diff --git a/.release-please-manifest.json b/.release-please-manifest.json index 5e8b5db08..b3bd09562 100644 --- a/.release-please-manifest.json +++ b/.release-please-manifest.json @@ -1,3 +1,3 @@ { - ".": "3.104.0" + ".": "3.105.0" } diff --git a/CHANGELOG.md b/CHANGELOG.md index 48a8e75e7..c1f6ef93f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,6 +12,219 @@ are generated at release time via its release PR, not hand-edited in PRs. See model. The history below is preserved as-is across the towncrier to release-please transition (#1776). +## [3.105.0](https://github.com/PaloAltoNetworks/shifter/compare/v3.104.0...v3.105.0) (2026-09-16) + + +### Features + +* add administrator audit log and activity history surface ([3a30e4c](https://github.com/PaloAltoNetworks/shifter/commit/3a30e4c4ea20abb3bf5a93b309f4ca5be3c3ff85)) +* add administrator audit log and activity history surface ([a22bfab](https://github.com/PaloAltoNetworks/shifter/commit/a22bfab950a1c7d2b121cd4f7d41909caff9b993)) +* add AWS environment teardown workflow ([ed3a891](https://github.com/PaloAltoNetworks/shifter/commit/ed3a89101b1a763e44712cb148f4252df2067c98)) +* add AWS environment teardown workflow ([#1287](https://github.com/PaloAltoNetworks/shifter/issues/1287)) ([346f868](https://github.com/PaloAltoNetworks/shifter/commit/346f868b3ba64abe0deef3fea6d3e12ce2f9b34e)) +* add in-tenant artifact preparation ([d14930f](https://github.com/PaloAltoNetworks/shifter/commit/d14930f492b9b9a1bed5c984ea823f08e4f1ffc1)) +* add in-tenant artifact preparation ([03f24dd](https://github.com/PaloAltoNetworks/shifter/commit/03f24dd26869194cb0dfb29deb8b40211c3008c2)) +* add nazgul GCP tenant scaffolding + bake lane ([f092e2e](https://github.com/PaloAltoNetworks/shifter/commit/f092e2e5c0e7070b612f9652ad1c01777de89a20)) +* add runtime Mission Control lease policies ([f830b44](https://github.com/PaloAltoNetworks/shifter/commit/f830b446716497270034bf4dcb1af31a4efa0752)) +* administer range-to-workspace scoping and reassignment (PLAT-237) ([b9b8268](https://github.com/PaloAltoNetworks/shifter/commit/b9b82681818fed7da26fcedaa93d37586bc14c74)) +* administer range-to-workspace scoping and reassignment (PLAT-237) ([21c27c4](https://github.com/PaloAltoNetworks/shifter/commit/21c27c4db22c4ecd4699679c91cc606166575b63)) +* **api:** expose retry-safe range operations and truthful cleanup outcomes ([07ab2ac](https://github.com/PaloAltoNetworks/shifter/commit/07ab2aca4a8bc629da6e4cde8ab7cb0989d0a3d6)) +* **api:** expose retry-safe range operations and truthful cleanup outcomes ([a1d823c](https://github.com/PaloAltoNetworks/shifter/commit/a1d823cb2ac99a82b485f071eeb5674d5066f132)) +* **cms:** ship a launchable smoke-linux in-box pack ([e596e71](https://github.com/PaloAltoNetworks/shifter/commit/e596e71ad81d75e59dd3eba9ec9f2b57197d86ce)) +* complete SPA and RAES authority cutover ([9cddc3c](https://github.com/PaloAltoNetworks/shifter/commit/9cddc3cfcf2c342997c561cda2c27705af7e8b59)) +* complete SPA and RAES cutover ([aaa78a6](https://github.com/PaloAltoNetworks/shifter/commit/aaa78a64d04f7cead06100ced10364445b5c9fe9)) +* **ctf:** add public event registration ([d40f27e](https://github.com/PaloAltoNetworks/shifter/commit/d40f27e7a854c840e77fc327b6e148ead6603ab6)) +* **ctf:** bind signed receipts to range identity ([ab5bcbd](https://github.com/PaloAltoNetworks/shifter/commit/ab5bcbdcde4189f874aa2dab6c937ac0651a7df1)) +* **ctf:** bind signed receipts to range identity ([ad97760](https://github.com/PaloAltoNetworks/shifter/commit/ad9776016c1659beb7a4e24113cb1aa79a281a71)) +* **ctf:** durable delivery worker and in-app channel for scoped communications ([56ed720](https://github.com/PaloAltoNetworks/shifter/commit/56ed720345e81554ee190dbfe8897f2cea6ef2fa)) +* **ctf:** durable delivery worker and in-app channel for scoped communications ([ee69e35](https://github.com/PaloAltoNetworks/shifter/commit/ee69e356389b1e7d150f30154c5200b051cd7570)) +* **ctf:** in-place content refresh for managed CTF events ([66ccfea](https://github.com/PaloAltoNetworks/shifter/commit/66ccfea956623e75c0cdd306dc835686e7dee181)) +* **ctf:** in-place content refresh for managed CTF events ([8416c53](https://github.com/PaloAltoNetworks/shifter/commit/8416c53850013ecb7992aa0905b5547679e92dbc)) +* **ctf:** model scoped communication campaigns, audiences, content, and deliveries ([0d7a75d](https://github.com/PaloAltoNetworks/shifter/commit/0d7a75d7a5c3d2487668772eea58719add930cdd)) +* **ctf:** model scoped communication campaigns, audiences, content, and deliveries ([28c4904](https://github.com/PaloAltoNetworks/shifter/commit/28c4904c1390559910aa094c5497d896e9feb54e)) +* **ctf:** platform-admin global CTF event administration ([2324f4b](https://github.com/PaloAltoNetworks/shifter/commit/2324f4b57e675a7b1b1f0430626b64b47408f578)) +* **ctf:** platform-admin global CTF event administration ([c7a02c6](https://github.com/PaloAltoNetworks/shifter/commit/c7a02c62f672466a4480b7c6fae9d382670c8491)) +* **ctf:** support multiple full co-organizers per CTF event ([7863ca0](https://github.com/PaloAltoNetworks/shifter/commit/7863ca042f4ddc35147f93384884cf2241e018e4)) +* **ctf:** support multiple full co-organizers per CTF event ([d16915a](https://github.com/PaloAltoNetworks/shifter/commit/d16915a761ee51ad9dc4713a7ada67b180ab27e6)) +* **ctf:** unified communication admission and scheduler due-time integration ([6a9da4f](https://github.com/PaloAltoNetworks/shifter/commit/6a9da4f00e81ffec5c9e8e1bc7676dff20efd375)) +* **ctf:** unified communication admission and scheduler due-time integration ([ac30b92](https://github.com/PaloAltoNetworks/shifter/commit/ac30b927bae932cb9c8fa4a1f1c412e7d41691c5)) +* deployment-configurable Mission Control range lease policy ([ac9a0e5](https://github.com/PaloAltoNetworks/shifter/commit/ac9a0e560ba20e99744d6a314f87894af5466cb7)) +* deployment-configurable Mission Control range lease policy ([79f160e](https://github.com/PaloAltoNetworks/shifter/commit/79f160e5ca94b855ae2899b264206767c1113b49)) +* enforce browser accessibility with an axe gate and ADR-055 baseline ratchet ([d0e9533](https://github.com/PaloAltoNetworks/shifter/commit/d0e953395c9c6e12c4734d03de1b549d7bf4f169)) +* enforce browser accessibility with an axe gate and ADR-055 baseline ratchet ([10d18f7](https://github.com/PaloAltoNetworks/shifter/commit/10d18f74e15a21a34534b3c935c2e907f19e65bb)) +* enforce GCP zero-egress firewall for pinned none ranges (PLAT-238) ([5e625db](https://github.com/PaloAltoNetworks/shifter/commit/5e625db97977581f59a8954909504fcd5ad85c3a)) +* **engine:** seed RAES image registry from base range image env ([c4b44fb](https://github.com/PaloAltoNetworks/shifter/commit/c4b44fb836f9ef16526653c2783415873381ec0c)) +* **gcp:** add the [#2087](https://github.com/PaloAltoNetworks/shifter/issues/2087) range-escape containment-signal seam ([dea807f](https://github.com/PaloAltoNetworks/shifter/commit/dea807f1dfcdeaddcdcc36aa3bc501475ac072ed)) +* **gcp:** add the [#2087](https://github.com/PaloAltoNetworks/shifter/issues/2087) range-escape containment-signal seam ([4a4613c](https://github.com/PaloAltoNetworks/shifter/commit/4a4613c44eda03f77758cf76b578e3b47070958d)) +* **gcp:** bootstrap single-project deployments from external inventory ([5fbf929](https://github.com/PaloAltoNetworks/shifter/commit/5fbf929df82717164ed027c01f8ed355b95c0929)) +* **gcp:** bootstrap single-project deployments from inventory ([0b08091](https://github.com/PaloAltoNetworks/shifter/commit/0b080912fccf7456751c92ea019c2a8761ad8563)) +* **gcp:** fail-fast on GCE range preconditions before gdc-bootstrap deploys ([0105598](https://github.com/PaloAltoNetworks/shifter/commit/0105598a1b365438f371fa3b24ef421cdf237669)) +* **gcp:** fail-fast on GCE range preconditions before gdc-bootstrap deploys ([d1b44b0](https://github.com/PaloAltoNetworks/shifter/commit/d1b44b0d16d2938ca9d3e8c27dfbe71f8b02b167)) +* **gcp:** multi-region range-cell placement via RANGE_NETWORK_ZONES ([b89c773](https://github.com/PaloAltoNetworks/shifter/commit/b89c77322e837086b0de02ac1b5636cc1a3a1501)) +* **gcp:** multi-region range-cell placement via RANGE_NETWORK_ZONES ([3d56aa4](https://github.com/PaloAltoNetworks/shifter/commit/3d56aa40990b63f22f012f6e3e25485b0b045f43)) +* **gcp:** package isolated model broker deployment ([345ef30](https://github.com/PaloAltoNetworks/shifter/commit/345ef3022c2aa00f3cf30445fc0be9f6d8d1f7e7)) +* **gcp:** package isolated model broker deployment ([05c51e8](https://github.com/PaloAltoNetworks/shifter/commit/05c51e84da898105be05fa55f577e6219a7994ec)) +* **installation:** complete AWS EKS bundle runtime-env projection and doctor preflight ([3aa0741](https://github.com/PaloAltoNetworks/shifter/commit/3aa0741783c2cd339e4a99a11a882d04c19f3712)) +* **installation:** complete AWS EKS bundle runtime-env projection, doctor preflight, and settings/inventory modules ([b2d3c14](https://github.com/PaloAltoNetworks/shifter/commit/b2d3c14e0c2360c52bb2cd681242e5d6a4784a7d)) +* **mission-control:** enforce per-file agent upload limit before transfer ([9b45170](https://github.com/PaloAltoNetworks/shifter/commit/9b4517081c40ce31f488a612f0276915d9dcc297)) +* **mission-control:** enforce