Skip to content

chore(deps): update dependency github:mongodb/kingfisher to v2 - #46

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-mongodb-kingfisher-2.x-lockfile
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-mongodb-kingfisher-2.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
github:mongodb/kingfisher tools major 1.110.0 → v2.9.1

Release Notes

mongodb/kingfisher (github:mongodb/kingfisher)

v2.9.1

Compare Source

  • Updated PyO3 to 0.29.3 to fix Python binding memory-safety and thread-safety advisories.
  • Fixed crates.io packaging and bumped kingfisher-core to 1.0.1.
  • Enabled Python SDK publishing on merges to main, preserving every pending release.
  • Added Rust and Python homepage quick starts and clarified the open-source revocation comparison.

v2.9.0

Compare Source

  • Fixed the validation-phase message to appear when credential validation begins.
  • Reduced scan CPU use in Base64 and Unicode detection without changing scan results.
  • Library behavior change: validation timeout(Duration::ZERO) and max_response_bytes(0) now disable their respective limits instead of returning a build error.
  • Added --no-limits for unlimited scan budgets and timeouts. Behavior change: --extraction-depth 0 disables the archive depth limit; use --no-extract-archives to disable extraction. #​524
  • GitHub user/org and GitLab user/group scans now overlap discovery, cloning, and scanning; added --user-file for both providers. Behavior change: clone limits select the first unique repositories discovered per provider in API order; explicit Git URLs and added wiki URLs are not counted. #​525
  • Added --since-hours N for recent Git history scans. Behavior change: --since-commit now scans all refs by default; use --branch HEAD to retain the previous scope. --branch restricts either scan. #​526

v2.8.0

Compare Source

  • Behavior change: --since-commit now scans full commit ranges by default, catching secrets later deleted. Use --git-history none for net-diff scanning. #​518
  • Added Git author name and email alongside committer information in finding metadata. #​519
  • Improved --branch scan performance by avoiding per-commit Git index setup.
  • Branch-only remote scans now fetch just the selected branch and keep branch-specific clones separate from full-repository clones. #​514
  • Added the optional native wizard (gui) for configuring scans, tracking progress, and inspecting JSON/JSONL or SARIF reports with filters, exports, and Git provenance.
  • Added independent report tabs and native Kingfisher desktop icons for macOS, Linux, and Windows.
  • Improved wizard readability with comma-separated counts, compact column controls, clickable commit links, and a Local Web Viewer action that preserves imported reports.
  • Library behavior changes: ScannerConfig::enable_dedup now defaults to false (previously true). Opt-in deduplication keys on both blob ID and source path, preserving identical content at different paths. Betterleaks filter evaluation errors now fail the scan call instead of silently keeping the finding.
  • Stabilized the 1.0.0 embedding APIs for kingfisher-core, kingfisher-rules, and kingfisher-scanner, with runnable examples and version-aware crates.io publishing for all crates, including kingfisher-bin.
  • Switched to the published kingfisher-vectorscan crate and its checksum-verified prebuilt archives, removing the local Vectorscan CMake build on supported targets. Windows builds use GNU/LLVM MinGW; MSVC is unsupported.
  • Replaced the temporary MongoDB driver Git pin with crates.io 3.8.0, retaining SRV validation and the Hickory 0.26 DNS fix.
  • Fixed scan-time validation requests to send a User-Agent, preventing services such as GitHub from rejecting them. Thanks @​wingc-canva. #​512

v2.7.0

Compare Source

  • Added opt-in bounded verification for ambiguous credential components, with ranked candidates for AWS, BrowserStack, ClickHouse Cloud, MongoDB Atlas, PlanetScale, Razorpay, and Wiz.
  • Kept unresolved pairings inconclusive: searches try at most 16 combinations within 30 seconds, and only authoritative validation success selects a pair. Candidate verification requires supported fixed destinations, disables HTTP redirects, and keeps unselected secrets out of reports.

