New
v5.2.0
What's Changed
π Security Scanner
- Upgraded gitleaks from v8.28.0 to v8.29.0 @secureCodeBoxBot (https://github.com/secureCodeBox/secureCodeBox/pull/3349)
- Upgraded nuclei from v3.4.10 to v3.5.1 @secureCodeBoxBot (https://github.com/secureCodeBox/secureCodeBox/pull/3365)
- Upgraded semgrep from 1.138.0 to 1.143.0 @secureCodeBoxBot (https://github.com/secureCodeBox/secureCodeBox/pull/3306, https://github.com/secureCodeBox/secureCodeBox/pull/3331, https://github.com/secureCodeBox/secureCodeBox/pull/3339, https://github.com/secureCodeBox/secureCodeBox/pull/3347, https://github.com/secureCodeBox/secureCodeBox/pull/3364)
- Upgraded subfinder from v2.9.0 to v2.10.0 @secureCodeBoxBot (https://github.com/secureCodeBox/secureCodeBox/pull/3379)
- Upgraded trivy from 0.67.0 to 0.67.2 @secureCodeBoxBot (https://github.com/secureCodeBox/secureCodeBox/pull/3321)
- Upgraded trivy-sbom from 0.67.0 to 0.67.2 @secureCodeBoxBot (https://github.com/secureCodeBox/secureCodeBox/pull/3320)
- Upgraded whatweb from v0.6.2 to v0.6.3 @secureCodeBoxBot (https://github.com/secureCodeBox/secureCodeBox/pull/3332)
- Avoid confusion in cascading scans between http on port 443 by @Reet00 in https://github.com/secureCodeBox/secureCodeBox/pull/3271
π Bug Fixes
- Fix missing sslyze findings with sslyze 6.x by @J12934 in https://github.com/secureCodeBox/secureCodeBox/pull/3351
π Documentation
- Improve AWS Pod Identity / IRSA Docs by @J12934 in https://github.com/secureCodeBox/secureCodeBox/pull/3314
- Add SCBaaS button by @p4trickweiss in https://github.com/secureCodeBox/secureCodeBox/pull/3350
- Add proposed ADR to use CEL in CascadingRules by @J12934 in https://github.com/secureCodeBox/secureCodeBox/pull/3328
π§ Maintenance
- Update semgrep parser image to explicitly define docker.io prefix by @J12934 in https://github.com/secureCodeBox/secureCodeBox/pull/3330
π Dependencies
Minor dependency updates (43 pull requests). Click to expand.
- Bump the pip-version-updates group across 1 directory with 3 updates by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3289
- Dependabot/gradle/hooks/persistence defectdojo/hook/gradle version updates 27032e4d85 by @Weltraumschaf in https://github.com/secureCodeBox/secureCodeBox/pull/3281
- Bump github.com/onsi/ginkgo/v2 from 2.25.3 to 2.26.0 in /auto-discovery/cloud-aws in the go-version-updates group across 1 directory by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3311
- Bump the github-actions-version-updates group across 1 directory with 3 updates by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3310
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3309
- Bump the npm-version-updates group in /documentation with 5 updates by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3307
- Bump the gradle-version-updates group in /hooks/persistence-defectdojo/hook with 5 updates by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3308
- Update golang Docker tag to v1.25.2 by @renovate[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3313
- Bump nodemailer from 6.10.1 to 7.0.7 in /hooks/notification/hook by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3312
- Update oven/bun Docker tag to v1.3 by @renovate[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3319
- Bump the npm-version-updates group in /documentation with 2 updates by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3322
- Bump the npm-version-updates group across 2 directories with 2 updates by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3323
- Bump the go-version-updates group across 3 directories with 1 update by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3325
- Update golang Docker tag to v1.25.3 by @renovate[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3326
- Bump the github-actions-version-updates group across 1 directory with 4 updates by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3324
- Bump github/codeql-action from 4.30.8 to 4.30.9 in /.github/workflows in the github-actions-version-updates group across 1 directory by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3335
- Bump @types/node from 24.7.2 to 24.8.1 in /hook-sdk/nodejs in the npm-version-updates group across 1 directory by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3336
- Bump python-gitlab from 6.4.0 to 6.5.0 in /scanners/git-repo-scanner/scanner in the pip-version-updates group across 1 directory by @dependabot[bot] in https://github.com/secureCodeBox/secureCodeBox/pull/3337
Full Changelog: https://github.com/secureCodeBox/secureCodeBox/compare/v5.1.0...v5.2.0