Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1103 commits
Select commit Hold shift + click to select a range
f8b4f17
Merge branch 'conjur-cloud' into CONCLOUDSE-260-remove-data-requireme…
May 27, 2024
7d3d132
CONCLOUDSE-260: Merge pull request #312 from Conjur-Enterprise/CONCL…
May 27, 2024
2c99493
Merge remote-tracking branch 'origin/conjur-cloud' into conjur-cloud
NofarVered May 27, 2024
71bc889
sync part1 : support for arm64 + cli version 8 + Add ARM64 packages b…
marek-jakubowski Nov 9, 2023
891fa29
ONYX-54541 : Synch with conjur v13.3 (part 1/3)
nofarNahum May 28, 2024
b99cf25
Add Issuer API to telemtries
May 27, 2024
9f7514d
CONCLOUSE-261: Merge pull request #320 from Conjur-Enterprise/CONCLOU…
May 30, 2024
57d4f1c
ONYX-55835: chore:Add email notification upon main branch failure
ld-cyberark Apr 30, 2024
97c75d7
Merge pull request #277 from Conjur-Enterprise/ONYX-55835
ld-cyberark May 30, 2024
862c682
Filter data out
May 15, 2024
7c0938a
CONCLOUDSE-252: Merge pull request #293 from Conjur-Enterprise/CONCL…
May 30, 2024
6b8a0ce
Filter secret_access_key
May 28, 2024
a088d9f
CONCLOUDSE-250: Merge pull request #323 from Conjur-Enterprise/CONCL…
May 30, 2024
19963d8
upgrade rack to 2.2.8.1 + Upgrade puma to 6.4.2 + Update authn_k8s te…
codihuston Jan 4, 2024
53ebd71
Merge pull request #326 from Conjur-Enterprise/Nofar/sync/30-5
nofarNahum May 30, 2024
cfe91e6
remove mask from acces_key
yoavgeva Jun 2, 2024
854accb
ONYX-00000: Merge pull request #328 from Conjur-Enterprise/change-mas…
yoavgeva Jun 2, 2024
8e82818
data field is no longer required
May 16, 2024
ab1fbb5
Merge pull request #313 from Conjur-Enterprise/CONCLOUDSE-272-verify-…
liubovra Jun 5, 2024
33197ef
Enable verified edges to show any secret
Jun 13, 2024
f6af876
ONYX-57459: Merge pull request #334 from Conjur-Enterprise/ONYX-57459…
Jun 18, 2024
e8e7b4c
CONJSE-1875: Recursively delete policy objects
szh May 29, 2024
4321570
Add rake tasks to clean up orphaned roles
szh Jun 3, 2024
65d5e0c
Merge pull request #340 from Conjur-Enterprise/recursive-delete
egvili Jun 18, 2024
dec9ece
Fix telemetry
ofiraburstein Jun 18, 2024
af15fc0
Merge pull request #339 from Conjur-Enterprise/ofira-test
ofiraburstein Jun 19, 2024
4b9cffb
suppress rack logs
egvili Jun 19, 2024
5ec7e32
Merge pull request #344 from Conjur-Enterprise/suppress-rack
egvili Jun 20, 2024
f852b76
Extend delete recursive test
egvili Jun 20, 2024
df0113f
Merge pull request #345 from Conjur-Enterprise/recursive-delete-tests
egvili Jun 20, 2024
6fb248d
add edge get singal secrete
Jun 17, 2024
d1b212d
ONYX-57460: Merge pull request #338 from Conjur-Enterprise/ONYX-5746…
Jun 20, 2024
1aa1f6f
Add test to verfity correct error
Jun 24, 2024
bc618bc
ONYX-44151: Merge pull request #347 from Conjur-Enterprise/ONYX-4415…
Jun 24, 2024
16dca21
Remove DB call from possibly edge
Jun 24, 2024
bc4a4fe
Onyx 58315 : Merge pull request #346 from Conjur-Enterprise/ONYX-5831…
Jun 24, 2024
4670e65
ONYX-58440: add ':' to allowed chars for name in workload create api
liubovra Jun 27, 2024
9a89fd8
Merge pull request #352 from Conjur-Enterprise/workload_name
liubovra Jun 30, 2024
c4b83aa
ONYX-58477: change minimal flag to projection flag in get issuer api
