA && arrange ghpkgToPURL structure
* fix miscs
* typo in error message
* fix ecosystem equally to trivy
* miscs
* refactoring
* recursive dependency graph pagination
* change var name && update comments
* omit map type of ghpkgToPURL in signatures
* fix vars name
* goimports
* make fmt
* fix comment
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2023-01-20 15:32:36 +09:00
Brian Prodoehl
554ecc437e
fix(report/email): add Critical to email summary ( #1565 )
...
* Add criticals to email summary
* chore(report/email): add Critical keys
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2022-12-20 11:56:07 +09:00
Kota Kanbe
f6cd4d9223
feat(libscan): support conan.lock C/C++ ( #1572 )
2022-12-20 11:22:36 +09:00
Kota Kanbe
03c59866d4
feat(libscan): support gradle.lockfile ( #1568 )
...
* feat(libscan): support gradle.lockfile
* add gradle.lockfile to integration test
* fix readme
* chore: update integration
* find *gradle.lockfile
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2022-12-20 08:52:45 +09:00
Kota Kanbe
1d97e91341
fix(libscan): delete map that keeps all file contents detected by FindLock to save memory ( #1556 )
...
* fix(libscan): delete Map that keeps all files detected by FindLock to save memory
* continue analyzing libs if err occurred
* FindLockDirs
* fix
* fix
2022-11-10 10:19:15 +09:00
MaineK00n
96333f38c9
chore(ubuntu): set Ubuntu 22.10 EOL ( #1552 )
2022-11-01 14:00:56 +09:00
MaineK00n
8b5d1c8e92
feat(cwe, cti): update dictionary ( #1553 )
...
* feat(cwe): update CWE dictionary
* feat(cti): update CTI dictionary
* fix(cwe): fix typo
2022-11-01 14:00:23 +09:00
MaineK00n
dea80f860c
feat(report): add cyclonedx format ( #1543 )
2022-11-01 13:58:31 +09:00
dependabot[bot]
6eb4c5a5fe
chore(deps): bump github.com/aquasecurity/trivy from 0.31.3 to 0.32.1 ( #1538 )
...
* chore(deps): bump github.com/aquasecurity/trivy from 0.31.3 to 0.32.1
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.31.3 to 0.32.1.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.31.3...v0.32.1 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
* chore(deps): bump github.com/aquasecurity/trivy 0.32.1 to 0.33.0
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2022-10-27 01:24:06 +09:00
Kota Kanbe
b219a8495e
fix(cpescan): match if affected version is NA ( #1548 )
...
https://github.com/vulsio/go-cve-dictionary/pull/283
2022-10-19 16:57:32 +09:00
Kota Kanbe
eb87d5d4e1
fix(saas): panic: runtime error: comparing uncomparable type config.PortScanConf ( #1537 )
2022-10-04 11:55:48 +09:00
tomofumi0003
6963442a5e
fix(report): send report to each slack channel ( #1530 )
...
* fix send report to each slack channel
* fix(report): use w.Cnf.Channel instead of channel
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2022-09-29 16:08:36 +09:00
Kota Kanbe
f7299b9dba
fix(scan): detect AL2 even when empty /etc/redhat-release ( #1536 )
2022-09-29 11:12:30 +09:00
Satoru Nihei
379fc8a1a1
fix: fix query ( #1534 )
2022-09-28 20:51:20 +09:00
MaineK00n
947fbbb29e
fix(ms): always sets isPkgCvesDetactable to true ( #1492 )
2022-09-07 12:05:16 +09:00
MaineK00n
06d2032c9c
docs: update slack invite URL ( #1524 )
2022-09-07 12:04:28 +09:00
dependabot[bot]
d055c48827
chore(deps): bump github.com/aquasecurity/trivy from 0.30.4 to 0.31.3 ( #1526 )
...
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.30.4 to 0.31.3.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.30.4...v0.31.3 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-09-07 12:02:08 +09:00
MaineK00n
2a00339da1
fix(lockfiles): fix privileges in lockfile scan ( #1512 )
...
* fix(lockfiles): fix privileges in lockfile scan
* style(fmt): add space in comment line
2022-09-02 18:18:00 +09:00
kidokidofire
2d959b3af8
Fix func to get EC2 instance ID by IMDSv2. ( #1522 )
...
Co-authored-by: kido3160 <s.kido.fy@future.co.jp >
2022-08-25 14:31:48 +09:00
kidokidofire
595e26db41
Enable to get EC2 instance ID by IMDSv2. ( #1520 )
...
Co-authored-by: kido3160 <s.kido.fy@future.co.jp >
2022-08-24 17:39:45 +09:00
Kota Kanbe
1e457320c5
chore: bump up version ( #1511 )
2022-08-08 16:55:31 +09:00
MaineK00n
a06e689502
feat(cwe): add cwe top25 2022 ( #1504 )
2022-08-04 18:00:45 +09:00
MaineK00n
ca3f6b1dbf
feat(amazon): support Amazon Linux 2 Extra Repository ( #1510 )
...
* feat(amazon): support Amazon Linux 2 Extra Repository
* feat(amazon): set Amazon Linux EOL
* feat(oracle): set Oracle Linux EOL
2022-08-04 17:52:42 +09:00
dependabot[bot]
f1c78e42a2
chore(deps): bump github.com/aquasecurity/trivy from 0.30.3 to 0.30.4 ( #1507 )
...
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.30.3 to 0.30.4.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.30.3...v0.30.4 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-03 09:53:08 +09:00
MaineK00n
2f3b8bf3cc
chore(rocky): set Rocky Linux 9 EOL ( #1495 )
2022-07-27 02:48:10 +09:00
MaineK00n
ab54266f9e
fix(library): fill libraryFixedIns{}.key in ftypes.Pnpm and ftypes.DotNetCore ( #1498 )
...
* fix(library): fill key in ftypes.Pnpm and ftypes.DotNetCore
* chore(library): change the data structure of LibraryMap
2022-07-26 13:53:50 +09:00
dependabot[bot]
d79d138440
chore(deps): bump github.com/aquasecurity/trivy from 0.30.2 to 0.30.3 ( #1499 )
...
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.30.2 to 0.30.3.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.30.2...v0.30.3 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-07-26 04:52:32 +09:00
dependabot[bot]
139f3a81b6
chore(deps): bump github.com/aquasecurity/trivy from 0.27.1 to 0.30.0 ( #1494 )
...
* chore(deps): bump github.com/aquasecurity/trivy from 0.27.1 to 0.30.0
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.27.1 to 0.30.0.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.27.1...v0.30.0 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
* chore(deps): bump github.com/aquasecurity/trivy from 0.30.0 to 0.30.2
* fix(library): change fanal to trivy/pkg/fanal
* chore: update integration
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2022-07-25 16:47:57 +09:00
MaineK00n
d1a617cfff
fix(ms): remove duplicate advisories ( #1490 )
2022-07-14 09:26:30 +09:00
MaineK00n
48f7597bcf
feat(ms): import gost:MaineK00n/new-windows ( #1481 )
...
* feat(ms): import gost:MaineK00n/new-windows
* chore(discover): add CTI section
* feat(ms): fill KB with VulnInfo.DistroAdvisories instead of CveContent.Optional
* fix(ms): Change bitSize from 32 to 64
* fix(ms): delete KB prefix
* chore(ms): change logger
* fix(ms): fill in correct AdvisoryID
Co-authored-by: Sadayuki Matsuno <sadayuki.matsuno@gmail.com >
2022-07-04 14:26:41 +09:00
sadayuki-matsuno
93731311a1
feat(saas) add vuls tags from env ( #1487 )
2022-07-04 12:00:02 +09:00
MaineK00n
999529a05b
feat(scanner): detect host key change ( #1406 )
...
* feat(scanner): detect host key change
* chore(scanner): add testcase
2022-07-04 10:57:43 +09:00
MaineK00n
847d820af7
feat(os): support Alpine Linux 3.16 ( #1479 )
2022-06-15 17:08:40 +09:00
MaineK00n
5234306ded
feat(cti): add Cyber Threat Intelligence info ( #1442 )
...
* feat(cti): add Cyber Threat Intelligence info
* chore: replace io/ioutil as it is deprecated
* chore: remove --format-csv in stdout writer
* chore(deps): go get go-cti@v0.0.1
* feat(cti): update cti dict(support MITRE ATT&CK v11.1)
* chore(deps): go get go-cti@master
2022-06-15 17:08:12 +09:00
MaineK00n
86b60e1478
feat(config): support CIDR ( #1415 )
2022-06-10 18:24:25 +09:00
MaineK00n
42fdc08933
feat(os): support RHEL 9, CentOS Stream 9, Alma Linux 9 ( #1465 )
...
* feat(os): support RHEL 9
* feat(os): support CentOS Stream9, AlmaLinux 9
2022-06-09 06:39:16 +09:00
MaineK00n
38b1d622f6
feat(cwe): update CWE dictionary ( #1443 )
2022-06-09 06:36:54 +09:00
MaineK00n
2477f9a8f8
chore: tidy go.mod, add arm64 and workflows update ( #1461 )
...
* chore: tidy go.mod
* chore(gh): add arm64 and workflows update
* chore: disable staticcheck SA1019 for xerrors.Errorf
* chore: fix github.com/boltdb/bolt switch to github.com/etcd-io/bbolt? #1457
2022-06-09 06:10:07 +09:00
kurita0
ec6e90acd3
fix getting wp core version string via ssh ( #1344 )
...
* fix getting wp core version string via ssh
* check DocRoot
2022-06-09 06:05:15 +09:00
sadayuki-matsuno
2aca2e4352
feat(contrib/trivy) fill image info into scan results ( #1475 )
...
* feat(contrib/trivy) fill image info into scan results
* fix match size
* fix match size
2022-06-08 17:00:32 +09:00
sadayuki-matsuno
14518d925e
fix(contriv/fvuls) initialize optional map ( #1469 )
2022-05-30 12:46:53 +09:00
sadayuki-matsuno
948f8c0751
add VULS_TAGS env into contiriv future-vuls ( #1466 )
2022-05-24 13:46:28 +09:00
sadayuki-matsuno
1c1e40058e
feat(library) output library type when err ( #1460 )
2022-05-16 09:58:58 +09:00
Satoru Nihei
2158fc6cb1
fix: judge by scannedVia ( #1456 )
2022-05-06 09:38:38 +09:00
MaineK00n
91ed318c5d
chore(deps): update trivy v0.27.1 ( #1453 )
...
* chore(deps): update trivy v0.27.1
* chore: add gosum
2022-04-27 15:43:23 +09:00
MaineK00n
bfc3828ce1
chore(deps): update goval-dictionary and gost ( #1452 )
2022-04-27 13:03:11 +09:00
dependabot[bot]
c7eac4e7fe
chore(deps): bump github.com/aquasecurity/trivy from 0.25.4 to 0.27.0 ( #1451 )
...
* chore(deps): bump github.com/aquasecurity/trivy from 0.25.4 to 0.27.0
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.25.4 to 0.27.0.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.25.4...v0.27.0 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
* fix(library): support go.mod scan
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2022-04-27 12:46:47 +09:00
MaineK00n
cc63a0eccf
feat(ubuntu): add Jammy Jellyfish(22.04) ( #1431 )
...
* feat(ubuntu): add Jammy Jellyfish(22.04)
* chore(deps): gost update
* chore(oval/ubuntu): fill kernel package name temporarily
2022-04-27 11:04:00 +09:00
Satoru Nihei
fd18df1dd4
feat: parse OS version from result of trivy-scan ( #1444 )
...
* chore(deps): bump github.com/aquasecurity/trivy from 0.24.2 to 0.25.4
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.24.2 to 0.25.4.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.24.2...v0.25.4 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
* test: add testcase
* feat: parse metadata
* refactor: change detect logic
* refactor: change parsing logic
* refactor: refactor check logic before detect
* fix: impl without reuseScannedCves
* feat: complement :latest tag
* Update contrib/trivy/parser/v2/parser.go
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2022-04-27 10:28:20 +09:00
MaineK00n
8775b5efdf
chore: fix lint error ( #1438 )
...
* chore: fix lint: revive error
* chore: golanci-lint uses go 1.18
* chore: refactor tasks in GNUmakefile
* chore: add trivy binary in fvuls image
2022-04-15 18:12:13 +09:00
dependabot[bot]
a9f29a6c5d
chore(deps): bump github.com/aquasecurity/trivy from 0.24.2 to 0.25.1 ( #1436 )
...
* chore(deps): bump github.com/aquasecurity/trivy from 0.24.2 to 0.25.0
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.24.2 to 0.25.0.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.24.2...v0.25.0 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
* chore(deps): bump up Go to 1.18 and trivy v0.25.1
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2022-04-05 13:27:49 +09:00
Satoru Nihei
05fdde48f9
feat: support server scan for suse with text/plain ( #1433 )
2022-04-04 12:45:44 +09:00
MaineK00n
3dfbd6b616
chore(mod): update go-exploitdb module ( #1428 )
...
* chore(mod): update go-exploitdb module
* docs: add inthewild datasource
* Unique because URLs sometimes duplicate on GitHub and InTheWild
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2022-03-26 05:26:06 +09:00
MaineK00n
04f246cf8b
chore: add fvuls image ( #1426 )
2022-03-25 06:17:33 +09:00
MaineK00n
7500f41655
chore(mod): update go-kev module ( #1425 )
2022-03-25 06:15:06 +09:00
MaineK00n
a1cc152e81
feat(library): add auto detect library ( #1417 )
2022-03-17 18:08:40 +09:00
Masato Yagi
1c77bc1ba3
feat: replace NVD-column with packages-column at output of report ( #1414 )
...
* replace NVD-col with packages-col
* fix typo
* set table row line
2022-03-17 17:14:41 +09:00
Satoru Nihei
ec31c54caf
chore: update trivy from 0.23.0 to 0.24.02 ( #1407 )
...
* chore: update trivy from 0.23.0 to 0.24.2
* chore: deal with changing structs
see: 11f4f81123
2022-03-04 16:00:08 +09:00
Satoru Nihei
2f05864813
fix: handling when image contains no trivy-target ( #1405 )
...
* fix: handling when image contains no trivy-target
* refactor: use scanResult.Optional
* fix: add suppoted list to error message
2022-03-02 06:13:26 +09:00
Kota Kanbe
2fbc0a001e
fix: nil pointer when no match for any OS ( #1401 )
...
* refactor: rename serverapi.go to scanner.go
* fix: nil pointer if no match for any OS
2022-02-24 07:58:29 +09:00
MaineK00n
7d8a24ee1a
refactor(detector): standardize db.NewDB to db.CloseDB ( #1380 )
...
* feat(subcmds/report,server): read environment variables when configPath is ""
* refactor: standardize db.NewDB to db.CloseDB
* chore: clean up import
* chore: error wrap
* chore: update goval-dictionary
* fix(oval): return Pseudo instead of nil for client
* chore: fix comment
* fix: lint error
2022-02-19 09:20:45 +09:00
MaineK00n
7750347010
fix(oval/suse): use def.Advisory.Cves[0].CveID instead of def.Title ( #1397 )
2022-02-17 19:16:14 +09:00
MaineK00n
9bcffcd721
fix(configtest,scan): fix validateSSHConfig ( #1395 )
...
* fix(configtest,scan): support StrictHostKeyChecking no
* fix(configtest,scan): support ServerTypePseudo
* fix(configtest,scan): skip if using proxy
2022-02-17 08:15:23 +09:00
MaineK00n
787604de6a
fix(suse): fix openSUSE, openSUSE Leap, SLES, SLED scan ( #1384 )
...
* fix(suse): fix openSUSE, openSUSE Leap scan
* docs: update README
* fix: unknown CveContent.Type
* fix: tui reporting
* fix: listening port was duplicated in format-full-text
* fix .gitignore
* fix: add EOL data for SLES12.5
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2022-02-15 17:11:54 +09:00
MaineK00n
5164fb1423
fix(util): Major() behavior for major version ( #1393 )
2022-02-15 07:59:29 +09:00
MaineK00n
07335617d3
fix(configtest,scan): support SSH config file ( #1388 )
...
* fix(configtest,scan): support SSH config file
* chore(subcmds): remove askKeyPassword flag
2022-02-12 21:50:56 +09:00
MaineK00n
e5855922c1
fix(redhat): detect RedHat version ( #1387 )
...
* fix(redhat): detect RedHat version
* fix err fmt string
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2022-02-12 20:09:51 +09:00
MaineK00n
671be3f2f7
feat(configtest,scan): detect known_hosts error ( #1386 )
2022-02-11 12:54:17 +09:00
MaineK00n
fe8d252c51
feat(debian): validate running kernel version ( #1382 )
...
* feat(debian): validate running kernel version
* chore(gost/debian): only stash when there is linux package
2022-02-11 12:36:48 +09:00
MaineK00n
0cdc7a3af5
chore(oval): update mod ( #1385 )
2022-02-09 10:20:07 +09:00
maito1201
1cfe155a3a
feat(fedora): support fedora ( #1367 )
...
* feat(fedora): support fedora
* fix(fedora): fix modular package scan
* fix(fedora): check needs-restarting, oval arch, add source link
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2022-02-09 09:30:44 +09:00
MaineK00n
2923cbc645
fix(centos): identify CentOS and CentOS Stream ( #1360 )
2022-02-03 05:32:03 +09:00
MaineK00n
7c209cc9dc
fix(gost): add nil check ( #1379 )
2022-02-03 05:25:11 +09:00
MaineK00n
84fa4ce432
feat(alpine): add Alpine 3.14, 3.15 EOL ( #1359 )
...
* feat(alpine): add Alpine 3.14, 3.15 EOL
* fix(alpine): change test case
2022-02-02 06:46:52 +09:00
MaineK00n
f2e9cd9668
fix(oval): fix query in PostgreSQL ( #1372 )
...
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2022-02-02 06:46:02 +09:00
Kota Kanbe
77049d6cbb
feat(libscan): support trivy v0.23.0 ( #1377 )
...
* feat(libscan): support trivy v0.23.0
* fix lint err
* review
2022-02-01 10:40:16 +09:00
sadayuki-matsuno
b4c23c158b
fix(scanner/base) export libFile fields ( #1366 )
2022-01-18 11:56:12 +09:00
sadayuki-matsuno
964b4aa389
fix(scanner/base) export libFile ( #1365 )
2022-01-18 11:31:36 +09:00
Kota Kanbe
dc5aa35db7
chore: update git submodule for integration test ( #1364 )
2022-01-18 10:22:00 +09:00
dependabot[bot]
43c05d06fc
chore(deps): bump github.com/aquasecurity/trivy from 0.20.0 to 0.22.0 ( #1350 )
...
* chore(deps): bump github.com/aquasecurity/trivy from 0.20.0 to 0.22.0
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy ) from 0.20.0 to 0.22.0.
- [Release notes](https://github.com/aquasecurity/trivy/releases )
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml )
- [Commits](https://github.com/aquasecurity/trivy/compare/v0.20.0...v0.22.0 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
* fix(library): trivy scan
* chore(integration): add lockfiles
* fix(library): support gobinary scan via trivy
* chore: add pom in IsTrivySupportedLib
* chore: fix LIBS
* fix(library): support trivy offline scan
* chore(integration): move vulsio/integration repository
* chore(integration): add integration as git submodule
* chore: update .gitignore
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2022-01-18 08:27:11 +09:00
Kota Kanbe
a3f7d1d7e7
feat(go-kev): update go-kev deps ( #1352 )
2022-01-07 08:21:48 +09:00
Kota Kanbe
bb4a1ca6c2
GPLv3 ( #1351 )
2021-12-26 09:08:38 +09:00
Kota Kanbe
57cce640e1
Create SECURITY.md
2021-12-26 08:51:44 +09:00
kurita0
1eb5d36668
fix configtest stalled with scanMode=fast-root ( #1339 )
...
* fix configtest stalled with scanMode=fast-root
* repoquery does not require sudo privileges on centos
2021-12-26 08:31:11 +09:00
MaineK00n
6bc4850596
fix(detector/ospkg): Skip OVAL/gost search when the number of packages is 0 ( #1343 )
...
* fix(detector/ospkg): Skip OVAL/gost search when the number of packages is 0
* chore: easy refactoring
2021-12-26 07:53:18 +09:00
MaineK00n
24005ae7ae
chore(GHActions): replace with dependabot ( #1348 )
...
* chore(GHActions): replace with dependabot
* chore(GHActions): remove tidy.yml due to deprecation
2021-12-26 07:48:11 +09:00
MaineK00n
7aa296bb57
fix(oval): fix RDB query ( #1347 )
2021-12-26 07:47:52 +09:00
Kota Kanbe
3829ed2f8e
Fix the parsing logic of FreeBSD pkg-audit ( #1334 )
...
* fix scanUnsecurePackages for FreeBSD pkg audit output change
* Add test case TestParseBlock for FreeBSD pkg audit output change
* Fix for no CVE in a block
* fix(scan): parse logic of pkg-audit
* fix
ca761fb218
Co-authored-by: User Kurita <kurita@vuls0.digitiminimi.com >
2021-12-24 10:27:38 +09:00
MaineK00n
2b7294a504
feat(amazon): support amazon linux 2022 ( #1338 )
2021-12-09 11:06:44 +09:00
MaineK00n
0c6a892893
style: fix lint ( #1335 )
2021-11-19 15:46:51 +09:00
MaineK00n
89d94ad85a
feat(detector): add known exploited vulnerabilities ( #1331 )
...
