Skip to content

Releases: Nikolasel/nuclei-security-center

v0.4.7-beta — UI style guide and redesigned notification mails

Choose a tag to compare

@Nikolasel Nikolasel released this 03 Oct 23:17
Immutable release. Only release title and notes can be modified.
2252888

Patch release on v0.4.6-beta. No schema changes — no new migrations.

Highlights

  • A written UI style guide, and every screen moved onto shared primitives. New docs/UI_STYLE_GUIDE.md defines color roles, the type scale, spacing, page anatomy and rules for buttons, tables, row actions, forms, dialogs, confirmations and feedback. Pages now compose the shared components in web/src/components/ui.tsx (Page/PageHeader, Table, RowActions, Alert, Badge, useConfirm, …), so buttons, headers, tables and messages look and behave the same everywhere (#339).
  • Redesigned scan notification mails. The digest and failed-scan mails are now embedded HTML templates styled to match the web app: brand header with the Nuclei logo (carried inline as a CID attachment), the app's system UI font stack, severity-colored counts table, status/severity chips and a clear "Open scan" button. Plain-text alternatives are unchanged (#340).
  • Dependency updates. npm minor/patch bumps for @tanstack/react-query, lucide-react and vite (#341).

Merged

  • #339 Add a UI style guide and align the web app with it
  • #340 Design the scan notification mails: embedded HTML templates per the UI style guide
  • #341 chore(deps): bump the npm-minor-patch group in /web

Full changelog: v0.4.6-beta...v0.4.7-beta

v0.4.6-beta — scan email notifications, schedule timezones, and admin environment view

Choose a tag to compare

@Nikolasel Nikolasel released this 03 Oct 09:56
Immutable release. Only release title and notes can be modified.
b422ce0

Patch release on v0.4.5-beta. Adds migrations 0004_schedule_timezone.sql and 0005_scan_notification_outbox.sql, applied automatically at startup. Alpha databases remain rejected (they are not upgradeable).

Highlights

  • Scan notification mail, opt-in per policy. A completed scan can email only its deltas — New / Changed (resurfaced) / Fixed, counted by effective severity, with links back to the scan and each finding — and failed or orphaned scans get a failure alert. Mail is off by default and switched on per scan policy (notify_enabled), which can also set its own recipients and a minimum severity (e.g. low drops info from counts and the list; unknown is kept). Without policy recipients, mail falls back to the deployment SMTP_TO admin mailbox. SMTP_HOST + SMTP_FROM enable sending; SMTP_PASSWORD_FILE is re-read before each send. An at-most-once outbox row is claimed before SMTP so a restart never resends; send failures are logged and never change a scan's terminal state (#321, #335, #328).
  • Schedules choose their own timezone. A schedule now stores an IANA timezone (default UTC) alongside its cron expression, so 0 3 * * * means 03:00 in that zone, including DST. Existing schedules keep UTC, and legacy TZ= / CRON_TZ= prefixes are migrated into the new column and stripped (#329, #332).
  • Settings → Environment configuration. Admins get a read-only view of the running backend's effective environment: every allowlisted variable with set/unset, the parsed value it actually consumes (booleans, durations, a credential-free DATABASE_URL), and the built-in default. Secrets never leave the backend, SCAN_ZONES reports a seed-node count only, and each row carries the same description as the configuration docs — enforced by a drift test (#336, #337).
  • The findings list remembers your filters and sort. Filter and sort state persists per browser (#333).
  • Template sync history collapses no-change runs. Repeated "no changes" sync results are summarized instead of filling the history (#334).

Merged

  • #328 Email scan result changes and failures, opt-in per policy
  • #332 Schedules: select an IANA timezone for cron
  • #333 Persist findings filter and sort in localStorage
  • #334 Summarize no-change template catalog syncs
  • #337 Admin settings: show effective environment configuration

Full changelog: v0.4.5-beta...v0.4.6-beta

v0.4.5-beta — findings triage: result identity, richer filters, occurrence history

Choose a tag to compare

@Nikolasel Nikolasel released this 27 Sep 18:19
Immutable release. Only release title and notes can be modified.
e8ad17e

Patch release on v0.4.4-beta. Adds migration 0003_finding_result_identity.sql, applied automatically at startup; existing rows are backfilled from the preserved raw findings. Alpha databases remain rejected (they are not upgradeable).

