Commit Graph

  • 3640871725 update(rules): remove falco_hostnetwork_images list (unused) Leo Di Donato 2021-06-21 11:22:37 +02:00
  • 6d507b054c update(build): update libs version for 0.31 release. Federico Di Pierro 2022-01-20 11:59:50 +01:00
  • f19a1d81c6 update(build): updated plugins to latest versions adding platform name to artifact url. Federico Di Pierro 2022-01-20 11:52:45 +01:00
  • 18c7b6500d refactor: remove apt-config from debian_packages monitoring Andrea Terzolo 2022-01-19 15:45:52 +00:00
  • 8239fa41f4 docs: fix priority level "info" to "informational" Andrea Terzolo 2022-01-18 16:31:42 +00:00
  • a9e7512936 fix setting the variable of User-Agent, it was missing the prefix. Switched to dedicated curl's method to do this yoshi314 2022-01-13 18:34:04 +01:00
  • f67e8bdad7 fix indentation in outputs_http.cpp Marcin Kowalski 2022-01-13 14:02:28 +00:00
  • a94e6de458 add useragent string to output Marcin Kowalski 2022-01-11 11:38:30 +00:00
  • 3e9f8c1ef1 chore(userpsace/engine): update fields checksum Leonardo Grasso 2022-01-17 17:36:57 +01:00
  • d20a326e09 Skip EPF_TABLE_ONLY fields with --list -N Mark Stemm 2022-01-05 14:16:56 -08:00
  • df3b4c1ae9 chore(userpsace/engine): update fields checksum field-properties-changes Leonardo Grasso 2022-01-17 17:36:57 +01:00
  • 85e25cb0d9 Skip EPF_TABLE_ONLY fields with --list -N Mark Stemm 2022-01-05 14:16:56 -08:00
  • 0c290d98f8 fix(tests): avoid hardcoding plugin version 0.1.0 in plugin tests. Federico Di Pierro 2022-01-17 16:24:53 +01:00
  • 1befb053d0 update(gitignore): drop 2 useless lines from gitignore that are now installed in the build folder. Federico Di Pierro 2022-01-17 15:44:16 +01:00
  • ae57718bda update(build): updated libs to latest master version. Updated plugins versions. Updated falco engine version. Federico Di Pierro 2022-01-17 15:28:10 +01:00
  • 55ce38cf3a use debian 11 slim as nodriver image Luca Guerra 2022-01-10 17:24:10 +00:00
  • 18571eb20d ci: build stripped tgz Luca Guerra 2021-12-22 20:04:34 +00:00
  • 9c449901f3 cmake: do not strip tar gz builds Luca Guerra 2021-12-22 20:01:21 +00:00
  • 4ab8d6db98 refactor(configuration): remove plugin config loading from file feature Jason Dellaluce 2022-01-12 16:46:19 +00:00
  • 5e354859a9 new(configuration): allow defining plugin config as YAML maps Jason Dellaluce 2022-01-12 15:31:59 +00:00
  • f4b79296fc fix: improve nested configuration field support Jason Dellaluce 2022-01-12 14:22:44 +00:00
  • 6bf8f34d9f fix(engine): correctly format json output in json_event Jason Dellaluce 2022-01-10 14:23:42 +00:00
  • f8f053c7fa Add an emty line to sattisfy the rules tests vadim.zyarko 2022-01-07 21:08:54 -08:00
  • b88a1cbb09 replace .. with table concat Signed-off-by: vadim.zyarko <vadim.zyarko@sysdig.com> VadimZy 2021-12-11 18:47:02 -08:00
  • c86615f68c Embed .lua files into falco executable Mark Stemm 2022-01-06 14:29:32 -08:00
  • 08df1c63cf Clean up lyaml build a bit Mark Stemm 2022-01-06 14:27:39 -08:00
  • 10512b9ef9 Move compiler/parser lua files to a "modules" subdir Mark Stemm 2022-01-06 14:26:06 -08:00
  • 0e3121b17c Embed .lua files into falco executable embed-lua-scripts Mark Stemm 2022-01-06 14:29:32 -08:00
  • b05b252100 Clean up lyaml build a bit Mark Stemm 2022-01-06 14:27:39 -08:00
  • 2df9a68140 Move compiler/parser lua files to a "modules" subdir Mark Stemm 2022-01-06 14:26:06 -08:00
  • 0e52ef9971 fix(grpc): ignore protobuf deprecation warning Jason Dellaluce 2022-01-10 13:38:02 +00:00
  • a371a995b4 update(outputs): adapt grpc output to new protobuf definitions Jason Dellaluce 2022-01-04 13:29:56 +00:00
  • 0f984c4dbe update(grpc): substitute and deprecate enum source field from protobuf Jason Dellaluce 2022-01-04 13:27:32 +00:00
  • 48a23121df new(userspace/falco): add support for kernel side simple consumer. Federico Di Pierro 2022-01-10 09:30:17 +01:00
