This repository has been archived by the owner on May 23, 2023. It is now read-only.
Releases: HXSecurity/DongTai-webapi
Releases · HXSecurity/DongTai-webapi
Release-1.3.1
What's Changed
- Bidaya0 patch changelog release 1.3.0 by @Bidaya0 in #418
- Security cspheaders by @Bidaya0 in #419
- Fix clickjack header middleware position by @Bidaya0 in #420
- Merge main by @Bidaya0 in #421
- bugfix:Boundary value catch by @Bidaya0 in #422
- Revert "Revert "Revert "Update deploy_to_test.yml""" by @Bidaya0 in #408
- Create ApiTest.yml by @Bidaya0 in #423
- Versioncontrol by @Bidaya0 in #424
- fix:version_update encoding by @Bidaya0 in #425
- fix: unifed version id by @Bidaya0 in #426
- Feature/versioncontrol by @Bidaya0 in #427
- Bidaya0 patch workflow yml by @Bidaya0 in #428
- Bidaya0 patch main stream version by @Bidaya0 in #429
- Update version.sql by @Bidaya0 in #430
- add cprofile-middleware by @Bidaya0 in #432
- Update deploy_to_test.yml by @Bidaya0 in #433
- add batect into develop and test stage by @Bidaya0 in #434
- make agent install deco by @Bidaya0 in #435
- union vul_summary count as one query to reduce IO time by @Bidaya0 in #436
- iast/base/agent.py revert by @Bidaya0 in #437
- talent status enable error by @Bidaya0 in #438
- optimise: gather query to reduce IO cost by @Bidaya0 in #440
- fix api slow response by @jinghao1 in #439
- Bump django from 3.2.11 to 3.2.12 by @dependabot in #441
- bugfix/project vulnerary show all vulnerary instead of only comfirmed by @Bidaya0 in #442
- bugfix/project report filename as project name by @Bidaya0 in #443
- bugfix/project_version_current-user-permission-and-remove-agent-statu… by @Bidaya0 in #445
- optimise: method graph query break large in to exists by @Bidaya0 in #444
- bugfix: apitest api header query add flat=True in query by @Bidaya0 in #446
- bugfix:change project_add and project_verison_update when api change by @Bidaya0 in #447
- development: add apitimelog to record api time by @Bidaya0 in #448
- Optimise/api route cover rate by @Bidaya0 in #449
- optimise: vuln list serilizer query by @Bidaya0 in #450
- optimise/engine_method_pool_sca use select_related to reduce query io by @Bidaya0 in #451
- optimise: sca list query time reduce by @Bidaya0 in #452
- optimise: engine_method_pool by @Bidaya0 in #453
- optimise: vul summary query remove unnecesssary condition by @Bidaya0 in #454
- optimise: logs api use cache to avoid count in every query by @Bidaya0 in #455
- Revert "optimise: logs api use cache to avoid count in every query" by @Bidaya0 in #456
- Enhanchment/sca package name modify by @Bidaya0 in #457
- bugfix: vul_summary groupby type fix by @Bidaya0 in #458
- Optimise i18n by @Bidaya0 in #459
- Revert "optimise: vuln list serilizer query" by @Bidaya0 in #460
Full Changelog: v1.3.0...v1.3.1
Release-1.3.0
What's Changed
- Update deploy_to_test.yml by @Bidaya0 in #374
- fix: type name query logic by @Bidaya0 in #379
- Enhancement: optimise agent_id query logic by @Bidaya0 in #381
- Developer update by @Bidaya0 in #382
- bugfix: change force param retrive by @Bidaya0 in #384
- Bugfix use pyre2 to prevent redos by @Bidaya0 in #387
- develop:config.ini.example-change by @Bidaya0 in #388
- bugfix:-utf-8-BOM-header by @Bidaya0 in #389
- Feature/issue 386 by @Bidaya0 in #390
- Feature issue 385 by @Bidaya0 in #391
- fix:bug-project_modify by @Bidaya0 in #392
- Update settings.py by @Bidaya0 in #393
- change sca from database to api by @luzhongyang in #394
- feature:project_detail add base_url test_req_header_key test_req_head… by @Bidaya0 in #395
- Bidaya0 patch dockerfile by @Bidaya0 in #396
- bugfix:i18n and talent modify by @Bidaya0 in #397
- bugfix: msg when talent exist by @Bidaya0 in #398
- fix show vul bug by @luzhongyang in #399
- fix vul show bugs by @luzhongyang in #400
- bugfix:project add i18n msg change by @Bidaya0 in #401
- compile i18n messages by @Bidaya0 in #403
- add sca api to openapi project by @luzhongyang in #402
- openapi spec export by @Bidaya0 in #405
- Feature: add release action by @exexute in #373
- fix level show by @luzhongyang in #406
- change config.ini for test by @Bidaya0 in #407
- fix level show bug by @luzhongyang in #409
- Feature/sca lib by @Bidaya0 in #410
- add permission by @Bidaya0 in #411
- Update views.py by @Bidaya0 in #417
Full Changelog: v1.2.0...v1.3.0
Release-1.2.0
What's Changed
- Update CHANGELOG_CN.md by @Bidaya0 in #339
- Update DockerfileTest by @Bidaya0 in #343
- fix history_data vul detected missing after vul_type modify by @Bidaya0 in #348
- feature/issue-350:list with id support project agent vuls scas @SpenserCai by @Bidaya0 in #351
- Update settings.py by @Bidaya0 in #354
- feature:#355:add api to batch modify hook rule type by @Bidaya0 in #356
- optimise sql to reduce io times in vuln/summary by @Bidaya0 in #358
- a temporary sca export for issue-377&380 by @Bidaya0 in #345
- fix confict by @Bidaya0 in #359
- bugfix: field binding incorrect by @Bidaya0 in #360
- bugfix:sensitive hook rule page field binding by @Bidaya0 in #361
- feature: add sca export i18n and optimise by @Bidaya0 in #362
- bugfix:search by name key error by @Bidaya0 in #363
- bugfix:search by name by @Bidaya0 in #364
- feature:add license field in sca by @Bidaya0 in #366
- Fix: sensitive regex match by @exexute in #367
- fix sca export filename by @Bidaya0 in #368
- fix regex match test by @Bidaya0 in #369
- Develop Document Update thanks for @xzy9999 by @Bidaya0 in #371
- Release 1.2.0 changelog by @Bidaya0 in #372
Full Changelog: v1.1.4...v1.2.0
Release-1.1.4
What's Changed
- Update agent.py by @Bidaya0 in #253
- Feature/issue 247 by @Bidaya0 in #254
- feature:feature/issue-248 by @Bidaya0 in #255
- fix import error by @Bidaya0 in #256
- fix import error by @Bidaya0 in #257
- Scan policy template management #247 by @piexlmax in #258
- fix bugs and add switch for vuln validation by @Bidaya0 in #263
- fix bugs in scan strategys by @Bidaya0 in #264
- fix bugs keyerror by @Bidaya0 in #265
- add allow_blank to vul_fix by @Bidaya0 in #267
- fix query bug by @Bidaya0 in #268
- fix hook_rule add bug by @Bidaya0 in #270
- add logic to change hook type by @Bidaya0 in #272
- add lower and strip to name by @Bidaya0 in #274
- fix permissions for sensitive information by @Bidaya0 in #276
- fix delete logic by @Bidaya0 in #277
- Added policy template to select all and patch to change status by @Bidaya0 in #279
- add try when object not exist by @Bidaya0 in #280
- add vul_validation field in single retrive by @Bidaya0 in #281
- test release_webapi.yml by @luzhongyang in #282
- fixflake by @Bidaya0 in #283
- fix :not enough values to unpack (expected 6, got 5) by @Bidaya0 in #285
- change return field by @Bidaya0 in #286
- fix choice by @Bidaya0 in #287
