From a98af726d774232cc64fef9a0af0b44ddd25f5bf Mon Sep 17 00:00:00 2001 From: fukusuket <41001169+fukusuket@users.noreply.github.com> Date: Mon, 31 Aug 2026 12:46:17 +0900 Subject: [PATCH] chore: update changelog for version 2.2.0 - Dev Release with improvements and bug fixes --- CHANGELOG-Japanese.md | 26 ++++++++++++++++++++++++++ CHANGELOG.md | 26 ++++++++++++++++++++++++++ WELA.ps1 | 9 ++++++++- website/docs/resources/changelog.ja.md | 26 ++++++++++++++++++++++++++ website/docs/resources/changelog.md | 26 ++++++++++++++++++++++++++ 5 files changed, 112 insertions(+), 1 deletion(-) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index a1a7a772..45565877 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -1,5 +1,31 @@ # CHANGELOG +## 2.2.0 [2026/xx/xx] - Dev Release + +**改善:** + +- ベースライン定義を`WELA.ps1`から`config/baselines.json`に外部化し、ベースラインの追加・変更をJSONの編集のみで行えるようにした。 (#358) (@fukusuket) + +**バグ修正:** + +- ルールのフィルタ条件が全て適用されず最後の条件のみが適用されていたため、ルール数が正確ではなかった。 (#358) (@fukusuket) +- 依存するログが無効になっているルールも使用可能として報告されていた。 (#358) (@fukusuket) +- 複数のカテゴリに属するルールが重複してカウントされ、CSVファイルにも重複して出力されていた。 (#358) (@fukusuket) +- どのカテゴリにも一致しないルールがCSVファイルとカバレッジの母数から除外されていた。現在は`Uncategorized`として報告される。 (#358) (@fukusuket) +- 使用率のしきい値が文字列として比較されていたため、割合の表示色が正しくなかった。 (#358) (@fukusuket) +- 監査が有効であるにもかかわらず`Success and Failure`が赤色で表示されていた。 (#358) (@fukusuket) +- MITRE ATT&CK Navigatorのレイヤーに不正なテクニックIDが含まれ、またUTF-16で出力されるためATT&CK Navigatorで読み込めなかった。 (#358) (@fukusuket) +- WELAが配置されているディレクトリ以外から実行すると失敗していた。 (#358) (@fukusuket) +- `audit-filesize`で1つのログが存在しないだけでチェック全体が中断されていた。 (#358) (@fukusuket) +- PowerShellのログ設定を32bitのレジストリビューからしか読んでいなかったため、GPOで設定された端末が`Disabled`と報告されていた。 (#358) (@fukusuket) +- `auditpol`の出力のパースが失敗する場合があり、また管理者権限なしで`audit-settings`を実行すると誤った結果を報告していた。 (#358) (@fukusuket) +- `configure -Baseline ASD`が警告なくYamatoSecurityの設定を適用していた。 (#358) (@fukusuket) +- `update-rules`のダウンロードに失敗した場合、既存の設定ファイルが壊れる可能性があった。 (#358) (@fukusuket) +- `std`、`table`、`gui`の各出力形式でCSVの出力が一貫していなかった。 (#358) (@fukusuket) +- リリースとCSV作成のGitHub Actionsワークフローが失敗していた。 (#358) (@fukusuket) + +**注意:** 上記の修正により、報告される使用率は2.1.0より低くなる(同一端末で23.38% -> 12.94%)。新しい値が正しい値であり、ログが無効なルールが使用可能としてカウントされなくなったことと、これまで除外されていたルールが母数に含まれるようになったことによるもの。 + ## 2.1.0 [2026/02/13] - Winter Release **バグ修正:** diff --git a/CHANGELOG.md b/CHANGELOG.md index 3129a6da..5e5fca3b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,31 @@ # CHANGELOG +## 2.2.0 [2026/xx/xx] - Dev Release + +**Improvements:** + +- Baseline definitions were moved out of `WELA.ps1` into a `config/baselines.json` config file, so adding or changing a baseline is now a JSON-only edit. (#358) (@fukusuket) + +**Bug Fixes:** + +- Rule filtering applied only the last criterion instead of all of them, so rule counts were inaccurate. (#358) (@fukusuket) +- Rules were reported as usable even when the logs they depend on were disabled. (#358) (@fukusuket) +- Rules that belong to multiple categories were counted and written to the CSV files multiple times. (#358) (@fukusuket) +- Rules that did not match any category were dropped from the CSV