{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":531211589,"defaultBranch":"main","name":"osquery-defense-kit","ownerLogin":"chainguard-dev","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2022-08-31T18:33:46.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/87436699?v=4","public":true,"private":false,"isOrgOwned":true},"refInfo":{"name":"","listCacheKey":"v0:1724799988.0","currentOid":""},"activityList":{"items":[{"before":"73f76d5f1d74a283650b718b326cd40af1a3cc56","after":"df577d4f1c08053a4a3bc53a5461736662fb3c82","ref":"refs/heads/main","pushedAt":"2024-08-27T23:06:00.000Z","pushType":"pr_merge","commitsCount":4,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #384 from tstromberg/fpr-aug27\n\nfpr: the largest of 2024 🎉","shortMessageHtmlLink":"Merge pull request #384 from tstromberg/fpr-aug27"}},{"before":"342aeda54338fa907c687e27d85987a978419200","after":"73f76d5f1d74a283650b718b326cd40af1a3cc56","ref":"refs/heads/main","pushedAt":"2024-08-27T22:42:33.000Z","pushType":"pr_merge","commitsCount":4,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #383 from tstromberg/suspicious-systemd\n\nnew detection: suspicious systemd units","shortMessageHtmlLink":"Merge pull request #383 from tstromberg/suspicious-systemd"}},{"before":"7f6078e23358992de98623a66547ee08499191dd","after":"342aeda54338fa907c687e27d85987a978419200","ref":"refs/heads/main","pushedAt":"2024-08-27T16:06:58.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #382 from tstromberg/active-systemd\n\nactive systemd units: populate more in-the-wild examples","shortMessageHtmlLink":"Merge pull request #382 from tstromberg/active-systemd"}},{"before":"0d46dcb083cf67880a4041701d3b36824fde6ce8","after":"7f6078e23358992de98623a66547ee08499191dd","ref":"refs/heads/main","pushedAt":"2024-08-26T20:10:09.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #381 from tstromberg/packed\n\nnew detection: recently downloaded files which have been packed","shortMessageHtmlLink":"Merge pull request #381 from tstromberg/packed"}},{"before":"7d468b6166b58d9bcb1c20c3b2d809ea2b82bcf3","after":"0d46dcb083cf67880a4041701d3b36824fde6ce8","ref":"refs/heads/main","pushedAt":"2024-08-26T16:49:37.000Z","pushType":"pr_merge","commitsCount":4,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #380 from tstromberg/udev\n\nlinux udevd: replace file-size based detection with YARA rules","shortMessageHtmlLink":"Merge pull request #380 from tstromberg/udev"}},{"before":"b04c3eb48d9f017365f598b6447850508547c8c4","after":"7d468b6166b58d9bcb1c20c3b2d809ea2b82bcf3","ref":"refs/heads/main","pushedAt":"2024-08-26T16:49:24.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #379 from tstromberg/fpr-aug20\n\nunexpected https: add GitHub to exceptions list","shortMessageHtmlLink":"Merge pull request #379 from tstromberg/fpr-aug20"}},{"before":"2fcde3a133407572101714f9268c35e92bce77b7","after":"b04c3eb48d9f017365f598b6447850508547c8c4","ref":"refs/heads/main","pushedAt":"2024-08-26T16:49:14.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #378 from tstromberg/fpr-aug12\n\nfpr: syft, krunner, k9s, espeak, chainctl, supermaven","shortMessageHtmlLink":"Merge pull request #378 from tstromberg/fpr-aug12"}},{"before":"bf9c1e007f9589cff5c2d52f1a74c073752d84c0","after":"2fcde3a133407572101714f9268c35e92bce77b7","ref":"refs/heads/main","pushedAt":"2024-07-26T18:54:28.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #377 from tstromberg/fpr-jul26\n\nfpr: sddm-helper, smartd, Xorg, elastic, WebEx, BambuStudio, keepass, etc.","shortMessageHtmlLink":"Merge pull request #377 from tstromberg/fpr-jul26"}},{"before":"aff147c7405416e305f493e9336e1105198e410e","after":"bf9c1e007f9589cff5c2d52f1a74c073752d84c0","ref":"refs/heads/main","pushedAt":"2024-07-23T15:17:13.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #376 from tstromberg/fpr-jul13\n\nAdd Mailvelope and SABconnect, sort Chrome extensions","shortMessageHtmlLink":"Merge pull request #376 from tstromberg/fpr-jul13"}},{"before":"55c9fd1c039a8f276858c4d8f755cfeaf18087be","after":"aff147c7405416e305f493e9336e1105198e410e","ref":"refs/heads/main","pushedAt":"2024-07-23T15:16:56.000Z","pushType":"pr_merge","commitsCount":6,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #375 from egibs/20240718-exceptions\n\nAdd exceptions for 1Password, Docker's kubectl, Loom, ngrok, SAFEQ, and Zed","shortMessageHtmlLink":"Merge pull request #375 from egibs/20240718-exceptions"}},{"before":"7ebe6a30c1058e1cc04fa89e44a6a1ef38cdd6ea","after":"55c9fd1c039a8f276858c4d8f755cfeaf18087be","ref":"refs/heads/main","pushedAt":"2024-07-15T21:39:37.