From 5df8e241822fa80d1066cb135904d69438eb2460 Mon Sep 17 00:00:00 2001 From: bkaiserinfosec <49665796+bkaiserinfosec@users.noreply.github.com> Date: Fri, 29 Dec 2023 20:53:22 -0800 Subject: [PATCH 01/37] Update pipeline-config.yaml (#440) --- pipeline-config.yaml | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/pipeline-config.yaml b/pipeline-config.yaml index 3c3e8bea..9d98c47f 100644 --- a/pipeline-config.yaml +++ b/pipeline-config.yaml @@ -9,54 +9,54 @@ stages: branches: - release unitTesting: - enabled: false + enabled: true branches: [] secretScanning: - enabled: false + enabled: true branches: - release sca: - enabled: false + enabled: true branches: - release codeLanguages: - Python - Javascript sast: - enabled: false + enabled: true branches: - release codeLanguages: - Python iac: - enabled: false + enabled: true branches: - release buildDocker: - enabled: false + enabled: true branches: - release containerScan: - enabled: false + enabled: true branches: - release containerName: secusphere containerTag: latest releaseToTest: - enabled: false + enabled: true branches: - release serviceName: secusphere containerTag: latest testRelease: - enabled: false + enabled: true branches: - release targetUrl: 'http://192.168.0.68:5010' dastTestType: full apiTargetUrl: 'http://192.168.0.68:5010/api/openapi.yaml' securityQualityGate: - enabled: false + enabled: true branches: - release deploy: @@ -83,7 +83,7 @@ stages: app.smtp.passwordRef: "SENDGRID-SMTP-PW" app.az.keyVaultName: "BkDevSecOpsKeyVault" post: - enabled: false + enabled: true branches: - release recipientEmails: 'brian@jbfinegoods.com' From c3fb035bf7c9b3c54717eb12a205942eef53905e Mon Sep 17 00:00:00 2001 From: bkaiserinfosec <49665796+bkaiserinfosec@users.noreply.github.com> Date: Fri, 29 Dec 2023 21:09:41 -0800 Subject: [PATCH 02/37] Update tox.ini (#441) --- src/tox.ini | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/src/tox.ini b/src/tox.ini index 5c4f7a01..eedeee12 100644 --- a/src/tox.ini +++ b/src/tox.ini @@ -7,7 +7,7 @@ deps = pytest coverage pytest-cov - Flask==2.2.2 + Flask==2.3.3 Flask-SQLAlchemy==3.0.3 Flask-Login==0.6.2 Flask-Moment==1.0.5 @@ -15,11 +15,11 @@ deps = Flask-Markdown==0.3 Flask-Bootstrap==3.3.7.1 pyotp==2.8.0 - PyJWT==2.6.0 + PyJWT==2.7.0 pycryptodome==3.17 PyQRCode==1.2.1 python-dateutil==2.8.2 - requests==2.28.2 + requests==2.31.0 azure-identity==1.12.0 azure-keyvault-secrets==4.6.0 azure-keyvault-certificates==4.6.0 From 57a681aae8c644eb08cd9166fa2fdd2709583866 Mon Sep 17 00:00:00 2001 From: bkaiserinfosec <49665796+bkaiserinfosec@users.noreply.github.com> Date: Sat, 30 Dec 2023 00:04:00 -0800 Subject: [PATCH 03/37] Feature/fix toxi (#443) * Update tox.ini * fix unit test failures --- src/vr/templates/vulns/all_vulnerabilities_filtered.html | 4 ---- src/vr/vulns/web/findings.py | 2 +- 2 files changed, 1 insertion(+), 5 deletions(-) diff --git a/src/vr/templates/vulns/all_vulnerabilities_filtered.html b/src/vr/templates/vulns/all_vulnerabilities_filtered.html index 22bfd116..f67b34cb 100644 --- a/src/vr/templates/vulns/all_vulnerabilities_filtered.html +++ b/src/vr/templates/vulns/all_vulnerabilities_filtered.html @@ -51,11 +51,7 @@