liubovra Jul 1, 2024
3aa903f
ONYX-58513: chnage allowed size for workload name to 120 from 60
liubovra Jul 1, 2024
7ecde08
Merge pull request #358 from Conjur-Enterprise/worload-name-size
liubovra Jul 1, 2024
6142cad
update Gemfile
Jun 24, 2024
cd3747c
CONCLOUDESE-287: Merge pull request #348 from Conjur-Enterprise/CONCL…
Jul 1, 2024
d695759
Merge branch 'conjur-cloud' into issuer-projection
liubovra Jul 1, 2024
f8dc6ed
ONYX-58477: change minimal flag to projection flag in get issuer api
liubovra Jul 1, 2024
9b190ac
limit ttl range
Jul 2, 2024
ba1bed6
ONYX-57641: Merge pull request #361 from Conjur-Enterprise/ONYX-5764…
Jul 2, 2024
d217ca1
CONJSE-1875: Recursive cleanup of orphaned roles and resources
szh Jun 18, 2024
e3fceca
Call cleanup rake on startup
egvili Jul 2, 2024
f345a1c
Merge branch 'conjur-cloud' into issuer-projection
liubovra Jul 3, 2024
16898cc
ONYX-58477: change minimal flag to projection flag in get issuer api
liubovra Jul 3, 2024
148d4dd
ONYX-58214: Merge pull request #362 from Conjur-Enterprise/clean-rake…
egvili Jul 3, 2024
71ebacb
Merge branch 'conjur-cloud' into issuer-projection
liubovra Jul 3, 2024
4d06df6
ONYX-58477: change minimal flag to projection flag in get issuer api
liubovra Jul 3, 2024
9568f85
ONYX-999: Merge pull request #360 from Conjur-Enterprise/issuer-proje…
egvili Jul 4, 2024
e201f27
Check resource visibility
egvili Jun 20, 2024
bc805f1
Merge pull request #355 from Conjur-Enterprise/403-404
yoavgeva Jul 4, 2024
f432262
ONYX-58477: fixing test
liubovra Jul 7, 2024
c991ca2
Merge pull request #366 from Conjur-Enterprise/issuers-test
liubovra Jul 7, 2024
e0700e7
ONYX-57016: Add clear cache step as backround to all cucumber tests s…
liubovra Jul 7, 2024
89c5e19
Merge pull request #370 from Conjur-Enterprise/redis-clear-cucmber
liubovra Jul 8, 2024
bd5524c
Remove ghosts cleaner
egvili Jul 8, 2024
fce6470
Merge pull request #369 from Conjur-Enterprise/remove-ghost-cleaner
egvili Jul 8, 2024
017303c
Add timestamp to Edge API response
aloncarmel111 Jul 7, 2024
f53696c
Merge pull request #368 from Conjur-Enterprise/add_timestamp
aloncarmel111 Jul 8, 2024
6ad3a1c
ONYX-58767: return the issuers list as is if its empty in sorting
liubovra Jul 8, 2024
ed62e62
Merge pull request #371 from Conjur-Enterprise/issuers-sort-empty-list
liubovra Jul 9, 2024
ca1e4a0
CONJSE-1875: Recursive cleanup of orphaned roles and resources
szh Jun 18, 2024
f5296a3
Add timestamp to Edge API response
aloncarmel111 Jul 8, 2024
601c1be
Merge pull request #373 from Conjur-Enterprise/alon_test
aloncarmel111 Jul 9, 2024
1ffa95d
events table with trigger and sequel module
NofarVered Jul 3, 2024
6ad5d6a
Merge pull request #363 from Conjur-Enterprise/create_events_table
egvili Jul 10, 2024
33519fb
Merge branch 'conjur-cloud' into fix-rspec
liubovra Jul 10, 2024
d29f91c
CONJSE-1875: Recursive cleanup of orphaned roles and resources
szh Jun 18, 2024
76758e3
Merge pull request #372 from Conjur-Enterprise/fix-rspec
liubovra Jul 10, 2024
3e3032f
stop printing puma's stacktrace
Jul 9, 2024
a9d8513
Concloudse 249: Merge pull request #374 from Conjur-Enterprise/CONCLO…
Jul 11, 2024
4bbde8d
Secret service
egvili Jul 10, 2024
