From 919500bd741ff020cc46e070b8a64a95dc055e18 Mon Sep 17 00:00:00 2001 From: vcerenu Date: Fri, 14 Jul 2023 16:22:52 -0300 Subject: [PATCH 01/10] bump master to 4.8.0 --- .env | 4 ++-- .github/.goss.yaml | 2 +- CHANGELOG.md | 5 +++++ README.md | 1 + VERSION | 4 ++-- build-docker-images/build-images.sh | 2 +- build-docker-images/wazuh-dashboard/config/config.sh | 4 ++-- build-docker-images/wazuh-indexer/config/config.sh | 4 ++-- build-docker-images/wazuh-manager/Dockerfile | 2 +- indexer-certs-creator/config/entrypoint.sh | 4 ++-- multi-node/docker-compose.yml | 12 ++++++------ single-node/docker-compose.yml | 6 +++--- 12 files changed, 28 insertions(+), 22 deletions(-) diff --git a/.env b/.env index a4909eb4..08a3c7ed 100755 --- a/.env +++ b/.env @@ -1,3 +1,3 @@ -WAZUH_VERSION=4.7.0 -WAZUH_IMAGE_VERSION=4.7.0 +WAZUH_VERSION=4.8.0 +WAZUH_IMAGE_VERSION=4.8.0 WAZUH_TAG_REVISION=1 diff --git a/.github/.goss.yaml b/.github/.goss.yaml index 95764f97..ee5833ce 100644 --- a/.github/.goss.yaml +++ b/.github/.goss.yaml @@ -56,7 +56,7 @@ package: wazuh-manager: installed: true versions: - - 4.7.0-1 + - 4.8.0-1 port: tcp:1514: listening: true diff --git a/CHANGELOG.md b/CHANGELOG.md index 8dd8664a..d032d59a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,11 @@ # Change Log All notable changes to this project will be documented in this file. +## Wazuh Docker v4.8.0 +### Added + +- Update Wazuh to version [4.8.0](https://github.com/wazuh/wazuh/blob/v4.8.0/CHANGELOG.md#v480) + ## Wazuh Docker v4.7.0 ### Added diff --git a/README.md b/README.md index 8dc20aa5..ff52c494 100644 --- a/README.md +++ b/README.md @@ -195,6 +195,7 @@ WAZUH_MONITORING_REPLICAS=0 ## | Wazuh version | ODFE | XPACK | |---------------|---------|--------| +| v4.8.0 | | | | v4.7.0 | | | | v4.6.0 | | | | v4.5.1 | | | diff --git a/VERSION b/VERSION index aa9abeed..ad87fa06 100644 --- a/VERSION +++ b/VERSION @@ -1,2 +1,2 @@ -WAZUH-DOCKER_VERSION="4.7.0" -REVISION="40700" +WAZUH-DOCKER_VERSION="4.8.0" +REVISION="40800" diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index ded56d43..250f6dee 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -1,4 +1,4 @@ -WAZUH_IMAGE_VERSION=4.7.0 +WAZUH_IMAGE_VERSION=4.8.0 WAZUH_VERSION=$(echo $WAZUH_IMAGE_VERSION | sed -e 's/\.//g') WAZUH_TAG_REVISION=1 WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '\"tag_name\":' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') diff --git a/build-docker-images/wazuh-dashboard/config/config.sh b/build-docker-images/wazuh-dashboard/config/config.sh index 8cdb1a01..79306721 100644 --- a/build-docker-images/wazuh-dashboard/config/config.sh +++ b/build-docker-images/wazuh-dashboard/config/config.sh @@ -9,8 +9,8 @@ export CONFIG_DIR=${INSTALLATION_DIR}/config ## Variables CERT_TOOL=wazuh-certs-tool.sh -PACKAGES_URL=https://packages.wazuh.com/4.7/ -PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.7/ +PACKAGES_URL=https://packages.wazuh.com/4.8/ +PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.8/ ## Check if the cert tool exists in S3 buckets CERT_TOOL_PACKAGES=$(curl --silent -I $PACKAGES_URL$CERT_TOOL | grep -E "^HTTP" | awk '{print $2}') diff --git a/build-docker-images/wazuh-indexer/config/config.sh b/build-docker-images/wazuh-indexer/config/config.sh index 0bdd1bef..a01b761c 100644 --- a/build-docker-images/wazuh-indexer/config/config.sh +++ b/build-docker-images/wazuh-indexer/config/config.sh @@ -53,8 +53,8 @@ tar -xf ${INDEXER_FILE} ## Variables CERT_TOOL=wazuh-certs-tool.sh PASSWORD_TOOL=wazuh-passwords-tool.sh -PACKAGES_URL=https://packages.wazuh.com/4.7/ -PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.7/ +PACKAGES_URL=https://packages.wazuh.com/4.8/ +PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.8/ ## Check if the cert tool exists in S3 buckets CERT_TOOL_PACKAGES=$(curl --silent -I $PACKAGES_URL$CERT_TOOL | grep -E "^HTTP" | awk '{print $2}') diff --git a/build-docker-images/wazuh-manager/Dockerfile b/build-docker-images/wazuh-manager/Dockerfile index 277b6e6c..c1184918 100644 --- a/build-docker-images/wazuh-manager/Dockerfile +++ b/build-docker-images/wazuh-manager/Dockerfile @@ -5,7 +5,7 @@ RUN rm /bin/sh && ln -s /bin/bash /bin/sh ARG WAZUH_VERSION ARG WAZUH_TAG_REVISION -ARG TEMPLATE_VERSION=4.7 +ARG TEMPLATE_VERSION=4.8 ARG FILEBEAT_CHANNEL=filebeat-oss ARG FILEBEAT_VERSION=7.10.2 ARG WAZUH_FILEBEAT_MODULE="wazuh-filebeat-0.2.tar.gz" diff --git a/indexer-certs-creator/config/entrypoint.sh b/indexer-certs-creator/config/entrypoint.sh index 03d866e7..5379402b 100644 --- a/indexer-certs-creator/config/entrypoint.sh +++ b/indexer-certs-creator/config/entrypoint.sh @@ -8,8 +8,8 @@ ## Variables CERT_TOOL=wazuh-certs-tool.sh PASSWORD_TOOL=wazuh-passwords-tool.sh -PACKAGES_URL=https://packages.wazuh.com/4.7/ -PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.7/ +PACKAGES_URL=https://packages.wazuh.com/4.8/ +PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.8/ ## Check if the cert tool exists in S3 buckets CERT_TOOL_PACKAGES=$(curl --silent -I $PACKAGES_URL$CERT_TOOL | grep -E "^HTTP" | awk '{print $2}') diff --git a/multi-node/docker-compose.yml b/multi-node/docker-compose.yml index 1ecbe45f..fdf63047 100644 --- a/multi-node/docker-compose.yml +++ b/multi-node/docker-compose.yml @@ -3,7 +3,7 @@ version: '3.7' services: wazuh.master: - image: wazuh/wazuh-manager:4.7.0 + image: wazuh/wazuh-manager:4.8.0 hostname: wazuh.master restart: always ports: @@ -38,7 +38,7 @@ services: - ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.worker: - image: wazuh/wazuh-manager:4.7.0 + image: wazuh/wazuh-manager:4.8.0 hostname: wazuh.worker restart: always environment: @@ -67,7 +67,7 @@ services: - ./config/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf wazuh1.indexer: - image: wazuh/wazuh-indexer:4.7.0 + image: wazuh/wazuh-indexer:4.8.0 hostname: wazuh1.indexer restart: always ports: @@ -93,7 +93,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh2.indexer: - image: wazuh/wazuh-indexer:4.7.0 + image: wazuh/wazuh-indexer:4.8.0 hostname: wazuh2.indexer restart: always environment: @@ -115,7 +115,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh3.indexer: - image: wazuh/wazuh-indexer:4.7.0 + image: wazuh/wazuh-indexer:4.8.0 hostname: wazuh3.indexer restart: always environment: @@ -137,7 +137,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh.dashboard: - image: wazuh/wazuh-dashboard:4.7.0 + image: wazuh/wazuh-dashboard:4.8.0 hostname: wazuh.dashboard restart: always ports: diff --git a/single-node/docker-compose.yml b/single-node/docker-compose.yml index 79919e53..76e71c17 100644 --- a/single-node/docker-compose.yml +++ b/single-node/docker-compose.yml @@ -3,7 +3,7 @@ version: '3.7' services: wazuh.manager: - image: wazuh/wazuh-manager:4.7.0 + image: wazuh/wazuh-manager:4.8.0 hostname: wazuh.manager restart: always ports: @@ -39,7 +39,7 @@ services: - ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.indexer: - image: wazuh/wazuh-indexer:4.7.0 + image: wazuh/wazuh-indexer:4.8.0 hostname: wazuh.indexer restart: always ports: @@ -64,7 +64,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh.dashboard: - image: wazuh/wazuh-dashboard:4.7.0 + image: wazuh/wazuh-dashboard:4.8.0 hostname: wazuh.dashboard restart: always ports: From 7db3d0d27896d2664af2c6e1167e1e68c58490cd Mon Sep 17 00:00:00 2001 From: vcerenu Date: Fri, 21 Jul 2023 15:22:22 -0300 Subject: [PATCH 02/10] Bump