Skip to content

Releases: AikidoSec/firewall-node

1.6.0-beta.6

24 Oct 13:53
582d667
Compare
Choose a tag to compare
1.6.0-beta.6 Pre-release
Pre-release
  • Add support for @graphql-tools/executor (used by GraphQL Yoga server)

1.6.0-beta.5

24 Oct 10:54
a0e3bc1
Compare
Choose a tag to compare
1.6.0-beta.5 Pre-release
Pre-release
  • Detect whether next is installed using env variable

1.6.0-beta.4

22 Oct 10:01
5b2a545
Compare
Choose a tag to compare
1.6.0-beta.4 Pre-release
Pre-release
  • Improve type definitions for setUser(...)
  • Add support for Fastify

1.6.0-beta.3

21 Oct 15:39
7df515d
Compare
Choose a tag to compare
1.6.0-beta.3 Pre-release
Pre-release
Merge pull request #424 from AikidoSec/patch-set-user

Log warning only once

1.6.0-beta.2

16 Oct 09:17
4eb25cb
Compare
Choose a tag to compare
1.6.0-beta.2 Pre-release
Pre-release
Merge pull request #417 from AikidoSec/patch-path

Avoid double wrapping path

1.6.0-beta.1

14 Oct 16:57
02ac426
Compare
Choose a tag to compare
1.6.0-beta.1 Pre-release
Pre-release
Merge pull request #324 from AikidoSec/new-hooks-system

Implement new hook system

1.6.0-beta.0

11 Oct 09:08
0719612
Compare
Choose a tag to compare
1.6.0-beta.0 Pre-release
Pre-release

1.5.70

08 Oct 11:35
e6b73a4
Compare
Choose a tag to compare
  • Improve metadata and stack traces for SSRF attacks
  • Improve route discovery
  • Improve path traversal detection (for absolute paths)
  • Improve file system functions coverage
  • Improve NoSQL detection
  • Introduce AIKIDO_DISABLE=1 to force disable firewall
  • Improve cookie parsing performance
  • Improve route matching

1.5.69

20 Sep 12:03
1bb57fd
Compare
Choose a tag to compare
  • Improvements for API discovery
  • Improvements for route generation from URL
  • Improvements for shell injection detection

1.5.68

18 Sep 09:53
006bad8
Compare
Choose a tag to compare
  • Improve accuracy using performance.now()
  • Ignore iss claim for JWT tokens
  • Check for path traversal in child_process.fork(...)
  • Improvements for API discovery