Commit Graph

2313 Commits

Author SHA1 Message Date
Sam Stepanyan c24e3b14e3
Merge pull request #755 from OWASP/dependabot/github_actions/actions/checkout-4.1.1
Bump actions/checkout from 4.1.0 to 4.1.1
2023-10-31 16:28:28 +00:00
Sam Stepanyan 0de31c6d68
Merge branch 'master' into dependabot/github_actions/actions/checkout-4.1.1
Signed-off-by: Sam Stepanyan <sam.stepanyan@owasp.org>
2023-10-31 03:39:19 +00:00
Sam Stepanyan b1a46436ae
Merge pull request #759 from jimmy-ly00/citrix_cve_2023_4966
New Module: Added CVE-2023-4966 vuln
2023-10-29 21:55:18 +00:00
Sam Stepanyan 157ef461d3
Merge branch 'master' into citrix_cve_2023_4966
Signed-off-by: Sam Stepanyan <sam.stepanyan@owasp.org>
2023-10-29 21:44:40 +00:00
Sam Stepanyan f7abce978e
Merge pull request #757 from jimmy-ly00/master
New Module: Added Confluence Version Scan and CVE-2023-22515
2023-10-29 19:53:06 +00:00
Jimmy 4bb4d91136 Create citrix_cve_2023_4966.yaml 2023-10-26 23:50:35 +01:00
Jimmy 4a1c42f023 Create citrix_cve_2023_4966.yaml 2023-10-26 23:46:19 +01:00
Jimmy 2181214c16
Merge branch 'master' into master 2023-10-23 18:33:13 +01:00
Jimmy a31fdf7735 Added Confluence Scans and CVE-2023-22515 2023-10-23 18:14:39 +01:00
Sam Stepanyan fbc60a2241
Merge pull request #749 from arkid15r/correct-sort-dict-method-name
Fix a typo in sort dictionary method name
2023-10-23 02:10:02 +01:00
Sam Stepanyan 40f7b921bb
Merge branch 'master' into correct-sort-dict-method-name 2023-10-23 01:58:50 +01:00
dependabot[bot] faf711c60d
Bump actions/checkout from 4.1.0 to 4.1.1
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.1.0 to 4.1.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4.1.0...v4.1.1)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-10-17 22:09:34 +00:00
Sam Stepanyan 9a58504340
Merge pull request #752 from OWASP/snyk-fix-21adb73e7146727149c932fb8de1476f
[Snyk] Security upgrade python from 3.11.5-slim to 3.11.6-slim
2023-10-16 22:59:35 +01:00
Sam Stepanyan c84355565f
Merge branch 'master' into snyk-fix-21adb73e7146727149c932fb8de1476f 2023-10-16 22:44:40 +01:00
Sam Stepanyan b1a65b7b08
Merge pull request #753 from Captain-T2004/LanguageTranslations_HINDI
Update to lib/messages/hi.yaml
2023-10-16 22:43:42 +01:00
Sam Stepanyan 83a1586160
Merge branch 'master' into LanguageTranslations_HINDI 2023-10-16 22:30:52 +01:00
Sam Stepanyan d1275caab1
Merge pull request #750 from arkid15r/update-gitignore
Update .gitignore: exclude VSCode workspace files
2023-10-14 10:53:39 +01:00
Captain-T2004 138df61103 Update to lib/messages/hi.yaml
I have thoroughly reviewed the translations in the '/lib/messages' folder for the Hindi language (hi.yaml). I've made several corrections and incorporated enhancements to ensure they are more grammatically accurate and convey a more meaningful message. I have checked and made sure that the application is running properly with the updated translations.