Highlights

  • The findings list now identifies each result. GET /api/findings already returned matched_at, type, tags and target_ids; the table now renders an Endpoint column by default (host + path, protocol pill) so https://host/admin and https://host/api are distinguishable at a glance instead of collapsing into one host. Target, Tags, CVE, First seen, Matched at and Result identity are available from the Columns menu, which persists per browser. Columns resize from the header (keyboard-operable separators, double-click resets one, and the last visible column absorbs leftover width), and matched_at / type are filterable in both the structured filter and the legacy flat params (#313, #322).
  • Result identity is stored, not just inside the raw JSON. Nuclei's matcher-name, extractor-name and extracted-results become real columns on findings and finding_lifecycle (migration 0003), written at ingest and backfilled for existing rows from findings.raw. Two lifecycle findings that share a template and matched_at no longer render identically: the identity appears as a compact line under the name, with an opt-in Result identity column when you want to sort it or widen it to read a long value. matcher and extracted_result are filterable, JSON/CSV/SARIF exports carry the fields, and the hashed dedup identity is unchanged (#315, #324).
  • The filter engine can ask real triage questions. Date ranges (before / after / between, inclusive, date-only values accepted) on first- and last-seen; not_contains / is_empty / is_not_empty for name; server-side sort + order over an allowlisted field set with stable paging. The list and the export share one parser, so a download matches what is on screen (#311, #325).
  • Triage overlay state is queryable. Filter on recast_severity (including recast vs never recast), observed_severity independently of a recast, accept_expires_at ranges, times_mitigated, occurrence_count and auto_mitigation_eligible. Accepted rows show their expiry in the list, and an Expiring acceptances quick filter returns accepted findings whose expiry falls in the next seven days — the ones that reopen silently otherwise (#312, #326).
  • Finding detail lists the retained occurrences. New GET /api/findings/{id}/occurrences (viewer role, paginated limit/offset, newest first, 404 for an unknown finding) backs a section on the finding page with links to each occurrence, its scan and its target, plus a one-click jump to the latest. A finding that still exists always has at least one occurrence: deleting a scan drops its occurrences and occurrence_count together, and deleting every scan that observed a finding deletes the lifecycle row, so the list never implies history it cannot show (#314, #327).

Fixes

  • Long extracted results wrap instead of overflowing their container on the occurrence and finding detail pages (#317).

Development environment

  • The local S3 stand-in is Garage (dxflrs/garage) rather than MinIO, which no longer publishes an anonymously pullable image. Compose, the deployment docs and the troubleshooting guide were updated; the backend's ObjectStore and its environment configuration are unchanged, and any S3-compatible endpoint still works (#320).

Maintenance

  • Frontend dependency bump (npm minor/patch group) via dependabot (#323).

Merged

  • #317 fix(ui): wrap long extracted results on occurrence and finding detail pages
  • #318 Show the running backend version in the account menu
  • #320 Replace local MinIO with Garage for raw-output archival
  • #322 Show matched URL, type, tags, and target on the findings list
  • #323 chore(deps): bump the npm-minor-patch group in /web with 2 updates
  • #324 Surface Nuclei matcher and extracted results on findings
  • #325 Findings filters: date ranges, name negation, and sorting
  • #326 Findings filters: triage overlay state
  • #327 List retained occurrences on finding detail

Full changelog: v0.4.4-beta...v0.4.5-beta

v0.4.4-beta — OIDC host canonicalization, light/dark theme, and operator UI fixes

Choose a tag to compare

@Nikolasel Nikolasel released this 20 Sep 11:18
Immutable release. Only release title and notes can be modified.
3beec52

Patch release on v0.4.3-beta. No schema changes.