per-file agent upload limit before transfer ([e624add](https://github.com/PaloAltoNetworks/shifter/commit/e624addf2e4f74ea2aab01a13a0ef6dd614209b3)) +* **model-access:** define policy catalog and shared access contracts ([fadb418](https://github.com/PaloAltoNetworks/shifter/commit/fadb418d3846cbc16066a570029bb048c3667df8)) +* **model-access:** enforce project sharing authority ([39c1337](https://github.com/PaloAltoNetworks/shifter/commit/39c1337f4a1402916f7f8445e5333290f78d4733)) +* **model-access:** enforce required scenario/event model admission before launch (PLAT-202) ([7511688](https://github.com/PaloAltoNetworks/shifter/commit/75116884dad647addaa0b69fdcc67641080d27a8)) +* **model-access:** enforce required scenario/event model admission before launch (PLAT-202) ([4cb00fa](https://github.com/PaloAltoNetworks/shifter/commit/4cb00fa9bb0c38a33f29dec720f628047db8ace7)) +* **model-access:** persist sharing bindings and resolve overlapping policies ([201f097](https://github.com/PaloAltoNetworks/shifter/commit/201f097d7d2bcc5751c76c7bf6f5f3adf1f5b38e)) +* **model-access:** persist sharing bindings and resolve overlapping policies ([551d671](https://github.com/PaloAltoNetworks/shifter/commit/551d671f5795b21cb5070bc3c244c98e56c6a571)) +* **model-access:** project sharing authority changes ([9d004d8](https://github.com/PaloAltoNetworks/shifter/commit/9d004d8b47d847b4da5df0daa3d888371e0e98b5)) +* parameterize gdc-bootstrap by environment for multi-tenant standup ([985f91e](https://github.com/PaloAltoNetworks/shifter/commit/985f91e806b7ea915ccb464adc324272addf32b2)) +* parity-safe GCP range pause/resume for GDC VM Runtime and GCE ([557c699](https://github.com/PaloAltoNetworks/shifter/commit/557c699b25546c7d2eca8bc6bd3b64cae82dd792)) +* parity-safe GCP range pause/resume for GDC VM Runtime and GCE ([144838e](https://github.com/PaloAltoNetworks/shifter/commit/144838e6ef6f0ded282593608694c732754cd54a)) +* range-owned GCP Cloud NAT so none ranges have no NAT path (PLAT-238) ([fd7842e](https://github.com/PaloAltoNetworks/shifter/commit/fd7842e39c3a4fcc4f461698f8d76ea61ffc04aa)) +* **range:** configurable warm pool for faster initial launch ([045d7e9](https://github.com/PaloAltoNetworks/shifter/commit/045d7e9c9eeb97a9e242b04a65c9e18b7ec675cb)) +* **range:** configurable warm pool for faster initial launch ([#28](https://github.com/PaloAltoNetworks/shifter/issues/28)) ([5672618](https://github.com/PaloAltoNetworks/shifter/commit/567261837c5a6799cc8a86260e91ba5a1cb858f5)) +* **range:** ship launchable smoke-linux pack + RAES-aware post-deploy smoke ([4e218af](https://github.com/PaloAltoNetworks/shifter/commit/4e218afcaa016b6332095ab0bb457a548725019a)) +* realize pinned range egress on the AWS provisioner path (PLAT-238) ([b741e72](https://github.com/PaloAltoNetworks/shifter/commit/b741e72af63b14d69dea9c3ca3b14e8f2147c77d)) +* user lifecycle administration (suspend/reset/ownership transfer) ([5764ad4](https://github.com/PaloAltoNetworks/shifter/commit/5764ad4ebdb1a4caa36e82a4b392d0c70e9a183c)) +* user lifecycle administration (suspend/reset/ownership transfer) ([d96706a](https://github.com/PaloAltoNetworks/shifter/commit/d96706aa127cc6f77a474ce35c71a7c268a85a3d)) +* workspace egress policy control in the SPA admin surface (PLAT-238) ([b5f3ede](https://github.com/PaloAltoNetworks/shifter/commit/b5f3ede4378ad2eb1687c76fa4819bc21ba4c6b3)) +* workspace network egress policy backend spine (PLAT-238) ([a97dcd8](https://github.com/PaloAltoNetworks/shifter/commit/a97dcd8fb4aa7929c28517323a11f6a0ce60b3ea)) +* workspace-level network egress policy (zero-egress) on AWS and GCP ([518fdbd](https://github.com/PaloAltoNetworks/shifter/commit/518fdbd685bdcd4a67cd6e45a43767b32881a209)) +* **workspaces:** add member invitations and onboarding ([810564a](https://github.com/PaloAltoNetworks/shifter/commit/810564a61edc79bf76ba4ceed93ebd21b69a8670)) +* **workspaces:** add member invitations and onboarding ([e0a4a57](https://github.com/PaloAltoNetworks/shifter/commit/e0a4a574fa4202fc4687980c5a7c3b22a5ee7d83)) +* **workspaces:** add per-workspace resource quotas and usage ([36a06b7](https://github.com/PaloAltoNetworks/shifter/commit/36a06b780004dc2318f8d36d99cb8a0da281dd4c)) +* **workspaces:** add per-workspace resource quotas and usage ([ce594fd](https://github.com/PaloAltoNetworks/shifter/commit/ce594fd5eafd55223fb8b7d4421c666ceb2ae739)) + + +### Bug Fixes + +* address pre-merge review — undeployable NAT, deny-all firewall, agent URL, token-auth contract (PLAT-238) ([f40bf02](https://github.com/PaloAltoNetworks/shifter/commit/f40bf02a5bebcdb709d6c974d81c212fa06096d1)) +* address