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #374 from egibs/20240715-allows","shortMessageHtmlLink":"Merge pull request #374 from egibs/20240715-allows"}},{"before":"c591d6d59580c8c035ec416f82ef55741afdfc29","after":"7ebe6a30c1058e1cc04fa89e44a6a1ef38cdd6ea","ref":"refs/heads/main","pushedAt":"2024-07-12T21:15:33.000Z","pushType":"pr_merge","commitsCount":6,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #373 from tstromberg/fpr-jul12\n\nfpr: kas, bitnami, redis, bincapz, kolide, docker, whatsapp, rpm-ostree","shortMessageHtmlLink":"Merge pull request #373 from tstromberg/fpr-jul12"}},{"before":"82f495748456f732e6b630694d3cbee5dc79610f","after":"c591d6d59580c8c035ec416f82ef55741afdfc29","ref":"refs/heads/main","pushedAt":"2024-07-12T21:08:32.000Z","pushType":"pr_merge","commitsCount":4,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #372 from egibs/littlesnitch-allows\n\nAdd Little Snitch exception_key","shortMessageHtmlLink":"Merge pull request #372 from egibs/littlesnitch-allows"}},{"before":"f4b0ed2d48d5acc9db58b0f90e3117ff6d8014d0","after":"82f495748456f732e6b630694d3cbee5dc79610f","ref":"refs/heads/main","pushedAt":"2024-07-02T01:57:29.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #371 from tstromberg/fpr-jul1\n\nfpr: lima, rpm-ostree, gitsign, kde, python, etc","shortMessageHtmlLink":"Merge pull request #371 from tstromberg/fpr-jul1"}},{"before":"32bd629b10a83ae981f0a1cd81b072af7752cedd","after":"f4b0ed2d48d5acc9db58b0f90e3117ff6d8014d0","ref":"refs/heads/main","pushedAt":"2024-06-28T14:32:19.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #370 from tstromberg/fpr-jun25\n\nfpr: PCP, SDDM, Chrome, etc","shortMessageHtmlLink":"Merge pull request #370 from tstromberg/fpr-jun25"}},{"before":"eecc2a3ed064e51d53cdcc1305e266a9c661ef33","after":"32bd629b10a83ae981f0a1cd81b072af7752cedd","ref":"refs/heads/main","pushedAt":"2024-06-28T14:09:16.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #369 from tstromberg/fpr-jun25\n\nfpr: Rule toning for podman, pip, zed, java, ssh, and more","shortMessageHtmlLink":"Merge pull request #369 from tstromberg/fpr-jun25"}},{"before":"0ddcb75ce0f5bf07d72be9b6970ee3c97d21164b","after":"eecc2a3ed064e51d53cdcc1305e266a9c661ef33","ref":"refs/heads/main","pushedAt":"2024-06-27T13:24:44.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #368 from tstromberg/fpr-jun25\n\nMassive false-positive reduction, particularly for uBlue","shortMessageHtmlLink":"Merge pull request #368 from tstromberg/fpr-jun25"}},{"before":"4601b6c2fa3a3c4713c01dfe81eda8aa59af1e26","after":"0ddcb75ce0f5bf07d72be9b6970ee3c97d21164b","ref":"refs/heads/main","pushedAt":"2024-06-26T00:49:33.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #367 from tstromberg/fpr-jun25\n\nfpr: Universal Blue and a little bit of everything else","shortMessageHtmlLink":"Merge pull request #367 from tstromberg/fpr-jun25"}},{"before":"a0c49efb3fc021b2cf7852fb4fe32d4b3940d7ec","after":"4601b6c2fa3a3c4713c01dfe81eda8aa59af1e26","ref":"refs/heads/main","pushedAt":"2024-05-24T01:25:22.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #366 from tstromberg/fpr-may22\n\nfpr: Fedora Silverblue, MHLinkServer, Elastic, ptyxis, Zed","shortMessageHtmlLink":"Merge pull request #366 from tstromberg/fpr-may22"}},{"before":"6dd798c4a083e42341419a01911bb6e01ffe321b","after":"a0c49efb3fc021b2cf7852fb4fe32d4b3940d7ec","ref":"refs/heads/main","pushedAt":"2024-04-29T13:33:45.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #365 from tstromberg/fpr-apr25\n\nmark command-events & execdir-events as 'extra' due to high CPU usage","shortMessageHtmlLink":"Merge pull request #365 from tstromberg/fpr-apr25"}},{"before":"2f790f040847db623e86e36622dcd2d8ae332069","after":"6dd798c4a083e42341419a01911bb6e01ffe321b","ref":"refs/heads/main","pushedAt":"2024-04-26T20:14:37.