v2.6.0

Compare Source

  • Added opt-in GitHub gist scanning #​508, plus GitLab and Bitbucket Cloud snippet scanning, with full Git history.
  • Reduced peak scan memory: findings now deduplicate on exact cryptographic digests alone (the Bloom prefilter and its dependency were removed), the Git object index stores each object ID once, and raw matcher bookkeeping was slimmed.
  • Added opt-in --disk-offload to reduce accumulated finding memory across repositories; it falls back to memory with a warning when temporary storage fills up.
  • Fixed HTML report validation filters to match displayed states, including assumed-valid, invalid-material, and skipped-canary findings.

v2.5.0

Compare Source

  • Behavior change: scan --branch <ref> now scans all reachable history by default, finding secrets deleted in later commits, including merged history. Use --git-history none to retain snapshot-only scanning; explicit diff options keep their existing scope. Full-history scans may need more time and memory, and history enumeration shares the repository’s --git-repo-timeout budget. #​503

v2.4.0

Compare Source

  • Fixed scans missing secrets in UTF-16 and UTF-32 files, including little-/big-endian files with or without a BOM.
  • Hardened the HTML report viewer with safer imported-data rendering, restricted external links, and a tighter browser security policy.

v2.3.0

Compare Source

  • Improved report filtering, grouped selection, command copying, and finding details in the local viewer and standalone HTML reports.
  • Fixed probabilistic deduplication dropping unique findings by confirming duplicates with exact keys.
  • Recorded terminal scan coverage for streamed non-Git inputs, including Docker images.
  • Pinned release Docker images to the requested release version.
  • Limited the pretty report's REPOSITORY COVERAGE section to scans that request --audit-log.
  • Fixed --no-dedup scans to reuse validation results across duplicate findings and parallel scan phases.
  • Fixed dependent-secret validation stalls and duplicate provider requests caused by concurrent waiters.
  • Added overlay-derived bare detection for contextual Betterleaks API-key rules (DeepSeek, Kimi, ZAI, and Voyage AI).
  • Fixed CredentialUri TLS-mode handling, dependency-aware deduplication, and ambiguous dependency pairing so validation does not guess an endpoint. #​500
  • Reused dependent validation when credential and dependency values match across source locations.
  • Made direct validation reject ambiguous short rule selectors instead of trying an unintended rule. #​500

v2.2.0

Compare Source

  • Added repository coverage manifests and incremental --audit-log JSONL events, including
    discovery, fetch, scan outcome, Git scope, and per-repository scan statistics.
  • Added read-only Google API-key blast-radius probes for Identity Toolkit, Generative Language,
    Translation, and YouTube services.
  • Updated Cargo dependencies, including AWS SDK, Git, TLS, and runtime libraries.
  • Explicitly enabled HTTP/2 for outbound validation requests to improve connection reuse and multiplexing.
  • Refreshed the pinned Betterleaks catalog to commit
    95237cf,
    adding the Voyage AI API-key detector. Built-in coverage is now 485 rules (459 Betterleaks and
    26 Veles), with 246 rules supporting validation. The OSV-SCALIBR Veles audit found no new secret
    detectors since the existing pinned revision.

v2.1.0

Compare Source

  • Added GitHub App authentication for GitHub organization scans. Configure
    KF_GITHUB_APP_ID, KF_GITHUB_APP_INSTALLATION_ID, and either
    KF_GITHUB_APP_PRIVATE_KEY or KF_GITHUB_APP_PRIVATE_KEY_PATH to let Kingfisher
    sign short-lived App JWTs and mint a fresh installation token immediately before
    each repository clone, allowing scans to run beyond GitHub's one-hour installation-token
    lifetime. A complete App configuration takes precedence over KF_GITHUB_TOKEN, which
    continues to support personal access tokens and pre-minted installation tokens. #​488
  • Further improved read-only AWS and GCP blast-radius role-impact analysis, included by default. AWS maps
    direct and one-hop assumable IAM roles; GCP maps impersonatable service accounts, inherited
    roles, and hierarchy scopes. Reachable roles and their policy grants are preserved in JSON,
    TOON, SARIF, and HTML reports/viewers.
  • Added direct single-finding blast-radius mapping with kingfisher blast-radius --rule <RULE> <SECRET>, including stdin and component variables. Exposed Blast Radius Cmd in all report formats, aligned pretty output labels, and documented JSON/jq command extraction in the defender workflow.
  • Added HTTPS Basic Auth validation for Betterleaks' generic-credential-uri rule. Kingfisher
    sends credentials only after an unauthenticated request receives an explicit Basic challenge;
    plaintext HTTP and endpoints without authoritative authentication evidence remain inconclusive.