- change permission in sensitive rule by @Bidaya0 in #288
- fix permission bug by @Bidaya0 in #289
- change agent name to alias by @Bidaya0 in #290
- change pagination data position by @Bidaya0 in #291
- change perimission by @Bidaya0 in #292
- add php agent by @Bidaya0 in #293
- enable python agent by @Bidaya0 in #294
- fix-edge-case by @Bidaya0 in #295
- swaggerupdate by @Bidaya0 in #296
- Update deploy_to_test.yml by @Bidaya0 in #297
- Bidaya0 create——changelog by @Bidaya0 in #298
- Add iast server logs to Aliyun SLS by @hardy4yooz in #301
- Split the logic of importing the app to support extension by @Bidaya0 in #303
- Add app monkey patch for For secondary development by @Bidaya0 in #304
- Bidaya0 temporary disable pythonagent by @Bidaya0 in #305
- Failure to properly handle database out of synchronization with agent language by @Bidaya0 in #307
- Modify the default testrunner by @Bidaya0 in #309
- Add VulDetail get_server Boundary value control by @Bidaya0 in #311
- fix:issue-312 change validation logic in vul serializers by @Bidaya0 in #313
- fix:bug/issue-316 change query logic to avoid timeout by @Bidaya0 in #317
- add field scan_name to solve scanlist missing caused by permission by @Bidaya0 in #318
- fix serilizer fields No indication of range by @Bidaya0 in #320
- add is_need_http_detail by @Bidaya0 in #322
- Bidaya0 changelog 1.1.4 by @Bidaya0 in #323
- add-dead-link-check by @Bidaya0 in #325
- Bidaya0 update md by @Bidaya0 in #327
- Bidaya0 patch 1 by @Bidaya0 in #329
- fix:report export vul_name incorrect by @Bidaya0 in #330
- Create codeql-analysis.yml by @Bidaya0 in #333
- Revert "Create codeql-analysis.yml" by @Bidaya0 in #334
- Create codeql-analysis.yml by @Bidaya0 in #335
- add field to record userid in user-feedback by @Bidaya0 in #336
- Fix param name in vul detail by @Bidaya0 in #337
New Contributors
Full Changelog: v1.1.2...v1.1.4
Release-1.1.3
What's Changed
- Update agent.py by @Bidaya0 in #253
- Feature/issue 247 by @Bidaya0 in #254
- feature:feature/issue-248 by @Bidaya0 in #255
- fix import error by @Bidaya0 in #256
- fix import error by @Bidaya0 in #257
- Scan policy template management #247 by @piexlmax in #258
- fix bugs and add switch for vuln validation by @Bidaya0 in #263
- fix bugs in scan strategys by @Bidaya0 in #264
- fix bugs keyerror by @Bidaya0 in #265
- add allow_blank to vul_fix by @Bidaya0 in #267
- fix query bug by @Bidaya0 in #268
- fix hook_rule add bug by @Bidaya0 in #270
- add logic to change hook type by @Bidaya0 in #272
- add lower and strip to name by @Bidaya0 in #274
- fix permissions for sensitive information by @Bidaya0 in #276
- fix delete logic by @Bidaya0 in #277
- Added policy template to select all and patch to change status by @Bidaya0 in #279
- add try when object not exist by @Bidaya0 in #280
- add vul_validation field in single retrive by @Bidaya0 in #281
- test release_webapi.yml by @luzhongyang in #282
- fixflake by @Bidaya0 in #283
- fix :not enough values to unpack (expected 6, got 5) by @Bidaya0 in #285
- change return field by @Bidaya0 in #286
- fix choice by @Bidaya0 in #287
- change permission in sensitive rule by @Bidaya0 in #288
- fix permission bug by @Bidaya0 in #289
- change agent name to alias by @Bidaya0 in #290
- change pagination data position by @Bidaya0 in #291
- change perimission by @Bidaya0 in #292
- add php agent by @Bidaya0 in #293
