chore(deps): update dependency github:mongodb/kingfisher to v2 - #46
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
🛡️ Plumber — CI/CD Security Compliance✅ No Critical-severity findingsNo findings on this branch. |
renovate
Bot
force-pushed
the
renovate/github-mongodb-kingfisher-2.x-lockfile
branch
3 times, most recently
from
September 29, 2026 20:04
3bdac7e to
1aaeeda
Compare
renovate
Bot
force-pushed
the
renovate/github-mongodb-kingfisher-2.x-lockfile
branch
from
October 2, 2026 01:24
1aaeeda to
e632cae
Compare
renovate
Bot
force-pushed
the
renovate/github-mongodb-kingfisher-2.x-lockfile
branch
from
October 2, 2026 04:46
e632cae to
743e362
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.110.0→v2.9.1Release Notes
mongodb/kingfisher (github:mongodb/kingfisher)
v2.9.1Compare Source
kingfisher-coreto 1.0.1.main, preserving every pending release.v2.9.0Compare Source
timeout(Duration::ZERO)andmax_response_bytes(0)now disable their respective limits instead of returning a build error.--no-limitsfor unlimited scan budgets and timeouts. Behavior change:--extraction-depth 0disables the archive depth limit; use--no-extract-archivesto disable extraction. #524--user-filefor both providers. Behavior change: clone limits select the first unique repositories discovered per provider in API order; explicit Git URLs and added wiki URLs are not counted. #525--since-hours Nfor recent Git history scans. Behavior change:--since-commitnow scans all refs by default; use--branch HEADto retain the previous scope.--branchrestricts either scan. #526v2.8.0Compare Source
--since-commitnow scans full commit ranges by default, catching secrets later deleted. Use--git-history nonefor net-diff scanning. #518--branchscan performance by avoiding per-commit Git index setup.wizard(gui) for configuring scans, tracking progress, and inspecting JSON/JSONL or SARIF reports with filters, exports, and Git provenance.ScannerConfig::enable_dedupnow defaults tofalse(previouslytrue). Opt-in deduplication keys on both blob ID and source path, preserving identical content at different paths. Betterleaks filter evaluation errors now fail the scan call instead of silently keeping the finding.kingfisher-core,kingfisher-rules, andkingfisher-scanner, with runnable examples and version-aware crates.io publishing for all crates, includingkingfisher-bin.kingfisher-vectorscancrate and its checksum-verified prebuilt archives, removing the local Vectorscan CMake build on supported targets. Windows builds use GNU/LLVM MinGW; MSVC is unsupported.v2.7.0Compare Source
v2.6.0Compare Source
--disk-offloadto reduce accumulated finding memory across repositories; it falls back to memory with a warning when temporary storage fills up.v2.5.0Compare Source
scan --branch <ref>now scans all reachable history by default, finding secrets deleted in later commits, including merged history. Use--git-history noneto retain snapshot-only scanning; explicit diff options keep their existing scope. Full-history scans may need more time and memory, and history enumeration shares the repository’s--git-repo-timeoutbudget. #503v2.4.0Compare Source
v2.3.0Compare Source
REPOSITORY COVERAGEsection to scans that request--audit-log.--no-dedupscans to reuse validation results across duplicate findings and parallel scan phases.v2.2.0Compare Source
--audit-logJSONL events, includingdiscovery, fetch, scan outcome, Git scope, and per-repository scan statistics.
Translation, and YouTube services.
95237cf,adding the Voyage AI API-key detector. Built-in coverage is now 485 rules (459 Betterleaks and
26 Veles), with 246 rules supporting validation. The OSV-SCALIBR Veles audit found no new secret
detectors since the existing pinned revision.
