fleet/changes
Lucas Manuel Rodriguez da171d3b8d
Merge pull request from GHSA-pr2g-j78h-84cr
* Fix access control issues with users

* Fix access control issues with packs

* Fix access control issues with software

* Changes suggested by Martin

* All users can access the global schedule

* Restrict access to activities

* Add explicit test for team admin escalation vuln

* All global users should be able to read all software

* Handbook editor pass - Security - GitHub Security (#5108)

* Update security.md

All edits are recorded by line:

395 replaced “open-source” with “open source”
411 replaced “open-source” with “open source”
439 added “the” before “comment”; replaced “repositories,” with “repositories”
445 deleted “being” before “located”
458 added “and” after “PR”
489 replaced “on” with “in”
493 replaced “open-source” with “open source”; Replaced “privileges,” with “privileges”

* Update security.md

line 479

* Update security.md

added (static analysis tools used to identify problems in code) to line 479

* Fix UI

* Fix UI

* revert api v1 to latest in documentation (#5149)

* revert api v1 to latest in documentation

* Update fleetctl doc page

Co-authored-by: Noah Talerman <noahtal@umich.edu>

* Add team admin team policy automation; fix e2e

* Update to company page of the handbook (#5164)

Updated "Why do we use a wireframe-first approach?" section of company.md

* removed extra data on smaller screens (#5154)

* Update for team automations; e2e

* Jira Integration: Cypress e2e tests only (#5055)

* Update company.md (#5170)

This is to update the formatting under "empathy" and to fix the spelling of "help text."
This was done as per @mikermcneil .
This is related to #https://github.com/fleetdm/fleet/pull/4941 and https://github.com/fleetdm/fleet/issues/4902

* fix update updated_at for aggregated_stats (#5112)

Update the updated_at column when using ON DUPLICATE UPDATE so that
the counts_updated_at is up to date

* basic sql formatting in code ie whitespace around operators

* Fix e2e test

* Fix tests in server/authz

Co-authored-by: gillespi314 <73313222+gillespi314@users.noreply.github.com>
Co-authored-by: Desmi-Dizney <99777687+Desmi-Dizney@users.noreply.github.com>
Co-authored-by: Michal Nicpon <39177923+michalnicp@users.noreply.github.com>
Co-authored-by: Noah Talerman <noahtal@umich.edu>
Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com>
Co-authored-by: Martavis Parker <47053705+martavis@users.noreply.github.com>
Co-authored-by: RachelElysia <71795832+RachelElysia@users.noreply.github.com>
2022-04-18 10:27:30 -07:00
..
.keep Issue 1009 calculate diff software (#1305) 2021-07-08 13:57:43 -03:00
activities-rbac Merge pull request from GHSA-pr2g-j78h-84cr 2022-04-18 10:27:30 -07:00
fix-policies-in-standard-query-library Fix policies in standard query library (#5177) 2022-04-15 19:22:48 -03:00
issue-2322-authd-metrics Add http basic auth to /metrics (#4974) 2022-04-07 09:40:53 -03:00
issue-2603-deprecate-global-in-routes Introduce API version 2022-04, deprecate use of /global in paths (#4731) 2022-04-05 11:35:53 -04:00
issue-2814-export-hosts-as-csv Manage Host Page: Export hosts as CSV (#4917) 2022-04-04 14:53:14 -04:00
issue-2825-os-versions Add os versions endpoint (#4749) 2022-03-28 09:15:45 -06:00
issue-2936-ui-includes-jira-integration UI: Settings > Integrations tab, Software Vulnerabilities Webhook v. Integration (#4874) 2022-04-11 15:04:41 -04:00
issue-3269-policy-automation-team Team policy automation (#5004) 2022-04-11 14:46:35 -07:00
issue-3300-policies-not-yet-accurate Indicate that a policy's data is not yet accurate (#5031) 2022-04-11 15:21:34 -05:00
issue-3502-tables Improve UI responsiveness for tables at narrower screen sizes (#4926) 2022-04-07 14:12:38 -05:00
issue-3573-remove-enroll-secrets-from-settings-page Remove viewing enroll secrets on app settings page, add changelog (#4896) 2022-04-04 12:27:13 -04:00
issue-4132-software-messaging Homepage & Manage Host Page: Improved empty software messages (#4953) 2022-04-06 10:08:11 -04:00
issue-4214-vulnerabilities-column Host Details Page: Software vulnerability column (#4836) 2022-04-04 12:33:02 -04:00
issue-4261-software-query Add optimization to Windows software query (#4952) 2022-04-05 10:56:47 -07:00
issue-4262-macOS-versions Add macOS version information to UI dashboard (#4719) 2022-04-05 15:04:00 -05:00
issue-4469-read-replica-non-sso-login Add read replica testing helpers and fix non-sso login bug (#4908) 2022-04-04 16:52:05 -07:00
issue-4521-test-jira-settings-on-config-save Make a test request to Jira when saving AppConfig with an enabled jira integration (#4954) 2022-04-06 07:55:25 -04:00
issue-4537-accessibility-through-tabbing UI Accessibility: Ability to tab through app (#4699) 2022-03-28 17:31:36 -04:00
issue-4540-remove-password-reset-for-api-only-users Remove required password reset flag when creating new API-only user (#4666) 2022-04-12 10:57:57 -03:00
issue-4572-sort-live-queries UI: Sort live queries/policies (#5060) 2022-04-11 17:17:24 -04:00
issue-4734-aggregated-stats-update fix update updated_at for aggregated_stats (#5112) 2022-04-15 14:09:47 -06:00
issue-4754-docker-interface Skip Docker interfaces for host primary IP (#5119) 2022-04-13 11:04:38 -07:00
issue-4792-download-tmp fix rename tmp file (#4862) 2022-04-01 09:03:11 -06:00
issue-4799-fix-table-headers Fix table headers showing or misaligned when selection is active (#4892) 2022-03-31 16:10:11 -05:00
issue-4807-fleet-desktop-windows Orbit: Add Fleet Desktop support to Windows (#4873) 2022-04-01 17:28:51 -03:00
issue-4846-add-jira-integrations-config Add Jira integrations config support (#4863) 2022-03-30 09:10:02 -04:00
issue-4847-queue-jira-ticket-creation-jobs Queue jobs for Jira integration when enabled and new vulnerabilities are found. (#4975) 2022-04-11 16:42:16 -04:00
issue-4864-enter-submits-form UI: Enter button presses action button for forms/modals (#4939) 2022-04-07 20:07:38 -05:00
issue-4879-extend-vuln-period Extend vulnerability age to 30 (#4901) 2022-04-06 11:42:02 -03:00
issue-5048-detect-noperm-redis-standalone Detect the NOPERM error to mean redis cluster is disabled (#5058) 2022-04-11 16:17:30 -04:00
issue-GHSA-pr2g-j78h-84cr Merge pull request from GHSA-pr2g-j78h-84cr 2022-04-18 10:27:30 -07:00
issue-jira-loadtest-add-recent-vuln-max-age Make recent vulnerabilities max age configurable. (#5081) 2022-04-12 14:48:15 -04:00