- enable python agent by @Bidaya0 in #294
- fix-edge-case by @Bidaya0 in #295
- swaggerupdate by @Bidaya0 in #296
- Update deploy_to_test.yml by @Bidaya0 in #297
- Bidaya0 create——changelog by @Bidaya0 in #298
- add changelog by @Bidaya0 in #299
- Update CHANGELOG.md by @Bidaya0 in #300
New Contributors
Full Changelog: v1.1.2...v1.1.3
Release-1.1.2
Release-1.1.1
Feature
- Added sensitive information rule management
#188 - Changed the relationship between the original strategy and hook rules to adapt to the design of sensitive rules #201
- Improved strategy management
#200 - It is now possible to set the CSRF trusted domain name through config.ini #197
Bug Fixes
- Inconsistent statistics due to multiple versions of the project
#186 - The corresponding strategy was not created at the same time when the dangerous rule was created #190
- Fix the program error when there is a null value #192
- Unreasonable escaping causes the text to display incorrectly #195
- CSRF Failed: Referer checking failed - https://dev-iast.huoxian.cn:1024/taint/search does not match any trusted origins. #197
What's Changed
- fix user auth bug by @luzhongyang in #178
- Update deploy-dongtai-webapi-prod.yml by @Bidaya0 in #180
- Add python agent in test env by @Bidaya0 in #182
- Update deploy_webapi_to_aws.yml by @Bidaya0 in #183
- update openapi by @Bidaya0 in #184
- fix:Inconsistent statistics due to multiple versions of the project by @Bidaya0 in #187
- fix:issue-190 add the corresponding creation strategy logic by @Bidaya0 in #191
- Dealing with None by @Bidaya0 in #193
- Revert "fix:issue-190 add the corresponding creation strategy logic" by @Bidaya0 in #194
- Unreasonable escaping causes the text to display incorrectly by @Bidaya0 in #196
- add csrf origin setting to config.ini by @Bidaya0 in #198
- Add deploy action to dev by @hardy4yooz in #199
- Add scarf tracking pixel by @hardy4yooz in #202
- Sensitive information rule configuration by @Bidaya0 in #203
- fix response data by @Bidaya0 in #204
- add requirement by @Bidaya0 in #215
- Feature issue200 by @Bidaya0 in #216
- fix state in single recheck by @Bidaya0 in #218
- strategy return all when page data is None by @Bidaya0 in #223
- vul summary fix when same name in strategy and hooktype by @Bidaya0 in #242
- change permission by @Bidaya0 in #244
- fix bug after vulmodel change by @Bidaya0 in #245
Full Changelog: v1.1.0...v1.1.1
Release-1.1.0
What's Changed
Feature
- Add project version tag for agent
- Feature/issue/319 Export project report asynchronous
- Add keyword for search by @Bidaya0 in #164
Bug fix
-
Fix action files by @hardy4yooz in #161
-
fix:HXSecurity/DongTai#330 by @Bidaya0 in #169
-
Feature/issue/319 by @luzhongyang in #170
-
Feature/issue/319 by @luzhongyang in #171
-
pause django api test by @luzhongyang in #172
-
Feature/issue/319 by @luzhongyang in #176
New Contributors
- @luzhongyang made their first contribution in #170
Full Changelog: v1.0.6...v1.1.0
Release-1.0.6
- Add the message center
- Add agent threshold configuration
- Add agent registration time and startup time display
- Add Agent alias
- bug fixs
What's Changed
- django.po complie to fix i18n missing by @Bidaya0 in #106
- Bug/issue 139 by @Bidaya0 in #108
- Feature/issue 137 Api navigations by @Bidaya0 in #107
- heartbeat by @Bidaya0 in #109
