Commit Graph

  • 038205f7b8 update: fwdb from v350+i20260512+1cce to v351+i20260512+1cce, 9 microcode changes autoupdate-fwdb speed47 2026-06-15 11:36:12 +00:00
  • 024e5a94b9 fix: another attempt to avoid sigpipe on grep (#519) test-build github-actions[bot] 2026-06-10 21:34:38 +00:00
  • 5bbffaf053 fix: another attempt to avoid sigpipe on grep (#519) test Stéphane Lesimple 2026-06-10 23:33:10 +02:00
  • 2ce3775287 fix: mmio: don't report "Intel never assessed this CPU" when the MSR is unreadable github-actions[bot] 2026-06-08 20:57:09 +00:00
  • 23ea5427b5 fix: mmio: don't report "Intel never assessed this CPU" when the MSR is unreadable Stéphane Lesimple 2026-06-08 22:55:45 +02:00
  • 476ebe59fc fix: dmesg_grep: avoid sigpipe on some systems (#519) github-actions[bot] 2026-06-08 19:42:39 +00:00
  • cc159fe7fd fix: dmesg_grep: avoid sigpipe on some systems (#519) Stéphane Lesimple 2026-06-08 21:41:08 +02:00
  • c1aee44717 chore: udpate stale github workflow master Stéphane Lesimple 2026-06-06 18:58:28 +02:00
  • 7847c95208 arm64: add SSBS detection github-actions[bot] 2026-06-06 15:04:30 +00:00
  • 737cfe4a5f arm64: add SSBS detection Stéphane Lesimple 2026-06-06 17:01:46 +02:00
  • 738a4f55f8 fix: zenbleed (CVE-2023-20593) handle the VM guest case (#488) github-actions[bot] 2026-06-06 14:15:18 +00:00
  • 0b022ee253 fix: zenbleed (CVE-2023-20593) handle the VM guest case (#488) Stéphane Lesimple 2026-06-06 16:09:55 +02:00
  • 1e33f40f0a mds/mmio/taa: don't claim "disable SMT" inside a VM guest (#343) Stéphane Lesimple 2026-06-06 15:57:45 +02:00
  • 1211c21261 xen: more reliable Xen/guest detection + container awareness (#173) Stéphane Lesimple 2026-06-06 15:39:46 +02:00
  • 03cde37e67 doc: add CVE-2026-46174 (AMD Zen 2 Op Cache Improper Resource Isolation) to the unsupported list github-actions[bot] 2026-06-06 13:08:44 +00:00
  • d8abfbe20a doc: add CVE-2026-46174 (AMD Zen 2 Op Cache Improper Resource Isolation) to the unsupported list Stéphane Lesimple 2026-06-06 15:07:18 +02:00
  • 4031b0f3bd chore: bump gh actions modules Stéphane Lesimple 2026-06-06 15:02:31 +02:00
  • ad2b7edeca doc: add unsupported CVE to list (CVE-2021-26314 / CVE-2021-26313 / CVE-2025-52533) github-actions[bot] 2026-06-06 10:55:16 +00:00
  • 45fe976ca9 doc: add unsupported CVE to list (CVE-2021-26314 / CVE-2021-26313 / CVE-2025-52533) Stéphane Lesimple 2026-06-06 12:53:21 +02:00
  • 1db12cd347 update: fwdb from v349+i20260512+1cce to v350+i20260512+1cce, 8 microcode changes (#578) source-build github-actions[bot] 2026-06-03 12:08:36 +00:00
  • 44ba92635f update: fwdb from v349+i20260512+1cce to v350+i20260512+1cce, 8 microcode changes (#578) source github-actions[bot] 2026-06-03 14:07:02 +02:00
  • d6624c30af v26.36.0602723 (#577) v26.36.0602723 Stéphane Lesimple 2026-06-02 18:05:47 +00:00
  • c107f2b2ea fix: arm64: collapse per-core CPU info lists to a single line (#576) github-actions[bot] 2026-06-02 17:22:53 +00:00
