Repository navigation
Releases: Pitangus-Dev/pitangus
Release list
Pitangus 0.12.2
Pitangus 0.12.2: create the GitHub App from the panel in two clicks and connect each installation with one, findings across several assets at once, images added without scanning, readable Slack and Teams notices, and a lighter panel.
Images (signed with cosign, SBOM and SLSA provenance attached; linux/amd64 and linux/arm64):
ghcr.io/pitangus-dev/pitangus:0.12.2(also:0.12)ghcr.io/pitangus-dev/pitangus-worker:0.12.2(also:0.12)
Verify them with make verify-images or the command in docs/deploy-vps.md.
Upgrading from 0.12.1 (installed with --branch v0.12.1): git fetch --tags && git checkout v0.12.2 && make update. Following main: make update.
Added
-
Findings of several assets at once. Findings has the same scope picker as Compliance: one asset (as before, with
its runs and settings), an organization, a chosen set of repositories and images, or everything, with the images
built from the chosen repositories. The cards add up the whole scope, a "By asset" block shows each asset's pending
and critical findings and opens it on its own, and the table gains an Asset column. Triage (one finding or a
selection across assets in one request, applied asset by asset with any failure named), Jira issues and the
consolidated audit evidence work on the scope. The scope stays in the address, so a reload or a shared link opens the
same view. New routeGET /api/findings/scope; a very large scope lists the 10,000 most urgent findings of the tab
and says so.POST /api/findings/triagealso takesselections([{run_id, fingerprints}], one per asset, up to 500
findings in all) instead ofrun_idandfingerprints, and answers each one's outcome inresults; it fails as a
whole only when none landed. The cards are counted by the server in every view:summary.kpisin an asset's state,
a run (GET /api/runs/{id}) and a scope, with what was fixed (by a scan or by hand) never counted as pending. -
Create the GitHub App from the panel (Integrations → GitHub → Create on GitHub). GitHub's form opens with
everything filled in (name, the four permissions, no webhook or OAuth, the return to this panel); you confirm there
and come back with the App connected, instead of copying values and uploading the.pem. The App is still yours and
its private key goes from GitHub straight to the server, encrypted; the link is single-use and lasts an hour. The
manual guide stays, folded underneath. API:POST /api/integrations/github/manifestand the return at
/github/app-created. -
Add an image without scanning it (Scanning → Images → Add image). Type its reference and, if you're an
administrator, the repository it's built from; it shows on the list as "Not scanned yet" and is scanned when you
choose ("Scan it now" does it right away). Adding one that is already there says so; if it isn't scanned yet, it now
scans the reference you just typed. Its first scan lands on the same asset, keeping the link; until then it has no
findings and stays out of the evidence scopes. At most 5,000 images wait unscanned at a time (scanned ones don't
count). An administrator can remove an image that was never scanned. API:POST /api/imagesandPOST /api/images/remove;
GET /api/imagesitems carryanalyzed. -
Connecting an installation takes one click. Coming back from installing the App on GitHub (its Setup URL) no
longer stops at a page that says to go back and look for it: it opens Integrations, which offers that account with
Connect (only to administrators; the server still checks it belongs to the App)./oauth/callbackno longer calls
GitHub: it only hands the installation to the panel.
Fixed
- Slack and Teams notices read better. No more emoji: each finding shows its severity in words and what it is,
with where it is on the line below ("Dependencynext 14.2.3" or the file and line), under "Most urgent". In Slack
the edge of the message takes the colour of the most severe finding. Dependency advisories drop the repeated package
prefix ("flatted 3.3.1: flatted: Flatted: Prototype pollution…" becomes "Prototype pollution…"); the signed webhook
gets the same cleanertitleand a newdependencyflag per item. - Slack messages no longer show a warning next to "Open in Pitangus". It was a button, and Slack treats every
button as interactive: with an incoming webhook (no interactivity URL) it marked it with a warning. It is now a plain
link that opens the same page.