review cycle 2 — move-chain, fail-closed egress, model layering, session-only auth (PLAT-238) ([53e9d19](https://github.com/PaloAltoNetworks/shifter/commit/53e9d195d4040637dc47164d2c58d1439b32dc2e)) +* **adr-guard:** address Sonar documentation findings ([613f365](https://github.com/PaloAltoNetworks/shifter/commit/613f365ac037a4b23481e3f87d1b841dec9ca33f)) +* **adr-guard:** address Sonar documentation findings ([245ec34](https://github.com/PaloAltoNetworks/shifter/commit/245ec34d0b38b7252f52f3f3210cf92301eaf6b6)) +* **adr-guard:** clarify ingress schema field ([e504650](https://github.com/PaloAltoNetworks/shifter/commit/e504650a31001a20e154e08a7c59dfcfff6dacab)) +* **adr-guard:** resolve new-code Sonar findings ([e85bafa](https://github.com/PaloAltoNetworks/shifter/commit/e85bafa93c1aa352dd207205b4df5bb79c792a81)) +* **adr-guard:** resolve new-code Sonar findings ([237e378](https://github.com/PaloAltoNetworks/shifter/commit/237e3787c832c073a054255d82fb051d0436caa1)) +* **api:** address CI Postgres-lane + SonarCloud findings on retry-safe operations ([aef8c4b](https://github.com/PaloAltoNetworks/shifter/commit/aef8c4b6ef5d1897bc3dbda83adfd6740fcaaa29)) +* **api:** align public contract with runtime boundaries ([ee6639c](https://github.com/PaloAltoNetworks/shifter/commit/ee6639ca9ab5a2c772860a482eab2213fc42bd4e)) +* **api:** align published contract with runtime authority ([33d15c7](https://github.com/PaloAltoNetworks/shifter/commit/33d15c73ad4ece7de4205f00d7ba2f10436980bc)) +* **api:** align scoreboard runtime with published contract ([bfa34eb](https://github.com/PaloAltoNetworks/shifter/commit/bfa34eb8c329866466bc8975c254b96899db54bf)) +* **api:** resolve SonarCloud findings in retry-safe launch mixin and cleanup projection ([1e98a9a](https://github.com/PaloAltoNetworks/shifter/commit/1e98a9aec0863481d54bb9fa2a85d414d75a5ee1)) +* **api:** split range history projection ([7fe8066](https://github.com/PaloAltoNetworks/shifter/commit/7fe806686476ed35377a5094524b3ca789e700b6)) +* **bootstrap:** stop deploy facade from clobbering distinct module main entrypoints ([9dcc016](https://github.com/PaloAltoNetworks/shifter/commit/9dcc016cc5e7f8bcb301fe034b27fcabf2fc7a94)) +* CI quality gate — mypy auth typing, ruff format, provisioner operation-dict assertion (PLAT-238) ([4808b41](https://github.com/PaloAltoNetworks/shifter/commit/4808b41cef944a35f51aa38ebefd28b6e5ba35a0)) +* clarify gcp resource metadata handling ([ec14d31](https://github.com/PaloAltoNetworks/shifter/commit/ec14d315789fff24eca9782a233b852a931b9e05)) +* clear artifact preparation quality findings ([4cb947d](https://github.com/PaloAltoNetworks/shifter/commit/4cb947d6bd43b134425b31fe6b192358b53da707)) +* clear remaining SonarCloud new-code smells (docstrings, type hint, S5778) ([e5a170a](https://github.com/PaloAltoNetworks/shifter/commit/e5a170a5ed847cd7a74eee0d6570151f247fe2b8)) +* close cyberscript GCE egress gap + RAES router leak; test-quality forwarding (PLAT-238) ([fdcd8d4](https://github.com/PaloAltoNetworks/shifter/commit/fdcd8d4a5c47a63ae7f1dd2812a1ae90d199df35)) +* **cms:** align retry-safe launch with post-PLAT-202 create_range_dispatch ([64bb600](https://github.com/PaloAltoNetworks/shifter/commit/64bb60057fecbc8a53d8e4307a921c24295d7540)) +* complete artifact preparation quality gates ([ab9e00b](https://github.com/PaloAltoNetworks/shifter/commit/ab9e00bfcc539d5663b5c415b0a6fdc25c0ebe90)) +* **ctf:** address validator quality findings ([eff78a4](https://github.com/PaloAltoNetworks/shifter/commit/eff78a4d09a7c2303a47a796ab5f240271996bf6)) +* **ctf:** address validator quality findings ([cd3e16a](https://github.com/PaloAltoNetworks/shifter/commit/cd3e16a2cfcd888d3997f8c0340be2b27002d28e)) +* **ctf:** clear remaining SonarCloud new-code findings (type hints, re-export imports) ([4583bd4](https://github.com/PaloAltoNetworks/shifter/commit/4583bd48ac1efb940f2b076304a69d4248a607c8)) +* **ctf:** close participant readiness safety gaps ([29fa2f3](https://github.com/PaloAltoNetworks/shifter/commit/29fa2f38c084315e315935de3b168bb3a1981cec)) +* **ctf:** close participant readiness safety gaps ([69abe12](https://github.com/PaloAltoNetworks/shifter/commit/69abe125ab3f3070c91fcae2945c38662cbb4bf9)) +* **ctf:** close participant readiness safety gaps ([7eecf96](https://github.com/PaloAltoNetworks/shifter/commit/7eecf96379df59b2f2db3c40089f5a0755850070)) +* **ctf:** keep staff-assign role request field backward-compatible (ADR-040) ([82e830d](https://github.com/PaloAltoNetworks/shifter/commit/82e830d0cdd0a1c9dcef5ec6dbf269e6a0686f26)) +* **ctf:** lock