diff --git a/constants.go b/constants.go index ca6fd93ec09..5fd32cd5def 100644 --- a/constants.go +++ b/constants.go @@ -252,6 +252,9 @@ const ( // ComponentInstance is an abstract component common to all services. ComponentInstance = "instance" + // ComponentVersionControl is the component common to all version control operations. + ComponentVersionControl = "version-control" + // DebugEnvVar tells tests to use verbose debug output DebugEnvVar = "DEBUG" diff --git a/lib/versioncontrol/github/github.go b/lib/versioncontrol/github/github.go new file mode 100644 index 00000000000..93e78ec2613 --- /dev/null +++ b/lib/versioncontrol/github/github.go @@ -0,0 +1,195 @@ +/* +Copyright 2022 Gravitational, Inc. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +*/ + +package github + +import ( + "encoding/json" + "fmt" + "io" + "net/http" + + "github.com/gravitational/teleport" + "github.com/gravitational/trace" + "github.com/sirupsen/logrus" + + "golang.org/x/mod/semver" +) + +// NOTE: when making modifications to package, make sure to run tests with +// `TEST_GITHUB_API=yes`. this will enable some additional tests that are not +// run as part of normal CI. + +var log = logrus.WithFields(logrus.Fields{ + trace.Component: teleport.ComponentVersionControl, +}) + +// defaultHaltingPoint represents the default cutoff for the iterator. this value +// is expanded/truncated to `.` so e.g. `v1` would halt iteration on the +// first `v1.0.X` release observed, and `v1.2.3` would halt iteration on the first +// `v1.2.X` release observed. +const defaultHaltingPoint = "v8" + +const defaultPageSize = 100 + +// Release represents a github release. +type Release struct { + // Version is the semver version from the git tag of the release. + Version string + + // TODO(fspmarshall): decide on a scheme for embedding additional tags + // in our git releases (e.g. security-patch=yes, etc). +} + +// release is the representation of a release returned +// by the github API. +type release struct { + TagName string `json:"tag_name"` +} + +// getter loads a page of releases. we override the standard page loading logic +// via this type in order to avoid issues with rate-limiting of the unauthenticated +// releases API. +type getter func(n, size int) ([]release, error) + +// getPage loads the specified page from the unauthenticated github releases API +// using the provided http client. +func getPage(clt http.Client, n, size int) ([]release, error) { + if n == 0 { + return nil, trace.BadParameter("unspecified page number for teleport/releases (this is a bug)") + } + if size == 0 { + return nil, trace.BadParameter("unspecified page size for teleport/releases (this is a bug)") + } + + // get page from the github api. see https://docs.github.com/rest/releases/releases for details. + res, err := clt.Get(fmt.Sprintf("https://api.github.com/repos/gravitational/teleport/releases?page=%d&per_page=%d", n, size)) + if err != nil { + return nil, trace.Errorf("failed to get teleport/releases: %v", err) + } + + body, err := io.ReadAll(res.Body) + res.Body.Close() + + if res.StatusCode > 299 { + // attempt to extract pretty error message + var gherr ghError + if json.Unmarshal(body, &gherr) == nil { + if gherr.Message != "" { + return nil, trace.Errorf("teleport/releases request failed with message: %s (%d)", gherr.Message, res.StatusCode) + } + } + // fallback to status code and quoted body + return nil, trace.Errorf("teleport/releases request failed with code=%d, body=%q", res.StatusCode, body) + } + + // handle error from rsp body read + if err != nil { + return nil, trace.Wrap(err) + } + + return parsePage(body) +} + +// deserialization helper for github api errors +type ghError struct { + Message string `json:"message"` +} + +func parsePage(page []byte) ([]release, error) { + var releases []release + if err := json.Unmarshal(page, &releases); err != nil { + return nil, trace.Errorf("failed to unmarshal releases page: %v", err) + } + return releases, nil +} + +// Iterator allows lazy consumption of github release pages. Not safe for +// concurrent use. Always check for err after iteration, even if one or more +// pages were loaded successfully. If a release being added concurrently with +// iteration may cause duplicate releases to be observed. +type Iterator struct { + getPage getter + n int + size int + page []Release + halt string + done bool + err error +} + +func (i *Iterator) setDefaults() { + if i.getPage == nil { + var clt http.Client + i.getPage = func(n, size int) ([]release, error) { + return getPage(clt, n, size) + } + } + + if i.size == 0 { + i.size = defaultPageSize + } + + if i.halt == "" { + i.halt = defaultHaltingPoint + } +} + +// Next attempts to load the next page. +func (i *Iterator) Next() bool { + i.setDefaults() + if i.done { + return false + } + i.n++ + var page []release + page, i.err = i.getPage(i.n, i.size) + if len(page) < i.size { + // check unfiltered page size for halt condition + i.done = true + } + i.page = make([]Release, 0, len(page)) + for _, r := range page { + if !semver.IsValid(r.TagName) { + log.Debugf("Skipping non-semver release tag: %q\n", r.TagName) + continue + } + i.page = append(i.page, Release{ + Version: r.TagName, + }) + + // only match `.` when finding halt point. theoretically + // unnecessary, but this feels a bit less brittle than halting on a specific + // tag, and is more consistent than using a gt/lt rule, since we occasionally + // release patches for very old versions. + if semver.MajorMinor(r.TagName) == semver.MajorMinor(i.halt) { + i.done = true + break + } + } + return i.err == nil && len(page) != 0 +} + +// Page loads the current page. Must not be called until after Next() has been +// called. Subsequent calls between calls to Next() return the same value. +func (i *Iterator) Page() []Release { + return i.page +} + +// Error checks if an error occurred during iteration. +func (i *Iterator) Error() error { + return i.err +} diff --git a/lib/versioncontrol/github/github_test.go b/lib/versioncontrol/github/github_test.go new file mode 100644 index 00000000000..603aeae057f --- /dev/null +++ b/lib/versioncontrol/github/github_test.go @@ -0,0 +1,212 @@ +/* +Copyright 2022 Gravitational, Inc. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +*/ + +package github + +import ( + _ "embed" + "fmt" + "os" + "testing" + + apiutils "github.com/gravitational/teleport/api/utils" + + "github.com/stretchr/testify/require" +) + +// TestGithubAPI tests the github releases iterator against the real github +// api. this test is disabled by default since we use the unauthenticated endpoint +// which doesn't like frequent request spamming. +func TestGithubAPI(t *testing.T) { + if run, _ := apiutils.ParseBool(os.Getenv("TEST_GITHUB_API")); !run { + t.Skip("Test disabled in CI. Enable it by setting env variable TEST_GITHUB_API=yes") + } + t.Parallel() + + var rr []Release + var iter Iterator + iter.halt = "v4" + for iter.Next() { + rr = append(rr, iter.Page()...) + } + require.NoError(t, iter.Error()) + + seen := make(map[string]struct{}) + for _, r := range rr { + seen[r.Version] = struct{}{} + } + + // some arbitrary versions we expect to exist (this may need to be updated + // at some point in the future if we ever start trimming history). + expected := []string{ + "v8.0.0-beta.2", + "v7.3.19", + "v7.1.1", + "v10.0.0", + "v5.0.0-rc.2", + "v7.3.21", + "v9.3.12", + } + for _, e := range expected { + require.Contains(t, seen, e) + } + + // some known tags that we aught to be filtering out + notExpected := []string{ + "teleport-connect-preview-1.0.2", + "teleport-connect-preview-1.0.1", + } + for _, n := range notExpected { + require.NotContains(t, seen, n) + } +} + +// TestGithubAPIError tests the api error message extraction. +func TestGithubAPIError(t *testing.T) { + if run, _ := apiutils.ParseBool(os.Getenv("TEST_GITHUB_API")); !run { + t.Skip("Test disabled in CI. Enable it by setting env variable TEST_GITHUB_API=yes") + } + t.Parallel() + + var iter Iterator + // any page size + number combo that would look further than 1000 releases + // into the past should generate an error. + iter.n = 20 + iter.size = 100 + for iter.Next() { + require.Fail(t, "request should fail on first iteration") + } + require.Error(t, iter.Error()) + + require.Contains(t, iter.Error().Error(), "Only the first 1000 results are available. (422)") +} + +//go:embed test_page_1.json +var page1 string + +//go:embed test_page_2.json +var page2 string + +//go:embed test_page_3.json +var page3 string + +const cachedPageSize = 10 + +// TestCachedReleases verifies expected behavior of the github release iterator +// using cached pages. +func TestCachedReleases(t *testing.T) { + tts := []struct { + pages []string + pageCount int + desc string + hitsEmptyPage bool + haltingPoint string + err error + }{ + { + pages: []string{ + page1, + page2, + page3, // page 3 is a partial page, which triggers iteration to halt + }, + pageCount: 3, + desc: "full iteration, ending on partial page", + }, + { + pages: []string{ + page3, + page2, + page1, + }, + pageCount: 1, + desc: "stop on first partial page", + }, + { + pages: []string{ + page1, + page2, + }, + pageCount: 2, + hitsEmptyPage: true, + desc: "end on full page", + }, + { + pages: []string{ + page1, + page2, + page3, + }, + pageCount: 1, + haltingPoint: "v10", + desc: "halt on fist v10.0.X release", + }, + { + pages: []string{ + page1, + page2, + page3, + }, + pageCount: 2, + haltingPoint: "v7.3", + desc: "halt on fist v7.3.X release", + }, + { + hitsEmptyPage: true, + desc: "empty case", + }, + { + err: fmt.Errorf("failure"), + desc: "error case", + }, + } + + for _, tt := range tts { + lastPageWasEmpty := false + + var iter Iterator + iter.size = cachedPageSize + iter.halt = tt.haltingPoint + iter.getPage = func(n, size int) ([]release, error) { + require.NotZero(t, n, tt.desc) + if tt.err != nil { + return nil, tt.err + } + if n > len(tt.pages) { + lastPageWasEmpty = true + return nil, nil + } + page := tt.pages[n-1] + return parsePage([]byte(page)) + } + + var ct int + for iter.Next() { + ct++ + require.NotZero(t, len(iter.Page()), tt.desc) + } + + if tt.err == nil { + require.NoError(t, iter.Error(), tt.desc) + } else { + require.Error(t, iter.Error(), tt.desc) + } + + require.Equal(t, tt.pageCount, ct, tt.desc) + + require.Equal(t, tt.hitsEmptyPage, lastPageWasEmpty) + + } +} diff --git a/lib/versioncontrol/github/test_page_1.json b/lib/versioncontrol/github/test_page_1.json new file mode 100644 index 00000000000..1f5efe22027 --- /dev/null +++ b/lib/versioncontrol/github/test_page_1.json @@ -0,0 +1,428 @@ +[ + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/73006529", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/73006529/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/73006529/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.3.13", + "id": 73006529, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EWf3B", + "tag_name": "v9.3.13", + "target_commitish": "master", + "name": "Teleport 9.3.13", + "draft": false, + "prerelease": false, + "created_at": "2022-07-27T19:58:06Z", + "published_at": "2022-07-27T21:31:30Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.3.13", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.3.13", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed issue with incorrect time being set on session.upload events. [#14560](https://github.com/gravitational/teleport/pull/14560)\r\n* Fixed issue with Teleport components not becoming ready when desktop access is enabled. [#14858](https://github.com/gravitational/teleport/pull/14858)\r\n* Fixed issue with token not being validated when generating a join script. [#14946](https://github.com/gravitational/teleport/pull/14946)\r\n* Added ability to override AWS database name via `teleport.dev/database_name` tag. [#14826](https://github.com/gravitational/teleport/pull/14826)\r\n* Added ability to call `tsh proxy db` without calling `tsh db login` first. [#14801](https://github.com/gravitational/teleport/pull/14801)\r\n* Added additional Prometheus metrics for DynamoDB. [#14761](https://github.com/gravitational/teleport/pull/14761)\r\n* Added support for external IDs in AWS Console access. [#14895](https://github.com/gravitational/teleport/pull/14895)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download.", + "reactions": { + "url": "https://api.github.com/repos/gravitational/teleport/releases/73006529/reactions", + "total_count": 1, + "+1": 1, + "-1": 0, + "laugh": 0, + "hooray": 0, + "confused": 0, + "heart": 0, + "rocket": 0, + "eyes": 0 + } + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/72994655", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/72994655/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/72994655/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v8.3.16", + "id": 72994655, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EWc9f", + "tag_name": "v8.3.16", + "target_commitish": "master", + "name": "Teleport 8.3.16", + "draft": false, + "prerelease": false, + "created_at": "2022-07-27T17:05:49Z", + "published_at": "2022-07-27T19:02:43Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v8.3.16", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v8.3.16", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed X11 forwarding issues on Windows and Mac. [#14438](https://github.com/gravitational/teleport/pull/14438)\r\n* Fixed issues with CAs not being propagated during CA rotation. [#14045](https://github.com/gravitational/teleport/pull/14045)\r\n* Fixed agent reconnect issues after proxy restart. [#14509](https://github.com/gravitational/teleport/pull/14509)\r\n* Fixed issue with PostgreSQL listener not starting when proxy is started in non-TLS mode. [#14330](https://github.com/gravitational/teleport/pull/14330)\r\n* Fixed issue with connection through a jump host when root cluster is offline. [#13929](https://github.com/gravitational/teleport/pull/13929)\r\n* Fixed issue with redirect URL not being preserved after application access login. [#14205](https://github.com/gravitational/teleport/pull/14205)\r\n* Fixed `--cluster` flag for `tsh db ls` command. [#14396](https://github.com/gravitational/teleport/pull/14396)\r\n* Fixed issue with resource listing pagination when there are denied resources. [#14544](https://github.com/gravitational/teleport/pull/14544)\r\n* Added ability to set AWS database name via `teleport.dev/database_name` tag. [#14827](https://github.com/gravitational/teleport/pull/14827)\r\n* Added ability to call `tsh proxy db` without `tsh db login`. [#14838](https://github.com/gravitational/teleport/pull/14838)\r\n* Added support for external IDs in AWS Console Access. [#14897](https://github.com/gravitational/teleport/pull/14897)\r\n* Improved `tsh db ls` performance for users with many roles. [#14288](https://github.com/gravitational/teleport/pull/14288)\r\n* Improved internal cache efficiency. [#14305](https://github.com/gravitational/teleport/pull/14305)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download.", + "reactions": { + "url": "https://api.github.com/repos/gravitational/teleport/releases/72994655/reactions", + "total_count": 1, + "+1": 0, + "-1": 0, + "laugh": 0, + "hooray": 1, + "confused": 0, + "heart": 0, + "rocket": 0, + "eyes": 0 + } + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/72468851", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/72468851/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/72468851/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.3.12", + "id": 72468851, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EUclz", + "tag_name": "v9.3.12", + "target_commitish": "master", + "name": "Teleport 9.3.12", + "draft": false, + "prerelease": false, + "created_at": "2022-07-20T18:30:25Z", + "published_at": "2022-07-20T20:28:52Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.3.12", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.3.12", + "body": "## Description\r\n\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Added ability to set session recording configuration from a resource. [#14612](https://github.com/gravitational/teleport/pull/14612)\r\n* Fixed an issue where `tsh` would shell out to `ssh`. [#14222](https://github.com/gravitational/teleport/pull/14222)\r\n* Improved error messages for Database Access. [#13902](https://github.com/gravitational/teleport/pull/13902) [#14476](https://github.com/gravitational/teleport/pull/14476)\r\n* Fixed issue with Ctrl-C hanging when the session is paused. [#14512](https://github.com/gravitational/teleport/pull/14512)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/72351795", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/72351795/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/72351795/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v10.0.2", + "id": 72351795, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EUAAz", + "tag_name": "v10.0.2", + "target_commitish": "master", + "name": "Teleport 10.0.2", + "draft": false, + "prerelease": false, + "created_at": "2022-07-19T02:37:46Z", + "published_at": "2022-07-19T17:16:21Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v10.0.2", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v10.0.2", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed issue with `tsh proxy ssh` command shelling out to `ssh` in non TLS routing mode. [#14522](https://github.com/gravitational/teleport/pull/14522)\r\n* Fixed issue with being able to create users with invalid roles via API. [#14459](https://github.com/gravitational/teleport/pull/14459)\r\n* Fixed issue with `tsh login` erroring out on non-existent PuTTY key file on Windows. [#14572](https://github.com/gravitational/teleport/pull/14572)\r\n* Fixed issue with application service not failing correctly with invalid configuration. [#14478](https://github.com/gravitational/teleport/pull/14478)\r\n* Improved error message when joining with invalid host ID using EC2 join method. [#14494](https://github.com/gravitational/teleport/pull/14494)\r\n* Include Machine ID's `tbot` binary in Docker images. [#14462](https://github.com/gravitational/teleport/pull/14462)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/72125989", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/72125989/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/72125989/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.3.10", + "id": 72125989, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4ETI4l", + "tag_name": "v9.3.10", + "target_commitish": "master", + "name": "Teleport 9.3.10", + "draft": false, + "prerelease": false, + "created_at": "2022-07-15T20:05:16Z", + "published_at": "2022-07-15T21:03:51Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.3.10", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.3.10", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed issue with SSH and Kubernetes sessions showing duplicate participants. [#13989](https://github.com/gravitational/teleport/pull/13989)\r\n* Fixed multiple issues with X11 forwarding on Windows and Mac. [#14439](https://github.com/gravitational/teleport/pull/14439)\r\n* Fixed issue with API not validating roles during user creation. [#14460](https://github.com/gravitational/teleport/pull/14460)\r\n* Fixed issue with PostgreSQL listener not starting when Proxy runs in `--insecure-no-tls` mode. [#14328](https://github.com/gravitational/teleport/pull/14328)\r\n* Fixed issue with blank `--ca-pin` flag overriding configuration. [#14362](https://github.com/gravitational/teleport/pull/14362)\r\n* Fixed potential panic in Desktop Access. [#14446](https://github.com/gravitational/teleport/pull/14446)\r\n* Fixed issue with Application Access agent not failing correctly with invalid configuration. [#14479](https://github.com/gravitational/teleport/pull/14479)\r\n* Fixed issue with redirect path not being preserved after login in Application Access. [#14053](https://github.com/gravitational/teleport/pull/14053)\r\n* Fixed issue with Machine ID not respecting configured TTL. [#14413](https://github.com/gravitational/teleport/pull/14413)\r\n* Fixed `--cluster` flag for `tsh db ls` command. [#14391](https://github.com/gravitational/teleport/pull/14391)\r\n* Fixed issue with labels not being expanded with traits in Desktop Access. [#14017](https://github.com/gravitational/teleport/pull/14017)\r\n* Fixed issue with resource listings returning different results between CLI and Web UI in some cases. [#14477](https://github.com/gravitational/teleport/pull/14477)\r\n* Improved `tsh login` to hint at required `--user` flag. [#14254](https://github.com/gravitational/teleport/pull/14254)\r\n* Improved CA rotation stability. [#14044](https://github.com/gravitational/teleport/pull/14044)\r\n* Improved agents reconnect time after Proxy restart. [#14461](https://github.com/gravitational/teleport/pull/14461)\r\n* Improved error message when `tctl` is run before Teleport is started. [#14083](https://github.com/gravitational/teleport/pull/14083)\r\n* Improved performance when using RBAC for sessions with DynamoDB backend. [#13284](https://github.com/gravitational/teleport/pull/13284)\r\n* Improved error message