Commit Graph

  • e3f1ac1be3 Don't look for event counts with -V/validate Mark Stemm 2020-10-02 16:52:44 -07:00
  • fb4e07e220 Automated tests for exceptions Mark Stemm 2020-10-02 16:51:43 -07:00
  • 9014153d7b Support exceptions properties on rules Mark Stemm 2020-09-17 18:21:00 -07:00
  • 8b56360f8c rule(list falco_sensitive_mount_images): add images docker.io/falcosecurity/falco and falcosecurity/falco Christian Zunker 2020-10-05 08:57:08 +02:00
  • 0bb6addcc0 Update tests to add error counts Mark Stemm 2020-10-02 16:54:55 -07:00
  • 3aa8ff6e84 Allow unknown top level obs as warnings Mark Stemm 2020-09-17 16:18:31 -07:00
  • a4b7d46717 Pass back warnings when loading rules Mark Stemm 2020-09-17 16:02:42 -07:00
  • bc570c58df More rule error/warnings handling cleanups add-exceptions-support-copy Mark Stemm 2020-10-02 16:56:22 -07:00
  • 68018d3a69 More exceptions handling cleanups. Mark Stemm 2020-10-02 16:56:03 -07:00
  • defde05c90 Update tests to add error counts Mark Stemm 2020-10-02 16:54:55 -07:00
  • 21ed93aa53 Don't look for event counts with -V/validate Mark Stemm 2020-10-02 16:52:44 -07:00
  • 2eb286fd02 Automated tests for exceptions Mark Stemm 2020-10-02 16:51:43 -07:00
  • ab5a39c994 Cleanups Mark Stemm 2020-10-02 10:37:18 -07:00
  • c4cc1d7996 Restructure exceptions Mark Stemm 2020-10-01 17:05:27 -07:00
  • 0a449afc3e docs: fix release notes for 0.26.0 (previous) 0.26.1 Leonardo Di Donato 2020-10-01 10:47:04 +00:00
  • e06e89b3d0 docs: CHANGELOG for 0.26.1 Leonardo Di Donato 2020-10-01 10:43:29 +00:00
  • 1500e74844 docs: release candency Leo Di Donato 2020-10-01 12:41:59 +02:00
  • db9fe762a4 docs: notify the community the Falco releases happen every two months starting from today Leonardo Di Donato 2020-10-01 10:24:19 +00:00
  • 2fd9ad1433 docs: add download/images table to release corpus template Leo Di Donato 2020-10-01 12:14:02 +02:00
  • 879bf37ffd rule(Write below root): require proc.name Mark Stemm 2020-09-30 15:05:43 -07:00
  • fc4355dd15 rule(Delete....shell history): Skip docker progs Mark Stemm 2020-09-30 12:54:18 -07:00
  • 1c7fca95e4 rule(Delete or rename shell history):fix warning Mark Stemm 2020-09-30 12:46:00 -07:00
  • bc1aeaceb2 feat(falco): Provide a parameter for loading lua files from an alternate path Radu Andries 2020-09-29 13:37:30 +02:00
  • 6bcc11aa47 build: standalone static analysis step Lorenzo Fontana 2020-09-28 15:42:27 +02:00
  • bbf044060a build: quality, install ca-certificates and attach only after that Lorenzo Fontana 2020-09-23 17:45:13 +02:00
  • 4f86e3e68b build: static code analysis CI reports Lorenzo Fontana 2020-09-23 15:33:33 +02:00
  • a51c4fc903 build: static code analysis structure and cppcheck Lorenzo Fontana 2020-09-23 15:32:40 +02:00
  • 271e23ce97 docs(brand): documenting Falco color scheme Leo Di Donato 2020-09-24 19:32:34 +02:00
  • 404762bd34 feat(release): Updating notes according to PR 0.26.0 Kris Nóva 2020-09-25 07:28:57 -07:00
  • 20f5e5d35a feat(release): Release 0.26 Kris Nóva 2020-09-24 11:22:03 -07:00
  • b9671f936d Ensure that exception fields are valid Mark Stemm 2020-09-23 09:23:46 -07:00
  • 33793d233b Rule(Disallowed K8s User): quote colons Mark Stemm 2020-09-10 10:47:22 -07:00
  • 331b2971be rule(Delete or rename shell history):skip dockerfs Mark Stemm 2020-09-10 09:27:56 -07:00
  • 558b18ea67 build: update the driver version to 2aa88dc Leonardo Grasso 2020-09-18 13:20:46 +02:00
  • bbfb27777b build: remove macrodefs about time (musl build) Leonardo Grasso 2020-09-14 15:21:27 +02:00