7634df6
Merge pull request #378 from Conjur-Enterprise/secret-service
egvili Jul 15, 2024
f1d2123
Secret service - secrets V1 + V2 + other
egvili Jul 15, 2024
0ac4ab2
Merge pull request #383 from Conjur-Enterprise/secret-service
egvili Jul 16, 2024
da8d5a3
Delete from cache as well from DB
Jul 18, 2024
4854b69
ONYX-57026: Merge pull request #392 from Conjur-Enterprise/ONYX-5702…
Jul 18, 2024
d11e5c6
add localstack infrastructure
NofarVered Jul 15, 2024
f3c8333
ONYX-57837 : localstack infrastucture
nofarNahum Jul 18, 2024
c766dd6
CNJR-2607 Fix for nested resources removal not audited when replacing…
Feb 26, 2024
c29e673
CNJR-4374: improve policy_log trigger performance
tarnowsc Mar 13, 2024
044177e
Rename to impact after remove error log changelog
egvili Jul 21, 2024
50ad5d0
Switch to statement level triggers for data loaded into policy_log
marek-jakubowski Mar 25, 2024
f9d6ab3
Rename to impact after policy_log_trigger changelog
egvili Jul 21, 2024
b42e46f
CHANGELOG + fix build_n_push.sh
egvili Jul 22, 2024
24a8533
Change log to src from opt
Jul 22, 2024
5099bee
Merge pull request #397 from Conjur-Enterprise/audit-imp
egvili Jul 28, 2024
41d3ac4
Fix flakiness Undefined method for nil class
egvili May 23, 2024
6253024
Merge pull request #401 from Conjur-Enterprise/slosilo_key_nil
egvili Jul 28, 2024
f4344a7
CNJR-4420: improve 'is_role_allowed_to' performance on large datasets
tarnowsc Mar 7, 2024
fffb53e
Changelog
egvili Jul 29, 2024
663364e
Merge pull request #402 from Conjur-Enterprise/imp-allowed-to
egvili Jul 30, 2024
0abd68e
CONJSE-1875: Recursive cleanup of orphaned roles and resources
szh Jun 18, 2024
ce095ae
ONYX-58718: retry connect to gcp on failure
liubovra Jul 31, 2024
3a62cab
publish to tpoic sns with rspec tests
NofarVered Jul 21, 2024
0dd8ba6
ONYX-58228 : Publish message to SNS topic function
nofarNahum Jul 31, 2024
1048e31
Merge branch 'conjur-cloud' into gcp-test
liubovra Aug 1, 2024
fb583da
Merge pull request #405 from Conjur-Enterprise/gcp-test
liubovra Aug 1, 2024
0f14918
Unsubscribe after pubsub
egvili Aug 1, 2024
59dfdf2
Merge pull request #410 from Conjur-Enterprise/fix-telemetry-flakiness
egvili Aug 4, 2024
56852bb
Work on fetch from events, sending to sns and delete from events tabl…
yoavgeva Jul 15, 2024
2572bd1
Integration with Configuration Manager
egvili Jul 17, 2024
2d0b446
Merge pull request #411 from Conjur-Enterprise/config-server
egvili Aug 7, 2024
0dff0dc
Work on fetch from events, sending to sns and delete from events tabl…
yoavgeva Jul 15, 2024
26532a6
Merge branch 'message-job' into message-schedular
yoavgeva Aug 7, 2024
c44e6f5
Work on fetch from events, sending to sns and delete from events tabl…
yoavgeva Jul 15, 2024
d1841c8
Merge branch 'message-job' into message-schedular
yoavgeva Aug 7, 2024
02ea364
current progress
yoavgeva Aug 7, 2024
eec2400
Work cleanly with prometheus
egvili Aug 7, 2024
608d678
Merge pull request #416 from Conjur-Enterprise/fix-telemetry-flakiness
egvili Aug 8, 2024
e97b6e3
Add token to request
egvili Aug 7, 2024
65d1e46
Merge pull request #417 from Conjur-Enterprise/token-cm
egvili Aug 8, 2024
9dec887
Work on fetch from events, sending to sns and delete from events tabl…