during `tsh login` if Proxy address wasn't configured correctly. [#14374](https://github.com/gravitational/teleport/pull/14374)\r\n* Improved `tsh db ls` performance for users with many roles. [#14287](https://github.com/gravitational/teleport/pull/14287)\r\n* Improved internal cache efficiency. [#14306](https://github.com/gravitational/teleport/pull/14306)\r\n* Made sure SSH config generated by Teleport includes workaround for SHA1 certificates. [#14058](https://github.com/gravitational/teleport/pull/14058)\r\n* Include Machine ID's `tbot` binary in Docker images. [#14464](https://github.com/gravitational/teleport/pull/14464)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/72110837", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/72110837/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/72110837/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v10.0.1", + "id": 72110837, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4ETFL1", + "tag_name": "v10.0.1", + "target_commitish": "master", + "name": "Teleport 10.0.1", + "draft": false, + "prerelease": false, + "created_at": "2022-07-14T22:02:20Z", + "published_at": "2022-07-15T17:04:38Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v10.0.1", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v10.0.1", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed \"unsupported option\" error when using passwordless with some hardware keys. [#14198](https://github.com/gravitational/teleport/pull/14198)\r\n* Fixed issue with automatic user provisioning creading invalid sudoer files for some usernames. [#14364](https://github.com/gravitational/teleport/pull/14364)\r\n* Fixed a number of issues with X11 forwarding on Mac and Windows. [#14437](https://github.com/gravitational/teleport/pull/14437)\r\n* Fixed interoperability issues between newer OpenSSH clients and Teleport. [#14442](https://github.com/gravitational/teleport/pull/14442)\r\n* Fixed issue causing Teleport instances running both Auth and Node services to emit `TeleportDegraded` events. [#14314](https://github.com/gravitational/teleport/pull/14314)\r\n* Fixed issue with HTTP proxy basic auth not being respected. [#14322](https://github.com/gravitational/teleport/pull/14322)\r\n* Fixed issue with blank `--ca-pin` flag overriding configuration. [#14361](https://github.com/gravitational/teleport/pull/14361)\r\n* Fixed potential panic in Desktop Access. [#14445](https://github.com/gravitational/teleport/pull/14445)\r\n* Fixed issue with App Access redirect to a URL containing \"nil\". [#14393](https://github.com/gravitational/teleport/pull/14393)\r\n* Fixed issues with resource request approvals in Web UI. [#14444](https://github.com/gravitational/teleport/pull/14444)\r\n* Fixed issue with resource request approvals for Windows Desktops. [#14452](https://github.com/gravitational/teleport/pull/14452)\r\n* Fixed issue with Machine ID ignoring configured certificate TTL. [#14338](https://github.com/gravitational/teleport/pull/14338)\r\n* Fixed issue with resource list results being different between Web UI and CLI. [#14472](https://github.com/gravitational/teleport/pull/14472)\r\n* Added TouchID prompt message to `tsh`. [#14186](https://github.com/gravitational/teleport/pull/14186)\r\n* Added hint about `--user` flag to `tsh login`. [#14253](https://github.com/gravitational/teleport/pull/14253)\r\n* Added ability to update user principals using `tctl users update --set-logins` command. [#14390](https://github.com/gravitational/teleport/pull/14390)\r\n* Added CA rotation support to Machine ID. [#14431](https://github.com/gravitational/teleport/pull/14431)\r\n* Added `--format` flag to `tsh proxy aws` command. [#14447](https://github.com/gravitational/teleport/pull/14447)\r\n* Improved `tsh login` error message when Proxy public address is not set. [#14338](https://github.com/gravitational/teleport/pull/14338)\r\n* Improved `tsh db ls` performance for users with many roles. [#14284](https://github.com/gravitational/teleport/pull/14284)\r\n* Start PostgreSQL listener when Proxy runs in `--insecure-no-tls` mode. [#14327](https://github.com/gravitational/teleport/pull/14327)\r\n* Create PuTTY compatible key pair on `tsh login`. [#14383](https://github.com/gravitational/teleport/pull/14383)\r\n* Display Kubernetes session in the list of active sessions in Web UI. [#14360](https://github.com/gravitational/teleport/pull/14360)\r\n* Reduced the number of cache reads in healthy clusters. [#14304](https://github.com/gravitational/teleport/pull/14304)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/71593618", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/71593618/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/71593618/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v10.0.0", + "id": 71593618, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4ERG6S", + "tag_name": "v10.0.0", + "target_commitish": "master", + "name": "Teleport 10.0.0", + "draft": false, + "prerelease": false, + "created_at": "2022-07-08T16:13:51Z", + "published_at": "2022-07-08T18:33:45Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v10.0.0", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v10.0.0", + "body": "## Description\r\n\r\nTeleport 10 is a major release that brings the following new features.\r\n\r\nPlatform:\r\n\r\n* Passwordless (Preview)\r\n* Resource Access Requests (Preview)\r\n* Proxy Peering (Preview)\r\n\r\nServer Access:\r\n\r\n* IP-Based Restrictions (Preview)\r\n* Automatic User Provisioning (Preview)\r\n\r\nDatabase Access:\r\n\r\n* Audit Logging for Microsoft SQL Server Database Access\r\n* Snowflake Database Access (Preview)\r\n* ElastiCache/MemoryDB Database Access (Preview)\r\n\r\nTeleport Connect:\r\n\r\n* Teleport Connect for Server and Database Access (Preview)\r\n\r\nMachine ID:\r\n\r\n* Machine ID Database Access Support (Preview)\r\n\r\n### Passwordless (Preview)\r\n\r\nTeleport 10 introduces passwordless support to your clusters. To use passwordless users may register a security key with resident credentials or use a built-in authenticator, like Touch ID.\r\n\r\nSee https://goteleport.com/docs/access-controls/guides/passwordless/.\r\n\r\n### Resource Access Requests (Preview)\r\n\r\nTeleport 10 expands just-in-time access requests to allow for requesting access to specific resources. This lets you grant users the least privileged access needed for their workflows.\r\n\r\nJust-in-time access requests are only available in Teleport Enterprise Edition.\r\n\r\n### Proxy Peering (Preview)\r\n\r\nProxy peering enables Teleport deployments to scale without an increase in load from the number of agent connections. This is accomplished by allowing Proxy Services to tunnel client connections to the desired agent through a neighboring proxy and decoupling the number of agent connections from the number of Proxies.\r\n\r\nProxy peering can be enabled with the following configurations:\r\n\r\n```yaml\r\nauth_service:\r\n tunnel_strategy:\r\n type: proxy_peering\r\n agent_connection_count: 1\r\n```\r\n\r\n```yaml\r\nproxy_service:\r\n peer_listen_addr: 0.0.0.0:3021\r\n```\r\n\r\nNetwork connectivity between proxy servers to the `peer_listen_addr` is required for this feature to work.\r\n\r\nProxy peering is only available in Teleport Enterprise Edition.\r\n\r\n### IP-Based Restrictions (Preview)\r\n\r\nTeleport 10 introduces a new role option to pin the source IP in SSH certificates. When enabled, the source IP that was used to request certificates is embedded in the certificate, and SSH servers will reject connection attempts from other IPs. This protects against attacks where valid credentials are exfiltrated from disk and copied out into other environments.\r\n\r\nIP-based restrictions are only available in Teleport Enterprise Edition.\r\n\r\n### Automatic User Provisioning (Preview)\r\n\r\nTeleport 10 can be configured to automatically create Linux host users upon login without having to use Teleport's PAM integration. Users can be added to specific Linux groups and assigned appropriate “sudoer” privileges.\r\n\r\nTo learn more about configuring automatic user provisioning read the guide: https://goteleport.com/docs/server-access/guides/host-user-creation/.\r\n\r\n### Audit Logging for Microsoft SQL Server Database Access\r\n\r\nTeleport 9 introduced a preview of Database Access support for Microsoft SQL Server which didn’t include audit logging of user queries. Teleport 10 captures users' queries and prepared statements and sends them to the audit log, similarly to other supported database protocols.\r\n\r\nTeleport Database Access for SQL Server remains in Preview mode with more UX improvements coming in future releases.\r\n\r\nRefer to the guide to set up access to a SQL Server with Active Directory authentication: https://goteleport.com/docs/database-access/guides/sql-server-ad/.\r\n\r\n### Snowflake Database Access (Preview)\r\n\r\nTeleport 10 brings support for Snowflake to Database Access. Administrators can set up access to Snowflake databases through Teleport for their users with standard Database Access features like role-based access control and audit logging, including query activity.\r\n\r\nConnect your Snowflake database to Teleport following this guide: https://goteleport.com/docs/database-access/guides/snowflake/.\r\n\r\n### Elasticache/MemoryDB Database Access (Preview)\r\n\r\nTeleport 9 added Redis protocol support to Database Access. Teleport 10 improves this integration by adding native support for AWS-hosted Elasticache and MemoryDB, including auto-discovery and automatic credential management in some deployment configurations.\r\n\r\nLearn more about it in this guide: https://goteleport.com/docs/database-access/guides/redis-aws/.\r\n\r\n### Teleport Connect for Server and Database Access (Preview)\r\n\r\nTeleport Connect is a graphical macOS application that simplifies access to your Teleport resources. Teleport Connect 10 supports Server Access and Database Access. Other protocols and Windows support are coming in a future release.\r\n\r\nGet Teleport Connect installer from the macOS tab on the downloads page: https://goteleport.com/download/.\r\n\r\n### Machine ID Database Access Support (Preview)\r\n\r\nIn Teleport 10 we’ve added Database Access support to Machine ID. Applications can use Machine ID to access databases protected by Teleport.\r\n\r\nYou can find Machine ID guide for database access in the documentation: https://goteleport.com/docs/machine-id/guides/databases/.\r\n\r\n### Breaking changes\r\n\r\nPlease familiarize yourself with the following potentially disruptive changes in Teleport 10 before upgrading.