Commit Graph

  • a8353307c7 update(cmake): bump libs and driver version to 2433c822e1c3ed55f6528c18a27373a677ce76af Jason Dellaluce 2022-08-25 09:57:26 +00:00
  • 6db7353264 update(tests/engine): sync ast structs to new libs definitions Jason Dellaluce 2022-08-25 09:27:07 +00:00
  • d35dba30ed update(userspace/engine): sync ast structs to new libs definitions Jason Dellaluce 2022-08-25 09:26:51 +00:00
  • 8872f256f6 Support multiple URLs for DRIVERS_REPO environment variable (comma separated) Ian Robertson 2022-08-16 15:16:14 -05:00
  • c40a216434 Identify DRIVER_VERSION and ARCH by storing in their proper directories Ian Robertson 2022-08-16 13:34:53 -05:00
  • 3e3a380702 update(CI): do not check hidden files with codespell Andrea Terzolo 2022-08-23 15:43:36 +02:00
  • 5e65e195ae fix(CI): codespell should ignore ro word Andrea Terzolo 2022-08-23 15:29:44 +02:00
  • 02fce93d02 update(CI): remove release branches from the push event Andrea Terzolo 2022-08-22 10:47:57 +00:00
  • 6051f2de81 update(CI): build Falco to run CodeQL Analysis Andrea Terzolo 2022-08-19 23:53:10 +02:00
  • 9359db904b update(CI): remove python from languages Andrea Terzolo 2022-08-19 23:49:51 +02:00
  • 4c3b797003 update(CI): remove codeQL schedule option Andrea Terzolo 2022-08-19 23:48:56 +02:00
  • 8259a2cd5f new(CI): add CodeQL security scanning to Falco. Andrea Terzolo 2022-08-19 15:31:05 +02:00
  • e7502431a2 update(userspace/falco): move rate limiter out of falco outputs framework Jason Dellaluce 2022-08-10 15:13:44 +00:00
  • bec103de1a docs(falco.yaml): improve rate limiter config docs Jason Dellaluce 2022-07-21 10:05:39 +00:00
  • 6c74aa1a29 update(userspace/falco): enable per-event-source rate limiter Jason Dellaluce 2022-07-21 09:58:39 +00:00
  • af0b624a3a fix(userspace/falco): set alert throttling config defaults Jason Dellaluce 2022-07-21 09:23:34 +00:00
  • 8760f04bf2 refactor(userspace/falco): make output framework explicitly thread-safe Jason Dellaluce 2022-07-21 09:22:04 +00:00
  • 88494d1412 update(falco.yaml): disable alert throttling by default Jason Dellaluce 2022-07-21 09:18:55 +00:00
  • db92f04474 wip test/new_libs Federico Di Pierro 2022-08-22 15:09:36 +02:00
  • 8e61e46016 Add an "Ok, with warnings" overall status. Mark Stemm 2022-08-10 18:21:56 -07:00
  • 3c7b6e037a Falco engine changes to support multiple files in rule load results Mark Stemm 2022-08-08 16:38:06 -07:00
  • 49b7f0474f Falco application changes to support multiple files in rules results Mark Stemm 2022-08-08 16:30:48 -07:00
  • 98c1e3d3f1 Restructure rules result to properly support multiple files Mark Stemm 2022-08-08 16:25:21 -07:00
  • 0828296abc cleanup(rules): cleanup rules disabled by default - 2 Melissa Kilby 2022-08-16 22:38:48 -07:00
  • 6971ed2dce update(PR-template): restore release-note Andrea Terzolo 2022-08-10 20:03:36 +02:00
  • be10b1f8cb update(PR-template): add some area/kind to the template Andrea Terzolo 2022-08-09 21:23:31 +02:00
  • 1efea20f57 update(PR-template): set NONE as default release-note Andrea Terzolo 2022-08-09 21:20:55 +02:00
  • fefd23f2f1 fix: print full rule load errors without verbose/-v Mark Stemm 2022-08-04 14:47:05 -05:00
  • 5643e2553c update(docs): changelog for version 0.32.2 0.32.2 release/0.32.2 Andrea Terzolo 2022-08-04 00:12:49 +02:00
  • 54580efaa8 fix: added arch to bpf download url Eric Engberg 2022-07-21 13:51:57 -05:00
  • 359bd41b2e chore(userspace/falco): correct comment update/remove-mesos-support Leonardo Grasso 2022-08-09 13:15:43 +02:00
  • 2a640daf13 update(docs): changelog for version 0.32.2 Andrea Terzolo 2022-08-04 00:12:49 +02:00
  • 27fb674406 chore: cleanup Mesos references Leonardo Grasso 2022-08-09 11:18:36 +02:00