v2.1.0Compare Source
KF_GITHUB_APP_ID,KF_GITHUB_APP_INSTALLATION_ID, and eitherKF_GITHUB_APP_PRIVATE_KEYorKF_GITHUB_APP_PRIVATE_KEY_PATHto let Kingfishersign short-lived App JWTs and mint a fresh installation token immediately before
each repository clone, allowing scans to run beyond GitHub's one-hour installation-token
lifetime. A complete App configuration takes precedence over
KF_GITHUB_TOKEN, whichcontinues to support personal access tokens and pre-minted installation tokens. #488
direct and one-hop assumable IAM roles; GCP maps impersonatable service accounts, inherited
roles, and hierarchy scopes. Reachable roles and their policy grants are preserved in JSON,
TOON, SARIF, and HTML reports/viewers.
kingfisher blast-radius --rule <RULE> <SECRET>, including stdin and component variables. ExposedBlast Radius Cmdin all report formats, aligned pretty output labels, and documented JSON/jqcommand extraction in the defender workflow.generic-credential-urirule. Kingfishersends credentials only after an unauthenticated request receives an explicit Basic challenge;
plaintext HTTP and endpoints without authoritative authentication evidence remain inconclusive.
v2.0.0Compare Source
generic-credential-urirule withoutchanging its detector: PostgreSQL, MySQL/MariaDB, and MongoDB URI captures now use the
corresponding live validator and feed validated credentials into blast-radius mapping, while
unsupported URI schemes remain detected with validation not attempted. JDBC strings containing
a credential-bearing PostgreSQL/MySQL URI are handled through that inner URI, and direct
CredentialUrivalidation also dispatches supportedjdbc:inputs.169.254.169.254), CGNAT, and other non-public addresses, turning the scan report into an internal-network reachability oracle. Every host in a Postgres multi-host URL and every MongoDB seed — including hosts resolved viamongodb+srv://SRV records — is now checked, and blocked targets report a constant message instead of the driver's connection error. Use--allow-internal-ipsto opt back in.validate_mongodb,validate_mysql,validate_postgres, andvalidate_jdbctake an additionalallow_internal_ips: boolargument.tls_modefor built-in rules. The imported-rule capability overlay now acceptstls_mode: strict | lax | off, andbetterleaks.mongodb-connection-stringandbetterleaks.jwtdeclarelaxso self-managed clusters and self-hosted IdPs presenting private-CA or self-signed certificates validate again. This remains opt-in on both sides: it takes effect only when the operator also runs--tls-mode lax(or--tls-mode off). The build rejects an unknowntls_modevalue, or atls_modeon a rule with no validator.--rule,--exclude-rule, andrules.disabledentries namingkingfisher.*IDs now resolve to their 2.x replacements through a new alias table, with a one-time deprecation warning naming the selector to migrate to, instead of failing the scan. Exactkingfisher.*IDs still win when the 1.x catalog is loaded via--rules-path, and an unknownkingfisher.*selector is still an error.crates/kingfisher-rules/data/legacy-rule-aliases.ymlmapsmigrated Kingfisher 1.x families with known 2.x replacements, and a test asserts each alias target
still resolves against the built-in catalog, so an upstream release that drops a replacement fails
the build instead of silently breaking that compatibility path.
Veles detectors filling gaps, giving the community a well-designed shared format and a common
place to develop generally useful rules.
time; the Kingfisher rule format (YAML) remains supported for custom rules.
v1.113.0Compare Source
summary.filtered_totalwas removed; readsummary.total(now always the per-sink filtered count) and the newsummary.unfiltered_totalfor the whole-scan count.FindingsStore::access_map_results/set_access_map_resultsandAccessMapCollector::into_requestsare no longer public.azurewebsites.net.v1.112.0Compare Source
--jobs 1. #469v1.111.0Compare Source
--jobsnow controls the scanner worker pool.--validation-filter actionable, allowing active credentials and high-confidence assumed-valid secrets such as private keys to remain visible together without labeling assumed findings active.--only-validremains strict active filtering. Thanks @wing-cheng. #440kingfisher scan - <path>discarding the sibling paths when staging stdin; stdin now replaces only the-placeholder.http-labeled HTTPS clone links instead of falling back to SSH. #462--allsupport. Thanks @Safenein. #460--blast-radiusis now the primary flag, while the--access-mapalias andaccess_mapJSON field names remain unchanged for backwards compatibility.Configuration
📅 Schedule: (in timezone UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.