\r\n\r\n#### Auth Service version check\r\n\r\nTeleport 10 agents will now refuse to start if they detect that the Auth Service is more than one major version behind them. You can use the `--skip-version-check` flag to bypass the version check.\r\n\r\nTake a look at component compatibility guarantees in the documentation: https://goteleport.com/docs/setup/operations/upgrading/#component-compatibility.\r\n\r\n#### HTTP_PROXY for reverse tunnels\r\n\r\nReverse tunnel connections will now respect `HTTP_PROXY` environment variables. This may result in reverse tunnel agents not being able to re-establish connections if the HTTP proxy is set in their environment and does not allow connections to the Teleport Proxy Service.\r\n\r\nRefer to the following documentation section for more details: https://goteleport.com/docs/setup/reference/networking/#http-connect-proxies.\r\n\r\n#### New APT repos\r\n\r\nWith Teleport 10 we’ve migrated to new APT repositories that now support multiple release channels, Teleport versions and OS distributions. The new repositories have been backfilled with Teleport versions starting from 6.2.31 and we recommend upgrading to them. The old repositories will be maintained for the foreseeable future.\r\n\r\nSee updated installation instructions: https://goteleport.com/docs/server-access/getting-started/#step-14-install-teleport-on-your-linux-host.\r\n\r\n#### Removed “tctl access ls”\r\n\r\nThe `tctl access ls` command that returned information about user server access within the cluster was removed. Please use a previous `tctl` version if you’d like to keep using it.\r\n\r\n#### Relaxed session join permissions\r\n\r\nIn previous versions of Teleport users needed full access to a Node/Kubernetes pod in order to join a session. Teleport 10 relaxes this requirement. Joining sessions remains deny-by-default but now only `join_policy` statements are checked for session join RBAC.\r\n\r\nSee the Moderated Sessions guide for more details: https://goteleport.com/docs/access-controls/guides/moderated-sessions/.\r\n\r\n#### GitHub connectors\r\n\r\nThe GitHub authentication connector’s `teams_to_logins` field is deprecated in favor of the new `teams_to_roles` field. The old field will be removed in a future release.\r\n\r\n#### Teleport FIPS AWS endpoints\r\n\r\nTeleport 10 will now automatically use FIPS endpoints for AWS S3 and DynamoDB when started with the `--fips` flag. You can use the `use_fips_endpoint=false` connection endpoint option to use regular endpoints for Teleport in FIPS mode, for example:\r\n\r\n```\r\ns3://bucket/path?region=us-east-1&use_fips_endpoint=false\r\n```\r\n\r\nSee the S3/DynamoDB backends documentation for more information: https://goteleport.com/docs/setup/reference/backends/#s3.\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download.", + "reactions": { + "url": "https://api.github.com/repos/gravitational/teleport/releases/71593618/reactions", + "total_count": 1, + "+1": 0, + "-1": 0, + "laugh": 0, + "hooray": 1, + "confused": 0, + "heart": 0, + "rocket": 0, + "eyes": 0 + } + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/71287713", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/71287713/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/71287713/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v10.0.0-rc.1", + "id": 71287713, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EP8Oh", + "tag_name": "v10.0.0-rc.1", + "target_commitish": "master", + "name": "Teleport 10.0.0-rc.1", + "draft": false, + "prerelease": true, + "created_at": "2022-07-02T02:08:50Z", + "published_at": "2022-07-05T14:59:03Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v10.0.0-rc.1", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v10.0.0-rc.1", + "body": "## Warning\r\n\r\nPre-releases are not production ready, use at your own risk!\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/71096325", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/71096325/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/71096325/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.3.9", + "id": 71096325, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EPNgF", + "tag_name": "v9.3.9", + "target_commitish": "master", + "name": "Teleport 9.3.9", + "draft": false, + "prerelease": false, + "created_at": "2022-07-01T15:20:31Z", + "published_at": "2022-07-01T18:26:26Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.3.9", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.3.9", + "body": "## Description\r\n\r\nThis release of Teleport contains a security fix, as well as multiple improvements and bug fixes.\r\n\r\n### Auth bypass in Moderated Sessions\r\n\r\nWhen checking a user’s roles prior to starting a session, Teleport may have incorrectly allowed a session to proceed without moderation depending on the order roles are received from the backend.\r\n\r\nIf you're using Moderated Sessions, we recommend upgrading Auth, Proxy, SSH and Kubernetes agents.\r\n\r\n### Other improvements and fixes\r\n\r\n* Fixed issue with per-session MFA swallowing keypresses. [#13822](https://github.com/gravitational/teleport/pull/13822)\r\n* Fixed issue with `tsh db ls -R` now showing allowed users. [#13626](https://github.com/gravitational/teleport/pull/13626)\r\n* Fixed vertical and horizontal scroll in desktop access. [#13905](https://github.com/gravitational/teleport/pull/13905)\r\n* Fixed issue with invalid query filters forcing `tsh` relogin. [#13747](https://github.com/gravitational/teleport/pull/13747)\r\n* Fixed issue with TLS routing and proxy jump. [#13928](https://github.com/gravitational/teleport/pull/13928)\r\n* Fixed issue with MongoDB connections timing out in certain scenarios. [#13859](https://github.com/gravitational/teleport/pull/13859)\r\n* Fixed issue with Machine ID certificate renewal with empty requested roles. [#13893](https://github.com/gravitational/teleport/pull/13893)\r\n* Fixed issue with Windows desktops not being labeled with LDAP attribute labels. [#13681](https://github.com/gravitational/teleport/pull/13681)\r\n* Fixed issue with desktop access streaming not being terminated properly. [#14024](https://github.com/gravitational/teleport/pull/14024)\r\n* Added ability to use FIPS endpoints for S3 and DynamoDB using `use_fips_endpoint` connection option. [#13703](https://github.com/gravitational/teleport/pull/13703)\r\n* Added ability to specify CA pin as a file path in the config. [#13089](https://github.com/gravitational/teleport/pull/13089)\r\n* Improved reconnect reliability after root proxy restart. [#13967](https://github.com/gravitational/teleport/pull/13967)\r\n* Improved error messages for failed auth client connections. [#13835](https://github.com/gravitational/teleport/pull/13835)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/70894219", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/70894219/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/70894219/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v8.3.15", + "id": 70894219, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EOcKL", + "tag_name": "v8.3.15", + "target_commitish": "master", + "name": "Teleport 8.3.15", + "draft": false, + "prerelease": false, + "created_at": "2022-06-29T17:02:51Z", + "published_at": "2022-06-29T18:13:40Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v8.3.15", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v8.3.15", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Improved reliability of dialing auth servers through the proxy. [#13310](https://github.com/gravitational/teleport/pull/13310)\r\n* Reduced network utilization when using many trusted clusters. [#13961](https://github.com/gravitational/teleport/pull/13961)\r\n* Fixed issue with dialing remote clusters after proxy restart. [#13798](https://github.com/gravitational/teleport/pull/13798)\r\n* Fixed backwards compatibility issue with fetching access requests. [#13427](https://github.com/gravitational/teleport/pull/13427)\r\n* Fixed issue with CA rotation not working when database service has not enabled databases. [#13518](https://github.com/gravitational/teleport/pull/13518)\r\n* Fixed issue with EC2 metadata options breaking generated Teleport config. [#13538](https://github.com/gravitational/teleport/pull/13538)\r\n* Added extra troubleshooting tools to Teleport Docker images. [#13198](https://github.com/gravitational/teleport/pull/13198)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + } +] diff --git a/lib/versioncontrol/github/test_page_2.json b/lib/versioncontrol/github/test_page_2.json new file mode 100644 index 00000000000..572faa7b02b --- /dev/null +++ b/lib/versioncontrol/github/test_page_2.json @@ -0,0 +1,487 @@ +[ + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/70436754", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/70436754/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/70436754/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v10.0.0-alpha.2", + "id": 70436754, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EMseS", + "tag_name": "v10.0.0-alpha.2", + "target_commitish": "master", + "name": "Teleport 10.0.0-alpha.2", + "draft": false, + "prerelease": true, + "created_at": "2022-06-23T17:41:58Z", + "published_at": "2022-06-23T21:13:03Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v10.0.0-alpha.2", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v10.0.0-alpha.2", + "body": "## Warning\r\n\r\nPre-releases are not production ready, use at your own risk!