Skip to content

Commit f5c05ec

Browse files
authored
Merge pull request #1274 from zapbot/add-on-release
Release add-on(s)
2 parents 2417cae + 2f68475 commit f5c05ec

File tree

2 files changed

+158
-114
lines changed

2 files changed

+158
-114
lines changed

ZapVersions-2.16.xml

Lines changed: 79 additions & 57 deletions
Original file line numberDiff line numberDiff line change
@@ -227,31 +227,41 @@
227227
<name>Active scanner rules (beta)</name>
228228
<description>The beta status Active Scanner rules</description>
229229
<author>ZAP Dev Team</author>
230-
<version>56</version>
231-
<file>ascanrulesBeta-beta-56.zap</file>
230+
<version>57</version>
231+
<file>ascanrulesBeta-beta-57.zap</file>
232232
<status>beta</status>
233233
<changes>&lt;h3&gt;Changed&lt;/h3&gt;
234234
&lt;ul&gt;
235-
&lt;li&gt;Log exception details in Out of Band XSS scan rule.&lt;/li&gt;
236-
&lt;li&gt;Maintenance changes.&lt;/li&gt;
237-
&lt;li&gt;The Anti-CSRF Tokens Check scan rule now only considers GET requests at Low Threshold (Issue 7741).&lt;/li&gt;
235+
&lt;li&gt;Update minimum ZAP version to 2.16.0.&lt;/li&gt;
236+
&lt;li&gt;The following scan rules now use more specific CWE IDs:
237+
&lt;ul&gt;
238+
&lt;li&gt;Proxy Disclosure (Issue 8713)&lt;/li&gt;
239+
&lt;li&gt;Possible Username Enumeration (Issue 8715)&lt;/li&gt;
240+
&lt;/ul&gt;
241+
&lt;/li&gt;
242+
&lt;li&gt;Remove double dot in skipped message of scan rules that use the Active Scan OAST service.&lt;/li&gt;
238243
&lt;/ul&gt;
239244
&lt;h3&gt;Fixed&lt;/h3&gt;
240245
&lt;ul&gt;
241-
&lt;li&gt;Address time-based false positives in Remote Code Execution - Shell Shock scan rule (Issue 8516).&lt;/li&gt;
246+
&lt;li&gt;Address exception when scanning a message without path with Possible Username Enumeration scan rule.&lt;/li&gt;
247+
&lt;li&gt;The WSTG alert tags on the HTTP Only Site scan rule.&lt;/li&gt;
248+
&lt;/ul&gt;
249+
&lt;h3&gt;Added&lt;/h3&gt;
250+
&lt;ul&gt;
251+
&lt;li&gt;Standardized Scan Policy related alert tags on various rules.&lt;/li&gt;
242252
&lt;/ul&gt;</changes>
243-
<url>https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesBeta-v56/ascanrulesBeta-beta-56.zap</url>
244-
<hash>SHA-256:e6dd4dc66fe79f192fae8e336e1708ca710eac190a04c79f1cd01e3fa9f2432c</hash>
253+
<url>https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesBeta-v57/ascanrulesBeta-beta-57.zap</url>
254+
<hash>SHA-256:d2574f4a79137a5d3d0b1bb82563863a8c414bd13c9ef42e0084090e37337b03</hash>
245255
<info>https://www.zaproxy.org/docs/desktop/addons/active-scan-rules-beta/</info>
246256
<repo>https://github.com/zaproxy/zap-extensions/</repo>
247-
<date>2024-09-24</date>
248-
<size>1768903</size>
249-
<not-before-version>2.15.0</not-before-version>
257+
<date>2025-01-15</date>
258+
<size>1777403</size>
259+
<not-before-version>2.16.0</not-before-version>
250260
<dependencies>
251261
<addons>
252262
<addon>
253263
<id>commonlib</id>
254-
<version>&gt;= 1.17.0 &amp; &lt; 2.0.0</version>
264+
<version>&gt;= 1.29.0 &amp; &lt; 2.0.0</version>
255265
</addon>
256266
<addon>
257267
<id>database</id>
@@ -736,45 +746,41 @@ to find and add subdomains to the Sites Tree.&lt;/li&gt;
736746
<name>Custom Payloads</name>
737747
<description>Ability to add, edit or remove payloads that are used i.e. by active scanners</description>
738748
<author>ZAP Dev Team</author>
739-
<version>0.13.0</version>
740-
<file>custompayloads-beta-0.13.0.zap</file>
741-
<status>beta</status>
749+
<version>0.14.0</version>
750+
<file>custompayloads-release-0.14.0.zap</file>