- HXSecurity/DongTai#155 fix a bug which the version number api does not properly handle administrator permissions by @Bidaya0 in #110
- Feature/issue 156 by @Bidaya0 in #111
- Bug/issue 161 by @Bidaya0 in #112
- Feature/issue 156 by @Bidaya0 in #113
- Bug/issue 162 by @Bidaya0 in #114
- xss bugfix by @Bidaya0 in #116
- status -> status_id by @Bidaya0 in #118
- 1.0.3 Api Route,Service status monitoring,And bug fixes by @Bidaya0 in #117
- modify the default number of return items by @Bidaya0 in #119
- Bug/issue 173 change domain and adjust request timeout by @Bidaya0 in #121
- modify the default number of return items by @Bidaya0 in #120
- feature/issue-214 Registration email modification by @Bidaya0 in #122
- Feature/issue 214 Registration email modification by @Bidaya0 in #124
- Bump sqlparse from 0.4.1 to 0.4.2 by @dependabot in #125
- Registration email modification by @Bidaya0 in #123
- 20210916/GitHub contributors by @Bidaya0 in #128
- Release 1.0.4 by @Bidaya0 in #129
- issue-242 Add order_by whitelist to avoid abnormal errors by @Bidaya0 in #132
- Apidocument by @Bidaya0 in #133
- feature:HXSecurity/issue-252 by @Bidaya0 in #134
- Enter custom rules by programming language by @Bidaya0 in #135
- fix:HXSecurity/issue-248 by @Bidaya0 in #136
- openapi setting restrict by @Bidaya0 in #137
- bug/issue-240 by @Bidaya0 in #138
- fix:HXSecurity/DongTai/issues/260 by @Bidaya0 in #139
- fix GET to POST by @Bidaya0 in #140
- provide iconreplace api and icon files support by @Bidaya0 in #141
- feature:HXSecurity:issue/268 add default language selection for user by @Bidaya0 in #142
- confilct resoved by @Bidaya0 in #144
- feature:HXSecurity-issue/266 by @Bidaya0 in #145
- Develop by @Bidaya0 in #143
- README UPDATE by @Bidaya0 in #146
- README UPDATE by @Bidaya0 in #147
- Update README by @Bidaya0 in #148
- document fix in engine_hook_rule_add by @Bidaya0 in #149
- Feature/issue 279 by @Bidaya0 in #150
- fix:iast/views/project_report_export.py file not found by @Bidaya0 in #151
- fix:enable github_contributor api by @Bidaya0 in #152
- fix:enable github_contributor api by @Bidaya0 in #155
- feature:agent alias agent limit and startup time by @Bidaya0 in #158
- Feature/issue 285 by @Bidaya0 in #159
- Add action for push image to DockerHub by @hardy4yooz in #156
- Release 1.0.5 by @Bidaya0 in #160
New Contributors
- @dependabot made their first contribution in #125
- @hardy4yooz made their first contribution in #156
Full Changelog: 1.0.2...v1.0.6
Release-1.0.3
- Fixed the regex error of the taint chain search, and added a hint. HXSecurity/DongTai#161 HXSecurity/DongTai#139
- The i18n field is added to separate the models with repeated character fields.
- Increase the display of api navigation function HXSecurity/DongTai#137
- Added api navigation replay function - Fixed duplicate data caused by improper constraints. HXSecurity/DongTai#140
- Reduced search api response time
- Fixed the missing project components and vulnerability display caused by incorrectly restricting the Agent status.
- Added Agent status display. HXSecurity/DongTai#147
- Added openapi and engine service status display. HXSecurity/DongTai#156
- Fixed a bug with multiple current versions due to improper handling of user permissions. HXSecurity/DongTai#155
- i18n text modification. HXSecurity/DongTai#136 HXSecurity/DongTai#162 HXSecurity/DongTai#160
HXSecurity/DongTai#159
HXSecurity/DongTai#145