Commit graph

1,348 commits

Author SHA1 Message Date
677c7a5d5f feat(gitea): add --clone-url-base flag for clone URL rewriting
Some checks failed
ClusterFuzzLite PR fuzzing / PR (address) (pull_request) Has been cancelled
CI Pull Request / Linux x64 (pull_request) Has been cancelled
CI Pull Request / Linux arm64 (pull_request) Has been cancelled
CI Pull Request / macOS arm64 (pull_request) Has been cancelled
CI Pull Request / Windows arm64 (pull_request) Has been cancelled
CI Pull Request / Windows x64 (pull_request) Has been cancelled
When scanning a self-hosted Gitea/Forgejo instance, the API may be
reachable at a different hostname than the git clone endpoint (e.g.,
internal API vs. public clone URL behind a reverse proxy). The
--clone-url-base flag rewrites the scheme, host, and port of clone
URLs returned by the API, preserving the path.

Example:
  kingfisher scan gitea \
    --api-url https://forge.internal.example.com/api/v1/ \
    --clone-url-base https://forge.internal.example.com/ \
    --user eblume

This avoids routing clone traffic through an external proxy when the
API and git endpoints share the same internal host but the instance's
ROOT_URL points to the public endpoint.

Includes unit tests for the URL rewriting function and an integration
test using wiremock to verify the full enumeration path.
2026-03-29 08:28:36 -07:00
Mick Grove
1d37d2983c
Merge pull request #301 from mongodb/development 2026-03-28 12:18:12 -07:00
Mick Grove
5b51aa941d fixed github actions 2026-03-28 12:09:28 -07:00
Mick Grove
af66acd18d fixed github actions 2026-03-28 11:59:22 -07:00
Mick Grove
6f9e3a05ae fixed github actions 2026-03-28 11:48:13 -07:00
Mick Grove
3d9ffd936d
Merge pull request #300 from mongodb/development v1.91.0 2026-03-28 08:17:35 -07:00
Mick Grove
b14522351b updated in response to ossf scorecard 2026-03-27 23:18:56 -07:00
Mick Grove
afd0eb5713 updated in response to ossf scorecard 2026-03-27 23:07:02 -07:00
Mick Grove
993a76ded1 updated in response to ossf scorecard 2026-03-27 22:57:19 -07:00
Mick Grove
93cd6e940c updated in response to ossf scorecard 2026-03-27 22:43:50 -07:00
Mick Grove
e0a403607f updated in response to ossf scorecard 2026-03-27 22:26:35 -07:00
Mick Grove
b04865e174 updated in response to ossf scorecard 2026-03-27 21:38:58 -07:00
Mick Grove
4e9a7364cd updated in response to ossf scorecard 2026-03-27 21:25:56 -07:00
Mick Grove
9c8c63db90 updated in response to ossf scorecard 2026-03-27 21:08:52 -07:00
Mick Grove
051e4ffdd2 updated in response to ossf scorecard 2026-03-27 21:08:39 -07:00
Mick Grove
411aeefa92 updated in response to ossf scorecard 2026-03-27 17:22:21 -07:00
Mick Grove
1c7341f3ac updated in response to ossf scorecard 2026-03-27 15:04:14 -07:00
Mick Grove
0d982be19f
Merge pull request #299 from mongodb/development
Update project in response to OSSF Scorecard feedback
2026-03-27 14:33:22 -07:00
Mick Grove
31042d4784 updated in response to ossf scorecard 2026-03-27 14:28:53 -07:00
Mick Grove
b462f2716a
Merge pull request #284 from mongodb/development
openssf scorecard suggested improvements
2026-03-26 23:02:29 -07:00
Mick Grove
3e0569d741 improve OpenSSF scorecard: tighten token permissions and add build provenance
Move write permissions from workflow top-level to job-level in cflite_batch,
cflite_pr, and release-docker workflows. Add sigstore build provenance
attestation to the release workflow via actions/attest-build-provenance.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-26 19:36:18 -07:00
Mick Grove
bfcec88482 updated dependencies 2026-03-24 09:40:06 -07:00
Mick Grove
da59ba9855 updated dependencies 2026-03-24 09:32:20 -07:00
Mick Grove
c0c641e03e updated dependencies 2026-03-24 09:11:02 -07:00
Mick Grove
d609900d56 updated dependencies 2026-03-24 08:55:34 -07:00
Mick Grove
e2c7dc3e41 openssf scorecard suggested improvements 2026-03-20 09:25:05 -07:00
Mick Grove
db97997521 openssf scorecard suggested improvements 2026-03-20 08:41:37 -07:00
Mick Grove
a1baaabde0
Merge pull request #283 from mongodb/development
Implement suggested improvements from OpenSSF Scorecard
2026-03-20 07:57:10 -07:00
Mick Grove
3a47fef398 openssf scorecard suggested improvements 2026-03-20 07:56:30 -07:00
Mick Grove
fd17cd2dcf openssf scorecard suggested improvements 2026-03-20 07:47:29 -07:00
Mick Grove
bd2d53b7b4 openssf scorecard suggested improvements 2026-03-20 07:45:37 -07:00
Mick Grove
0795036893
Merge pull request #282 from mongodb/development
Implement suggested improvements from OpenSSF Scorecard
2026-03-20 07:36:24 -07:00
Mick Grove
0c77e3c4a3 openssf scorecard suggested improvements 2026-03-19 23:52:38 -07:00
Mick Grove
ae8c5f62a4 openssf scorecard suggested improvements 2026-03-19 23:40:46 -07:00
Mick Grove
5fa4ce59b7 openssf scorecard suggested improvements
Made-with: Cursor
2026-03-19 23:39:36 -07:00
Mick Grove
2a2ddc2a44
Merge pull request #262 from mongodb/development
Implement suggested improvements from OpenSSF Scorecard
2026-03-19 22:49:03 -07:00
Mick Grove
d637a7b6fb openssf scorecard suggested improvements 2026-03-19 20:45:58 -07:00
Mick Grove
66055953a0 openssf scorecard suggested improvements 2026-03-19 20:31:10 -07:00
Mick Grove
d3eca972c8 openssf scorecard suggested improvements 2026-03-19 20:24:21 -07:00
Mick Grove
6c32e374c3 openssf scorecard suggested improvements 2026-03-19 20:14:35 -07:00
Mick Grove
8b83b2d87c
Merge pull request #260 from mongodb/development v1.90.0
v1.90.0
2026-03-18 19:50:07 -07:00
Mick Grove
cb56a332ba changes in response to PR review 2026-03-18 17:28:38 -07:00
Mick Grove
f681591ee8 changes in response to PR review 2026-03-18 17:19:30 -07:00
Mick Grove
e6dd9cd7db v1.90.0 2026-03-18 17:06:55 -07:00
Mick Grove
f0a3bee587 added --max-validation-response-length <BYTES> 2026-03-16 22:25:32 -07:00
Mick Grove
e80eb6cc2b
Merge pull request #258 from trevermckee/feature/testkube-api-key-support
Add testkube API key support (API Key, Env Key, and Org Key) with validation.
2026-03-16 20:00:47 -07:00
Trever McKee
25219f2ed8
Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Trever McKee <132310752+trevermckee@users.noreply.github.com>
2026-03-16 17:22:55 -07:00
Trever McKee
99e673c1a8 Add testkube API key support (API Key, Env Key, and Org Key) with validation. 2026-03-16 16:15:18 -07:00
Mick Grove
e2c7072094
Merge pull request #257 from mongodb/development v1.89.0
v1.89.0
2026-03-15 19:58:08 -07:00
Mick Grove
8fe66e4caf fixed test that fails on windows 2026-03-15 17:26:02 -07:00