Skip to content

v0.1.0: First release

Choose a tag to compare

@foca foca released this 15 Nov 12:50
0baacc1

What's Changed

  • Properly catch generic SQL injection attacks in #2
  • Sink to prevent SQLi for the Trilogy MySQL adapter in #3
  • PG sink and sample app in #4
  • SQLite3 sink and sample app in #5
  • Add unit tests for all the sinks in #6
  • Poll the API for firewall settings changes in #7
  • Simplify our e2e tests in #8
  • Send the "started" event on agent start in #9
  • Add logs and tests to the Agent's runner process in #10
  • Properly implement sinks and start stat gathering in #11
  • Gather stats and send heartbeat events in #12
  • Fix Packages serialization in #13
  • Flesh out attack JSON payloads in #14
  • Test against many rubies in #16
  • Tag input sources with their type and path in #15
  • Send a heartbeat after 1 minute if receivedAnyStats == false in #17
  • Refactor "Request" into Context, and add the missing sources in #18
  • Report routes being visited in #19
  • Send the platform version with the agent info in #22
  • Fix attack reporting on GET requests in #20
  • Track outbound connections in #21
  • Add a sink for HTTP.rb in #23
  • Add a sink for HTTPX in #24
  • Add a sink for HTTPClient in #25
  • Add a sink for Excon in #26
  • Add a sink for EventMachine::HttpRequest in #31
  • Add a sink for Async::HTTP in #30
  • Add a sink for Typhoeus in #29
  • Add a sink for Patron in #28
  • Adds a sink for Curb in #27
  • API for user tracking in #32
  • Rate limit our own API to avoid overwhelming the server in #35
  • Rename to Aikido::Zen in #33
  • Honor all the per-endpoint settings: rate limiting, allowed IPs, and disabling protection in #34
  • Handle SSRFs on libcurl wrappers in #38
  • SSRF Detection: Part 2 in #37
  • SSRF Detection: Part 1 in #36
  • API Discovery in #40
  • Replace SQL Injection detection with libzen_internal's implementation in #39
  • Update libzen to 0.1.26 and handle libzen errors in #42
  • Release scripts in #41
  • Refactor the Agent and fix stats gathering in #43
  • Per-user rate limiting, fixed to work in Rails in #44
  • Remove API sampling feature flag in #45
  • Run benchmarks on CI in #46
  • README and docs in #47

Full Changelog: https://github.com/AikidoSec/firewall-ruby/commits/v0.1.0