93 Commits

Author SHA256 Message Date
Dominique Leuenberger
bcae309186 Accepting request 1247497 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1247497
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=19
2025-02-21 20:36:00 +00:00
842475de99 - Use the latest llvm/clang on tumbleweed
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=93
2025-02-20 20:33:57 +00:00
Ana Guerrero
b91f6c3f9e Accepting request 1241332 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1241332
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=18
2025-01-30 13:53:12 +00:00
Darragh O'Reilly
d786a0a8c0 - Use llvm17 for SLE15SP6+
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=91
2025-01-30 11:32:38 +00:00
Ana Guerrero
c7a7b38eaf Accepting request 1240816 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1240816
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=17
2025-01-28 16:19:16 +00:00
Darragh O'Reilly
79154de78f - Don't try to build or use system-user-velociraptor on SLE12
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=89
2025-01-28 12:59:25 +00:00
Dominique Leuenberger
c55c4a754a Accepting request 1238559 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1238559
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=16
2025-01-18 12:18:22 +00:00
Ana Guerrero
01f2a0eeaf Accepting request 1238528 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1238528
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=15
2025-01-17 17:44:00 +00:00
502257d078 Accepting request 1238558 from home:ateixeira:velociraptor
- Reorganize llvm dependency version conditionals
- Use llvm17 for Leap 15.5

OBS-URL: https://build.opensuse.org/request/show/1238558
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=87
2025-01-17 17:41:09 +00:00
d7095f76a9 - Drop CVE-2022-25883-npm-watch-semver-deps.patch
* Fix was included upstream

OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=86
2025-01-17 15:25:25 +00:00
356fc93fac - Update to version 0.7.0.4.git142.862ef23:
* github: fix deprecated upload artifact again
  * Update npm packages
    Includes fixes for the following vulnerabilities:
    CVE-2023-45133
    CVE-2023-46234
    CVE-2024-55565
    CVE-2024-45296
    CVE-2023-44270
    CVE-2024-47068
    CVE-2024-23331
    CVE-2024-31207
    CVE-2024-45812
    CVE-2024-45811
  * Update go dependencies
    Includes fixes for the following vulnerabilities:
    CVE-2024-45338
    CVE-2024-37298
    CVE-2024-24786
    CVE-2023-45683 (bsc#1216310)
    CVE-2023-1732
  * Update jwt to 4.5.1
    Fixes CVE-2024-51744 (bsc#1232944)
  * Update go-retryablehttp to 0.7.7
    Fixes CVE-2024-6104 (bsc#1227061)
  * Update go-oidc and go-jose
    Fixes CVE-2024-28180 (bsc#1235168)
  * Update dompurify to 3.1.3
    Fixes CVE-2024-47875 (bsc#1231574)
  * Update package-lock.json
  * Update micromatch to 4.0.8
    Partial fix for CVE-2024-4067 (bsc#1224367)
    Partial fix for CVE-2024-4068 (bsc#1224296)
  * Update axios to 1.7.9
    Fixes CVE-2024-39338 (bsc#1229424)
  * Update cross-spawn to 7.0.6
    Fixes CVE-2024-21538 (bsc#1233845)
  * Update elliptic to 6.6.1
    Update contains fixes for:
    CVE-2024-48949 (bsc#1231558)
    CVE-2024-48948 (bsc#1231685)
    CVE-2024-42459 (bsc#1232543)
    CVE-2024-42460 (bsc#1232543)
    CVE-2024-42461 (bsc#1232543)
  * Update follow-redirects to 1.15.6
    Fixes CVE-2024-28849 (bsc#1221456)
  * fix: gui/velociraptor/package.json to reduce vulnerabilities
    Fixes CVE-2022-25883 (bsc#1212572)

OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=85
2025-01-17 15:17:19 +00:00
0c486d078c - Update to version 0.7.0.4.git126.27cfbe1:
* bpf: fix plugins not stopping when context cancelled
  * tcpsnoop: move parsing to its own function
  * bpf plugins: remove depreciated libbpfgo calls
  * bpf plugins: add context to error logs
  * chattrsnoop: fix files not getting closed
  * chattrsnoop: move hashing from plugin to artifact
  * RPM artifact: start checks immediately on artifact load
  * rpm plugin: fix ndb magic error
  * audit s390x: fix arch filter rules errors
  * github: fix deprecated upload artifact
  * tcpsnoop: fix ipv6 local and remote addresses order
  * tcpsnoop: fix missing ipv6 outbound connections
  * Linux.Events.ProcessExecutions: remove parent cmdline
  * audit: reduce FileBufferLeaseSize to ease GC overhead
  * audit: fix auditBuf allocation and go vet warnings
  * audit: fix plugin shutdown race condition
  * audit: fix audit client data races
  * audit: fix race in subscriber
  * audit: prevent Windows loading audit package
  * sdjournal: fix package causing test failures
  * github: run linux unit tests

OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=84
2025-01-15 22:35:24 +00:00
Ana Guerrero
ecefcb440b Accepting request 1194777 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1194777
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=14
2024-08-20 14:13:41 +00:00
8ffa39547e - Update node modules with security fixes.
* Fixes CVE-2024-39338 (bsc#1229424)
  * Remove CVE-2024-28849-follow-redirects-drop-proxy-authorization.patch
    as the update is included.

OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=82
2024-08-19 21:02:37 +00:00
Dominique Leuenberger
3e27b00639 Accepting request 1193528 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1193528
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=13
2024-08-13 11:24:37 +00:00
6d2f044fdf - Move system-user-velociraptor to the client flavor build in order
to build it on all architectures.

OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=80
2024-08-12 21:17:58 +00:00
Ana Guerrero
7d1c0aa6dc Accepting request 1186660 from security:sensor
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1186660
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=12
2024-07-11 18:31:52 +00:00
40fdbdda96 Accepting request 1185208 from home:ateixeira:branches:security:sensor
- Update to version 0.7.0.4.git97.675e45f9:
  * kafka-humio-gateway: update go version and dependency list
  * kafka-humio-gateway: specific mTLS cert paths in config.yml
  * docker-compose: set kafka replication factor and min ISRs
  * kafka-humio-gateway: add http post retry mechanism
  * kafka-humio-gateway: add pprof debugging option
  * kafka-humio-gateway: format with gofmt
  * kafka-humio-gateway: fix go-staticcheck issues
  * kafka-humio-gateway: fix sendEvents() never exiting
  * Kafka.Events.Client: Update to use new artifactset type
  * docker-compose: add optional Kafka cluser
  * kafka-humio-gateway: add mTLS support
  * contrib/kafka-humio-gateway: add new debug option for noisy events
  * contrib/kafka-humio-gateway: backoff and retry for metadata
  * kafka-humio-gateway: add sample config file
  * kafka-humio-gateway: update sarama and dependencies
  * Add Kafka-Humio Gateway [Depends on PR#10] (#8)
  * vql/server/kafka: connect sarama logging to velociraptor logging
  * vql/server/kafka: add exponential backoff (limited to 30s) for metadata retries
  * vql/server/kafka: set appropriate ClientID
  * Add a Kafka export plugin
- Use llvm17 when available

OBS-URL: https://build.opensuse.org/request/show/1185208
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=78
2024-07-03 17:41:32 +00:00
Ana Guerrero
3a9a3e671f Accepting request 1177630 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1177630
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=11
2024-05-30 13:33:20 +00:00
61b53625a0 Accepting request 1177399 from home:ateixeira:branches:security:sensor
- Patches changes:
  * Change CVE-2024-28849-follow-redirects-drop-proxy-authorization.patch
    to update the follow-redirects package instead of patching directly.
  * Added CVE-2022-25883-npm-watch-semver-deps.patch (bsc#1212572)
- Add a package-lock.json to the package

OBS-URL: https://build.opensuse.org/request/show/1177399
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=76
2024-05-29 18:06:32 +00:00
Ana Guerrero
9a6b61d408 Accepting request 1170491 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1170491
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=10
2024-04-28 19:50:38 +00:00
f4ebb447db Accepting request 1170490 from home:ateixeira:sensor:sp3
- Fix group(velociraptor) dependency for SLE 15 SP3

OBS-URL: https://build.opensuse.org/request/show/1170490
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=74
2024-04-27 16:58:31 +00:00
Ana Guerrero
87d48ffde8 Accepting request 1169863 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1169863
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=9
2024-04-23 16:57:23 +00:00
a667aa6514 Accepting request 1169862 from home:ateixeira:branches:security:sensor
- Change system-user-velociraptor to noarch

OBS-URL: https://build.opensuse.org/request/show/1169862
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=72
2024-04-23 11:45:06 +00:00
Ana Guerrero
8987b20063 Accepting request 1168852 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1168852
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=8
2024-04-18 20:12:21 +00:00
9b9a6402e4 Accepting request 1168666 from home:jeff_mahoney:branches:security:sensor
- Fix unresolveable Debian group-velociraptor dependency.

OBS-URL: https://build.opensuse.org/request/show/1168666
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=70
2024-04-18 12:45:01 +00:00
c7549ca9ab Accepting request 1168648 from home:jeff_mahoney:branches:security:sensor
- Restore velociraptor group for client
- Add %{name}(project:%_project) Provides for SLE15 and newer
- Fixed SLE12-SP5 build

OBS-URL: https://build.opensuse.org/request/show/1168648
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=69
2024-04-17 19:45:07 +00:00
Ana Guerrero
db2ba9b3f0 Accepting request 1165646 from security:sensor
OBS-URL: https://build.opensuse.org/request/show/1165646
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=7
2024-04-05 18:28:36 +00:00
4606785411 Accepting request 1165645 from home:ateixeira:branches:security:sensor
- Obsolete old velociraptor-kafka-humio-gateway package

OBS-URL: https://build.opensuse.org/request/show/1165645
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=67
2024-04-05 13:08:37 +00:00
84e1ed1154 Accepting request 1164383 from home:ateixeira:branches:security:sensor
- Update to version 0.7.0.4.git74.3426c0a:
  * Fix services artifact symbol pid not found error
  * chattrsnoop: correct read size for flags
  * chattrsnoop: fix wrong FS_IOC_SETFLAGS value for ppc
  * chattrsnoop: fix do_vfs_ioctl kprobe failure

- Remove nodejs sources from main spec file. 

- Update to version 0.7.0.4.git68.ad1f4e5:
  * Fix undefined binary.NativeEndian build errors
- Add llvm16-libclang13 dependency for SLE 15 SP5 and above

- Disable eBPF for SLE 15 SP2

- Fix builds for SLE 15 SP3 and SLE 12
  * Revert to gzip compression instead of zstd for go modules

OBS-URL: https://build.opensuse.org/request/show/1164383
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=66
2024-04-03 15:02:45 +00:00
241ebf3914 Accepting request 1161552 from home:ateixeira:branches:security:sensor
- Update to version 0.7.0.4.git66.eea7659:
  * dnssnoop: fix loading protocol from ip header on s390
  * dnssnoop: fix htons() so it works on s390 too
  * Fix systemd Services artifact missing events
  * chattrsnoop: replace global variables with locals
  * tcpsnoop: fix garbled results on s390
  * chattrsnoop: fix immutable attribute set on s390
  * chattrsnoop: fix bpf_probe_read for s390
  * tcpsnoop: remove unused filtering code
  * Add artifact to collect new files without owner
  * bpf plugins: set a logger callback
- Add CVE-2024-28849-follow-redirects-drop-proxy-authorization.patch
  (bsc#1221456)

OBS-URL: https://build.opensuse.org/request/show/1161552
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=65
2024-03-25 20:16:39 +00:00
5968657952 Accepting request 1153587 from home:ateixeira:branches:security:sensor
- Reintroduce system-user-velociraptor package due to client %pre
  and %postun scripts depending on velociraptor user and group.

OBS-URL: https://build.opensuse.org/request/show/1153587
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=64
2024-02-29 19:22:00 +00:00
b0c8b246d2 Accepting request 1152799 from home:ateixeira:branches:security:sensor
- Obsolete old system-user-velociraptor package.
- Use zst compression for go modules.