* feat(kevuln): add known exploited vulnerabilities
* chore: transfer repository owner
* feat: show CISA on top of CERT
* chore: rename var
* chore: rename var
* chore: fix review
* chore: fix message
2021-11-19 15:06:17 +09:00
sadayuki-matsuno
ffdb78962f
update dictionaries ( #1326 )
2021-10-29 11:24:49 +09:00
Kota Kanbe
321dae37ce
chore: update readme
2021-10-24 17:38:57 +09:00
Kota Kanbe
a31797af0b
Merge branch 'sakura'
2021-10-24 17:33:48 +09:00
Kota Kanbe
32999cf432
chore: udpate readme
2021-10-24 17:32:35 +09:00
Kota Kanbe
88218f5d92
chore: update sponsor ( #1325 )
2021-10-24 17:25:03 +09:00
Kota Kanbe
15761933ac
chore: update sponsor
2021-10-24 17:01:35 +09:00
Kota Kanbe
0b62842f0e
chore: fix go-sqlite3 deps ( #1324 )
2021-10-20 12:33:59 +09:00
Kota Kanbe
6bceddeeda
chore: update goval-dictionary ( #1323 )
...
* chore: update goval-dictionary
* fix errs
2021-10-20 11:10:33 +09:00
Kota Kanbe
2dcbff8cd5
chore: sponsor ( #1321 )
...
* fix readme
* chore: fix lint
2021-10-17 16:41:51 +09:00
Kota Kanbe
8659668177
fix(cpescan): bug in NvdVendorProductMatch ( #1320 )
...
* fix(cpescan): bug in NvdVendorProductMatch
* update go mod
2021-10-13 12:55:01 +09:00
Kota Kanbe
e07b6a9160
feat(report): show Amazon ALAS link to report ( #1318 )
2021-10-12 09:09:58 +09:00
Kota Kanbe
aac5ef1438
feat: update-trivy ( #1316 )
...
* feat: update-trivy
* add v2 parser
* implement v2
* refactor
* feat: add show version to future-vuls
* add test case for v2
* trivy v0.20.0
* support --list-all-pkgs
* fix lint err
* add test case for jar
* add a test case for gemspec in container
* remove v1 parser and change Library struct
* Changed the field name in the model struct LibraryScanner
* add comment
* fix comment
* fix comment
* chore
* add struct tag
2021-10-08 17:22:06 +09:00
sadayuki-matsuno
d780a73297
add log json option ( #1317 )
2021-10-07 16:00:01 +09:00
Kota Kanbe
9ef8cee36e
refactor(exploitdb): use pipeline effectively ( #1314 )
...
https://github.com/vulsio/go-exploitdb/pull/64
2021-10-01 09:10:49 +09:00
Kota Kanbe
77808a2c05
feat(go-cve): add error handling ( #1313 )
2021-09-30 12:42:43 +09:00
MaineK00n
177e553d12
feat(go-exploitdb): add error handling ( #1310 )
...
* feat(go-exploitdb): add error handling
* chore: rename
* go get -u go-exploitdb
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2021-09-30 11:33:18 +09:00
MaineK00n
40f8272a28
feat(go-msfdb): add error handling and support http mode ( #1308 )
...
* feat(go-msfdb): add error handling
* feat(go-msfdb): support http mode
* go get -u go-msfdb
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2021-09-30 11:16:41 +09:00
MaineK00n
a7eb1141ae
feat(gost): add error handling ( #1311 )
...
* feat(gost): add error handling
* go get -u gost
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2021-09-30 10:51:41 +09:00
Kota Kanbe
c73ed7f32f
chore: update find-lock file type ( #1309 )
2021-09-24 16:23:23 +09:00
Kota Kanbe
f047a6fe0c
breaking-change: Update vuls-dictionaries ( #1307 )
...
* chore: udpate dictionaries
* update gost
* chore: update gost
* chore(go-cve-dict): use v0.8.1
* chore: change linter from golint to revive
* chore(linter): set revive config
* chore: fix commands and update golangci-lint version
* fix: lint errs
* chore: update gost
Co-authored-by: MaineK00n <mainek00n.1229@gmail.com >
2021-09-21 05:10:29 +09:00
MaineK00n
7f15a86d6a
chore: change repository owner ( #1306 )
2021-09-16 11:05:37 +09:00
Kota Kanbe
da1e515253
breaking-change(goval): change-redis-architecture ( #1305 )
...
https://github.com/kotakanbe/goval-dictionary/pull/145
2021-09-15 08:25:14 +09:00
MaineK00n
591786fde6
feat(oval): support new goval-dictionary model ( #1280 )
...
* feat(oval): support new goval-dictionary model
* chore: fix lint err
* chore: set len of slice to 0
* fix(oval): avoid contamination of AffectedPackages by writing directly to defPacks
* fix(oval): avoid contamination of AffectedPackages by writing directly to defPacks
* feat(report): do not add duplicate CveContent
* chore: goval-dictionary update
* chore: go mod tidy
* fix(oval): preload Advisory.Cves for Ubuntu
https://github.com/kotakanbe/goval-dictionary/pull/152
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2021-09-13 10:19:59 +09:00
Kota Kanbe
47e6ea249d
chore: fix lint warning ( #1301 )
2021-09-12 20:35:56 +09:00
Kota Kanbe
4a72295de7
feat(saas): support for library-only scanning ( #1300 )
2021-09-10 15:38:35 +09:00
MaineK00n
9ed5f2cac5
feat(debian): support Debian 11(bullseye) ( #1298 )
...
* feat(debian): support bullseye
* fix(debian): fix test case
2021-09-08 10:47:34 +09:00
Kota Kanbe
3e67f04fe4
breaking-change(cpescan): Improve Cpe scan ( #1290 )
...
* chore(cpescan): enable to pass useJvn to detector.DetectCpeURIsCves()
* review comment
* chore: go mod update go-cve
* feat(cpescan): set JvnVendorProductMatch to confidence If detected by JVN
* add NvdExactVersionMatch andd NvdRoughVersionMatch
* add confidence-over option to report
* sort CveContetens
* fix integration-test
2021-09-07 16:18:59 +09:00
Kota Kanbe
b9416ae062
fix(report): too many SQL variables ( #1296 )
...
* fix(report): too many SQL variables
https://github.com/kotakanbe/go-cve-dictionary/pull/210
* fix lint err
2021-09-01 10:42:19 +09:00
otuki
b4e49e093e
feat(GAdocker): Publish docker image with Github Actions ( #1291 )
...
* feat(GAdocker): publish docker image with Github Actions
* feat(master): publish Docker image with GHActions:
* feat(docker): publish docker image with GHAtions
* feat(master): remove unnecessary GHActions
* feat(master): remove unnecessary GHActions
* feat(master): Add user ID and password at Docker GHActions
* feat(master): Add user ID and password with docker/login
2021-09-01 08:44:55 +09:00
Kota Kanbe
020f6ac609
fix(scan): warning if err occurred while scanning ports ( #1294 )
...
[Aug 26 20:59:11] ERROR [localhost] Error on host, err: [Failed to scan Ports:
github.com/future-architect/vuls/scanner.Scanner.getScanResults.func1
/go/src/github.com/future-architect/vuls/scanner/serverapi.go:658
- dial tcp 172.19.0.1:80: connect: no route to host]
Scan Summary
================
host Error Use configtest subcommand or scan with --debug to view the details
[Aug 26 20:59:11] ERROR [localhost] Failed to scan: Failed to scan. err:
github.com/future-architect/vuls/scanner.Scanner.Scan
/go/src/github.com/future-architect/vuls/scanner/serverapi.go:103
- An error occurred on [host]
2021-08-27 06:20:50 +09:00
sadayuki-matsuno
7e71cbdd46
fix(gost) sort in ms converter ( #1293 )
2021-08-26 14:32:45 +09:00
Kota Kanbe
1003f62212
chore: update go-cve-dictionary ( #1292 )
2021-08-26 13:45:40 +09:00
Kota Kanbe
9b18e1f9f0
breaking-change(go-exploitdb): support new go-exploitdb ( #1288 )
2021-08-20 08:00:57 +09:00
Kota Kanbe
24f790f474
feat(go-cve): update go-cve-dictionary ( #1287 )
...
diff: a31a3152c1...5043255
2021-08-19 05:34:03 +09:00
MaineK00n
fb8749fc5e
fix(cpescan): fix confidence in cpe uri scan ( #1286 )
...
* fix(cpescan): fix confidence in cpe uri scan
* feat(cpe): add NA case
* chore: use HasNvd, HasJvn instead of len
* chore: go-cve-dictionary update
2021-08-19 04:59:09 +09:00
MaineK00n
96c3592db1
breaking-change(go-cve-dict): support new go-cve-dictionary ( #1277 )
...
* feat(model): change CveContents(map[string]CveContent) to map[string][]CveContent
* fix(cpescan): use CveIDSource
* chore: check Nvd, Jvn data
* chore: go-cve-dictionary update
* chore: add to cveDetails as is, since CveID is embedded in the response
2021-08-13 18:00:55 +09:00
Kota Kanbe
d65421cf46
fix(cpescan): JVN scan False-Negative on RDB-backend ( #1283 )
...
https://github.com/kotakanbe/go-cve-dictionary/pull/199
2021-08-13 09:58:04 +09:00
Kota Kanbe
c52ba448cd
chore: update readme ( #1282 )
2021-08-12 09:37:45 +09:00
Kota Kanbe
21adce463b
update readme
2021-08-12 09:31:12 +09:00
MaineK00n
f24240bf90
feat(library): update trivy v0.19.2 ( #1278 )
2021-08-02 05:40:57 +09:00
kazuminn
ff83cadd6e
feat(os) : support Alma Linux ( #1261 )
...
* support Alma Linux
* fix miss
* feat(os) : support Rocky linux (#1260 )
* support rocky linux scan
* fix miss
* lint
* fix : like #1266 and error Failed to parse CentOS
* pass make test
* fix miss
* fix pointed out with comment
* fix golangci-lint error
2021-08-02 04:36:43 +09:00
Phil
e8c09282d9
Update ubuntu.go ( #1279 )
...
URI correction for ubuntu; see gost project: https://github.com/knqyf263/gost/blob/master/server/server.go#L48
2021-08-02 04:25:51 +09:00
Kota Kanbe
5f4d68cde4
feat(go-msf): update deps ( #1275 )
...
https://github.com/takuzoo3868/go-msfdb/pull/22
2021-07-21 09:13:34 +09:00
Kota Kanbe
9077a83ea8
fix(docker): docker build error ( #1274 )
2021-07-20 05:31:05 +09:00
Kota Kanbe
543dc99ecd
fix(cpescan): CpeVendorProductMatch not set when Redis Backend ( #1273 )
...
* fix(cpescan): CpeVendorProductMatch not set when Redis Backend
* fix(integration): deprecated CPE URI
* fix(integration-test): add a test case for CpeVendorProductMatch
* fix review
* update deps go-cve-dict v0.6.2
2021-07-19 08:43:58 +09:00
Kota Kanbe
f0b3a8b1db
feat(cpescan): Use JVN as a second DB for CPE scan ( #1268 )
...
* feat(cpescan): Use JVN as a second DB for CPE scan
* feat(tui): display score of detectionmethod
* update go.mod
2021-07-08 12:39:46 +09:00
Norihiro NAKAOKA
0b9ec05181
Support scanning Ubuntu using Gost ( #1243 )
...
* chore: add vuls binary in gitignore
* feat(gost): support ubuntu
* chore(debian): fix typo
* feat(ubuntu): more detail on CveContent
* chore: update .gitignore
* chore: update gost deps
* feat(ubuntu): add test in gost/ubuntu
* chore: fix typo
* Revert "chore: fix typo"
This reverts commit 9f2f1db233 .
* docs: update README
2021-07-08 08:31:46 +09:00
Norihiro NAKAOKA
0bf12412d6
fix(rocky): fix Scan in Rocky Linux ( #1266 )
...
* fix(rocky): fix OVAL scan in Rocky Linux
* chore: add FreeBSD13 EOL, fix #1245
* chore(rocky): add Rocky Linux EOL tests
* feat(rocky): implement with reference to CentOS
* feat(raspbian): add Raspbian to Server mode
* feat(rocky): support gost scan
* fix(rocky): rocky support lessThan
* chore: update doc and comment
2021-07-08 05:39:48 +09:00
Peter Sedgewick
0ea4d58c63
fix(gost): Use DBDriver ctx in Psuedo ( #1264 )
2021-07-02 06:18:44 +09:00
kazuminn
5755b00576
feat(os) : support Rocky linux ( #1260 )
...
* support rocky linux scan
* fix miss
* lint
2021-07-02 05:35:47 +09:00
Shigechika AIKAWA
1c8e074c9d
Feat report googlechat ( #1257 ) ( #1258 )
...
* feat: Support Ubuntu21
* feat(report): Send report via Google Chat
* feat(report): Send report via Google Chat
* Snip too long message as (The rest is omitted).
* sorry for mixed feat-ubuntu21 branch. exlucded it
* append diff, attack vector and exploits info
* add ServerName filter by regexp
* rename variables and rewrite validators
* fix renaming miss
* fix renaming miss, again
2021-07-02 05:32:00 +09:00
Shigechika AIKAWA
0e0e5ce4be
feat: Support Ubuntu21 ( #1231 )
2021-06-28 10:28:54 +09:00
Kota Kanbe
23dfe53885
chore: update go-exploitdb ( #1262 )
2021-06-28 08:29:16 +09:00
Norihiro NAKAOKA
8e6351a9e4
feat(oval): goval-dictionary update ( #1259 )
...
* feat(oval): err check for GetLastModified
* feat(oval): goval-dictionary update
2021-06-25 14:08:50 +09:00
Shigechika AIKAWA
3086e2760f
fix Ubuntu 20.10 End of Life on July 22 2021 ( #1256 )
2021-06-23 08:14:38 +09:00
Norihiro NAKAOKA
b8db2e0b74
feat(report): Change the priority of CVE information in Debian ( #1202 )
...
* fix (bug) : using ScanResults refs #1019
* feat(gost): WIP change priority of CVE Info in Debian
* feat(report): change priority of CVE Info in Debian
* refactor: move RemoveRaspbianPackFromResult
* style: remove comment
* fix: lint error
* style: change coding style
* feat(report): support reporting with gost alone
* fix: merge error
* refactor(debian): change code to be simple
2021-06-21 15:14:41 +09:00
Kota Kanbe
43b46cb324
chore: add test data for integration test ( #1254 )
2021-06-17 14:01:10 +09:00
Kota Kanbe
d0559c7719
chore: update gost deps ( #1253 )
2021-06-16 18:45:48 +09:00
Kota Kanbe
231c63cf62
fix(libscan): support empty LibraryFixedIn ( #1252 )
2021-06-16 13:28:12 +09:00
Kota Kanbe
2a9aebe059
fix(report): improve cpe match logic ( #1251 )
...
* fix(report): improve cpe match logic
https://github.com/kotakanbe/go-cve-dictionary/pull/189
* fix vet error
2021-06-11 14:39:41 +09:00
Kota Kanbe
4e535d792f
chore: fix build-tags in .goreleaser.yml ( #1250 )
2021-06-09 09:49:26 +09:00
Kota Kanbe
4b487503d4
chore: add go.sum test data for integration test ( #1249 )
...
* add go.sum test data for integration test
* chore: .gitignore
2021-06-09 09:18:32 +09:00
Kota Kanbe
0095c40e69
fix(vet): go vet err of make build-scanner ( #1248 )
2021-06-09 08:00:52 +09:00
Kota Kanbe
82c1abfd3a
fix(report): detection logic bugs for Oracle Linux ( #1247 )
...
* fix(report): continue detecting if arch is emtpy for Oracle Linux
* fix test case
* fix(report): a bug of `Not Fixed Yet` of Oracle linux scanning
2021-06-09 05:46:42 +09:00
sadayuki-matsuno
40988401bd
feat(scanner) separate func analize libraries ( #1246 )
...
* feat(scanner) separate func analize libraries
* fix(scanner) fix typo
2021-06-04 07:42:29 +09:00
Kota Kanbe
e8e3f4d138
feat(lib): support of Go (go.sum) scan ( #1244 )
...
* chore: update trivy deps
* fix(test): fix sort order in json
* parse go.sum in scanning
* feat(lib): support go.sum
2021-06-03 11:31:37 +09:00
Norihiro NAKAOKA
7eb77f5b51
feat(scan): support external port scanner(nmap) in host machine ( #1207 )
...
* feat(scan): load portscan settings from config.toml
* feat(scan): support external port scanner:nmap
* style: rename variable
* feat(scan): logging apply options
* feat(scan): remove spoof ip address option
* feat(scan): more validate port scan config
* style: change comment
* fix: parse port number as uint16
* feat(discover): add portscan section
* feat(discover): change default scanTechniques
* feat(docker): add nmap and version update
* feat(scan): nmap module upgrade
* fix: wrap err using %w
* feat(scan): print cmd using external port scanner
* feat(scan): more details external port scan command
* feat(scan): add capability check in validation
* fix(scanner): format error
* chore: change format
2021-05-26 09:35:28 +09:00
Kota Kanbe
e115235299
fix(test): dev mode to false in package-lock.json ( #1242 )
...
* fix(test): dev mode to false in package-lock.json
* fix: vet warning
2021-05-17 08:04:16 +09:00
otuki
151d4b2d30
fix(scan): Avoid panic when SSH connection refused ( #1236 )
...
* fix(fix-ssh-fata): Avoid panic when SSH connection refused
* chore(fix-ssh-fata): fix typo
2021-05-12 18:30:26 +09:00
Kota Kanbe
e553f8b4c5
feat(trivy): go mod update trivy v0.17.2 ( #1235 )
...
* feat(trivy): go mod update trivy v0.17.2
* wg.Wait
* fix reporting
* fix test case
* add gemfile.lock of redmine to integration test
* fix(test): add Pipfile.lock
* add poetry.lock to integration test
* add composer.lock to integration test
* add integration test case
2021-05-12 18:27:55 +09:00
Kota Kanbe
47652ef0fb
fix(report): include the num of criticals in total #1233 ( #1234 )
2021-05-07 07:57:33 +09:00
Kota Kanbe
ab0e950800
fix(oracle): extracting only advisory ID from OVAL.title ( #1232 )
2021-04-29 12:54:36 +09:00
otuki
a7b0ce1c85
refactor(git-conf): config template in github section changed ( #1229 )
2021-04-28 14:53:11 +09:00
otuki
dc9c0edece
refactor(git-conf): Specifing ignoreGitHubDismissed per repository ( #1224 )
...
* refactor(git-conf): Specifing ignoreGitHubDismissed per repository with config.toml
* refactor(git-conf): change json tag into camelCase
* refactor(git-conf): change first char of json tag into lowercase
2021-04-28 13:41:38 +09:00
Kota Kanbe
17ae386d1e
chore: add a test case #1227 ( #1228 )
2021-04-28 12:18:18 +09:00
Kota Kanbe
2d369d0cfe
Fix false positive for Oracle Linux ( #1227 )
...
* fix(oracle): false-positive(handle arch of pkgs)
* fix(oracle): false positive kernel-related CVEs
* add a test case for ksplice1
* fix(scan): handle uek kernel for Oracle linux
* fix(scan): hanlde uek kernel for reboot required
* fix(oracle): false-positive for redis-backend
2021-04-27 20:38:45 +09:00
Kota Kanbe
c36e645d9b
fix(report): false positive for kernel-related CVE for RedHat, CentOS, Oracle and Amazon #1199 ( #1223 )
2021-04-23 08:59:46 +09:00
Kota Kanbe
40039c07e2
fix(report): panic when closing db connection of gost ( #1222 )
2021-04-23 06:14:12 +09:00
Kota Kanbe
a692cec0ef
fix(gost): close gost DB connection in server mode #1217 ( #1221 )
2021-04-21 11:59:11 +09:00
otuki
e7ca491a94
fix(report): Avoid http reports error ( #1216 )
2021-04-21 10:00:58 +09:00
Shigechika AIKAWA
23f3e2fc11
fix(config): add Ubuntu 20.10 ( #1218 )
2021-04-21 09:05:33 +09:00
Kota Kanbe
27b3e17b79
feat(saas): delete json dir automatically after upload ( #1212 )
...
* feat(saas): delete json dir automatically after upload
* fix lint err
2021-04-15 05:58:41 +09:00
Kota Kanbe
740781af56
feat(logging): add -log-to-file and don't output to file by default ( #1209 )
...
* feat(logging): add -log-to-file and don't output to file by default
* update go-cve-dict
* fix lint err
2021-04-05 17:41:07 +09:00
Kota Kanbe
36c9c229b8
fix(report): avoid nil pointer when report FreeBSD ( #1208 )
2021-04-05 12:54:27 +09:00
Norihiro NAKAOKA
183fdcbdef
fix: support for missing files in the results or results directory ( #1206 )
...
* fix: support for missing files in the results or results directory
* fix: support for missing files in the results or results directory
2021-04-05 07:28:20 +09:00
Kota Kanbe
a2a697900a
refactor: move const to constant pkg ( #1205 )
2021-04-02 15:33:02 +09:00
Kota Kanbe
6fef4db8a0
fix .goreleaser.yml ( #1204 )
...
* fix .goreleaser.yml
* chore: fix lint warnings
2021-04-01 17:43:54 +09:00
sadayuki-matsuno
e879ff1e9e
feat(scanner) export pkg list scan method ( #1203 )
...