Highlights

  • 127.0.0.1 no longer breaks login. GET /api/auth/login and SPA document requests whose cookie host (hostname + non-default port) does not match APP_BASE_URL are 302'd to the same path on the configured origin before an auth-state cookie is minted, so a 127.0.0.1 visit cannot start a flow whose callback and host-locked cookies live on localhost — the "invalid or expired login state" failure (#298, #308). Scheme is ignored in the comparison, so a TLS-terminating ingress that presents the public Host over plaintext cannot 302-loop. Redirect destinations are always derived from APP_BASE_URL, never from Host, so a spoofed host is not an open redirect; a missing or malformed APP_BASE_URL fails closed. /healthz and other /api/* routes are not redirected, so probes and service-account callers may still use an IP.
  • Light/dark theme toggle in the header. Flips the dark class on <html> — now a class-based Tailwind variant — persists per browser, and follows the OS preference until the first toggle. Applied before first paint so the initial render does not flash the wrong theme, color-scheme follows so browser chrome matches, and a storage listener keeps multiple open tabs in sync (#292, #293).
  • Scanner Nodes table fits 1280×800. Health and Discovery collapse into one Status column, tags and CIDRs move under Name/Scope, the nuclei version and last-seen fold into the catalog cell, and the action column is pinned with a scroll shadow — Edit / Sync / Delete stay on screen without horizontal scrolling (#299, #307).

Fixes

  • Target Save requires Name and Hosts. Both fields are marked required (visible *, aria-required) and Save stays disabled until they have values, matching backend validation and the node-create form (#300, #306).
  • Custom Templates empty state. The catalog table's filter-oriented copy ("No templates match these filters") is replaced with "No custom templates yet." on the Custom Templates tab, which has no filters (#301, #305).

Development environment

  • Cloud Agent (Cursor) environment. .cursor/environment.json plus install / start / dockerd / logs scripts bring up the docker-compose stack so cloud agents can verify PRs against the real stack. .cursor/ is deliberately not gitignored so that environment stays shared (#302).
  • Local AI-agent state is ignored. .claude, .commandcode, .codex, .gemini, .qwen, .opencode, .crush, .continue, .windsurf, .roo, .kilocode, .junie, .specstory, .aider* can no longer be committed by accident; shared instructions stay in AGENTS.md (#303). CLAUDE.md is now a one-line @AGENTS.md import rather than a symlink, so Cursor does not ingest a second copy (#291).
  • Compose MinIO image moved to Quay (quay.io/minio/minio) — MinIO no longer publishes an anonymously pullable Docker Hub image, so docker compose up would have failed against Docker Hub.
  • Docs refreshed for the above: API.md, ARCHITECTURE.md, DEVELOPMENT.md, README.md, CONTRIBUTING.md, and the admin guide (Authentication / Configuration / Deployment / Troubleshooting).

Maintenance

  • Go toolchain → 1.26; coreos/go-oidc/v3 3.21.0, jackc/pgx/v5 5.11.0, golang.org/x/oauth2 0.37.0, golang.org/x/time 0.16.0.
  • Frontend: React / React DOM 19.3, Vite 8.3, @tanstack/react-query 5.103.1, lucide-react 1.46, react-router-dom 7.18.4, @vitejs/plugin-react 6.1.1.

Merged

  • #291 docs: load agent instructions once via CLAUDE.md @AGENTS.md
  • #293 Add header light/dark theme toggle (#292)
  • #294 chore(deps): bump github.com/coreos/go-oidc/v3 to 3.21.0
  • #295 chore(deps): bump the npm-minor-patch group in /web with 4 updates
  • #296 chore(deps): bump the go-minor-patch group
  • #297 chore(deps): bump the npm-minor-patch group in /web with 5 updates
  • #302 Add Cloud Agent development environment (Docker Compose stack)
  • #303 chore(gitignore): ignore local AI agent state, keep .cursor tracked
  • #305 fix(ui): show a true empty state on Custom Templates (#301)
  • #306 fix(ui): require Name and Hosts before saving a target (#300)
  • #307 fix(ui): keep scanner-node row actions visible at 1280×800 (#299)
  • #308 Redirect 127.0.0.1 onto APP_BASE_URL before OIDC login (#298)
  • #309 chore(deps): bump the npm-minor-patch group in /web with 4 updates

Full changelog: v0.4.3-beta...v0.4.4-beta

v0.4.3-beta — Nuclei 3.11.1, operator UI fixes, and public-launch docs

Choose a tag to compare

@Nikolasel Nikolasel released this 05 Sep 21:00
Immutable release. Only release title and notes can be modified.
63d1db3

Patch release on v0.4.2-beta. No schema changes.

Highlights

  • Nuclei 3.11.1. Scanner image pin (deploy/Dockerfile.scanner) so new scans run the current upstream binary.
  • Template-set Duplicate copies membership. Duplicating an exact or exclude set no longer saved an empty set (#277).
  • Nodes page shows effective naabu scan type. GET /v1/capabilities reports the node's normalized NAABU_SCAN_TYPE (SYN default, connect fallback); the nodes table surfaces SYN / Connect / unknown without shelling in. A scan policy's discovery_scan_type can still override (#271).
  • Scan-policies table layout. Execution knobs (rate, concurrency, timeout, max-host-error, resp read/save) collapse into one summary column so the row fits at 1280px without clipping Delete (#276).

Public launch

  • Canonical AGPL-3.0 LICENSE (GitHub now detects AGPL-3.0), CONTRIBUTING.md, Contributor Covenant 2.1, PR and bug-report templates.
  • GHCR backend/scanner images are public; admin docs cover pull coordinates and Compose wiring. Prerelease tags publish version + sha-* only (no latest).
  • Administration guide (docs/admin/) is published to the GitHub wiki on main and v* tags.

Maintenance

  • Frontend minor/patch bumps: @tanstack/react-query, lucide-react, Vite, @vitejs/plugin-react.

Merged

  • #278 chore(scanner): upgrade pinned nuclei to v3.11.1
  • #279 fix(template-sets): copy members and exclusions when duplicating a set (#277)
  • #280 feat(nodes): surface effective naabu scan type on nodes page (#271)
  • #281 fix(scan-policies): collapse execution knobs into summary column (#276)
  • #284 chore: public-launch prep (license, fixtures, community files)
  • #285 docs(release): correct stale comment — GHCR images are public
  • #287 docs: publish pull instructions for the public GHCR images
  • #288 docs(admin): publish administration guide to the GitHub wiki
  • #289 fix(wiki): authenticate wiki checkout like the main repo
  • #290 chore(deps): bump the npm-minor-patch group in /web with 5 updates

Full changelog: v0.4.2-beta...v0.4.3-beta

v0.4.2-beta — Bound nuclei response sizes and auto-tune GOMEMLIMIT to prevent OOM

Choose a tag to compare

@Nikolasel Nikolasel released this 24 Aug 20:45
Immutable release. Only release title and notes can be modified.
ce1c5ea

Fixes the scanner OOM-killed at the container 2 GiB cap reported in #274.

Problem

During a scan of ~106 endpoints the nuclei process was killed twice by the kernel OOM killer (CONSTRAINT_MEMCG) after reaching the container's 2 GiB limit. Heap climbed from baseline to ~2 GiB within ~5 s — dozens of simultaneous connections to a single CDN edge with 1.5–4.7 MiB unread Recv-Q each, plus Go heap anon-rss:2 GiB. Model: heap ≈ 1–1.5 × concurrency × response-size-read (nuclei default 10 MiB) stacked with cgroup-accounted TCP buffers.

Fix (#275)

Two complementary, deployment-independent fixes:

  • Per-response caps as scan-policy knobs — scan_policies.response_size_read / _save (nullable, >0, CHECK) via forward migration 0002_add_scan_policy_response_limits.sql (post-beta freeze, 0001_init.sql untouched). Plumbed types.ScanOptions → store.ScanPolicy → validateScanPolicy/overlayScanPolicy → runner.buildArgs (-response-size-read/-save, omitted ⇒ nuclei default 10 MiB/1 MiB) → bundle snapshot → SPA (modal/table, placeholders 10485760/1048576). Lowering read toward 1 MiB linearly shrinks worst-case heap.

