What's Changed
Here is a new version again of OWASP WrongSecrets, this time with java reverse-engineer challenges!
Bugfixes and new content
- Fix Cypress workflow failures caused by invalid aws4 lockfile tarballs by @Copilot in #2504
- Update README challenge totals and links for current challenge set (0–64) by @Copilot in #2508
- Fix security & quality issues from GitHub security dashboard by @Copilot in #2512
- Add Java CLI reverse-engineering challenges and bundle JAR variants by @Copilot in #2523
- updaetd contributors by @commjoen in #2541
- Ignore Heroku
JAVA_TOOL_OPTIONSbanner in challenge 65/66 spoilers by @Copilot in #2542 - Harden global security headers and add regression coverage for filter behavior by @Copilot in #2506
LCM
- chore(deps): bump org.springframework.security:spring-security-web from 7.0.4 to 7.0.5 by @dependabot[bot] in #2509
- fix(deps): update spring.security.version to v7.0.5 [security] by @renovate[bot] in #2510
- chore(deps): bump org.springframework.security:spring-security-config from 7.0.4 to 7.0.5 by @dependabot[bot] in #2511
- chore(deps): update dependency com.puppycrawl.tools:checkstyle to v13.4.2 by @renovate[bot] in #2515
- fix(deps): update dependency org.springframework.boot:spring-boot-starter-parent to v4.0.6 by @renovate[bot] in #2520
- fix(deps): update dependency org.projectlombok:lombok to v1.18.46 by @renovate[bot] in #2519
- chore(deps): update elco/setup-vault action to v1.0.4 by @renovate[bot] in #2518
- chore(deps): update dependency maven to v3.9.15 by @renovate[bot] in #2517
- chore(deps): update dependency com.tngtech.archunit:archunit-junit5 to v1.4.2 by @renovate[bot] in #2516
- chore(deps): update dependency @commitlint/config-conventional to v20.5.3 by @renovate[bot] in #2514
- chore(deps): update dependency @babel/preset-env to v7.29.3 by @renovate[bot] in #2513
- chore(deps-dev): bump fast-uri from 3.1.0 to 3.1.2 in /js by @dependabot[bot] in #2521
- chore(deps-dev): bump @babel/plugin-transform-modules-systemjs from 7.29.0 to 7.29.4 by @dependabot[bot] in #2522
- chore(deps): update go toolchain directive to v1.26.3 by @renovate[bot] in #2525
- chore(deps): update dependency @babel/preset-env to v7.29.5 by @renovate[bot] in #2524
- fix(deps): update dependency org.owasp:dependency-check-maven to v12.2.2 by @renovate[bot] in #2527
- Add Mayank Yadav to contributors list by @commjoen in #2528
- fix(deps): update dependency org.springframework.vault:spring-vault-core to v4.0.2 by @renovate[bot] in #2529
- chore(deps): update alpine docker tag to v3.23 - autoclosed by @renovate[bot] in #2531
- chore(deps): update dependency com.diffplug.spotless:spotless-maven-plugin to v3.5.0 by @renovate[bot] in #2532
- chore(deps): update dependency globals to v17.6.0 by @renovate[bot] in #2534
- chore(deps): update dependency eslint-plugin-chai-friendly to v1.2.0 by @renovate[bot] in #2533
- fix(deps): update dependency org.thymeleaf.extras:thymeleaf-extras-springsecurity6 to v3.1.5.release by @renovate[bot] in #2530
- chore(deps): update docker/dockerfile docker tag to v1.24 by @renovate[bot] in #2535
- chore(deps): update go by @renovate[bot] in #2536
- chore(deps): update pre-commit hook alessandrojcm/commitlint-pre-commit-hook to v9.25.0 by @renovate[bot] in #2537
- chore(deps): update terraform azurerm to v4.73.0 by @renovate[bot] in #2538
- chore(deps): update terraform http to ~> 3.6.0 by @renovate[bot] in #2539
- chore(deps): update terraform random to ~> 3.9.0 by @renovate[bot] in #2540
Special thanks
special thanks to @commjoen for his hard work on this release
Full Changelog: 1.13.3...1.13.5