  • c277a7a443 Merge remote-tracking branch 'origin/master' into source-build Stéphane Lesimple 2026-06-02 19:30:19 +02:00
  • 7d9345a32f fix: arm64: collapse per-core CPU info lists to a single line (#576) Stéphane Lesimple 2026-06-02 17:21:31 +00:00
  • fa6f0b14e9 fix: arm64: collapse per-core CPU info lists to a single line github-actions[bot] 2026-06-02 17:16:47 +00:00
  • 44ba3790d9 fix: arm64: collapse per-core CPU info lists to a single line Stéphane Lesimple 2026-06-02 19:11:45 +02:00
  • 26cf31b282 Merge source-build for v26.36.0601873 (#575) Stéphane Lesimple 2026-06-02 16:57:51 +00:00
  • fd7caec415 Merge remote-tracking branch 'origin/source-build' master-merge Stéphane Lesimple 2026-06-02 18:17:06 +02:00
  • 68116d87fd update: fwdb from v349+i20260227+615b to v349+i20260512+1cce, 19 microcode changes github-actions[bot] 2026-06-01 20:58:15 +00:00
  • 645a79846b update: fwdb from v349+i20260227+615b to v349+i20260512+1cce, 19 microcode changes github-actions[bot] 2026-06-01 20:56:45 +00:00
  • 3f4801e6a7 autoupdate workflow: add missing pkg Stéphane Lesimple 2026-06-01 20:55:08 +00:00
  • 9a3688b6fd chore: use scripts in autoupdate workflow (#572) Stéphane Lesimple 2026-06-01 20:52:54 +00:00
  • c060a2d2c9 Merge pull request #571 from speed47/test github-actions[bot] 2026-06-01 20:46:12 +00:00
  • 0045d237fa Merge pull request #571 from speed47/test Stéphane Lesimple 2026-06-01 20:44:44 +00:00
  • 17056d8f08 add scripts/update_mcedb.sh to be used in cron github workflow github-actions[bot] 2026-06-01 20:22:11 +00:00
  • 5d1363ee4b add scripts/update_mcedb.sh to be used in cron github workflow Stéphane Lesimple 2026-06-01 22:20:03 +02:00
  • 0c89d162a3 chore: fix autoupdate workflow Stéphane Lesimple 2026-05-31 12:50:31 +00:00
  • 985450f72d chore: fix autoupdate workflow autoupdate_workflow Stéphane Lesimple 2026-05-31 14:49:08 +02:00
  • 43bbfabc34 hw: detect VM guest via hypervisor CPUID flag, warn on unreliable microcode Stéphane Lesimple 2026-04-22 00:08:11 +02:00
  • e844f9cff3 feat: hide CVE checks that arebirrelevant for current arch github-actions[bot] 2026-04-21 06:56:29 +00:00
  • 7329c1fd2f feat: hide CVE checks that arebirrelevant for current arch Stéphane Lesimple 2026-04-21 08:53:08 +02:00
  • 8a302b56e6 feat: add ARM64 silicon errata checks (issue #357) Stéphane Lesimple 2026-04-21 08:31:00 +02:00
  • 5262efbf55 fix: mmio stale data: EOL Intel CPUs may be vulnerable (#437) github-actions[bot] 2026-04-20 20:44:06 +00:00
  • 03b1787d69 fix: mmio stale data: EOL Intel CPUs may be vulnerable (#437) Stéphane Lesimple 2026-04-20 22:42:04 +02:00
  • 440424f524 doc: readme: correct markdown indentation for unordered list items (#569) github-actions[bot] 2026-04-20 16:05:45 +00:00
  • 8a417e5579 doc: readme: correct markdown indentation for unordered list items (#569) 林博仁 Buo-ren Lin 2026-04-21 00:02:47 +08:00
  • 02fa416bab doc: readme: correct markdown indentation for unordered list items (#569) 林博仁 Buo-ren Lin 2026-04-21 00:02:47 +08:00