  • Automatic GOMEMLIMIT on the scanner node — internal/scanner/memlimit.go reads cgroup limit from /sys/fs/cgroup/memory.max (v2) then memory/memory.limit_in_bytes (v1) (treating max/>1 PiB/sentinel 9223372036854771712 as unlimited), derives GOMEMLIMIT ≈75% of cap (truncated to MiB, floored at 64 MiB, documented assumption for non-tiny cgroups), leaves 25% for kernel TCP buffers/RSS slack. Explicit GOMEMLIMIT wins (runtime already honored at startup). Applied via GOMEMLIMIT env (inherited by nuclei/naabu) and debug.SetMemoryLimit so GC pressure replaces kills.

Tests: TestBuildArgsResponseSize, TestOverlayScanPolicy (response sizes), TestValidateScanPolicy, TestParseGOMEMLIMIT (TiB/MiB/GiB/KiB/B, case-insensitive), TestParseCgroupLimitValue, TestGomemlimitFromCgroup (floor/truncation).

Operational notes

  • Existing GOMEMLIMIT=1500MiB workaround still honored (explicit wins).
  • Existing policies get nuclei defaults until edited; set response_size_read to 1048576 (1 MiB) to bound CDN streaming.
  • No tcp_rmem change; headroom is in GOMEMLIMIT.

Merged

  • #275 fix(scanner): bound nuclei response sizes and auto-tune GOMEMLIMIT to prevent OOM (#274)

Full changelog: v0.4.1-beta...v0.4.2-beta

v0.4.1-beta — Fix scanner image HOME for cap_drop ALL

Choose a tag to compare

@Nikolasel Nikolasel released this 24 Aug 12:05
Immutable release. Only release title and notes can be modified.
b132f1a

Fixes the scanner startup failure under least-privilege hardening (cap_drop: ALL) reported in #272.

Fix

  • Scanner image (deploy/Dockerfile.scanner): hardened /root to 0550 but left ENV HOME=/root. With CAP_DAC_OVERRIDE dropped, nuclei’s mkdir $HOME/.config failed with EACCES (mkdir /root/.config: permission denied) and every scan failed closed. Now bakes a dedicated private HOME at /home/scanner (mkdir -p /home/scanner && chmod 0700, ENV HOME=/home/scanner) for nuclei/naabu/uncover config+cache ($HOME/.config, $HOME/.cache, $HOME/nuclei-templates). Avoids the world-writable /tmp (1777) symlink/pre-creation surface that HOME=/tmp would have kept. A future move to a non-root USER will need a matching chown (e.g. chown 1001:0 /home/scanner).

Operational notes

  • cap_drop: ALL is often paired with read_only: true. With a read-only root filesystem the scanner now needs writable scratch at both /home/scanner (image HOME) and /tmp (SCANNER_WORK_DIR defaults to a private 0700 dir under os.TempDir()//tmp). Mount writable emptyDir/tmpfs volumes at both paths (as with EXPORT_SPOOL_DIR/TEMPLATE_SYNC_DIR for the backend). Documented in docs/ADMIN_GUIDE.md:103 and SCANNER_WORK_DIR.

Verification

  • Before: docker run --cap-drop ALL ghcr.io/...:0.4.0-beta nuclei -tl → mkdir /root/.config: permission denied
  • After: docker run --cap-drop ALL ghcr.io/...:0.4.1-beta nuclei -tl → Successfully installed nuclei-templates at /home/scanner/nuclei-templates
  • ls -ld /home/scanner → drwx------ (0700, root-owned), /root stays dr-xr-x---, scanner /v1/capabilities healthy under cap_drop ALL; --read-only --tmpfs /tmp --tmpfs /home/scanner starts clean.

Merged

  • #273 fix: point scanner HOME to writable /home/scanner so nuclei works with cap_drop ALL (#272)

Full changelog: v0.4.0-beta...v0.4.1-beta

v0.4.0-beta — First beta: security-hardening pass, template-set modes, scan bundles

Choose a tag to compare

@Nikolasel Nikolasel released this 23 Aug 13:12
Immutable release. Only release title and notes can be modified.
1594019

The first beta release. Nuclei Security Center graduates from alpha after a comprehensive external security review — the bulk of this release is a security-hardening pass across auth, sessions, scanner I/O, and resource bounds — plus new template-set modes, versioned scan bundles, a mobile-friendly SPA, and a frozen migration baseline that makes future schema changes forward-migratable.