v2.0.0

Compare Source

  • Added Kingfisher-side typed validation for Betterleaks' generic-credential-uri rule without
    changing its detector: PostgreSQL, MySQL/MariaDB, and MongoDB URI captures now use the
    corresponding live validator and feed validated credentials into blast-radius mapping, while
    unsupported URI schemes remain detected with validation not attempted. JDBC strings containing
    a credential-bearing PostgreSQL/MySQL URI are handled through that inner URI, and direct
    CredentialUri validation also dispatches supported jdbc: inputs.
  • Removed the Veles Paystack, PyPI, and Square OAuth application-secret adapters. PyPI upload-token and Square access-token detection remain covered by Betterleaks; Paystack and Square OAuth application-secret built-in coverage are no longer included.
  • Security: the MongoDB, MySQL, Postgres, and JDBC validators now enforce the same SSRF gate as the HTTP/gRPC/JWT validators. Previously they only rejected loopback/unspecified hosts, so a crafted connection string in scanned content could make Kingfisher open TCP connections to RFC1918, link-local (including 169.254.169.254), CGNAT, and other non-public addresses, turning the scan report into an internal-network reachability oracle. Every host in a Postgres multi-host URL and every MongoDB seed — including hosts resolved via mongodb+srv:// SRV records — is now checked, and blocked targets report a constant message instead of the driver's connection error. Use --allow-internal-ips to opt back in.
  • Breaking (library): validate_mongodb, validate_mysql, validate_postgres, and validate_jdbc take an additional allow_internal_ips: bool argument.
  • Restored per-rule tls_mode for built-in rules. The imported-rule capability overlay now accepts tls_mode: strict | lax | off, and betterleaks.mongodb-connection-string and betterleaks.jwt declare lax so self-managed clusters and self-hosted IdPs presenting private-CA or self-signed certificates validate again. This remains opt-in on both sides: it takes effect only when the operator also runs --tls-mode lax (or --tls-mode off). The build rejects an unknown tls_mode value, or a tls_mode on a rule with no validator.
  • Kingfisher 1.x rule selectors keep working. --rule, --exclude-rule, and rules.disabled entries naming kingfisher.* IDs now resolve to their 2.x replacements through a new alias table, with a one-time deprecation warning naming the selector to migrate to, instead of failing the scan. Exact kingfisher.* IDs still win when the 1.x catalog is loaded via --rules-path, and an unknown kingfisher.* selector is still an error.
  • Added a rule-coverage drift guard. crates/kingfisher-rules/data/legacy-rule-aliases.yml maps
    migrated Kingfisher 1.x families with known 2.x replacements, and a test asserts each alias target
    still resolves against the built-in catalog, so an upstream release that drops a replacement fails
    the build instead of silently breaking that compatibility path.
  • Restored scan-time access mapping for validated Veles rules (Slack app-level/config tokens, DigitalOcean, SendGrid), which previously reached the rule-ID dispatch and matched nothing.
  • Breaking: moved the candidate detector catalog to the Betterleaks rule format, with selected
    Veles detectors filling gaps, giving the community a well-designed shared format and a common
    place to develop generally useful rules.
  • Kingfisher now fetches and parses the Betterleaks catalog and selected Veles source files at build
    time; the Kingfisher rule format (YAML) remains supported for custom rules.
  • Preserved Kingfisher's engine capabilities around validation, blast-radius mapping, and credential revocation while allowing us to focus investment on scan performance, integrations, and analysis workflows.
  • All rules now use Vectorscan candidate detection, eliminating unconditional whole-blob regex fallbacks for Betterleaks' large generic credential patterns; Betterleaks path and finding-filter regex helpers are also compiled once with Vectorscan instead of being rebuilt per path or finding.