  • 3bedcc42d8 build: update the driver version to 2aa88dc chore/remove-time-macrodefs Leonardo Grasso 2020-09-18 13:20:46 +02:00
  • 30f29d8905 build: remove macrodefs about time (musl build) Leonardo Grasso 2020-09-14 15:21:27 +02:00
  • 5b926386a8 rule(macro consider_packet_socket_communication): change a value to always_true Hiroki Suezawa 2020-09-15 17:36:12 +09:00
  • 0ffd1e9c5c WIP: most of exceptions parsing support Mark Stemm 2020-09-17 18:21:00 -07:00
  • 81cdab21be Allow unknown top level obs as warnings Mark Stemm 2020-09-17 16:18:31 -07:00
  • 60052bffcb Pass back warnings when loading rules Mark Stemm 2020-09-17 16:02:42 -07:00
  • a766dff9ec docs: add sections about drivers into RELEASE.md file update/release-drivers Leo Di Donato 2020-09-16 19:46:01 +02:00
  • 1efa4d3af0 update(scripts): driver loader cycle available gcc versions Lorenzo Fontana 2020-09-16 16:14:24 +02:00
  • 8611af4373 chore(.circleci): re-enable cleanup of falco development packages only when on the master branch Leonardo Di Donato 2020-09-11 18:17:33 +00:00
  • b6fd43f4db update(.circleci): update CI references to cleanup script Leonardo Di Donato 2020-09-11 12:54:52 +00:00
  • 2971d0de7f fix(scripts): move cleanup (falco development packages) into scripts dir Leonardo Di Donato 2020-09-11 12:54:33 +00:00
  • d2dbe64723 update: bump Falco engine version to 7 Leonardo Grasso 2020-09-07 16:27:04 +02:00
  • 66309e3a1f build(.circleci): fix static build path Leonardo Grasso 2020-09-11 11:39:47 +02:00
  • cb2439d757 Append Slash to Sensitive Mount Path startswith bgeesaman 2020-09-10 15:45:55 -04:00
  • 532188e3a8 rule(Delete or rename shell history):skip dockerfs rules-bash-history-top-only Mark Stemm 2020-09-10 09:27:56 -07:00
  • f02a998526 build: update the driver version to 73554b9 Leonardo Di Donato 2020-09-10 10:36:30 +00:00
  • d1ee7d3d79 chore(.circleci): re-enable the usual falco-tester docker image for CI Leonardo Di Donato 2020-09-10 10:02:28 +00:00
  • 0586a7d33c update(docker/no-driver): use the statically linked falco tarball Leonardo Di Donato 2020-09-10 09:58:42 +00:00
  • e0f0db96d3 build(rules): fix rules etc dir Leonardo Di Donato 2020-09-10 09:57:52 +00:00
  • 045cb4a45d build(.circleci): specify falco etc directory for musl build Leonardo Di Donato 2020-09-10 09:36:31 +00:00
  • 4319f16fa6 build: publish musl artifacts Leonardo Di Donato 2020-09-09 14:52:19 +00:00
  • c2603c0130 new(.circleci): test the minimal build Leonardo Di Donato 2020-09-09 13:46:08 +00:00
  • 5316e39379 chore(cmake/modules): correct logging for string-view-lite (always) bundled header dependency Leonardo Di Donato 2020-09-09 13:43:28 +00:00
  • 9a29203a4d build: engine fields checksum only when not building the minimal Falco Leonardo Di Donato 2020-09-09 11:09:55 +00:00
  • 7e28e305a6 deps: update driver version Leonardo Di Donato 2020-09-09 11:09:13 +00:00
  • ec2ccf4d1c build: fix cares include Leonardo Grasso 2020-09-09 12:11:51 +02:00
  • d2ecc52253 build(.circleci): fix build/musl when releasing Leonardo Grasso 2020-09-09 11:06:33 +02:00
  • be7ba9fea4 build: fix cares include path Leonardo Grasso 2020-09-09 10:49:15 +02:00
  • 2141580a10 update(userspace/engine): bump driver version to 9c7755ae7aaa221a3d17c1d98911c4c2cbdbd21317559d744e53bf63a2677a4b Leonardo Grasso 2020-09-09 10:20:15 +02:00
  • 1e64f0a5c9 build(.circleci): publish static tgz on release Leonardo Grasso 2020-09-07 14:08:30 +02:00
  • 7e9ca5c540 build: run_regression_tests.sh skip packages tests if asked Lorenzo Fontana 2020-09-03 11:43:28 +02:00
  • 98a5813bd7 build: allow the tester command to retrieve the source and build env variables Lorenzo Fontana 2020-09-02 15:44:47 +02:00
  • 492fe0c372 build: circleci musl build Lorenzo Fontana 2020-09-02 15:06:54 +02:00
  • 00d930199f build: strip userspace/falco/falco in release when building with musl optimizations Lorenzo Fontana 2020-09-02 14:29:14 +02:00
  • f2bc92ac58 build: allow configurable cpack targets Lorenzo Fontana 2020-09-02 14:28:37 +02:00
  • d5f752de7a build: add MUSL_OPTIMIZED_BUILD option Leonardo Grasso 2020-09-01 18:13:20 +02:00
  • 109efc2799 chore(cmake/modules): refine sysdig cmake for minimal build Leonardo Grasso 2020-08-26 12:08:44 +02:00
  • c46dbc7f11 build: remove gRPC, openssl, curl from minimal build Leonardo Grasso 2020-08-26 11:10:44 +02:00
  • b7e75095e6 build(userspace): avoid openssl dep for engine fields verification Leonardo Grasso 2020-08-24 16:11:21 +02:00
  • 68f937f5e8 build: disallow k8s audit trace file when minimal build Leonardo Grasso 2020-08-24 14:32:08 +02:00
  • 0c1ed551ca build: remove civetweb when minimal build Leonardo Grasso 2020-08-24 14:19:35 +02:00
  • bdd14604d4 build: remove webserver from minimal build Leonardo Grasso 2020-08-24 12:14:29 +02:00
  • 9d88bfd0d4 build: add MINIMAL_BUILD option Leonardo Grasso 2020-08-24 12:13:49 +02:00
  • 361fec452e chore(.circleci): typos Leo Di Donato 2020-09-07 10:38:48 +02:00
  • cd449cb89b update(.circleci): cleanup/packages-dev job Leonardo Di Donato 2020-09-02 18:46:17 +02:00
  • 2880bb1f23 build(.circleci): script for automatic cleanup of Falco development releases Leonardo Di Donato 2020-09-02 18:39:24 +02:00
  • d25e07381e update(proposals): clarify that prebuilding drivers is on a best-effort basis Leo Di Donato 2020-09-07 10:44:36 +02:00
  • 481eedb80e update(proposals): artifacts cleanup (prebuilt drivers part) Leonardo Di Donato 2020-09-02 01:14:05 +02:00
  • f077f2887f new(proposals): artifacts cleanup (packages part) Leonardo Di Donato 2020-09-01 15:57:46 +02:00
  • d80ffeae5b update(proposals): artifacts storage proposal Leonardo Di Donato 2020-09-01 11:42:43 +02:00
  • 2d24df1ce2 new(proposals): initial document about SoA of artifacts storage Leonardo Di Donato 2020-08-18 14:24:47 +02:00
  • f32bb84851 Start versioning trace files Mark Stemm 2020-08-31 16:34:05 -07:00
  • 7666bc3f3a rule(System ClusterRole Modified/Deleted): + role Mark Stemm 2020-08-27 18:10:41 -07:00
  • 08d38d8269 Rule(Pod Created in Kube Namespace): add images Mark Stemm 2020-08-27 18:08:29 -07:00
  • 3fd4464dee rule(Disallowed K8s User): add known users Mark Stemm 2020-08-27 18:00:53 -07:00
  • 702d989cd0 rule(Create HostNetwork Pod): add images Mark Stemm 2020-08-27 17:58:15 -07:00
  • de9c8720c0 rule(Launch Privileged Container) add images Mark Stemm 2020-08-27 17:51:38 -07:00
  • 534cb8e59f rule(Launch Privileged Container): sort/reorg list Mark Stemm 2020-08-27 17:42:15 -07:00
  • 9b3adc1373 rule(Read sensitive file untrusted):google_oslogin Mark Stemm 2020-08-27 17:36:36 -07:00
  • fb5e13c694 rule(Write below root): add mysqlsh Mark Stemm 2020-08-27 17:33:42 -07:00
  • 7effc02c60 rule(Write below etc): add calco exceptions Mark Stemm 2020-08-27 17:33:05 -07:00
  • 7ae0ce1936 rule(Update Package Repository): restrict files Mark Stemm 2020-08-27 17:29:37 -07:00
  • 891965375d rule(Read sensitive file untrusted): linux-bench Mark Stemm 2020-08-27 17:09:39 -07:00
  • 7a4d790458 rule(Change thread namespace): Require proc name Mark Stemm 2020-08-27 13:32:19 -07:00
  • 5d71d70a14 added brakets to three macros to make them less ambiguous Loris Degioanni 2020-08-28 16:21:38 -07:00