yoavgeva Jul 15, 2024
1ef10fe
localstack2
yoavgeva Aug 8, 2024
195041f
remove sns topic in development
yoavgeva Aug 8, 2024
c85a6ff
clean
yoavgeva Aug 8, 2024
9650c5f
Merge pull request #414 from Conjur-Enterprise/message-job
yoavgeva Aug 8, 2024
6f90ff9
Merge branch 'message-job' into message-schedular
yoavgeva Aug 8, 2024
460fd2d
Merge remote-tracking branch 'origin/conjur-cloud' into message-sched…
yoavgeva Aug 8, 2024
c57c6fb
Add scheduler to send events to sns message
yoavgeva Aug 8, 2024
9f93493
Merge pull request #419 from Conjur-Enterprise/message-schedular
yoavgeva Aug 8, 2024
d51faff
defactor
egvili Aug 11, 2024
1972c48
Merge pull request #420 from Conjur-Enterprise/secret-defactor
egvili Aug 12, 2024
0b6d095
assume role function for publishing in sns topic
nofarNahum Aug 6, 2024
2f0ef52
ONYX-58175 : Assume role function with a publish permission to sns topic
nofarNahum Aug 12, 2024
4b3b485
assume role
nofarNahum Aug 12, 2024
bf5e2ca
ONYX-58229 : add tags tenant_id to assume role
nofarNahum Aug 12, 2024
16c9a85
fix region env in docker compose ci
nofarNahum Aug 13, 2024
fd47e95
ONYX-58229 : fix region env in docker compose ci
nofarNahum Aug 13, 2024
94b3f83
pubsub feature flag from CM
egvili Aug 13, 2024
f5e741e
Merge pull request #424 from Conjur-Enterprise/enable-pubsub-cm
egvili Aug 13, 2024
507e808
Adding tenant id
ofiraburstein Aug 14, 2024
899aa18
Merge pull request #425 from Conjur-Enterprise/ofira_get_tenant_id
ofiraburstein Aug 14, 2024
4b84687
filter out ownership
egvili Aug 13, 2024
8e31653
Merge pull request #426 from Conjur-Enterprise/eyal-60k
egvili Aug 14, 2024
c920d46
Fix Rate
ofiraburstein Aug 15, 2024
9b941fe
Merge branch 'conjur-cloud' into ofira_get_tenant_id
ofiraburstein Aug 15, 2024
825dbbb
Merge pull request #427 from Conjur-Enterprise/ofira_get_tenant_id
ofiraburstein Aug 15, 2024
b88436e
Integration with CM
egvili Aug 15, 2024
f31c4ad
Merge pull request #428 from Conjur-Enterprise/cm-integ
egvili Aug 18, 2024
de16f88
Consume pubsubs params from CM
egvili Aug 19, 2024
1c02d27
CNJR-3517: Pin debase ruby core source to fix the package script
mFelgate Jan 31, 2024
8b2998a
Merge pull request #431 from Conjur-Enterprise/pubsub-params-cm
egvili Aug 21, 2024
0e98bd3
Restrict types for grant operation
egvili Aug 19, 2024
d4941d6
CNJR-3846: Update Trusted Proxies to support IPv6
imheresamir Feb 26, 2024
e838da6
Update Policy Parser to support IPv6
nofarNahum Aug 21, 2024
f0c420a
Merge pull request #432 from Conjur-Enterprise/restrict-grant
egvili Aug 21, 2024
3504bb9
Merge branch 'conjur-cloud' into Nofar/-13.3-leftovers
nofarNahum Aug 21, 2024
a0dc0b7
ONYX-59003 : Nofar/ 13.3v leftovers 1/3part
nofarNahum Aug 21, 2024
ecb5267
Test fix
egvili Aug 21, 2024
bde16d6
Merge pull request #433 from Conjur-Enterprise/restrict-grant
egvili Aug 21, 2024
32a98b0
Use the same timestamp basis for token claims
Mar 6, 2024
a802ffa
ONYX-59003: Sync with Conjur Ent 13.3 leftovers 2/4
nofarNahum Aug 22, 2024
1259b17
Merge branch 'conjur-cloud' into ONYX-move-conjur-jenkins-log-path
Aug 25, 2024
f885432
ONYX-59326: Merge pull request #399 from Conjur-Enterprise/ONYX-move-…
Aug 25, 2024
7a07d84
current progress
