Commit Graph

13051 Commits

Author SHA1 Message Date
Kenneth Kehl
65ea248429 #446 remove crown 2023-04-13 07:13:04 -07:00
Ryan Ahearn
6587ed5223 Merge pull request #443 from GSA/redis-4.5.4
Update dependencies (Admin)
2023-03-29 17:02:17 -04:00
Ryan Ahearn
80184a98fd Remove ignore-vulnerability line for remediated redis vuln 2023-03-29 16:55:42 -04:00
Ryan Ahearn
0120937777 Update dependencies 2023-03-29 16:55:18 -04:00
Ryan Ahearn
03321da575 Merge pull request #440 from GSA/ignore-known-redis-vuln
Ignore known issue with redis 4.5.3 (Admin)
2023-03-28 11:17:22 -04:00
Ryan Ahearn
1fe0ad0d83 Ignore known issue with redis 4.5.3 2023-03-28 09:16:09 -04:00
Ryan Ahearn
c11394b984 Merge pull request #439 from GSA/dependabot/pip/redis-4.5.3
Bump redis from 4.5.1 to 4.5.3
2023-03-28 08:27:56 -04:00
dependabot[bot]
8f754ab559 Bump redis from 4.5.1 to 4.5.3
Bumps [redis](https://github.com/redis/redis-py) from 4.5.1 to 4.5.3.
- [Release notes](https://github.com/redis/redis-py/releases)
- [Changelog](https://github.com/redis/redis-py/blob/master/CHANGES)
- [Commits](https://github.com/redis/redis-py/compare/v4.5.1...v4.5.3)

---
updated-dependencies:
- dependency-name: redis
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-03-27 21:48:03 +00:00
Ryan Ahearn
750961052d Merge pull request #438 from GSA/update-terraform-triggers
Run terraform on deploy when shared modules change
2023-03-27 13:19:06 -04:00
Ryan Ahearn
d4397831fe Run terraform on deploy when shared modules change 2023-03-27 08:52:07 -04:00
Ryan Ahearn
3223e417ff Merge pull request #436 from GSA/restage-apps
Match prod space name to env name
2023-03-23 10:56:59 -04:00
Ryan Ahearn
804e53988a Match prod space name to env name 2023-03-21 17:46:31 -04:00
Ryan Ahearn
300d26bc96 Merge pull request #435 from GSA/terraform-drift
Add terraform drift detector
2023-03-20 16:25:43 -04:00
Ryan Ahearn
d7b72bd3dc Add terraform drift detector 2023-03-20 14:13:20 -04:00
Ryan Ahearn
e837879787 Merge pull request #420 from GSA/dev-infra-setup
Add scripts for provisioning admin development credentials
2023-03-15 16:44:08 -04:00
Ryan Ahearn
76c74ec392 Make sure we're in the correct directory
this will make relative paths and terraform find the correct files
2023-03-15 16:38:16 -04:00
Ryan Ahearn
e3610f7d9d Address PR feedback 2023-03-14 16:00:40 -04:00
Ryan Ahearn
67b64f11b9 Use credentials output by terraform/development 2023-03-13 15:30:37 -04:00
Ryan Ahearn
e6f3bace40 Add terraform/development for retrieving credentials for local development use 2023-03-13 14:42:11 -04:00
Ryan Ahearn
c243b77ee1 Merge pull request #413 from GSA/remove-unsafe-csp
Remove unsafe rules from CSP
2023-03-08 10:57:41 -05:00
Ryan Ahearn
703847e184 Respect HTTP_PROTOCOL config when forcing https 2023-03-08 10:48:22 -05:00
Ryan Ahearn
bb77086342 Put default spark-bar-bar css in table.scss file 2023-03-08 09:17:31 -05:00
Ryan Ahearn
73a3511ef2 Remove uses of inline-styles 2023-03-08 09:08:07 -05:00
Ryan Ahearn
2a6bc62003 Use csp nonces for inline scripts and styles 2023-03-08 08:29:19 -05:00
Ryan Ahearn
e8e8c889d6 Add flask-talisman for security headers 2023-03-07 16:08:39 -05:00
Tim Lowden
218f0d0c85 Merge pull request #410 from GSA/em-herrick-patch-1
Update notify-pilot-info.md
2023-03-07 11:01:37 -05:00
Emily Herrick
2db1d26e32 Update notify-pilot-info.md 2023-03-07 10:55:47 -05:00
Steven Reilly
b3c358a8de Merge pull request #402 from GSA/tdlowden-fixes-branch
Pricing page content updates
2023-03-01 11:21:43 -05:00
Tim Lowden
f4c122b9f6 Update index.html 2023-03-01 11:10:16 -05:00
Tim Lowden
1a6610c85a Update index.html 2023-02-28 08:39:23 -05:00
Ryan Ahearn
276e96be42 Merge pull request #394 from GSA/dependabot/pip/markdown-it-py-2.2.0
Bump markdown-it-py from 2.1.0 to 2.2.0
2023-02-24 16:27:32 -05:00
dependabot[bot]
8aaa3665ed Bump markdown-it-py from 2.1.0 to 2.2.0
Bumps [markdown-it-py](https://github.com/executablebooks/markdown-it-py) from 2.1.0 to 2.2.0.
- [Release notes](https://github.com/executablebooks/markdown-it-py/releases)
- [Changelog](https://github.com/executablebooks/markdown-it-py/blob/master/CHANGELOG.md)
- [Commits](https://github.com/executablebooks/markdown-it-py/compare/v2.1.0...v2.2.0)