- Changelog formatting and adding lost entries

OBS-URL: https://build.opensuse.org/request/show/1152799
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=63
2024-02-27 23:25:38 +00:00
1565eb03b8 Accepting request 1149917 from home:doreilly:branches:security:sensor
- Update to version 0.7.0.4.git47.0f8a4de1:
  * Rename SUSE specific artifacts to have SUSE prefix
  * Add SUSE.Linux.Events.NewZeroSizeLogFile artifact
  * Move NewFiles artifact to SUSE
  * Move ImmutableFile artifact to SUSE
  * Make ImmutableFile artifact consistent with others
  * Fix absolute path case in ExecutableFiles artifact
  * Add client monitoring artifact for RPMs
  * Add artifact to collect new hidden files
  * Add artifact to monitor ssh authorized_keys files
  * Fix split_records error on older clients
  * Add hash fields to Linux.Events.ProcessExecutions
  * Add artifact to collect systemd service events
  * Fix SystemLogins artifacts file extensions
  * Add SUSE.Linux.Events.Timers artifact
  * Fix audit filter key typo in Linux.Events.NewFiles
  * Add server artifact to delete old client data on server
  * Add SUSE.Linux.Sys.At artifact
  * chattrsnoop: include full error details in logs
  * chattrsnoop: handle os.Stat() error properly
  * chattrsnoop: don't log.Fatal() on hash error
  * Fix Linux.Events.ImmutableFile not showing hash in GUI
  * SUSE.Linux.Events.Crontab: Add task execution artifacts
  * Raise client connection log level to ERROR
  * sdjournal: Correctly seek to current tail
- Remove verbose flag from client config
 
- Update to version 0.7.0.4.git6.7b40b8b:
  * go.mod: increase go version to 1.19

OBS-URL: https://build.opensuse.org/request/show/1149917
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=62
2024-02-23 12:55:34 +00:00
241bb91d31 Accepting request 1149391 from home:ateixeira:branches:security:sensor
- Use clang16 for SLE 15 SP4 and above.

OBS-URL: https://build.opensuse.org/request/show/1149391
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=61
2024-02-22 13:27:13 +00:00
Darragh O'Reilly
7e4a12a3fa Accepting request 1139763 from home:ateixeira:branches:security:sensor
- Fixed Debian %postun scripts being used for other distros.

OBS-URL: https://build.opensuse.org/request/show/1139763
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=60
2024-01-23 14:28:17 +00:00
0c4d6def1a Accepting request 1134354 from home:jeff_mahoney:branches:security:sensor
- Added workaround for missing Maintainers tag in Debian-based packages.
  obs-service-format_spec_file strips the Packager tag from the spec file
  before committing.  The build service replaces it with its own.  debbuild
  expects the Packager field to be present to generate the Maintainers tag
  in the output but it only receives the "cleaned" spec file.

- Added Recommends: auditd
  - Technically not *required* but Velociraptor's audit client enables
    audit and then listens on the multicast socket.  Without a listener
    on the unicast socket, the kernel will spam the system log with events.

- Fixed debian packaging:
  * /etc/sysconfig -> /etc/default
  * %postun for systemd service cleanup
  * Note: obs-service-format_spec_file strips the Packager tag that
    debbuild uses to generate the Maintainer tag

OBS-URL: https://build.opensuse.org/request/show/1134354
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=59
2023-12-21 00:29:28 +00:00
befaca9186 - Fix %SOURCE references.
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=58
2023-12-19 14:25:07 +00:00
8c712ed88b revert: - go.mod asks for go 1.18, so we don't need to require go 1.19
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=57
2023-12-18 20:31:47 +00:00
de4fd9d928 - go.mod asks for go 1.18, so we don't need to require go 1.19
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=56
2023-12-18 20:13:13 +00:00
ac85413735 Accepting request 1133905 from home:jeff_mahoney:branches:security:sensor
- Temporarily use the NODE_MODULES BEGIN/END form of the node_modules
  service due to a bug in debbuild preventing Debian builds from succeeding.
- Update to version 0.7.0.4.git4.c1b68a5b:
  * hash: fix nil pointer dereference panic
  * velociraptor: add dummy main function for mage
- Removed patch:
  * velociraptor-golang-mage-vendoring.diff
- Switched to using go_modules and node_modules source services
  - Eliminated bespoke vendoring scripts.
- Pulled sysuser definition into the velociraptor package.

- Remove PrivateTmp and PrivateDevices settings in velociraptor-client.service (SENS-70)

- Update to version 0.7.0.4.git0.e09a0df8:
  * Add additional sanitization to HTML templates on JS side. (#2) (#3077) (CVE-2023-5950)
  * vql/linux/sdjournal: Fix open/close lifetimes
  * vql/linux/audit: fix shutdown races
  * vql/linux/audit: fix goroutine lifetimes
  * vql/linux/audit: limit messageQueue to within runService
  * vql/linux/audit: add auditService.Log()
  * vql/linux/audit: pull parts of shutdown into shutdown watcher
  * vql/linux/audit: remove unnecessary error handling for reassembler
  * vql/linux/audit: remove unused waitgroup from main event loop
  * vql/linux/audit: handle top-level cancelation properly
  * vql/linux/audit: make explicit that goroutines in the main errgroup don't return errors
  * vql/linux/audit: make stats reporting separate from debug prints
  * vql/linux/audit: simplify polling in listener
  * vql/linux/audit: tests, check various rule scenarios
  * vql/linux/audit: Add more client failure test cases
  * vql/linux/audit: Fix audit client lifecycle

