Skip to content

[pull] main from GreedyBear-Project:main - #43

Merged
pull[bot] merged 44 commits into
threatcode:mainfrom
GreedyBear-Project:main
Sep 24, 2026
Merged

pull[bot] merged 44 commits into
threatcode:mainfrom
GreedyBear-Project:main

Conversation

@pull

@pull pull Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

dependabot Bot and others added 30 commits September 4, 2026 09:44
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 1 to 4.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v1...v4)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pilosus/action-pip-license-checker](https://github.com/pilosus/action-pip-license-checker) from 2 to 3.
- [Release notes](https://github.com/pilosus/action-pip-license-checker/releases)
- [Changelog](https://github.com/pilosus/action-pip-license-checker/blob/main/CHANGELOG.md)
- [Commits](pilosus/action-pip-license-checker@v2...v3)

---
updated-dependencies:
- dependency-name: pilosus/action-pip-license-checker
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v5...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps library/nginx from 1.31.4-alpine to 1.31.5-alpine.

---
updated-dependencies:
- dependency-name: library/nginx
  dependency-version: 1.31.5-alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v2...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: joshuavetos <joshuavetos@users.noreply.github.com>
 (#1563)

* Document rationale for add_tags vs replace_tags_for_source. Progresses #1551

* Fix indentation: replace tabs with spaces

* Fix trailing whitespace
* fix: normalize SHA256 case in payload extraction. Closes #1556

* refactor: inline .lower() instead of a wrapper function
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4 to 5.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](actions/dependency-review-action@v4...v5)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.16.5 to 0.16.6.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.5...0.16.6)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@v2...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…A256. Closes #1509 (#1552)

* feat: Link HoneypotPayload to Cowrie sessions and attacker IOCs by SHA256. Closes #1509

* fix: use lower-cased shasum matching instead of __iexact

---------

Co-authored-by: Rohit Padala <rohit.padala@jodopay.com>
* Move gb-ui components into frontend

* Add table visual regression tests

* Exclude visual specs from Vitest

* Keep visual tests out of CI

* Keep visual tests out of DataTable

* Remove unused chart wrappers

* Document shared UI component source

* sync package-lock.json

---------

Co-authored-by: tim <46972822+regulartim@users.noreply.github.com>
* remove Daniele and add GSoC contributors to "special thanks"

* update GSoC section and decouple it from IntelOwl

* fix typo

* add project links
…1590)

* Extract BaseEnrichmentJob/HttpEnrichmentJob and move enrichment jobs into their own folder

* Address review comments on enrichment refactor. Progresses #1551
* Fix payload extraction time window

* move get_time_window to greedybear/utils.py and fix keyword arguments

* Clean leftover changes

---------

Co-authored-by: tim <46972822+regulartim@users.noreply.github.com>
* feat: allow querying Cowrie sessions by ID. Closes #1578

* Address review: hex regex, 16 digit limit, duration filter, clearer errors
…ng them. Closes #1530 (#1593)

* fix: let payload extraction upgrade hash-only stubs instead of skipping them. Closes #1530

* fix: handle NULL payload_file, preserve fields on upgrade, revert to get_or_create

fix: handle NULL payload_file, preserve fields on upgrade, revert to get_or_create
* fix: allow GreedyBear to run without Elasticsearch

* refactor: handle unavailable Elasticsearch in repository

* test: cover Elasticsearch unavailable cronjobs

* fix: update Elasticsearch configuration warning

* fix format

---------

Co-authored-by: tim <46972822+regulartim@users.noreply.github.com>
* add GreedyBearModelAdmin base class with disabled facet counts

* fix format
* add credentials to raw_id_fields in CowrieSessionModelAdmin

* add source to raw_id_fields in CredentialModelAdmin
dev-aditya-hub and others added 14 commits September 22, 2026 08:14
* Keep feed cache version from expiring on bump

* Shorten comment and reuse the class set wrapper
…1601 (#1600)

* Recover event batches stuck in processing after worker crash

* Claim batches with no started_at and expose the field
* feat: add payload SHA256 hashes to the advanced feed responses. Closes #1543

* fix(feeds): gate payload_hashes on verbose to avoid unbounded response size. Closes #1543

* condense comment

---------

Co-authored-by: tim <46972822+regulartim@users.noreply.github.com>
…loses #1614 (#1620)

* Count IOCs linked to any active honeypot in feeds_types statistics. Closes #1614

* Simplify statistics regression tests to plain URLs per review
* Guard scoring jobs against empty IoC data. Closes #1625

* Snapshot training data on empty-feature skip per review
Bumps library/nginx from 1.31.5-alpine to 1.31.6-alpine.

---
updated-dependencies:
- dependency-name: library/nginx
  dependency-version: 1.31.6-alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.16.6 to 0.16.7.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.6...0.16.7)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…1628 (#1632)

* Enforce Tag identity uniqueness and deduplicate existing rows. Closes #1628

* Set ignore_conflicts in replace_tags_for_source
…1635)

IOCs ingested through the event collector API never reached any feed:
they were saved with no honeypot, while every feed filters on
honeypots__active=True.

Each event IOC is now linked to a Honeypot derived from the reporting
sensor's honeypot_software, defaulting to "External" when unset and
creating the honeypot as active if missing. honeypot_software is capped
at 15 characters in SensorCreateSerializer so it always fits
Honeypot.name, and is truncated during processing to keep sensors
registered before the cap from failing a whole batch.
@pull pull Bot locked and limited conversation to collaborators Sep 24, 2026
@pull pull Bot added the ⤵️ pull label Sep 24, 2026
@pull
pull Bot merged commit 713e73d into threatcode:main Sep 24, 2026
1 check passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.