\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/70086668", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/70086668/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/70086668/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.3.7", + "id": 70086668, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4ELXAM", + "tag_name": "v9.3.7", + "target_commitish": "master", + "name": "Teleport 9.3.7", + "draft": false, + "prerelease": false, + "created_at": "2022-06-22T18:03:03Z", + "published_at": "2022-06-22T20:38:47Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.3.7", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.3.7", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed issue with startup delay caused by AWS EC2 check. [#13167](https://github.com/gravitational/teleport/pull/13167)\r\n* Added `tsh ls -R` that displays resources across all clusters and profiles. [#13313](https://github.com/gravitational/teleport/pull/13313)\r\n* Fixed issue with `tsh` not correctly reporting \"address in use\" error during port forwarding. [#13679](https://github.com/gravitational/teleport/pull/13679)\r\n* Fixed two potential panics. [#13590](https://github.com/gravitational/teleport/pull/13590), [#13655](https://github.com/gravitational/teleport/pull/13655)\r\n* Fixed issue with enhanced session recording not working on recent Ubuntu versions. [#13650](https://github.com/gravitational/teleport/pull/13650)\r\n* Fixed issue with CA rotation when Database Service does not contain any databases. [#13517](https://github.com/gravitational/teleport/pull/13517)\r\n* Fixed issue with Desktop Access connection failing with \"invalid channel name rdpsnd\" error. [#13450](https://github.com/gravitational/teleport/issues/13450)\r\n* Fixed issue with invalid Teleport config when enabling IMDSv2 in Terraform config. [#13537](https://github.com/gravitational/teleport/pull/13537)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download.", + "reactions": { + "url": "https://api.github.com/repos/gravitational/teleport/releases/70086668/reactions", + "total_count": 1, + "+1": 0, + "-1": 0, + "laugh": 0, + "hooray": 0, + "confused": 0, + "heart": 0, + "rocket": 1, + "eyes": 0 + } + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/69472531", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/69472531/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/69472531/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.3.6", + "id": 69472531, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EJBET", + "tag_name": "v9.3.6", + "target_commitish": "master", + "name": "Teleport 9.3.6", + "draft": false, + "prerelease": false, + "created_at": "2022-06-14T23:25:50Z", + "published_at": "2022-06-15T00:24:56Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.3.6", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.3.6", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Added Unicode clipboard support to Desktop Access. [#13391](https://github.com/gravitational/teleport/pull/13391)\r\n* Fixed backwards compatibility issue with fetch access requests from older servers. [#13490](https://github.com/gravitational/teleport/pull/13490)\r\n* Fixed issue with Application Access requests periodically failing with 500 errors. [#13469](https://github.com/gravitational/teleport/pull/13469)\r\n* Fixed issues with pagination when displaying applications. [#13451](https://github.com/gravitational/teleport/pull/13451)\r\n* Fixed file descriptor leak in Machine ID. [#13386](https://github.com/gravitational/teleport/pull/13386)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download.", + "reactions": { + "url": "https://api.github.com/repos/gravitational/teleport/releases/69472531/reactions", + "total_count": 4, + "+1": 2, + "-1": 0, + "laugh": 0, + "hooray": 0, + "confused": 0, + "heart": 0, + "rocket": 1, + "eyes": 1 + } + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/69354038", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/69354038/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/69354038/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.3.5", + "id": 69354038, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EIkI2", + "tag_name": "v9.3.5", + "target_commitish": "master", + "name": "Teleport 9.3.5", + "draft": false, + "prerelease": false, + "created_at": "2022-06-13T21:26:35Z", + "published_at": "2022-06-14T02:17:40Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.3.5", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.3.5", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed backwards compatibility issue with fetching access requests from older servers. [#13428](https://github.com/gravitational/teleport/pull/13428)\r\n* Fixed issue with using Microsoft SQL Server Management Studio with Database Access. [#13337](https://github.com/gravitational/teleport/pull/13337)\r\n* Added support for `tsh proxy ssh -J` to improve interoperability with OpenSSH clients. [#13311](https://github.com/gravitational/teleport/pull/13311)\r\n* Added ability to provide security context in Helm charts. [#13286](https://github.com/gravitational/teleport/pull/13286)\r\n* Added Application and Database Access support to reference AWS Terraform deployment. [#13383](https://github.com/gravitational/teleport/pull/13383)\r\n* Improved reliability of dialing Auth Server through the Proxy. [#13399](https://github.com/gravitational/teleport/pull/13399)\r\n* Improved `kubectl exec` auditing by logging access denied attempts. [#12831](https://github.com/gravitational/teleport/pull/12831), [#13400](https://github.com/gravitational/teleport/pull/13400)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download.", + "reactions": { + "url": "https://api.github.com/repos/gravitational/teleport/releases/69354038/reactions", + "total_count": 3, + "+1": 2, + "-1": 0, + "laugh": 0, + "hooray": 1, + "confused": 0, + "heart": 0, + "rocket": 0, + "eyes": 0 + } + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/69013858", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/69013858/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/69013858/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.3.4", + "id": 69013858, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EHRFi", + "tag_name": "v9.3.4", + "target_commitish": "master", + "name": "Teleport 9.3.4", + "draft": false, + "prerelease": false, + "created_at": "2022-06-08T23:24:45Z", + "published_at": "2022-06-09T02:02:52Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.3.4", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.3.4", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple security, bug fixes and improvements.\r\n\r\n### Escalation attack in agent forwarding\r\n\r\nWhen setting up agent forwarding on the node, Teleport did not handle unix socket creation in a secure manner.\r\n\r\nThis could have given a potential attacker an opportunity to get Teleport to change arbitrary file permissions to the attacker’s user.\r\n\r\n### Websockets CSRF\r\n\r\nWhen handling websocket requests, Teleport did not verify that the provided Bearer token was generated for the correct user.\r\n\r\nThis could have allowed a malicious low privileged Teleport user to use a social engineering attack to gain higher privileged access on the same Teleport cluster.\r\n\r\n### Denial of service in access requests\r\n\r\nWhen accepting an access request, Teleport did not enforce the maximum request reason size.\r\n\r\nThis could allow a malicious actor to mount a DoS attack by creating an access request with a very large request reason.\r\n\r\n### Auth bypass in moderated sessions\r\n\r\nWhen initializing a moderated session, Teleport did not discard participant’s input prior to the moderator joining.\r\n\r\nThis could prevent a moderator from being able to interrupt a malicious command executed by a participant.\r\n\r\n## Actions\r\n\r\nWe recommend upgrading Auth, Proxy, SSH and Kubernetes agents.\r\n\r\nUsers should [backup the Teleport cluster](https://goteleport.com/docs/setup/operations/backup-restore/), then follow the standard Teleport [upgrade procedure](https://goteleport.com/docs/setup/operations/upgrading/#upgrade-sequence).\r\n\r\n### Other fixes\r\n\r\n* Fixed issue with stdin hijacking when per-session MFA is enabled. [#13212](https://github.com/gravitational/teleport/pull/13212)\r\n* Added support for automatic tags import when running on AWS EC2. [#12593](https://github.com/gravitational/teleport/pull/12593)\r\n* Added ability to use multiple redirect URLs in OIDC connectors. [#13046](https://github.com/gravitational/teleport/pull/13046)\r\n* Fixed issue with ANSI escape sequences being broken when using `tsh` on Windows. [#13221](https://github.com/gravitational/teleport/pull/13221)\r\n* Fixed issue with `tsh ssh` printing extra error upon exit if last command was unsuccessful. [#12903](https://github.com/gravitational/teleport/pull/12903)\r\n* Added support for Proxy Protocol v2 in MySQL proxy. [#12993](https://github.com/gravitational/teleport/pull/12993)\r\n* Upgraded to Go `v1.17.11`. [#13104](https://github.com/gravitational/teleport/pull/13104)\r\n* Added Windows desktops labeling based on their LDAP attributes. [#13238](https://github.com/gravitational/teleport/pull/13238)\r\n* Improved performance when listing resources for users with many roles. [#13263](https://github.com/gravitational/teleport/pull/13263)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/69013851", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/69013851/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/69013851/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v8.3.14", + "id": 69013851, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EHRFb", + "tag_name": "v8.3.14", + "target_commitish": "master", + "name": "Teleport 8.3.14", + "draft": false, + "prerelease": false, + "created_at": "2022-06-08T21:00:43Z", + "published_at": "2022-06-09T02:02:46Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v8.3.14", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v8.3.14", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple security, bug fixes and improvements.\r\n\r\n### Escalation attack in agent forwarding\r\n\r\nWhen setting up agent forwarding on the node, Teleport did not handle unix socket creation in a secure manner.\r\n\r\nThis could have given a potential attacker an opportunity to get Teleport to change arbitrary file permissions to the attacker’s user.\r\n\r\n### Websockets CSRF\r\n\r\nWhen handling websocket requests, Teleport did not verify that the provided Bearer token was generated for the correct user.\r\n\r\nThis could have allowed a malicious low privileged Teleport user to use a social engineering attack to gain higher privileged access on the same Teleport cluster.\r\n\r\n### Denial of service in access requests\r\n\r\nWhen accepting an access request, Teleport did not enforce the maximum request reason size.\r\n\r\nThis could allow a malicious actor to mount a DoS attack by creating an access request with a very large request reason.\r\n\r\n## Actions\r\n\r\nWe recommend upgrading Auth, Proxy, SSH and Kubernetes agents.\r\n\r\nUsers should [backup the Teleport cluster](https://goteleport.com/docs/setup/operations/backup-restore/), then follow the standard Teleport [upgrade procedure](https://goteleport.com/docs/setup/operations/upgrading/#upgrade-sequence).