File Changed: /lib/messages/hi.yaml
2023-10-14 15:01:00 +05:30
snyk-bot ba39a2c279
fix: Dockerfile to reduce vulnerabilities
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-5894114
- https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-5894115
- https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-5927132
- https://snyk.io/vuln/SNYK-DEBIAN12-GLIBC-5927132
- https://snyk.io/vuln/SNYK-DEBIAN12-OPENSSL-5812633
2023-10-13 18:50:33 +00:00
Arkadii Yakovets 7d57a3faf4
Update .gitignore: exclude VSCode workspace files 2023-10-10 13:36:13 -07:00
Arkadii Yakovets 1b4e6296a3
Fix a typo in sort dictionary method name 2023-10-10 13:28:09 -07:00
Ali Razmjoo d926de783b
Merge pull request #737 from OWASP/dependabot/pip/netaddr-0.9.0
Bump netaddr from 0.8.0 to 0.9.0
2023-10-05 15:46:35 +02:00
Ali Razmjoo 9f161b7546
Merge pull request #738 from OWASP/dependabot/pip/numpy-1.26.0
Bump numpy from 1.25.2 to 1.26.0
2023-10-05 15:46:24 +02:00
Ali Razmjoo 98a71d87ae
Merge pull request #742 from OWASP/dependabot/github_actions/actions/checkout-4.1.0
Bump actions/checkout from 4.0.0 to 4.1.0
2023-10-05 15:46:15 +02:00
Ali Razmjoo c6813ed31e
Merge pull request #744 from OWASP/dependabot/pip/ipython-8.16.1
Bump ipython from 8.14.0 to 8.16.1
2023-10-05 15:46:07 +02:00
Ali Razmjoo 6f847791fc
Merge pull request #745 from OWASP/dependabot/pip/flask-3.0.0
Bump flask from 2.3.2 to 3.0.0
2023-10-05 15:45:52 +02:00
dependabot[bot] b27e4412a2
Bump flask from 2.3.2 to 3.0.0
Bumps [flask](https://github.com/pallets/flask) from 2.3.2 to 3.0.0.
- [Release notes](https://github.com/pallets/flask/releases)
- [Changelog](https://github.com/pallets/flask/blob/main/CHANGES.rst)
- [Commits](https://github.com/pallets/flask/compare/2.3.2...3.0.0)

---
updated-dependencies:
- dependency-name: flask
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-10-02 22:52:39 +00:00
dependabot[bot] 7ef72940a9
Bump ipython from 8.14.0 to 8.16.1
Bumps [ipython](https://github.com/ipython/ipython) from 8.14.0 to 8.16.1.
- [Release notes](https://github.com/ipython/ipython/releases)
- [Commits](https://github.com/ipython/ipython/commits)

---
updated-dependencies:
- dependency-name: ipython
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-10-02 22:52:35 +00:00
dependabot[bot] 1cd95719a0
Bump actions/checkout from 4.0.0 to 4.1.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.0.0 to 4.1.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4.0.0...v4.1.0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-09-22 22:57:21 +00:00
dependabot[bot] 219ff2280c
Bump numpy from 1.25.2 to 1.26.0
Bumps [numpy](https://github.com/numpy/numpy) from 1.25.2 to 1.26.0.
- [Release notes](https://github.com/numpy/numpy/releases)
- [Changelog](https://github.com/numpy/numpy/blob/main/doc/RELEASE_WALKTHROUGH.rst)
- [Commits](https://github.com/numpy/numpy/compare/v1.25.2...v1.26.0)

---
updated-dependencies:
- dependency-name: numpy
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-09-18 22:16:36 +00:00
dependabot[bot] 95a36d1c58
Bump netaddr from 0.8.0 to 0.9.0
Bumps [netaddr](https://github.com/drkjam/netaddr) from 0.8.0 to 0.9.0.
- [Changelog](https://github.com/netaddr/netaddr/blob/master/CHANGELOG)
- [Commits](https://github.com/drkjam/netaddr/commits)