* feat(scanner) export pkg list scan method
* fix args
* fix func
* fix init debian
2021-04-01 17:38:20 +09:00
Kota Kanbe
9bfe0627ae
refactor: don't use global Config in private func ( #1197 )
...
* refactor: cve_client.go
* refactor: don't use global Config in private func
* remove import alias for config
* refactor: dbclient
* refactor: resultDir
* refactor: resultsDir
* refactor
* refactor: gost
* refactor: db client
* refactor: cveDB
* refactor: cvedb
* refactor: exploitDB
* refactor: remove detector/dbclient.go
* refactor: writer
* refactor: syslog writer
* refactor: ips
* refactor: ensureResultDir
* refactor: proxy
* fix(db): call CloseDB
* add integration test
* feat(report): sort array in json
* sort func for json diff
* add build-int to makefile
* add int-rds-redis to makefile
* fix: test case, makefile
* fix makefile
* show cve count after diff
* make diff
* diff -c
* sort exploits in json for diff
* sort metasploit, exploit
2021-04-01 13:36:24 +09:00
Tomoya Amachi
0179f4299a
fix(trivy-to-vuls): converts even if null vulnerabilities ( #1201 )
2021-03-22 19:32:08 +09:00
Kota Kanbe
56017e57a0
feat(trivy): update trivy ( #1196 )
2021-03-12 09:31:48 +09:00
Kota Kanbe
cda91e0906
refactor: loading owasp dependency check xml ( #1195 )
2021-03-11 08:51:44 +09:00
Kota Kanbe
5d47adb5c9
fix(report): prioritize env vars over config.toml ( #1194 )
2021-03-10 07:39:58 +09:00
Kota Kanbe
54e73c2f54
fix(wordpress): enable to detect vulns of WordPress Core ( #1193 )
2021-03-09 10:40:52 +09:00
segatomo
2d075079f1
fix(log): remove log output of opening and migrating db ( #1191 )
...
* fix(log): remove log output of opening and migrating db
* fix(log): remove log output of opening and migrating db
2021-03-05 16:16:10 +09:00
Kota Kanbe
2a8ee4b22b
refactor(report): azure and aws writer ( #1190 )
2021-03-04 07:42:38 +09:00
Kota Kanbe
1ec31d7be9
fix(configtest): all servers in the config if no args #1184 ( #1189 )
2021-03-03 12:51:07 +09:00
Kota Kanbe
02286b0c59
fix(scan): scan all servers in the config if no args #1184 ( #1188 )
2021-03-03 12:30:30 +09:00
Kota Kanbe
1d0c5dea9f
fix(ubuntu): Fix deferred packages not showing as affected ( #1187 )
...
* fix(ubuntu): Fix deferred packages not showing as affected
https://github.com/kotakanbe/goval-dictionary/pull/122
* chore: Go version up
2021-03-02 07:50:35 +09:00
Kota Kanbe
1c4a12c4b7
refactor(report): initialize DB connection ( #1186 )
2021-03-02 06:34:46 +09:00
Kota Kanbe
3f2ac45d71
Refactor logger ( #1185 )
...
* refactor: logger
* refactor: logging
* refactor: rename func
* refactor: logging
* refactor: logging format
2021-02-26 10:36:58 +09:00
Kota Kanbe
518f4dc039
refactor: VulnDict ( #1183 )
2021-02-25 10:13:51 +09:00
Kota Kanbe
2cdeef4ffe
refactor(config): validateOnReport ( #1182 )
2021-02-25 07:41:49 +09:00
Kota Kanbe
03579126fd
refactor(config): localize config used like a global variable ( #1179 )
...
* refactor(report): LocalFileWriter
* refactor -format-json
* refacotr: -format-one-email
* refactor: -format-csv
* refactor: -gzip
* refactor: -format-full-text
* refactor: -format-one-line-text
* refactor: -format-list
* refacotr: remove -to-* from config
* refactor: IgnoreGitHubDismissed
* refactor: GitHub
* refactor: IgnoreUnsocred
* refactor: diff
* refacotr: lang
* refacotr: cacheDBPath
* refactor: Remove config references
* refactor: ScanResults
* refacotr: constant pkg
* chore: comment
* refactor: scanner
* refactor: scanner
* refactor: serverapi.go
* refactor: serverapi
* refactor: change pkg structure
* refactor: serverapi.go
* chore: remove emtpy file
* fix(scan): remove -ssh-native-insecure option
* fix(scan): remove the deprecated option `keypassword`
2021-02-25 05:54:17 +09:00
Kota Kanbe
e3c27e1817
fix(saas): Don't overwrite config.toml if UUID already set ( #1180 )
...
* fix(saas): Don't overwrite config.toml if UUID already set
* add a test case
2021-02-19 06:42:22 +09:00
Richard Alloway
aeaf308679
Add test-case to verify proper version comparison in lessThan() ( #1178 )
...
* Add test-case to verify proper version comparison when either/both/neither of newVer and ovalmodels.Package contain "_<minor version>"
* Rename vera to newVer in Test_lessThan()
* Fix oval/util_test.go formatting (make fmt)
Co-authored-by: Richard Alloway (OpenLogic) <ralloway@perforce.com >
2021-02-14 05:30:07 +09:00
Kota Kanbe
f5e47bea40
chore: add a test-case to #1176 ( #1177 )
2021-02-12 13:46:29 +09:00
Richard Alloway
50cf13a7f2
Pass packInOVAL.Version through centOSVersionToRHEL() to remove the "_<point release>" portion so that packInOVAL.Version strings like 1.8.23-10.el7_9.1 become 1.8.23-10.el7.1 (same behavior as newVer, which now allows packInOVAL.Version and newVer to be directly compared). ( #1176 )
...
Co-authored-by: Richard Alloway (OpenLogic) <ralloway@perforce.com >
2021-02-12 13:33:36 +09:00
Kota Kanbe
abd8041772
fix(scan): yum ps warning for Red Hat family ( #1174 )
...
* fix(yumps): no debug message for known patterns
* refactor(scan): yum-ps
* refacotr(scan): pkgPs
2021-02-12 13:03:06 +09:00
Kota Kanbe
847c6438e7
chore: fix debug message ( #1169 )
2021-02-11 06:31:51 +09:00
Kota Kanbe
ef8309df27
chore: remove the heck binary ( #1173 )
2021-02-11 06:31:32 +09:00
sadayuki-matsuno
0dff6cf983
fix(gost/microsoft) add workaround into mitigation ( #1170 )
...
* fix(gost/microsoft) add workaround into mitigation
* fix(gost/microsoft) fix typo and delete workaround field from vulninfo
2021-02-10 19:37:28 +09:00
kazuminn
4c04acbd9e
feat(report) : Differences between vulnerability patched items ( #1157 )
...
* add plusDiff() and minusDiff()
* add plusDiff minusDiff test
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2021-02-10 06:55:48 +09:00
Kota Kanbe
1c4f231572
fix(scan): ignore rpm -qf exit status ( #1168 )
2021-02-09 17:26:12 +09:00
Kota Kanbe
51b8e169d2
fix(scan): warning if lsof command not found ( #1167 )
2021-02-07 07:28:45 +09:00
Kota Kanbe
b4611ae9b7
fix(scan): fix yum-ps warning Failed to exec which -bash ( #1166 )
2021-02-07 07:23:12 +09:00
Kota Kanbe
cd6722017b
fix(scan): yum-ps err Failed to find the package ( #1165 )
2021-02-06 08:42:06 +09:00
Kota Kanbe
290edffccf
fix(log): output version to log for debugging purpose ( #1163 )
2021-02-04 07:47:56 +09:00
Kota Kanbe
64a6222bf9
fix(report): set created_at and updated_at of trivy to json ( #1162 )
2021-02-03 17:52:44 +09:00
Kota Kanbe
adb686b7c9
fix(report): set created_at and updated_at of wpscan.com to json ( #1161 )
2021-02-03 16:41:44 +09:00
Kota Kanbe
d4af341b0f
fix(report): remove duplicated refreshing logic when report with -diff ( #1160 )
2021-02-03 07:37:19 +09:00
Kota Kanbe
fea7e93c8d
chore: fix comment ( #1158 )
2021-02-02 06:06:49 +09:00
sadayuki-matsuno
8b6b8d0f2e
feat(wordpress): define API limit exceed error for wpscan.com ( #1155 )
...
* feat(wordpress) specify wp err
* fix typo, chagne const name
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2021-01-30 09:53:41 +09:00
Kota Kanbe
4dcbd865cc
fix(report): set http timeout 10 sec ( #1154 )
...
* fix(report): set http timeout 10 sec
* fix: add an error handling
2021-01-30 09:40:33 +09:00
Kota Kanbe
39b19444fe
Merge branch 'master' of github.com:future-architect/vuls
2021-01-28 16:24:14 +09:00
Kota Kanbe
644d5a5462
fix(report): remove retry logic for wpscan.com ( #1151 )
...
* fix(saas) change saas upload s3 key (#1116 )
* fix(report): remove retry logic for wpscan.com
Co-authored-by: sadayuki-matsuno <sadayuki.matsuno@gmail.com >
2021-01-28 16:21:33 +09:00
Kota Kanbe
8e18451e3f
Merge branch 'master' of github.com:future-architect/vuls
2021-01-28 08:24:23 +09:00
Kota Kanbe
3dbdd01f97
fix(report): wordrpess scanning skipped when package is emtpy ( #1150 )
2021-01-28 08:24:03 +09:00
sadayuki-matsuno
a89079c005
fix(saas) change saas upload s3 key ( #1116 )
2021-01-28 08:20:13 +09:00
sadayuki-matsuno
a8c0926b4f
fix(saas) change saas upload s3 key ( #1116 )
2021-01-27 14:43:09 +09:00
Kota Kanbe
dd2959a31b
fix(eol): add eol for alpine 3.13 ( #1149 )
2021-01-27 12:52:07 +09:00
Kota Kanbe
51099f42c3
fix(tui): runtime panic when tui with docker-base-setup ( #1148 )
...
* fix(tui): runtime panic when tui with docker-base-setup
* pass test case
2021-01-26 09:40:26 +09:00
Kota Kanbe
63f170cc7a
fix(report): set severity in Red Hat OVAL to both CVSS v3 and v2 #1146 ( #1147 )
2021-01-26 07:58:59 +09:00
Kota Kanbe
3c1489e588
feat(report): range notion calc by severity when no-cvss-score ( #1145 )
2021-01-25 13:22:55 +09:00
Kota Kanbe
e4f1e03f62
feat(github): display GitHub Security Advisory details ( #1143 )
2021-01-24 09:15:04 +09:00
Kota Kanbe
83d48ec990
Create codeql-analysis.yml
2021-01-24 09:06:13 +09:00
Kota Kanbe
b20d2b2684
fix(scan): skip wordpress scan for preudo servers ( #1142 )
2021-01-21 07:11:55 +09:00
Kota Kanbe
2b918c70ae
fix(scan): config dump nocolor in debug mode. ( #1141 )
2021-01-21 06:38:37 +09:00
Kota Kanbe
1100c133ba
feat(config): Default values for WordPress scanning to be set in config.toml ( #1140 )
...
* chore: update go mod
* fix(wordpress): set default if defined in config.toml
2021-01-21 06:22:25 +09:00
Kota Kanbe
88899f0e89
refactor: around CheckHTTPHealth ( #1139 )
2021-01-20 07:41:29 +09:00
Kota Kanbe
59dc0059bc
fix(model): omit changelog from json if empty ( #1137 )
2021-01-19 09:01:35 +09:00
Kota Kanbe
986fb304c0
fix(scan): add --nogpgcheck to dnf mod list to avoid Error: Cache-only enabled but no cache for *** ( #1136 )
2021-01-19 08:05:20 +09:00
Kota Kanbe
d6435d2885
fix(xml): remove -format-xml #1068 ( #1134 )
2021-01-18 04:38:00 +09:00
shopper
affb456499
fix(email.go):Fix runtime error(invalid memory address) ( #1133 )
2021-01-18 04:08:14 +09:00
Kota Kanbe
705ed0a0ac
fix(discover): change config.toml template ( #1132 )
2021-01-16 07:58:46 +09:00
Kota Kanbe
dfffe5b508
fix(config): err occurs when host not set in local-scan-mode ( #1129 )
...
If host is not set in local scan mode, an error occurs.
2021-01-14 09:22:04 +09:00
Shigechika AIKAWA
fca102edba
fix dnf prompt and ssh user ( #1126 )
2021-01-14 08:22:06 +09:00
Kota Kanbe
554b6345a2
chore: go mod update ( #1127 )
2021-01-14 08:12:47 +09:00
Kota Kanbe
aa954dc84c
fix(scan): kindness msg when no-cache err on dnf mod list ( #1128 )
2021-01-14 08:12:35 +09:00
Kota Kanbe
b5506a1368
chore: go mod update ( #1125 )
2021-01-13 11:56:35 +09:00
Kota Kanbe
0b55f94828
Improve implementation around config ( #1122 )
...
* refactor config
* fix saas config
* feat(config): scanmodule for each server in config.toml
* feat(config): enable to specify containersOnly in config.toml
* add new keys of config.toml to discover.go
* fix summary output, logging
2021-01-13 08:46:27 +09:00
Kota Kanbe
a67052f48c
fix(scan): err detecting EOL for alpine Linux ( #1124 )
2021-01-12 20:10:22 +09:00
Kota Kanbe
6eff6a9329
feat(report): display EOL information to scan summary ( #1120 )
...
* feat(report): display EOL information to scan summary
* detect Amazon linux EOL
2021-01-09 07:58:55 +09:00
Kota Kanbe
69d32d4511
feat(report): add a err code to wpscan.com API error ( #1119 )
2021-01-07 14:57:49 +09:00
Kota Kanbe
d7a613b710
chore: go mod update ( #1118 )
2021-01-07 08:02:29 +09:00
sadayuki-matsuno
669c019287
fix(cvecontent) Fixed not to split empty string ( #1117 )
2021-01-06 15:52:55 +09:00
Shigechika AIKAWA
fcc4901a10
fix(scan): Failed to parse CentOS Stream ( #1098 )
2021-01-06 14:57:19 +09:00
Kota Kanbe
4359503484
fix(redhat): possibility of false positives on RHEL ( #1115 )
2021-01-06 13:33:08 +09:00
Kota Kanbe
b13f93a2d3
feat(scan): support dnf modules ( #1114 )
...
* feat(scan): support dnf modules
* change dnf module list --installed to --enabled
* chore: refactor
* feat(report): detect logic for dnf modularity label
* fix func name
* chore: update go mods
2021-01-06 11:36:41 +09:00
Kota Kanbe
8405e0fad6
refactor(gost): Duplicate code into function ( #1110 )
...
* refactor(gost): Duplicate code into function
* fix
2020-12-30 08:33:30 +09:00
Kota Kanbe
aceb3f1826
fix(scan): add an error case for rpm -qa ( #1109 )
2020-12-30 08:05:14 +09:00
Kota Kanbe
a206675f3e
fix(wordpress): remove cache because not permitted. ( #1107 )
2020-12-29 07:25:58 +09:00
Kota Kanbe
f4253d74ae
fix(wordpress): wpscan.com unmarshal error ( #1106 )
...
* refactor(report): remove Integration.apply
* add an err check
* fix(wordpress): wpscan.com unmarshal error
* fix warnings
2020-12-29 07:11:04 +09:00
Kota Kanbe
aaea15e516
refactor(report): remove Integration.apply ( #1105 )
...
* refactor(report): remove Integration.apply
* add an err check
2020-12-29 06:59:48 +09:00
Kota Kanbe
83d1f80959
chore(report): remove stride and hipchat support ( #1104 )
2020-12-26 08:52:45 +09:00
Kota Kanbe
a33cff8f13
fix(reprot): use SQLite3 in current dir if not specified ( #1103 )
2020-12-26 08:24:17 +09:00
Kota Kanbe
8679759f60
chore: fix typo ( #1102 )
2020-12-26 08:23:02 +09:00
Kota Kanbe
53deaee3d7
refactor(config): remove DependencyCheckXMLPath in config.toml ( #1100 )
2020-12-25 06:38:00 +09:00
Kota Kanbe
5a14a58fe4
refactor(nvdxml): Remove codes related to NVD xml(deprecated) ( #1099 )
2020-12-25 06:16:14 +09:00
Kota Kanbe
fb1fbf8f95
feat(report): Add NVD as a source for mitigations, primarySrc URL and Patch URL ( #1097 )
...
* feat(report): Add NVD as a src for mitigations.
* feat(report): display "Vendor Advisory" URL in NVD
* feat(report): display patch urls in report, tui
2020-12-24 08:37:10 +09:00
Kota Kanbe
cfbf779f9b
feat(exploit): add exploit link in NVD as a source ( #1096 )
...
Added Refs information with NVD's Expoit tag as an information source
for Exploit.
2020-12-16 07:10:18 +09:00
Kota Kanbe
d576b6c6c1
refactor(report): around FillCveInfo ( #1095 )
...
* refactor(report): around FillCveInfo
* refacotr(report): around FillCveInfo
2020-12-15 15:48:23 +09:00
Kota Kanbe
514eb71482
fix(server): make config loading same as scan ( #1091 )
...
* fix(server): make config loading same as scan
* also remove from report, tui
2020-12-15 04:33:14 +09:00
Kota Kanbe
43ed904db1
fix(deps): update dependencies ( #1094 )
...
* fix(dpes): update dependencies
* update go ver
* update go ver
* update go
* update go
2020-12-15 04:32:23 +09:00
Kota Kanbe
0a440ca629
fix(saas): add saas subcmd ( #1093 )
2020-12-11 16:19:36 +09:00
Kota Kanbe
eff1dbf95b
feat(scanner): vuls-scanner binary on release archive ( #1092 )
2020-12-11 11:05:48 +09:00
Kota Kanbe
9a32a94806
refactor: fix build warnings ( #1090 )
2020-12-11 06:45:39 +09:00
Shigechika AIKAWA
2534098509
fix(report): wpvulndb poor versioning( #1088 ) ( #1089 )
2020-12-11 05:53:41 +09:00
sadayuki-matsuno
9497365758
update pkg ( #1087 )
2020-12-04 15:57:02 +09:00
Kota Kanbe
101c44c9c0
Change .goreleaser to build binaries for arm, 386, amd64 at release. ( #1082 )
...
* fix go-releaser
* add vuls-scanner
2020-11-28 06:39:52 +09:00
Kota Kanbe
ffd745c004
fix a compile error #1083 ( #1084 )
2020-11-27 15:14:04 +09:00
Kota Kanbe
5fea4eaef8
feat(nocgo): enable to build with CGO_ENABLED=0 ( #1080 )
2020-11-27 09:55:09 +09:00
Kota Kanbe
1f610043cf
feat(scan): IgnoredJSONKyes to clear values in result json #1071 ( #1078 )
2020-11-20 10:36:36 +09:00
Kota Kanbe
3f8de02683
fix(portscan): to keep backward compatibility before v0.13.0 ( #1076 )
2020-11-19 16:54:36 +09:00
Kota Kanbe
d02535d053
fix(debian): false negative of kernel cves with rdb backend ( #1075 )
...
* fix(debian): false negative of kernel cves with rdb backend
* update golangci.yml
* add --timeout=10m to golangci.yml
2020-11-18 10:32:37 +09:00
Kota Kanbe
75fceff5f7
refactor(report): format-csv ( #1072 )
2020-11-05 21:10:35 +09:00
gy741
ebd3834a35
add(report) -format-csv option ( #1034 )
2020-11-05 20:56:19 +09:00
Kota Kanbe
93059b74c3
feat(report): IgnoredJSONKyes to clear values in result json ( #1071 )
...
* feat(report): IgnoredJSONKyes to clear values in result json
* fix(report): marshal indent in JSON everytime
2020-11-05 20:13:09 +09:00
Kota Kanbe
2fc3462d35
fix(libscan): update trivy deps ( #1070 )
2020-11-05 15:38:12 +09:00
Kota Kanbe
f78dab50cb
fix(fast-root): affectedProcs, ports bug ( #1067 )
2020-10-31 14:21:11 +09:00
Norihiro NAKAOKA
edb324c3d9
fix(portscan): ignore loopback address on remote scan ( #1062 )
...
* change ignore loop back address on remote scan
* fix test case
* change append simple
* fix format
* set golangci-lint timeout
* Revert "set golangci-lint timeout"
This reverts commit 56b1c7089a .
2020-10-23 16:40:03 +09:00
Norihiro NAKAOKA
83bcca6e66
experimental: add smart(fast, minimum ports, silently) TCP port scanner ( #1060 )
...
* add struct ListenPorts
* change parse to models.ListenPorts from string
* change support models.ListenPorts in TUI
* add scanPort template , detectScanDest
* add Test_detectScanDest
* change impl scanPorts template
* fix build error
* change collect scan success address
* add Test_matchListenPorts
* add Test_updatePortStatus
* change display port scan result on tui
* change display scan emoji on report
* Revert "change display scan emoji on report"
This reverts commit e281882cc6 .
* add continue
* change display format
* change no use loop label
* remove comment code
* change display
* fix padding
* change refactoring var , fn name
* fix var name
* fix var name
* change eye icon
* change icon
* delete unuse mod
2020-10-19 17:47:20 +09:00
Kota Kanbe
a124518d78
fix: hard-coded version #1057 ( #1059 )
2020-10-16 20:42:31 +09:00
Alexander Stein
94bf630e29
Expand negative grep match for any error for lib scans. ( #1056 )
...
Many thanks 👍
Sure, that's better.