\r\n\r\n## Other fixes\r\n\r\n* Fixed issue with `tsh ssh` printing extra error upon exit when last command was unsuccessful. [#12904](https://github.com/gravitational/teleport/pull/12904)\r\n* Fixed issue with Kubernetes Access not working with clusters using public CAs. [#12873](https://github.com/gravitational/teleport/pull/12873)\r\n* Upgrade to Go `v1.17.11`. [#13107](https://github.com/gravitational/teleport/pull/13107)\r\n* Reduced glibc requirements by removing dependency on OpenSSL. [#12411](https://github.com/gravitational/teleport/pull/12411)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/69013840", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/69013840/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/69013840/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v7.3.23", + "id": 69013840, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EHRFQ", + "tag_name": "v7.3.23", + "target_commitish": "master", + "name": "Teleport 7.3.23", + "draft": false, + "prerelease": false, + "created_at": "2022-06-08T21:42:38Z", + "published_at": "2022-06-09T02:02:37Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v7.3.23", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v7.3.23", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple security and bug fixes.\r\n\r\n## Escalation attack in agent forwarding\r\n\r\nWhen setting up agent forwarding on the node, Teleport did not handle unix socket creation in a secure manner.\r\n\r\nThis could have given a potential attacker an opportunity to get Teleport to change arbitrary file permissions to the attacker’s user.\r\n\r\n## Websockets CSRF\r\n\r\nWhen handling websocket requests, Teleport did not verify that the provided Bearer token was generated for the correct user.\r\n\r\nThis could have allowed a malicious low privileged Teleport user to use a social engineering attack to gain higher privileged access on the same Teleport cluster.\r\n\r\n## Actions\r\n\r\nWe recommend upgrading Auth, Proxy, SSH and Kubernetes agents.\r\n\r\nUsers should [backup the Teleport cluster](https://goteleport.com/docs/setup/operations/backup-restore/), then follow the standard Teleport [upgrade procedure](https://goteleport.com/docs/setup/operations/upgrading/#upgrade-sequence).\r\n\r\n## Other fixes\r\n\r\n* Fixed issue with `tsh ssh` printing extra error upon exit when last command was unsuccessful. [#12902](https://github.com/gravitational/teleport/pull/12902)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/68294179", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/68294179/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/68294179/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.3.2", + "id": 68294179, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EEhYj", + "tag_name": "v9.3.2", + "target_commitish": "master", + "name": "Teleport 9.3.2", + "draft": false, + "prerelease": false, + "created_at": "2022-05-31T20:00:47Z", + "published_at": "2022-05-31T23:09:11Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.3.2", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.3.2", + "body": "## Description\r\n\r\nThis release of Teleport contains two bug fixes.\r\n\r\n* Fixed issue with Machine ID's `tsh` version check. [#13037](https://github.com/gravitational/teleport/pull/13037)\r\n* Fixed AWS related log spam in database agent when not running on AWS. [#12984](https://github.com/gravitational/teleport/pull/12984)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download.", + "reactions": { + "url": "https://api.github.com/repos/gravitational/teleport/releases/68294179/reactions", + "total_count": 1, + "+1": 0, + "-1": 0, + "laugh": 0, + "hooray": 1, + "confused": 0, + "heart": 0, + "rocket": 0, + "eyes": 0 + } + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/68061355", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/68061355/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/68061355/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.3.0", + "id": 68061355, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EDoir", + "tag_name": "v9.3.0", + "target_commitish": "master", + "name": "Teleport 9.3.0", + "draft": false, + "prerelease": false, + "created_at": "2022-05-28T00:44:03Z", + "published_at": "2022-05-28T02:03:13Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.3.0", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.3.0", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed issue with `tctl` not taking `TELEPORT_HOME` environment variable into account. [#12738](https://github.com/gravitational/teleport/pull/12738)\r\n* Fixed issue with Redis `AUTH` command not always authenticating the user in database access. [#12754](https://github.com/gravitational/teleport/pull/12754)\r\n* Fixed issue with Teleport not starting with deprecated U2F configuration. [#12826](https://github.com/gravitational/teleport/pull/12826)\r\n* Fixed issue with `tsh db ls` not showing allowed users for leaf clusters. [#12853](https://github.com/gravitational/teleport/pull/12853)\r\n* Fixed issue with `teleport configure` failing when given non-existent data directory. [#12806](https://github.com/gravitational/teleport/pull/12806)\r\n* Fixed issue with `tctl` not outputting debug logs. [#12920](https://github.com/gravitational/teleport/pull/12920)\r\n* Fixed issue with Kubernetes access not working when using default CA pool. [#12874](https://github.com/gravitational/teleport/pull/12874)\r\n* Fixed issue with Machine ID not working in TLS routing mode. [#12990](https://github.com/gravitational/teleport/pull/12990)\r\n* Added database access support to Machine ID. [#12990](https://github.com/gravitational/teleport/pull/12990)\r\n* Improved connection performance in large clusters. [#12832](https://github.com/gravitational/teleport/pull/12832)\r\n* Improved memory usage in large clusters. [#12724](https://github.com/gravitational/teleport/pull/12724)\r\n\r\n### Breaking Changes\r\n\r\nTeleport 9.3.0 reduces the minimum GLIBC requirement to 2.18 and enforces more secure cipher suites for desktop access.\r\n\r\nAs a result of these changes, desktop access users with desktops running Windows Server 2012R2 will need to perform\r\n[additional configuration](https://goteleport.com/docs/desktop-access/getting-started/#step-47-configure-a-certificate-for-rdp-connections) to force Windows to use commpatible cipher suites.\r\n\r\nWindows desktops running Windows Server 2016 and newer will continue to operate normally - no additional configuration is required.\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/68253708", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/68253708/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/68253708/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/teleport-connect-preview-1.0.2", + "id": 68253708, + "author": { + "login": "zmb3", + "id": 7527103, + "node_id": "MDQ6VXNlcjc1MjcxMDM=", + "avatar_url": "https://avatars.githubusercontent.com/u/7527103?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/zmb3", + "html_url": "https://github.com/zmb3", + "followers_url": "https://api.github.com/users/zmb3/followers", + "following_url": "https://api.github.com/users/zmb3/following{/other_user}", + "gists_url": "https://api.github.com/users/zmb3/gists{/gist_id}", + "starred_url": "https://api.github.com/users/zmb3/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/zmb3/subscriptions", + "organizations_url": "https://api.github.com/users/zmb3/orgs", + "repos_url": "https://api.github.com/users/zmb3/repos", + "events_url": "https://api.github.com/users/zmb3/events{/privacy}", + "received_events_url": "https://api.github.com/users/zmb3/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EEXgM", + "tag_name": "teleport-connect-preview-1.0.2", + "target_commitish": "master", + "name": "Teleport Connect Preview v1.0.2", + "draft": false, + "prerelease": false, + "created_at": "2022-05-28T00:42:39Z", + "published_at": "2022-05-31T14:53:19Z", + "assets": [ + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/assets/67139287", + "id": 67139287, + "node_id": "RA_kwDOAeGNGc4EAHbX", + "name": "Teleport.Connect.Preview-1.0.2.dmg", + "label": null, + "uploader": { + "login": "zmb3", + "id": 7527103, + "node_id": "MDQ6VXNlcjc1MjcxMDM=", + "avatar_url": "https://avatars.githubusercontent.com/u/7527103?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/zmb3", + "html_url": "https://github.com/zmb3", + "followers_url": "https://api.github.com/users/zmb3/followers", + "following_url": "https://api.github.com/users/zmb3/following{/other_user}", + "gists_url": "https://api.github.com/users/zmb3/gists{/gist_id}", + "starred_url": "https://api.github.com/users/zmb3/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/zmb3/subscriptions", + "organizations_url": "https://api.github.com/users/zmb3/orgs", + "repos_url": "https://api.github.com/users/zmb3/repos", + "events_url": "https://api.github.com/users/zmb3/events{/privacy}", + "received_events_url": "https://api.github.com/users/zmb3/received_events", + "type": "User", + "site_admin": false + }, + "content_type": "application/x-diskcopy", + "state": "uploaded", + "size": 107427207, + "download_count": 139, + "created_at": "2022-05-31T14:52:35Z", + "updated_at": "2022-05-31T14:53:06Z", + "browser_download_url": "https://github.com/gravitational/teleport/releases/download/teleport-connect-preview-1.0.2/Teleport.Connect.Preview-1.0.2.dmg" + } + ], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/teleport-connect-preview-1.0.2", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/teleport-connect-preview-1.0.2", + "body": "Teleport Connect is a developer-friendly browser for cloud infrastructure.\r\n\r\nTraditional terminals are optimized for accessing localhost. Teleport Connect offers enhanced user experience and identity-based access for engineers who work in the cloud.\r\n\r\nTeleport Connect requires an installation of Teleport. Download Teleport [here](https://goteleport.com/download), and download Teleport Connect below.\r\n\r\nThe preview of Teleport Connect is available for amd64 Macs only. It also works on M1 Macs with Rosetta. Support for additional platforms and architectures will be added soon.