751+
<status>release</status>
742752
<changes>&lt;h3&gt;Changed&lt;/h3&gt;
743753
&lt;ul&gt;
744-
&lt;li&gt;Update minimum ZAP version to 2.14.0.&lt;/li&gt;
754+
&lt;li&gt;Promoted to Release status.&lt;/li&gt;
755+
&lt;li&gt;Update minimum ZAP version to 2.16.0.&lt;/li&gt;
745756
&lt;li&gt;Maintenance changes.&lt;/li&gt;
746-
&lt;li&gt;Promoted to Beta.&lt;/li&gt;
757+
&lt;li&gt;The superfluous/unused ID element of the custom payloads has been removed from the GUI and config.&lt;/li&gt;
758+
&lt;li&gt;Now depends on the Common Library add-on.&lt;/li&gt;
747759
&lt;/ul&gt;
748760
&lt;h3&gt;Added&lt;/h3&gt;
749761
&lt;ul&gt;
750-
&lt;li&gt;Initial API support:
751-
&lt;ul&gt;
752-
&lt;li&gt;Actions
753-
&lt;ul&gt;
754-
&lt;li&gt;Enable payloads.&lt;/li&gt;
755-
&lt;li&gt;Disable payloads.&lt;/li&gt;
756-
&lt;li&gt;Enable payload.&lt;/li&gt;
757-
&lt;li&gt;Disable payload.&lt;/li&gt;
758-
&lt;li&gt;Add payload.&lt;/li&gt;
759-
&lt;li&gt;Remove payload.&lt;/li&gt;
762+
&lt;li&gt;Add help button to Options panel and add further detailed Help content.&lt;/li&gt;
760763
&lt;/ul&gt;
761-
&lt;/li&gt;
762-
&lt;li&gt;Views:
764+
&lt;h3&gt;Fixed&lt;/h3&gt;
763765
&lt;ul&gt;
764-
&lt;li&gt;Payload categories.&lt;/li&gt;
765-
&lt;li&gt;Payloads (optionally filtered by category).&lt;/li&gt;
766-
&lt;/ul&gt;
767-
&lt;/li&gt;
768-
&lt;/ul&gt;
769-
&lt;/li&gt;
766+
&lt;li&gt;The add-on will no longer attempt to save or load Payloads for which there is no Category.&lt;/li&gt;
767+
&lt;li&gt;Ensure file is selected, exists, and is readable when attempting to import multiple payloads.&lt;/li&gt;
770768
&lt;/ul&gt;</changes>
771-
<url>https://github.com/zaproxy/zap-extensions/releases/download/custompayloads-v0.13.0/custompayloads-beta-0.13.0.zap</url>
772-
<hash>SHA-256:07c571e121291980add70fad1b64933382742e93959c7dd470426b4fb111921e</hash>
769+
<url>https://github.com/zaproxy/zap-extensions/releases/download/custompayloads-v0.14.0/custompayloads-release-0.14.0.zap</url>
770+
<hash>SHA-256:fe99e67a3a456c70a25c35e5d25961c1dca417d2c94124316c2ea26965009ec2</hash>
773771
<info>https://www.zaproxy.org/docs/desktop/addons/custom-payloads/</info>
774772
<repo>https://github.com/zaproxy/zap-extensions/</repo>
775-
<date>2023-11-10</date>
776-
<size>246425</size>
777-
<not-before-version>2.14.0</not-before-version>
773+
<date>2025-01-15</date>
774+
<size>292156</size>
775+
<not-before-version>2.16.0</not-before-version>
776+
<dependencies>
777+
<addons>
778+
<addon>
779+
<id>commonlib</id>
780+
<version>&gt;= 1.17.0 &amp; &lt; 2.0.0</version>
781+
</addon>
782+
</addons>
783+
</dependencies>
778784
</addon_custompayloads>
779785
<addon>database</addon>
780786
<addon_database>
@@ -2373,20 +2379,30 @@ to find and add subdomains to the Sites Tree.&lt;/li&gt;
23732379
<name>Passive scanner rules (beta)</name>
23742380
<description>The beta status Passive Scanner rules</description>
23752381
<author>ZAP Dev Team</author>
2376-
<version>41</version>
2377-
<file>pscanrulesBeta-beta-41.zap</file>
2382+
<version>42</version>
2383+
<file>pscanrulesBeta-beta-42.zap</file>
23782384
<status>beta</status>
2379-
<changes>&lt;h3&gt;Fixed&lt;/h3&gt;
2385+
<changes>&lt;h3&gt;Changed&lt;/h3&gt;
2386+
&lt;ul&gt;
2387+
&lt;li&gt;Update minimum ZAP version to 2.16.0.&lt;/li&gt;
2388+
&lt;li&gt;Updated help with specific Category identifier for use with the Custom Payloads add-on for the &amp;quot;Dangerous JS Functions&amp;quot; rule.&lt;/li&gt;
2389+
&lt;/ul&gt;
2390+