  • b7b0efa773 doc: add Jump Conditional Code (JCC) Erratum to the unsupported list github-actions[bot] 2026-04-20 15:49:22 +00:00
  • b7a6182a65 doc: add Jump Conditional Code (JCC) Erratum to the unsupported list Stéphane Lesimple 2026-04-20 17:47:50 +02:00
  • 1c067add59 release v26.33.0420460 (#567) v26.33.0420460 Stéphane Lesimple 2026-04-20 15:18:11 +00:00
  • fe0d3f49f4 Merge pull request #566 from speed47/test github-actions[bot] 2026-04-20 11:04:05 +00:00
  • 3e2b6cc734 Merge pull request #566 from speed47/test Stéphane Lesimple 2026-04-20 11:02:38 +00:00
  • cf156a2ee5 doc: update output formats doc + normalize json to bool github-actions[bot] 2026-04-20 10:56:59 +00:00
  • e2d110a3b5 doc: update output formats doc + normalize json to bool Stéphane Lesimple 2026-04-20 12:47:43 +02:00
  • 4eb0d04808 chore: remove from test branch workflows that must live on master github-actions[bot] 2026-04-20 10:55:20 +00:00
  • 1bb33d5cf2 chore: remove from test branch workflows that must live on master Stéphane Lesimple 2026-04-20 12:53:36 +02:00
  • 7f5256f15e chore: workflow: handle manual bootstrap vuln-watch Stéphane Lesimple 2026-04-19 17:56:46 +02:00
  • 00bb4a951c workflow: expose reconsider_age_days input + env var Stéphane Lesimple 2026-04-19 12:46:56 +00:00
  • 7a3224ad61 throttle reconsider pass by last-review age (default 7 days) Stéphane Lesimple 2026-04-19 12:17:31 +00:00
  • 31cf549c75 prompt: point classifier at authoritative scope docs + flip tocheck bias Stéphane Lesimple 2026-04-19 11:19:38 +00:00
  • b305cc48c3 reconsider prior backlog each run + recognize CVEs from context Stéphane Lesimple 2026-04-19 10:41:52 +00:00
  • 12f545dc45 extract dates from intel/amd HTML + honor WINDOW_HOURS env Stéphane Lesimple 2026-04-19 10:06:07 +00:00
  • 43d5b77885 chore: workflow: add manual model + window_hours inputs, add reconsider Stéphane Lesimple 2026-04-19 10:55:03 +00:00
  • 50845adbfb doc: CVE-2018-3665 (Lazy FP State Restore (LazyFP)), unsupported github-actions[bot] 2026-04-19 10:50:48 +00:00
  • 6732eb141b doc: CVE-2018-3665 (Lazy FP State Restore (LazyFP)), unsupported Stéphane Lesimple 2026-04-19 12:49:17 +02:00
  • 94356c4992 init: daily vulnerability watch automation Stéphane Lesimple 2026-04-19 08:25:16 +00:00
  • 78a6e4a418 chore: move cron vuln-watch workflow script files to their own branch Stéphane Lesimple 2026-04-19 09:14:21 +00:00
  • 7eaa794980 enh: add FPDSS check for AMD Zen1/Zen+ (CVE-2025-54505) github-actions[bot] 2026-04-18 15:20:22 +00:00
  • 048ce5b6a2 enh: add FPDSS check for AMD Zen1/Zen+ (CVE-2025-54505) Stéphane Lesimple 2026-04-18 10:56:21 +00:00
  • 5af1a9fec9 chore: workflow: add scan id Stéphane Lesimple 2026-04-18 14:23:47 +00:00
  • b93027640f chore: vuln workflow: use opus, no persist creds, conditional upload Stéphane Lesimple 2026-04-18 14:19:10 +00:00
