Aller au contenu principal

2 articles tagués avec « endpoint-protection »

Voir tous les tags

2026.9

Versioncalendar icon Release Date
2026.9.0September 25, 2026

System Requirements Update​

Ensure your infrastructure meets the latest requirements for optimal performance and security:

ComponentMinimum VersionRecommended Version
KOTS1.117.3Latest
Kubernetes1.301.35
PostgreSQL1517
Redis67
ggscout0.32.0Latest

The ggscout minimum moves to 0.32.0, the first version that classifies collected secrets with the Secrets Detection Engine. The chart ships 0.32.0; upgrade any ggscout you run outside the cluster.

Helm & Upgrade Considerations​

To ensure compatibility, please review Helm values updates from the previous version. Air gap deployment? Find all the images and tag names in the air gap install page.

Upgrading to 2026.9

Jira Data Center and Confluence Data Center: this release removes the system that renewed Personal Access Tokens on your behalf. Before upgrading, update the token of every Jira Data Center and Confluence Data Center integration, sources and notifiers alike, with a long-lived PAT. Update it in place from the integration settings, do not reinstall. An integration still relying on renewal stops working when its token expires. See the customer notice.

ClickHouse (Helm installations): ClickHouse is now rendered by the GitGuardian chart itself, under a single clickhouse.* key, instead of the vendored clickhouse-server subchart. If you enabled ClickHouse in 2026.8, move your clickhouse-server.* values to clickhouse.* before upgrading: the chart refuses to render while a clickhouse-server block is present. Object storage and backup settings are now structured under clickhouse.objectStorage and clickhouse.backup, and the clickhouse.serverConfig keys switch to camelCase. See ClickHouse storage and the Helm values changelog.

Argo CD installations: this release only creates the proxy Secrets, gim-proxy and gim-migration-proxy, when you actually set a proxy URL. Earlier releases created them on every install. If you do not use an outbound proxy, upgrading therefore leaves the old Secret behind, and Argo CD does not remove resources a chart has stopped rendering unless pruning is enabled. The sync ends with 1 resources require pruning and the application stays OutOfSync, even though its health is Healthy. Nothing is broken meanwhile, because the Secret is only ever read as an optional value. To settle the sync, prune once, either by enabling automated pruning on the application or by running argocd app sync <app> --prune.

Feature highlights​

  • AI Hooks for Codex and Mistral Vibe, and the AI agents and MCP inventory: AI Hooks now block secrets inside Codex and Mistral Vibe, alongside Claude Code, Cursor, Copilot CLI, and VS Code. The new inventory shows which AI agents and MCP servers run on each endpoint, whether hooks are installed, and whether an agent runs under a personal or a company subscription. The inventory is unlocked by the Endpoints entitlement of your license and requires ggshield 1.54.0 or later. Learn more.
  • Vaulted secrets classified by value: ggscout now runs the Secrets Detection Engine on every value it collects, so the NHI inventory can filter by detector, detector type, secret family, category, and provider. Requires ggscout 0.32.0 or later. Learn more.
  • Honeytoken protection on endpoints: ggshield plants a decoy AWS credential in the file credential-harvesting malware reads first, so any use of it raises an alert naming the compromised endpoint. A coverage card in the Endpoints dashboard tracks the share of your fleet that is protected. Requires Endpoint Protection, Honeytoken, and ClickHouse on your instance. Learn more.
  • GitGuardian Bridge on Self-Hosted: scan sources that live in an isolated network, such as a GitLab instance behind a firewall, without opening an inbound connection into it. You install the bridge server yourself, declare each bridge in your Helm values under GGBridge.bridges, and the bridge client inside the isolated network dials out to it. Learn more.

Secrets Detection Engine​

  • v2.170: 6 new detectors (Firebase ID Token, Coze Access Token, Keycloak Access Token, Keycloak Refresh Token, Fish Audio API Key, Azure Custom Vision Training Key), 8 improved detectors (Fastly Personal Token and Scaleway Token precision, Docker Hub personal access tokens used with docker login --username, revoked-key detection for the three New Relic checkers, Bitbucket Keys checker no longer reports invalid credentials as valid, Google OAuth2 Keys banlist), 1 new analyzer (Apify Token), 1 analyzer fix (Google Cloud Keys).
  • v2.171: 7 improved detectors (n8n API Key and n8n MCP Access Token host detection, Hashicorp Vault AppRole Authentication recall, Generic High Entropy Secret no longer reports variables ending in checksum, fixed Scaleway Token, Workato API Key and Open VSX Access Token checkers), 2 new analyzers (Akamai API Credentials, Docker Credentials), 3 analyzer updates (GitLab Token, Figma Personal Access Token, OpenAI API Key).

