🚀 Features
- Make the healthchecks for the operator configurable via helm values by @J12934 in #3223
- Switch ncrack password encryption from RSA to age-encryption by @p4trickweiss in #3247
- Improve operator and auto-discovery log consistency and switch to json logs by @J12934 in #3227
🚓 Security Scanner
- Upgraded nuclei from v3.4.7 to v3.4.10 @secureCodeBoxBot (#3228, #3232)
- Upgraded semgrep from 1.131.0 to 1.138.0 @secureCodeBoxBot (#3211, #3231, #3248, #3258, #3269, #3283, #3296)
- Upgraded subfinder from v2.8.0 to v2.9.0 @secureCodeBoxBot (#3298)
- Upgraded trivy from 0.65.0 to 0.67.0 @secureCodeBoxBot (#3252, #3303)
- Upgraded trivy-sbom from 0.65.0 to 0.67.0 @secureCodeBoxBot (#3253, #3304)
- Upgraded whatweb from v6.0.1 to v0.6.2 @secureCodeBoxBot (#3236)
🐛 Bug Fixes
- Fix Dependency Track Hook by @p4trickweiss in #3290
- Added affinity and tolerations fields to ssh-audit-scan-type.yaml by @DevikHaruko in #3297
- Migrate scan kubernetes finalizers to avoid warnings about non-recommended finalizer url structure by @J12934 in #3226
📚 Documentation
- Fix minor documentation issues by @J12934 in #3221
- Replace Snyk badge with OpenSSF Scorecard Badge by @J12934 in #3233
- Update supported k8s versions to include new Kubernetes 1.34 release. by @J12934 in #3255
- Update Security Policy with new supported Versions and Update Advisory Publishing Process by @J12934 in #3235
🔧 Maintenance
- Automatically set labels for renovate PRs by @J12934 in #3203
- Renovate for ci.yaml dependencies by @J12934 in #3204
- Optimize Go Docker builds with native cross-compilation by @J12934 in #3206
- Migrate docker repository for petstore by @Reet00 in #3213
- Remove unnecessary create-blog-post script by @Weltraumschaf in #3244
- Migrate parser-sdk to typescript by @J12934 in #3254
- Changes the comments behind pinned actions to include their full version by @J12934 in #3264
- Rewrite pull-secret-extractor in Go by @p4trickweiss in #3267
- Pin GitHub Pipeline Action Dependencies and specify reduced pipeline permissions by @J12934 in #3229
📌 Dependencies
Minor dependency updates (41 pull requests). Click to expand.
- Update golang Docker tag by @renovate[bot] in #3207
- Update dependency go-task/task to v3.44.1 by @renovate[bot] in #3208
- Update dependency helm/helm to v3.18.5 by @renovate[bot] in #3209
- Update dependency kubernetes/kubernetes to v1.33.4 by @renovate[bot] in #3210
- Bump the go-version-updates group across 4 directories with 6 updates by @dependabot[bot] in #3217
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3214
- Bump actions/checkout from 4 to 5 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3216
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 3 updates by @dependabot[bot] in #3215
- Update docker.io/swaggerapi/petstore3 Docker tag to v1.0.27 by @renovate[bot] in #3218
- Update dependency helm/helm to v3.18.6 by @renovate[bot] in #3222
- Bump the go-version-updates group across 3 directories with 2 updates by @dependabot[bot] in #3240
- Bump io.freefair.lombok from 8.14 to 8.14.2 in /hooks/persistence-defectdojo/hook in the gradle-version-updates group by @dependabot[bot] in #3237
- Add pip to dependabot by @Reet00 in #3234
- Bump the npm-version-updates group across 1 directory with 2 updates by @dependabot[bot] in #3241
- Update dependency kubernetes-sigs/kind to v0.30.0 by @renovate[bot] in #3245
- Update dependency kubernetes/kubernetes to v1.34.0 by @renovate[bot] in #3246
- Dependabot/gradle/hooks/persistence defectdojo/hook/gradle version updates 7f209d1a84 by @Weltraumschaf in #3251
- Update docker.io/bkimminich/juice-shop Docker tag to v19 by @renovate[bot] in #3257
- Update golang Docker tag to v1.25.1 by @renovate[bot] in #3256
- Bump the npm-version-updates group across 2 directories with 1 update by @dependabot[bot] in #3261
- Bump the npm-version-updates group in /documentation with 4 updates by @dependabot[bot] in #3260
- Bump the github-actions-version-updates group across 1 directory with 5 updates by @dependabot[bot] in #3265
- Update debian Docker tag to v13.1 by @renovate[bot] in #3266
- Bump the go-version-updates group across 4 directories with 9 updates by @dependabot[bot] in #3263
- Update dependency kubernetes/kubernetes to v1.34.1 by @renovate[bot] in #3268
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in #3275
- Bump the npm-version-updates group across 2 directories with 1 update by @dependabot[bot] in #3277
- Update dependency helm/helm to v3.19.0 by @renovate[bot] in #3273
- Bump github/codeql-action from 3.30.1 to 3.30.3 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3274
- Bump the go-version-updates group across 4 directories with 5 updates by @dependabot[bot] in #3278
- Update dependency go-task/task to v3.45.3 by @renovate[bot] in #3280
- Update dependency go-task/task to v3.45.4 by @renovate[bot] in #3282
- Update golang Docker tag to v1.25.1 by @renovate[bot] in #3288
- Bump @types/node from 24.4.0 to 24.5.2 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in #3287
- Bump oxsecurity/megalinter from 8.8.0 to 9.0.1 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in #3286
- Bump tar-fs from 3.0.10 to 3.1.1 in /tests/integration in the npm-security-updates group across 1 directory by @dependabot[bot] in #3292
- Bump tar-fs from 3.1.0 to 3.1.1 in /hooks/notification/hook by @dependabot[bot] in #3291
- Bump tar-fs from 3.1.0 to 3.1.1 in /hooks/cascading-scans/hook by @dependabot[bot] in #3293
- Bump the npm-security-updates group across 2 directories with 1 update by @dependabot[bot] in #3294
- Bump the npm-version-updates group across 1 directory with 9 updates by @dependabot[bot] in #3300
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in #3302
New Contributors
- @p4trickweiss made their first contribution in #3247
- @DevikHaruko made their first contribution in #3297
Full Changelog: v5.0.0...v5.1.0