branch for trivy scan --- .github/workflows/trivy-dashboard-4-4.yml | 2 +- .github/workflows/trivy-indexer-4-4.yml | 2 +- .github/workflows/trivy-manager-4-4.yml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/trivy-dashboard-4-4.yml b/.github/workflows/trivy-dashboard-4-4.yml index eb3f3b4f..863f4b03 100644 --- a/.github/workflows/trivy-dashboard-4-4.yml +++ b/.github/workflows/trivy-dashboard-4-4.yml @@ -31,7 +31,7 @@ jobs: steps: - name: Checkout code uses: actions/checkout@v3 - with: { ref: 4.4 } + with: { ref: v4.4.5 } - name: Installing dependencies run: | diff --git a/.github/workflows/trivy-indexer-4-4.yml b/.github/workflows/trivy-indexer-4-4.yml index d48d0d85..9baec82c 100644 --- a/.github/workflows/trivy-indexer-4-4.yml +++ b/.github/workflows/trivy-indexer-4-4.yml @@ -31,7 +31,7 @@ jobs: steps: - name: Checkout code uses: actions/checkout@v3 - with: { ref: 4.4 } + with: { ref: v4.4.5 } - name: Installing dependencies run: | diff --git a/.github/workflows/trivy-manager-4-4.yml b/.github/workflows/trivy-manager-4-4.yml index 8a886871..d8631089 100644 --- a/.github/workflows/trivy-manager-4-4.yml +++ b/.github/workflows/trivy-manager-4-4.yml @@ -31,7 +31,7 @@ jobs: steps: - name: Checkout code uses: actions/checkout@v3 - with: { ref: 4.4 } + with: { ref: v4.4.5 } - name: Installing dependencies run: | From d0eaae482c9314efb0d4fcfffbde32fd5175d47d Mon Sep 17 00:00:00 2001 From: vcerenu Date: Fri, 11 Aug 2023 12:15:28 -0300 Subject: [PATCH 03/10] modify base for Wazuh Docker images --- build-docker-images/wazuh-dashboard/Dockerfile | 4 ++-- build-docker-images/wazuh-indexer/Dockerfile | 4 ++-- build-docker-images/wazuh-manager/Dockerfile | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/build-docker-images/wazuh-dashboard/Dockerfile b/build-docker-images/wazuh-dashboard/Dockerfile index 1b95ca88..e6c8c71b 100644 --- a/build-docker-images/wazuh-dashboard/Dockerfile +++ b/build-docker-images/wazuh-dashboard/Dockerfile @@ -1,5 +1,5 @@ # Wazuh Docker Copyright (C) 2017, Wazuh Inc. (License GPLv2) -FROM ubuntu:focal AS builder +FROM ubuntu:jammy AS builder ARG WAZUH_VERSION ARG WAZUH_TAG_REVISION @@ -42,7 +42,7 @@ RUN mkdir -p $INSTALL_DIR/data/wazuh/logs && chown -R 101:101 $INSTALL_DIR/data/ # Add entrypoint # Add wazuh_app_config ################################################################################ -FROM ubuntu:focal +FROM ubuntu:jammy # Set environment variables ENV USER="wazuh-dashboard" \ diff --git a/build-docker-images/wazuh-indexer/Dockerfile b/build-docker-images/wazuh-indexer/Dockerfile index 696c0462..f2b809c3 100644 --- a/build-docker-images/wazuh-indexer/Dockerfile +++ b/build-docker-images/wazuh-indexer/Dockerfile @@ -1,5 +1,5 @@ # Wazuh Docker Copyright (C) 2017, Wazuh Inc. (License GPLv2) -FROM ubuntu:focal AS builder +FROM ubuntu:jammy AS builder ARG WAZUH_VERSION ARG WAZUH_TAG_REVISION @@ -26,7 +26,7 @@ RUN bash config.sh # Copy wazuh-indexer from stage 0 # Add entrypoint ################################################################################ -FROM ubuntu:focal +FROM ubuntu:jammy ENV USER="wazuh-indexer" \ GROUP="wazuh-indexer" \ diff --git a/build-docker-images/wazuh-manager/Dockerfile b/build-docker-images/wazuh-manager/Dockerfile index c1184918..20ceac4e 100644 --- a/build-docker-images/wazuh-manager/Dockerfile +++ b/build-docker-images/wazuh-manager/Dockerfile @@ -1,5 +1,5 @@ # Wazuh Docker Copyright (C) 2017, Wazuh Inc. (License GPLv2) -FROM ubuntu:focal +FROM ubuntu:jammy RUN rm /bin/sh && ln -s /bin/bash /bin/sh From 6a4dc3c3eb01d9c530dcceb46eebc1cce3e18d4d Mon Sep 17 00:00:00 2001 From: vcerenu Date: Fri, 18 Aug 2023 15:11:21 -0300 Subject: [PATCH 04/10] change repository checkout --- .../workflows/{trivy-dashboard-4-4.yml => trivy-dashboard.yml} | 3 ++- .github/workflows/{trivy-indexer-4-4.yml => trivy-indexer.yml} | 3 ++- .github/workflows/{trivy-manager-4-4.yml => trivy-manager.yml} | 3 ++- 3 files changed, 6 insertions(+), 3 deletions(-) rename .github/workflows/{trivy-dashboard-4-4.yml => trivy-dashboard.yml} (94%) rename .github/workflows/{trivy-indexer-4-4.yml => trivy-indexer.yml} (94%) rename .github/workflows/{trivy-manager-4-4.yml => trivy-manager.yml} (94%) diff --git a/.github/workflows/trivy-dashboard-4-4.yml b/.github/workflows/trivy-dashboard.yml similarity index 94% rename from .github/workflows/trivy-dashboard-4-4.yml rename to .github/workflows/trivy-dashboard.yml index 863f4b03..a9c04a23 100644 --- a/.github/workflows/trivy-dashboard-4-4.yml +++ b/.github/workflows/trivy-dashboard.yml @@ -31,12 +31,13 @@ jobs: steps: - name: Checkout code uses: actions/checkout@v3 - with: { ref: v4.4.5 } - name: Installing dependencies run: | sudo apt-get update sudo apt-get install -y jq + latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') + git checkout $latest - name: Build Wazuh images run: build-docker-images/build-images.sh diff --git a/.github/workflows/trivy-indexer-4-4.yml b/.github/workflows/trivy-indexer.yml similarity index 94% rename from .github/workflows/trivy-indexer-4-4.yml rename to .github/workflows/trivy-indexer.yml index 9baec82c..2a5b182a 100644 --- a/.github/workflows/trivy-indexer-4-4.yml +++ b/.github/workflows/trivy-indexer.yml @@ -31,12 +31,13 @@ jobs: steps: - name: Checkout code uses: actions/checkout@v3 - with: { ref: v4.4.5 } - name: Installing dependencies run: | sudo apt-get update sudo apt-get install -y jq + latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') + git checkout $latest - name: Build Wazuh images run: build-docker-images/build-images.sh diff --git a/.github/workflows/trivy-manager-4-4.yml b/.github/workflows/trivy-manager.yml similarity index 94% rename from .github/workflows/trivy-manager-4-4.yml rename to .github/workflows/trivy-manager.yml index d8631089..8b1dc659 100644 --- a/.github/workflows/trivy-manager-4-4.yml +++ b/.github/workflows/trivy-manager.yml @@ -31,12 +31,13 @@ jobs: steps: - name: Checkout code uses: actions/checkout@v3 - with: { ref: v4.4.5 } - name: Installing dependencies run: | sudo apt-get update sudo apt-get install -y jq + latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') + git checkout $latest - name: Build Wazuh images run: build-docker-images/build-images.sh From bd513e80cc524132c22e57643e5c07ccbdeecfa2 Mon Sep 17 00:00:00 2001 From: vcerenu Date: Fri, 18 Aug 2023 15:18:56 -0300 Subject: [PATCH 05/10] add new step --- .github/workflows/trivy-dashboard.yml | 3 +++ .github/workflows/trivy-indexer.yml | 3 +++ .github/workflows/trivy-manager.yml | 3 +++ 3 files changed, 9 insertions(+) diff --git a/.github/workflows/trivy-dashboard.yml b/.github/workflows/trivy-dashboard.yml index a9c04a23..8ee00521 100644 --- a/.github/workflows/trivy-dashboard.yml +++ b/.github/workflows/trivy-dashboard.yml @@ -36,8 +36,11 @@ jobs: run: | sudo apt-get update sudo apt-get install -y jq + + - name: Checkout latest tag latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') git checkout $latest + - name: Build Wazuh images run: build-docker-images/build-images.sh diff --git a/.github/workflows/trivy-indexer.yml b/.github/workflows/trivy-indexer.yml index 2a5b182a..71d272e0 100644 --- a/.github/workflows/trivy-indexer.yml +++ b/.github/workflows/trivy-indexer.yml @@ -36,8 +36,11 @@ jobs: run: | sudo apt-get update sudo apt-get install -y jq + + - name: Checkout latest tag latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') git checkout $latest + - name: Build Wazuh images run: build-docker-images/build-images.sh diff --git a/.github/workflows/trivy-manager.yml b/.github/workflows/trivy-manager.yml index 8b1dc659..e5787f80 100644 --- a/.github/workflows/trivy-manager.yml +++ b/.github/workflows/trivy-manager.yml @@ -36,8 +36,11 @@ jobs: run: | sudo apt-get update sudo apt-get install -y jq + + - name: Checkout latest tag latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') git checkout $latest + - name: Build Wazuh images run: build-docker-images/build-images.sh From a2f50192b6c560b414a3acd326a06230b2d5fd06 Mon Sep 17 00:00:00 2001 From: vcerenu Date: Fri, 18 Aug 2023 15:21:07 -0300 Subject: [PATCH 06/10] add new step --- .github/workflows/trivy-dashboard.yml | 1 + .github/workflows/trivy-indexer.yml | 1 + .github/workflows/trivy-manager.yml | 1 + 3 files changed, 3 insertions(+) diff --git a/.github/workflows/trivy-dashboard.yml b/.github/workflows/trivy-dashboard.yml index 8ee00521..5f247878 100644 --- a/.github/workflows/trivy-dashboard.yml +++ b/.github/workflows/trivy-dashboard.yml @@ -38,6 +38,7 @@ jobs: sudo apt-get install -y jq - name: Checkout latest tag + run: | latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') git checkout $latest diff --git a/.github/workflows/trivy-indexer.yml b/.github/workflows/trivy-indexer.yml index 71d272e0..aacb42b9 100644 --- a/.github/workflows/trivy-indexer.yml +++ b/.github/workflows/trivy-indexer.yml @@ -38,6 +38,7 @@ jobs: sudo apt-get install -y jq - name: Checkout latest tag + run: | latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') git checkout $latest diff --git a/.github/workflows/trivy-manager.yml b/.github/workflows/trivy-manager.yml index e5787f80..89db7dc7 100644 --- a/.github/workflows/trivy-manager.yml +++ b/.github/workflows/trivy-manager.yml @@ -38,6 +38,7 @@ jobs: sudo apt-get install -y jq - name: Checkout latest tag + run: | latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') git checkout $latest From 1d8332725f2f5ce90140e2002219b44664a9a49d Mon Sep 17 00:00:00 2001 From: vcerenu Date: Fri, 18 Aug 2023 15:23:12 -0300 Subject: [PATCH 07/10] add fetch --- .github/workflows/trivy-dashboard.yml | 1 + .github/workflows/trivy-indexer.yml | 1 + .github/workflows/trivy-manager.yml | 1 + 3 files changed, 3 insertions(+) diff --git a/.github/workflows/trivy-dashboard.yml b/.github/workflows/trivy-dashboard.yml index 5f247878..8bc2decf 100644 --- a/.github/workflows/trivy-dashboard.yml +++ b/.github/workflows/trivy-dashboard.yml @@ -40,6 +40,7 @@ jobs: - name: Checkout latest tag run: | latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') + git fetch origin git checkout $latest - name: Build Wazuh images diff --git a/.github/workflows/trivy-indexer.yml b/.github/workflows/trivy-indexer.yml index aacb42b9..3582e21d 100644 --- a/.github/workflows/trivy-indexer.yml +++ b/.github/workflows/trivy-indexer.yml @@ -40,6 +40,7 @@ jobs: - name: Checkout latest tag run: | latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') + git fetch origin git checkout $latest - name: Build Wazuh images diff --git a/.github/workflows/trivy-manager.yml b/.github/workflows/trivy-manager.yml index 89db7dc7..18bdf1b8 100644 --- a/.github/workflows/trivy-manager.yml +++ b/.github/workflows/trivy-manager.yml @@ -40,6 +40,7 @@ jobs: - name: Checkout latest tag run: | latest=$(curl -s "https://api.github.com/repos/wazuh/wazuh-docker/releases/latest" | jq -r '.tag_name') + git fetch origin git checkout $latest - name: Build Wazuh images From b40e90d19c11d2bb7fe5272603a281d8e3454d32 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Gonzalo=20Acu=C3=B1a?