  • 5c27284119 chore: workflow: save logs Stéphane Lesimple 2026-04-18 14:05:15 +00:00
  • f2e5999fc0 chore: explicit prompt for workflow Stéphane Lesimple 2026-04-18 13:41:03 +00:00
  • 25f20b8860 chore: fix workflow perms (#558) Stéphane Lesimple 2026-04-18 13:29:54 +00:00
  • 77e3dbd6b2 add scheduled vuln research (#557) Stéphane Lesimple 2026-04-18 13:14:13 +00:00
  • 7e5eee74ac fix: remove useless checks under ARM for CVE-2023-28746 github-actions[bot] 2026-04-10 17:51:49 +00:00
  • 48454a5344 fix: remove useless checks under ARM for CVE-2023-28746 Stéphane Lesimple 2026-04-10 19:50:15 +02:00
  • 9bef6ec533 enh: use g_mode to explicitly save/load the current running mode github-actions[bot] 2026-04-10 17:29:38 +00:00
  • e67c9e4265 enh: use g_mode to explicitly save/load the current running mode Stéphane Lesimple 2026-04-10 19:26:46 +02:00
  • f7ba617e16 enh: guard x86/arm specific checks in kernel/cpu for the proper arch Stéphane Lesimple 2026-04-10 18:37:32 +02:00
  • f587d9355e enh: guard x86/arm specific checks in kernel/cpu for the proper arch github-actions[bot] 2026-04-10 16:40:49 +00:00
  • e110706df8 enh: factorize is_arch_kernel Stéphane Lesimple 2026-04-10 18:37:14 +02:00
  • 83be8fd544 chore: fix build workflow github-actions[bot] 2026-04-08 21:02:02 +00:00
  • de853fc801 chore: fix build workflow Stéphane Lesimple 2026-04-08 23:00:40 +02:00
  • 98ec067aef enh: rework json/prom output to better split x86/arm Stéphane Lesimple 2026-04-08 22:27:30 +02:00
  • ff42393fa6 new batch mode docs, add doc/ to -build branch Stéphane Lesimple 2026-04-08 21:57:03 +02:00
  • f0fb59310e fix: add a missing pstatus to CVE-2023-20588 check Stéphane Lesimple 2026-04-08 21:42:19 +02:00
  • be0f2d20d2 fix: remove misleading explain on correctly mitigated SLS Stéphane Lesimple 2026-04-08 21:41:55 +02:00
  • 3639de9e8a chore: fix github workflow check with new --batch output Stéphane Lesimple 2026-04-08 21:41:24 +02:00
  • df3c2aeaa3 add screenshot to README Stéphane Lesimple 2026-04-08 21:32:16 +02:00
  • 945f70bb63 fix: early abort when using --allow-msr-write Stéphane Lesimple 2026-04-08 21:11:12 +02:00
  • db84fc10de chore: make fmt Stéphane Lesimple 2026-04-08 21:03:57 +02:00
  • 60ea669e41 enh: better explain the 4 run modes Stéphane Lesimple 2026-04-08 20:53:50 +02:00
  • f1c0d5548c chg: remove --no-intel-db, it's now always used when available Stéphane Lesimple 2026-04-08 20:53:35 +02:00
  • 9e617a4363 remove prometheus-legacy format Stéphane Lesimple 2026-04-08 20:53:19 +02:00
  • b9c203120b enh: --no-runtime and --no-hw modes replacing --live and implicit 'offline' mode Stéphane Lesimple 2026-04-08 20:53:00 +02:00
  • 3f7e0a11f7 enh: CVE-2018-3640 (Spectre 3a): enhance ARM mitigation detection Stéphane Lesimple 2026-04-08 20:52:22 +02:00
  • 5c469787ea enh: rework --batch nrpe entirely Stéphane Lesimple 2026-04-08 20:51:58 +02:00
  • a952fe32c4 fix: exit_cleanup: don't lose passed exit code Stéphane Lesimple 2026-04-08 20:51:36 +02:00