Highlights

  • Security-hardening pass (external review). A full external security review of the codebase drove a wide set of fixes: host-locked and CSRF-protected OIDC login and session cookies, bounded session TTL with an admin revocation path, per-subject live-session caps and paginated admin sessions, audited failed-authentication and OIDC-callback 401s, RP-initiated IdP logout that fails closed when server-side revocation fails, blocked scanner-client redirects, bounded scanner responses / stderr / JSONL records, bounded findings queries and exports, bounded scan-bundle and auth-flow creation, escaped LIKE metacharacters in filters, clickjacking/MIME security headers, a service_accounts.role CHECK constraint, rejected mTLS-on-HTTP misconfiguration, and S3_USE_SSL now defaulting to true (fail closed).
  • Explicit template-set modes. Template sets are now exact, all, or exclude, resolved at dispatch, replacing the retired POC filter columns.
  • Versioned scan bundles. Complete scans export and import as versioned bundles (JSON or zip), with streamed decoding bounded to a fixed heap and imported coverage as an explicit opt-in.
  • Host discovery independent of scan type. Naabu host discovery is decoupled from SYN/connect selection, and executed nuclei/naabu commands are now captured in the scan execution log.
  • Mobile-friendly SPA. The React interface is usable on small/mobile viewports, with a sidebar that stays visible while scrolling.
  • Reliability. Reliable scan cancellation (#217), scanner work-dir/job reclamation after completion, ascending-order lifecycle locking to avoid deadlocks across concurrent scan deletions, and overflow-safe retention windows.

Beta readiness — migration baseline frozen

  • The alpha migration chain is squashed into a single consolidated baseline (0001_init.sql), now frozen as of this release. From beta onward, each schema change ships as a new numbered forward migration that applies on an existing database; applied migrations are immutable and checksum-verified at startup.
  • Alpha databases are not upgradeable to beta. Deploy beta against an empty Postgres database and move portable data with template/template-set exports and scan bundles; the backend rejects an unsupported migration history at startup instead of attempting a partial upgrade.

Upgrade notes

  • Start from an empty PostgreSQL database. There is no in-place upgrade path from any alpha.
  • S3_USE_SSL now defaults to true. Set it explicitly to false only for a plaintext dev endpoint.

Maintenance

  • Dependency updates across Go modules, frontend npm packages, the Go toolchain (1.27), and base images.

Full changelog: v0.3.0-alpha...v0.4.0-beta

v0.3.0-alpha

v0.3.0-alpha Pre-release
Pre-release

Choose a tag to compare

@Nikolasel Nikolasel released this 23 Jul 17:55
Immutable release. Only release title and notes can be modified.
8b2ce58

This alpha release makes scan policies the central configuration for every scan, adds optional naabu-based port discovery, and expands operational visibility and findings triage.

Highlights

  • Policy-driven scans: every scan and schedule now selects a reusable scan policy that combines an approved target, an optional template set, and Nuclei execution controls. Policies add max_host_error support and keep scans in scope by construction.
  • Port discovery before Nuclei: policies can run a naabu pre-pass so Nuclei scans only discovered host:port endpoints. Discovery is enabled by default, supports SYN and connect modes, has independent timeout/rate/probe/retry tuning, reports live discovery progress, and persists the endpoints that were scanned. Discovery failures fail closed.
  • Expressive findings search: the findings view now has a ServiceNow-style condition builder with AND/OR groups, field-specific operators, breadcrumbs, and an open-findings default. The same structured filter applies consistently to JSON, CSV, SARIF, and raw exports.
  • Better scan operations: completed scans can archive and download the scanner execution log; scan detail records the selected scanner node and shows a live ETA; polling budgets now derive from the policy's discovery and scan timeouts.
  • Configurable retention: admins can automatically remove old terminal scans while preserving the latest scan needed for lifecycle calculations, with configurable treatment of ad-hoc scans and audit events for sweeper deletions.
  • Refreshed interface: adds the neon Nuclei Security Center logo, favicon, and updated product branding.
  • Maintenance: updates Go/Node GitHub Actions and frontend dependencies, and consolidates contributor-agent guidance.