Note: FreeBSD
find: `find: /var/run/ppp: Permission denied`
2020-10-12 11:30:11 +09:00
shopper
31bb33fd90
ignore apk warning ( #1052 )
2020-10-12 10:40:01 +09:00
Kota Kanbe
4b680b9960
fix(scan-freebsd): also get installed with pkg info #1042 ( #1051 )
...
* fix(scan-freebsd): also get installed with `pkg info` #1042
* fix test
2020-09-12 05:08:41 +09:00
Kota Kanbe
8a8ab8cb18
feat(libscan): enable to scan vulns of libs with pseudo #1035 ( #1050 )
2020-09-11 13:09:59 +09:00
Kota Kanbe
8146f5fd1b
update readme ( #1049 )
2020-09-11 10:26:57 +09:00
shopper
425c585e47
Support for smtp LOGIN authentication ( #1048 )
...
* finished to implement new mail client
* delete email_test.go
2020-09-04 15:45:29 +09:00
Kota Kanbe
4f1578b2d6
[WIP]fix(scan): collect a running version of kernel-devel ( #1044 )
...
* fix(scan): collect a running kernel-devel version
* refactor
2020-09-01 14:37:40 +09:00
Norihiro NAKAOKA
7969b343b0
Raspberry Pi OS(Raspbian) scanning using OVAL DB ( #1019 )
...
* change: never refer to ChangeLog
* change raspberry pi os use debian oval at report
* change do not use r.Family
* change gost do not use r.Family
* change use r.Family because family has a large impact
* change replace MaineK00n/goval-dictionary@raspberrypi-oval
* note Raspbian Scan Policy
* add Raspbian Changelog support policy
* change grep Package for Raspbian at fast-scan mode
* add changelog preprocessing for Raspbian
* add take note of TODO
* change Changelog fetch part to function
* change error handling
* change solve one TODO
* change make ChangelogDir once
* add comment
* fix oval support Amazon Linux :refs #824
* change to useScannedCves from ovalSupproted
* change confidence for Raspbian
* change skip package for raspbian in OVAL DB
* change separate raspbian implementation from util
* change error, log format
* change print format
* change log format(delete newline)
* change support changelog.(Debian.)gz
* Revert "change support changelog.(Debian.)gz"
This reverts commit 2265a72c67 .
* change test chnage.(Debian.)gz
* change support raspbian package(*raspberry*)
* change error format
* fix regexp pattern
* fix typo
* fix changelog cache
* change rename function name
* add TestParseChangelog
* change changelog lenient match for raspbian
* fix test case
* change clog dir support symbolic link, clog save dir name append suffix
* change remove more package for raspberry pi
* fix error handling
* change module update
* change refactoring around identifying raspbian package
* update go module
* update scan image
* update scan image
* change clarify scan mode
* change raspiPackNamePattern and add test case
2020-08-25 14:11:34 +09:00
Kota Kanbe
58cf1f4c8e
refactor(typo): fix typos ( #1041 )
2020-08-24 16:34:32 +09:00
Norihiro NAKAOKA
a5b87af862
delete unnecessary images ( #1036 )
...
* delete unnecessary images
* Revert "delete unnecessary images"
This reverts commit 0967e1c522 .
* delete unnecessary images
2020-08-21 17:07:20 +09:00
Kota Kanbe
a0e592b934
fix(report): fix segfault while uploading to s3 ( #1033 )
2020-08-07 10:31:43 +09:00
Kota Kanbe
7eccc538bb
fix(msfdb): udpate go-msfdb-deps ( #1032 )
2020-08-06 16:54:14 +09:00
Kota Kanbe
59daa8570a
fix(gost): suppress err logging when unsupported debian ( #1031 )
2020-08-05 20:05:50 +09:00
Kota Kanbe
3f52d318bc
fix(log): suppress err msg if no access priv to logfile ( #1029 )
2020-07-31 16:55:12 +09:00
takuzoo
11a7a0c934
Display metasploit module information for each detected CVE-IDs ( #1011 )
...
* add metasploit
* fix go deps
* fix msf report
* fix msfdb server port number
* delete non-unique msfdb url from fulltext report
* fix(report): validate msfdb config on report (#1 )
* fix(msfdb): update deps (go-msfdb)
* version up go-msfdb v0.1.0
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2020-07-03 14:05:07 +09:00
sadayuki-matsuno
89f49b0e29
Fix trivy parser test ( #1014 )
...
* fix trivy parser test
* fixed parser data
2020-06-24 17:14:43 +09:00
Kota Kanbe
72457cbf8e
bump up version
2020-06-24 10:57:39 +09:00
Kota Kanbe
c11ba27509
fix(libscan): include a lockfile path of libs ( #1012 )
2020-06-24 10:46:00 +09:00
segatomo
8a611f9ba6
add diff-mode info ( #1008 )
2020-06-19 16:07:14 +09:00
Kota Kanbe
4a73875e4d
bump up version ( #1007 )
2020-06-17 12:21:26 +09:00
shopper
d9d5e612ff
Support ProxyJump option when using ssh command ( #1004 )
...
* Add proxyjump func
* Run go mod tidy
* Run make fmt
2020-06-17 12:15:12 +09:00
Kota Kanbe
4d8599e4fc
update deps ( #1006 )
...
see https://github.com/knqyf263/go-apk-version/pull/1
2020-06-16 07:48:07 +09:00
Norihiro NAKAOKA
59c7061d29
Fix SSH failure due to .ssh/config owner ( #1005 )
...
* use -F option, success configtest and scan
* add sshConfigPath in config.toml
* Use sshConfigPath in config.toml when using ssh -F
* change -ssh-config to deprecated
* fix typo
* add sshConfigPath in tomltemplate
2020-06-16 05:48:31 +09:00
segatomo
996557c667
support alpine3.11 ( #1002 )
2020-06-12 13:42:11 +09:00
ahulab
519fb19a77
Added ReportedAt time for server mode reports ( #996 )
...
- Fixes #928
2020-06-11 11:42:04 +09:00
kazuminn
36456cb151
feat(wordpress): Cache WpVulnDB ( #989 )
...
* add wpVulnCache
* fix bug
* add test
* fmt
* fix bug
* refactor
* fix bug
2020-06-05 16:08:28 +09:00
sadayuki-matsuno
4ae87cc36c
Fix releaser ( #988 )
...
* fix releaser
* fix releaser
* fix releaser
* fix releaser
* add 32 bit releaser and add exit code in cmd
* delete 32 bit releaser
* fix
2020-06-05 15:04:06 +09:00
shopper
b37df89fb1
Support SMTPS when using report -to-email ( #991 )
...
* Add smtps func
* Add SMTPS implementation
* fix error message
2020-06-05 14:42:01 +09:00
sadayuki-matsuno
d18e7a751d
add trivy parser ( #981 )
...
* add trivy parser
* fix test
* format
* add title and summary
* add trivy parse command
* add uploader
* set args by env
* add README
* add err check
* fix
* fix
* fix
* fix test
* update trivy
* refactor
* delete require uuid
* delete uuid from trivy parser
Co-authored-by: Kota Kanbe <kotakanbe@gmail.com >
2020-05-29 18:06:45 +09:00
kazuminn
8d5ea98e50
add -wp-ignore-inactive flag which ignores inactive plugin or themes ( #974 )
...
* command
* config
* ignore inactive
* fix
* add test
* fmt
* add unset test
* rename
* add test
* refactor
* fix
* refactor
* refactor
* fix golangci-lint error
2020-05-29 15:27:47 +09:00
Kota Kanbe
835dc08049
fix .golangci.yml
2020-05-27 20:33:57 +09:00
Kota Kanbe
62c9409fe9
add a github actions config ( #985 )
...
* add a github actions config
* fix(log): Don't create a log dir when testing
* remove a meaningless test case
* Thanks for everything, Mr, Travys.
* add golangci
* add goreleaser.yml
* add tidy.yml
* add golang-ci
* fix many lint warnings
2020-05-27 20:11:24 +09:00
Kota Kanbe
2374f578ed
Bump up version
2020-05-26 09:32:10 +09:00
shopper
34e2f033d8
add kernelnames ubuntu20.04 ( #982 )
2020-05-22 12:19:07 +09:00
kazuminn
420825cacc
remove append ( #978 )
2020-05-20 13:55:07 +09:00
Kota Kanbe
466ec93d8e
bump up version
2020-05-08 17:15:25 +09:00
Kota Kanbe
3f5bb6ab29
fix(scan): alpine detection #965 ( #966 )
...
* fix(scan): alpine detection #965
* use knqyf263/go-apk-version
2020-05-08 16:12:01 +09:00
Kota Kanbe
ebe5f858c8
update trivy, and unsupport image scanning feature ( #971 )
...
* update trivy, fanal. unsupport image scanning
* Update models/library.go
Co-authored-by: Teppei Fukuda <teppei@elab.ic .i.u-tokyo.ac.jp>
* add -no-progress flag to report/tui cmd
* Display trivy vuln info to tui/report
* add detection method to vulninfo detected by trivy
* fix(uuid): change uuid lib to go-uuid #929 (#969 )
* update trivy, fanal. unsupport image scanning
* Update models/library.go
Co-authored-by: Teppei Fukuda <teppei@elab.ic .i.u-tokyo.ac.jp>
* add -no-progress flag to report/tui cmd
* Display trivy vuln info to tui/report
* add detection method to vulninfo detected by trivy
* unique ref links in TUI
* download trivy DB only when lock file is specified in config.toml
Co-authored-by: Teppei Fukuda <teppei@elab.ic .i.u-tokyo.ac.jp>
2020-05-08 15:24:39 +09:00
Kota Kanbe
9dd025437b
fix(uuid): change uuid lib to go-uuid #929 ( #969 )
2020-05-06 14:14:07 +09:00
Wagde Zabit
c0ebac305a
composer.lock insteaad of composer.json ( #973 )
...
Co-authored-by: Wagde Zabit <wagde@orcasecurity.io >
2020-05-01 15:20:33 +09:00
Kota Kanbe
1f23ab7ba4
Bump up version
2020-04-28 14:27:46 +09:00
Kota Kanbe
ea3b63998d
fix(report): GitHub Security Alerts Integration ( #970 )
2020-04-28 14:26:37 +09:00
Kota Kanbe
3093426458
fix(logging): panic if no write permission #949 ( #968 )
2020-04-27 17:37:30 +09:00
Kota Kanbe
37716feac7
refactor(lint): fix lint warnings ( #967 )
2020-04-27 17:02:27 +09:00
Kota Kanbe
56b12c38d2
fix(config): not working with empty config #962 ( #963 )
2020-04-23 10:50:35 +09:00
Kota Kanbe
749ead5d4a
update go mod ( #960 )
2020-04-20 21:33:11 +09:00
Kota Kanbe
3be50ab8da
bump up version
2020-04-19 09:06:01 +09:00
Kota Kanbe
649f4a6991
fix(report): kernel vulns detection BUG in Ubuntu ( #958 )
...
* fix(report): kernel vulns detection in Ubuntu
* fix(ubuntu): remove linux-* to detect only running kernel vulns
2020-04-19 09:04:08 +09:00
Kota Kanbe
0ff7641471
feat(report): display "fixed" when updatable even in fast mode ( #957 )
2020-04-13 18:20:32 +09:00
Kota Kanbe
1679bfae20
Update FUNDING.yml
2020-04-10 21:25:10 +09:00
Kota Kanbe
45aa364436
Update FUNDING.yml
2020-04-10 21:24:24 +09:00
Kota Kanbe
778516c4d9
Create FUNDING.yml
2020-04-10 21:21:30 +09:00
Kota Kanbe
464d523c42
Display fixed-in version for each package in report ( #801 )
...
* refactor(model): PackageFixStatus.Name to BinName
* refacotr(oval): change var name
* feat(report): Add FixedIn in JSON
* refactor(tui): chage args
* display fixedin in report
* refactor(model): change fileld name
* remove unused field of PackageFixStatus
2020-04-08 21:26:34 +09:00
Kota Kanbe
0f6a1987d4
fix(configtest): yum-utils instead of dnf-utils on RHEL8, Cent8 ( #948 )
2020-04-06 19:40:05 +09:00
Shigechika AIKAWA
20c6247ce5
fix CentOS8 configtest always failed ( #947 )
2020-04-06 15:47:08 +09:00
gy741
a10dd67e0f
Fix typo in models/scanresults.go ( #942 )
2020-04-06 15:00:43 +09:00
segatomo
5729ad6026
Add CWE Top25 and SANS Top25 ( #925 )
...
* add top25 rank
* add CweTop25 and SansTop25
* fix report
* add cwetop25 and sanstop25 url
* fix condition branch
* fix condition branch
2020-03-03 17:33:06 +09:00
Tomoya Amachi
9aa0d87a21
feat : scan with image digest ( #939 )
2020-03-03 16:51:06 +09:00
ishiDACo
fe3f1b9924
Update OWASP Dependency Check parser for dependency-check.2.2.xsd schema ( #936 )
2020-02-27 10:08:26 +09:00
Kota Kanbe
00e52a88fa
Update README.md
2020-02-01 09:27:17 +09:00
Kota Kanbe
5811dffe7a
fix(report): Support CVSS 3.1 for Red Hat OVAL #930 ( #932 )
2020-01-30 22:48:04 +09:00
sadayuki-matsuno
7278982af4
update fanal ( #931 )
2020-01-30 20:40:49 +09:00
nyao
c17b4154ec
fix(config): fix double checking ResultsDir Path ( #927 )
2019-12-12 09:29:12 +09:00
Kota Kanbe
d6e74cce08
bump up version ( #923 )
2019-11-26 09:54:30 +09:00
Kota Kanbe
3f80749241
Merge branch 'master' of github.com:future-architect/vuls
2019-11-26 09:44:10 +09:00
Kota Kanbe
7f72b6ac69
Warn no ip ( #922 )
...
* fix(scan): ignore wp-cli stderr messages (#825 ) (#915 )
* fix(scan): warn if unable to get ip address on the scan tareget server
* fix test case
2019-11-26 09:40:38 +09:00
Kota Kanbe
03e7b90b9f
Merge branch 'master' of github.com:future-architect/vuls
2019-11-26 08:53:03 +09:00
Kota Kanbe
7936b3533b
Fill Red Hat CVE data for all distros ( #920 )
...
* fix(scan): ignore wp-cli stderr messages (#825 ) (#915 )
* refactor
* feat(report): fill Red Hat CVE data for all distros
* fix lint err
* fix cve judgment (#921 )
2019-11-25 17:01:18 +09:00
Shigechika AIKAWA
bd7e61d7cc
fix(scan): ignore wp-cli stderr messages ( #825 ) ( #915 )
2019-11-22 20:58:24 +09:00
Shigechika AIKAWA
69214e0c22
fix(scan): ignore wp-cli stderr messages ( #825 ) ( #915 )
2019-11-01 10:01:50 +09:00
Wagde Zabit
45bff26558
Consider grep return value 1 as success ( #907 )
...
* Allow Offline scanning on Alpine
* Consider grep return value 1 as success
2019-09-18 23:26:37 +09:00
Kota Kanbe
b2e429ccc6
fix(log): add .log extension to vuls logfile ( #910 )
2019-09-18 23:21:06 +09:00
Kota Kanbe
76363c227b
fix(report): enable to report when the sshkey not exist ( #909 )
2019-09-18 22:40:36 +09:00
Kota Kanbe
d5a3e5c2c5
fix(report): fix cert key in result json ja to jp ( #908 )
2019-09-18 19:30:32 +09:00
Kota Kanbe
2b02807ef0
fix(report): ignore exploits of no-cve-id vulns ( #906 )
2019-09-13 12:49:57 +09:00
Kota Kanbe
be659ae094
fix(docker): add git to image ( #905 )
2019-09-13 01:10:27 +09:00
Kota Kanbe
b2c105adbc
fix(tui): enable to exec tui mode without cve.sqlite3 ( #904 )
2019-09-12 18:35:21 +09:00
Kota Kanbe
c61f462948
fix(report): show POC, CERT in tui and format-list. use vendor summary over NVD ( #902 )
...
* fix(report): show POC, CERT in tui and format-list. show vendor summary
* fix test case
2019-09-10 10:00:17 +09:00
Kota Kanbe
3ffed18e02
Change GPL v3 to AGPL v3 because of aquasecurity/trivy dependency ( #897 )
2019-09-09 21:12:17 +09:00
Kota Kanbe
f54e7257d1
fix(report): fill cert alerts from NVD and JVN feeds ( #899 )
...
* fix(report): fill cert alerts from NVD and JVN feeds
* fix import alias cve to cvemodels
* fix import alias cve to cvemodels
* remove unnecessary func
2019-09-09 21:11:59 +09:00
Kota Kanbe
cc13b6a27c
fix(report): enable to report without NVD, exit if no OVAL data ( #900 )
...
* feat(report): enable to report without NVD
* fix(report): enable to report without NVD and exit if no OVAL data
* update deps
* go mod tidy
* fix err msg
2019-09-09 21:00:34 +09:00
Kota Kanbe
8877db1979
udpate deps, go 1.13 ( #901 )
2019-09-09 20:26:26 +09:00
Tomoya Amachi
af58122c91
for Amazon Linux image ( #896 )
...
* fit amazon linux image's version to OVAL
* add Arch to SrcPackage
* lint go.mod
* make fmt
2019-09-06 10:34:14 +09:00
Kota Kanbe
b7ca5e5590
feat(scan): add -wordpress-only and -libs-only flag ( #898 )
2019-09-06 10:33:03 +09:00
Tomoya Amachi
69b6d875e6
scanVuln => GetScanResults and writeScanResults ( #891 )
2019-09-04 13:28:34 +09:00
Kota Kanbe
1fbd516b83
fix(report): fix too many variables while reporting ( #888 )
2019-08-25 17:56:47 +09:00
DjinnS
dec5d3b165
No warning(s) in the output file with -quiet option. Report command ( #885 )
2019-08-25 10:56:42 +09:00
DjinnS
d5e2040cef
awk is useless because ps already formats the output. Also, this syntaxe isn't correct when the command is excuted on a container because of the ' . ( #883 )
2019-08-25 10:13:58 +09:00
wagdez
4326befdec
Allow Offline scanning on Alpine ( #877 )
2019-07-30 17:47:01 +09:00
Kota Kanbe
3d4a5d9917
fix(report): Unsupport family: centos ( #876 )
...
* fix(report): Unsupport family: centos
* go mod tidy
2019-07-25 12:47:41 +09:00
Shigechika AIKAWA
d770034788
fix centos yum makecache --assumeyes ( #872 )
2019-07-17 11:10:20 +09:00
Masahiro Fujimura
a977533c78
Fix performance and bug ( #867 )
...
* Fix performance
* Update goval-dictionary
* Go mod tidy
2019-07-15 21:20:01 +09:00
Kota Kanbe
c5e13dd5e4
fix(configtest): remove yum-plugin-ps check on Amazon Linux ( #870 )
2019-07-12 07:25:47 +09:00
Kota Kanbe
a8040fe4d2
fix(wordpress): add --allow-root to wp cmd for docker based wp ( #865 )
2019-07-07 19:15:17 +09:00
Tomoya Amachi
9e066008c3
fix go module problems & update trivy version ( #864 )
...
* update trivy version
* use goval-dictionary@v0.1.4
2019-07-07 17:04:52 +09:00
Kota Kanbe
22c6601526
make fmt
2019-07-06 23:25:46 +09:00
Kota Kanbe
425464fd76
fix(scan): allow exit 1 for no match lsof | grep ( #863 )
2019-07-06 23:15:34 +09:00
Kota Kanbe
ccb0751ffd
fix(scan): show listening ip:port of procs ( #862 )
2019-07-06 14:10:08 +09:00
Kota Kanbe
f832de81b7
feat(saas): log.info done after uploading
2019-07-05 17:30:31 +09:00
Tomoya Amachi
8a37de0686
Add ips flag to scan ( #861 )
...
* add scan -ips flag
* fix usage
2019-07-04 18:42:12 +09:00
Kota Kanbe
836e4704f8
feat(scan): Display listen port of affected procs for each vulnerable pkgs ( #859 )
...
* refactor(redhat): move rpmQa and rpmQf to redhatbase.go
* feat(scan): Display listen port of affected procs
2019-07-03 23:01:59 +09:00
Kota Kanbe
3e5390309c
feat(redhat): ignore will not fix vulns ( #858 )
2019-07-03 20:59:23 +09:00
Kota Kanbe
f8c0b38716
feat(fast-root): get running procs for each pkgs (all RHEL, CentOS, AmazonLinux, Ubuntu, Debian) ( #855 )
...
* fix(scan): exec yum-plugin-ps on RHEL6 and 7
* feat(yumps): get affected procs on RHEL6 and RHEL8
* feat(scan): get affected processes for each packages
* tuning
* feat(scan): get running procs for each pkgs on Debian, Ubuntu
2019-07-02 14:55:46 +09:00
Masahiro Fujimura
65e6070e5f
Fix race condition in server mode ( #857 )
2019-07-02 10:11:36 +09:00
Tomoya Amachi
7b78ebbc42
retrieve ips(deep security) identifiers ( #852 )
...