yoavgeva Aug 22, 2024
f03dddd
Merge pull request #444 from Conjur-Enterprise/fix-intergrations
yoavgeva Aug 25, 2024
88dd51d
Remove internal links
gl-johnson Mar 14, 2024
cd02956
Merge pull request #209 from Conjur-Enterprise/dont-use-kubectl-cp-wi…
micahlee Mar 15, 2024
981dad9
Comment out pubsub scheduler
egvili Aug 26, 2024
fa3d3de
Merge pull request #447 from Conjur-Enterprise/comment-scheduler
liubovra Aug 26, 2024
ca9fb84
Merge branch 'conjur-cloud' into Nofar/sync-13.3v-part3
nofarNahum Aug 27, 2024
f814250
ONYX-59003 : sync-13.3v-part3/4
nofarNahum Aug 27, 2024
0c9b013
Skip auth for edge with redis
egvili Aug 26, 2024
e1e456b
add test
yoavgeva Aug 27, 2024
4eeaf9c
Merge pull request #449 from Conjur-Enterprise/pubsub-integ-debug
yoavgeva Aug 27, 2024
c5fdfe0
test-base
Aug 25, 2024
0600797
ONYX-59236: Merge pull request #443 from Conjur-Enterprise/ONYX-5923…
Aug 28, 2024
3943213
Check if this code is a must
Aug 27, 2024
8d06a55
ONYX-57422: Merge pull request #448 from Conjur-Enterprise/ONYX-57422…
Aug 28, 2024
07caa41
ONYX-57422: Merge pull request #448 from Conjur-Enterprise/ONYX-57422…
Aug 28, 2024
0af16f1
add rspec logs
Aug 28, 2024
55b2592
Onyx 59236: Merge pull request #454 from Conjur-Enterprise/ONYX-59236…
Aug 28, 2024
1812384
Enable user/host token TTL to be set
jvanderhoof Jan 23, 2024
d275e43
ONYX-59003 : Jason commit authentocator-refactor-oidc
nofarNahum Aug 29, 2024
f8a27ba
Fix CPU hit
yoavgeva Aug 28, 2024
7818ab6
Merge pull request #456 from Conjur-Enterprise/fix-schedular
yoavgeva Aug 29, 2024
80c9b53
Remove built-in groups delete restriction +
egvili Aug 26, 2024
2b9b18a
Merge pull request #452 from Conjur-Enterprise/grant-err-message
egvili Sep 1, 2024
0c5f35a
Fixed eager loading in logger.debug to lazy loading
yoavgeva Aug 31, 2024
e9849ba
Merge pull request #463 from Conjur-Enterprise/fix-log-debug
yoavgeva Sep 1, 2024
9bbb75d
change the test not consider the order
nofarNahum Sep 1, 2024
454715a
ONYX-60367 : fix_flaky_test_authenticator_repo
nofarNahum Sep 1, 2024
d6b9b86
Fail On Purpose
Sep 1, 2024
23a34bd
ONYX-00000: Merge pull request #468 from Conjur-Enterprise/fix-Jenkin…
Sep 2, 2024
d6249df
change value to 38
yoavgeva Sep 2, 2024
870631b
Merge pull request #470 from Conjur-Enterprise/change-to-38
yoavgeva Sep 2, 2024
4d15f3a
Connections leak fix
ofiraburstein Sep 2, 2024
8041976
Connections leak fix
ofiraburstein Sep 2, 2024
8b444d8
Merge branch 'conjur-cloud' into ofira_connections_leak
ofiraburstein Sep 2, 2024
85f63fe
Fix
ofiraburstein Sep 2, 2024
d9748fd
Only return an error code is authentication fails
nofarNahum Sep 3, 2024
0955368
ONYX-60466 : security authenticate response in error case
nofarNahum Sep 3, 2024
79bbd55
concate url with URI
Sep 3, 2024
8572543
Merge branch 'conjur-cloud' into fixup/fix-url-concat
nofarNahum Sep 4, 2024
61957c3
chnage log
nofarNahum Sep 4, 2024
4c6239c
ONYX-60467: Merge pull request #475 from Conjur-Enterprise/fixup/fix-…
Sep 4, 2024
10eff47
Change from .name to [:name]
yoavgeva Sep 1, 2024
1ef7dd3
fix
yoavgeva Sep 1, 2024
c96d8e3
Merge pull request #466 from Conjur-Enterprise/fix-name-method-edge
yoavgeva Sep 5, 2024
dff145d
return the response
Sep 4, 2024
a0475f5
Check if passes
Sep 4, 2024
99ef114
try to mitigate
Sep 4, 2024
8833e1f
ONYX-00000: Merge pull request #478 from Conjur-Enterprise/fixup/disc…
Sep 5, 2024
ab14210
CNJR-3859 bring Policy Factories to GA
jvanderhoof Mar 13, 2024
1cf6b14
chnage log
nofarNahum Sep 8, 2024
3578629
ONYX-60368 : policy factories sync
nofarNahum Sep 8, 2024
f07b79b
Merge branch 'conjur-cloud' into ofira_connections_leak
ofiraburstein Sep 10, 2024
542e606
Adding changelog
ofiraburstein Sep 10, 2024
27e90c0
Merge pull request #472 from Conjur-Enterprise/ofira_connections_leak
ofiraburstein Sep 10, 2024
d572b1f
Adding telemetry
ofiraburstein Sep 16, 2024
5c390f2
Fix
ofiraburstein Sep 16, 2024
2fa0e77
Merge pull request #487 from Conjur-Enterprise/ofira_telemetry4
ofiraburstein Sep 16, 2024
9976968
Fix gcp infra
liubovra Sep 16, 2024
0fb4afe
Merge branch 'conjur-cloud' into gcp-tests
liubovra Sep 16, 2024
7987e99
Fix gcp infra
liubovra Sep 16, 2024
e6a025f
Merge pull request #489 from Conjur-Enterprise/gcp-tests
liubovra Sep 16, 2024
3e6cdd7
ignore localstack's cahce
Sep 17, 2024
13a9888
ONYX-0000: Merge pull request #490 from Conjur-Enterprise/ONYX-0000-…
Sep 18, 2024
8d4ba99
Fixed bug assume role didn't work when credentials expired
yoavgeva Sep 16, 2024
49281c8
Merge pull request #488 from Conjur-Enterprise/fix-assume-role-sns
yoavgeva Sep 18, 2024
dd95e50
Cache role membership results for edge replication
egvili Sep 1, 2024
b5c11a9
Merge pull request #485 from Conjur-Enterprise/cache-role-membership-…
egvili Sep 18, 2024
ef27c0c
Add permission service - only add
Sep 11, 2024
35f7cb1
Onyx-60405: Merge pull request #482 from Conjur-Enterprise/ONYX-60405…
Sep 18, 2024
29a5b69
Check nil
egvili Sep 18, 2024
4a43cf8
Merge pull request #492 from Conjur-Enterprise/check-nil
egvili Sep 19, 2024
f9206ba
Add delete permission
Sep 19, 2024
32c44d0
ONYX-60406: Merge pull request #493 from Conjur-Enterprise/ONYX-6040…
Sep 19, 2024
f243da8
add resource service
yoavgeva Sep 16, 2024
a5daff1
Merge pull request #494 from Conjur-Enterprise/resource-service
yoavgeva Sep 19, 2024
ae5323c
fix nil
Sep 19, 2024
1e8b8a7
ONYX-59427: Merge pull request #495 from Conjur-Enterprise/fix-delete…
Sep 22, 2024
a76aa78
Change create
Sep 22, 2024
0dfe186
ONYX-59427: Merge pull request #499 from Conjur-Enterprise/ONYX-59427…
Sep 23, 2024
d40e61b
Revert "CNJR-3859 bring Policy Factories to GA"
nofarNahum Sep 23, 2024
8d1381d
ONYX-61069 : Revert "CNJR-3859 bring Policy Factories to GA"
nofarNahum Sep 23, 2024
4fb7d38
adjust according to comments
yoavgeva Sep 22, 2024
161096c
Merge pull request #500 from Conjur-Enterprise/resource-service-v2
yoavgeva Sep 23, 2024
7ebf226
Revert "Change create"
egvili Sep 24, 2024
6964b6f
Merge pull request #505 from Conjur-Enterprise/rollback-permission
egvili Sep 24, 2024
9e5450b
ONYX-60667: cicd:Align versioning mechanizem and promote to main ECR
ld-cyberark Sep 24, 2024
dbea020
Merge pull request #508 from Conjur-Enterprise/ONYX-60667
ld-cyberark Sep 25, 2024
5e7109c
[create-pull-request] automated change
jonahx Nov 10, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
4 changes: 4 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -12,16 +12,20 @@ cucumber

