mirror of
https://github.com/empayre/fleet.git
synced 2024-11-06 00:45:19 +00:00
main
7 Commits
Author | SHA1 | Message | Date | |
---|---|---|---|---|
Eric
|
da32121f00
|
Vuln dashboard: Update moment dependency to resolve code scanning alerts (#17849)
Related to: #17764 Changes: - Updated ee/vulnerability-dashboard/assets/dependencies/moment.js to resolve two code scanning alerts. |
||
StepSecurity Bot
|
80335d88d1
|
[StepSecurity] Apply security best practices (#17811) | ||
Eric
|
413107b93a
|
Vuln dashboard: Update Okta SSO hook (#17773)
Closes: #17772 More context: https://github.com/fleetdm/fleet/pull/17601#issuecomment-2013383611 Changes: - Updated the order of the vulnerability dashboard's HTTP middleware if Okta SSO is enabled. |
||
Eric
|
1d8e208c32
|
Vulnerability dashboard: Add a way to start a local vulnerability dashboard with Docker (#17676)
Related to: https://github.com/fleetdm/confidential/issues/5637 Changes: - Added a way to start a vulnerability dashboard with Docker. - Updated the folder readme to include instructions for starting the vulnerability dashboard with docker |
||
dependabot[bot]
|
27a59ed37c
|
Bump grunt from 1.0.4 to 1.5.3 in /ee/vulnerability-dashboard (#17600)
Bumps [grunt](https://github.com/gruntjs/grunt) from 1.0.4 to 1.5.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/gruntjs/grunt/releases">grunt's releases</a>.</em></p> <blockquote> <h2>v1.5.3</h2> <ul> <li>Merge pull request <a href="https://redirect.github.com/gruntjs/grunt/issues/1745">#1745</a> from gruntjs/fix-copy-op 572d79b</li> <li>Patch up race condition in symlink copying. 58016ff</li> <li>Merge pull request <a href="https://redirect.github.com/gruntjs/grunt/issues/1746">#1746</a> from JamieSlome/patch-1 0749e1d</li> <li>Create SECURITY.md 69b7c50</li> </ul> <p><a href="https://github.com/gruntjs/grunt/compare/v1.5.2...v1.5.3">https://github.com/gruntjs/grunt/compare/v1.5.2...v1.5.3</a></p> <h2>v1.5.2</h2> <ul> <li>Update Changelog 7f15fd5</li> <li>Merge pull request <a href="https://redirect.github.com/gruntjs/grunt/issues/1743">#1743</a> from gruntjs/cleanup-link b0ec6e1</li> <li>Clean up link handling 433f91b</li> </ul> <p><a href="https://github.com/gruntjs/grunt/compare/v1.5.1...v1.5.2">https://github.com/gruntjs/grunt/compare/v1.5.1...v1.5.2</a></p> <h2>v1.5.1</h2> <ul> <li>Merge pull request <a href="https://redirect.github.com/gruntjs/grunt/issues/1742">#1742</a> from gruntjs/update-symlink-test ad22608</li> <li>Fix symlink test 0652305</li> </ul> <p><a href="https://github.com/gruntjs/grunt/compare/v1.5.0...v1.5.1">https://github.com/gruntjs/grunt/compare/v1.5.0...v1.5.1</a></p> <h2>v1.5.0</h2> <ul> <li>Updated changelog b2b2c2b</li> <li>Merge pull request <a href="https://redirect.github.com/gruntjs/grunt/issues/1740">#1740</a> from gruntjs/update-deps-22-10 3eda6ae</li> <li>Update testing matrix 47d32de</li> <li>More updates 2e9161c</li> <li>Remove console log 04b960e</li> <li>Update dependencies, tests... aad3d45</li> <li>Merge pull request <a href="https://redirect.github.com/gruntjs/grunt/issues/1736">#1736</a> from justlep/main fdc7056</li> <li>support .cjs extension e35fe54</li> </ul> <p><a href="https://github.com/gruntjs/grunt/compare/v1.4.1...v1.5.0">https://github.com/gruntjs/grunt/compare/v1.4.1...v1.5.0</a></p> <h2>v1.4.1</h2> <ul> <li>Update Changelog e7625e5</li> <li>Merge pull request <a href="https://redirect.github.com/gruntjs/grunt/issues/1731">#1731</a> from gruntjs/update-options 5d67e34</li> <li>Fix ci install d13bf88</li> <li>Switch to Actions 08896ae</li> <li>Update grunt-known-options eee0673</li> <li>Add note about a breaking change 1b6e288</li> </ul> <p><a href="https://github.com/gruntjs/grunt/compare/v1.4.0...v1.4.1">https://github.com/gruntjs/grunt/compare/v1.4.0...v1.4.1</a></p> <h2>v1.4.0</h2> <ul> <li>Merge pull request <a href="https://redirect.github.com/gruntjs/grunt/issues/1728">#1728</a> from gruntjs/update-deps-changelog 63b2e89</li> <li>Update changelog and util dep 106ed17</li> <li>Merge pull request <a href="https://redirect.github.com/gruntjs/grunt/issues/1727">#1727</a> from gruntjs/update-deps-apr 49de70b</li> <li>Update CLI and nodeunit 47cf8b6</li> <li>Merge pull request <a href="https://redirect.github.com/gruntjs/grunt/issues/1722">#1722</a> from gruntjs/update-through e86db1c</li> <li>Update deps 4952368</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/gruntjs/grunt/blob/main/CHANGELOG">grunt's changelog</a>.</em></p> <blockquote> <p>v1.5.3 date: 2022-04-23 changes: - Patch up race condition in symlink copying. v1.5.2 date: 2022-04-12 changes: - Unlink symlinks when copy destination is a symlink. v1.5.1 date: 2022-04-11 changes: - Fixed symlink destination handling. v1.5.0 date: 2022-04-10 changes: - Updated dependencies. - Add symlink handling for copying files. v1.4.1 date: 2021-05-24 changes: - Fix --preload option to be a known option - Switch to GitHub Actions v1.4.0 date: 2021-04-21 changes: - Security fixes in production and dev dependencies - Liftup/Liftoff upgrade breaking change. Update your scripts to use --preload instead of --require. Ref: <a href=" |
