diff --git a/.env b/.env index d51cc0c4..a4909eb4 100755 --- a/.env +++ b/.env @@ -1,3 +1,3 @@ -WAZUH_VERSION=4.6.0 -WAZUH_IMAGE_VERSION=4.6.0 +WAZUH_VERSION=4.7.0 +WAZUH_IMAGE_VERSION=4.7.0 WAZUH_TAG_REVISION=1 diff --git a/.github/.goss.yaml b/.github/.goss.yaml index c4244c3e..95764f97 100644 --- a/.github/.goss.yaml +++ b/.github/.goss.yaml @@ -56,7 +56,7 @@ package: wazuh-manager: installed: true versions: - - 4.6.0-1 + - 4.7.0-1 port: tcp:1514: listening: true diff --git a/.github/workflows/trivy-dashboard-4-4.yml b/.github/workflows/trivy-dashboard-4-4.yml new file mode 100644 index 00000000..eb3f3b4f --- /dev/null +++ b/.github/workflows/trivy-dashboard-4-4.yml @@ -0,0 +1,71 @@ +# This workflow uses actions that are not certified by GitHub. +# They are provided by a third-party and are governed by +# separate terms of service, privacy policy, and support +# documentation. + +name: Trivy scan Wazuh dashboard + +on: + release: + types: + - published + pull_request: + branches: + - master + - stable + schedule: + - cron: '34 2 * * 1' + workflow_dispatch: + +permissions: + contents: read + +jobs: + build: + permissions: + contents: read # for actions/checkout to fetch code + security-events: write # for github/codeql-action/upload-sarif to upload SARIF results + + name: Build images and upload Trivy results + runs-on: "ubuntu-latest" + steps: + - name: Checkout code + uses: actions/checkout@v3 + with: { ref: 4.4 } + + - name: Installing dependencies + run: | + sudo apt-get update + sudo apt-get install -y jq + - name: Build Wazuh images + run: build-docker-images/build-images.sh + + - name: Create enviroment variables + run: | + cat .env > $GITHUB_ENV + echo "GITHUB_REF_NAME="${GITHUB_REF_NAME%/*} >> $GITHUB_ENV + + - name: Run Trivy vulnerability scanner for Wazuh dashboard + uses: aquasecurity/trivy-action@2a2157eb22c08c9a1fac99263430307b8d1bc7a2 + with: + image-ref: 'wazuh/wazuh-dashboard:${{env.WAZUH_IMAGE_VERSION}}' + format: 'template' + template: '@/contrib/sarif.tpl' + output: 'trivy-results-dashboard.sarif' + severity: 'LOW,MEDIUM,CRITICAL,HIGH' + + - name: Upload Trivy scan results to GitHub Security tab + uses: github/codeql-action/upload-sarif@v2 + with: + sarif_file: 'trivy-results-dashboard.sarif' + + - name: Slack notification + uses: rtCamp/action-slack-notify@v2 + env: + SLACK_CHANNEL: cicd-monitoring + SLACK_COLOR: ${{ job.status }} # or a specific color like 'good' or '#ff00ff' + #SLACK_ICON: https://github.com/rtCamp.png?size=48 + SLACK_MESSAGE: "Check the results: https://github.com/wazuh/wazuh-docker/security/code-scanning?query=is%3Aopen+branch%3A${{ env.GITHUB_REF_NAME }}" + SLACK_TITLE: Wazuh docker Trivy vulnerability scan finished. + SLACK_USERNAME: github_actions + SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} \ No newline at end of file diff --git a/.github/workflows/trivy-indexer-4-4.yml b/.github/workflows/trivy-indexer-4-4.yml new file mode 100644 index 00000000..d48d0d85 --- /dev/null +++ b/.github/workflows/trivy-indexer-4-4.yml @@ -0,0 +1,71 @@ +# This workflow uses actions that are not certified by GitHub. +# They are provided by a third-party and are governed by +# separate terms of service, privacy policy, and support +# documentation. + +name: Trivy scan Wazuh indexer + +on: + release: + types: + - published + pull_request: + branches: + - master + - stable + schedule: + - cron: '34 2 * * 1' + workflow_dispatch: + +permissions: + contents: read + +jobs: + build: + permissions: + contents: read # for actions/checkout to fetch code + security-events: write # for github/codeql-action/upload-sarif to upload SARIF results + + name: Build images and upload Trivy results + runs-on: "ubuntu-latest" + steps: + - name: Checkout code + uses: actions/checkout@v3 + with: { ref: 4.4 } + + - name: Installing dependencies + run: | + sudo apt-get update + sudo apt-get install -y jq + - name: Build Wazuh images + run: build-docker-images/build-images.sh + + - name: Create enviroment variables + run: | + cat .env > $GITHUB_ENV + echo "GITHUB_REF_NAME="${GITHUB_REF_NAME%/*} >> $GITHUB_ENV + + - name: Run Trivy vulnerability scanner for Wazuh indexer + uses: aquasecurity/trivy-action@2a2157eb22c08c9a1fac99263430307b8d1bc7a2 + with: + image-ref: 'wazuh/wazuh-indexer:${{env.WAZUH_IMAGE_VERSION}}' + format: 'template' + template: '@/contrib/sarif.tpl' + output: 'trivy-results-indexer.sarif' + severity: 'LOW,MEDIUM,CRITICAL,HIGH' + + - name: Upload Trivy scan results to GitHub Security tab + uses: github/codeql-action/upload-sarif@v2 + with: + sarif_file: 'trivy-results-indexer.sarif' + + - name: Slack notification + uses: rtCamp/action-slack-notify@v2 + env: + SLACK_CHANNEL: cicd-monitoring + SLACK_COLOR: ${{ job.status }} # or a specific color like 'good' or '#ff00ff' + #SLACK_ICON: https://github.com/rtCamp.png?size=48 + SLACK_MESSAGE: "Check the results: https://github.com/wazuh/wazuh-docker/security/code-scanning?query=is%3Aopen+branch%3A${{ env.GITHUB_REF_NAME }}" + SLACK_TITLE: Wazuh docker Trivy vulnerability scan finished. + SLACK_USERNAME: github_actions + SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} \ No newline at end of file diff --git a/.github/workflows/trivy-manager-4-4.yml b/.github/workflows/trivy-manager-4-4.yml new file mode 100644 index 00000000..8a886871 --- /dev/null +++ b/.github/workflows/trivy-manager-4-4.yml @@ -0,0 +1,71 @@ +# This workflow uses actions that are not certified by GitHub. +# They are provided by a third-party and are governed by +# separate terms of service, privacy policy, and support +# documentation. + +name: Trivy scan Wazuh manager + +on: + release: + types: + - published + pull_request: + branches: + - master + - stable + schedule: + - cron: '34 2 * * 1' + workflow_dispatch: + +permissions: + contents: read + +jobs: + build: + permissions: + contents: read # for actions/checkout to fetch code + security-events: write # for github/codeql-action/upload-sarif to upload SARIF results + + name: Build images and upload Trivy results + runs-on: "ubuntu-latest" + steps: + - name: Checkout code + uses: actions/checkout@v3 + with: { ref: 4.4 } + + - name: Installing dependencies + run: | + sudo apt-get update + sudo apt-get install -y jq + - name: Build Wazuh images + run: build-docker-images/build-images.sh + + - name: Create enviroment variables + run: | + cat .env > $GITHUB_ENV + echo "GITHUB_REF_NAME="${GITHUB_REF_NAME%/*} >> $GITHUB_ENV + + - name: Run Trivy vulnerability scanner for Wazuh manager + uses: aquasecurity/trivy-action@2a2157eb22c08c9a1fac99263430307b8d1bc7a2 + with: + image-ref: 'wazuh/wazuh-manager:${{env.WAZUH_IMAGE_VERSION}}' + format: 'template' + template: '@/contrib/sarif.tpl' + output: 'trivy-results-manager.sarif' + severity: 'LOW,MEDIUM,CRITICAL,HIGH' + + - name: Upload Trivy scan results to GitHub Security tab + uses: github/codeql-action/upload-sarif@v2 + with: + sarif_file: 'trivy-results-manager.sarif' + + - name: Slack notification + uses: rtCamp/action-slack-notify@v2 + env: + SLACK_CHANNEL: cicd-monitoring + SLACK_COLOR: ${{ job.status }} # or a specific color like 'good' or '#ff00ff' + #SLACK_ICON: https://github.com/rtCamp.png?size=48 + SLACK_MESSAGE: "Check the results: https://github.com/wazuh/wazuh-docker/security/code-scanning?query=is%3Aopen+branch%3A${{ env.GITHUB_REF_NAME }}" + SLACK_TITLE: Wazuh docker Trivy vulnerability scan finished. + SLACK_USERNAME: github_actions + SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} \ No newline at end of file diff --git a/CHANGELOG.md b/CHANGELOG.md index 106ab35c..8dd8664a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,11 @@ # Change Log All notable changes to this project will be documented in this file. +## Wazuh Docker v4.7.0 +### Added + +- Update Wazuh to version [4.7.0](https://github.com/wazuh/wazuh/blob/v4.7.0/CHANGELOG.md#v470) + ## Wazuh Docker v4.6.0 ### Added diff --git a/README.md b/README.md index a3fce172..8dc20aa5 100644 --- a/README.md +++ b/README.md @@ -195,6 +195,7 @@ WAZUH_MONITORING_REPLICAS=0 ## | Wazuh version | ODFE | XPACK | |---------------|---------|--------| +| v4.7.0 | | | | v4.6.0 | | | | v4.5.1 | | | | v4.5.0 | | | diff --git a/VERSION b/VERSION index bcd17c34..aa9abeed 100644 --- a/VERSION +++ b/VERSION @@ -1,2 +1,2 @@ -WAZUH-DOCKER_VERSION="4.6.0" -REVISION="40600" +WAZUH-DOCKER_VERSION="4.7.0" +REVISION="40700" diff --git a/build-docker-images/build-images.sh b/build-docker-images/build-images.sh index 09644c70..ded56d43 100755 --- a/build-docker-images/build-images.sh +++ b/build-docker-images/build-images.sh @@ -1,4 +1,4 @@ -WAZUH_IMAGE_VERSION=4.6.0 +WAZUH_IMAGE_VERSION=4.7.0 WAZUH_VERSION=$(echo $WAZUH_IMAGE_VERSION | sed -e 's/\.//g') WAZUH_TAG_REVISION=1 WAZUH_CURRENT_VERSION=$(curl --silent https://api.github.com/repos/wazuh/wazuh/releases/latest | grep '\"tag_name\":' | sed -E 's/.*\"([^\"]+)\".*/\1/' | cut -c 2- | sed -e 's/\.//g') diff --git a/build-docker-images/wazuh-dashboard/config/config.sh b/build-docker-images/wazuh-dashboard/config/config.sh index 94719b93..8cdb1a01 100644 --- a/build-docker-images/wazuh-dashboard/config/config.sh +++ b/build-docker-images/wazuh-dashboard/config/config.sh @@ -9,8 +9,8 @@ export CONFIG_DIR=${INSTALLATION_DIR}/config ## Variables CERT_TOOL=wazuh-certs-tool.sh -PACKAGES_URL=https://packages.wazuh.com/4.6/ -PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.6/ +PACKAGES_URL=https://packages.wazuh.com/4.7/ +PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.7/ ## Check if the cert tool exists in S3 buckets CERT_TOOL_PACKAGES=$(curl --silent -I $PACKAGES_URL$CERT_TOOL | grep -E "^HTTP" | awk '{print $2}') diff --git a/build-docker-images/wazuh-indexer/config/config.sh b/build-docker-images/wazuh-indexer/config/config.sh index adfae164..0bdd1bef 100644 --- a/build-docker-images/wazuh-indexer/config/config.sh +++ b/build-docker-images/wazuh-indexer/config/config.sh @@ -53,8 +53,8 @@ tar -xf ${INDEXER_FILE} ## Variables CERT_TOOL=wazuh-certs-tool.sh PASSWORD_TOOL=wazuh-passwords-tool.sh -PACKAGES_URL=https://packages.wazuh.com/4.6/ -PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.6/ +PACKAGES_URL=https://packages.wazuh.com/4.7/ +PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.7/ ## Check if the cert tool exists in S3 buckets CERT_TOOL_PACKAGES=$(curl --silent -I $PACKAGES_URL$CERT_TOOL | grep -E "^HTTP" | awk '{print $2}') diff --git a/build-docker-images/wazuh-manager/Dockerfile b/build-docker-images/wazuh-manager/Dockerfile index da310bd6..277b6e6c 100644 --- a/build-docker-images/wazuh-manager/Dockerfile +++ b/build-docker-images/wazuh-manager/Dockerfile @@ -5,7 +5,7 @@ RUN rm /bin/sh && ln -s /bin/bash /bin/sh ARG WAZUH_VERSION ARG WAZUH_TAG_REVISION -ARG TEMPLATE_VERSION=4.6 +ARG TEMPLATE_VERSION=4.7 ARG FILEBEAT_CHANNEL=filebeat-oss ARG FILEBEAT_VERSION=7.10.2 ARG WAZUH_FILEBEAT_MODULE="wazuh-filebeat-0.2.tar.gz" diff --git a/indexer-certs-creator/config/entrypoint.sh b/indexer-certs-creator/config/entrypoint.sh index 7568812a..03d866e7 100644 --- a/indexer-certs-creator/config/entrypoint.sh +++ b/indexer-certs-creator/config/entrypoint.sh @@ -8,8 +8,8 @@ ## Variables CERT_TOOL=wazuh-certs-tool.sh PASSWORD_TOOL=wazuh-passwords-tool.sh -PACKAGES_URL=https://packages.wazuh.com/4.6/ -PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.6/ +PACKAGES_URL=https://packages.wazuh.com/4.7/ +PACKAGES_DEV_URL=https://packages-dev.wazuh.com/4.7/ ## Check if the cert tool exists in S3 buckets CERT_TOOL_PACKAGES=$(curl --silent -I $PACKAGES_URL$CERT_TOOL | grep -E "^HTTP" | awk '{print $2}') diff --git a/multi-node/docker-compose.yml b/multi-node/docker-compose.yml index cc04171c..1ecbe45f 100644 --- a/multi-node/docker-compose.yml +++ b/multi-node/docker-compose.yml @@ -3,7 +3,7 @@ version: '3.7' services: wazuh.master: - image: wazuh/wazuh-manager:4.6.0 + image: wazuh/wazuh-manager:4.7.0 hostname: wazuh.master restart: always ports: @@ -38,7 +38,7 @@ services: - ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.worker: - image: wazuh/wazuh-manager:4.6.0 + image: wazuh/wazuh-manager:4.7.0 hostname: wazuh.worker restart: always environment: @@ -67,7 +67,7 @@ services: - ./config/wazuh_cluster/wazuh_worker.conf:/wazuh-config-mount/etc/ossec.conf wazuh1.indexer: - image: wazuh/wazuh-indexer:4.6.0 + image: wazuh/wazuh-indexer:4.7.0 hostname: wazuh1.indexer restart: always ports: @@ -93,7 +93,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh2.indexer: - image: wazuh/wazuh-indexer:4.6.0 + image: wazuh/wazuh-indexer:4.7.0 hostname: wazuh2.indexer restart: always environment: @@ -115,7 +115,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh3.indexer: - image: wazuh/wazuh-indexer:4.6.0 + image: wazuh/wazuh-indexer:4.7.0 hostname: wazuh3.indexer restart: always environment: @@ -137,7 +137,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh.dashboard: - image: wazuh/wazuh-dashboard:4.6.0 + image: wazuh/wazuh-dashboard:4.7.0 hostname: wazuh.dashboard restart: always ports: diff --git a/single-node/docker-compose.yml b/single-node/docker-compose.yml index 94db30d6..79919e53 100644 --- a/single-node/docker-compose.yml +++ b/single-node/docker-compose.yml @@ -3,7 +3,7 @@ version: '3.7' services: wazuh.manager: - image: wazuh/wazuh-manager:4.6.0 + image: wazuh/wazuh-manager:4.7.0 hostname: wazuh.manager restart: always ports: @@ -39,7 +39,7 @@ services: - ./config/wazuh_cluster/wazuh_manager.conf:/wazuh-config-mount/etc/ossec.conf wazuh.indexer: - image: wazuh/wazuh-indexer:4.6.0 + image: wazuh/wazuh-indexer:4.7.0 hostname: wazuh.indexer restart: always ports: @@ -64,7 +64,7 @@ services: - ./config/wazuh_indexer/internal_users.yml:/usr/share/wazuh-indexer/opensearch-security/internal_users.yml wazuh.dashboard: - image: wazuh/wazuh-dashboard:4.6.0 + image: wazuh/wazuh-dashboard:4.7.0 hostname: wazuh.dashboard restart: always ports: