⚡️ Release notes and discussion: #2803 ⚡️
Docker images
docker pull docker.io/aquasec/tracee:0.12.0 (embedded eBPF CO-RE obj with BTFHUB support)
docker pull docker.io/aquasec/tracee:full-0.12.0 (compiles non CO-RE eBPF object on startup)
commit log
- refactor: simplify output flags by @josedonizetti in #2700
- chore: generate k8s statics by @josedonizetti in #2703
- tracee: fix filters by @josedonizetti in #2720
- flags: remove cache-events from output help by @josedonizetti in #2729
- swap uint and containers equality order by @geyslan in #2726
- types: upgrade go-yaml by @josedonizetti in #2719
- dep: update githuhub.com/aquasecrity/tracee/types by @josedonizetti in #2730
- ebpf: add prog_override_return arg to bpf_attach by @roikol in #2560
- build(deps): bump github.com/containerd/containerd from 1.6.15 to 1.6.18 by @dependabot in #2732
- filterscopes: create a filterscopes pkg by @rafaeldtinoco in #2738
- log when not a container cgroup instead of err by @geyslan in #2737
- pkg/ebpf: add derived events for ld SO symbols collision (rebase) by @rafaeldtinoco in #2740
- sign container images with cosign by @developer-guy in #2607
- chore: bump golang.org/x/net from 0.5.0 to 0.7.0 by @dependabot in #2741
- trace: add hidden kernel module struct by @OriGlassman in #2742
- adjust recently merged symbols_collision event and better document it by @rafaeldtinoco in #2743
- refactor: rules renamed to signatures by @josedonizetti in #2715
- logger: set libbpfgo logger callback by @geyslan in #2663
- events: print seconds of timespec by @roikol in #2712
- ebpf: save_args_to_submit_buf minor format change by @rafaeldtinoco in #2755
- types: add event metadata by @josedonizetti in #2752
- events: add vfs_utimes event by @roikol in #2690
- Provide Fluent Forward output option by @patrick-stephens in #2155
- chore (tests): add e2e instrumentation tests by @roikol in #2764
- Refactor output forward flag by @josedonizetti in #2766
- feat: add do_truncate event by @roikol in #2749
- Add signature event metadata by @josedonizetti in #2753
- tracee: fix args on signatures events by @josedonizetti in #2713
- tests: fix integration pkg race conditions by @geyslan in #2768
- test: fix flaky TestFindingToEvent by @josedonizetti in #2774
- workflow: move runners to jenkins by @rafaeldtinoco in #2776
- errors: improve error output by @rafaeldtinoco in #2773
- flags: cli: docs: rename trace flag to filter by @geyslan in #2767
- libbpfgo: set libbpfgo callbacks by @geyslan in #2761
- signatures: load sigs as default events by @josedonizetti in #2779
- tracee: make it the default binary by @josedonizetti in #2777
- Add multiple printers by @josedonizetti in #2746
- Add file modification event by @roikol in #2780
- Add webhook printer by @josedonizetti in #2782
- k8s: remove flag everythingIsAnEvent from helm by @josedonizetti in #2785
- Improve building docs by @rafaeldtinoco in #2787
- printer: block instead of drop events for broadcast by @josedonizetti in #2789
- k8s: fix templates to use unified binary by @josedonizetti in #2786
- k8s: bump version by @josedonizetti in #2791
- k8s: remove falcosidekiq yaml by @josedonizetti in #2795
- documentation: add syscall events markdown files from ChatGPT by @rafaeldtinoco in #2792
- gptdocs: add option to generate docs for a list of events by @rafaeldtinoco in #2800
- sets: default set can't have network events v419 by @rafaeldtinoco in #2771
- adding promtail tutorial by @AnaisUrlichs in #2781
- docs: restructure #2788 by @AnaisUrlichs in #2797
- docs: update output docs by @itaysk in #2802
New Contributors
- @developer-guy made their first contribution in #2607
- @patrick-stephens made their first contribution in #2155
Full Changelog: v0.11.1...v0.12.0