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #364 from tstromberg/fpr-apr25\n\nfpr: MHLink, k3d, BlueFin, query tuning","shortMessageHtmlLink":"Merge pull request #364 from tstromberg/fpr-apr25"}},{"before":"dd6b2e43fb113f72b4130ab234c0354b2889a85d","after":"2f790f040847db623e86e36622dcd2d8ae332069","ref":"refs/heads/main","pushedAt":"2024-03-29T14:13:55.000Z","pushType":"pr_merge","commitsCount":4,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #363 from tstromberg/springbreak\n\nFPR: Docker, Yubikey, Aerospace, WhatsApp, nuclei, etc.","shortMessageHtmlLink":"Merge pull request #363 from tstromberg/springbreak"}},{"before":"a673c28222b845775ee90488f46fb6e2ce732786","after":"dd6b2e43fb113f72b4130ab234c0354b2889a85d","ref":"refs/heads/main","pushedAt":"2024-03-15T23:10:28.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #360 from jedsalazar/pr/jed/harden-runner-osq-dk\n\nAdd Harden Runner audit configs","shortMessageHtmlLink":"Merge pull request #360 from jedsalazar/pr/jed/harden-runner-osq-dk"}},{"before":"6eb5b9ebdb4b24b8959f6ecdcd3e5464143d83d2","after":"a673c28222b845775ee90488f46fb6e2ce732786","ref":"refs/heads/main","pushedAt":"2024-03-15T23:07:10.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #362 from tstromberg/kandji\n\nPerformance tuning, mark some Linux queries as 'extra'","shortMessageHtmlLink":"Merge pull request #362 from tstromberg/kandji"}},{"before":"7c5599c07d396279d14ebee5f97006482a008307","after":"6eb5b9ebdb4b24b8959f6ecdcd3e5464143d83d2","ref":"refs/heads/main","pushedAt":"2024-03-15T19:35:44.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #361 from tstromberg/kandji\n\nAllow Kandji to do weird things with expect","shortMessageHtmlLink":"Merge pull request #361 from tstromberg/kandji"}},{"before":"72f182847504c24f7d7d365c8511b0fbe8a5461f","after":"7c5599c07d396279d14ebee5f97006482a008307","ref":"refs/heads/main","pushedAt":"2024-03-07T21:34:35.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #359 from tstromberg/fpr-mar7\n\nfpr: snapd, cups, ubuntu, etc","shortMessageHtmlLink":"Merge pull request #359 from tstromberg/fpr-mar7"}},{"before":"51ecee8d9b511e0378b22ed9c7e2c78cf9bdbd8f","after":"72f182847504c24f7d7d365c8511b0fbe8a5461f","ref":"refs/heads/main","pushedAt":"2024-02-26T22:29:47.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #358 from tstromberg/fpr-feb26\n\nfpr: Docker Desktop, code-oss, incus, geoclue, etc","shortMessageHtmlLink":"Merge pull request #358 from tstromberg/fpr-feb26"}},{"before":"d1f6aede22e15aed0712a5999c3c8e1db06f9c9a","after":"51ecee8d9b511e0378b22ed9c7e2c78cf9bdbd8f","ref":"refs/heads/main","pushedAt":"2024-02-23T21:27:36.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #357 from tstromberg/feb16-fpr\n\nfpr: Incus, Firefox, mbim, networkd, incus","shortMessageHtmlLink":"Merge pull request #357 from tstromberg/feb16-fpr"}},{"before":"6b5d7445053667275d44d7f11921ba56a74bc163","after":"d1f6aede22e15aed0712a5999c3c8e1db06f9c9a","ref":"refs/heads/main","pushedAt":"2024-02-23T20:10:23.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #356 from tstromberg/ktaint\n\nIgnore taint code 4096 (out-of-tree driver)","shortMessageHtmlLink":"Merge pull request #356 from tstromberg/ktaint"}},{"before":"0d5467e72da69bf03a2a4eb5c17e487d7e75e1fd","after":"6b5d7445053667275d44d7f11921ba56a74bc163","ref":"refs/heads/main","pushedAt":"2024-02-16T22:24:41.000Z","pushType":"pr_merge","commitsCount":5,"pusher":{"login":"tstromberg","name":"Thomas Strömberg","path":"/tstromberg","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/101424?s=80&v=4"},"commit":{"message":"Merge pull request #355 from tstromberg/feb16-fpr\n\nfpr: Elastic, IR, Velociraptor, BitDefender, incus, Adguard","shortMessageHtmlLink":"Merge pull request #355 from tstromberg/feb16-fpr"}}],"hasNextPage":true,"hasPreviousPage":false,"activityType":"all","actor":null,"timePeriod":"all","sort":"DESC","perPage":30,"cursor":"Y3Vyc29yOnYyOpK7MjAyNC0wOC0yN1QyMzowNjowMC4wMDAwMDBazwAAAASl5LnV","startCursor":"Y3Vyc29yOnYyOpK7MjAyNC0wOC0yN1QyMzowNjowMC4wMDAwMDBazwAAAASl5LnV","endCursor":"Y3Vyc29yOnYyOpK7MjAyNC0wMi0xNlQyMjoyNDo0MS4wMDAwMDBazwAAAAP9ApD_"}},"title":"Activity · chainguard-dev/osquery-defense-kit"}