&lt;h3&gt;Fixed&lt;/h3&gt;
2391+
&lt;ul&gt;
2392+
&lt;li&gt;Fix typo in log message.&lt;/li&gt;
2393+
&lt;li&gt;Fix Insufficient Site Isolation scan rule check that filters responses based on whether a response is a success or not.&lt;/li&gt;
2394+
&lt;/ul&gt;
2395+
&lt;h3&gt;Changed&lt;/h3&gt;
23802396
&lt;ul&gt;
2381-
&lt;li&gt;A possible false positive condition with the Dangerous JS Functions scan rule with substrings in certain circumstances (Issue 8553).&lt;/li&gt;
2397+
&lt;li&gt;Maintenance changes.&lt;/li&gt;
23822398
&lt;/ul&gt;</changes>
2383-
<url>https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesBeta-v41/pscanrulesBeta-beta-41.zap</url>
2384-
<hash>SHA-256:afb76940929bf4f3bf2ab4a2d0a0fa9d50ef834969b551c5397459746caf6e76</hash>
2399+
<url>https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesBeta-v42/pscanrulesBeta-beta-42.zap</url>
2400+
<hash>SHA-256:91626262fbe76d097b508a2e85b3192c8b12645dfb82387715ac12358989d562</hash>
23852401
<info>https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules-beta/</info>
23862402
<repo>https://github.com/zaproxy/zap-extensions/</repo>
2387-
<date>2024-09-02</date>
2388-
<size>677612</size>
2389-
<not-before-version>2.15.0</not-before-version>
2403+
<date>2025-01-15</date>
2404+
<size>678315</size>
2405+
<not-before-version>2.16.0</not-before-version>
23902406
<dependencies>
23912407
<addons>
23922408
<addon>
@@ -3168,27 +3184,33 @@ to find and add subdomains to the Sites Tree.&lt;/li&gt;
31683184
<name>Technology Detection</name>
31693185
<description>Technology detection using various fingerprints and identifiers.</description>
31703186
<author>ZAP Dev Team</author>
3171-
<version>21.43.0</version>
3172-
<file>wappalyzer-release-21.43.0.zap</file>
3187+
<version>21.44.0</version>
3188+
<file>wappalyzer-release-21.44.0.zap</file>
31733189
<status>release</status>
31743190
<changes>&lt;h3&gt;Changed&lt;/h3&gt;
31753191
&lt;ul&gt;
31763192
&lt;li&gt;Updated with enthec upstream icon and pattern changes.&lt;/li&gt;
3177-
&lt;li&gt;Maintenance changes.&lt;/li&gt;
3193+
&lt;li&gt;Update minimum ZAP version to 2.16.0.&lt;/li&gt;
3194+
&lt;li&gt;Depend on Passive Scanner add-on (Issue 7959).&lt;/li&gt;
3195+
&lt;li&gt;The scan rule no longer sets a CWE for alerts (Issue 8733).&lt;/li&gt;
31783196
&lt;/ul&gt;</changes>
3179-
<url>https://github.com/zaproxy/zap-extensions/releases/download/wappalyzer-v21.43.0/wappalyzer-release-21.43.0.zap</url>
3180-
<hash>SHA-256:f5bf3028d5a9bc262f522b920c9012a542d84e75b4429919c3eeb12851127c7b</hash>
3197+
<url>https://github.com/zaproxy/zap-extensions/releases/download/wappalyzer-v21.44.0/wappalyzer-release-21.44.0.zap</url>
3198+
<hash>SHA-256:b740a362994d4d21ec06be7b96889bb82c9743b9c2baecd8682c3758dd9f82bc</hash>
31813199
<info>https://www.zaproxy.org/docs/desktop/addons/technology-detection/</info>
31823200
<repo>https://github.com/zaproxy/zap-extensions/</repo>
3183-
<date>2024-11-25</date>
3184-
<size>19759181</size>
3185-
<not-before-version>2.15.0</not-before-version>
3201+
<date>2025-01-15</date>
3202+
<size>20162575</size>
3203+
<not-before-version>2.16.0</not-before-version>
31863204
<dependencies>
31873205
<addons>
31883206
<addon>
31893207
<id>commonlib</id>
31903208
<version>&gt;= 1.17.0 &amp; &lt; 2.0.0</version>
31913209
</addon>
3210+
<addon>
3211+
<id>pscan</id>
3212+
<version>&gt;= 0.1.0 &amp; &lt; 1.0.0</version>
3213+
</addon>
31923214
</addons>
31933215
</dependencies>
31943216
</addon_wappalyzer>

0 commit comments

Comments
 (0)