  • 4b35d71c99 chore(userspace/falco): remove unused mesos_api var Leonardo Grasso 2022-08-09 11:15:35 +02:00
  • 710d15a2fd chore(userspace/falco/app_actions): remove Mesos support Leonardo Grasso 2022-08-09 11:13:27 +02:00
  • 3a445c6457 update!: remove --mesos-api and -pm command-line flags Leonardo Grasso 2022-08-09 11:12:30 +02:00
  • 0ab66c6fb5 update(userspace/falco): rename some buffer kernel side event drop metrics, add comments Melissa Kilby 2022-07-19 20:11:59 -07:00
  • 1588f37788 update(userspace/falco): extend buffer kernel side event drop metrics Melissa Kilby 2022-06-23 21:53:55 -07:00
  • 66af8ad52b new(userspace/falco): extend ebpf buffer kernel side event drop metrics incertum 2022-06-20 10:41:11 -07:00
  • ff247f922d chore(test/utils): remove unused script Andrea Terzolo 2022-08-05 17:08:33 +02:00
  • e9ba5d751f cleanup(rules): cleanup rules disabled by default Melissa Kilby 2022-08-04 10:40:01 -07:00
  • c81f3fc87e docs(falco-driver-loader): add some comments in falco-driver-loader Andrea Terzolo 2022-08-03 20:51:41 +00:00
  • a37e2252b2 Update tests to use result struct + json-based validation Mark Stemm 2022-06-28 17:12:58 -07:00
  • 550cdbd176 Falco application changes to support rule loading result struct Mark Stemm 2022-06-23 17:55:50 -07:00
  • f7f6d72ac0 Rule loader changes to support result objects Mark Stemm 2022-06-15 17:06:37 -07:00
  • cbe7cceb87 Modify rule reader to use a result struct Mark Stemm 2022-06-15 16:35:22 -07:00
  • bb44d992ab Change filter_warning_resolver to use warning codes Mark Stemm 2022-06-15 16:25:39 -07:00
  • 0066ba49ea Falco engine changes to support load_rules result class Mark Stemm 2022-06-15 16:17:14 -07:00
  • 8497f25a43 Add a load result interface for use in new load_rules methods Mark Stemm 2022-06-15 16:10:25 -07:00
  • 6b7be38e41 test: update a comment Andrea Terzolo 2022-08-03 18:16:55 +00:00
  • 9d443685ea new(userspace): support SCAP_FILTERED_EVENT return code Andrea Terzolo 2022-08-01 14:07:53 +00:00
  • 928d3225b9 fix(cmake): force using bundled valijson Jason Dellaluce 2022-08-03 13:10:33 +00:00
  • a531e8b3ed fix(test): use old event versions in trace tests Jason Dellaluce 2022-08-03 12:56:42 +00:00
  • 07fde46e7c fix(test): sync plugin tests to new plugin loader errors Jason Dellaluce 2022-08-03 12:56:17 +00:00
  • 136b528849 fix(tests): index old version of events in rulesets Jason Dellaluce 2022-08-03 12:55:42 +00:00
  • a46cbcffe8 fix(engine): index old version of events in rulesets Jason Dellaluce 2022-08-03 12:55:30 +00:00
  • 577ba5904b update(engine): bump version to 14 and update fields checksum Jason Dellaluce 2022-08-03 12:53:59 +00:00
  • 1b8c8a86ec update(cmake): bump libs version to b4c198773bf05486e122f6d3f7f63be125242413 Jason Dellaluce 2022-08-03 12:51:52 +00:00
  • 7317d80dd8 update(cmake): bump driver version to b4c198773bf05486e122f6d3f7f63be125242413 Jason Dellaluce 2022-08-03 12:51:46 +00:00
  • c8bc5758c3 new(userspace): print architecture information Andrea Terzolo 2022-07-29 18:36:54 +00:00
  • ae43f30b0d fix(ci): fixed docker manifest circleci. Federico Di Pierro 2022-07-29 11:39:47 +02:00
  • fb579615a3 cleanup(ci): natively builds docker images for x86_64 and arm64 and then use docker manifest to combine them. Federico Di Pierro 2022-07-14 16:19:49 +02:00
  • b759e77fda new(userspace): print if the BPF probe is enabled Andrea Terzolo 2022-07-14 18:35:25 +02:00
  • 74b6186f7d new(userspace): print enabled sources when falco starts Andrea Terzolo 2022-07-14 18:32:07 +02:00
  • baf5540c30 Remove required_engine_version from falco engine load_rules APIs Mark Stemm 2022-06-27 14:51:13 -07:00
  • c3ddd7d5f1 fix: added arch to bpf download url Eric Engberg 2022-07-21 13:51:57 -05:00