\r\n\r\n## Changelog\r\n\r\n- ⬆️ Update Electron to v19\r\n- ⬆️ bundle `tsh` v9.3.0\r\n- Increased terminal scrollback to 5000 lines\r\n- Add tooltips with keyboard shortcuts\r\n\r\n![image](https://user-images.githubusercontent.com/7527103/171218601-542c5afe-045d-4d3a-8c35-fb8afe1a07a0.png)\r\n\r\n\r\n## Notes\r\n\r\n- Per-session MFA is not currently supported\r\n- Connecting to databases requires a cluster running Teleport 9.1 or newer\r\n- Shared SSH sessions and SCP are not yet supported.", + "reactions": { + "url": "https://api.github.com/repos/gravitational/teleport/releases/68253708/reactions", + "total_count": 4, + "+1": 0, + "-1": 0, + "laugh": 0, + "hooray": 4, + "confused": 0, + "heart": 0, + "rocket": 0, + "eyes": 0 + } + } +] diff --git a/lib/versioncontrol/github/test_page_3.json b/lib/versioncontrol/github/test_page_3.json new file mode 100644 index 00000000000..7b75d4e5551 --- /dev/null +++ b/lib/versioncontrol/github/test_page_3.json @@ -0,0 +1,388 @@ +[ + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/67978603", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/67978603/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/67978603/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v7.3.21", + "id": 67978603, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EDUVr", + "tag_name": "v7.3.21", + "target_commitish": "master", + "name": "Teleport 7.3.21", + "draft": false, + "prerelease": false, + "created_at": "2022-05-27T00:32:16Z", + "published_at": "2022-05-27T01:33:27Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v7.3.21", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v7.3.21", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple bug fixes and stability improvements.\r\n\r\n* Fixed issue with `tctl` not outputting debug logs. [#12918](https://github.com/gravitational/teleport/pull/12918)\r\n* Fixed issue with Kubernetes access not working when using system CA pool. [#12876](https://github.com/gravitational/teleport/pull/12876)\r\n* Improved proxy restart stability. [#12694](https://github.com/gravitational/teleport/pull/12694)\r\n* Improved memory usage in large clusters. [#12722](https://github.com/gravitational/teleport/pull/12722)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/67978623", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/67978623/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/67978623/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v8.3.12", + "id": 67978623, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EDUV_", + "tag_name": "v8.3.12", + "target_commitish": "master", + "name": "Teleport 8.3.12", + "draft": false, + "prerelease": false, + "created_at": "2022-05-26T19:01:10Z", + "published_at": "2022-05-27T01:33:57Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v8.3.12", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v8.3.12", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed issue with `tctl` not respecting `TELEPORT_HOME` environment variable. [#12758](https://github.com/gravitational/teleport/pull/12758)\r\n* Fixed issue with `tsh db ls` not displaying allowed users for databases in leaf clusters. [#12854](https://github.com/gravitational/teleport/pull/12854)\r\n* Fixed issue with not being able to execute prepared statements through MySQL database access. [#12735](https://github.com/gravitational/teleport/pull/12735)\r\n* Fixed issue with `tctl` not outputting debug logs. [#12919](https://github.com/gravitational/teleport/pull/12919)\r\n* Improved memory usage in large clusters. [#12723](https://github.com/gravitational/teleport/pull/12723)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/67432289", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/67432289/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/67432289/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.2.4", + "id": 67432289, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EBO9h", + "tag_name": "v9.2.4", + "target_commitish": "master", + "name": "Teleport 9.2.4", + "draft": false, + "prerelease": false, + "created_at": "2022-05-20T17:14:32Z", + "published_at": "2022-05-20T21:30:14Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.2.4", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.2.4", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed compatibility issue with agents connected to older auth servers. [#12728](https://github.com/gravitational/teleport/pull/12728)\r\n* Fixed issue with TLS routing endpoint advertising preference for `http/1.1` over `h2`. [#12749](https://github.com/gravitational/teleport/pull/12749)\r\n* Implemented multiple proxy restart stability improvements. [#12632](https://github.com/gravitational/teleport/pull/12632), [#12488](https://github.com/gravitational/teleport/pull/12488), [#12689](https://github.com/gravitational/teleport/pull/12689)\r\n* Improved compatibility with PuTTY. [#12662](https://github.com/gravitational/teleport/pull/12662)\r\n* Added support for global tsh config file `/etc/tsh.yaml`. [#12626](https://github.com/gravitational/teleport/pull/12626)\r\n* Added `tbot configure` command. [#12576](https://github.com/gravitational/teleport/pull/12576)\r\n* Fixed issue with Desktop Access not working in Teleport Cloud. [#12781](https://github.com/gravitational/teleport/pull/12781)\r\n* Improved Web UI performance in large clusters. [#12637](https://github.com/gravitational/teleport/pull/12637)\r\n* Fixed issue with running MySQL stored procedures via Database Access. [#12734](https://github.com/gravitational/teleport/pull/12734)\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/67325757", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/67325757/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/67325757/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v8.3.11", + "id": 67325757, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4EA089", + "tag_name": "v8.3.11", + "target_commitish": "master", + "name": "Teleport 8.3.11", + "draft": false, + "prerelease": false, + "created_at": "2022-05-19T19:38:57Z", + "published_at": "2022-05-19T21:02:05Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v8.3.11", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v8.3.11", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed issue with Teleport inadvertently respecting `HTTP_PROXY` for reverse tunnel connections. [#12335](https://github.com/gravitational/teleport/pull/12335)\r\n* Fixed issue with `tctl users rm` treating provided username as a prefix instead of full username. [#12726](https://github.com/gravitational/teleport/pull/12726)\r\n* Fixed issue with TLS routing endpoint advertising `http/1.1` preference instead of `h2`. [#12752](https://github.com/gravitational/teleport/pull/12752)\r\n* Implemented multiple proxy restart stability improvements. [#12633](https://github.com/gravitational/teleport/pull/12633), [#12545](https://github.com/gravitational/teleport/pull/12545), [#12693](https://github.com/gravitational/teleport/pull/12693)\r\n* Added support for global tsh config file `/etc/tsh.yaml`. [#12625](https://github.com/gravitational/teleport/pull/12625)\r\n* Upgraded Go to v1.17.10. [#12601](https://github.com/gravitational/teleport/pull/12601)\r\n* Improved proxy memory usage in large clusters. [#12571](https://github.com/gravitational/teleport/pull/12571)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/67010637", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/67010637/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/67010637/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v7.3.20", + "id": 67010637, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4D_oBN", + "tag_name": "v7.3.20", + "target_commitish": "master", + "name": "Teleport 7.3.20", + "draft": false, + "prerelease": false, + "created_at": "2022-05-16T18:54:40Z", + "published_at": "2022-05-16T20:20:34Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v7.3.20", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v7.3.20", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple performance and stability improvements.\r\n\r\n* Fixed issue with broken SSH connectivity after CA rotation. [#12334](https://github.com/gravitational/teleport/pull/12334)\r\n* Fixed issues with bulk deletions when using Firestore backend. [#12175](https://github.com/gravitational/teleport/pull/12175)\r\n* Improved reliability of auth/proxy services restart. [#12546](https://github.com/gravitational/teleport/pull/12546), [#12634](https://github.com/gravitational/teleport/pull/12634), [#12561](https://github.com/gravitational/teleport/pull/12561)\r\n* Improved reliability of the internal cache system. [#12245](https://github.com/gravitational/teleport/pull/12245), [#12249](https://github.com/gravitational/teleport/pull/12249)\r\n* Improved proxy service memory usage in large clusters. [#12562](https://github.com/gravitational/teleport/pull/12562)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/66755587", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/66755587/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/66755587/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.2.3", + "id": 66755587, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4D-pwD", + "tag_name": "v9.2.3", + "target_commitish": "master", + "name": "Teleport 9.2.3", + "draft": false, + "prerelease": false, + "created_at": "2022-05-13T02:11:04Z", + "published_at": "2022-05-13T03:36:29Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.2.3", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.2.3", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements and bug fixes.\r\n\r\n* Fixed issue with `HTTP_PROXY` being inadvertently respected in reverse tunnel connections. [#12335](https://github.com/gravitational/teleport/pull/12335)\r\n* Added `--format` flag to `tctl token add` command. [#12588](https://github.com/gravitational/teleport/pull/12588)\r\n* Fixed backwards compatibility issues with session upload. [#12535](https://github.com/gravitational/teleport/pull/12535)\r\n* Added support for persistency in custom mode in Helm charts. [#12218](https://github.com/gravitational/teleport/pull/12218)\r\n* Fixed issue with PostgreSQL backend not respecting username from certificate. [#12553](https://github.com/gravitational/teleport/pull/12553)\r\n* Fixed issues with `kubectl cp` and `kubectl exec` not working through Kubernetes Access. [#12541](https://github.com/gravitational/teleport/pull/12541)\r\n* Fixed issues with dynamic registration logic for cloud databases. [#12451](https://github.com/gravitational/teleport/pull/12451)\r\n* Fixed issue with automatic Add Application script failing to join the cluster. [#12539](https://github.com/gravitational/teleport/pull/12539)\r\n* Fixed issue with `tctl` crashing when PAM is enabled. [#12572](https://github.com/gravitational/teleport/pull/12572)\r\n* Added support for setting priority class and extra labels in Helm charts. [#12568](https://github.com/gravitational/teleport/pull/12568)\r\n* Fixed issue with App Access JWT tokens not including `iat` claim. [#12589](https://github.com/gravitational/teleport/pull/12589)\r\n* Added ability to inject App Access JWT tokens in rewritten headers. [#12589](https://github.com/gravitational/teleport/pull/12589)\r\n* Desktop Access automatically adds a `teleport.dev/ou` label for desktops discovered via LDAP. [#12502](https://github.com/gravitational/teleport/pull/12502)\r\n* Updated Machine ID to generates identity files compatible with `tctl` and `tsh`. [#12500](https://github.com/gravitational/teleport/pull/12500)\r\n* Updated internal build infrastructure to Go 1.17.10. [#12607](https://github.com/gravitational/teleport/pull/12607)\r\n* Improved proxy memory usage in clusters with large number of nodes. [#12573](https://github.com/gravitational/teleport/pull/12573)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/66513797", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/66513797/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/66513797/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v8.3.10", + "id": 66513797, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4D9uuF", + "tag_name": "v8.3.10", + "target_commitish": "master", + "name": "Teleport 8.3.10", + "draft": false, + "prerelease": false, + "created_at": "2022-05-10T18:53:42Z", + "published_at": "2022-05-10T20:19:43Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v8.3.10", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v8.3.10", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple bug fixes and stability improvements.