---
updated-dependencies:
- dependency-name: markdown-it-py
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-02-23 20:08:58 +00:00
Ryan Ahearn
47828c35e2 Merge pull request #326 from GSA/tdlowden-guidance
Changes to guidance pages
2023-02-21 11:15:54 -05:00
Ryan Ahearn
2582dcccfb Merge branch 'main' into tdlowden-guidance
* main: (21 commits)
  Expect sms 2nd factor codes to be 6 digits
  Bump werkzeug from 2.2.2 to 2.2.3
  Switch egress proxy to official repo
  Run pipenv update
  Pin openpyxls to avoid bug between 3.1 and pyexcel-xlsx
  Bump cryptography from 39.0.0 to 39.0.1
  Remove direct use of aws creds from deployed environments
  Add cf-cli version check to create_service_account
  Tweak tail & jq usage to parse cf-cli@8 output
  Load New Relic in manifest.yml startup command
  Document how to retrieve NEW_RELIC_LICENSE_KEY for dev
  Use main notifications-utils branch again
  Remove wildcard matcher on egress allow
  Update proxy settings to enable sending data to new relic
  Updates for sandbox env
  Fix header test
  Configure egress proxy for new relic integration
  Add newrelic to browser CSP directives
  Validate new relic config in github actions
  Report data to newrelic
  ...
2023-02-21 11:10:34 -05:00
Tim Lowden
cb8aeccb6d Update index.html
per @rahearn catch
2023-02-21 11:02:06 -05:00
Ryan Ahearn
dfd0858980 Merge pull request #387 from GSA/increase-sms-code-length
Expect sms 2nd factor codes to be 6 digits
2023-02-17 13:18:55 -05:00
Ryan Ahearn
d9f1ee5af6 Expect sms 2nd factor codes to be 6 digits 2023-02-17 11:53:44 -05:00
Ryan Ahearn
ee2c3ebc27 Merge pull request #379 from GSA/dependabot/pip/werkzeug-2.2.3
Bump werkzeug from 2.2.2 to 2.2.3
2023-02-16 08:01:37 -05:00
dependabot[bot]
c5405d44e1 Bump werkzeug from 2.2.2 to 2.2.3
Bumps [werkzeug](https://github.com/pallets/werkzeug) from 2.2.2 to 2.2.3.
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](https://github.com/pallets/werkzeug/compare/2.2.2...2.2.3)

---
updated-dependencies:
- dependency-name: werkzeug
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-02-16 07:35:35 +00:00
Ryan Ahearn
baf926f14d Merge pull request #378 from GSA/utils-and-proxy-update
Utils lib and proxy deploy update
2023-02-14 16:50:13 -05:00
Ryan Ahearn
1ccdfebc08 Switch egress proxy to official repo 2023-02-14 12:20:10 -05:00
Ryan Ahearn
3ae078a976 Run pipenv update 2023-02-14 12:20:01 -05:00
Ryan Ahearn
396c2148a3 Merge pull request #367 from GSA/dependabot/pip/cryptography-39.0.1
Bump cryptography from 39.0.0 to 39.0.1
2023-02-08 10:58:32 -05:00
Ryan Ahearn
a08ddd83bb Pin openpyxls to avoid bug between 3.1 and pyexcel-xlsx 2023-02-08 10:37:44 -05:00
dependabot[bot]
25e748ba9a Bump cryptography from 39.0.0 to 39.0.1
Bumps [cryptography](https://github.com/pyca/cryptography) from 39.0.0 to 39.0.1.
- [Release notes](https://github.com/pyca/cryptography/releases)
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/39.0.0...39.0.1)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-02-08 05:29:22 +00:00
Ryan Ahearn
05881827f9 Merge pull request #361 from GSA/remove-default-s3-creds
Remove direct use of aws creds from deployed environments
2023-02-03 12:39:12 -05:00
Ryan Ahearn
aa3043e8df Remove direct use of aws creds from deployed environments 2023-02-01 11:57:59 -05:00
Ryan Ahearn
6682f306d7 Merge pull request #357 from GSA/cf-cli-8
Tweak tail & jq usage to parse cf-cli@8 output
2023-01-27 15:34:33 -05:00
Ryan Ahearn
873c9caf21 Add cf-cli version check to create_service_account 2023-01-27 14:54:29 -05:00
Ryan Ahearn
ff6ef9f26a Tweak tail & jq usage to parse cf-cli@8 output 2023-01-27 14:28:17 -05:00