fleet/changes
Lucas Manuel Rodriguez 4194c44131
Use NVD API 2.0 to download CVE information (#15102)
#14888

@getvictor This is ready for review, but keeping as draft as there are
probably many tests that need amending.

I used the new version of the `./tools/nvd/nvdvuln/nvdvuln.go` to
compare the current vulnerabilities found in our dogfood environment
with the vulnerabilities found by the code in this PR and both results
match:
```
go run -race -tags fts5 ./tools/nvd/nvdvuln/nvdvuln.go --debug --db_dir ./local --software_from_url <dogfood URL> --software_from_api_token <API_TOKEN> --sync 2>&1 | tee out.txt
[...]
CVEs found and expected matched!
```

- [X] Changes file added for user-visible changes in `changes/` or
`orbit/changes/`.
See [Changes
files](https://fleetdm.com/docs/contributing/committing-changes#changes-files)
for more information.
- [ ] Added/updated tests
- [X] Manual QA for all new/changed functionality

---------

Co-authored-by: Victor Lyuboslavsky <victor@fleetdm.com>
Co-authored-by: Victor Lyuboslavsky <victor.lyuboslavsky@gmail.com>
2023-11-21 12:30:07 -06:00
..
.keep Issue 1009 calculate diff software (#1305) 2021-07-08 13:57:43 -03:00
11446-queries-run-when-forbidden Fixes to /fleet/queries/run endpoint (#14909) 2023-11-06 11:03:42 -06:00
12409-allow-to-revert-deleted-munki Allow reverting a deleted Munki. (#15183) 2023-11-17 12:21:42 -06:00
12634-keep-user-email feat: don't remove user email from activity feed when user deleted (#14975) 2023-11-09 15:50:01 -05:00
13160-sort-order fix: sort order for Last restarted (#14878) 2023-11-15 16:42:57 -05:00
14102-fix-label-filter-select UI – Improve UX of label filter dropdown (#15199) 2023-11-20 12:42:55 -08:00
14116-citrix-false-pos fix: address citrix workspace false positive (#15152) 2023-11-17 13:42:05 -05:00
14260-host-expiry-window UI – Update Advanced settings page (#15181) 2023-11-16 14:32:53 -08:00
14345-JIT-provisioned-login-activities UI – Clarify activity items for JIT provisioned SSO user initial logins (#15192) 2023-11-20 10:29:36 -08:00
14361-fleetctl-apply-changes allow fleetctl to configure windows mdm profiles for teams and "no team" (#15161) 2023-11-15 18:04:24 -03:00
14362-mdm-profiles-summary-api Add GET /mdm/profiles/summary endpoint (#15077) 2023-11-17 10:49:30 -06:00
14424-hosts-filter-windows-profiles-status Add Windows MDM profiles to host details API response (#15210) 2023-11-20 14:34:57 -06:00
14493-truncate-long-results-columns UI – Truncate long query results cells (#15079) 2023-11-10 13:31:11 -08:00
14571-carves-after-parameter Enabled support and validation of 'after' parameter for several endpoints (#15047) 2023-11-09 13:18:29 -06:00
14752-windows-scripts UI – Add support for Windows powershell scripts (#15128) 2023-11-15 11:28:57 -08:00
14753-windows-ps1-api 14753 windows ps1 api (#15113) 2023-11-14 09:23:51 -05:00
14763-show-host-display-name-in-query-report Show host display name in query results. (#15173) 2023-11-16 14:26:57 -06:00
14824-NVD-work report metrics from every 3 days to every 24H (#15024) 2023-11-08 11:08:31 -05:00
14888-nvd-cve-sync-conversion Use NVD API 2.0 to download CVE information (#15102) 2023-11-21 12:30:07 -06:00
14991-bump-minimum-osquery-versions Bump minimum osquery versions (#15101) 2023-11-15 14:18:35 -08:00
15135-remove-atom-packages Remove atom_packages table from software inventory query (#15195) 2023-11-17 15:26:17 -06:00
15143-CPE-false-matches-on-bundle-id Tightening the CPE matching to reduce false positive rate. (#15187) 2023-11-20 11:59:31 -06:00
fix-redis-cluster-disabled-detection Fix detection of Redis cluster on RedisLabs (#15104) 2023-11-15 09:03:06 -05:00
issue-11665-two-column-edit-columns-modal Update edit columns modal to have two columns (#15000) 2023-11-08 15:34:59 +00:00
issue-14359-windows-profiles Implement windows custom profiles in fleet UI (#15205) 2023-11-20 18:35:46 -03:00
issue-14360-add-windows-profiles-tables Implement the database migrations for the Windows profiles story. (#14973) 2023-11-07 09:28:43 -05:00
issue-14363-api-windows-profiles Add endpoint to get or download a profile (Windows and macOS) (#15105) 2023-11-14 08:19:29 -05:00
issue-14366-api-upload-profiles Add endpoint to upload an MDM custom profile for Windows and macOS (#15150) 2023-11-15 10:58:59 -05:00
issue-14446-validate-enable-windows-mdm Validate that WSTEP is configured before enabling Windows MDM (#14858) 2023-11-09 10:08:54 -03:00
issue-14708-fix-cached-team-mdm Implement custom cloning of Team MDM config for the cached mysql layer. (#14965) 2023-11-07 09:51:55 -05:00
issue-15050-pluralize-query-deletion-activity-log Fix pluralization in the "delete multiple queries" activity log (#15099) 2023-11-17 12:22:47 -08:00
issue-15111-list-profiles Add endpoint to list macOS and Windows profiles combined, paginated (#15165) 2023-11-15 15:36:20 -05:00
windows-custom-settings-configs allow to set mdm.windows_settings.custom_settings in configs (#15145) 2023-11-15 13:58:46 -03:00