Skip to content

Releases: DataDog/guarddog

v1.5.0

02 Nov 13:00
a8287bc
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v1.4.0...v1.4.1

v1.4.0

03 Oct 12:26
5290371
Compare
Choose a tag to compare

What's Changed

  • Add new NPM metadata detector to catch dependencies fetched from URLs by @juliendoutre in #279

New Contributors

v1.3.0

22 Aug 12:44
83ca3cb
Compare
Choose a tag to compare

What's Changed

Features:

Bug fixes:

Chores:

New Contributors

Full Changelog: v1.2.1...v1.3.0

v1.2.1

04 Jul 14:39
3316149
Compare
Choose a tag to compare

What's Changed

Enhancements:

Full Changelog: v1.2...v1.2.1

v1.2

03 Jul 07:16
c2b5536
Compare
Choose a tag to compare

What's Changed

Features:

  • Add new heuristics for the download-executable module by @romain-dd in #214

Enhancements:

Bug fixes:

Chores:

New Contributors

Full Changelog: v1.1.4...v1.2

v1.1.4

30 Mar 10:57
f4cad6b
Compare
Choose a tag to compare

What's Changed

Minor enhancements and bug fixes:

  • Detect when join(...) is used in exec/eval/... functions by @romain-dd in #207
  • Bump tarsafe version to benefit from a performance improvement by @christophetd in #209
  • Allow specifying a location where to cache top packages by @christophetd in #213

Chores:

New Contributors

Full Changelog: v1.1.3...v1.1.4

v1.1.3

08 Mar 10:44
38105ae
Compare
Choose a tag to compare

What's Changed

Bug fixes:

  • Fix integrity rule crash when a project does not have a homepage URL set (#190) by @christophetd in #199
  • Fix 'potentially_compromised_email_domain' behavior when a package on… by @christophetd in #198

Chores:

Full Changelog: v1.1.2...v1.1.3

v1.1.2

02 Mar 20:28
4ae5645
Compare
Choose a tag to compare

What's Changed

Bug fixes:

  • Fix JSON output (#188)

Chores:

Full Changelog: v1.1.1...v1.1.2

v1.1.1

26 Feb 16:46
27ff024
Compare
Choose a tag to compare

What's Changed

Enhancements:

  • Catch code execution through exec(...(zlib.decompress(xxx)) by @christophetd in #164
  • Remove incorrect double quotes from semgrep rule for code-execution (closes #178) by @christophetd in #179

Bug fixes:

Chores:

Full Changelog: v1.1.0...v1.1.1

v1.1.0

15 Feb 07:47
91a35fb
Compare
Choose a tag to compare

What's Changed

New features:

  • Create new heuristic to identify PyPI packages with a single Python file (closes #160) by @christophetd in #162

Enhancements:

  • Catch dynamic execution of base64-encoded code through __import__ (fixes #157) by @christophetd in #158

Bug fixes:

Chores:

Full Changelog: v1.0.2...v1.1.0