Repository navigation
chore(deps): update dependency mongodb/kingfisher to v2.11.1 - #506
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.9.1→v2.11.1v2.10.0→v2.11.1Note: The
pre-commitmanager in Renovate is not supported by thepre-commitmaintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.Release Notes
mongodb/kingfisher (mongodb/kingfisher)
v2.11.1Compare Source
kingfisherpackage name and replacing misnamed packages.v2.11.0Compare Source
Handled malformed Git tree modes without panics, guarded staged tree ancestry, normalized legacy index modes, and avoided revisiting reachable commits when including unreachable objects.
Propagated strict archive member errors, removed partial ZIP/TAR files, preserved TAR/ZIP bytes when no output directory is supplied, and bounded best-effort SQLite schema listing with skipped-table warnings.
Pruned stale compiled-cache temporary files, preserved existing entries when replacement fails, reported cache rejection reasons once per process, and bound line-filter cache keys to source identity without cloning patterns on hits.
Validated Python archive/content options eagerly, excluded case variants of
.git, rejected unrepresentable Git hour bounds, and clarified extraction budgets and format-specific entry accounting.Preserved separately encoded secrets in nested Base64 siblings by scoping CLI and SDK containment checks to each decoded buffer.
Refreshed the Betterleaks catalog to v2.0.0-rc.1,
adding Bitbucket Data Center HTTP access tokens, Cloudflare
cfut_/cfat_tokens and theiraccount-ID helper, and fixing Tableau personal access tokens beginning with
+or/.The legacy Cloudflare rule is now
betterleaks.cloudflare-api-key.1; the family selectorcontinues to cover both formats. Updated expression-helper support preserves upstream
validation checks. Built-in coverage is now 488 rules (462 Betterleaks and 26 Veles),
with 255 supporting validation. Regenerated the bundle, provenance, source archive, and docs.
Preserved every repeated TAR member during extraction and made SDK compressed-stream budget exhaustion fail before returning partial archive members.
Reused compiled rule caches across compatible deployments with exact engine build identity and automatic recompilation on native CPU/version rejection. #538
Enabled Python SDK caching by default with
Rules(cache_dir=...)andRules(cache=False)controls.Fixed SDK lazy-span scan slowdowns (up to 50× faster) without changing findings. #536
Fixed dense-finding scan slowdowns in regex confirmation, catalog/component matching, URI overlap, and inline-ignore checks. #537
Improved dense scans with long lines, chained components, Base64 URIs, and HTML/CSS; fixed inconsistent source locations.
Added regression benchmarks: up to 144× faster SDK and 74× faster CLI on the issue reproducer, with unchanged finding counts and comparable or improved repository and Git-history scan times.
Added composable Python filesystem and Git-history enumeration through
ScanInput,filesystem(),git_history(), andScanner.scan_inputs(). Callers can supply their own Python iterators or use native enumeration without changing existing SDK signatures or behavior.Added explicit Python archive expansion with shared CLI extractors, nested-depth and per-root budgets, cooperative controls, and source/Git metadata retained with each findings group.
Added commented Python examples for filesystem enumeration, native versus Python-managed Git history, and archive scanning from files or bytes; documented composition, limits, and validation grouping.
Preserved invalid UTF-8 secrets during HTML/CSS context filtering in the CLI and SDK.
Added opt-in Python
DetectionScannerand Rust detection options for shared CLI confirmation/component-window semantics, credential-URI fallback and secret containment suppression, bounded two-level Base64 decoding, inline-ignore and HTML/CSS context filtering. Existing SDK signatures and defaults remain unchanged.Isolated new CLI helper APIs behind explicitly unstable features, kept optimized confirmation state opaque, and preserved exhaustive matches of the existing embedding confirmation enum.
Added CLI/SDK parity, nested Base64 limit, full-match component-anchor, and context-phase interruption regressions; interrupted scans return no partial findings or dedup commits.
Added composable
expand_content()for shared SQLite SQL and Python bytecode string extraction from files, historical blobs and archive members, with source provenance, per-input budgets and controls retained.Added native
git_inputs()withGitScopehistory baselines, inclusive branch roots, time windows, snapshots, net diffs, staged index content and unreachable object coverage;GitInputretains multiple scoped occurrences, author/committer identities and times, parents and messages without modifying repositories.Added commented detection, SQLite/bytecode and Git-scope examples, contract/regression tests and updated SDK/Rust documentation.
Added frozen Python
DetectionPolicyconfiguration, direct native finding properties and structured result conversion, and scanning of borrowed Python bytes.Improved dense multiline credential scanning by reusing confirmed matches while preserving capture values and offsets.
Shared native Git scope enumeration with the Rust library, skipped unchanged subtrees, shared commit metadata, and added blob/preparation limits, non-UTF-8 path provenance and explicit missing-object handling.
Enforced nested extraction budgets while writing, hardened SQLite parsing, supported temporary-directory selection and reported malformed-content fallback diagnostics. Corrected Python 3.11+ marshal code-object parsing and handled Python 3.14 slice constants.
Added cancellable validation/revocation batch deadlines, Ctrl-C handling and safe revocation error categories.
Hardened compiled cache ownership/permissions and payload integrity, removed the shared temporary fallback, and preserved exact native engine build identity.
Bumped
kingfisher-coreto 1.0.3,kingfisher-rulesto 1.2.0 andkingfisher-scannerand Python SDK to 1.3.0.v2.10.0Compare Source
KF_GIT_BINARY,KF_GIT_SSL_BACKEND, and Git for Windows CI coverage.nightly-2026-10-02; added latest-stable CI coverage. Minimum Rust is now 1.99.kingfisher-core1.0.2,kingfisher-rules1.1.0,kingfisher-scanner1.2.0, and Python SDK 1.1.0 for the toolchain, matching, and embedding updates.gixfor faster repository audit metadata.Configuration
📅 Schedule: (UTC)
* * * * 6)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.