= <33964202+teddytpc1@users.noreply.github.com> Date: Wed, 20 Sep 2023 08:29:53 -0300 Subject: [PATCH 08/10] Create SECURITY.md Wazuh security policy added. --- SECURITY.md | 45 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..54e59de1 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,45 @@ +# Wazuh Open Source Project Security Policy + +Version: 2023-06-12 + +## Introduction +This document outlines the Security Policy for Wazuh's open source projects. It emphasizes our commitment to maintain a secure environment for our users and contributors, and reflects our belief in the power of collaboration to identify and resolve security vulnerabilities. + +## Scope +This policy applies to all open source projects developed, maintained, or hosted by Wazuh. + +## Reporting Security Vulnerabilities +If you believe you've discovered a potential security vulnerability in one of our open source projects, we strongly encourage you to report it to us responsibly. + +Please submit your findings as security advisories under the "Security" tab in the relevant GitHub repository. Alternatively, you may send the details of your findings to [security@wazuh.com](mailto:security@wazuh.com). + +## Vulnerability Disclosure Policy +Upon receiving a report of a potential vulnerability, our team will initiate an investigation. If the reported issue is confirmed as a vulnerability, we will take the following steps: + +- Acknowledgment: We will acknowledge the receipt of your vulnerability report and begin our investigation. +- Validation: We will validate the issue and work on reproducing it in our environment. +- Remediation: We will work on a fix and thoroughly test it +- Release & Disclosure: After 90 days from the discovery of the vulnerability, or as soon as a fix is ready and thoroughly tested (whichever comes first), we will release a security update for the affected project. We will also publicly disclose the vulnerability by publishing a CVE (Common Vulnerabilities and Exposures) and acknowledging the discovering party. +- Exceptions: In order to preserve the security of the Wazuh community at large, we might extend the disclosure period to allow users to patch their deployments. + +This 90-day period allows for end-users to update their systems and minimizes the risk of widespread exploitation of the vulnerability. + +## Automatic Scanning +We leverage GitHub Actions to perform automated scans of our supply chain. These scans assist us in identifying vulnerabilities and outdated dependencies in a proactive and timely manner. + +## Credit +We believe in giving credit where credit is due. If you report a security vulnerability to us, and we determine that it is a valid vulnerability, we will publicly credit you for the discovery when we disclose the vulnerability. If you wish to remain anonymous, please indicate so in your initial report. + +We do appreciate and encourage feedback from our community, but currently we do not have a bounty program. We might start bounty programs in the future. + +## Compliance with this Policy +We consider the discovery and reporting of security vulnerabilities an important public service. We encourage responsible reporting of any vulnerabilities that may be found in our site or applications. + +Furthermore, we will not take legal action against or suspend or terminate access to the site or services of those who discover and report security vulnerabilities in accordance with this policy because of the fact. + +We ask that all users and contributors respect this policy and the security of our community's users by disclosing vulnerabilities to us in accordance with this policy. + +## Changes to this Security Policy +This policy may be revised