Mick Grove
|
87f6bd818f
|
copilot fixes
|
2026-04-30 11:40:22 -07:00 |
|
Mick Grove
|
b89c952043
|
copilot fixes
|
2026-04-30 11:28:45 -07:00 |
|
Mick Grove
|
cceab35ec1
|
copilot fixes
|
2026-04-30 10:56:35 -07:00 |
|
Mick Grove
|
997480ffc7
|
Added first-class **Postman** scanning target: new kingfisher scan postman subcommand (and equivalent --postman-* flags) fetches workspaces, collections, and environments via the Postman API and scans them for hard-coded credentials in request auth blocks, pre-request/test scripts, saved example responses, and — notably — secret-typed environment variables, which the API returns in plaintext despite the UI mask. Selectors: --workspace, --collection, --environment, --all, with optional --include-mocks-monitors and --api-url for self-hosted endpoints. Authenticates via KF_POSTMAN_TOKEN (or POSTMAN_API_KEY) sent as X-Api-Key; honors X-RateLimit-RetryAfter on 429s. Findings link back to https://go.postman.co/... URLs in reports.
|
2026-04-29 08:12:08 -07:00 |
|
Mick Grove
|
19dafa42ea
|
Added provider endpoint overrides for validation and revocation via global --endpoint PROVIDER=URL and --endpoint-config FILE, with built-in support for self-hosted GitHub, GitLab, Gitea, Jira, Confluence, and Artifactory instances.
|
2026-04-27 13:20:16 -07:00 |
|
Mick Grove
|
e4cd6dd164
|
performance improvements and rule improvements
|
2026-04-17 16:53:21 -07:00 |
|
Mick Grove
|
93a9cb796e
|
updates to new rules
|
2026-04-15 17:13:10 -07:00 |
|
Mick Grove
|
58e9cfd585
|
changes in response to PR review
|
2026-04-08 16:16:31 -07:00 |
|
Mick Grove
|
17c57e96e3
|
changes in response to PR review
|
2026-04-08 08:29:50 -07:00 |
|
Mick Grove
|
afee0b7181
|
updated rules
|
2026-04-07 10:42:44 -07:00 |
|
Mick Grove
|
45a565fa6e
|
added more rules
|
2026-04-06 22:18:58 -07:00 |
|
Mick Grove
|
b04865e174
|
updated in response to ossf scorecard
|
2026-03-27 21:38:58 -07:00 |
|
Mick Grove
|
4e9a7364cd
|
updated in response to ossf scorecard
|
2026-03-27 21:25:56 -07:00 |
|
Mick Grove
|
1c7341f3ac
|
updated in response to ossf scorecard
|
2026-03-27 15:04:14 -07:00 |
|
Mick Grove
|
f0a3bee587
|
added --max-validation-response-length <BYTES>
|
2026-03-16 22:25:32 -07:00 |
|
Mick Grove
|
349b8165aa
|
Added TOON output support, to optimize usage of kingfisher from LLM/agent workflows
|
2026-03-15 15:00:59 -07:00 |
|
Mick Grove
|
60931c11a9
|
added Teams support
|
2026-03-13 17:39:34 -07:00 |
|
Mick Grove
|
3220ed3a80
|
Merge branch 'codex/pr-244-mergeable' into development
* codex/pr-244-mergeable:
Add Jira comment and changelog scanning
|
2026-02-28 11:14:19 -07:00 |
|
Mick Grove
|
719b91301d
|
Add Jira comment and changelog scanning
|
2026-02-28 11:13:00 -07:00 |
|
Mick Grove
|
0ae4e8445c
|
Updated kingfisher scan to accept Git repository URLs as positional targets (for example kingfisher scan github.com/org/repo or kingfisher scan https://gitlab.com/group/project.git) without requiring --git-url.
|
2026-02-26 23:14:18 -07:00 |
|
Mick Grove
|
92f43d2e29
|
added --turbo mode
|
2026-02-24 12:25:12 -07:00 |
|
Mick Grove
|
aa29ee0e99
|
added '--fast' mode which sets maximum scan speed. Omits git commit context and will not base64 decode
|
2026-02-23 22:34:23 -07:00 |
|
Mick Grove
|
e72f40b169
|
Fixed CI runner failure when executing tests
|
2026-02-12 16:51:55 -08:00 |
|
Mick Grove
|
5882468177
|
Added optional validation rate limiting via --validation-rps (global) and repeatable --validation-rps-rule <RULE_SELECTOR=RPS> (per-rule override) for both scan and validate. Throttling now applies across built-in validator types (HTTP/gRPC plus AWS, GCP, Coinbase, MongoDB, Postgres, MySQL, JDBC, JWT, and Azure Storage). Rule selectors support the short form (for example, github=2 matches kingfisher.github.*) with longest-prefix precedence when multiple selectors apply.
|
2026-02-12 12:33:59 -08:00 |
|
Mick Grove
|
4a74e95756
|
v1.81.0
|
2026-02-10 19:43:34 -08:00 |
|
Mick Grove
|
e518fb30f2
|
v1.81.0
|
2026-02-10 19:24:19 -08:00 |
|
Mick Grove
|
2866367c2e
|
v1.80.0
|
2026-02-09 12:11:35 -08:00 |
|
Mick Grove
|
5253204c2a
|
preparing for v1.78.0
|
2026-02-02 23:22:08 -08:00 |
|
Mick Grove
|
63f1d515ae
|
preparing for v1.78.0
|
2026-02-02 18:39:24 -08:00 |
|
Mick Grove
|
8be7941333
|
Added 'revoke' subcommand and support for a new optional 'revocation' structure to the rules. Supporting GitHub and Slack right now
|
2026-01-29 12:45:32 -08:00 |
|
Mick Grove
|
1c45efde3e
|
Refactored into multiple crates. Added the 'validate' subcommand
|
2026-01-28 22:24:35 -08:00 |
|
Mick Grove
|
76be1df60c
|
Refactored into multiple crates. Added the 'validate' subcommand
|
2026-01-28 10:27:24 -08:00 |
|