* retrieve ips identifiers
* fix golangci
* use IPS type
* fix log message
* fix lockfiles config
* change label
* IPS : only work with fast-root mode
2019-07-02 10:06:30 +09:00
Masahiro Fujimura
03c3189c02
Changes don't required config.toml in server mode ( #853 )
2019-06-26 21:21:17 +09:00
Masahiro Fujimura
4a34dfe0e9
Support amazonlinux via http text/plain ( #850 )
2019-06-25 10:00:54 +09:00
Kota Kanbe
4cf9a723fe
set GO111MODULE=on in .goreleaser.yml
2019-06-18 10:15:42 +09:00
Kota Kanbe
bd1b135db3
Add vulsrepo issue template
2019-06-17 14:15:23 +09:00
alfe
8c3b305149
fix(readme): typo in news ( #841 )
2019-06-15 18:39:00 +09:00
Kota Kanbe
a3719038b8
fix(scan): scan Amazon Linux with offline mode ( #840 )
2019-06-14 19:10:07 +09:00
Kota Kanbe
c68a261c0b
Update README.md
2019-06-14 19:02:21 +09:00
Kota Kanbe
75fea79ac1
feat(scan): Support RHEL8 ( #813 )
...
* feat(scan): Support RHEL8
* fix(scan): check if `dnf-uils` is installed
2019-06-14 12:28:16 +09:00
Kota Kanbe
eb9f9680ec
refactor(scan): remove yum-security related code ( #836 )
...
* refactor(scan): remove yum-security related code
* fix(reporting): error if no OVAL entry
2019-06-14 11:42:38 +09:00
Tomoya Amachi
3634afdb81
enhance issue_template ( #837 )
2019-06-14 11:34:36 +09:00
Sajan Alexander
77b5df896a
update goval-dictionary dependency to valid version ( #839 )
2019-06-14 09:28:39 +09:00
Kota Kanbe
b81f64058c
fix(report): remove extra check logic #802 ( #835 )
2019-06-13 21:45:22 +09:00
Kota Kanbe
a8a90d7c63
refactor(report): speed up oval reporting #833 ( #834 )
2019-06-13 17:47:36 +09:00
Kota Kanbe
17bb575002
fix(scan): enable to report if some warnings occured on scanning ( #805 )
...
* fix(scan): enable to report if some warnings occured on scanning
* alpine, debian, freebsd, suse
* -format-full-text, -format-list, -format-one-line-text
* implement slack.go
* implement tui.go
* go fmt
2019-06-12 21:35:21 +09:00
Tomoya Amachi
abcea1a14d
add Library Scan (with image scan) ( #829 )
...
* add static container image scan
* server has many staticContainers
* use go module
* for staticContainer
* fix typo
* fix setErrs error
* change name : StaticContainer -> Image
* add scan -images-only flag
* fix makefile
* fix makefile for go module
* use rpmcmd instead of rpm
* add scrutinizer.yml
* change scrutinizer.yml
* fix scrutinizer.yml
* fix scrutinizer.yml
* fix scrutinizer.yml
* fix scrutinizer.yml
* delete scrutinizer
* add report test
* add sourcePackages and Arch
* fix for sider
* fix staticContainer -> image
* init scan library
* add library scan for servers
* fix tui bug
* fix lint error
* divide WpPackageFixStats and LibraryPackageFixedIns
* fix error
* Delete libManager_test.go
* stop use alpine os if err occurred in container
* merge upstream/master
* Delete libManager.go
* update goval-dictionary
* fix go.mod
* update Readme
* add feature : auto detect lockfiles
2019-06-12 18:50:07 +09:00
Kota Kanbe
10942f7c08
fix(scan): fetch only updatable package changelogs ( #815 )
2019-06-12 15:08:03 +09:00
Kota Kanbe
87ee829e80
fix(scan): exec yum makecache to update metadata on RedHat based linux ( #810 )
...
* fix(scan): exec `yum makecache` to update metadata on RedHat based linux
* sudo
2019-06-12 14:44:42 +09:00
Chandrapal Badshah
fcc2c1e4c7
Changing the scannedAt time in the original result ( #823 )
2019-06-12 07:55:29 +09:00
Kota Kanbe
269095d034
feat(report): support Amazon OVAL scanning ( #824 )
...
* feat(report): support Amazon OVAL scanning
* add distroAdvisories
* see goval/master
2019-06-10 23:20:39 +09:00
Neal McBurnett
40492ee00a
fix typos, extraneous text ( #831 )
2019-06-10 09:55:17 +09:00
Shigechika AIKAWA
64cdd5aedc
fix(report): WordPress(WPVULNDB API) 429 Too Many Requests ( #826 )
...
* fix(report): WordPress(WPVULNDB API) 429 Too Many Requests
* fix(report): WordPress(WPVULNDB API) 429 Too Many Requests
2019-06-04 12:11:40 +09:00
Kota Kanbe
3bb650cb77
fix(report-redhat): fix false negative of affected vulns #827 ( #828 )
2019-06-04 09:55:32 +09:00
Kota Kanbe
774544c975
fix(report): warning only if the kernel version is unknown ( #822 )
2019-05-24 10:09:11 +09:00
Kota Kanbe
299805a726
[WIP]fix(scan): false negative of kernel related vulns on Ubuntu 16 ( #819 )
...
* fix(scan): a bug of detect kernel vulns on Ubuntu 16
* fix(scan): support Ubuntu 14
2019-05-23 23:52:00 +09:00
Kota Kanbe
276363e793
fix(scan): a bug of kernel Vulns detection on Ubuntu18 ( #818 )
...
* fix(scan): a bug of kernel Vulns detection on Ubuntu18
* fix the test case
2019-05-23 17:00:33 +09:00
Kota Kanbe
e750bd53fc
fix(report): fix the number of fixed/total in reporting ( #817 )
2019-05-20 14:30:29 +09:00
sadayuki-matsuno
98fee7b5d2
Implement Vuls's own error code ( #812 )
...
* add error pkg
* fix fmt format
* fix NewError -> New
* fix err msg format
2019-05-15 17:42:09 +09:00
sadayuki-matsuno
53aaea9fe2
add scannedVia field to know the way of access such as SSH, local or pseudo ( #811 )
...
* add sacnned via
* change scannedVia type to const
2019-05-15 13:33:09 +09:00
Chandrapal
824fbb6368
Updated config.toml reference url ( #809 )
...
* Update URL in scan.go
* Update URL in configtest.go
2019-05-10 07:11:30 +09:00
Kota Kanbe
80566b91ab
fix(report): exit 1 when scan result has errors ( #804 )
2019-04-25 15:09:29 +09:00
Kota Kanbe
533d05a1b5
fix(report): Error when GitHub integration failed ( #800 )
2019-04-15 21:51:04 +09:00
Kota Kanbe
6a1fc4fade
Merge branch 'master' of https://github.com/future-architect/vuls
...
* 'master' of https://github.com/future-architect/vuls :
fix goreleaser.yml
Add news to readme
2019-04-08 21:19:12 +09:00
Kota Kanbe
9008d0ddf0
Add news to readme
2019-04-08 21:17:05 +09:00
Kota Kanbe
583f4577bc
fix goreleaser.yml
2019-04-08 19:51:58 +09:00
Kota Kanbe
e5716d5092
Add news to readme
2019-04-08 18:22:03 +09:00
Kota Kanbe
7192ae1287
Bump up version
2019-04-08 17:33:57 +09:00
kazuminn
99c65eff48
feat(scan): WordPress Vulnerability Scan (core, plugin, theme) ( #769 )
...
https://github.com/future-architect/vuls/pull/769
2019-04-08 17:27:44 +09:00
Josh Soref
91df593566
Editorial fixes ( #798 )
...
mostly suggested by app.grammarly.com
* articles
* brand name fixes
* hyphenation
* Oxford comma
* sorting lists
* spelling
2019-04-04 22:51:06 +09:00
sadayuki-matsuno
07aeaeb989
update go-exploitdb ( #797 )
2019-03-28 00:49:31 +09:00
sadayuki-matsuno
cfeecdacd0
update pkgs ( #796 )
2019-03-26 10:56:14 +09:00
sadayuki-matsuno
564dfa8b62
update cve dictionary ( #795 )
2019-03-26 10:10:40 +09:00
seph
75dd6f2010
Specify VOLUME using json syntax ( #791 )
...
When using a json array for VOLUME, values must be quoted. Else it's interpreted as a string, eg /[vuls
Fixes https://github.com/kotakanbe/goval-dictionary/issues/58
2019-03-22 16:30:23 +09:00
Kota Kanbe
e26fd0b759
fix(report): Critical Bug Fix for CPE based scanning #793 ( #794 )
2019-03-22 16:28:40 +09:00
Kota Kanbe
d630680a51
feat(slack): enable -format-one-line-text with -to-slack ( #792 )
2019-03-18 13:56:49 +09:00
Kota Kanbe
1723c3f6a0
fix(report): cpe match bug: go-cve-dictionary#120 ( #790 )
2019-03-15 21:31:21 +09:00
Kota Kanbe
53dd90302e
fix(scan): parse error on SUSE #515 ( #786 )
2019-03-12 17:36:27 +09:00
b3tyar
5c6e06b05e
Handle no-auth SMTP Servers and one liner email fix ( #772 )
...
* Handle no-auth SMTP Servers
* Remove unneeded else block
* Fix for Issue #633
2019-03-12 16:45:25 +09:00
Iskander (Alex) Sharipov
cf6fb0c8a5
models: fix no-op append calls ( #785 )
...
Fixed simplest cases of append calls that have no
effect aside from driving Go static analysis tools crazy.
One issue remains (#784 ) since I'm not sure
what would be the right behavior there.
2019-03-07 11:28:44 +09:00
sadayuki-matsuno
e0e71b2eae
add scanner info in -to-saas ( #783 )
2019-03-04 16:36:32 +09:00
sadayuki-matsuno
53f4a29fb1
change implemention of integration ( #780 )
2019-02-21 14:06:21 +09:00
Kota Kanbe
89d58d1abc
bump up version
2019-02-20 14:58:49 +09:00
Kota Kanbe
d6b6969cb3
update README
2019-02-20 14:56:24 +09:00
kazuminn
e7bf6fa69d
feat(README): contiruters shield ( #778 )
...
* add contiruters shield
* Update README.md
* Update README.md
2019-02-20 12:20:56 +09:00
Kota Kanbe
6e51970b91
fix(discovery): show the template of GitHub Security Alerts integration to discovery subcommand
2019-02-20 12:08:22 +09:00
Kota Kanbe
56d7d43768
feat(report): GitHub security alerts integration ( #775 )
...
feat(report): integrate to GitHub security alerts
2019-02-20 12:04:10 +09:00
Shota Ito
256c99ffa2
Delete tab from output in case of No CVE-IDs ( #768 )
2019-01-25 00:21:41 +09:00
Takayuki Ushida
9c0bc3b13b
modify build time ( #766 )
2019-01-24 15:26:12 +09:00
Kota Kanbe
9b8a323d85
fix(report): detect 0 vulns for Amazon, FreeBSD, Raspbian ( #765 )
2019-01-24 11:49:33 +09:00
kota kanbe
3178c1e326
Merge branch 'master' of https://github.com/future-architect/vuls
...
* 'master' of https://github.com/future-architect/vuls :
Add Telegram support (#762 )
2019-01-23 00:25:54 +09:00
kota kanbe
321d68e03a
Bump up version
2019-01-23 00:25:02 +09:00
Yao Ding
3d8753c621
Add Telegram support ( #762 )
...
* add telegram support
* format message
* remove debug print
* fix linting error
* add telegram to discover; group message by 10
* use chatID instead of channel
* apply refactor
* remove reduntant space
2019-01-23 00:19:16 +09:00
Tomoya Amachi
967c56909d
add ScannedIPv4Addrs and ScannedIPv6Addrs ( #764 )
2019-01-19 22:19:06 +09:00
Takayuki Ushida
7c4831d2d1
add build time ( #763 )
2019-01-18 13:13:50 +09:00
Shigechika AIKAWA
4b49e11a33
add(report) -format-list option to -to-email ( #761 )
2019-01-17 16:31:04 +09:00
Kota Kanbe
d84a6a8627
fix(oracle): vuls report returns different result each time in the case of Oracle Linux ( #759 )
...
https://github.com/kotakanbe/goval-dictionary/pull/56
2019-01-12 23:11:06 +09:00
sadayuki-matsuno
63b7f4a8db
delete paperr ( #758 )
2019-01-12 22:40:56 +09:00
yahharo
ca2160264a
Remove ThreadTimeStamp from message struct ( #756 )
...
- If `thread_ts` valus sent as empty string ("") to Slack, it returns error `invalid_thread_ts`
- When API try to send, it use `slack.PostMessageParameters`, not use `message`
2018-12-25 12:27:53 +09:00
Kota Kanbe
7842594f53
fix(scan): OS detection ssh timeout in first run #699 ( #753 )
2018-12-20 13:59:54 +09:00
Kota Kanbe
7db056102c
fix(report): overdetection for Red Hat/CentOS with redis backend ( #748 )
...
fix(report): miss detection for Red Hat/CentOS with redis backend
2018-12-06 15:29:28 +09:00
Tomoya Amachi
a5a800fa0a
add alert data to result json ( #747 )
...
* add alert data to result json
* delete omitempty from AlertDict
2018-12-05 15:38:23 +09:00
Tomoya Amachi
9147ec148d
Beautify alert ( #746 )
...
* update dep
* to make easy edit alert data manually
* fix alert data bug
2018-12-05 12:30:04 +09:00
sadayuki-matsuno
b3260588c6
fix(gost) update pkg to incorporate the latest gost ( #745 )
2018-12-04 17:33:31 +09:00
sadayuki-matsuno
7d31328271
export exploit func ( #744 )
2018-11-30 16:53:51 +09:00
Kota Kanbe
6e82981ee3
feat(report): Display CERT information to reports ( #741 )
...
* fix(tui): show JPCERT Alert URL in TUI
* feat(tui): show `!` when the CVE-ID corresponds to USCERT or JPCERT alert
* feat(report): display cert alert info to stdout report
* fix(report): Display CVEs detected by CPEs with -ignore-unfixed flag
2018-11-30 15:41:59 +09:00
Tomoya Amachi
9d7b115bb5
add JPCERT and USCERT alert dictionary ( #740 )
...
* add alert dictionary
* fix for sider review
* fix for sider review
2018-11-30 14:17:17 +09:00
Kota Kanbe
8eae5002a3
fix(report): return both scores of gost and oval ( #739 )
2018-11-29 12:17:19 +09:00
Kota Kanbe
31bd6c0371
feat(scan): get repository name of updatable pkgs for debian/ubuntu ( #738 )
2018-11-26 12:02:52 +09:00
Kota Kanbe
7585f9d537
fix(report): fix cvedb-url, add -cvedb-type=http ( #734 )
...
* fix(report): fix cvedb-url, add -cvedb-type=http
* feat(report): support go-exploitdb server mode
* update deps
* implement tui
* fix server mode
* fix(tui): default value of cvedb-type to ""
* update deps
2018-11-16 21:22:18 +09:00
sadayuki-matsuno
76037cdf72
fix new cve contents ( #735 )
2018-11-15 13:43:06 +09:00
sadayuki-matsuno
98c5421edc
fix exploit db ( #733 )
2018-11-12 17:36:53 +09:00
Kota Kanbe
e63fc7e3f5
fix(report): nil pointer in deep scan mode #728 ( #732 )
2018-11-10 12:36:12 +09:00
sadayuki-matsuno
6ed9cf3fb4
add scan mode ( #731 )
2018-11-05 15:35:50 +09:00
sadayuki-matsuno
9865eab2c0
Display exploit codes information for each detected CVE-IDs ( #729 )
...
* add exploit
* bug fix while loading config in TUI, display in format-full-text
* fix readme
2018-11-03 16:36:59 +09:00
Kota Kanbe
678e72a8b6
fix(gost): a bug of parseCwe ( #726 )
2018-10-29 21:21:20 +09:00
sadayuki-matsuno
ec41899089
check cve_contents init ( #725 )
...
check cve_contents init to avoid nil pointer
2018-10-29 16:27:54 +09:00
Harald Nordgren
b2d913cc21
Bump Go versions and use '.x' to always get latest patch versions ( #724 )
2018-10-29 16:26:20 +09:00
sadayuki-matsuno
bc86c24e6a
update pkg ( #723 )
...
* update pkg
* change lint url
2018-10-18 13:37:17 +09:00
sadayuki-matsuno
87a77dd95c
update pkgs ( #720 )
2018-10-10 17:43:26 +09:00
sadayuki-matsuno
e8188f3432
add ms gost ( #718 )
...
* add ms gost
* change gost branch
2018-10-05 12:45:26 +09:00
Kota Kanbe
50506be546
[WIP] feat(report): show repository of affected pkgs ( #713 )
...
feat(report): show repository of affected pkgs
2018-10-04 16:01:55 +09:00
Iskander (Alex) Sharipov
4ded028258
config: remove commented-out code from tomlloader ( #714 )
...
Signed-off-by: Iskander Sharipov <quasilyte@gmail.com >
2018-10-04 12:37:58 +09:00
Iskander (Alex) Sharipov
6da8b3c4a1
commands: simplify s[:] to s ( #715 )
...
If s is a slice, then `s[:]` is identical to just `s`.
Signed-off-by: Iskander Sharipov <quasilyte@gmail.com >
2018-10-04 12:37:31 +09:00
Iskander (Alex) Sharipov
d5c92cbcb3
report: simplify x = x <op> y to x <op>= y ( #716 )
...
Signed-off-by: Iskander Sharipov <quasilyte@gmail.com >
2018-10-04 12:35:02 +09:00
sadayuki-matsuno
ed5f98d6f0
change syslog pkg ( #717 )
2018-10-04 12:34:23 +09:00
Kota Kanbe
f854b8f908
fix(report): fix an error while loading cveDict.type in config.toml ( #711 )
2018-10-02 09:27:34 +09:00
Shigechika AIKAWA
de7a6159d4
remove table.SetHeaderColor codes ( #709 )
...
table.SetHeaderColor does not need in case of formatFullPlainText().
2018-09-25 10:31:22 +09:00
Kota Kanbe
6090a34037
fix(cpe): update deps to avoid parsing err of cpeNames ( #708 )
2018-09-13 13:42:04 +09:00
Kota Kanbe
f566745479
fix(config): a DB URL error 'does not validate as url' #705 ( #706 )
2018-09-11 09:19:24 +09:00
kota kanbe
153234b623
update readme
2018-08-29 22:39:05 +09:00
Kota Kanbe
ac510d21ff
fix(scan): fix err msg when unable to connect via SSH ( #702 )
2018-08-29 10:48:32 +09:00
Kota Kanbe
44fa2c5800
v0.5.0 (no backwards compatibility) ( #478 )
...
* Change config.toml, Auto-generate UUIDs, change structure of optional field
* Detect processes affected by update using yum-ps (#482 )
Detect processes affected by update using yum-ps
* Detect processes needs restart using checkrestart on Debian and Ubuntu.
* pass cpename by args when calling FillCveInfo (#513 )
* fix new db (#502 )
* Include Version,Revision in JSON
* Include hostname in JSON
* Update goval-dictionary's commit hash in Gopkg.lock
* Remove README.ja.md
* update packages (#596 )
* fix: change ControlPath to .vuls of SSH option (#618 )
* feat: checkrestart for Ubuntu and Debian (#622 )
* feat: checkrestart for Ubuntu and Debian
* fix: dependencies check logic of configtest
* feat: need-restarting on RedHat
* refactor: Process.ProcName to Process.Name
* feat: detect a systemd service name of need-restarting-process
* feat: detect a systemd service name of need-restarting-process on Ubuntu
* feat: fill a service name of need-restarting-process, init-system
* Support NVD JSON and CVSS3 of JVN (#605 )
* fix: compile errors
* fix: Show CVSS3 on TUI
* fix: test cases
* fix: Avoid null in JSON
* Fix maxCvssScore (#621 )
* Fix maxCvssScore
* Update vulninfos.go
* fix(init): remove unnecessary log initialization
* refactor(nvd): use only json feed if exists json data. if not, use xml feed
* fix(scan): make Confidence slice
* feat(CWE): Display CWE name to TUI
* feat(cwe): import CWE defs in Japanese
* feat(cwe): add OWASP Top 10 ranking to CWE if applicable
* feat(scan): add -fast-root mode, implement scan/amazon.go
* refactor(const): change const name JVN to Jvn
* feat(scan): add -fast-root mode, implement scan/centos.go
* refactor(dep): update deps
* fix(amazon): deps check
* feat(scan): add -fast-root mode, implement scan/rhel.go
* feat(scan): add -fast-root mode, implement scan/oracle.go
* fix complile err
* feat(scan): add -fast-root mode, implement scan/debian.go
* fix testcase
* fix(amazon): scan using yum
* fix(configtest): change error message, status when no scannnable servers
* Fix(scan): detect init process logic
* fix(tui): display cvss as table format
* fix(scan): parse a output of reboot-notifier on CentOS6.9
* fix(tui): don't display score, vector when score is zero
* fix(scan): add -offline mode to suse scanner
* fix(scan): fix help message
* feat(scan): enable to define scan mode for each servers in config.toml #510
* refactor(config): chagne cpeNames to cpeURIs
* refactor(config): change dependencyCheckXMLPath to owaspDCXMLPath
* fix(config): containers -> containersIncluded, Excluded, containerType
* feature(report): enable to define cpeURIs for each contaner
* feature(report): enable to specify owasp dc xml path for each container
* fix(discover): fix a template displayed at the end of discover
* feature(report): add ignorePkgsRegexp #665
* feature(report): enable to define ignoreCves for each container #666
* fix(report): Displayed nothing in TUI detail area when CweID is nil
* Gopkg.toml diet
* feat(server): support server mode (#678 )
* feat(server): support server mode
* Lock go version
* Use the latest kernel release among the installed release when the running kernel release is unknown
* Add TestViaHTTP
* Set logger to go-cve-dictionary client
* Add -to-localfile
* Add -to-http option to report
* Load -to-http conf from config.toml
* Support gost (#676 )
* feat(gost): Support RedHat API
* feat(gost): Support Debian Security Tracker
* feat(db): display error msg when SQLite3 is locked at the beginning of reporting.
