Kenneth Kehl
65ea248429
#446 remove crown
2023-04-13 07:13:04 -07:00
Ryan Ahearn
6587ed5223
Merge pull request #443 from GSA/redis-4.5.4
...
Update dependencies (Admin)
2023-03-29 17:02:17 -04:00
Ryan Ahearn
80184a98fd
Remove ignore-vulnerability line for remediated redis vuln
2023-03-29 16:55:42 -04:00
Ryan Ahearn
0120937777
Update dependencies
2023-03-29 16:55:18 -04:00
Ryan Ahearn
03321da575
Merge pull request #440 from GSA/ignore-known-redis-vuln
...
Ignore known issue with redis 4.5.3 (Admin)
2023-03-28 11:17:22 -04:00
Ryan Ahearn
1fe0ad0d83
Ignore known issue with redis 4.5.3
2023-03-28 09:16:09 -04:00
Ryan Ahearn
c11394b984
Merge pull request #439 from GSA/dependabot/pip/redis-4.5.3
...
Bump redis from 4.5.1 to 4.5.3
2023-03-28 08:27:56 -04:00
dependabot[bot]
8f754ab559
Bump redis from 4.5.1 to 4.5.3
...
Bumps [redis](https://github.com/redis/redis-py ) from 4.5.1 to 4.5.3.
- [Release notes](https://github.com/redis/redis-py/releases )
- [Changelog](https://github.com/redis/redis-py/blob/master/CHANGES )
- [Commits](https://github.com/redis/redis-py/compare/v4.5.1...v4.5.3 )
---
updated-dependencies:
- dependency-name: redis
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-03-27 21:48:03 +00:00
Ryan Ahearn
750961052d
Merge pull request #438 from GSA/update-terraform-triggers
...
Run terraform on deploy when shared modules change
2023-03-27 13:19:06 -04:00
Ryan Ahearn
d4397831fe
Run terraform on deploy when shared modules change
2023-03-27 08:52:07 -04:00
Ryan Ahearn
3223e417ff
Merge pull request #436 from GSA/restage-apps
...
Match prod space name to env name
2023-03-23 10:56:59 -04:00
Ryan Ahearn
804e53988a
Match prod space name to env name
2023-03-21 17:46:31 -04:00
Ryan Ahearn
300d26bc96
Merge pull request #435 from GSA/terraform-drift
...
Add terraform drift detector
2023-03-20 16:25:43 -04:00
Ryan Ahearn
d7b72bd3dc
Add terraform drift detector
2023-03-20 14:13:20 -04:00
Ryan Ahearn
e837879787
Merge pull request #420 from GSA/dev-infra-setup
...
Add scripts for provisioning admin development credentials
2023-03-15 16:44:08 -04:00
Ryan Ahearn
76c74ec392
Make sure we're in the correct directory
...
this will make relative paths and terraform find the correct files
2023-03-15 16:38:16 -04:00
Ryan Ahearn
e3610f7d9d
Address PR feedback
2023-03-14 16:00:40 -04:00
Ryan Ahearn
67b64f11b9
Use credentials output by terraform/development
2023-03-13 15:30:37 -04:00
Ryan Ahearn
e6f3bace40
Add terraform/development for retrieving credentials for local development use
2023-03-13 14:42:11 -04:00
Ryan Ahearn
c243b77ee1
Merge pull request #413 from GSA/remove-unsafe-csp
...
Remove unsafe rules from CSP
2023-03-08 10:57:41 -05:00
Ryan Ahearn
703847e184
Respect HTTP_PROTOCOL config when forcing https
2023-03-08 10:48:22 -05:00
Ryan Ahearn
bb77086342
Put default spark-bar-bar css in table.scss file
2023-03-08 09:17:31 -05:00
Ryan Ahearn
73a3511ef2
Remove uses of inline-styles
2023-03-08 09:08:07 -05:00
Ryan Ahearn
2a6bc62003
Use csp nonces for inline scripts and styles
2023-03-08 08:29:19 -05:00
Ryan Ahearn
e8e8c889d6
Add flask-talisman for security headers
2023-03-07 16:08:39 -05:00
Tim Lowden
218f0d0c85
Merge pull request #410 from GSA/em-herrick-patch-1
...
Update notify-pilot-info.md
2023-03-07 11:01:37 -05:00
Emily Herrick
2db1d26e32
Update notify-pilot-info.md
2023-03-07 10:55:47 -05:00
Steven Reilly
b3c358a8de
Merge pull request #402 from GSA/tdlowden-fixes-branch
...
Pricing page content updates
2023-03-01 11:21:43 -05:00
Tim Lowden
f4c122b9f6
Update index.html
2023-03-01 11:10:16 -05:00
Tim Lowden
1a6610c85a
Update index.html
2023-02-28 08:39:23 -05:00
Ryan Ahearn
276e96be42
Merge pull request #394 from GSA/dependabot/pip/markdown-it-py-2.2.0
...
Bump markdown-it-py from 2.1.0 to 2.2.0
2023-02-24 16:27:32 -05:00
dependabot[bot]
8aaa3665ed
Bump markdown-it-py from 2.1.0 to 2.2.0
...