Breaking changes

  • POST /api/scans now accepts only { "scan_policy_id": "..." }; the former target, template-set, raw-spec, and timeout launch inputs are removed.
  • Schedules now reference a scan policy instead of carrying target/template/timeout configuration. Migration 0017 clears pre-alpha schedules created under the old schema.
  • Port discovery defaults to enabled for new policies. Operators can disable it per policy when a scanner environment should run Nuclei directly.

Merged changes

  • #115 naabu port-discovery pre-pass before Nuclei
  • #119 neon product branding
  • #114 findings condition builder
  • #113 scan policies as central scan configuration
  • #110 scanner execution-log archival and download
  • #112 selected scanner node and live ETA
  • #111 configurable scan retention
  • #105, #106 dependency updates

Full changelog: v0.2.0-alpha...v0.3.0-alpha

v0.2.0-alpha — Scanner node fleet, per-node mTLS, hardened multi-arch images

Choose a tag to compare

@Nikolasel Nikolasel released this 19 Jul 08:03
Immutable release. Only release title and notes can be modified.
6143553

Alpha milestone focused on running scans across a fleet of scanner nodes, hardening the
backend↔node trust boundary, and shipping minimal, multi-arch container images. Also brings
service-account tokens, live scan progress, and a reorganized web UI.

Pre-release / alpha: interfaces and schema may still change between alpha tags.

Highlights

Scanner node fleet

  • DB-backed scanner node registry — admin-managed nodes (config-seeded on first boot), replacing the static single-node config. (#22)
  • Scan zones — map each node to the network CIDRs it serves; dispatch picks the node whose zone contains the target, with overlapping CIDRs rejected. (#77)
  • Node health monitoring — the backend polls each node's /v1/capabilities; dispatch fails fast to a known-unhealthy node instead of hanging. (#98)
  • Scanner nodes admin UI — manage nodes and see health/last-error from the web app. (#99)

Backend ↔ node security

  • Per-node mTLS — each node can carry its own server-CA + client cert/key (client key write-only), so nodes in untrusted segments only accept dispatch over a mutually-authenticated connection, bearer token still on top. (#26)

Container images & deployment

  • Red Hat UBI 10 Micro base for both backend and scanner — minimal, no package manager/shell, long support window. (#103)
  • Multi-arch linux/amd64 + linux/arm64 manifest lists (Graviton / Apple-silicon runners run without a second image).
  • Self-contained scanner — a pinned, SHA-256-verified nuclei binary plus the community templates baked in at build time, refreshed to the newest set before each scan. No dependence on a mutable upstream nuclei:latest tag.
  • Backend now runs non-root; both images ship a CA bundle for outbound TLS.

Scan control & visibility

  • Live scan progress bar driven by nuclei's -stats-json (percent / requests / hosts / rps), including multi-target scans. (#66)
  • Stop/cancel + delete scans, with target visibility on the scan views. (#74)
  • Partial results are ingested before a failure is recorded, and nuclei_version / templates_commit are captured even on failed or cancelled scans. (#89)
  • timeout_sec override honored for schedules, not just ad-hoc scans.

Access & resilience

  • Service-account API tokens for headless/automation access, with an admin UI to create/rotate/revoke. Audit events distinguish service_account from user actors. (#70)
  • Ambient/IAM object-store credentials — the backend can use an instance/role identity for S3 instead of static keys. (#72)
  • Rotating database credentials via a password file re-read per connection. (#71)
  • Infrastructure faults (unreachable session/identity store) now surface as 503, no longer masked as 401. (#82)

Web UI

  • Collapsible, category-grouped sidebar navigation (Findings / Scanning / Admin) with an icon rail and tooltips. (#96)
  • Modal scrolling fix for tall content and wider content on large screens.

Findings

  • Findings read path refactored behind a FindingsSearcher interface (seam for richer multi-value filtering). (#92)
  • Lifecycle history is repaired when a scan is deleted, and evidence-free rows are dropped rather than left "active".

Images

Published to GHCR as multi-arch manifest lists:

  • ghcr.io/nikolasel/nuclei-security-center-backend:0.2.0-alpha
  • ghcr.io/nikolasel/nuclei-security-center-scanner:0.2.0-alpha

Full changelog: v0.1.2-alpha...v0.2.0-alpha