Security
- The images no longer carry pip. It installs the pinned dependencies and is then removed, from the app image and
from Checkov's environment in the worker with the engines inside: nothing runs it, and the 25.0.1 that Python 3.12
bundles has six known vulnerabilities (pip 26 would trade them for its vendored urllib3, msgpack and setuptools). - Checkov's asteval goes to 1.0.10 in the worker with the engines inside. Checkov 3.3.19 (and every later release
so far) pins 1.0.6, which it uses to evaluate the Terraform expressions of the scanned repository; 1.0.9 fixed two
sandbox escapes (GHSA-89v8-rhwq-hf77, GHSA-9w56-46f6-3qhx). It is installed by hash over the lock, from
docker/checkov/overrides.txt; Checkov's results don't change. - The Docker client in the image goes to 29.9.0, built with Go 1.26.9: the 13 Go standard library vulnerabilities
of 29.8.2 (two high: CVE-2026-78667, CVE-2026-97031) are gone. It came out on 2026-10-09, so it goes in as an
exception to the week-old rule, checked against its SHA-256 like before. - The Python base image moves to the current
python:3.12-slim-bookwormdigest (still Python 3.12.15). The engines stay
where they were: they are already the newest releases at least a week old, and the Go standard library fixes their
remaining findings need (Go 1.26.9 and 1.27.2) came out on 2026-10-08.
Upgrading from 0.12.1
- If you installed a release (
git clone --branch v0.12.1, as in the quickstart),make updatealone stays on it:
git fetch --tags && git checkout v0.12.2 && make update. Followingmain,make updateis enough. The new
"Upgrade" section of docs/installation.md explains both. - The database gets one new table (the images added without scanning), created on start: nothing to do by hand.
- Slack and Teams notices change format (no emoji); a signed webhook receiver gets a cleaner
titleand a new
dependencyfield per item.
Pitangus 0.12.1
Pitangus 0.12.1: an Images page with the repository each image is built from, one scope picker for compliance evidence, eleven more audit frameworks (EU, US and Mexico), redesigned PDF reports and English panel paths.
Images (signed with cosign, SBOM and SLSA provenance attached; linux/amd64 and linux/arm64):
ghcr.io/pitangus-dev/pitangus:0.12.1(also:0.12)ghcr.io/pitangus-dev/pitangus-worker:0.12.1(also:0.12)
Verify them with make verify-images or the command in docs/deploy-vps.md.
Added
- Images page (Scanning → Images): every analyzed image, the repository it's built from and how it was linked
(OCI label or by hand), with a "not linked" tab for the ones that still need one. An administrator links, changes or
removes the link there; each row opens its findings or scans the image again. Repositories show how many images are
built from each one, and from a repository you can link another image to it. - One scope picker for the evidence in Compliance. Three steps: which assets (one, an organization, several or all),
which framework, and the downloads for that scope, with a preview of what it covers (repositories, images, how many
with a complete scan) before downloading anything. The separate "one asset" and "portfolio" blocks are gone. - An image knows which repository it is built from. Pitangus reads its OCI labels (
org.opencontainers.image.source
and.revision, set bydocker/build-push-actionand GHCR) and links it to that repository when it is analyzed too;
an administrator can set or change the link by hand in Compliance. The reports say "built from org/repo @ commit". - Portfolio evidence for the scope you choose: every analyzed asset, the repositories of one organization, or a
chosen set of repositories and images; with a repository come the images built from it (it can be turned off). It
applies to the portfolio SBOM, VEX and consolidated audit evidence. - Audit evidence for eleven more frameworks. European Union: NIS2 (Art. 21(2) and Implementing Regulation
2024/2690), DORA (with RTS 2024/1774) and GDPR Art. 32. United States: NIST SSDF (SP 800-218), NIST CSF 2.0,
NIST SP 800-53 Rev. 5 and the HIPAA Security Rule. Mexico: CNBV rules for banks (CUB) and crowdfunding institutions,
e-money institutions (IFPE) and LFPDPPP Art. 18. Each control says what the evidence covers and what stays out
(infrastructure scanning, external pentests, dynamic testing): it supports an audit, it doesn't certify compliance.
Changed
- The panel's paths are English (
#/findings,#/compliance,#/images…) whatever its language, so a shared link
reads the same for everyone. The Spanish paths of earlier versions (#/hallazgos,#/resumen…) still work and are
rewritten, so links already sent in Jira issues, notifications or bookmarks don't break. - New look for every PDF report (technical, audit evidence, consolidated, threat model): a cover with the system,
date, revision and reference; «Confidential» on every page and «page N of M» in the footer; Source Serif 4 and IBM
Plex (embedded, SIL OFL) instead of Helvetica; ruled tables and key figures without fills; severity as coloured text. - The technical report reads like one a person would write: a short executive summary, each action with an ID
(PIT-001…) used throughout the report, and one sheet per critical or high code finding with what happens, how to
fix it (before and after) and how to verify it. Method, coverage, sources and the closing notice are together in
"About this report".
Fixed
-
make openapiworks again:openapi-typescriptruns fromweb/tools/openapiwith the TypeScript 5 its compiler API
needs (the panel moved to TypeScript 7). -
A Jira rule's backfill no longer skips findings whose issues were deleted in Jira. Like a manual export, it now
asks Jira which linked issues still exist and creates again the ones that are gone; before, a cleanup in Jira left
those findings out of every backfill. The backfill dialog's count asks Jira too, so it no longer offers "0 issues"
when the linked ones were deleted. -
Threat diagram arrows no longer run behind other components. Each flow picks the sides and the curve that go
around what is in between, and flows leaving the same side of a component spread along it instead of starting at one
point; the editor, the SVG and the PDF draw them the same way. In the bundled examples, flows running over another
component went from 108 of 156 to 12 (one flow per example still needs a route with bends). Wide curves and their
labels now stay inside the exported drawing. -
A threat marked mitigated or not applicable while the scans still find it goes back to "with evidence", with a
note saying who decided and asking to review the decision. The decision is kept and applies again once the
evidence is gone. -
Threat model reports for MITRE ATT&CK and attack trees now open with their own figures (techniques by status;
goals still reachable or cut), with the techniques or the trees in the body instead of an appendix after "0
threats". An attack tree with no steps yet is no longer counted as cut. -
LINDDUN is no longer mixed with STRIDE: its "D" and "I" are counted apart, and the OWASP Threat Dragon export
names its threats (Detecting, Identifying…) as LINDDUN instead of Denial of service or Information disclosure. -
"What to address first" no longer repeats a component already listed with evidence, and shows the high patterns
when there are no critical ones. A flow can't take a component's ID. Smaller fixes: appendix letters in order,
decision dates, plurals in Spanish, ATT&CK names in the report's language, linked repositories counted apart from
pending ones, and the closing note no longer left alone on the last page. -
The audit report's period is now real. On a repository's state it keeps the findings detected by the end of the
period and not fixed before it starts, and says so; a single scan outside the period is refused instead of being
presented as evidence for it. The consolidated report filters the same way. -
Figures that add up. Findings out of scope no longer count as in scope; the critical and high figures are the
open ones in both reports; a single scan no longer shows "0 fixed" (it can't know). -
Evidence whole. The revision is the git commit (the snapshot's SHA-256 goes apart, whole), the reference is no
longer cut, long paths keep their file name and line, and the closing note no longer claims a review nobody signed. -
Smaller fixes: "page X of Y", code shown as code instead of backticks, dependency advisories located at their
manifest, EPSS with the locale's decimal separator, Spanish agreeing with «hallazgos», and the Markdown export with
its states translated and its headings nested properly.
Security
- The panel and the docs site build with pnpm instead of npm, pinned by hash through corepack, with supply-chain
settings in theirpnpm-workspace.yaml. A release has to be a week old before it is installed, and a recent version
that loses the provenance its predecessors had is refused. Transitive dependencies can't come from git or tarballs,
and dependencies' install scripts never run (the way the 2025 npm worms spread). The lockfiles keep npm's versions,
except that the docs site goes back to astro 7.3.5 and Starlight 0.42.5 (the newer ones came out that same day). A
security fix younger than a week goes in as an exception for that exact version.openapi-typescriptis now a pinned
dev dependency instead of annpxdownload. - Vite 8.3.3 in the panel's development server (GHSA-9jrq-w75r-8gcw, GHSA-vfpm-58rq-9qcg, GHSA-rq7h-c2jc-7f22).
The built panel doesn't contain Vite.
Upgrading from 0.12.0
make update(orgit pullandmake up): the published0.12images move to 0.12.1. No migration to run by hand.- The panel's addresses are now English; bookmarks and links with the Spanish ones keep working.