*.deb
.git
.idea
engines/conjur_audit/spec/dummy/log
coverage
demo
dev
docker
gems/slosilo/Gemfile.lock
gems/slosilo/spec/reports
log
package
run
spec/reports
spec/reports-audit

tmp

# Ignore directories that are only relevant in gh
Expand Down
11 changes: 1 addition & 10 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,10 +1 @@
* @cyberark/conjur-core-team @conjurinc/conjur-core-team @conjurdemos/conjur-core-team

# Changes to .trivyignore require Security Architect approval
.trivyignore @cyberark/security-architects @conjurinc/security-architects @conjurdemos/security-architects

# Changes to .codeclimate.yml require Quality Architect approval
.codeclimate.yml @cyberark/quality-architects @conjurinc/quality-architects @conjurdemos/quality-architects

# Changes to SECURITY.md require Security Architect approval
SECURITY.md @cyberark/security-architects @conjurinc/security-architects @conjurdemos/security-architects
* @cyberark/ConjurCloud
27 changes: 27 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -73,4 +73,31 @@ conjur_git_commit
# AuthnOIDC V2 w/ Identity setup
dev/policies/authenticators/authn-oidc/identity-users.yml

gem/slosilo/*.gem
gem/slosilo/*.rbc
gem/slosilo/.bundle
gem/slosilo/.yardoc
gem/slosilo/InstalledFiles
gem/slosilo/_yardoc
gem/slosilo/coverage
gem/slosilo/doc/
gem/slosilo/lib/bundler/man
gem/slosilo/pkg
gem/slosilo/rdoc
gem/slosilo/spec/reports
gem/slosilo/test/tmp
gem/slosilo/test/version_tmp
gem/slosilo/tmp
gem/slosilo/.rvmrc
gem/slosilo/.project
gem/slosilo/.kateproject.d
gem/slosilo/.idea