receipt range without nullable join ([1117dd4](https://github.com/PaloAltoNetworks/shifter/commit/1117dd48152a4dd9581dc4a11a7be0927d19440a)) +* **ctf:** narrow parsed URL type ([ffde5d3](https://github.com/PaloAltoNetworks/shifter/commit/ffde5d3509bf42c29bf2741b377b6a453fe7e719)) +* **ctf:** narrow parsed URL type ([5840905](https://github.com/PaloAltoNetworks/shifter/commit/5840905e4d57a4afacd74d7db001dc14bcbe6fa8)) +* **ctf:** precompute challenge filter URLs in the view (Web:MaxLineLengthCheck) ([800f1be](https://github.com/PaloAltoNetworks/shifter/commit/800f1bec0485c08cb494560b220c5a2bf2de8756)) +* **ctf:** refresh submission API contract ([e28fdbf](https://github.com/PaloAltoNetworks/shifter/commit/e28fdbfee7d677eaf435ea045d21a739a4e0fb04)) +* **ctf:** renumber shared audit entity_type migration to 0015 after dev merge ([984fc05](https://github.com/PaloAltoNetworks/shifter/commit/984fc0540b37a6a53ee6e00ea6c2a902584982cc)) +* **ctf:** resolve SonarCloud new-code findings (type hints, file split, audit atomicity) ([4ddbfe0](https://github.com/PaloAltoNetworks/shifter/commit/4ddbfe0006dbccef946aa29eaad88201d06f1dcd)) +* **ctf:** service-boundary authz asserts, stale-role revocation, and file splits ([b573353](https://github.com/PaloAltoNetworks/shifter/commit/b573353105e5eb54b6a11a4cb1c71abce76eb374)) +* **ctf:** trim _crud.py docstrings under the 500-line new-code limit ([6db33c4](https://github.com/PaloAltoNetworks/shifter/commit/6db33c4c45db3b0537fbc66b6ab2aa84fb3bd943)) +* enforce participant readiness evidence ([84d7f9f](https://github.com/PaloAltoNetworks/shifter/commit/84d7f9f6b175f5e45a3a849d8a802af317bb5b1c)) +* enforce participant readiness evidence ([4209e94](https://github.com/PaloAltoNetworks/shifter/commit/4209e946051efb724caf321268e0c73feedc57da)) +* finish nazgul GCP standup — Helm metadata netpol, evidence read, polaris verify-stack ([d28af86](https://github.com/PaloAltoNetworks/shifter/commit/d28af86019f84cc36f56927d1d34f641dbe9b26b)) +* **frontend:** redirect legacy settings route ([711245d](https://github.com/PaloAltoNetworks/shifter/commit/711245df8cf823cc20e5754573a9d51caefd4604)) +* gate GCS usage-log delivery for Domain Restricted Sharing orgs ([435c9ef](https://github.com/PaloAltoNetworks/shifter/commit/435c9ef380d240c717aef63e397d0dada737c23a)) +* **gcp:** add platform-network Private Google Access DNS for googleapis ([3114d68](https://github.com/PaloAltoNetworks/shifter/commit/3114d680280faf49707f0d3ed87554927a058fe2)) +* **gcp:** add platform-network Private Google Access DNS for googleapis ([8c853fa](https://github.com/PaloAltoNetworks/shifter/commit/8c853facf1c21ee26eb8017311b52616dbb26c6d)) +* **gcp:** add the missing Workload Identity annotation for provisioner-launcher ([3bc7234](https://github.com/PaloAltoNetworks/shifter/commit/3bc7234fa5858cb63807656b09331785c4d1c999)) +* **gcp:** address bootstrap CI and Sonar findings ([09118d7](https://github.com/PaloAltoNetworks/shifter/commit/09118d7a4686b05e6b5691b9930716cee7c6d3c0)) +* **gcp:** allow egress to the GKE metadata server for Workload Identity ([5ec586e](https://github.com/PaloAltoNetworks/shifter/commit/5ec586e604072ee8d045adb3aafce02fb217da96)) +* **gcp:** allow provisioner-launcher egress to the GKE control-plane CIDR ([8e21f89](https://github.com/PaloAltoNetworks/shifter/commit/8e21f898ac0e4e77dd9258850461872e0952daf6)) +* **gcp:** allow shifter-jobs egress to Cloud SQL for range provisioning ([ef015d2](https://github.com/PaloAltoNetworks/shifter/commit/ef015d2672934b18d0de68944bcdb12bd3dc8486)) +* **gcp:** allow the Google APIs backend range on platform/jobs egress ([f45b1ab](https://github.com/PaloAltoNetworks/shifter/commit/f45b1ab7bfb8e76609644b32d397ccbd89db1488)) +* **gcp:** close range-cell egress release-blockers under ADR-056 ([27cd255](https://github.com/PaloAltoNetworks/shifter/commit/27cd255ca3a6dec132d3711b380f1e32946a052a)) +* **gcp:** close range-cell egress release-blockers under ADR-056 ([84217da](https://github.com/PaloAltoNetworks/shifter/commit/84217dadb1fdbd480c72b09dd5e6b19d1468f3f9)) +* **gcp:** deploy worker-operation-result-applier (was orphaned manifest) ([a5a536c](https://github.com/PaloAltoNetworks/shifter/commit/a5a536c088e0c27ace2a96ec48658696e703744c)) +* **gcp:** disable NodeLocal DNSCache (incompatible with Dataplane V2) ([08865ff](https://github.com/PaloAltoNetworks/shifter/commit/08865ff40701b540f11f63c80b863c3f748cd10d)) +* **gcp:** disable NodeLocal DNSCache (incompatible with Dataplane V2) ([bf33891](https://github.com/PaloAltoNetworks/shifter/commit/bf3389132ce1331987d1703e883b6104e88f00e0)) +* **gcp:** docstring