Skip to content

Pitangus 0.12.1

Choose a tag to compare

@BrayansStivens BrayansStivens released this 09 Oct 08:59
ea8645b

Pitangus 0.12.1: an Images page with the repository each image is built from, one scope picker for compliance evidence, eleven more audit frameworks (EU, US and Mexico), redesigned PDF reports and English panel paths.

Images (signed with cosign, SBOM and SLSA provenance attached; linux/amd64 and linux/arm64):

  • ghcr.io/pitangus-dev/pitangus:0.12.1 (also :0.12)
  • ghcr.io/pitangus-dev/pitangus-worker:0.12.1 (also :0.12)

Verify them with make verify-images or the command in docs/deploy-vps.md.

Added

  • Images page (Scanning → Images): every analyzed image, the repository it's built from and how it was linked
    (OCI label or by hand), with a "not linked" tab for the ones that still need one. An administrator links, changes or
    removes the link there; each row opens its findings or scans the image again. Repositories show how many images are
    built from each one, and from a repository you can link another image to it.
  • One scope picker for the evidence in Compliance. Three steps: which assets (one, an organization, several or all),
    which framework, and the downloads for that scope, with a preview of what it covers (repositories, images, how many
    with a complete scan) before downloading anything. The separate "one asset" and "portfolio" blocks are gone.
  • An image knows which repository it is built from. Pitangus reads its OCI labels (org.opencontainers.image.source
    and .revision, set by docker/build-push-action and GHCR) and links it to that repository when it is analyzed too;
    an administrator can set or change the link by hand in Compliance. The reports say "built from org/repo @ commit".
  • Portfolio evidence for the scope you choose: every analyzed asset, the repositories of one organization, or a
    chosen set of repositories and images; with a repository come the images built from it (it can be turned off). It
    applies to the portfolio SBOM, VEX and consolidated audit evidence.
  • Audit evidence for eleven more frameworks. European Union: NIS2 (Art. 21(2) and Implementing Regulation
    2024/2690), DORA (with RTS 2024/1774) and GDPR Art. 32. United States: NIST SSDF (SP 800-218), NIST CSF 2.0,
    NIST SP 800-53 Rev. 5 and the HIPAA Security Rule. Mexico: CNBV rules for banks (CUB) and crowdfunding institutions,
    e-money institutions (IFPE) and LFPDPPP Art. 18. Each control says what the evidence covers and what stays out
    (infrastructure scanning, external pentests, dynamic testing): it supports an audit, it doesn't certify compliance.

Changed

  • The panel's paths are English (#/findings, #/compliance, #/images…) whatever its language, so a shared link
    reads the same for everyone. The Spanish paths of earlier versions (#/hallazgos, #/resumen…) still work and are
    rewritten, so links already sent in Jira issues, notifications or bookmarks don't break.
  • New look for every PDF report (technical, audit evidence, consolidated, threat model): a cover with the system,
    date, revision and reference; «Confidential» on every page and «page N of M» in the footer; Source Serif 4 and IBM
    Plex (embedded, SIL OFL) instead of Helvetica; ruled tables and key figures without fills; severity as coloured text.
  • The technical report reads like one a person would write: a short executive summary, each action with an ID
    (PIT-001…) used throughout the report, and one sheet per critical or high code finding with what happens, how to
    fix it (before and after) and how to verify it. Method, coverage, sources and the closing notice are together in
    "About this report".

Fixed

  • make openapi works again: openapi-typescript runs from web/tools/openapi with the TypeScript 5 its compiler API
    needs (the panel moved to TypeScript 7).

  • A Jira rule's backfill no longer skips findings whose issues were deleted in Jira. Like a manual export, it now
    asks Jira which linked issues still exist and creates again the ones that are gone; before, a cleanup in Jira left
    those findings out of every backfill. The backfill dialog's count asks Jira too, so it no longer offers "0 issues"
    when the linked ones were deleted.

  • Threat diagram arrows no longer run behind other components. Each flow picks the sides and the curve that go
    around what is in between, and flows leaving the same side of a component spread along it instead of starting at one
    point; the editor, the SVG and the PDF draw them the same way. In the bundled examples, flows running over another
    component went from 108 of 156 to 12 (one flow per example still needs a route with bends). Wide curves and their
    labels now stay inside the exported drawing.

  • A threat marked mitigated or not applicable while the scans still find it goes back to "with evidence", with a
    note saying who decided and asking to review the decision. The decision is kept and applies again once the
    evidence is gone.

  • Threat model reports for MITRE ATT&CK and attack trees now open with their own figures (techniques by status;
    goals still reachable or cut), with the techniques or the trees in the body instead of an appendix after "0
    threats". An attack tree with no steps yet is no longer counted as cut.

  • LINDDUN is no longer mixed with STRIDE: its "D" and "I" are counted apart, and the OWASP Threat Dragon export
    names its threats (Detecting, Identifying…) as LINDDUN instead of Denial of service or Information disclosure.

  • "What to address first" no longer repeats a component already listed with evidence, and shows the high patterns
    when there are no critical ones. A flow can't take a component's ID. Smaller fixes: appendix letters in order,
    decision dates, plurals in Spanish, ATT&CK names in the report's language, linked repositories counted apart from
    pending ones, and the closing note no longer left alone on the last page.

  • The audit report's period is now real. On a repository's state it keeps the findings detected by the end of the
    period and not fixed before it starts, and says so; a single scan outside the period is refused instead of being
    presented as evidence for it. The consolidated report filters the same way.

  • Figures that add up. Findings out of scope no longer count as in scope; the critical and high figures are the
    open ones in both reports; a single scan no longer shows "0 fixed" (it can't know).

  • Evidence whole. The revision is the git commit (the snapshot's SHA-256 goes apart, whole), the reference is no
    longer cut, long paths keep their file name and line, and the closing note no longer claims a review nobody signed.

  • Smaller fixes: "page X of Y", code shown as code instead of backticks, dependency advisories located at their
    manifest, EPSS with the locale's decimal separator, Spanish agreeing with «hallazgos», and the Markdown export with
    its states translated and its headings nested properly.

Security

  • The panel and the docs site build with pnpm instead of npm, pinned by hash through corepack, with supply-chain
    settings in their pnpm-workspace.yaml. A release has to be a week old before it is installed, and a recent version
    that loses the provenance its predecessors had is refused. Transitive dependencies can't come from git or tarballs,
    and dependencies' install scripts never run (the way the 2025 npm worms spread). The lockfiles keep npm's versions,
    except that the docs site goes back to astro 7.3.5 and Starlight 0.42.5 (the newer ones came out that same day). A
    security fix younger than a week goes in as an exception for that exact version. openapi-typescript is now a pinned
    dev dependency instead of an npx download.
  • Vite 8.3.3 in the panel's development server (GHSA-9jrq-w75r-8gcw, GHSA-vfpm-58rq-9qcg, GHSA-rq7h-c2jc-7f22).
    The built panel doesn't contain Vite.

Upgrading from 0.12.0

  • make update (or git pull and make up): the published 0.12 images move to 0.12.1. No migration to run by hand.
  • The panel's addresses are now English; bookmarks and links with the Spanish ones keep working.