# Rufus scheduler lock file
.slosilo-rotation-rufus-scheduler.lock

# Ignore localstack's cache
dev/localstack/cache/**


VERSION
93 changes: 0 additions & 93 deletions .trivyignore
Original file line number Diff line number Diff line change
@@ -1,93 +0,0 @@
# OpenSSL CVEs
#
# Because of the way OpenSSL 1.0.2 has moved to premium support and our Ubuntu
# base image, trivy flags a number of OpenSSL issues in Conjur because the fix
# for most Ubuntu users is to move to 1.1.1 instead of having the continued support
# in the 1.0.2 line. Additionally, trivy flages 1.0.2zf as vulnerable to issues that
# only affect 1.1.x. As of the time of this writing, we use 1.0.2zf which either
# has the fix or is unaffected by these issues.
CVE-2022-2097
CVE-2022-2068
CVE-2022-1292
CVE-2022-0778
CVE-2021-23841
CVE-2021-23840
CVE-2021-3712
CVE-2019-1563
CVE-2019-1551
CVE-2019-1549
CVE-2019-1547
CVE-2018-0735
CVE-2018-0734

# NULL pointer deref. OpenSSL 1.0.2 is not impacted
CVE-2021-3449

# We already use a later version than the ones listed as impacted by this
# CVE, so we believe this is just a scanner issue.
CVE-2014-7819

# Rake vulnerability for versions < 12.3.3. The version of Rake used by Conjur
# has been updated to 13.0.1. Some of the Conjur dependencies still declare a
# vulnerable version of Rake in their development dependencies, but do not pose
# a risk to Conjur.
CVE-2020-8130

# Applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake
# may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert"
# TLS extension. this issue was fixed in OpenSSL 1.1.1g
#
# In order to support fips with openssl we are required to downgrading openssl version to 1.0.2 until openssl will
# support fips module in newer versions
# This vulnerability this is not relevant to us as
# 1. The installed version (1.0.2u) does not support 1.3
# 2. Trivy detect the usage of openssl 1.0.2 (can be reproduced with
# docker run -v /var/run/docker.sock:/var/run/docker.sock
# -v $(PWD):/workspace --rm aquasec/trivy -f json -o /workspace/scan_results-conjur-unfixed.json --no-progress
# --ignorefile .trivyignore registry.tld/ruby-fips-base-image-phusion:1.0.0)
#
# Performed by @yahalomk approved by @shaharglazner
CVE-2020-1967

# CVE-2020-1971
# The X.509 GeneralName type is a generic type for representing different types
# of names. One of those name types is known as EDIPartyName. OpenSSL provides a
# function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME
# to see if they are equal or not. This function behaves incorrectly when both
# GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash
# may occur leading to a possible denial of service attack.
# OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes:
#
# 1) Comparing CRL distribution point names between an available CRL and a CRL
# distribution point embedded in an X509 certificate.
#
# 2) When verifying that a timestamp response token signer matches the timestamp
# authority name (exposed via the API functions TS_RESP_verify_response and
# TS_RESP_verify_token) If an attacker can control both items being compared
# then that attacker could trigger a crash.
#
# All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Fixed in OpenSSL
# 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w).
#
# In order to support FIPS with OpenSSL we are required to use OpenSSL version
# 1.0.2 until OpenSSL supports the FIPS module in newer versions. The latest
# available version to us is 1.0.2u, which does not include this fix.
#
# We've determined that we are not impacted by this vulnerability because:
# - we do not directly perform CRL checks in the Conjur or DAP software
# - we do not enable automatic CRL checks in openssl tools
# - we do not call any of the impacted OpenSSL APIs or any of the APIs that expose
# impacted behavior.
#
# Performed by @micahlee, approved by @andytinkham
CVE-2020-1971

# CVE-2021-3711
# The vulnerability is not affected Conjur's version of OpenSSL 1.0.2u (https://www.openssl.org/news/secadv/20210824.txt)
# Conjur does not use SM2 algorithm (https://www.openssl.org/docs/manmaster/man7/SM2.html)
CVE-2021-3711

# We have the fix for CVE-2023-0286 in openssl 1.0.2zg, but because OpenSSL 1.0.2
# is only available in premium support, trivy thinks we should use something in the 1.1.1
# line. We can't, due to FIPS compliance, so need to continue to ignore this issue.
CVE-2023-0286
2 changes: 1 addition & 1 deletion API_VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
5.3.0
5.3.1
Loading