Commit graph

259 commits

Author SHA1 Message Date
Mick Grove
3c090ec980
Merge pull request #87 from mongodb/development v1.40.0
v1.40.0
2025-08-13 10:19:36 -07:00
Mick Grove
1054476a3b fixed test 2025-08-13 09:23:03 -07:00
Mick Grove
a062e82728 fixed test 2025-08-13 09:20:36 -07:00
Mick Grove
12e9a01b5e Improved Tailscale api key detectors 2025-08-13 09:13:50 -07:00
Mick Grove
e7a8da6b3c Dropped the “prevalidated” flag from rule definitions and validation logic so every finding now flows through the standard active/inactive/unknown pipeline, simplifying rule configuration and preventing special‑case bypasses 2025-08-13 08:22:53 -07:00
Mick Grove
00b1833bb6
Merge pull request #86 from mongodb/development v1.39.0
v1.39.0
2025-08-11 10:03:33 -07:00
Mick Grove
25268eabef Added support for scanning Confluence pages 2025-08-11 09:03:58 -07:00
Mick Grove
bf4fc622fa Added support for scanning Confluence pages 2025-08-11 08:26:49 -07:00
Mick Grove
2a40b9efee Added support for scanning Confluence pages 2025-08-11 08:25:24 -07:00
Mick Grove
979d5e0f3d Added support for scanning Confluence pages 2025-08-11 08:04:52 -07:00
Mick Grove
0502eeb7a1 Added support for scanning Confluence pages 2025-08-10 21:57:35 -07:00
Mick Grove
5e678155ba Added support for scanning Confluence pages 2025-08-10 21:55:45 -07:00
Mick Grove
94e2e11de3 Added support for scanning Confluence pages 2025-08-10 21:54:26 -07:00
Mick Grove
baa7b6e761 Added support for scanning Confluence pages 2025-08-10 21:51:31 -07:00
Mick Grove
9ca6ea5fb6 removed unused cli argument, snippet-length 2025-08-10 17:27:36 -07:00
Mick Grove
690db297e3 removed unused cli argument, snippet-length 2025-08-10 17:25:32 -07:00
Mick Grove
9310ecae40
Merge pull request #85 from mongodb/development v1.38.0
v1.38.0
2025-08-09 16:51:29 -07:00
Mick Grove
979bc469c5 - --quiet now suppresses scan summaries and rule statistics unless --rule-stats is explicitly provided
- Added X Consumer key detection and validation
2025-08-09 15:52:00 -07:00
Mick Grove
c9c0aba687 - --quiet now suppresses scan summaries and rule statistics unless --rule-stats is explicitly provided
- Added X Consumer key detection and validation
2025-08-09 15:36:12 -07:00
Mick Grove
229a66655c Added X Consumer key detection and validation 2025-08-09 08:46:07 -07:00
Mick Grove
e53ad9f309 Added X Consumer key detection and validation 2025-08-09 08:45:27 -07:00
Mick Grove
d731c2c95c
Merge pull request #84 from mongodb/development v1.37.0
v1.37.0
2025-08-08 22:42:05 -07:00
Mick Grove
701d833adc GitLab: include nested subgroup projects when enumerating group repositories 2025-08-08 21:43:01 -07:00
Mick Grove
0a53a58ac1 GitLab: include nested subgroup projects when enumerating group repositories 2025-08-08 21:42:49 -07:00
Mick Grove
2f720247c7
Merge pull request #83 from mongodb/development
v1.37.0
2025-08-08 19:44:06 -07:00
Mick Grove
4dd8a4531b GitLab: include nested subgroup projects when enumerating group repositories 2025-08-08 18:08:17 -07:00
Mick Grove
8025d91a65
Merge pull request #82 from mongodb/development
v1.37.0
2025-08-08 16:29:21 -07:00
Mick Grove
cdfdd5f54e GitLab: include nested subgroup projects when enumerating group repositories 2025-08-08 15:12:33 -07:00
Mick Grove
c763780905 GitLab: include nested subgroup projects when enumerating group repositories 2025-08-08 15:11:44 -07:00
Mick Grove
02803a9bb2 GitLab: include nested subgroup projects when enumerating group repositories 2025-08-08 15:11:36 -07:00
Mick Grove
df53586475
Merge pull request #80 from mongodb/development v1.36.0
v1.36.0
2025-08-07 19:46:11 -07:00
Mick Grove
a912043eb9 changes in response to code review 2025-08-07 18:45:46 -07:00
Mick Grove
0bdd68c900 JWT tokens without both 'iss' and 'aud' are no longer reported as active credentials 2025-08-07 18:30:40 -07:00
Mick Grove
b3ddc119a4 JWT tokens without both 'iss' and 'aud' are no longer reported as active credentials 2025-08-07 17:36:39 -07:00
Mick Grove
061d3d97ed JWT tokens without both 'iss' and 'aud' are no longer reported as active credentials 2025-08-07 17:21:31 -07:00
Mick Grove
b71fb5e6e2 JWT tokens without both 'iss' and 'aud' are no longer reported as active credentials 2025-08-07 17:21:16 -07:00
Mick Grove
de181634cb Fixed GitHub organization and GitLab group scans when using '--git-history=none' 2025-08-07 16:13:57 -07:00
Mick Grove
f84d503f7c
Merge pull request #79 from mongodb/development v1.35.0
v1.35.0
2025-08-06 22:44:17 -07:00
Mick Grove
57ba607a33 Fixed validation logic for clarifai rule 2025-08-06 21:31:02 -07:00
Mick Grove
8d32662c1a fixed issue where --redact did not function properly 2025-08-06 21:23:27 -07:00
Mick Grove
e48b9617c8 Remote scans with --git-history=none now clone repositories with a working tree and scan the current files instead of erroring with 'No inputs to scan.' 2025-08-06 19:16:22 -07:00
Mick Grove
0b8e8fcc75 Remote scans with --git-history=none now clone repositories with a working tree and scan the current files instead of erroring with 'No inputs to scan.' 2025-08-06 19:15:50 -07:00
Mick Grove
5c1eb63751
Merge pull request #75 from mongodb/development v1.34.0
fixing github action failure for linux-arm6 when making deb
2025-08-05 18:06:39 -07:00
Mick Grove
d9b90fbc50 fixing github action failure for linux-arm6 when making deb 2025-08-05 18:06:09 -07:00
Mick Grove
5cf5d4f9c3
Merge pull request #74 from mongodb/development
v1.34.0
2025-08-05 16:26:44 -07:00
Mick Grove
c2e227a832 Updated Supabase rule to detect project url's and validate their corresponding tokens 2025-08-05 16:25:22 -07:00
Mick Grove
756fd89097 - Use system TLS root certificates to support self-hosted GitLab instances with internal CAs
- Added new rule: Coze personal access token
2025-08-05 14:45:51 -07:00
Mick Grove
f8f33de074
Merge pull request #73 from mongodb/development v1.33.0
v1.33.0
2025-08-04 21:38:49 -07:00
Mick Grove
3ebb8ecf8e - Fixed header precedence so custom HTTP validation headers like "Accept" are preserved
- Added new Heroku rule
2025-08-04 21:38:23 -07:00
Mick Grove
17e2e1453f
Merge pull request #72 from mongodb/development
v1.33.0
2025-08-04 20:48:54 -07:00