from time to time. Each version of the policy will be identified at the top of the page by its effective date. + +If you have any questions about this Security Policy, please contact us at [security@wazuh.com](mailto:security@wazuh.com). From 5aaeb0d944647c055eea49de46ba2855f6877c70 Mon Sep 17 00:00:00 2001 From: vcerenu Date: Mon, 9 Oct 2023 06:34:35 -0300 Subject: [PATCH 09/10] Updated version in new builder script --- build-docker-images/README.md | 2 +- build-docker-images/build-images.sh | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/build-docker-images/README.md b/build-docker-images/README.md index a62978ac..10ba48d0 100644 --- a/build-docker-images/README.md +++ b/build-docker-images/README.md @@ -26,7 +26,7 @@ Usage: build-docker-images/build-images.sh [OPTIONS] -d, --dev [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default. -f, --filebeat-module [Optional] Set Filebeat module version. By default 0.2. -r, --revision [Optional] Package revision. By default 1 - -v, --version [Optional] Set the Wazuh version should be builded. By default, 4.6.0. + -v, --version [Optional] Set the Wazuh version should be builded. By default, 4.7.1. -h, --help Show this help. ``` \ No newline at end of file diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index 092cdc67..611b065a 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -12,7 +12,7 @@ IMAGE_VERSION=${WAZUH_IMAGE_VERSION} # License (version 2) as published by the FSF - Free Software # Foundation. -WAZUH_IMAGE_VERSION="4.6.0" +WAZUH_IMAGE_VERSION="4.7.1" WAZUH_TAG_REVISION="1" WAZUH_DEV_STAGE="" FILEBEAT_MODULE_VERSION="0.2" From 4d153f6705e613a84d7f3b3a48f36bc7fe40e12a Mon Sep 17 00:00:00 2001 From: vcerenu Date: Wed, 11 Oct 2023 05:44:48 -0300 Subject: [PATCH 10/10] bump new builder script --- build-docker-images/README.md | 4 ++-- build-docker-images/build-images.sh | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/build-docker-images/README.md b/build-docker-images/README.md index 10ba48d0..10a5da78 100644 --- a/build-docker-images/README.md +++ b/build-docker-images/README.md @@ -13,7 +13,7 @@ This script initializes the environment variables needed to build each of the im The script allows you to build images from other versions of Wazuh, to do this you must use the -v or --version argument: ``` -$ build-docker-images/build-images.sh -v 4.5.2 +$ build-docker-images/build-images.sh -v 4.8.0 ``` To get all the available script options use the -h or --help option: @@ -26,7 +26,7 @@ Usage: build-docker-images/build-images.sh [OPTIONS] -d, --dev [Optional] Set the development stage you want to build, example rc1 or beta1, not used by default. -f, --filebeat-module [Optional] Set Filebeat module version. By default 0.2. -r, --revision [Optional] Package revision. By default 1 - -v, --version [Optional] Set the Wazuh version should be builded. By default, 4.7.1. + -v, --version [Optional] Set the Wazuh version should be builded. By default, 4.8.0. -h, --help Show this help. ``` \ No newline at end of file diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index cabc2b99..04e1084f 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -1,4 +1,4 @@ -WAZUH_IMAGE_VERSION=4.7.1 +WAZUH_IMAGE_VERSION=4.8.0 WAZUH_VERSION=$(echo $WAZUH_IMAGE_VERSION | sed -e 's/\.//g') WAZUH_TAG_REVISION=1 WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '\"tag_name\":' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') @@ -12,7 +12,7 @@ IMAGE_VERSION=${WAZUH_IMAGE_VERSION} # License (version 2) as published by the FSF - Free Software # Foundation. -WAZUH_IMAGE_VERSION="4.7.1" +WAZUH_IMAGE_VERSION="4.8.0" WAZUH_TAG_REVISION="1" WAZUH_DEV_STAGE="" FILEBEAT_MODULE_VERSION="0.2"