Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[pull] master from MobSF:master #383

Open
wants to merge 231 commits into
base: master
Choose a base branch
from
Open

Conversation

pull[bot]
Copy link

@pull pull bot commented Oct 11, 2021

See Commits and Changes for more details.


Created by pull[bot]

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull bot added the ⤵️ pull label Oct 11, 2021
ajinabraham and others added 27 commits October 11, 2021 23:52
Landscape-oriented pages make the results more legible in the generated PDF

Co-authored-by: Ajin Abraham <ajin25@gmail.com>
Fix non-working PATH environment variable in Dockerfile  (#1840)
* update apktool to 2.6.0

* update frida to 15.1.6

Co-authored-by: Ajin Abraham <ajin25@gmail.com>
* Add --no-cache-dir to pip install

* Add --no-cache-dir to pip install in install_java_wkhtmltopdf.sh
* update apktool to 2.6.0
#1812)

* Run service as unprivileged user

* Update Dockerfile

Co-authored-by: superpoussin22 <vincent.nadal@orange.fr>
Co-authored-by: Ajin Abraham <ajin25@gmail.com>
This change to the setup.sh  adds the wheel package which is necessary for correct installation of some packages such as Frida on linux installations.

Co-authored-by: Ajin Abraham <ajin25@gmail.com>
* Py deps update and QA
* lint fix
* Modify cert_analysis - Janus

Updated the Janus Vulnerability to reflect the difference cases.

Co-authored-by: Th30 <theo.dm@gmail.com>
* Initial commit - Activity launcher
* Fixed broken OpenSSL link
* Various fixes to activity launcher
* disable dynamic report button when does not exist
* Small fixes after CR
* QA
* the setting ACTIVITY_TESTER_SLEEP is not available for old users
* QA + REST API
Co-authored-by: matan.dobr <matan.dobr@otorio.com>
Co-authored-by: Ajin Abraham <ajin25@gmail.com>
Co-authored-by: Ajin Abraham <ajinabraham@C-C02G30P9MD6R.chime.local>
* Upgrade Quark Version

* suppress unnecessary print()

* suppress androguard warnings

* fix wkhtmltopdf in windows

* Remove version string
Co-authored-by: Haeter <3461569+haeter525@users.noreply.github.com>
Co-authored-by: Haeter <3461569+haeter525@users.noreply.github.com>
Co-authored-by: Ajin Abraham <ajin25@gmail.com>
* MobSF Application Security Score Card
* Scorecard API
* Improved App Security Scoring Mechanism
* Improved PDF Report
* Disable CVSSv2 by default. 
* For application security use case, use severity levels High, Warning, Low and Secure across all components applicable.
* Non blocking upload flow.
* Fixes #1885
miaoyc666 and others added 30 commits April 3, 2024 16:43
 Authentication and Authorization (`Maintainer` , Viewer`) support in MobSF
* Basic User Management
* Bug Fixes in Runtime Executable Tampering
* Ratelimiting support for login endpoint
* Disable AuthZ/AuthN for REST API and also via ENV VAR `MOBSF_DISABLE_AUTHENTICATION=1`
* Bug Fix #2285 
* Bug Fix Icon Analysis Nonetype
* Update SSRF Filter
* Dependency Bump
* Beta to Stable release from V4
* Runs with DEBUG=False
* New home screen UI
* Add support for SSO with SAML2.0
* Bump Deps
* Docs Updated
* Bump MobSF version
* Added support for proxy setup and custom SP host
* AAB to APK conversion
* relative urls fix for recent scan
* QA
* Add new android rule setAllow*FromFileURLs
* android root bypass and debugger bypass scripts improvements
* Dockerfile qa
* prevent entrypoint exit if username already exists
…c Analyzer (#2402)

* iOS  Dynamic Analyzer String Compare Frida script improvement
* Android Dynamic Analyzer Deeplink UI trigger support 
* Android & iOS Dynamic Analyzer UI Improvements
* Android & iOS Dynamic Analyzer Bug fixes
* Realtime Scan Status in UI and PDF reports
* Scan Status REST API & tests
* Fixes #2414
* Address #2413
* Code QA
* Dependency and version bump
* Fixes GHSA-4hh3-vj32-gr6j
* update SECURITY.md
* update dependencies
* Check for internet before attempting to download APK
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.