OBS-URL: https://build.opensuse.org/request/show/1133905
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=55
2023-12-18 18:44:23 +00:00
Ana Guerrero
9ee7c5b57b Accepting request 1101044 from security:sensor
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1101044
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=6
2023-07-27 14:53:11 +00:00
6ab20944e0 Accepting request 1099705 from home:msmeissn:branches:security:sensor
- require the group / user only in the server build

OBS-URL: https://build.opensuse.org/request/show/1099705
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=53
2023-07-20 09:59:08 +00:00
Dominique Leuenberger
0f4e498491 Accepting request 1085933 from security:sensor
- Update to version 0.6.7.5~git81.01be570:
  * libbpfgo: pull fix for double-free
  * logscale: add documentation for plugin

- bump minimum nodejs to 18:
  building against 16 causes errors

OBS-URL: https://build.opensuse.org/request/show/1085933
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=5
2023-05-10 14:19:17 +00:00
154074cae5 - Update to version 0.6.7.5~git81.01be570:
* libbpfgo: pull fix for double-free
  * logscale: add documentation for plugin

OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=51
2023-05-10 00:51:00 +00:00
7bb1958b78 Accepting request 1085748 from home:darix:apps
- bump minimum nodejs to 18:
  building against 16 causes errors

OBS-URL: https://build.opensuse.org/request/show/1085748
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=50
2023-05-09 23:43:33 +00:00
Dominique Leuenberger
116b27c951 Accepting request 1085597 from security:sensor
- Provide sysuser template for velociraptor user and group. (forwarded request 1085596 from jeff_mahoney)

OBS-URL: https://build.opensuse.org/request/show/1085597
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/velociraptor?expand=0&rev=4
2023-05-09 11:08:33 +00:00
c313187484 Accepting request 1085596 from home:jeff_mahoney:branches:security:sensor:updates
- Provide sysuser template for velociraptor user and group.

OBS-URL: https://build.opensuse.org/request/show/1085596
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=48
2023-05-09 02:00:49 +00:00
f537d3a99b OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=47 2023-05-09 00:52:45 +00:00
3a5ec10ba3 Accepting request 1085591 from home:jeff_mahoney:branches:security:sensor:updates
- Update to version 0.6.7.5~git78.2bef6fc:
  * bpf: fix path to vmlinux.h

- Update to version 0.6.7.5~git77.997aa73:
  * file_store/test_utils/server_config.go: update test certificate
  * Update bluemonday dependency.
  * vql/functions/hash: cache results on Linux
  * libbpfgo: update to velociraptor-branch-v0.4.8-libbpf-1.2.0
  * logscale/backport: don't use networking.GetHttpTransport
  * vql/tools/logscale: add plugin to post events to LogScale ingestion endpoint
  * file_store/directory: add ability to report pending size
- Change clang dependency to clang16
- Fix velociraptor-golang-mage-vendoring.diff to account for newer
  'go mod vendor' honoring build flags.
- Fix update-vendoring.sh script to actually run the %setup part of
  the spec.
- Merge client package into server spec and use _multibuild to create
  client package from same spec file.
- Adjust changelog to retain changes for client package.
- Fix building in static mode on earlier releases.
  - Added patch: velociraptor-libbpfgo-only-build-libbpf.patch

- Tightening the security of the services a bit:
  - tmp files are now moved to /var/lib/velociraptor{,-client}/tmp
    from /tmp
  - run velociraptor server as user velociraptor instead of root
    we do not really need root permissions here
  - introduce /var/lib/velociraptor/filestore to make it easier to
    split out large file upload
  - change permissions for the data directory and subdirectories to

OBS-URL: https://build.opensuse.org/request/show/1085591
OBS-URL: https://build.opensuse.org/package/show/security:sensor/velociraptor?expand=0&rev=46
2023-05-09 00:49:51 +00:00