* feat(gost): TUI
* Only use RedHat information of installed packages
* feat(tui): show mitigation on TUI
* feat(gost): support redis backend
* fix test case
* fix nil pointer when db is nil
* fix(gost): detect vulns of src packages for Debian
* feat(gost): implement redis backend for gost redhat api
* feat(report): display fixState of unfixed pkgs
* fix(report): display distincted cweIDs
* feat(slack): display gost info
* feat(slack): display mitigation
* feat(report): display available patch state as fixed/total
* fix(tui): display - if source of reference is empty
* update deps
* fix(report): key in ScanResult JSON be lowerCamelcase.
* some keys to lower camel
* fix(configtest): dep check logic of yum-plugin-ps
* fix(tui): format
* feat(report): add -format-list option
* fix(report): -format-full-text
* fix(report): report -format-full-text
* fix(report): display v3 score detected by gost
* fix(scan): scan in fast mode if not defined in config.toml
* fix(gost): fetch RedHat data for fixed CVEs
* feat(report): show number of cves detected in each database
* fix(report): show new version as `Unknown` in offline and fast scan mode
* fix(report): fix num of upadtable and fixed
* fix(report): set `Not fixed yet` if packageStatus is empty
* refact(gost): make convertToModel public
* fix(test): fix test case
* update deps
* fix(report): include gost score in MaxCvssScore
* [WIP] feat(config): enable to set options in config.toml instead of cmd opt (#690 )
* feat(config): enable to set options in config.toml instead of cmd opt
* fix(config): change Conf.Report.Slack to Conf.Slack
* fix(discover): change tempalte
* fix(report): fix config.toml auto-generate with -uuid
* Add endpoint for health check and change endpoint
* refact(cmd): refactor flag set
* fix(report): enable to specify opts with cmd arg and env value
* fix(scan): enable to parse the release version of amazon linux 2
* add(report) add -to-saas option (#695 )
* add(report) add -to-saas option
* ignore other writer if -to-saas
* fix(saas) fix bug
* fix(scan): need-restarting needs internet connection
* fix(scan,configtest): check scan mode
* refactor(scan): change func name
* fix(suse): support offline mode, bug fix on AWS, zypper --no-color
* fix(tui): fix nil pointer when no vulns in tui
* feat(report): enable to define CPE FS format in config.toml
* fix(vet): fix warnings of go vet
* fix(travis): go version to 1.11
* update deps
2018-08-27 13:51:09 +09:00
Masayuki Matsuki
d785fc2a54
Lint ( #700 )
...
* adjust GNUmakefile by using ... wildcard
go command excludes vendored packages from ... wildcard Go1.9 or later
* fix vet warnings
* fmt
2018-08-26 21:22:37 +09:00
Kota Kanbe
ea800e04bc
fix(report): generate report even if some scan-err-jsons are included #685 ( #686 )
2018-07-24 22:26:46 +09:00
kota kanbe
fe582ac635
Change GitHub templates
2018-07-19 10:04:31 +09:00
Takayuki Ushida
330edb3bce
change copyright ( #677 )
2018-07-17 15:10:36 +09:00
Teppei Fukuda
212fec7115
Remove old Dockerfile ( #684 )
2018-07-12 21:02:59 +09:00
Teppei Fukuda
24d7021c47
Refactor Dockerfile ( #683 )
2018-07-12 20:28:18 +09:00
Kota Kanbe
e3a01ff6a8
fix(report): database is locked with SQLite3 backend #681 ( #682 )
2018-07-11 11:11:57 +09:00
Kota Kanbe
81f2ba8a46
fix(report): record not found on reporting with OVAL #679 ( #680 )
...
* fix(report): record not found on reporting with OVAL #679
* lock go version in .travis.yml
2018-07-10 15:14:35 +09:00
Kota Kanbe
9e9370b178
refactor(suse): add testcase for detectSUSE ( #675 )
...
* refactor(suse): add testcase for detectSUSE
2018-06-25 14:46:41 +09:00
jenningsloy318
ced6114a95
pull request to add SLES variant OS SLES_SAP support ( #672 )
...
* add SLES_SAP fix
* add SLES_SAP version regexp
2018-06-25 14:34:40 +09:00
Teppei Fukuda
3144faae5d
feat(syslog): add all CVSS scores/vectors ( #664 )
2018-06-06 20:56:56 +09:00
Teppei Fukuda
8960c67a82
fix(report): use CVSS score not calculated from severity preferentially ( #663 )
2018-06-06 18:58:24 +09:00
Teppei Fukuda
f8ca924434
Add title to syslog ( #662 )
2018-06-06 10:36:59 +09:00
Kota Kanbe
399a08775e
feat(scan): add -ssh-config option #417 ( #660 )
2018-05-31 12:39:46 +09:00
Zsolt
92f36ca558
Add missing ca-certificates, needed for slack webhook ( #657 )
2018-05-24 10:16:13 +09:00
Zsolt
3dcc58205a
Move to alpine based docker images ( #643 )
2018-05-23 15:32:05 +09:00
Kota Kanbe
09779962cf
Fix(reporting): NotFixedYet of SourcePackage in OVAL match on Debian and Ubuntu ( #656 )
...
* fix(refactoring): oval
* Fix(reporting): NotFixedYet of SourcePackage in OVAL match on Debian and Ubuntu #655
2018-05-22 18:53:08 +09:00
Kota Kanbe
9cc78770a3
fix(configtest): Only warning when reboot-notifier is not installed on Debian ( #654 )
2018-05-21 14:57:05 +09:00
Zsolt
f653ca9131
Don't check reboot-notifier package for debian containers ( #642 )
2018-05-21 14:11:59 +09:00
Teppei Fukuda
6f9fd91849
Send logs via syslog when no CVE-IDs found ( #646 )
2018-05-17 12:04:23 +09:00
Teppei Fukuda
cb1aec4fc0
Add scanned_at into syslog report ( #641 )
2018-05-11 11:17:45 +09:00
Kota Kanbe
7cebaf8a76
Use servername for SSH ControlPath filename ( #640 )
2018-05-09 16:45:03 +09:00
Kota Kanbe
241c943424
fix(tui): show CVSS severity on TUI for Ubuntu ( #638 )
...
* fix(tui): show CVSS severity on TUI for Ubuntu
* refactoring
2018-05-02 17:07:20 +09:00
kazuminn
d5d88d8cf0
Refactor stride ( #637 )
...
* refactor
* go fmt
2018-05-02 16:58:29 +09:00
nohararc
cf9d26068c
Update README.md ( #631 )
...
fix typo.
2018-04-27 15:52:40 +09:00
Cyrille Hemidy
308a93dc72
misspell ( #632 )
...
* Update tomlloader.go
fix misspelling
* Update packages.go
fix misspelling
* Update scanresults.go
fix misspelling
2018-04-27 15:52:16 +09:00
kota kanbe
d6a7e65e4c
[refactor]make fmt
2018-04-27 15:07:12 +09:00
kazuminn
e0a5c5d3b8
refactoring : hipchat ( #635 )
...
* refactoring
2018-04-27 15:04:35 +09:00
adachin
314f775243
Chatwork support ( #634 )
2018-04-27 14:59:58 +09:00
kazuminn
7a1644135a
Stride support ( #624 )
2018-04-10 13:30:22 +09:00
Kota Kanbe
5076326589
Fix Amazon Linux 2 scanning ( #630 )
...
* fix(amazon2): fix OS version parse error
2018-04-10 11:53:11 +09:00
Kota Kanbe
ce56261b52
fix(redhat): fix detection method of changelog scan ( #628 )
...
fix(redhat, deepscan): fix detection method of changelog scan
2018-03-29 21:17:44 +09:00
Kota Kanbe
baa0e897b2
fix: a bug of diff logic when multiple oval defs found for a certain CVE-ID and same updated_at ( #627 )
...
* fix: a bug of diff logic when multiple oval-defs hav certain CVE-ID and same updated_at
Commented out beause a bug of diff logic when multiple oval defs has certain CVE-ID and same updated_at.
If these OVAL defs have different affected packages, this logic detects not-updated-CVE-ID as updated.
This logic will be uncommented after integration with ghost https://github.com/knqyf263/gost
2018-03-26 22:29:14 +09:00
Teppei Fukuda
1d49c0e1ce
fix(scan): fix RHEL 5 ( #626 )
2018-03-26 17:40:39 +09:00
Teppei Fukuda
08755e446e
fix(fmt): fix gofmt warn ( #625 )
2018-03-23 12:28:12 +09:00
Kota Kanbe
bb12d9dadb
Add diff to TUI ( #620 )
...
* fix: change ControlPath to .vuls of SSH option (#618 )
* feat: Add diff option to TUI
2018-03-16 15:18:10 +09:00
Kota Kanbe
fd1429fef0
Fix diff logic ( #619 )
...
* fix: change ControlPath to .vuls of SSH option (#618 )
* fix: Bug of diff logic
2018-03-16 15:07:26 +09:00
kazuminn
d3c421a4a8
inform new release on diff option ( #614 )
...
inform new release on diff option (#614 )
2018-03-15 13:30:33 +09:00
Kota Kanbe
0c919da4b1
fix: change ControlPath to .vuls of SSH option ( #618 )
2018-03-14 16:39:17 +09:00
Kota Kanbe
9afbf1255f
feat: Add -vvv option to scan cmd ( #617 )
2018-03-14 12:18:03 +09:00
Kota Kanbe
50b105c4af
fix: SSH session multiplexing ( #616 )
2018-03-13 22:35:25 +09:00
kazuminn
028508c1f7
fix link nvd on hipchat ( #613 )
2018-03-13 12:32:55 +09:00
Kota Kanbe
f0137a3695
feat: Display pkg information to slack notification #611 ( #612 )
2018-03-09 10:26:41 +09:00
Kota Kanbe
e6d3a1718c
fix: validation for reporting ( #610 )
2018-03-07 14:01:52 +09:00
Kota Kanbe
86ba551e07
fix: remove a validation of hipchat ( #609 )
2018-03-07 05:21:57 +09:00
kazuminn
26418be937
hipchat support ( #593 )
...
* first commit
* hipchat conf
* hipchat conf
2018-03-06 17:40:21 +09:00
Kota Kanbe
092a19bdc1
fix: bug of report -diff option ( #607 )
2018-03-06 16:50:09 +09:00
Kota Kanbe
6d3398574c
fix: support CentOS cloud image ( #606 )
...
https://bugzilla.redhat.com/show_bug.cgi?id=1332025
2018-03-06 14:10:21 +09:00
Teppei Fukuda
b08969ad89
Support a reporting via Syslog ( #604 )
...
* Support a reporting via syslog
* Update dependencies
2018-02-27 20:38:34 +09:00
Kota Kanbe
0653656526
fix: add some logging for goval-dictionary ( #603 )
2018-02-19 13:30:42 +09:00
Teppei Fukuda
7a5793c562
Add IP address to scan results ( #602 )
2018-02-19 12:50:00 +09:00
Emilien Kenler
562ff7807d
Support AWS S3 Server-Side Encryption ( #597 )
...
* Support AWS S3 Server-Side Encryption
* Improve documentation for aws-s3-server-side-encryption
2018-02-12 11:26:23 +09:00
Kota Kanbe
7971bdf7f7
fix: Kindness error message in reporting ( #601 )
2018-02-12 10:57:09 +09:00
Kota Kanbe
d926b7fd6d
Update deps ( #592 )
2018-01-24 01:02:02 +09:00
Kota Kanbe
c00404793a
Add offline option to scan and configtest ( #588 )
...
Add offline option to scan and configtest
2018-01-19 01:07:44 +09:00
Kota Kanbe
a0e0ee6c1e
Move README to Vulsdoc https://vuls.io ( #586 )
2018-01-17 18:03:37 +09:00
Kota Kanbe
4ccbee705b
If the OWASP dc XML does not exist, continue reporting after warning #580 ( #582 )
2018-01-16 17:08:12 +09:00
Mai MISHIRO
db43d55b2c
Fixed panic occurred when blank line continued in changelog ( #569 )
2018-01-05 10:23:44 +09:00
~Stack~
5a3a333eec
Fixed Typo ( #574 )
2018-01-05 10:20:35 +09:00
nakamurakyo
039edf1616
fix typo(BackSpace) in README.ja.md ( #576 )
2018-01-05 10:20:06 +09:00
Kota Kanbe
47498bbf23
Fix a bug of sending to closed socket while oval access via HTTP #578 ( #579 )
2018-01-05 10:12:21 +09:00
Yoshikazu Aoyama
cc28bf4ae2
fix typo in reports/s3.go ( #573 )
2017-12-27 22:30:26 +09:00
Mai MISHIRO
0e8736045e
LXC container support without LXD ( #552 )
...
* LXC container support without LXD
* Fix: LXC required root privilege
* Update README
2017-12-18 22:54:32 +09:00
Kota Kanbe
19b581edef
Support Amazon Linux2 ( #562 )
2017-12-15 20:07:49 +09:00
Mai MISHIRO
295f6656d9
Fix #548 and #557 - RHEL's Fast Scan no longer required internet connection and root privilege ( #559 )
2017-12-15 19:34:10 +09:00
Mai MISHIRO
1214d8c14d
Change error handling of "Reboot Required" detection ( #556 )
2017-12-12 17:03:42 +09:00
Mai MISHIRO
b4cd96fc9a
Fix some RPM related commands failed in the container ( #554 )
2017-12-12 12:14:57 +09:00
Davor Kapsa
3238a9b898
travis: update go version ( #555 )
2017-12-11 14:35:13 +09:00
Mai MISHIRO
c0f66320f6
Add more kernel related packages ( Fix #541 ) ( #551 )
2017-12-11 14:32:20 +09:00
Kota Kanbe
383220f384
Remove empty CveContent output to JSON with Alpine Linux scan ( #550 )
2017-12-04 12:52:32 +09:00
Takayuki Ushida
76a9c37e6b
Update README ( #547 )
2017-12-02 00:47:49 +09:00
Kota Kanbe
e788e6a5ad
Support Alpine Linux #194 ( #545 )
...
* Support Alpine Linux #194
* Fix testcase
* Fix README
* Fix dep files
* Fix changelog
* Bump up version
2017-12-01 23:17:28 +09:00
Flaviu
d00e912934
Replace strings.HasPrefix with strings.Index for SuSE scanner ( #546 )
2017-11-21 11:37:43 +09:00
Kota Kanbe
8ebb663368
Fix yum changelog option ( #543 )
2017-11-15 17:32:17 +09:00
nnao45
445ffc4123
Update README.md ( #542 )
2017-11-14 17:05:12 +09:00
Kota Kanbe
6af49f4d55
Fix false positive: ignore oval info when kernel major version is different. ( #541 )
2017-11-10 23:33:43 +09:00
Mai MISHIRO
1de9e8c086
Fix: Misdetection of OvalMatch for CentOS and Scientific in oval/util.go ( #536 )
...
* Fix: Misdecection of OvalMatch for CentOS in oval/util.go
* Remediation: Misdetection of OvalMatch for Scientific (currently treated as RHEL) oval/util.go
* The regular expression was changed because the release number of CentOS and Scientific's unchanged package is different from upstream.
* OvalMatch test of RedHat and CentOS has been added.
2017-11-09 11:20:23 +09:00
Mai MISHIRO
59b0812adf
Fix: "Reboot Required" detection process in scan/redhat.go ( #534 )
2017-11-08 17:16:59 +09:00
kota kanbe
719785c1ed
Remove README.fr.md because unable to maintenance..
2017-11-08 16:11:03 +09:00
nakacya
8e5f627e59
README Typo Update ( #538 )
...
* Update README.ja.md
Typo Update
* Update README.md
Typo Update
2017-11-08 15:57:18 +09:00
Kota Kanbe
5ced3c72b8
Insert sudo only at the beginning of command in deep scan #495 ( #539 )
...
* Insert `sudo` only at the beginning of command in deep scan #495
* Fix testcase
2017-11-08 15:48:43 +09:00
Kota Kanbe
c002f0168c
Fix config.toml validation ( #537 )
2017-11-06 09:56:18 +09:00
Kota Kanbe
00c690f516
Add pseudo server type for non-ssh scanning (only cpe scan) #512 ( #531 )
...
* Add pseudo server type for non-ssh scanning (only cpe scan) #512
* Don't check hostname for pseudo type
* Update README.md
2017-11-02 17:02:06 +09:00
nakacya
ab68ad5cc5
README Update ( #530 )
...
* README.ja.md Update
Add Update steps
* Update README.ja.md
* Update README.ja.md
* README.md update
Add Update steps
2017-10-30 13:24:46 +09:00
kota kanbe
5c84ebefab
Update README
2017-10-26 14:54:15 +09:00
sadayuki-matsuno
eb2acaff22
send slack msg by api ( #525 )
2017-10-26 13:30:01 +09:00
shimojomasatsugummm
84d0655c52
fix typo Privious -> Previous ( #523 )
2017-10-25 18:51:29 +09:00
nashiox
e137ebb9c2
Fix package query fails on debian based container ( #519 ) ( #522 )
...
* Fix package query fails on debian based container (#519 )
* Fix executil test (#519 )
2017-10-25 18:49:47 +09:00
atsu
10d690d929
fix typo from "enviroment" to "environment" ( #518 )
2017-10-21 18:28:53 +09:00
yuu26
14611d2fd9
Fix typo in config/jsonloader.go ( #517 )
2017-10-20 14:34:48 +09:00
x-blood
0665bfe15f
Modified Spell Miss of "README.md". ( #516 )
...
* Modified spell miss of README.md. 1305:Calculator
* Revert "Modified spell miss of README.md. 1305:Calculator"
This reverts commit 0e0db1be8d .
* Modified spell miss of README.md. line:1305"Calculator"
2017-10-20 14:02:16 +09:00
kota kanbe
473096d35d
Fix .goreleaser.yml
2017-10-19 14:31:35 +09:00
kota kanbe
0eae26e261
Merge branch 'master' of https://github.com/future-architect/vuls
...
* 'master' of https://github.com/future-architect/vuls :
Fix a bug of making channels when fill oval information via HTTP (#514 )
2017-10-17 13:37:06 +09:00
Kota Kanbe
a32845f652
Fix a bug of making channels when fill oval information via HTTP ( #514 )
...
* Fix a bug of making channels when fill oval information via HTTP
2017-10-17 13:36:49 +09:00
kota kanbe
15a0f7eadb
Merge branch 'master' of https://github.com/future-architect/vuls
...
* 'master' of https://github.com/future-architect/vuls :
Fix OVAL detection on Debian and Ubuntu (#509 )
2017-10-16 14:13:40 +09:00
Kota Kanbe
5a0a6abf11
Fix OVAL detection on Debian and Ubuntu ( #509 )
...
* Add filter options to tui subcommand (#508 )
* Capture version of source packages on Debian based linux
* Change makefile, gofmt -s
* Refactoring
* Implement OVAL detection of source packages for Debian, Ubuntu
2017-10-13 17:22:11 +09:00
kota kanbe
032b8d9572
Merge branch 'master' of https://github.com/future-architect/vuls
...
* 'master' of https://github.com/future-architect/vuls :
Add filter options to tui subcommand (#508 )
2017-09-29 08:41:31 +09:00
Kota Kanbe
5798e3af83
Add filter options to tui subcommand ( #508 )
2017-09-29 08:37:32 +09:00
Kota Kanbe
8e15b9ce1c
Add filter options to tui subcommand ( #508 )
2017-09-28 18:31:09 +09:00
Kota Kanbe
7a1f132c1f
Add -ignore-unfixed option to report subcommand #485 ( #507 )
2017-09-28 17:29:47 +09:00
Emilien Kenler
a8483b2195
Add goreleaser to distribute binaries ( #460 )
...
See https://github.com/future-architect/vuls/issues/459
2017-09-28 15:29:27 +09:00
kota kanbe
83bbbd0cb0
Add goreportcard to README
2017-09-28 15:23:51 +09:00
Kota Kanbe
132432dce6
Support SUSE Enterprise Linux ( #487 )
...
* Support SUSE Enterprise Linux
* Implement Reboot Required detection on SLES
* Fix query OVAL because SUSE provides OVAL data each major.minor version
* Update README
* Support SUSE Enterprise 11
2017-09-28 12:23:19 +09:00
Xiuming Chen
e5eb8e42f5
Debian: Use --showformat flag to get status of packages and ignore n(not-inst… ( #484 )
...
* Use --showformat flag to get status of packages and ignore n(not-installed) and c(removed, only has config files remaining) packages.
* Ignoring all packages that are not in 'Installed' status.
* Simplify char escaping in the command.
* Fix typo.
2017-09-27 09:43:59 +09:00
Takayuki Ushida
1095ebea24
fix vulsrepo dockerfile ( #496 )
2017-09-26 18:17:46 +09:00
328
1541a602b2
Update README.ja.md ( #498 )
2017-09-26 18:17:19 +09:00
~Stack~
03a141c252
Fix typos ( #499 )
...
* Update bolt.go
Fix typos
* Update util.go
Fix Typos
2017-09-26 18:16:54 +09:00
Kota Kanbe
5f2183fc8e
Check repoquery with sudo nopasswd in deep scan mode on RedHat ( #492 )
2017-09-14 09:14:20 -07:00
Kota Kanbe
820831fa5d
Fix sort order of servers on TUI ( #481 )
2017-09-05 15:54:13 +09:00
Kota Kanbe
6d2d767c52
Fix a arg of report subcommand ( #479 )
2017-09-04 14:47:25 +08:00
Kota Kanbe
e0c3a728ae
Fix ping option of discover subcommand #471 ( #472 )
2017-08-30 14:13:53 +08:00
sadayuki-matsuno
ec92f7797f
add windows type ( #470 )
2017-08-28 18:49:34 +08:00
Kota Kanbe
0ba490c6df
Merge pull request #469 from usiusi360/use_vulsrepo-server
...
use_vulsrepo-server
2017-08-25 21:59:52 +09:00
usiusi360
cfd668e11d
use_vulsrepo-server
2017-08-25 21:42:33 +09:00
kota kanbe
a8bc25321e
Update Changelog.md
2017-08-25 11:21:31 +08:00
Kota Kanbe
fec13bcb86
Merge pull request #449 from future-architect/support_oval
...
v0.4.0
2017-08-25 11:20:02 +09:00
kota kanbe
cb1c07f998
Update README
2017-08-25 10:08:41 +08:00
Yasunari Momoi
6312b97faa
fix typos in commands. ( #464 )
2017-08-23 19:29:31 +09:00
sadayuki-matsuno
21f13b55eb
export fill cve info ( #467 )
2017-08-23 18:09:22 +09:00
kota kanbe
187598382b
Update README
2017-08-23 17:38:23 +09:00
kota kanbe
551fdd5022
Display "Reboot Required" on report if the kernel has been updated but not restarted
2017-08-23 13:59:19 +09:00
kota kanbe
58b0d03e28
No escape on details view in TUI
2017-08-23 12:02:58 +09:00
kota kanbe
3790197699
Fix ignoreCves option
2017-08-22 20:28:24 +09:00
kota kanbe
579fff122c
Merge branch 'support_oval' of https://github.com/future-architect/vuls into dev_v0.4.0
...
* 'support_oval' of https://github.com/future-architect/vuls :
add oval docker (#466 )
2017-08-22 18:14:43 +09:00
kota kanbe
feb3f79a13
Update Gopkg
2017-08-22 18:14:00 +09:00
kota kanbe
b5cb08ac43
Handle kernel's vulns using OVAL
2017-08-22 17:44:50 +09:00
sadayuki-matsuno
4ac5d9e0da
add oval docker ( #466 )
...
* add oval docker
* Update README.md
2017-08-22 12:40:54 +09:00
kota kanbe
93f741da35
Show Not Fixed Yet in report, tui
2017-08-19 00:21:11 +09:00
kota kanbe
648a999514
Include config in json result
2017-08-18 22:39:45 +09:00
kota kanbe
71490aebd9
Fix sudo in deep scan of RHEL
2017-08-17 21:17:13 +09:00
kota kanbe
9e90c0f912
Implement NotFixedYet for CentOS
2017-08-17 20:07:39 +09:00
kota kanbe
de65073f61
Set NotFixedYet for Ubuntu Scan
2017-08-17 15:32:22 +09:00
kota kanbe
6129ac7bd4
Change model ScanResult.ScannedCves.AffectedPackages
2017-08-17 12:18:06 +09:00
kota kanbe
b5d4d27312
Fix "Vulnerable package: is not found" error on FreeBSD
2017-08-16 14:34:59 +09:00
kota kanbe
823fcd91f4
Merge branch 'support_oval' of https://github.com/future-architect/vuls into dev_v0.4.0
...
* 'support_oval' of https://github.com/future-architect/vuls :
Update README.ja.md
2017-08-16 11:54:45 +09:00
kota kanbe
477e12d5cf
Fix FreeBSD detection
2017-08-16 11:54:19 +09:00
Kota Kanbe
a36a226ae2
Update README.ja.md
2017-08-15 17:29:14 +09:00
kota kanbe
886a21c633
Bump up version to 0.4.0
2017-08-15 10:43:59 +09:00
kota kanbe
fd19fa2082
nosudo repoquery
2017-08-15 10:37:11 +09:00
kota kanbe
843f1a462f
Fix checkDependencies for redhat.go
2017-08-14 15:53:11 +09:00
kota kanbe
5c5b8a361d
Merge branch 'support_oval' of https://github.com/future-architect/vuls into dev_v0.4.0
...
* 'support_oval' of https://github.com/future-architect/vuls :
Update README (#463 )
2017-08-14 00:07:54 +09:00
Kota Kanbe
417df0582d
Update README ( #463 )
2017-08-14 00:07:39 +09:00
kota kanbe
999d8f5866
Update README
2017-08-14 00:05:20 +09:00
kota kanbe
47a444e795
Use CVE>Impact as severity when it is not empty (RedHat OVAL)
2017-08-13 22:17:25 +09:00
kota kanbe
dbceca8780
Update Gopkg.lock
2017-08-13 21:51:43 +09:00
kota kanbe
c66898e608
Set actually affected package's name only to vulnInfo.PackageNames
2017-08-13 20:50:26 +09:00
kota kanbe
ee20cb59a5
Refactoring
2017-08-13 17:56:12 +09:00
kota kanbe
5c51d83573
Refactoring
2017-08-13 17:18:01 +09:00
kota kanbe
47b3b3848b
Refactoring
2017-08-13 15:31:14 +09:00
sadayuki-matsuno
95eb980f58
export FillWithOval ( #462 )
2017-08-11 17:27:10 +09:00
kota kanbe
f738622c28
Update png in README.md
2017-08-11 13:31:02 +09:00
kota kanbe
577509bbf9
Fix MaxCvssScore logic
2017-08-09 16:18:09 +09:00
kota kanbe
774c78add0
Fix oval-db existence check on reporting
2017-08-09 16:18:09 +09:00
kota kanbe
b14406e329
Fix check logic of dependent packages in redhat.go
2017-08-09 16:18:09 +09:00
kota kanbe
29cf4bb517
Setup changelog cache only when necessary
2017-08-09 16:18:09 +09:00
kota kanbe
a233e08929
When scanning raspbian, always scan with deep scan mode
2017-08-09 16:18:09 +09:00
sadayuki-matsuno
cbd1c12773
add s3 dirctory option ( #457 )
2017-08-09 16:18:08 +09:00
sadayuki-matsuno
0a3f0f9ffc
add serveruuid field ( #458 )
2017-08-09 16:18:08 +09:00
kota kanbe
d3014025b0
Update README
2017-08-09 16:18:08 +09:00
kota kanbe
2887dc0d36
Fix configtest to match fast and deep scan mode
2017-08-09 16:15:25 +09:00
kota kanbe
5f49e7da8e
Refactoring
2017-08-09 16:15:25 +09:00
kota kanbe
9e0032b258
Fix cvss link in slack notification
2017-08-09 16:15:25 +09:00
kota kanbe
008da49b83
Imlement OVAL scan on Oracle Linux
2017-08-09 16:15:25 +09:00
kota kanbe
9899cba816
Display summary of advisory when no entry in NVD, OVAL
2017-08-09 16:15:25 +09:00
kota kanbe
27724a2faf
Use CVSS seveirty of distro advisory when no entiry in NVD and OVAL
2017-08-09 16:15:25 +09:00
kota kanbe
8b6a283114
Add a deep flag to scan
2017-08-09 16:15:25 +09:00
kota kanbe
4379b8bacf
Use version comparison logic when parsing change log (Ubuntu, Debian)
2017-08-09 16:15:25 +09:00
kota kanbe
56603dcfae
Fix a bug of lower limit of cursor movement in TUI
2017-08-09 16:15:25 +09:00
kota kanbe
1752736714
Fix nil pointer
2017-08-09 16:15:25 +09:00
kota kanbe
b1428b6758
Fix a bug of fill oval information of Ubuntu
2017-08-09 16:15:25 +09:00
kota kanbe
9b6d84def6
Fix false positive detection on RHEL, Amazon and Oracle
2017-08-09 16:15:25 +09:00
kota kanbe
ed162d7d6e
Display the information of yum updateinfo on TUI (for RHEL, Amazon, Oracle)
2017-08-09 16:15:25 +09:00
kota kanbe
1aae425945
Undisplay the number of CVEs at the end of 'scan --package-list-only'
2017-08-09 16:15:25 +09:00
kota kanbe
26e447f11a
Check existence and last modified time of local OVAL database when reporting
2017-08-09 16:15:25 +09:00
Kota Kanbe
ffbaa0a508
Extract Advisory.Description on RHEL, Amazon, Oracle ( #450 )
2017-08-09 16:15:25 +09:00
Kota Kanbe
a9ebac3818
nosudo on CentOS and Fetch Changelogs on Amazon, RHEL ( #448 )
...
* Use repoquery for no sudo and avoid unintended line feed of yum or rpm. #444
* Change data type of enablerepo in config.toml. string to array
* Fetch yum changelogs at once then grep CVE-IDs
* Fix changelog parse logic and Update Gopkg
2017-08-09 16:15:25 +09:00
sadayuki-matsuno
738e9fb119
change logrus package to lowercase and update other packages ( #446 )
2017-08-09 16:15:25 +09:00
sadayuki-matsuno
7778783dd8
add db backend redis ( #445 )
2017-08-09 16:15:25 +09:00
Kota Kanbe
c442a433b0
Add OVAL HTTP health check
2017-08-09 16:15:24 +09:00
Kota Kanbe
f7aa85746d
Add retry-max to HTTP access
2017-08-09 16:15:24 +09:00
Kota Kanbe
1883da3b2a
Implement HTTP access to oval-dictionary
2017-08-09 16:15:24 +09:00
Kota Kanbe
997dd6022f
Kind error message when SSH connection fails
2017-08-09 16:15:24 +09:00
Kota Kanbe
63394a2400
Fix error handling while loading JSON in reporting
2017-08-09 16:15:24 +09:00
Kota Kanbe
a662b038dc
Fix CVSS2 in TUI
2017-08-09 16:15:24 +09:00
Kota Kanbe
e9df2bfa01
Convert null to empty in JSON
2017-08-09 16:15:24 +09:00
Kota Kanbe
a7951b727c
Remove commented out code
2017-08-09 16:15:24 +09:00
Kota Kanbe
c6ad9ea57a
Fix tui
2017-08-09 16:15:24 +09:00
Kota Kanbe
a14810bbd4
Fix -to-slack
2017-08-09 16:15:24 +09:00
Kota Kanbe
bc5a95ebb3
Fix -to-email
2017-08-09 16:15:24 +09:00
Kota Kanbe
306182e2ae
Fix test cases
2017-08-09 16:15:24 +09:00
Kota Kanbe
ad096196ee
Add vendor links to -format-shor-text
2017-08-09 16:15:24 +09:00
Kota Kanbe
af66e44427
SHow Vendor Links in text report
2017-08-09 16:15:24 +09:00
Kota Kanbe
0a012273ec
Fix -ignore-unscored-cves
2017-08-09 16:15:24 +09:00
Kota Kanbe
73b011eba7
Sort results order by CVSS score, CVE-ID
2017-08-09 16:15:24 +09:00
Kota Kanbe
a31974a3c0
Use Severity ranking in OVAL when the CVSS scores are empty.
2017-08-09 16:15:24 +09:00
Kota Kanbe
eb02bdd95a
Add test cases of models.Packages
2017-08-09 16:15:24 +09:00
Kota Kanbe
74805c6be8
Add test cases of CveContents
2017-08-09 16:15:24 +09:00
Kota Kanbe
d9bc4499a4
Refactoring
2017-08-09 16:15:24 +09:00
Kota Kanbe
9128e2748b
Refactoring
2017-08-09 16:15:24 +09:00
Kota Kanbe
7f8c975bd7
Avoid concurrent Map writes
2017-08-09 16:15:24 +09:00
Kota Kanbe
8b6c841b1e
Fix TestCase
2017-08-09 16:15:24 +09:00
Kota Kanbe
4fcdea3ccb
Implement -format-full-text
2017-08-09 16:15:24 +09:00
Kota Kanbe
3be11cf52f
Implement format-short-text
2017-08-09 16:15:24 +09:00
Kota Kanbe
b285cb0e57
Remove CRUD funcs of CveContents
2017-08-09 16:15:24 +09:00
Kota Kanbe
dd5a7920e5
Add JSON Version
2017-08-09 16:15:24 +09:00
Kota Kanbe
cfb848918f
Change structure of ScanResult.[]VulnInfo to Map
2017-08-09 16:15:24 +09:00
Kota Kanbe
b977558f38
Change structure of VulnInfo.Pacakges to []string
2017-08-09 16:15:24 +09:00
Kota Kanbe
210e3dc990
Change ScanResult.Packages structure to Map
2017-08-09 16:15:24 +09:00
Kota Kanbe
f36671784e
Fix testcase
2017-08-09 16:15:24 +09:00
Kota Kanbe
d626cc8a8b
Rename PackageInfoList to Packages
2017-08-09 16:15:24 +09:00
Kota Kanbe
f26b61d773
Change CveContents data type to map
2017-08-09 16:15:24 +09:00
Kota Kanbe
12c2d3cbc6
Fix test cases
2017-08-09 16:15:24 +09:00
Kota Kanbe
209ca704de
Fixed a bug caused by capturing epoch number on RedHat.go
2017-08-09 16:15:24 +09:00
Kota Kanbe
2e37d3adc1
Improve sort logics
2017-08-09 16:15:24 +09:00
Kota Kanbe
509fb045b6
Refactoring diff logic
2017-08-09 16:15:24 +09:00
Kota Kanbe
a2c364f9eb
Refacotring
2017-08-09 16:15:23 +09:00
Kota Kanbe
17a4e532c1
Fix testcase
2017-08-09 16:15:23 +09:00
Kota Kanbe
c103b79ec2
Change models structure
2017-08-09 16:15:23 +09:00
Kota Kanbe
b545b5d0a3
Unify the models of NVD, JVN, OVAL
2017-08-09 16:15:23 +09:00
Kota Kanbe
342a1c6cff
Refactoring
2017-08-09 16:15:23 +09:00
Kota Kanbe
aafbdcd34d
Fix testcase
2017-08-09 16:15:23 +09:00
Kota Kanbe
ec092501c3
[BreakingChange]Remove models.ScanHistory
2017-08-09 16:15:23 +09:00
Kota Kanbe
bb708db89f
Make it work on FreeBSD
2017-08-09 16:15:23 +09:00
Kota Kanbe
085a9dcb79
Fix Test Case
2017-08-09 16:15:23 +09:00
Kota Kanbe
037e12b0bd
Add Ubuntu Support
2017-08-09 16:15:23 +09:00
Kota Kanbe
c9ab956f8f
Make it work on Amazon Linux
2017-08-09 16:15:23 +09:00
Kota Kanbe
587c87b3a0
Fix RHEL oval scan
2017-08-09 16:15:23 +09:00
Kota Kanbe
1a319859eb
Include RHEL, CentOS epoch number in version
2017-08-09 16:15:23 +09:00
knqyf263
c989c31aeb
Support RHEL
2017-08-09 16:15:23 +09:00
Kota Kanbe
e5d32c8764
Debian Report using OVAL
2017-08-09 16:15:23 +09:00
Kota Kanbe
23c177ed4a
-package-list-only for Debian
2017-08-09 16:15:23 +09:00
knqyf263
10a27042b5
Support Debian
2017-08-09 16:15:23 +09:00
Takayuki Ushida
2cec20c7ee
Fix when reading tui config.toml ( #441 )
2017-08-08 20:35:04 +09:00
sadayuki-matsuno
7ecd09f497
fast go test ( #435 )
2017-06-24 00:51:48 +09:00
sadayuki-matsuno
8bf7f6cac5
fix typo ( #433 )
2017-06-24 00:51:12 +09:00
sadayuki-matsuno
067a2315df
Add support for PostgreSQL as a DB storage back-end ( #431 )
2017-06-20 17:29:44 +09:00
ryurock
fecd1ad464
typo README.js.md ( #426 )
2017-04-24 23:30:05 +09:00
Kota Kanbe
a3f2555bc1
Add TOC to README ( #425 )
...
Add TOC to README
2017-04-22 21:02:26 +09:00
Teppei Fukuda
5bf4cd46ff
Enable -timeout option when detecting OS ( #410 )
2017-04-22 18:39:13 +09:00
elfgoh
f878e225cc
Fixing #420 where lock and manifest have moved to TOML ( #421 )
...
https://github.com/golang/dep/pull/342
2017-04-14 15:06:37 +09:00
Ján Koščo
eb2598f3b3
Define timeout for vulnerabilities scan and platform detection ( #414 )
2017-04-09 16:25:45 +09:00
Kota Kanbe
e20a59b991
SSH Hostkey check ( #417 )
...
* Add Hostkey check as default behavior when SSH
2017-04-06 18:08:55 +09:00
Kota Kanbe
703c142659
Change NVD URL to new one ( #419 )
2017-04-06 18:08:24 +09:00
Kota Kanbe
8335b40368
Add some testcases ( #418 )
2017-04-06 13:09:51 +09:00
Kota Kanbe
05884c2d29
Change default ssh method from go library to external command ( #416 )
...
* Change default ssh method from go library to external command
2017-04-06 12:00:09 +09:00
Teppei Fukuda
33b2aa2d52
Add containers-only option to configtest ( #411 )
2017-04-04 14:34:56 +09:00
Kota Kanbe
9ab0622886
Fix SSH dial error ( #413 )
...
Error message:
[Apr 2 13:36:49] DEBUG [localhost] Failed to Dial to u16, err: ssh: must specify HostKeyCallback, Retrying in 552.330144ms...
It is caused by breaking changes of Go library.
https://go-review.googlesource.com/c/38701/
2017-04-02 14:01:30 +09:00
Kota Kanbe
b33cd54916
Update deps, Change deps tool from glide to dep ( #412 )
2017-04-01 20:06:28 +09:00
Paul Furtado
d4bec0dd9a
Add --user root to docker exec command ( #389 )
...
* Add --user root to docker exec command
If containers were run with their user set to something other than root,
docker exec will exec the command in the container as that user by
default. Unfortunately, this causes many package manager commands to
fail. This commit adds --user root to the docker exec command so that
commands executed inside the container will always run as root.
* Use numerical id for root rather than name
2017-03-31 18:58:00 +09:00
Teppei Fukuda
bdf6efeaac
Merge pull request #401 from knqyf263/fix_readme
...
Remove duplicate command in README
2017-03-31 12:13:53 +09:00
hogehogehugahuga
74431ca63f
fix report option Loaded error-info ( #406 )
2017-03-30 23:45:18 +09:00
knqyf263
c90be385ef
Remove duplicate command
2017-03-24 16:50:32 +09:00
Kota Kanbe
b0d9c0b550
Update Changelog
2017-03-24 14:55:28 +09:00
Kota Kanbe
9255132f9b
Bump up version
2017-03-24 14:37:48 +09:00
大沼
d5c0092fa3
fix typo ( #394 )
2017-03-24 00:25:23 +09:00
Teppei Fukuda
c7019debb9
Notify the difference from the previous scan result ( #392 )
...
add diff option
2017-03-23 23:58:05 +09:00
Kota Kanbe
7131270cad
Add timeout option to configtest ( #400 )
2017-03-23 20:52:25 +09:00
Kota Kanbe
af5a1204bc
Update README ( #387 )
...
Update Tutorial in README
2017-03-21 10:47:19 +09:00
Kota Kanbe
58afcfc49a
Fix nil-ponter in TUI ( #388 )
2017-03-17 16:46:42 +09:00
Avi Miller
986762ca85
Add Oracle Linux support ( #386 )
...
Adding support for Oracle Linux
2017-03-16 17:07:43 +09:00
Kota Kanbe
6342cf79f5
Merge pull request #383 from usiusi360/Fix_README
...
Fix README
2017-03-15 17:47:36 +09:00
Kota Kanbe
5fbf67f971
Merge pull request #384 from future-architect/mysql
...
Fix Bug of Mysql Backend
2017-03-15 16:51:25 +09:00
Kota Kanbe
e441e5a696
Fix Bug of Mysql Backend
2017-03-15 16:44:49 +09:00
usiusi360
d201efb029
Fix README
2017-03-15 13:53:42 +09:00
Kota Kanbe
25960126c7
Fix README
2017-03-15 12:35:50 +09:00
Kota Kanbe
63d5a6f584
Merge pull request #382 from beuno/patch-1
...
s/dictinary/dictionary typo
2017-03-15 10:32:36 +09:00
Martin Albisetti
2030951a8f
s/dictinary/dictionary typo
2017-03-14 16:50:36 -03:00
Kota Kanbe
cd841462cd
Merge pull request #381 from future-architect/container-excluded
...
Change container scan format in config.toml
2017-03-14 20:32:22 +09:00
Kota Kanbe
735aa835a6
Change container scan setting in config.toml
2017-03-14 20:07:51 +09:00
Kota Kanbe
92e213ca32
Merge pull request #379 from future-architect/fix-scan-confidence-on-debian
...
Fix scan confidence on Ubuntu/Debian/Raspbian #362
2017-03-13 21:03:12 +09:00
Kota Kanbe
d077c29716
Fix scan confidence on Ubuntu/Debian/Raspbian #362
2017-03-13 20:55:23 +09:00
Kota Kanbe
d6eba48a50
Merge pull request #377 from IMAI-Yuji/IMAI-Yuji-patch-1
...