  • b378c3a77d Add darryk10 as rules OWNERS as reviewer Signed-off-by: darryk10 <stefano.chierici@sysdig.com> Stefano 2022-07-20 11:56:26 +02:00
  • 0cab9ba6ed chore(OWNERS): remove duplicates in reviewers Jason Dellaluce 2022-07-05 16:45:22 +00:00
  • 8cb6fc532f cleanup(OWNERS): remove inactive approvers Jason Dellaluce 2022-07-05 14:23:01 +00:00
  • 35db0b4a24 cleanup(userspace): remove unused logic Andrea Terzolo 2022-07-13 16:51:49 +02:00
  • 4136a27de1 new(userspace): add exception management Andrea Terzolo 2022-07-13 13:24:17 +02:00
  • e73dbd4b42 new(userspace): add current drop_pct Andrea Terzolo 2022-07-13 13:19:41 +02:00
  • b57a2d5a5f update(userspace): introduce nlohmann json library Andrea Terzolo 2022-07-13 13:16:44 +02:00
  • 1bf5f864bc chore(docs): updated release.md template for packages adding aarch64 packages. Federico Di Pierro 2022-07-11 12:45:01 +02:00
  • c40d1a5141 Update rules/falco_rules.yaml Alessandro Brucato 2022-07-13 10:31:26 +02:00
  • 409ca4382e Update rules/falco_rules.yaml Alessandro Brucato 2022-07-13 10:16:44 +02:00
  • a71a635b7e Update rules/falco_rules.yaml Alessandro Brucato 2022-07-13 10:16:30 +02:00
  • 07024a2e0f Update rules/falco_rules.yaml Alessandro Brucato 2022-07-13 10:15:32 +02:00
  • 6feeaee0cd Added exception to Launch Privileged Container Brucedh 2022-07-07 15:48:41 +02:00
  • a7153f2fd8 fix(userspace): compute the drop ratio in the right way Andrea Terzolo 2022-07-12 19:23:56 +02:00
  • c078f7c21d Falco Rules/Conditions Updates Ravi Ranjan 2022-04-25 09:38:29 +02:00
  • 46f625c449 chore(engine): remove trailing colon from logs when loading rule files Aldo Lacuku 2022-07-12 09:49:12 +02:00
  • 55fb5fe72d docs: remove fntlnz remove-fntlnz Lorenzo Fontana 2022-07-11 16:22:31 +02:00
  • 4c4ed56c19 update(docs): changelog for version 0.32.1 0.32.1 Luca Guerra 2022-07-11 07:53:56 +00:00
  • 773156de04 update(falco): update libs to 0.7.0 Luca Guerra 2022-07-11 07:29:50 +00:00
  • 62c1e875d5 update(userspace/falco): simplify sinsp logger sev decoding Jason Dellaluce 2022-07-01 13:41:40 +00:00
  • 7dade32688 refactor(userspace/falco): make sinsp logging part of the configuration (default to false) Jason Dellaluce 2022-06-27 13:33:03 +00:00
  • bae68b37ee new(userspace/falco): enable attaching libsinsp logger to the falco one Jason Dellaluce 2022-06-27 13:09:14 +00:00
  • 3ddabc3b95 docs(readme): added arm64 mention + packages + badge. Federico Di Pierro 2022-06-29 11:26:43 +02:00
  • a8b9ec18b0 fix(circleci): properly set BUILD_DIR and SOURCE_DIR to /build and /source respectively. Federico Di Pierro 2022-06-29 14:08:32 +02:00
  • 34404141e4 fix(circleci): share docker socket with docker container. Federico Di Pierro 2022-06-29 12:44:34 +02:00
  • 315b44dc17 new(circleci): enable integration tests for arm64. Federico Di Pierro 2022-06-29 09:29:38 +02:00
  • 161fe6fb3c update(falco): upgrade drivers to 2.0.0, libs to latest rc Luca Guerra 2022-07-05 08:19:44 +00:00
  • 3cde70eda8 fix(falco): parameter ordering in initialization Luca Guerra 2022-06-28 07:33:37 +00:00
  • 982e8663be update(gvisor): make gvisor_enable depend on config Luca Guerra 2022-06-27 14:56:12 +00:00
  • 993516f430 new(falco): add compile-time option to enable or disable gvisor support Luca Guerra 2022-06-27 14:43:02 +00:00
  • 60b149709d fix(gvisor): formatting Luca Guerra 2022-06-27 16:37:32 +02:00
  • 698eda8680 new(gvisor): add option to generate gVisor configuration Luca Guerra 2022-06-24 13:20:07 +00:00
  • 0b75433cee update(gvisor): update to the latest sinsp interface Luca Guerra 2022-06-24 13:19:13 +00:00
  • 0ba492c280 new(falco): do not alert on syscall frequency when gvisor is enabled Luca Guerra 2022-06-20 14:47:59 +00:00