||
dependabot[bot]
|
94da1ec032
|
Bump @okta/oidc-middleware from 4.0.1 to 5.0.0 in /ee/vulnerability-dashboard (#17601)
Bumps [@okta/oidc-middleware](https://github.com/okta/okta-oidc-middleware) from 4.0.1 to 5.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/okta/okta-oidc-middleware/releases"><code>@okta/oidc-middleware</code>'s releases</a>.</em></p> <blockquote> <h2>5.0.0</h2> <h3>Breaking Changes</h3> <ul> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/54">#54</a> Requires Node >= 12.19.0. Update production dependencies: <ul> <li><code>openid-client@5.1.9</code> (was 3.12.2)</li> </ul> </li> </ul> <h1>4.5.1</h1> <h3>Bug Fixes</h3> <ul> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/43">#43</a> fix: correctly preprends <code>appBaseUrl</code> to redirect url when <code>appBaseUrl</code> contains a base path</li> </ul> <h2>4.5.0</h2> <h3>Features</h3> <ul> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/40">#40</a> Allows passing <code>loginHint</code> to <code>ensureAuthenticated</code></li> </ul> <h3>Bug Fixes</h3> <ul> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/42">#42</a> Fixes <code>appBaseUrl</code> option not prepending to login redirect url</li> </ul> <h2>4.4.0</h2> <h3>Bug Fixes</h3> <ul> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/34">#34</a> Fixes Org AS login issue</li> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/3">#3</a> Call <code>res.redirect()</code> after custom <code>routes.loginCallback.handler</code></li> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/37">#37</a> fix: <code>.logout</code> no longer throws error without valid credentials</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/okta/okta-oidc-middleware/blob/master/CHANGELOG.md"><code>@okta/oidc-middleware</code>'s changelog</a>.</em></p> <blockquote> <h1>5.0.0</h1> <h3>Breaking Changes</h3> <ul> <li><a href="">#</a> Requires Node >= 12.19.0. Update production dependencies: <ul> <li><code>openid-client@5.1.9</code> (was 3.12.2)</li> </ul> </li> </ul> <h1>4.6</h1> <p>-<a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/53">#53</a> Fix: prevents open redirects</p> <h1>4.5.1</h1> <h3>Bug Fixes</h3> <ul> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/43">#43</a> fix: correctly preprends <code>appBaseUrl</code> to redirect url when <code>appBaseUrl</code> contains a base path</li> </ul> <h1>4.5.0</h1> <h3>Features</h3> <ul> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/40">#40</a> Allows passing <code>loginHint</code> to <code>ensureAuthenticated</code></li> </ul> <h3>Bug Fixes</h3> <ul> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/42">#42</a> Fixes <code>appBaseUrl</code> option not prepending to login redirect url</li> </ul> <h1>4.4.0</h1> <h3>Bug Fixes</h3> <ul> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/34">#34</a> Fixes Org AS login issue</li> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/3">#3</a> Call <code>res.redirect()</code> after custom <code>routes.loginCallback.handler</code></li> <li><a href="https://redirect.github.com/okta/okta-oidc-middleware/pull/37">#37</a> fix: <code>.logout</code> no longer throws error without valid credentials</li> </ul> <h1>4.3.0</h1> <h3>Other</h3> <ul> <li>Release after migrating from monorepo</li> <li></li> </ul> <h1>4.2.0</h1> <h3>Bug Fixes</h3> <ul> <li><a href="https://redirect.github.com/okta/okta-oidc-js/pull/1020">#1020</a> Fixes issue with UUID returning null</li> </ul> <h1>4.1.0</h1> <h3>Features</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href=" |
||
Eric
|
b1945b2128
|
Add fleet-vulnerability-dashboard repo to ee/ folder (#17428)
Closes: https://github.com/fleetdm/confidential/issues/4057 Changes: - Added the contents of the fleet-vulnerability-dashboard repo to ee/vulnerability-dashboard - Added a github workflow to deploy the vulnerability dashboard on Heroku - Added a github workflow to test changes to the vulnerability-dashboard - Updated the website's custom configuration to enable auto-approvals/review requests to files in the ee/vulnerability-dashboard folder |