Fix Japanese typo
2017-03-13 17:27:11 +09:00
Kota Kanbe
2a1608d1d2
Merge pull request #378 from future-architect/obsolete-centos5
...
Obsolete CentOS5 support
2017-03-13 17:04:36 +09:00
Kota Kanbe
cc7d3dc2aa
Obsolete CentOS5
2017-03-13 16:57:43 +09:00
Kota Kanbe
a5c4c682f5
Merge pull request #375 from future-architect/deprecate-prepare
...
Deprecate prepare subcommand to minimize the root authority defined by /etc/sudoers
2017-03-13 15:59:35 +09:00
Kota Kanbe
688cfd6872
Deprecate prepare subcommand to minimize the root authority #375
2017-03-13 13:21:01 +09:00
Yuji IMAI
7e268dbae1
Fix Japanese typo
2017-03-10 11:34:53 +09:00
Kota Kanbe
ce6a4231ef
Deprecate prepare subcommand to minimize the root authority defined by /etc/sudoers
2017-03-07 18:09:10 +09:00
Kota Kanbe
e1de8ab626
Merge pull request #370 from ohsawa0515/support_iam_role
...
Support IAM role for report to S3.
2017-03-07 14:07:32 +09:00
Kota Kanbe
0058eaf357
Merge pull request #374 from future-architect/package-count
...
Fix updatalbe packages count #373
2017-03-07 14:03:19 +09:00
Kota Kanbe
732d95098a
Fix updatalbe packages count #373
2017-03-07 13:49:25 +09:00
Shuichi Ohsawa
52f0943207
Add ec2 roles credentials.
2017-03-07 12:37:31 +09:00
Kota Kanbe
41f99f2b65
Merge pull request #372 from future-architect/sudo-check-update-rhel
...
sudo yum check-update on RHEL
2017-03-06 15:16:38 +09:00
Kota Kanbe
1f9e5c6263
sudo yum check-update on RHEL
2017-03-06 14:43:02 +09:00
Kota Kanbe
2f3eddd2ab
Merge pull request #369 from knqyf263/change_option
...
Change ssh option from -t to -tt
2017-03-06 14:37:29 +09:00
knqyf263
619a0ee700
Change ssh option from -t to -tt
2017-03-03 11:20:57 +09:00
Kota Kanbe
b1b5c2c9a0
Merge pull request #356 from future-architect/changelog
...
Output changelog in report, TUI and JSON for Ubuntu/Debian/CentOS
2017-03-02 22:28:29 +09:00
Kota Kanbe
a86035c0bf
Output changelog in report, TUI and JSON for Ubuntu/Debian/CentOS
2017-03-02 22:22:35 +09:00
Kota Kanbe
c66b0f4db4
Merge pull request #364 from knqyf263/increase_width
...
Increase the width of RequestPty
2017-03-01 12:15:23 +09:00
knqyf263
a4cf4bd314
Increase the width of RequestPty
2017-02-28 14:29:12 +09:00
Kota Kanbe
f1cd9383c1
Merge pull request #358 from ymomoi/remove-unused-import
...
remove unused import line.
2017-02-28 14:23:55 +09:00
Kota Kanbe
6fa57abe10
Merge pull request #363 from knqyf263/support_travis
...
Add .travis.yml
2017-02-28 13:08:42 +09:00
knqyf263
6e77c714b5
Add .travis.yml
2017-02-27 21:42:22 +09:00
Yasunari Momoi
fbab020e6e
remove unused import line.
2017-02-25 04:48:28 +09:00
Kota Kanbe
5581a5cce7
Merge pull request #354 from future-architect/mistook-english
...
Fix candidate to confidence.
2017-02-23 12:07:44 +09:00
Kota Kanbe
b4be11775e
Fix candidate to confidence.
2017-02-23 12:05:13 +09:00
Kota Kanbe
b079f5e52e
Update README.ja.md
2017-02-22 21:15:01 +09:00
Kota Kanbe
f9bf470a37
Update README.md
2017-02-22 21:13:54 +09:00
Kota Kanbe
9d783dd2ab
Merge pull request #350 from future-architect/show-false-positive
...
Output confidence score of detection accuracy and detection method to JSON or Reporting
2017-02-22 20:57:39 +09:00
Kota Kanbe
1b9aafbbaf
Output confidence ranking of detection accuracy to JSON or Reporting
2017-02-22 20:51:58 +09:00
Kota Kanbe
1d3ee6a241
Merge pull request #328 from federacy/leniant_changelog_parsing_for_debian
...
Add leniancy to the version matching for debian to account for versio…
2017-02-22 20:43:46 +09:00
Kota Kanbe
2f9c3071a6
Merge pull request #351 from hasegawa-tomoki/patch-1
...
Improve kanji character
2017-02-21 15:48:24 +09:00
HASEGAWA Tomoki
4b0be4f115
Fix typo(?)
2017-02-21 15:45:17 +09:00
Kota Kanbe
1419c7c8c6
Merge pull request #348 from knqyf263/add_template
...
Add PULL_REQUEST_TEMPLATE.md
2017-02-20 15:37:44 +09:00
knqyf263
851cecdd73
Add PULL_REQUEST_TEMPLATE.md
2017-02-19 23:36:22 +09:00
Kota Kanbe
753da3aad7
Merge pull request #347 from knqyf263/update_readme
...
Update README
2017-02-19 09:57:28 +09:00
Kota Kanbe
65c10d6d8e
Merge pull request #346 from knqyf263/send_cc
...
Bug fix: not send e-mail to cc address
2017-02-19 09:56:20 +09:00
Kota Kanbe
1b8b423131
Merge pull request #345 from future-architect/avoid-null
...
Avoid null slice being null in JSON
2017-02-19 09:37:36 +09:00
Kota Kanbe
55b1264c7d
Avoid null slice being null in JSON
2017-02-19 09:34:24 +09:00
knqyf263
902a1888d4
Update README
2017-02-17 18:33:11 +09:00
knqyf263
98151f7d0e
Bug fix: not send e-mail to cc address
2017-02-16 22:25:04 +09:00
Kota Kanbe
a6f0c559f8
Merge pull request #332 from kazuminn/add-err-handling
...
add error handling
2017-02-16 18:06:59 +09:00
kazuminn
e7ec5b841d
due to miss error handling
...
I fixed it according to the review
2017-02-16 12:49:13 +09:00
Kota Kanbe
d6f72ac0f3
Merge pull request #343 from knqyf263/fix_typo
...
Fix typo
2017-02-16 12:01:03 +09:00
Kota Kanbe
7e3a10025a
Merge pull request #344 from future-architect/fix-testcase
...
Fix test case
2017-02-16 11:33:07 +09:00
Kota Kanbe
e16ec15226
Fix test case
2017-02-16 11:32:18 +09:00
Kota Kanbe
6935b56c9d
Merge pull request #308 from lapthorn/update-readme
...
Update readme
2017-02-16 07:54:51 +09:00
Alan Lapthorn
0e3a0b64e7
Update READMEs
...
Fix typo
Fix typo in comment
2017-02-15 22:53:03 +00:00
knqyf263
74e6aee236
Fix typo
2017-02-15 23:51:46 +09:00
Kota Kanbe
db0602b7b8
Merge pull request #296 from galigalikun/update-readme
...
update readme
2017-02-15 22:08:51 +09:00
Kota Kanbe
c9b7c3f179
Merge pull request #331 from knqyf263/add_one-email
...
Add -format-one-email option
2017-02-15 21:58:14 +09:00
knqyf263
5bd9f4afb4
Add -format-one-email option
2017-02-15 18:31:51 +09:00
Kota Kanbe
9d2ba5912e
Merge pull request #340 from future-architect/freebsd-version
...
Change the command used for os detection from uname to freebsd-version
2017-02-15 14:39:31 +09:00
Kota Kanbe
9986c4a6f3
Change the command used for os detection from uname to freebsd-version
2017-02-15 14:34:53 +09:00
Kota Kanbe
df2c9697ef
Merge pull request #339 from future-architect/gnu-makefile
...
Rename Makefile to GNUmakefile #313
2017-02-15 14:13:45 +09:00
Kota Kanbe
ab0388e882
Rename Makefile to GNUmakefile #313
2017-02-15 14:07:43 +09:00
Kota Kanbe
c05d8a36eb
Merge pull request #338 from future-architect/update-readme
...
Update README
2017-02-14 12:47:33 +09:00
Kota Kanbe
492753d905
Update README
2017-02-14 12:45:28 +09:00
Kota Kanbe
6e08bd23f4
Merge pull request #330 from knqyf263/support_raspbian
...
Support Raspbian
2017-02-14 12:15:28 +09:00
Kota Kanbe
a687c97808
Merge pull request #337 from future-architect/fix-error-handling
...
Fix error handling of detectOS
2017-02-14 11:58:43 +09:00
Kota Kanbe
c6864289cb
Fix error handling of detectOS
2017-02-14 11:54:06 +09:00
Kota Kanbe
97d85258c5
Merge pull request #309 from future-architect/continue_scan_on_error
...
Continue scanning even when some hosts have tech issues
2017-02-14 11:10:13 +09:00
knqyf263
bee25f5aa2
Support Raspbian
2017-02-13 22:15:09 +09:00
Kota Kanbe
386b97d2be
Continue scanning even when some hosts have tech issues
...
see #264
2017-02-13 21:55:55 +09:00
Kota Kanbe
00660485b7
Merge pull request #324 from federacy/aptitude_changelog_more_to_cat
...
aptitude changelog defaults to using more, which is not interactive a…
2017-02-13 14:54:12 +09:00
Kota Kanbe
1e8f24dedb
Merge pull request #326 from federacy/add_image_info_for_docker
...
Add image information for docker containers
2017-02-13 13:48:11 +09:00
Kota Kanbe
2be190f863
Merge pull request #322 from knqyf263/delete_sudo_echo
...
Do not use sudo when echo
2017-02-13 12:19:16 +09:00
Kota Kanbe
ec7c6e6c85
Merge pull request #317 from federacy/fix_cve_dictionary_url_conditional
...
Don't check for a CVE DB when CVE Dictionary URL is defined
2017-02-13 10:49:36 +09:00
Kota Kanbe
c52bc53fd8
Merge pull request #314 from justyns/fixcontainertypo
...
Fix typo contianer -> container
2017-02-13 10:43:47 +09:00
James Sulinski
981631503a
Add leniancy to the version matching for debian to account for versions without the "+" when package maintainers aren't using them.
2017-02-10 11:38:46 -08:00
Kota Kanbe
48de3a6a4f
Merge pull request #319 from federacy/nosudo_for_debian_scans
...
Reduce privilege requirements for commands that don't need sudo on Ubuntu/Debian
2017-02-10 19:40:34 +09:00
Kota Kanbe
d1983a6978
Merge pull request #329 from future-architect/retry-exceeded-slack
...
Fix infinite retry at size overrun error in Slack report
2017-02-10 18:41:22 +09:00
Kota Kanbe
f821a26aec
Fix infinite retry at size overrun error in Slack report
2017-02-10 18:40:29 +09:00
James Sulinski
3380e905de
Add image information for docker containers
2017-02-09 01:05:12 -08:00
James Sulinski
b5c2718756
aptitude changelog defaults to using more, which is not interactive and breaks docker scans. Set PAGER=cat before running to default to cat.
2017-02-09 00:54:47 -08:00
James Sulinski
a03a803b89
Reduce privilege requirements for commands that don't need sudo
2017-02-09 00:47:08 -08:00
knqyf263
e743177ae6
Do not use sudo when echo
2017-02-09 17:43:15 +09:00
James Sulinski
6e12c69953
Don't check for a CVE DB when CVE Dictionary URL is defined
2017-02-09 00:36:23 -08:00
Justyn Shull
019ab77466
Fix typo contianer -> container
2017-02-08 17:17:12 -06:00
Kota Kanbe
1730caf124
Merge pull request #306 from knqyf263/update_lock
...
Update glide.lock to fix import error
2017-01-30 17:50:03 +09:00
knqyf263
59d1533795
Update glide.lock to fix import error
2017-01-30 17:49:23 +09:00
Kota Kanbe
a6278ab7ea
Merge pull request #305 from future-architect/fix-changelog-cache
...
Fix the changelog cache logic for ubuntu/debian
2017-01-28 04:16:04 +09:00
Kota Kanbe
42a6004c7d
Fix the changelog cache logic for ubuntu/debian
2017-01-28 04:08:57 +09:00
Kota Kanbe
6084c1b1d3
Merge pull request #304 from future-architect/fix-yum-updateinfo-opts
...
Fix yum updateinfo options
2017-01-27 18:50:17 +09:00
Kota Kanbe
c96fbc1dba
Fix yum updateinfo options
...
see #281
2017-01-27 18:42:14 +09:00
Kota Kanbe
5546a8b093
Merge pull request #303 from future-architect/glide
...
Update glide.lock to fix create-log-dir error.
2017-01-26 21:37:23 +09:00
Kota Kanbe
6b76b38dcd
Update glide.lock to fix create-log-dir error.
...
see https://github.com/kotakanbe/go-cve-dictionary/pull/40
2017-01-26 21:34:44 +09:00
Kota Kanbe
941e50b460
Merge pull request #302 from future-architect/log-dir
...
Fix a bug in logging (file output) at scan command
2017-01-26 17:22:45 +09:00
Kota Kanbe
5a10e5c9ff
Fix a bug in logging (file output) at scan command
...
Log of localhost was not output to file. #301
2017-01-26 17:21:03 +09:00
Kota Kanbe
883fe13756
Merge pull request #301 from knqyf263/add_logdir
...
Add -log-dir option
2017-01-26 16:51:31 +09:00
knqyf263
2e7c34cf9f
Add -log-dir option
2017-01-26 15:36:30 +09:00
Kota Kanbe
9216efbd2f
Merge pull request #300 from knqyf263/use_assumeno
...
Use --assumeno option
2017-01-24 15:07:58 +09:00
teppei-fukuda
6c8100e5b6
Use --assumeno option
2017-01-24 12:28:39 +09:00
Kota Kanbe
e7ef50bedf
Update README.md
2017-01-24 01:17:05 +09:00
Kota Kanbe
386ca3565a
Merge pull request #299 from future-architect/fix-pipe-problem
...
Add -pipe flag #294
2017-01-24 01:13:48 +09:00
Kota Kanbe
2d854cd64d
Add -pipe flag #294
...
Solved the problem of trying to read from STDIN and stopping on the way when running from CRON or AWS Lambda.
2017-01-24 01:06:22 +09:00
Kota Kanbe
49b4b8be22
Update README.md
2017-01-23 18:47:42 +09:00
Kota Kanbe
db975ebfee
Merge pull request #297 from knqyf263/update_readme
...
Update docker README
2017-01-23 18:36:31 +09:00
Kota Kanbe
d60a41139b
Merge pull request #298 from knqyf263/check_echo
...
Check whether echo is executable with nopasswd
2017-01-23 17:42:17 +09:00
knqyf263
f62d869d27
Check whether echo is executable with nopasswd
2017-01-22 23:15:25 +09:00
knqyf263
6cbe3cdb93
Update docker README
2017-01-21 22:04:57 +09:00
akaishi takeshi
b13e7b9da4
update readme
2017-01-18 14:34:23 +09:00
Kota Kanbe
8fe34c8474
Fix architecture image file
2017-01-17 00:32:53 +09:00
Kota Kanbe
bef29be50f
Merge pull request #291 from future-architect/localscan
...
Add local scan mode(Scan without SSH when target server is localhost)
2017-01-17 00:22:09 +09:00
Kota Kanbe
20275a1063
Add local scan mode.
...
If the scan target server is localhost, Don't use SSH. #210
2017-01-17 00:16:46 +09:00
Kota Kanbe
910385b084
Merge pull request #288 from jiazio/add-lxd-support
...
Add LXD support
2017-01-16 16:43:51 +09:00
Kota Kanbe
8e779374a7
Merge pull request #293 from future-architect/fix-rhel5
...
Fix RHEL5 scan stopped halfway
2017-01-13 06:41:26 +09:00
Kota Kanbe
44fc6f728e
Fix RHEL5 scan stopped halfway
2017-01-13 06:40:03 +09:00
Kota Kanbe
1f62dcf22a
Merge pull request #292 from future-architect/fix-bug-amazon-linux
...
Fix amazon linux scan stopped halfway
2017-01-13 04:59:34 +09:00
Kota Kanbe
0416c3b561
Fix amazon linux scan stopped halfway
2017-01-13 04:56:59 +09:00
Kota Kanbe
a6912cae76
Merge pull request #289 from future-architect/rhel5
...
Support RHEL5
2017-01-10 16:34:37 +09:00
Kota Kanbe
63dfe8a952
Support RHEL5
2017-01-10 16:32:06 +09:00
Kota Kanbe
62d1b761bd
Update CHANGELOG
2017-01-10 16:24:02 +09:00
Kota Kanbe
082b10a15b
Merge pull request #270 from future-architect/report-subcommand
...
Add report subcommand, change scan options. #239
2017-01-10 16:15:01 +09:00
Kota Kanbe
1a6bcd82b0
Merge pull request #287 from jiazio/fix-container-os-dectecion
...
Fix container os detection
2017-01-10 14:35:07 +09:00
jiazio
6ecd70220b
Add LXD support
2017-01-06 22:11:13 +09:00
jiazio
e9f55f5772
Fix container os detection
2017-01-06 16:32:42 +09:00
Kota Kanbe
155cadf901
Add report subcommand, change scan options. Bump up ver #239
2017-01-05 13:40:25 +09:00
Kota Kanbe
cb29289167
Merge pull request #283 from ymomoi/add-date-header
...
Add date header to report mail.
2017-01-02 09:13:33 +09:00
Yasunari Momoi
e4db9d1d91
Add date header to report mail.
2016-12-16 11:22:09 +09:00
Kota Kanbe
7b2e2cb817
Merge pull request #280 from hogehogehugahuga/add-mail-header
...
Add Content-Type header to report/mail.go .
2016-12-15 10:53:25 +09:00
hogehogehugahuga
c717f8d15d
Add Content-Type header to report/mail.go .
...
(fix pull request, "utf8" to "utf-8".)
I did the following test.
- compile vuls with this fix.
- I executed the following command and confirmed that garbled display is not done.
+ vuls scan -lang=en -report-mail -cve-dictionary...
+ vuls scan -lang=ja -report-mail -cve-dictionary...
Mail header is as follows.
Message-Id: <...>
Subject: <...>
Content-Type: text/plain; charset=utf8
From: <...>
To: <...>
Cc: <...>
2016-12-15 10:27:34 +09:00
Kota Kanbe
8db147acab
Merge pull request #272 from yoheimuta/sort-CveInfo-PackageInfo
...
Keep output of "vuls scan -report-*" to be same every times
2016-11-29 12:15:19 +09:00
yoheimuta
e6de7aa9ca
Sorted PackageInfos by Name to keep report texts same every times
2016-11-22 01:11:42 +09:00
Kota Kanbe
46f96740a2
Merge pull request #271 from future-architect/json-dir-regex
...
Fix JSON-dir regex pattern #265
2016-11-17 22:17:40 +09:00
Kota Kanbe
8f9fb5c262
Fix JSON-dir regex pattern #265
2016-11-17 22:14:41 +09:00
Kota Kanbe
171d6d6684
Merge pull request #263 from Code0x58/ssh-external-tidy
...
Stop quietly ignoring `--ssh-external` on Windows
2016-11-16 16:31:58 +09:00
Oliver Bristow
f648b5ad0a
Refactor SSHExternal flag so it isn't quietly ignored on Windows
2016-11-16 06:42:34 +00:00
Kota Kanbe
ef21376f0a
Merge pull request #265 from Code0x58/rfc3339-timestamps
...
Use RFC3339 timestamps in the results
2016-11-16 11:13:02 +09:00
Kota Kanbe
58958d68d8
Merge pull request #266 from Code0x58/260-prepare-confirm-flag
...
Add --assume-yes to prepare #260
2016-11-16 10:36:33 +09:00
Kota Kanbe
a06b565ee9
Merge pull request #262 from Code0x58/261-fix-gocui-signature-change
...
Fix gocui.NewGui after signature change #261
2016-11-16 09:49:24 +09:00
Oliver Bristow
a7db27ce5a
Add --assume-yes to prepare #260
2016-11-14 20:44:19 +00:00
Oliver Bristow
cda69dc7f0
Use RFC3339 timestamps in the results
2016-11-14 19:10:58 +00:00
Oliver Bristow
39f9594548
Update glide.lock and fix gocui.NewGui after signature change #261
2016-11-14 18:05:28 +00:00
Kota Kanbe
6d82ad32a9
Merge pull request #254 from Code0x58/patch-2
...
Replace inconsistent tabs with spaces
2016-11-14 04:53:52 +09:00
Kota Kanbe
cfcd8bf223
Merge pull request #253 from Code0x58/patch-1
...
Fix non-interactive `apt-get install` #251
2016-11-14 04:49:12 +09:00
Oliver Bristow
8149ad00b5
Replace inconsistent tabs with spaces
2016-11-11 19:26:41 +00:00
Oliver Bristow
2310522806
Fix non-interactive apt-get install #251
2016-11-11 19:13:51 +00:00
Kota Kanbe
e40ef656d6
Merge pull request #249 from usiusi360/Fix-README
...
Fix README
2016-11-08 22:54:24 +09:00
Takayuki Ushida
e060d40a32
Fix README
2016-11-08 22:27:57 +09:00