Repository navigation
Pitangus 0.12.2
Pitangus 0.12.2: create the GitHub App from the panel in two clicks and connect each installation with one, findings across several assets at once, images added without scanning, readable Slack and Teams notices, and a lighter panel.
Images (signed with cosign, SBOM and SLSA provenance attached; linux/amd64 and linux/arm64):
ghcr.io/pitangus-dev/pitangus:0.12.2(also:0.12)ghcr.io/pitangus-dev/pitangus-worker:0.12.2(also:0.12)
Verify them with make verify-images or the command in docs/deploy-vps.md.
Upgrading from 0.12.1 (installed with --branch v0.12.1): git fetch --tags && git checkout v0.12.2 && make update. Following main: make update.
Added
-
Findings of several assets at once. Findings has the same scope picker as Compliance: one asset (as before, with
its runs and settings), an organization, a chosen set of repositories and images, or everything, with the images
built from the chosen repositories. The cards add up the whole scope, a "By asset" block shows each asset's pending
and critical findings and opens it on its own, and the table gains an Asset column. Triage (one finding or a
selection across assets in one request, applied asset by asset with any failure named), Jira issues and the
consolidated audit evidence work on the scope. The scope stays in the address, so a reload or a shared link opens the
same view. New routeGET /api/findings/scope; a very large scope lists the 10,000 most urgent findings of the tab
and says so.POST /api/findings/triagealso takesselections([{run_id, fingerprints}], one per asset, up to 500
findings in all) instead ofrun_idandfingerprints, and answers each one's outcome inresults; it fails as a
whole only when none landed. The cards are counted by the server in every view:summary.kpisin an asset's state,
a run (GET /api/runs/{id}) and a scope, with what was fixed (by a scan or by hand) never counted as pending. -
Create the GitHub App from the panel (Integrations → GitHub → Create on GitHub). GitHub's form opens with
everything filled in (name, the four permissions, no webhook or OAuth, the return to this panel); you confirm there
and come back with the App connected, instead of copying values and uploading the.pem. The App is still yours and
its private key goes from GitHub straight to the server, encrypted; the link is single-use and lasts an hour. The
manual guide stays, folded underneath. API:POST /api/integrations/github/manifestand the return at
/github/app-created. -
Add an image without scanning it (Scanning → Images → Add image). Type its reference and, if you're an
administrator, the repository it's built from; it shows on the list as "Not scanned yet" and is scanned when you
choose ("Scan it now" does it right away). Adding one that is already there says so; if it isn't scanned yet, it now
scans the reference you just typed. Its first scan lands on the same asset, keeping the link; until then it has no
findings and stays out of the evidence scopes. At most 5,000 images wait unscanned at a time (scanned ones don't
count). An administrator can remove an image that was never scanned. API:POST /api/imagesandPOST /api/images/remove;
GET /api/imagesitems carryanalyzed. -
Connecting an installation takes one click. Coming back from installing the App on GitHub (its Setup URL) no
longer stops at a page that says to go back and look for it: it opens Integrations, which offers that account with
Connect (only to administrators; the server still checks it belongs to the App)./oauth/callbackno longer calls
GitHub: it only hands the installation to the panel.
Fixed
- Slack and Teams notices read better. No more emoji: each finding shows its severity in words and what it is,
with where it is on the line below ("Dependencynext 14.2.3" or the file and line), under "Most urgent". In Slack
the edge of the message takes the colour of the most severe finding. Dependency advisories drop the repeated package
prefix ("flatted 3.3.1: flatted: Flatted: Prototype pollution…" becomes "Prototype pollution…"); the signed webhook
gets the same cleanertitleand a newdependencyflag per item. - Slack messages no longer show a warning next to "Open in Pitangus". It was a button, and Slack treats every
button as interactive: with an incoming webhook (no interactivity URL) it marked it with a warning. It is now a plain
link that opens the same page.
Security
- The images no longer carry pip. It installs the pinned dependencies and is then removed, from the app image and
from Checkov's environment in the worker with the engines inside: nothing runs it, and the 25.0.1 that Python 3.12
bundles has six known vulnerabilities (pip 26 would trade them for its vendored urllib3, msgpack and setuptools). - Checkov's asteval goes to 1.0.10 in the worker with the engines inside. Checkov 3.3.19 (and every later release
so far) pins 1.0.6, which it uses to evaluate the Terraform expressions of the scanned repository; 1.0.9 fixed two
sandbox escapes (GHSA-89v8-rhwq-hf77, GHSA-9w56-46f6-3qhx). It is installed by hash over the lock, from
docker/checkov/overrides.txt; Checkov's results don't change. - The Docker client in the image goes to 29.9.0, built with Go 1.26.9: the 13 Go standard library vulnerabilities
of 29.8.2 (two high: CVE-2026-78667, CVE-2026-97031) are gone. It came out on 2026-10-09, so it goes in as an
exception to the week-old rule, checked against its SHA-256 like before. - The Python base image moves to the current
python:3.12-slim-bookwormdigest (still Python 3.12.15). The engines stay
where they were: they are already the newest releases at least a week old, and the Go standard library fixes their
remaining findings need (Go 1.26.9 and 1.27.2) came out on 2026-10-08.
Upgrading from 0.12.1
- If you installed a release (
git clone --branch v0.12.1, as in the quickstart),make updatealone stays on it:
git fetch --tags && git checkout v0.12.2 && make update. Followingmain,make updateis enough. The new
"Upgrade" section of docs/installation.md explains both. - The database gets one new table (the images added without scanning), created on start: nothing to do by hand.
- Slack and Teams notices change format (no emoji); a signed webhook receiver gets a cleaner
titleand a new
dependencyfield per item.