Skip to content

Pitangus 0.12.2

Choose a tag to compare

@BrayansStivens BrayansStivens released this 09 Oct 19:44
· 12 commits to main since this release
fbdde54

Pitangus 0.12.2: create the GitHub App from the panel in two clicks and connect each installation with one, findings across several assets at once, images added without scanning, readable Slack and Teams notices, and a lighter panel.

Images (signed with cosign, SBOM and SLSA provenance attached; linux/amd64 and linux/arm64):

  • ghcr.io/pitangus-dev/pitangus:0.12.2 (also :0.12)
  • ghcr.io/pitangus-dev/pitangus-worker:0.12.2 (also :0.12)

Verify them with make verify-images or the command in docs/deploy-vps.md.

Upgrading from 0.12.1 (installed with --branch v0.12.1): git fetch --tags && git checkout v0.12.2 && make update. Following main: make update.

Added

  • Findings of several assets at once. Findings has the same scope picker as Compliance: one asset (as before, with
    its runs and settings), an organization, a chosen set of repositories and images, or everything, with the images
    built from the chosen repositories. The cards add up the whole scope, a "By asset" block shows each asset's pending
    and critical findings and opens it on its own, and the table gains an Asset column. Triage (one finding or a
    selection across assets in one request, applied asset by asset with any failure named), Jira issues and the
    consolidated audit evidence work on the scope. The scope stays in the address, so a reload or a shared link opens the
    same view. New route GET /api/findings/scope; a very large scope lists the 10,000 most urgent findings of the tab
    and says so. POST /api/findings/triage also takes selections ([{run_id, fingerprints}], one per asset, up to 500
    findings in all) instead of run_id and fingerprints, and answers each one's outcome in results; it fails as a
    whole only when none landed. The cards are counted by the server in every view: summary.kpis in an asset's state,
    a run (GET /api/runs/{id}) and a scope, with what was fixed (by a scan or by hand) never counted as pending.

  • Create the GitHub App from the panel (Integrations → GitHub → Create on GitHub). GitHub's form opens with
    everything filled in (name, the four permissions, no webhook or OAuth, the return to this panel); you confirm there
    and come back with the App connected, instead of copying values and uploading the .pem. The App is still yours and
    its private key goes from GitHub straight to the server, encrypted; the link is single-use and lasts an hour. The
    manual guide stays, folded underneath. API: POST /api/integrations/github/manifest and the return at
    /github/app-created.

  • Add an image without scanning it (Scanning → Images → Add image). Type its reference and, if you're an
    administrator, the repository it's built from; it shows on the list as "Not scanned yet" and is scanned when you
    choose ("Scan it now" does it right away). Adding one that is already there says so; if it isn't scanned yet, it now
    scans the reference you just typed. Its first scan lands on the same asset, keeping the link; until then it has no
    findings and stays out of the evidence scopes. At most 5,000 images wait unscanned at a time (scanned ones don't
    count). An administrator can remove an image that was never scanned. API: POST /api/images and POST /api/images/remove;
    GET /api/images items carry analyzed.

  • Connecting an installation takes one click. Coming back from installing the App on GitHub (its Setup URL) no
    longer stops at a page that says to go back and look for it: it opens Integrations, which offers that account with
    Connect (only to administrators; the server still checks it belongs to the App). /oauth/callback no longer calls
    GitHub: it only hands the installation to the panel.

Fixed

  • Slack and Teams notices read better. No more emoji: each finding shows its severity in words and what it is,
    with where it is on the line below ("Dependency next 14.2.3" or the file and line), under "Most urgent". In Slack
    the edge of the message takes the colour of the most severe finding. Dependency advisories drop the repeated package
    prefix ("flatted 3.3.1: flatted: Flatted: Prototype pollution…" becomes "Prototype pollution…"); the signed webhook
    gets the same cleaner title and a new dependency flag per item.
  • Slack messages no longer show a warning next to "Open in Pitangus". It was a button, and Slack treats every
    button as interactive: with an incoming webhook (no interactivity URL) it marked it with a warning. It is now a plain
    link that opens the same page.

Security

  • The images no longer carry pip. It installs the pinned dependencies and is then removed, from the app image and
    from Checkov's environment in the worker with the engines inside: nothing runs it, and the 25.0.1 that Python 3.12
    bundles has six known vulnerabilities (pip 26 would trade them for its vendored urllib3, msgpack and setuptools).
  • Checkov's asteval goes to 1.0.10 in the worker with the engines inside. Checkov 3.3.19 (and every later release
    so far) pins 1.0.6, which it uses to evaluate the Terraform expressions of the scanned repository; 1.0.9 fixed two
    sandbox escapes (GHSA-89v8-rhwq-hf77, GHSA-9w56-46f6-3qhx). It is installed by hash over the lock, from
    docker/checkov/overrides.txt; Checkov's results don't change.
  • The Docker client in the image goes to 29.9.0, built with Go 1.26.9: the 13 Go standard library vulnerabilities
    of 29.8.2 (two high: CVE-2026-78667, CVE-2026-97031) are gone. It came out on 2026-10-09, so it goes in as an
    exception to the week-old rule, checked against its SHA-256 like before.
  • The Python base image moves to the current python:3.12-slim-bookworm digest (still Python 3.12.15). The engines stay
    where they were: they are already the newest releases at least a week old, and the Go standard library fixes their
    remaining findings need (Go 1.26.9 and 1.27.2) came out on 2026-10-08.

Upgrading from 0.12.1

  • If you installed a release (git clone --branch v0.12.1, as in the quickstart), make update alone stays on it:
    git fetch --tags && git checkout v0.12.2 && make update. Following main, make update is enough. The new
    "Upgrade" section of docs/installation.md explains both.
  • The database gets one new table (the images added without scanning), created on start: nothing to do by hand.
  • Slack and Teams notices change format (no emoji); a signed webhook receiver gets a cleaner title and a new
    dependency field per item.