\r\n\r\n* Fixed issue with broken SSH connectivity after CA rotation. [#12332](https://github.com/gravitational/teleport/pull/12332)\r\n* Fixed issue with `tsh db ls` not working for leaf clusters. [#12319](https://github.com/gravitational/teleport/pull/12319)\r\n* Fixed issue with labels matching for dynamic databases. [#12452](https://github.com/gravitational/teleport/pull/12452)\r\n* Fixed issue with resource listing not respecting limit. [#12501](https://github.com/gravitational/teleport/pull/12501)\r\n* Improved DynamoDB pay-per-request mode support. [#12460](https://github.com/gravitational/teleport/pull/12460)\r\n* Improved expiration handling in the internal caching system. [#12246](https://github.com/gravitational/teleport/pull/12246)\r\n* Improved reliability of restart/shutdown in certain scenarios. [#12394](https://github.com/gravitational/teleport/pull/12394)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/66173490", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/66173490/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/66173490/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/v9.2.1", + "id": 66173490, + "author": { + "login": "r0mant", + "id": 339322, + "node_id": "MDQ6VXNlcjMzOTMyMg==", + "avatar_url": "https://avatars.githubusercontent.com/u/339322?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/r0mant", + "html_url": "https://github.com/r0mant", + "followers_url": "https://api.github.com/users/r0mant/followers", + "following_url": "https://api.github.com/users/r0mant/following{/other_user}", + "gists_url": "https://api.github.com/users/r0mant/gists{/gist_id}", + "starred_url": "https://api.github.com/users/r0mant/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/r0mant/subscriptions", + "organizations_url": "https://api.github.com/users/r0mant/orgs", + "repos_url": "https://api.github.com/users/r0mant/repos", + "events_url": "https://api.github.com/users/r0mant/events{/privacy}", + "received_events_url": "https://api.github.com/users/r0mant/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4D8boy", + "tag_name": "v9.2.1", + "target_commitish": "master", + "name": "Teleport 9.2.1", + "draft": false, + "prerelease": false, + "created_at": "2022-05-05T21:15:18Z", + "published_at": "2022-05-05T22:50:51Z", + "assets": [], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/v9.2.1", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/v9.2.1", + "body": "## Description\r\n\r\nThis release of Teleport contains multiple improvements, security and bug fixes.\r\n\r\n* Updated `tctl rm` command to support removing tokens. [#12439](https://github.com/gravitational/teleport/pull/12439)\r\n* Fixed issue with Teleport failing to start when using DynamoDB backend in pay-per-request mode. [#12461](https://github.com/gravitational/teleport/pull/12461)\r\n* Fixed issue with Kubernetes port forwarding not working. [#12468](https://github.com/gravitational/teleport/pull/12468)\r\n* Fixed issue with IAM policy limit when using database auto-discovery on Kubernetes. [#12457](https://github.com/gravitational/teleport/pull/12457)\r\n* Fixed issue with U2F facets not being properly validated. [#12208](https://github.com/gravitational/teleport/pull/12208)\r\n* Hardened SQLite permissions. [#12360](https://github.com/gravitational/teleport/pull/12360)\r\n* Fixed issue with OIDC callback not checking `email_verified` claim. [#12360](https://github.com/gravitational/teleport/pull/12360)\r\n* Added `max_kubernetes_connections` role option for limiting simultaneous Kubernetes connections. [#12360](https://github.com/gravitational/teleport/pull/12360)\r\n* Fixed issue with Teleport failing to start with pay-per-request DynamoDB mode. [#12360](https://github.com/gravitational/teleport/pull/12360)\r\n* Reduced Machine ID verbosity in case of missing secure symlink kernel support. [#12423](https://github.com/gravitational/teleport/pull/12423)\r\n* Fixed `tsh proxy db` tunnel mode not working for CockroachDB connections. [#12400](https://github.com/gravitational/teleport/pull/12400)\r\n* Added support for database access certificates in Machine ID. [#12195](https://github.com/gravitational/teleport/pull/12195)\r\n* Improved shutdown/restart stability in certain scenarios. [#12393](https://github.com/gravitational/teleport/pull/12393)\r\n* Added support for clickable labels in web UI. [#12422](https://github.com/gravitational/teleport/pull/12422)\r\n\r\n## Download\r\n\r\nDownload the current and previous releases of Teleport at https://gravitational.com/teleport/download." + }, + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/66270517", + "assets_url": "https://api.github.com/repos/gravitational/teleport/releases/66270517/assets", + "upload_url": "https://uploads.github.com/repos/gravitational/teleport/releases/66270517/assets{?name,label}", + "html_url": "https://github.com/gravitational/teleport/releases/tag/teleport-connect-preview-1.0.1", + "id": 66270517, + "author": { + "login": "zmb3", + "id": 7527103, + "node_id": "MDQ6VXNlcjc1MjcxMDM=", + "avatar_url": "https://avatars.githubusercontent.com/u/7527103?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/zmb3", + "html_url": "https://github.com/zmb3", + "followers_url": "https://api.github.com/users/zmb3/followers", + "following_url": "https://api.github.com/users/zmb3/following{/other_user}", + "gists_url": "https://api.github.com/users/zmb3/gists{/gist_id}", + "starred_url": "https://api.github.com/users/zmb3/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/zmb3/subscriptions", + "organizations_url": "https://api.github.com/users/zmb3/orgs", + "repos_url": "https://api.github.com/users/zmb3/repos", + "events_url": "https://api.github.com/users/zmb3/events{/privacy}", + "received_events_url": "https://api.github.com/users/zmb3/received_events", + "type": "User", + "site_admin": false + }, + "node_id": "RE_kwDOAeGNGc4D8zU1", + "tag_name": "teleport-connect-preview-1.0.1", + "target_commitish": "master", + "name": "Teleport Connect Preview v1.0.1", + "draft": false, + "prerelease": false, + "created_at": "2022-05-05T20:41:54Z", + "published_at": "2022-05-06T21:55:14Z", + "assets": [ + { + "url": "https://api.github.com/repos/gravitational/teleport/releases/assets/64717495", + "id": 64717495, + "node_id": "RA_kwDOAeGNGc4D24K3", + "name": "Teleport.Connect.Preview-1.0.1.dmg", + "label": null, + "uploader": { + "login": "zmb3", + "id": 7527103, + "node_id": "MDQ6VXNlcjc1MjcxMDM=", + "avatar_url": "https://avatars.githubusercontent.com/u/7527103?v=4", + "gravatar_id": "", + "url": "https://api.github.com/users/zmb3", + "html_url": "https://github.com/zmb3", + "followers_url": "https://api.github.com/users/zmb3/followers", + "following_url": "https://api.github.com/users/zmb3/following{/other_user}", + "gists_url": "https://api.github.com/users/zmb3/gists{/gist_id}", + "starred_url": "https://api.github.com/users/zmb3/starred{/owner}{/repo}", + "subscriptions_url": "https://api.github.com/users/zmb3/subscriptions", + "organizations_url": "https://api.github.com/users/zmb3/orgs", + "repos_url": "https://api.github.com/users/zmb3/repos", + "events_url": "https://api.github.com/users/zmb3/events{/privacy}", + "received_events_url": "https://api.github.com/users/zmb3/received_events", + "type": "User", + "site_admin": false + }, + "content_type": "application/x-diskcopy", + "state": "uploaded", + "size": 103924324, + "download_count": 59, + "created_at": "2022-05-06T21:54:41Z", + "updated_at": "2022-05-06T21:55:11Z", + "browser_download_url": "https://github.com/gravitational/teleport/releases/download/teleport-connect-preview-1.0.1/Teleport.Connect.Preview-1.0.1.dmg" + } + ], + "tarball_url": "https://api.github.com/repos/gravitational/teleport/tarball/teleport-connect-preview-1.0.1", + "zipball_url": "https://api.github.com/repos/gravitational/teleport/zipball/teleport-connect-preview-1.0.1", + "body": "Teleport Connect is a developer-friendly browser for cloud infrastructure.\r\n\r\nTraditional terminals are optimized for accessing localhost. Teleport Connect offers enhanced user experience and identity-based access for engineers who work in the cloud.\r\n\r\nTeleport Connect requires an installation of Teleport. Download Teleport [here](https://goteleport.com/download), and download Teleport Connect below.\r\n\r\nThe preview of Teleport Connect is available for amd64 Macs only. It also works on M1 Macs with Rosetta. Support for additional platforms and architectures will be added soon.\r\n\r\n## Changelog\r\n\r\n- 🐛 fix for TOTP authenticators\r\n- ⬆️ bundle `tsh` v9.2.1\r\n\r\n## Notes\r\n\r\n- Per-session MFA is not currently supported\r\n- Connecting to databases requires a cluster running Teleport 9.1 or newer\r\n- Shared SSH sessions and SCP are not yet supported." + } +] diff --git a/lib/versioncontrol/versioncontrol.go b/lib/versioncontrol/versioncontrol.go new file mode 100644 index 00000000000..c52260ebb36 --- /dev/null +++ b/lib/versioncontrol/versioncontrol.go @@ -0,0 +1,17 @@ +/* +Copyright 2022 Gravitational, Inc. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. +*/ + +package versioncontrol