  • 475ed0dbeb fix(userspace/engine,userspace/falco): set http output contenttype to text/plain when json output is disabled Federico Di Pierro 2022-01-10 09:40:40 +01:00
  • eaccfbe82d Pick some lint Zach Stone 2022-01-05 14:45:56 -05:00
  • e496c91562 Add Giant Swarm to Adopters list Zach Stone 2022-01-05 14:42:21 -05:00
  • cef2c2d5c1 chore: improve --list output using is_source_valid Lorenzo Susini 2022-01-04 08:07:29 +00:00
  • 2ee0645f25 update(tests): remove token_bucket unit tests Jason Dellaluce 2021-11-18 15:29:04 +00:00
  • 42f8b1cd83 Update to version of libs with better output formatting Mark Stemm 2021-12-08 12:40:31 -08:00
  • 455be15b0b Fill in new shortdesc/data_type/tags for json fields Mark Stemm 2021-12-08 12:39:01 -08:00
  • 64e8feb200 Update fields checksum (no changes, order only) Mark Stemm 2021-12-08 12:38:01 -08:00
  • eded1062cd Use filter_fieldclass_info::as_string to print field info Mark Stemm 2021-12-08 12:32:34 -08:00
  • 473b94b386 fix(build): use consistent 7-character build abbrev sha Luca Guerra 2021-12-23 11:06:55 +00:00
  • 226d1fb728 update(OWNERS): add jasondellaluce Jason Dellaluce 2021-12-10 16:15:05 +00:00
  • 6319be8146 update(rules): Add containerd socket to sensitive_mount macro Lorenzo Susini 2021-12-06 08:45:22 +00:00
  • cf4672675c add Phoenix to adopters list Akos Kaldy 2021-11-23 18:00:59 +01:00
  • f035829ca2 fix(rules): typo in Create Symlink Over Sensitive Files rule output Angelo Puglisi 2021-12-13 13:43:35 +01:00
  • cd471a78db re-add double empty newline Calvin Bui 2021-12-10 12:12:40 +11:00
  • 65969c30f9 Add ECR repository to rules Calvin Bui 2021-12-10 12:05:15 +11:00
  • bb8b75a2cd update(userspace/falco): enforce check that content-type actually starts with "application/json" string. Federico Di Pierro 2021-11-23 09:58:34 +01:00
  • b359f71511 fix(userspace/falco): accept 'Content-Type' header that contains "application/json", but it is not strictly equal to it. Federico Di Pierro 2021-11-19 17:19:45 +01:00
  • 9dcd8bccac fix(userspace/falco): in case output_file cannot be opened, throw a falco exception. Federico Di Pierro 2021-11-08 11:01:47 +01:00
  • b5667cab99 chore(test): remove unused files in test directory Jason Dellaluce 2021-11-22 08:49:20 +00:00
  • 2a00a4d853 rules: adding support to openat2 Jason Dellaluce 2021-11-18 14:28:21 +00:00
  • 697d4427a7 chore(scripts): refine removal output messages Jason Dellaluce 2021-12-03 11:26:51 +00:00
  • bf04fed71c fix(scripts): correctly remove loaded drivers Jason Dellaluce 2021-11-18 14:16:35 +00:00
  • c005af22cc fix: set config value and create node if not existing Jason Dellaluce 2021-11-18 14:01:55 +00:00
  • c93029ce74 fix(build): use correct libyaml variable in tests cmake Jason Dellaluce 2021-11-17 17:05:48 +00:00
  • 076aabcea6 test(falco): adding unit tests for yaml_configuration Jason Dellaluce 2021-11-17 14:52:12 +00:00
  • d8c588becf update: add yaml-cpp to unit tests Jason Dellaluce 2021-11-17 14:51:38 +00:00
  • 1a7611a761 chore(engine): using is_defined config method instead of private get_node Jason Dellaluce 2021-11-17 14:01:24 +00:00
  • 7fb61ba4a3 refactor(engine): access config fields with new key syntax Jason Dellaluce 2021-11-17 14:00:31 +00:00
  • 9ab810f431 update(engine): support accessing nested config fields Jason Dellaluce 2021-11-17 13:56:49 +00:00
  • 7781385769 refactor(engine): support string config loading and add ad-hoc methods Jason Dellaluce 2021-11-17 13:53:52 +00:00
  • 205a8fd23b Move wget and curl to own rule Erick Cheng 2021-11-10 09:44:56 +01:00
  • bdba37a790 Fix remove scp and add curl Erick Cheng 2021-11-02 16:34:42 +01:00
  • 19fb3458ef Add wget and curl to remote_file_copy_binaries Erick Cheng 2021-11-02 16:21:32 +01:00
  • b0565794f5 Move user_known_ingress_remote_file_copy_activities to outside condition Erick Cheng 2021-11-19 09:55:48 +01:00
  • 66df790b9d Fix syntax error Erick Cheng 2021-11-18 16:47:08 +01:00
  • 749d4b4512 Add more curl download checks Erick Cheng 2021-11-16 10:27:21 +01:00
  • 851033c5f4 Add curl macro Erick Cheng 2021-11-16 10:09:16 +01:00
  • af6f3bfeab Move wget and curl to own rule Erick Cheng 2021-11-10 09:44:56 +01:00
  • c4d25b1d24 Fix remove scp and add curl Erick Cheng 2021-11-02 16:34:42 +01:00
  • d434853d5f Add wget and curl to remote_file_copy_binaries Erick Cheng 2021-11-02 16:21:32 +01:00
  • 4c8e369691 update(build): bump fakeit version Jason Dellaluce 2021-11-18 15:08:19 +00:00
  • b15a0458b7 update(build): allow using local libs source dir Jason Dellaluce 2021-11-18 10:54:11 +00:00
  • d6cb8bc4bd refactor(build): setting variable defaults according to newest libs version Jason Dellaluce 2021-11-18 10:48:49 +00:00
  • 2cc7fd9072 update(build): bump libs version Jason Dellaluce 2021-11-18 10:47:57 +00:00
  • 589829ae2f update(build): remove libscap patch Jason Dellaluce 2021-11-16 17:43:19 +00:00
  • 85db078dc4 chore: renaming comment references Jason Dellaluce 2021-11-16 17:41:17 +00:00
  • 23706da75e Allow append of new exceptions to rules sai-arigeli 2021-11-10 10:06:44 -08:00
  • 35302f6f09 update(build): update libs to falcosecurity/libs master. Federico Di Pierro 2021-11-17 13:52:34 +01:00
  • 375a6f66c5 update(build): force using libs-bundled luajit. Federico Di Pierro 2021-11-17 10:07:56 +01:00
  • e8a243d6ea wip: point to my own library for CI purposes. Federico Di Pierro 2021-11-16 14:58:23 +01:00
  • 7927f45d9f update(build): dropped Falco local luajit module, use the one provided by libs (upgraded) instead. Federico Di Pierro 2021-11-16 14:47:04 +01:00
  • d9aff8d564 update(build): switched back to falcosecurity libs on master. Federico Di Pierro 2021-11-17 09:39:39 +01:00
  • 40e3fdd09c update(build): updated libs. Federico Di Pierro 2021-11-12 17:17:07 +01:00
  • ba2323046a fix(build): properly use correct lib/lib64 folder for CIVETWEB_LIB variables. Federico Di Pierro 2021-11-12 16:40:43 +01:00
  • 5e6f30109e update(build): dropped civetweb patch. Use different ExternalProject_Add when building with bundled openssl or not, to avoid depending on an unexhistent target. Federico Di Pierro 2021-11-12 14:26:06 +01:00
  • f3c3de7e05 fix(build): properly share OPENSSL_INCLUDE_DIR and OPENSSL_LIBRARIES vars to civetweb cmake. Federico Di Pierro 2021-11-12 13:30:46 +01:00
  • ca61f87682 update(build): civetweb depends on openssl. Federico Di Pierro 2021-11-12 11:52:37 +01:00
  • 113bb5cdd6 update(build): update falcosecurity libs to use my own libs repo and version to be able to test the build against FedeDP:fix_ssl_1_1_get_all_data branch (not yet merged). Federico Di Pierro 2021-11-11 17:13:57 +01:00
  • 8a603c3c5d update(build): latest libs correctly set OPENSSL_LIBRARIES for us. Federico Di Pierro 2021-11-11 16:31:55 +01:00
  • 0539e948c8 update(build): moved civetweb to its own cmake module. Moved its patch too. Federico Di Pierro 2021-11-11 15:27:04 +01:00
  • 5f1d04ec82 fix(build): build civetweb using cmake and linking to static openssl built by us. Federico Di Pierro 2021-11-11 15:16:46 +01:00
  • 9d8fc4c8d2 update(build): updated civetweb to version 1.15 to correctly support openssl1.1. Federico Di Pierro 2021-11-11 11:07:45 +01:00
  • 09799e125d chore(build): update libs version to 7906f7ec416a8b67b82d92d37b25f28d545bcb8f Luca Guerra 2021-11-16 16:28:34 +00:00
  • 446c65007d test(userspace/engine): add integration test for rules enabled with enabled flag only Jason Dellaluce 2021-11-15 18:40:37 +00:00
  • df3728ec3f test(userspace/engine): add integration test for rules disabled with enabled flag only Jason Dellaluce 2021-11-15 18:39:49 +00:00