Bumps [markdown-it-py](https://github.com/executablebooks/markdown-it-py ) from 2.1.0 to 2.2.0.
- [Release notes](https://github.com/executablebooks/markdown-it-py/releases )
- [Changelog](https://github.com/executablebooks/markdown-it-py/blob/master/CHANGELOG.md )
- [Commits](https://github.com/executablebooks/markdown-it-py/compare/v2.1.0...v2.2.0 )
---
updated-dependencies:
- dependency-name: markdown-it-py
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-02-23 20:08:58 +00:00
Ryan Ahearn
47828c35e2
Merge pull request #326 from GSA/tdlowden-guidance
...
Changes to guidance pages
2023-02-21 11:15:54 -05:00
Ryan Ahearn
2582dcccfb
Merge branch 'main' into tdlowden-guidance
...
* main: (21 commits)
Expect sms 2nd factor codes to be 6 digits
Bump werkzeug from 2.2.2 to 2.2.3
Switch egress proxy to official repo
Run pipenv update
Pin openpyxls to avoid bug between 3.1 and pyexcel-xlsx
Bump cryptography from 39.0.0 to 39.0.1
Remove direct use of aws creds from deployed environments
Add cf-cli version check to create_service_account
Tweak tail & jq usage to parse cf-cli@8 output
Load New Relic in manifest.yml startup command
Document how to retrieve NEW_RELIC_LICENSE_KEY for dev
Use main notifications-utils branch again
Remove wildcard matcher on egress allow
Update proxy settings to enable sending data to new relic
Updates for sandbox env
Fix header test
Configure egress proxy for new relic integration
Add newrelic to browser CSP directives
Validate new relic config in github actions
Report data to newrelic
...
2023-02-21 11:10:34 -05:00
Tim Lowden
cb8aeccb6d
Update index.html
...
per @rahearn catch
2023-02-21 11:02:06 -05:00
Ryan Ahearn
dfd0858980
Merge pull request #387 from GSA/increase-sms-code-length
...
Expect sms 2nd factor codes to be 6 digits
2023-02-17 13:18:55 -05:00
Ryan Ahearn
d9f1ee5af6
Expect sms 2nd factor codes to be 6 digits
2023-02-17 11:53:44 -05:00
Ryan Ahearn
ee2c3ebc27
Merge pull request #379 from GSA/dependabot/pip/werkzeug-2.2.3
...
Bump werkzeug from 2.2.2 to 2.2.3
2023-02-16 08:01:37 -05:00
dependabot[bot]
c5405d44e1
Bump werkzeug from 2.2.2 to 2.2.3
...
Bumps [werkzeug](https://github.com/pallets/werkzeug ) from 2.2.2 to 2.2.3.
- [Release notes](https://github.com/pallets/werkzeug/releases )
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst )
- [Commits](https://github.com/pallets/werkzeug/compare/2.2.2...2.2.3 )
---
updated-dependencies:
- dependency-name: werkzeug
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-02-16 07:35:35 +00:00
Ryan Ahearn
baf926f14d
Merge pull request #378 from GSA/utils-and-proxy-update
...
Utils lib and proxy deploy update
2023-02-14 16:50:13 -05:00
Ryan Ahearn
1ccdfebc08
Switch egress proxy to official repo
2023-02-14 12:20:10 -05:00
Ryan Ahearn
3ae078a976
Run pipenv update
2023-02-14 12:20:01 -05:00
Ryan Ahearn
396c2148a3
Merge pull request #367 from GSA/dependabot/pip/cryptography-39.0.1
...
Bump cryptography from 39.0.0 to 39.0.1
2023-02-08 10:58:32 -05:00
Ryan Ahearn
a08ddd83bb
Pin openpyxls to avoid bug between 3.1 and pyexcel-xlsx
2023-02-08 10:37:44 -05:00
dependabot[bot]
25e748ba9a
Bump cryptography from 39.0.0 to 39.0.1
...
Bumps [cryptography](https://github.com/pyca/cryptography ) from 39.0.0 to 39.0.1.
- [Release notes](https://github.com/pyca/cryptography/releases )
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/39.0.0...39.0.1 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-02-08 05:29:22 +00:00
Ryan Ahearn
05881827f9
Merge pull request #361 from GSA/remove-default-s3-creds
...
Remove direct use of aws creds from deployed environments
2023-02-03 12:39:12 -05:00
Ryan Ahearn
aa3043e8df
Remove direct use of aws creds from deployed environments
2023-02-01 11:57:59 -05:00
Ryan Ahearn
6682f306d7
Merge pull request #357 from GSA/cf-cli-8
...
Tweak tail & jq usage to parse cf-cli@8 output
2023-01-27 15:34:33 -05:00
Ryan Ahearn
873c9caf21
Add cf-cli version check to create_service_account
2023-01-27 14:54:29 -05:00
Ryan Ahearn
ff6ef9f26a
Tweak tail & jq usage to parse cf-cli@8 output
2023-01-27 14:28:17 -05:00