---
updated-dependencies:
- dependency-name: netaddr
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-09-18 22:15:55 +00:00
Sam Stepanyan da0bd3f33f
Merge pull request #736 from OWASP/securestep9-wp-plugins-update0823
Update wp_plugin_small.txt
2023-09-13 01:51:12 +01:00
Sam Stepanyan a5d52dd147
Update wp_plugin_small.txt
Adding to the list the Wordpress plugins with recent Critical CVEs:
media-library-assistant (CVE-2023-463) and
forminator (CVE-2023-4596)
2023-09-13 01:33:09 +01:00
Sam Stepanyan 7fb110f6ef
Merge pull request #734 from OWASP/dependabot/github_actions/docker/login-action-3
Bump docker/login-action from 2 to 3
2023-09-13 01:28:07 +01:00
Sam Stepanyan 2e0c246357
Merge branch 'master' into dependabot/github_actions/docker/login-action-3 2023-09-13 01:16:30 +01:00
Sam Stepanyan c570fb8c16
Merge pull request #735 from OWASP/dependabot/github_actions/docker/setup-qemu-action-3
Bump docker/setup-qemu-action from 2 to 3
2023-09-13 01:15:57 +01:00
dependabot[bot] 73f92d09a2
Bump docker/setup-qemu-action from 2 to 3
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 2 to 3.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](https://github.com/docker/setup-qemu-action/compare/v2...v3)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-09-12 23:52:31 +00:00
dependabot[bot] 5ade63c4a4
Bump docker/login-action from 2 to 3
Bumps [docker/login-action](https://github.com/docker/login-action) from 2 to 3.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](https://github.com/docker/login-action/compare/v2...v3)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-09-12 23:52:26 +00:00
Sam Stepanyan 10ad53d1c4
Merge pull request #733 from OWASP/dependabot/github_actions/docker/setup-buildx-action-3
Bump docker/setup-buildx-action from 2 to 3
2023-09-13 00:51:50 +01:00
Sam Stepanyan d8d887c852
Merge branch 'master' into dependabot/github_actions/docker/setup-buildx-action-3 2023-09-13 00:38:44 +01:00
Sam Stepanyan 2e7886e6e8
Merge pull request #732 from OWASP/dependabot/github_actions/docker/build-push-action-5
Bump docker/build-push-action from 4 to 5
2023-09-13 00:37:53 +01:00
dependabot[bot] 88df5a2851
Bump docker/setup-buildx-action from 2 to 3
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 2 to 3.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/v2...v3)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-09-12 22:34:46 +00:00
dependabot[bot] 61dbef7f7a
Bump docker/build-push-action from 4 to 5
Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 4 to 5.
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](https://github.com/docker/build-push-action/compare/v4...v5)

---
updated-dependencies:
- dependency-name: docker/build-push-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-09-12 22:34:43 +00:00
Ali Razmjoo ce82452f84
Merge pull request #699 from OWASP/dependabot/pip/py3dns-4.0.0
Bump py3dns from 3.2.1 to 4.0.0
2023-09-10 16:49:09 +02:00
Ali Razmjoo f44f4c7c8f
Merge branch 'master' into dependabot/pip/py3dns-4.0.0 2023-09-10 16:28:19 +02:00
Ali Razmjoo add41136a6
Merge pull request #718 from OWASP/dependabot/pip/pyyaml-6.0.1
Bump pyyaml from 6.0 to 6.0.1
2023-09-10 16:28:13 +02:00
Ali Razmjoo 34e0622268
Merge branch 'master' into dependabot/pip/py3dns-4.0.0 2023-09-10 16:28:07 +02:00
Ali Razmjoo 8c24ed7a61
Merge pull request #722 from OWASP/dependabot/pip/paramiko-3.3.1
Bump paramiko from 3.2.0 to 3.3.1
2023-09-10 16:27:18 +02:00
Ali Razmjoo b3c23de9dd
Merge pull request #723 from OWASP/dependabot/pip/numpy-1.25.2
Bump numpy from 1.24.3 to 1.25.2
2023-09-10 16:27:10 +02:00
Ali Razmjoo 44ae9a67ea
Merge branch 'master' into dependabot/pip/paramiko-3.3.1 2023-09-10 16:13:21 +02:00