the containment-signal delivery helper (Sonar) ([2e6a5b9](https://github.com/PaloAltoNetworks/shifter/commit/2e6a5b9fc384d8e17b593e5b0606b71b5a14e58b)) +* **gcp:** drop the inert 34.126.0.0/18 backend range (red herring) ([a92846d](https://github.com/PaloAltoNetworks/shifter/commit/a92846d88f7bbf0428cd3a69796bdbd52ae2c530)) +* **gcp:** enable Cloud NAT dynamic port allocation for the platform VPC ([b44cfa7](https://github.com/PaloAltoNetworks/shifter/commit/b44cfa72d7475f6aca59453e628d484a00bd8f4f)) +* **gcp:** enable Cloud NAT dynamic port allocation for the platform VPC ([7754782](https://github.com/PaloAltoNetworks/shifter/commit/7754782ae996e83f215ed57a872c1f124c502e7a)) +* **gcp:** enable workload identity for gcp-dev platform pods ([c26362a](https://github.com/PaloAltoNetworks/shifter/commit/c26362a344e80393a1b81fbba1947f9cff55d312)) +* **gcp:** enforce control-plane NetworkPolicy via GKE Dataplane V2 ([4d4b726](https://github.com/PaloAltoNetworks/shifter/commit/4d4b7268f23d01567700d99af7b4851abace54a0)) +* **gcp:** enforce control-plane NetworkPolicy via GKE Dataplane V2 ([07ff61f](https://github.com/PaloAltoNetworks/shifter/commit/07ff61f589119f0f496d41ab31f711849778c50b)) +* **gcp:** fix fresh GCE-backend deploy gaps (GDC baremetal-gcr gate + virtctl) ([218faf1](https://github.com/PaloAltoNetworks/shifter/commit/218faf1a5fcdef7a631c6ff32e345d245793915d)) +* **gcp:** gate GDC baremetal-gcr image-reader off the default GCE apply ([3c2d810](https://github.com/PaloAltoNetworks/shifter/commit/3c2d81013d690c44f6e53c19e6e2442ccd4145fd)) +* **gcp:** grant the CI deploy SA the platform-core roles it needs ([a35a5fb](https://github.com/PaloAltoNetworks/shifter/commit/a35a5fb429e239d535f364de20c1751e6c4da9e6)) +* **gcp:** grant the CI deploy SA the platform-core roles it needs (enumerated) ([24d2497](https://github.com/PaloAltoNetworks/shifter/commit/24d2497c10a55159356fe3496de3684a5987d16e)) +* **gcp:** harden the cluster default node pool config (Shielded secure boot) ([f6328bb](https://github.com/PaloAltoNetworks/shifter/commit/f6328bb27ab93da270b7151c781f38b37251265c)) +* **gcp:** keep range model under the S104 line ceiling ([47e06c1](https://github.com/PaloAltoNetworks/shifter/commit/47e06c16797a7450068a7be65a9f73c905cb81b9)) +* **gcp:** make CI OIDC/WIF a foundational root so gcp-dev destroy+rebuild cycles ([728403d](https://github.com/PaloAltoNetworks/shifter/commit/728403d141509587e2ac811f95b33430cf09c258)) +* **gcp:** make CI OIDC/WIF a foundational root so gcp-dev destroy+rebuild cycles ([b84ff7c](https://github.com/PaloAltoNetworks/shifter/commit/b84ff7cfa39a744fd3dceb132b86fdb647d4e9b8)) +* **gcp:** make range guests reachable for setup + probe ([19cefe0](https://github.com/PaloAltoNetworks/shifter/commit/19cefe0ae4196176137833f1d671c3b476daca62)) +* **gcp:** pin the GKE cluster default node pool to the dedicated node SA ([6fd9463](https://github.com/PaloAltoNetworks/shifter/commit/6fd946352ec22c8bf373a04b52f738f9f6c6a9f4)) +* **gcp:** pin the GKE cluster default node pool to the dedicated node SA ([8a5b504](https://github.com/PaloAltoNetworks/shifter/commit/8a5b5044dcbed66c26af2bbc2cacb3abdd21353a)) +* **gcp:** pin virtctl digest and gate it off the default GCE provisioner image ([afea747](https://github.com/PaloAltoNetworks/shifter/commit/afea7478b8ff0447205d7d3240108eeb6168362c)) +* **gcp:** resolve gcp-dev-destroy state addresses by suffix ([e55a65e](https://github.com/PaloAltoNetworks/shifter/commit/e55a65ecb11ebb1fdf2c277bfcb015dc0d29c1ea)) +* **gcp:** resolve gcp-dev-destroy state addresses by suffix (fix skipped guards) ([2da283e](https://github.com/PaloAltoNetworks/shifter/commit/2da283ec471dd16250d85e23edc4641a0701487b)) +* **gcp:** scope the deploy SA's serviceAccountUser to the GKE node SA ([b1d944d](https://github.com/PaloAltoNetworks/shifter/commit/b1d944d1bc9a0006ca502bf9408501c4577be500)) +* **gcp:** separate CI identities ([f6f0b7b](https://github.com/PaloAltoNetworks/shifter/commit/f6f0b7b340cd3dd81f9de8b3bd49368ad5e2e774)) +* **gcp:** separate CI identities ([d1a1146](https://github.com/PaloAltoNetworks/shifter/commit/d1a11466d755b34df4f6a26c0e0d587ec26308d5)) +* **gcp:** support immutable GitHub deployment identities ([abfd5e9](https://github.com/PaloAltoNetworks/shifter/commit/abfd5e9b45480d9bd6c2d9f32768751001c0c985)) +* **gcp:** type hints + keep range model within line budget (Sonar [#2037](https://github.com/PaloAltoNetworks/shifter/issues/2037)) ([1dc3f89](https://github.com/PaloAltoNetworks/shifter/commit/1dc3f89b389bb99f908491251e5c0a3ba988c47f)) +* grant