What's Changed
- Bump 4.14.8 branch by @wazuhci in #37404
- Multi SCA, Decoder and Rule fixes by @Johnng007 in #37434
- Maintain crypto_method on keystore rebuild by @jpcerrone in #37524
- Merge 4.14.7 into 4.14.8 by @vikman90 in #37679
- Fix RBAC permission bypass in GET /security/actions and /security/resources by @vikman90 in #37678
- Validate destination paths when uploading list, rule, and decoder files by @vikman90 in #37691
- Prevent cluster worker from overwriting protected master files by @vikman90 in #37694
- Improve access control on the agent active-configuration endpoint by @vikman90 in #37716
- Fix typo in SCA rules by @Miguevrgo in #37652
- Prevent race condition in Windows RSA key container initialization (randombytes) by @MarcelKemp in #37701
- Limit node expansion in yaml2json by @vikman90 in #37725
- Reorder revoke-token from API integration test by @Antoniogm03 in #37696
- Fix benchmark test_cluster_error_logs test by @jepalfer in #37425
- Correct EnableMulticast expected value in Windows LLMNR checks by @Darioortegaleyva in #37765
- Prevent spurious CRITICAL (1211) queue error during rootcheck/FIM shutdown on WPK upgrade by @Darioortegaleyva in #37715
- Add sshd-session/sshd-auth to default macOS ULS query by @Darioortegaleyva in #37769
- Remove multiple warning messages for each unathorized shared policy by @Miguevrgo in #37741
- Fix typo in SCA rules by @Miguevrgo in #37770
- Fix analysisd deadlock on AR send when the queue is not drained by @ignaciogalle12git in #37764
- Disable OpenSSL runtime CPU probing in Python daemon wrappers by @jotacarma90 in #37839
- Expose audit_uid, audit_gid and effective_uid in eBPF whodata provider by @Darioortegaleyva in #37060
- Reject upgrade commands from the agent channel in wazuh-analysisd by @vikman90 in #37745
- initializeContext thread-safe with std::call_once by @hernanvalenzuela in #37768
- Validate destination paths when deleting rule and decoder files by @vikman90 in #37838
- Use DisplayName and python.exe version for Microsoft Store packages by @Darioortegaleyva in #37441
- Fix analysisd flaky test by @jepalfer in #37754
- Update MITRE mapping in Microsoft Graph rules by @AwwalQuan in #37950
- Validate read path in CDB list file retrieval by @vikman90 in #37901
- Merge 4.14.7 into 4.14.8 by @jotacarma90 in #37971
- Fix flaky content manager component tests caused by a race in the fake server startup by @jotacarma90 in #37902
- Discard_regex values containing a space break argument parsing by @jepalfer in #37929
- Decouple authd use_password invalid test from the manager restart return code by @ignaciogalle12git in #37930
- Prevent empty string version from being stored for agents by @Antoniogm03 in #37934
- Prevent exiting Wazuh-DB worker when oversized message arrives. by @MiguelazoDS in #37850
- Classify SCA policy remoteness by activation source, not file path by @vikman90 in #37953
- Reject undersized legacy-format agent messages in wazuh-remoted by @vikman90 in #38099
- Remove WMI dependancy when installing msi packages by @rjcausarano in #38059
- Remove startup deprecation warning from agent_upgrade by @jotacarma90 in #38085
- Improve login attempt limiting under concurrent requests by @vikman90 in #38135
- Fix out-of-bounds write when generating FIM alerts in wazuh-analysisd by @vikman90 in #38145
- Enforce password validation for empty passwords in
update_userby @vikman90 in #38180 - Enforce token revocation for run_as (authorization-context) API sessions by @vikman90 in #38193
- Fix wildcard matching in the installed-files check by @vikman90 in #38213
- Prevent orphaned S3 artifacts and false-positive collisions in AWS integration tests [4.14.8] by @Darioortegaleyva in #38105
- Report macOS 26 and 27 release codenames by @anromerom in #38187
- Validate CDB list paths in list-retrieval and delete cluster callables by @vikman90 in #38214
- Skip 4.x CI checks on draft pull requests by @vikman90 in #38240
- Fix remote-command configuration validation by @vikman90 in #38239
- Revert agent workflows to GitHub runners 4x by @lchico in #38223
- Perpended string "data." in field names removed from FortiAuth rules and decoders by @AwwalQuan in #38195
- Remove stale EC2-timing exclusion in syscollector-rtr by @lchico in #38271
- Validate read paths in group configuration and daemon stats retrieval by @vikman90 in #38339
- Suppress StarletteDeprecationWarning for cluster_control and all framework CLI tools by @jotacarma90 in #38412
- Move the 4.14.8 server workflows to GitHub-hosted runners and add sccache compilation caching by @jotacarma90 in #38460
- Avoid holding exec_sock_mutex while connecting to the exec queue by @jotacarma90 in #38510
- AWS integration tests: isolate concurrent runs on the shared bucket with a per-run S3 namespace (GITHUB_RUN_ID) [4.14.8] by @Darioortegaleyva in #38254
- Remove avoidable copies, double lookups and pessimizing moves in agent-side hot paths by @Miguevrgo in #38234
- Bump 4.14.8 branch by @wazuhci in #39117
- Add the 4.10.5 entry to the changelog by @jotacarma90 in #39303
- Size the FIM alert full_log buffer to the alert instead of OS_MAXSTR by @jotacarma90 in #39404
- Decode audit_gid and audit_group_name in FIM whodata alerts by @Antoniogm03 in #39416
- Change default eBPF whodata loginuid to -1 instead of 0 by @Miguevrgo in #39335
- Fix uid and gid swap when unpacking bpf_get_current_uid_gid() in FIM eBPF whodata by @Miguevrgo in #39402
- Bump 4.14.8 branch by @wazuhci in #39436
Full Changelog: v4.14.7...v4.14.8-rc2
SOCIAL SHARE CARD GENERATOR