Enhancements​

  • SSO and SCIM sign-in now works when the identity provider supplies no first and last name, which are derived from the user's email address instead. Learn more.
  • Linked Jira tickets get comments for more incident events (reassignment, regression, validity, access grants and revocations, public sharing, feedback), per-team incident permissions can be set when promoting a user to Member, and the unhealthy integration banner shows only to managers and owners. Learn more.
  • Self-Hosted:
    • ClickHouse is now covered by the Admin Area Health check page, the admin banner, and the notification emails: reachability over HTTP, metadata volume fill level against a configurable threshold, and backup freshness read from the backup sidecar. When ClickHouse is down, only reachability turns red and the other two checks report the reason instead of guessing. Its logs and collectors are included in the support bundle, and the ClickHouse and backup sidecar Prometheus metrics come with recommended thresholds and alerts. ClickHouse remains optional in 2026.9. Learn more or see the health check page.
    • The in-app analytics job can write to PostgreSQL schemas you choose, through inAppAnalytics.postgresql.applicationSchema, useSeparateAnalyticsSchema and analyticsSchema, for databases that forbid the public schema or cannot grant CREATE to the GitGuardian user. Leaving them unset keeps the current layout. Learn more.
    • The support bundle pod can be scheduled with replicated.supportBundle.nodeSelector, tolerations and affinity, for example on tainted nodes, and the Admin Area now reports why a support bundle pod cannot be scheduled instead of waiting silently.
    • Your own MCP gateway can be registered as an OAuth callback through mcpServer.oauth.extraRedirectUris.
    • GitHub app installations made outside the dashboard, for example from the app's public GitHub page, no longer join the monitored perimeter on their own. They wait on the GitHub or GitHub Enterprise Server settings page until an Owner or a Manager approves or rejects them. Installations started from the dashboard are unaffected.
    • Validity checks can leave a detector's default host out and check secrets against your custom hosts only, which matters on air-gapped networks that cannot reach the vendor's public host. Learn more.

Fixes​

  • Invalid incidents that a playbook filter should have ignored are now ignored, missing scan statuses were added to the pygitguardian client and the API documentation, Jira Cloud recurrent scans no longer fail on multi-page issue listings, and an integration no longer remains out of sync after a GitHub outage. Learn more.
  • The revoke button is displayed again for revocable secrets to members with Full Access. Learn more.
  • Uninstalling a GitLab integration no longer fails. Learn more.
  • Source locations are no longer recomputed too frequently, which caused excessive repository clones and bandwidth usage. Learn more.
  • Self-Hosted:
    • ClickHouse pods failed to start with ImagePullBackOff because the volume-permissions init container image could not be pulled. The init container now uses the wolfi/bash image the chart already ships.
    • The MCP server image is pulled through the Replicated proxy like every other image, so proxy-only installs no longer need direct access to ghcr.io.
    • The chart no longer creates proxy Secrets on installs that set no proxy URL.
    • Loki queries no longer miss log lines. After a log rotation, gunicorn workers could keep writing to several log files at once while fluent-bit tailed only one of them. The log file is now rotated once across all forked workers.
    • Triggering an ML backpopulate scan from the Admin Area gives immediate feedback again, and the same run can no longer be started twice. This was a 2026.8.0 regression.
    • Endpoint scans sent by a newer ggshield are accepted even when they carry fields the server does not know yet, instead of being rejected.

2026.8

Versioncalendar icon Release Date
2026.8.0August 27, 2026
2026.8.1September 8, 2026

System Requirements Update​

Ensure your infrastructure meets the latest requirements for optimal performance and security:

ComponentMinimum VersionRecommended Version
KOTS1.117.3Latest
Kubernetes1.301.35
PostgreSQL1517
Redis67
ggscout0.19.0Latest

Helm & Upgrade Considerations​

To ensure compatibility, please review Helm values updates from the previous version. Air gap deployment? Find all the images and tag names in the air gap install page.

Feature highlights​

  • ClickHouse on Self-Hosted: a new optional, in-cluster column-oriented database that powers features needing fast analytics over large volumes of data, starting with Endpoint Protection. It is deployed as a single-node StatefulSet backed by object storage you provide (S3-compatible, with Azure Blob Storage and GCS in progress), ships a clickhouse-backup sidecar for scheduled backups, and is available on both Helm and KOTS installs. PostgreSQL remains the primary datastore for the rest of the application. ClickHouse is optional in 2026.8 and becomes mandatory in 2027.1.0. Learn more or read the customer notice.
  • GitHub check runs page: a dedicated Check runs page in the Perimeter section brings every check run into the dashboard with its status, repository, commit, and linked pull request. Filter and search across hundreds of thousands of runs, re-run or skip a check without switching to GitHub, and jump straight to the incidents a run detected. Learn more.
  • Mention members and teams in incident notes: type @ in an incident note or feedback to mention a member or a whole team and notify them by email, on both Internal Monitoring and Public Monitoring incidents. Learn more.
  • Set your own validity status by API: run the validity check yourself on the internal systems GitGuardian cannot reach, then send valid or invalid back with one API call. Incidents display Custom validity with the date it was set, and the change is recorded in the incident activity log and your audit log. Learn more.
  • A smarter search bar: the unified filter bar is now enabled on self-hosted, letting you find incidents by secret value, commit author, or file path. Plain-English search (AI Filters) is included for self-hosted, but it only becomes available once a workspace administrator turns on the External LLM toggle under Settings > Workspace > AI and an LLM provider is reachable. Learn more or see AI Settings.