v1.113.0

Compare Source

  • Added repository-aware v2 baselines with safe multi-repository updates, atomic writes, and automatic migration while retaining legacy baseline compatibility.
  • Added configurable webhook finding filters, empty-alert suppression, dry-run previews, and access-map impact summaries.
  • Breaking: the alert payload field summary.filtered_total was removed; read summary.total (now always the per-sink filtered count) and the new summary.unfiltered_total for the whole-scan count.
  • Breaking (library): FindingsStore::access_map_results/set_access_map_results and AccessMapCollector::into_requests are no longer public.
  • Added Qwen, Solana, and Starknet detection rules, plus Databricks OAuth client-secret and Kubernetes ServiceAccount token rules.
  • Tightened MongoDB Atlas API key detection and stopped the Databricks workspace-host rule from matching azurewebsites.net.
  • Fixed Google API-key attribution and validation, including YouTube handling and documented Gemini header authentication; added Google Chat webhook detection and authoritative rule provenance.
  • Removed the duplicate Google OAuth rule and clarified Firebase FCM legacy server-key detection and documentation.
  • Refreshed built-in rule and revocation coverage documentation.

v1.112.0

Compare Source

  • Added offline Ethereum key/BIP-39 detection with explicit local-validation outcomes, inspired by #​468 from @​audityourcontracts.
  • Hardened validation caching and panic handling to avoid secret exposure.
  • Fixed remote Git URL scans hanging with --jobs 1. #​469

v1.111.0

Compare Source

  • Reduced Git scan metadata memory usage by interning repeated committer names and email addresses.
  • Reduced peak memory during large scans by bounding Git delta caches per worker and streaming matcher chunks; --jobs now controls the scanner worker pool.
  • Added first-class validation outcomes and --validation-filter actionable, allowing active credentials and high-confidence assumed-valid secrets such as private keys to remain visible together without labeling assumed findings active. --only-valid remains strict active filtering. Thanks @​wing-cheng. #​440
  • Expanded GCP coverage with validated generic and Express Mode API keys, GCS HMAC key pairs, and Application Default Credentials, drawing on Veles and Betterleaks.
  • Hardened GCP validation with Google-only OAuth endpoints, read-only multi-API key probes, and concise responses that avoid exposing minted access tokens or bucket metadata.
  • Fixed alert webhooks reporting a temporary stdin file instead of an explicitly requested non-path scan target in non-interactive runs. #​452
  • Fixed kingfisher scan - <path> discarding the sibling paths when staging stdin; stdin now replaces only the - placeholder.
  • Fixed direct validation for Atlassian API keys using the documented Organizations API. #​461
  • Fixed self-hosted Bitbucket scans to recognize http-labeled HTTPS clone links instead of falling back to SSH. #​462
  • Added Jira Cloud and Confluence Cloud scanning improvements, including complete pagination, full issue descriptions, and --all support. Thanks @​Safenein. #​460
  • Renamed "Access Map" to "Blast Radius" throughout the CLI, HTML and pretty reporters, the standalone and report viewers, and documentation; --blast-radius is now the primary flag, while the --access-map alias and access_map JSON field names remain unchanged for backwards compatibility.

Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

🛡️ Plumber — CI/CD Security Compliance

✅ No Critical-severity findings

No findings on this branch.

View this run

@renovate
renovate Bot force-pushed the renovate/github-mongodb-kingfisher-2.x-lockfile branch 3 times, most recently from 3bdac7e to 1aaeeda Compare September 29, 2026 20:04
@renovate
renovate Bot force-pushed the renovate/github-mongodb-kingfisher-2.x-lockfile branch from 1aaeeda to e632cae Compare October 2, 2026 01:24
@renovate
renovate Bot force-pushed the renovate/github-mongodb-kingfisher-2.x-lockfile branch from e632cae to 743e362 Compare October 2, 2026 04:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants