Repository navigation
Pitangus 0.12.1
Pitangus 0.12.1: an Images page with the repository each image is built from, one scope picker for compliance evidence, eleven more audit frameworks (EU, US and Mexico), redesigned PDF reports and English panel paths.
Images (signed with cosign, SBOM and SLSA provenance attached; linux/amd64 and linux/arm64):
ghcr.io/pitangus-dev/pitangus:0.12.1(also:0.12)ghcr.io/pitangus-dev/pitangus-worker:0.12.1(also:0.12)
Verify them with make verify-images or the command in docs/deploy-vps.md.
Added
- Images page (Scanning → Images): every analyzed image, the repository it's built from and how it was linked
(OCI label or by hand), with a "not linked" tab for the ones that still need one. An administrator links, changes or
removes the link there; each row opens its findings or scans the image again. Repositories show how many images are
built from each one, and from a repository you can link another image to it. - One scope picker for the evidence in Compliance. Three steps: which assets (one, an organization, several or all),
which framework, and the downloads for that scope, with a preview of what it covers (repositories, images, how many
with a complete scan) before downloading anything. The separate "one asset" and "portfolio" blocks are gone. - An image knows which repository it is built from. Pitangus reads its OCI labels (
org.opencontainers.image.source
and.revision, set bydocker/build-push-actionand GHCR) and links it to that repository when it is analyzed too;
an administrator can set or change the link by hand in Compliance. The reports say "built from org/repo @ commit". - Portfolio evidence for the scope you choose: every analyzed asset, the repositories of one organization, or a
chosen set of repositories and images; with a repository come the images built from it (it can be turned off). It
applies to the portfolio SBOM, VEX and consolidated audit evidence. - Audit evidence for eleven more frameworks. European Union: NIS2 (Art. 21(2) and Implementing Regulation
2024/2690), DORA (with RTS 2024/1774) and GDPR Art. 32. United States: NIST SSDF (SP 800-218), NIST CSF 2.0,
NIST SP 800-53 Rev. 5 and the HIPAA Security Rule. Mexico: CNBV rules for banks (CUB) and crowdfunding institutions,
e-money institutions (IFPE) and LFPDPPP Art. 18. Each control says what the evidence covers and what stays out
(infrastructure scanning, external pentests, dynamic testing): it supports an audit, it doesn't certify compliance.
Changed
- The panel's paths are English (
#/findings,#/compliance,#/images…) whatever its language, so a shared link
reads the same for everyone. The Spanish paths of earlier versions (#/hallazgos,#/resumen…) still work and are
rewritten, so links already sent in Jira issues, notifications or bookmarks don't break. - New look for every PDF report (technical, audit evidence, consolidated, threat model): a cover with the system,
date, revision and reference; «Confidential» on every page and «page N of M» in the footer; Source Serif 4 and IBM
Plex (embedded, SIL OFL) instead of Helvetica; ruled tables and key figures without fills; severity as coloured text. - The technical report reads like one a person would write: a short executive summary, each action with an ID
(PIT-001…) used throughout the report, and one sheet per critical or high code finding with what happens, how to
fix it (before and after) and how to verify it. Method, coverage, sources and the closing notice are together in
"About this report".
Fixed
-
make openapiworks again:openapi-typescriptruns fromweb/tools/openapiwith the TypeScript 5 its compiler API
needs (the panel moved to TypeScript 7). -
A Jira rule's backfill no longer skips findings whose issues were deleted in Jira. Like a manual export, it now
asks Jira which linked issues still exist and creates again the ones that are gone; before, a cleanup in Jira left
those findings out of every backfill. The backfill dialog's count asks Jira too, so it no longer offers "0 issues"
when the linked ones were deleted. -
Threat diagram arrows no longer run behind other components. Each flow picks the sides and the curve that go
around what is in between, and flows leaving the same side of a component spread along it instead of starting at one
point; the editor, the SVG and the PDF draw them the same way. In the bundled examples, flows running over another
component went from 108 of 156 to 12 (one flow per example still needs a route with bends). Wide curves and their
labels now stay inside the exported drawing. -
A threat marked mitigated or not applicable while the scans still find it goes back to "with evidence", with a
note saying who decided and asking to review the decision. The decision is kept and applies again once the
evidence is gone. -
Threat model reports for MITRE ATT&CK and attack trees now open with their own figures (techniques by status;
goals still reachable or cut), with the techniques or the trees in the body instead of an appendix after "0
threats". An attack tree with no steps yet is no longer counted as cut. -
LINDDUN is no longer mixed with STRIDE: its "D" and "I" are counted apart, and the OWASP Threat Dragon export
names its threats (Detecting, Identifying…) as LINDDUN instead of Denial of service or Information disclosure. -
"What to address first" no longer repeats a component already listed with evidence, and shows the high patterns
when there are no critical ones. A flow can't take a component's ID. Smaller fixes: appendix letters in order,
decision dates, plurals in Spanish, ATT&CK names in the report's language, linked repositories counted apart from
pending ones, and the closing note no longer left alone on the last page. -
The audit report's period is now real. On a repository's state it keeps the findings detected by the end of the
period and not fixed before it starts, and says so; a single scan outside the period is refused instead of being
presented as evidence for it. The consolidated report filters the same way. -
Figures that add up. Findings out of scope no longer count as in scope; the critical and high figures are the
open ones in both reports; a single scan no longer shows "0 fixed" (it can't know). -
Evidence whole. The revision is the git commit (the snapshot's SHA-256 goes apart, whole), the reference is no
longer cut, long paths keep their file name and line, and the closing note no longer claims a review nobody signed. -
Smaller fixes: "page X of Y", code shown as code instead of backticks, dependency advisories located at their
manifest, EPSS with the locale's decimal separator, Spanish agreeing with «hallazgos», and the Markdown export with
its states translated and its headings nested properly.
Security
- The panel and the docs site build with pnpm instead of npm, pinned by hash through corepack, with supply-chain
settings in theirpnpm-workspace.yaml. A release has to be a week old before it is installed, and a recent version
that loses the provenance its predecessors had is refused. Transitive dependencies can't come from git or tarballs,
and dependencies' install scripts never run (the way the 2025 npm worms spread). The lockfiles keep npm's versions,
except that the docs site goes back to astro 7.3.5 and Starlight 0.42.5 (the newer ones came out that same day). A
security fix younger than a week goes in as an exception for that exact version.openapi-typescriptis now a pinned
dev dependency instead of annpxdownload. - Vite 8.3.3 in the panel's development server (GHSA-9jrq-w75r-8gcw, GHSA-vfpm-58rq-9qcg, GHSA-rq7h-c2jc-7f22).
The built panel doesn't contain Vite.
Upgrading from 0.12.0
make update(orgit pullandmake up): the published0.12images move to 0.12.1. No migration to run by hand.- The panel's addresses are now English; bookmarks and links with the Spanish ones keep working.