packer SA bucket-metadata reader on gdc-vm-images (GDC export + polaris stack fetch) ([77f0e9b](https://github.com/PaloAltoNetworks/shifter/commit/77f0e9ba2688f21bba24f044d703bc3256483afe)) +* ignore create-only default-pool node_config drift on GKE cluster ([f39a905](https://github.com/PaloAltoNetworks/shifter/commit/f39a9056f2f0dad917a3fb2a2e8307522db9e46a)) +* make network firewall teardown ordering-safe (rule-group dereference + inspection route toggle) ([f722188](https://github.com/PaloAltoNetworks/shifter/commit/f7221883b0c43b837d5eda5608b5b73ec3b6d284)) +* **model-access:** regenerate /api/v1 contract for CTFEvent.model_demand ([1c20b63](https://github.com/PaloAltoNetworks/shifter/commit/1c20b6360e257070eec044f1365aaf8426a0e18f)) +* **model-access:** regenerate SPA openapi types for CTFEvent.model_demand ([f8ecdf6](https://github.com/PaloAltoNetworks/shifter/commit/f8ecdf610f769972357e0a60dd657d2f23142c22)) +* **model-access:** resolve remaining quality findings ([23521bf](https://github.com/PaloAltoNetworks/shifter/commit/23521bfc318a4fe0d1e16de1b7faeeb6c635ff6c)) +* **model-access:** resolve SonarCloud quality-gate findings ([ac84696](https://github.com/PaloAltoNetworks/shifter/commit/ac84696924103d7344f5dc67ddbf5a36cab05097)) +* **model-access:** satisfy PostgreSQL and quality gates ([f34e4d7](https://github.com/PaloAltoNetworks/shifter/commit/f34e4d7608d6d0d60465158b8688f096327fa112)) +* **model-access:** satisfy Sonar line-length rule ([e9ec4ec](https://github.com/PaloAltoNetworks/shifter/commit/e9ec4ec610db679f9367515686a1337b84cf57ed)) +* **ngfw:** drop dead popup.closed===undefined check (javascript:S3403) ([9323209](https://github.com/PaloAltoNetworks/shifter/commit/93232094e6149dc3970910dc60e9a5b31eff94c7)) +* order-safe Network Firewall teardown for range rule groups and portal route toggle ([bbd41fe](https://github.com/PaloAltoNetworks/shifter/commit/bbd41fe6116193472104fce10943b7154afcd2f5)) +* **packer:** kali GCE guest boots + sshd binds — static networkd config ([bee2443](https://github.com/PaloAltoNetworks/shifter/commit/bee2443a4fb504cd1ca615e63ac08b0152b35ffe)) +* **packer:** kali guest boots on GCE — remove NetworkManager dual-stack ([0496561](https://github.com/PaloAltoNetworks/shifter/commit/049656157922c8411ecb6f4b1812726b838382c7)) +* parametrize dict generics for SonarCloud new-code gate ([#1287](https://github.com/PaloAltoNetworks/shifter/issues/1287)) ([11fd1de](https://github.com/PaloAltoNetworks/shifter/commit/11fd1de573b700087b9732d3f40aca5bd6e4da09)) +* polaris splice helper hands off to a14-kali's real entrypoint path ([e028a88](https://github.com/PaloAltoNetworks/shifter/commit/e028a880fc10a3d7a96ab5a0dbfd480a597fc47b)) +* **polaris:** preserve splice credential on recreation ([3c497cc](https://github.com/PaloAltoNetworks/shifter/commit/3c497cc83b568595593e4cc7ba0f0e4c94752868)) +* **polaris:** preserve splice credential on recreation ([9b0f5a9](https://github.com/PaloAltoNetworks/shifter/commit/9b0f5a9c4dbb094a0a820a1498520420417040e5)) +* postgres FOR UPDATE join + SonarCloud new-code findings ([19c0f15](https://github.com/PaloAltoNetworks/shifter/commit/19c0f153aee41d80c62eb004bfa48f1963040e7f)) +* **provisioner:** drop invalid provider= kwarg to build_guest_execution_context ([483e7c0](https://github.com/PaloAltoNetworks/shifter/commit/483e7c0dd8278aa2912d7da786dde912bfda3b06)) +* **provisioner:** keep compensation diagnostics bounded and file under size gate ([42284ca](https://github.com/PaloAltoNetworks/shifter/commit/42284ca216f16cd8eb055737e52bf2f00894fd40)) +* **provisioner:** log credential-channel failure type without leaking secrets ([c6cd210](https://github.com/PaloAltoNetworks/shifter/commit/c6cd210c3c7451bf91022f58006e79e70b1f829e)) +* **provisioner:** route failed-provision compensation through canonical teardown ([e3ce40d](https://github.com/PaloAltoNetworks/shifter/commit/e3ce40dd1cc0c6341aa1060cf5f98dd938f20d88)) +* **provisioner:** route failed-provision compensation through canonical teardown ([cfbe0cd](https://github.com/PaloAltoNetworks/shifter/commit/cfbe0cdeac125d034b5140bc5d2baea1b67a742b)) +* **provisioner:** surface the real cause of credential-channel failures ([a741e85](https://github.com/PaloAltoNetworks/shifter/commit/a741e856ba0a50177c42d3738581cf8efd841ba7)) +* **quality:** extract inline template JS to static files, split long JS/templates, bundle tags-builder params; document verified SonarCloud false-positives ([c3b01ee](https://github.com/PaloAltoNetworks/shifter/commit/c3b01ee538ffc02aca52b9e40a27833b2e53e0a2)) +* **quality:** resolve ~400 SonarCloud maintainability findings (type hints, docstrings, static methods, comment placement, complexity) ([811713f](https://github.com/PaloAltoNetworks/shifter/commit/811713f18df4985566ab7dfd2370b67f6d7f0175)) +* **quality:** resolve all open SonarCloud findings across the repo ([a3cd24a](https://github.com/PaloAltoNetworks/shifter/commit/a3cd24a821b584e000d1bcacbaa871bacb1ebe7e)) +* **quality:** resolve all open SonarCloud findings across the repo ([9a069f9](https://github.com/PaloAltoNetworks/shifter/commit/9a069f9a4b4b4084c0cefe7c0dc61036513c8e1d)) +* **quality:** resolve SonarCloud vulnerabilities, bugs, and critical findings (code smells tracked in [#2185](https://github.com/PaloAltoNetworks/shifter/issues/2185)) ([25f22ed](https://github.com/PaloAltoNetworks/shifter/commit/25f22ed06a42edc6588d45fd1ac6f64ae537440a)) +* **raes:** scope image-registry projection by authored source name ([0bb8530](https://github.com/PaloAltoNetworks/shifter/commit/0bb8530d8df557a0692a4305c332cacd1bb6dfd8)) +* re-parent 0055 egress-mode migration onto 0054 placement-zone leaf (PLAT-238) ([879a570](https://github.com/PaloAltoNetworks/shifter/commit/879a570643d282485a12d7bdcc426076ea86c1ae)) +* resolve API contract drift and SonarCloud new-code smells (PLAT-237) ([845defa](https://github.com/PaloAltoNetworks/shifter/commit/845defa7d74f9229e8c4f192319beb42120d17db)) +* resolve bootstrap SAST B404 on type-only subprocess import ([#1287](https://github.com/PaloAltoNetworks/shifter/issues/1287)) ([e758373](https://github.com/PaloAltoNetworks/shifter/commit/e758373752c35586ca1cbdbb1fac47bcb8b118c8)) +* resolve remaining preparation quality findings ([1c95d7a](https://github.com/PaloAltoNetworks/shifter/commit/1c95d7ac4524c13cf657fbe2f4138bfac354f6e9)) +* return authored range-scope error messages (CodeQL py/stack-trace-exposure) ([b36d668](https://github.com/PaloAltoNetworks/shifter/commit/b36d6686dd9e1cfa8c8680748ade3880e67ff3d1)) +* **runner:** standardize isolated runner network placement ([43e6b79](https://github.com/PaloAltoNetworks/shifter/commit/43e6b79fc44812fe22f6b8283f7274404e7ccbd7)) +* **runner:** standardize isolated runner network placement ([bab316e](https://github.com/PaloAltoNetworks/shifter/commit/bab316e1b7621121a48595648d0922a65af25dc3)) +* sanitize request id in range-scope logs (CodeQL py/log-injection) ([6dcd083](https://github.com/PaloAltoNetworks/shifter/commit/6dcd08378e3c4fb1df2ce1cf37dec04499cf2645)) +* satisfy cutover API and quality gates ([3482e15](https://github.com/PaloAltoNetworks/shifter/commit/3482e1541aa518b00ae6c54b78f409e02a7d356f)) +* **security:** validate same-origin redirect targets in extracted JS and stop exception-detail exposure in auth session view (CodeQL) ([540e793](https://github.com/PaloAltoNetworks/shifter/commit/540e7932466b5d3c1fb20557e7052214417d4ab9)) +* **smoke-linux:** re-bind pack digest after concepts.md em-dash fix ([ffed60e](https://github.com/PaloAltoNetworks/shifter/commit/ffed60ef50ad4d944116f79af0f68c81f09212ad)) +* **smoke:** make post-deploy smoke work with RAES-native ranges ([dd717eb](https://github.com/PaloAltoNetworks/shifter/commit/dd717eb9fa54a9b54b36af2065caa6be37008bad)) +* supply bake-time DC01_IP so polaris dns service starts during polaris-vm bake ([853ea93](https://github.com/PaloAltoNetworks/shifter/commit/853ea93caf4fbd810c832ff0c50d29bff163eb31)) +* **test:** satisfy gce range preconditions via the process boundary, not a first-party patch ([03d3330](https://github.com/PaloAltoNetworks/shifter/commit/03d333064cac233ff17df37056e494b41a2f9c42)) +* **warm-pool:** clear remaining Sonar new-code findings (cast replace(), re-export __all__, test globals) ([14da16d](https://github.com/PaloAltoNetworks/shifter/commit/14da16db016788be3fbe5ee8f78dc5209d50c2fa)) +* **warm-pool:** resolve Sonar quality-gate findings and claim-consistency constraint ([7cf9b9c](https://github.com/PaloAltoNetworks/shifter/commit/7cf9b9ce749e983c40327c49cc35db0115e51766)) +* **workspaces:** clear remaining invitation quality findings ([6d6879c](https://github.com/PaloAltoNetworks/shifter/commit/6d6879c91610ed898865a1b7543a6865bcfc3427)) +* **workspaces:** resolve invitation quality findings ([6a60f3c](https://github.com/PaloAltoNetworks/shifter/commit/6a60f3c13cb8026ab8446bac991334c52f924469)) + ## [3.104.0](https://github.com/Brad-Edwards/shifter/compare/v3.103.0...v3.104.0) (2026-09-16) diff --git a/version.txt b/version.txt index 2e00703aa..8250be224 100644 --- a/version.txt +++ b/version.txt @@ -1 +1 @@ -3.104.0 +3.105.0