Secrets Detection Engine​

  • v2.167: 11 new detectors (Azure SQL Credentials, Azure Machine Learning Key, Azure Video Indexer Key, Azure Health Insights Key, Azure Fluid Relay Key, LiteLLM API Key, DashScope API Key, Apify Proxy Token, Authress Access Key, and two Gemfury token variants), 3 improved detectors (Datadog API Credentials, Snyk Key, Okta Token with Host), 6 new or upgraded checkers (LiteLLM Without Host, LaunchDarkly SDK Key, Llama Cloud API Key, New Relic APM License Key, npm Token, Hume AI API Key), 1 analyzer fix (Figma Personal Access Token).
  • v2.168: 4 new detectors (Azure Immersive Reader Key, DashScope Coding Plan API Key, DashScope Token Plan API Key, Prefect Cloud API Key), 2 new checkers (Alibaba Cloud IAM, GitLab Deploy Token), 7 improved detectors (Generic High Entropy Secret, Okta Token with Host, and HTML/Markdown scanning extended to npm, GitHub Personal Access, GitHub OAuth, GitHub App and Slack Application tokens), 2 hardened checkers (Auth0 Keys, Microsoft Power Apps Webhook).
  • v2.169: 7 new detectors (Slack Webhook Trigger URL, n8n API Key, Atlassian Auth Key, AWS Cognito Access Token, OpenAI Access Token, Vercel OIDC Token, OpenCode API Key), 1 new checker (Supabase Service Role JWT), 15 improved detectors (GitHub and npm format validation, Generic Password, Generic High Entropy Secret, AWS IAM Keys, PostgreSQL Credentials, Azure Event Hub and Service Bus checkers, and more), 4 analyzer fixes (GitHub Enterprise custom host URLs, Google API Key 403 handling), 1 removed (Grafbase Access Token) and 1 disabled (Amadeus OAuth Credentials) as both services were discontinued.
  • v2.169.1: 2 new detectors (Lovable Access Token, Lovable Git Token), and 4 improved detectors, where values failing format validation are no longer reported by generic detectors for GitHub Personal Access, GitHub OAuth, GitHub App and npm tokens.

Enhancements​

  • Fine-grained GitHub personal access for private members monitoring (Public Monitoring perimeter); removal of the Display as Tree view from integration source pages for better performance on large perimeters. Learn more.
  • Personal Access Tokens and Service Account Tokens can now be created through the public API for automated rotation workflows, automatic monitoring and automatic scan toggles reached Jira Cloud, Jira Data Center, Confluence Cloud, Confluence Data Center and Microsoft Teams, and a new Azure DevOps extension adds a ggshield scan job to every pipeline in an organization with a single pipeline decorator. Learn more.
  • The "Only use detectors with validators" option is now settable on custom sources through the public API, and tooltips on disabled source actions explain why monitoring, criticality, or team assignment is unavailable. Learn more.
  • Self-Hosted: Added tunable emptyDir volume limits for the ml-secret-engine pod in the Helm chart.

Fixes​

  • Multi-factor authentication emails now reach users who were globally unsubscribed in the email delivery system, push events no longer trigger a full repository clone when cached data is available, the Slack integration no longer monitors channels that were not manually added when auto-monitor is off, and incident feedback mentions display the member's name instead of a raw identifier. Learn more.
  • Scans triggered via a Personal Access Token now emit an audit log event, the "Edit issue" dialog no longer closes unexpectedly, notifier team names are populated on workspaces with more than 100 teams, deactivated members no longer appear in the grant access dialog, a disabled detector can no longer block a pull request through GitHub check runs, the JFrog Container Registry reachability check now routes through ggbridge, GitLab sources marked as monitored are reflected in the perimeter view, and the decoded claims panel of a JWT secret no longer breaks on malformed claims. Learn more.
  • A missing endpoint was added to the OpenAPI specification, incident IDs are displayed in the ID column again, an off-by-one issue in the dashboard date filter was corrected, and bulk scan requests no longer fail when enqueuing a very large number of sources at once. Learn more.
  • Self-Hosted:
    • Celery worker pods failed their liveness and readiness probes on FIPS images and never reached a ready state, which blocked the deployment from completing.
    • The in-app analytics dashboards no longer query Public Monitoring data or report a monitored perimeter developer count on self-hosted instances, where neither is applicable.

Hotfixes​

2026.8.1​

calendar icon   Release Date: September 8, 2026

Enhancements​

  • NHI Governance: AWS access keys stored in a secrets manager, Vault, or Kubernetes are now linked to their AWS IAM identity in the identity map.

Fixes​

  • Validity checks: validity check results and incident creation events are now processed as soon as they arrive on self-hosted instead of piling up.
  • Images versions: Basalt 0.8.1 and Loki 3.7.7 bumps, see the air gap install page for the updated tags.