Skip to content

PAPP-38109: harden Censys result handling - #26

Merged
phantom-jacob merged 8 commits into
mainfrom
sodle/espm-5228-censys-security-fixes
Jul 20, 2026
Merged

PAPP-38109: harden Censys result handling#26
phantom-jacob merged 8 commits into
mainfrom
sodle/espm-5228-censys-security-fixes

Conversation

@sodle-splunk

Copy link
Copy Markdown
Contributor

Bug Fixes

  • Escape upstream action messages and remove raw response bodies from JSON errors for PSAAS-30375.
  • Escape widget values before embedding them in inline JavaScript for PSAAS-30832.
  • Remove captured credential-bearing HTTP headers before persisting action results for PSAAS-31808.
  • Bound cursor pagination, stop zero-progress pages, truncate oversized responses, and add request timeouts for PSAAS-31815.
  • Treat Censys rate limits and v2 API error bodies as action failures for PSAAS-31819.

Manual Documentation

  • I have verified that manual documentation has been updated where appropriate

Other information


Please refer to our Contribution Guide for any questions on submitting a pull request.

Thanks for contributing!

Updated by Codex for the ESPM-5228 remediation campaign.
Remediates PSAAS-30375. Written by Codex.
Remediates PSAAS-30832. Written by Codex.
Remediates PSAAS-31808. Written by Codex.
Remediates PSAAS-31815. Written by Codex.
Remediates PSAAS-31819. Written by Codex.
Generated by the released connector hooks. Written by Codex.
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

Merging this PR will release 2.2.5 with the following release notes:

2.2.5 (2026-07-18)

Connector release changes

  • Escaped upstream action messages in the Censys widget and removed raw response bodies from JSON parsing errors.
  • Escaped Censys widget values before embedding them in inline JavaScript contexts.
  • Removed credential-bearing HTTP headers from Censys records before storing action-result data.
  • Bounded Censys search pagination, stopped zero-progress cursors, truncated oversized pages, and added request timeouts.
  • Reported Censys rate limits and v2 API error bodies as action failures instead of empty successful results.

@sodle-splunk
sodle-splunk marked this pull request as ready for review July 17, 2026 20:25
Keep one generated list operator per security fix so semantic-release renders clean changelog entries.\n\nWritten by Codex.

@phantom-jacob phantom-jacob left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved by Codex after reviewing draft status, release-note formatting, code changes, and associated ticket scope.

@phantom-jacob
phantom-jacob merged commit 3c4711f into main Jul 20, 2026
11 of 19 checks passed
@phantom-jacob
phantom-jacob deleted the sodle/espm-5228-censys-security-fixes branch July 20, 2026 18:31
@splunk-soar-semantic-release

Copy link
Copy Markdown

🎉 This PR is included in version 2.2.5 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants