Onefuzz

Latest version: v9.0.0

Safety actively analyzes 688365 Python packages for vulnerabilities to keep your Python projects secure.

Scan your dependencies

Page 10 of 18

2.29.1

Not secure
Fixed

* Agent: Fixed an issue with the "Premium" storage account utilities. [1111](https://github.com/microsoft/onefuzz/pull/1111)
* Agent: Addressed a rate-limiting issue when using `azcopy` from a large number of VMs with numbers cores. [1112](https://github.com/microsoft/onefuzz/pull/1112)

2.29.0

Not secure
Added

* Service: PII is now removed from Jobs, Tasks, and Repros after 18 months. [1051](https://github.com/microsoft/onefuzz/pull/1051)
* Service: Unused notifications are now removed after 18 months. [1051](https://github.com/microsoft/onefuzz/pull/1051)

Changed

* Service: SignalR events are routed through an Azure Storage Queue to prevent SignalR outages from impacting the entire service. [1100](https://github.com/microsoft/onefuzz/pull/1100), [#1102](https://github.com/microsoft/onefuzz/pull/1102)
* Service: Functionality used prior to 1.0.0 for assigning tasks to VMs rather than Pools is no longer supported. [1105](https://github.com/microsoft/onefuzz/pull/1105)
* Service: The `coverage` and `generic_generator` tasks now verify `{input}` is used in `target_env` or `target_options`. [1106](https://github.com/microsoft/onefuzz/pull/1106)

Fixed

* Service: Fixed an issue reimaging old nodes with `debug_keep_node` set. [1103](https://github.com/microsoft/onefuzz/pull/1103)
* Service: Fixed an issue authenticating to Azure services. [1099](https://github.com/microsoft/onefuzz/pull/1099)
* Service: Fixed an issue preventing Pools and Scalesets set to `shutdown` from being set to `halt`. [1104](https://github.com/microsoft/onefuzz/pull/1104)

2.28.0

Not secure
Added

* CLI: Added the ability to remove existing container notifications upon creating a notification integration. [1084](https://github.com/microsoft/onefuzz/pull/1084)
* CLI/Documentation: Added an example `generic_analysis` task that demonstrates collecting LLVM source-based coverage. [1072](https://github.com/microsoft/onefuzz/pull/1072)
* Supervisor: Added service-interaction resiliency for node commands. [1098](https://github.com/microsoft/onefuzz/pull/1098)

Changed

* Agent/Supervisor/Proxy: Addressed multiple new `cargo-clippy` warnings. [1089](https://github.com/microsoft/onefuzz/pull/1089)
* Agent: Added more context to errors in generator tasks. [1094](https://github.com/microsoft/onefuzz/pull/1094)
* Agent: Added support for ASAN runtime identification of format string bugs. [1093](https://github.com/microsoft/onefuzz/pull/1093)
* Agent: Added verification that `{input}` is provided to the application under test via `target_env` or `target_options`. [1097](https://github.com/microsoft/onefuzz/pull/1097)
* Agent: Continued development related to upcoming features. [1090](https://github.com/microsoft/onefuzz/pull/1090), [#1091](https://github.com/microsoft/onefuzz/pull/1091)
* CLI/Service: Updated multiple first-party and third-party Python dependencies. [1086](https://github.com/microsoft/onefuzz/pull/1086)
* CLI: Changed job templates to replace existing notifications for the unique report container. [1084](https://github.com/microsoft/onefuzz/pull/1084)
* Service: Added more context to Azure DevOps errors. [1082](https://github.com/microsoft/onefuzz/pull/1082)
* Service: Notification secrets are now deleted from Azure KeyVault upon notification deletion. [1085](https://github.com/microsoft/onefuzz/pull/1085)

Fixed

* Agent: Fixed an issue logging ASAN output upon ASAN log parse errors. [1092](https://github.com/microsoft/onefuzz/pull/1092)
* Agent: Fixed issues handling non-UTF8 output from applications under test. [1088](https://github.com/microsoft/onefuzz/pull/1088)

2.27.0

Not secure
Changed

* Agent: Batch processing results are now saved after every 10 executions. [1076](https://github.com/microsoft/onefuzz/pull/1076)
* Service: Optimized `file_added` event queueing by avoiding unnecessary Azure queries. [1075](https://github.com/microsoft/onefuzz/pull/1075)
* Agent: Optimized directory change monitoring. [1078](https://github.com/microsoft/onefuzz/pull/1078)
* Supervisor: Optimized agent monitoring. [1080](https://github.com/microsoft/onefuzz/pull/1080)

2.26.1

Not secure
Fixed

* CLI: Fixed an issue handling long-running requests. [1068](https://github.com/microsoft/onefuzz/pull/1068)
* CLI/Service: Fixed an issue related to upcoming features. [1067](https://github.com/microsoft/onefuzz/pull/1067)
* CLI: Fixed an issue handling `target_options` for libFuzzer jobs. [1066](https://github.com/microsoft/onefuzz/pull/1066)

2.26.0

Not secure
Added

* Supervisor: Added a `panic` handler to record supervisor failures. [1062](https://github.com/microsoft/onefuzz/pull/1062)

Changed

* Agent: Added more context to file upload errors. [1063](https://github.com/microsoft/onefuzz/pull/1063)
* CLI: Made errors locating `azcopy` more clear. [1061](https://github.com/microsoft/onefuzz/pull/1061)

Fixed

* Service: Fixed an issue where long-lived VM scaleset instances could get reimaged with out-of-date VM setup scripts. [1060](https://github.com/microsoft/onefuzz/pull/1060)
* Service: Fixed an issue where VM setup script updates were not always pushed. [1059](https://github.com/microsoft/onefuzz/pull/1059)

Page 10 of 18

© 2024 Safety CLI Cybersecurity Inc. All Rights Reserved.