taylanbakircioglu
613ed0bf99
fix(security): patch CRITICAL Dependabot findings (python-jose 3.4.0, jspdf 4.2.1)
...
- python-jose[cryptography] 3.3.0 -> 3.4.0 (CVE-2024-33663 algorithm
confusion) in backend + api-gateway. App uses HS256 only; encode/decode
API unchanged; 3.3.0<->3.4.0 tokens cross-verifiable (rolling-deploy safe).
- jspdf 4.0.0 -> 4.2.1 (CVE-2026-31938 HTML injection in new-window paths)
in frontend; @babel/runtime bumped 7.28.4 -> 7.28.6 (required by jspdf
4.2.1). App uses only new jsPDF()/autoTable()/doc.save() — vulnerable
output path not used.
Verified: jose roundtrip + cross-version, frontend npm build, backend &
frontend docker images, and Kubernetes (kind) jose 3.4.0 + frontend serve.
No feature/UI behavior change; backward compatible.
2026-06-03 01:35:06 +03:00
taylanbakircioglu
6e503368f7
feat: L7 (Application Level) observability — Service Map, Trace Explorer, APM, Beyla
...
- Grafana Beyla DaemonSet for kernel-level HTTP/gRPC/DNS capture (passive,
zero application changes, W3C traceparent header propagation)
- flowfish-l7-collector in-cluster bridge: OTLP receiver + buffered pull API
- L7 Ingestion Service: K8s service-proxy poll → enrich → RabbitMQ
- ClickHouse l7_http_flows / l7_grpc_flows / l7_dns_flows + APM RED MVs
- Neo4j L7Workload nodes + SAME_WORKLOAD cross-cluster bridges
- New pages: Service Map, Trace Explorer, APM Services List, APM Service Detail
- Analysis Wizard now supports L4 / L7 / Both modes with HTTP/gRPC/DNS picks
- Integration Hub gains L7 dependency summary + tree-summary integrations
- Multi-Cluster Management: dual-agent install (Inspector Gadget L4 + Beyla L7),
runtime OpenShift detection so SCCs auto-install with kubectl too
- ServiceMap edge → Trace Explorer drill-down with virtual_trace_id correlation
- Docs: new L7 architecture diagram, README L7 sections, 3 new screenshots
2026-05-14 10:09:15 +03:00