files and from the coverage total. They are now reported under `Uncategorized`. (#358) (@fukusuket) +- The utilization threshold was compared as a string, so the percentage was shown in the wrong color. (#358) (@fukusuket) +- `Success and Failure` was shown in red even though auditing was enabled. (#358) (@fukusuket) +- The MITRE ATT&CK Navigator layer contained invalid technique IDs and was written as UTF-16, which ATT&CK Navigator cannot read. (#358) (@fukusuket) +- Running WELA from a directory other than the one it is installed in failed. (#358) (@fukusuket) +- `audit-filesize` aborted the whole check when a single log was missing. (#358) (@fukusuket) +- PowerShell logging settings were only read from the 32-bit registry view, so a machine configured by GPO was reported as `Disabled`. (#358) (@fukusuket) +- Parsing of the `auditpol` output could fail, and running `audit-settings` without Administrator privileges produced a confidently wrong report. (#358) (@fukusuket) +- `configure -Baseline ASD` silently applied the YamatoSecurity settings. (#358) (@fukusuket) +- A failed download in `update-rules` could corrupt the existing config files. (#358) (@fukusuket) +- CSV output was inconsistent between the `std`, `table` and `gui` output types. (#358) (@fukusuket) +- The release and CSV creation GitHub Actions workflows were failing. (#358) (@fukusuket) + +**Note:** because of the fixes above, the reported utilization is now lower than in 2.1.0 (23.38% -> 12.94% on the same machine). The new number is the correct one: rules whose logs are disabled are no longer counted as usable, and rules that were previously dropped are now included in the total. + ## 2.1.0 [2026/02/13] - Winter Release **Bug Fixes:** diff --git a/WELA.ps1 b/WELA.ps1 index 22c033a3..51099fbe 100644 --- a/WELA.ps1 +++ b/WELA.ps1 @@ -7,6 +7,9 @@ [switch]$Help ) +$WELAVersion = "2.2.0" +$WELAReleaseName = "Dev Release" + # 実行時のカレントディレクトリに依存しないよう、すべてスクリプトの場所を基準にする $ScriptRoot = if ($PSScriptRoot) { $PSScriptRoot } else { (Get-Location).Path } $BaselineConfigPath = Join-Path $ScriptRoot "config/baselines.json" @@ -1270,6 +1273,7 @@ Usage: ./WELA.ps1 configure -Baseline YamatoSecurity # Configure audit settings based on the specified baseline ./WELA.ps1 configure -Baseline YamatoSecurity -Auto # Configure audit settings automatically without prompts ./WELA.ps1 update-rules # Update rule config files from https://github.com/Yamato-Security/WELA + ./WELA.ps1 version # Show the WELA version ./WELA.ps1 help # Show this help "@ @@ -1277,7 +1281,7 @@ Usage: [Console]::OutputEncoding = [System.Text.Encoding]::UTF8 Write-Host $logo -ForegroundColor Green Write-Host "" -Write-Host "WELA v2.1.0 - Winter Release" +Write-Host "WELA v$WELAVersion - $WELAReleaseName" Write-Host "" switch ($Cmd.ToLower()) { @@ -1350,6 +1354,9 @@ switch ($Cmd.ToLower()) { } UpdateRules } + "version" { + # バージョンはバナーで表示済みなので、ここでは何もしない + } "help" { Write-Host $usage } diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 1721e887..824bdc5b 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -3,6 +3,32 @@ !!! info "情報" このページはプロジェクトの [`CHANGELOG.md`](https://github.com/Yamato-Security/WELA/blob/main/CHANGELOG-Japanese.md) を反映したものです。ダウンロードは [リリースページ](https://github.com/Yamato-Security/WELA/releases) をご覧ください。 +## 2.2.0 [2026/08/31] - Dev Release + +**改善:** + +- ベースライン定義を`WELA.ps1`から`config/baselines.json`に外部化し、ベースラインの追加・変更をJSONの編集のみで行えるようにした。 (#358) (@fukusuket) + +**バグ修正:** + +- ルールのフィルタ条件が全て適用されず最後の条件のみが適用されていたため、ルール数が正確ではなかった。 (#358) (@fukusuket) +- 依存するログが無効になっているルールも使用可能として報告されていた。 (#358) (@fukusuket) +- 複数のカテゴリに属するルールが重複してカウントされ、CSVファイルにも重複して出力されていた。 (#358) (@fukusuket) +- どのカテゴリにも一致しないルールがCSVファイルとカバレッジの母数から除外されていた。現在は`Uncategorized`として報告される。 (#358) (@fukusuket) +- 使用率のしきい値が文字列として比較されていたため、割合の表示色が正しくなかった。 (#358) (@fukusuket) +- 監査が有効であるにもかかわらず`Success and Failure`が赤色で表示されていた。 (#358) (@fukusuket) +- MITRE ATT&CK Navigatorのレイヤーに不正なテクニックIDが含まれ、またUTF-16で出力されるためATT&CK Navigatorで読み込めなかった。 (#358) (@fukusuket) +- WELAが配置されているディレクトリ以外から実行すると失敗していた。 (#358) (@fukusuket) +- `audit-filesize`で1つのログが存在しないだけでチェック全体が中断されていた。 (#358) (@fukusuket) +- PowerShellのログ設定を32bitのレジストリビューからしか読んでいなかったため、GPOで設定された端末が`Disabled`と報告されていた。 (#358) (@fukusuket) +- `auditpol`の出力のパースが失敗する場合があり、また管理者権限なしで`audit-settings`を実行すると誤った結果を報告していた。 (#358) (@fukusuket) +- `configure -Baseline ASD`が警告なくYamatoSecurityの設定を適用していた。 (#358) (@fukusuket) +- `update-rules`のダウンロードに失敗した場合、既存の設定ファイルが壊れる可能性があった。 (#358) (@fukusuket) +- `std`、`table`、`gui`の各出力形式でCSVの出力が一貫していなかった。 (#358) (@fukusuket) +- リリースとCSV作成のGitHub Actionsワークフローが失敗していた。 (#358) (@fukusuket) + +**注意:** 上記の修正により、報告される使用率は2.1.0より低くなる(同一端末で23.38% -> 12.94%)。新しい値が正しい値であり、ログが無効なルールが使用可能としてカウントされなくなったことと、これまで除外されていたルールが母数に含まれるようになったことによるもの。 + ## 2.1.0 [2026/02/13] - Winter Release **バグ修正:** diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 62467981..87ae1eeb 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -3,6 +3,32 @@ !!! info This page mirrors the project [`CHANGELOG.md`](https://github.com/Yamato-Security/WELA/blob/main/CHANGELOG.md). See the [Releases page](https://github.com/Yamato-Security/WELA/releases) for downloads. +## 2.2.0 [2026/08/31] - Dev Release + +**Improvements:** + +- Baseline definitions were moved out of `WELA.ps1` into a `config/baselines.json` config file, so adding or changing a baseline is now a JSON-only edit. (#358) (@fukusuket) + +**Bug Fixes:** + +- Rule filtering applied only the last criterion instead of all of them, so rule counts were inaccurate. (#358) (@fukusuket) +- Rules were reported as usable even when the logs they depend on were disabled. (#358) (@fukusuket) +- Rules that belong to multiple categories were counted and written to the CSV files multiple times. (#358) (@fukusuket) +- Rules that did not match any category were dropped from the CSV files and from the coverage total. They are now reported under `Uncategorized`. (#358) (@fukusuket) +- The utilization threshold was compared as a string, so the percentage was shown in the wrong color. (#358) (@fukusuket) +- `Success and Failure` was shown in red even though auditing was enabled. (#358) (@fukusuket) +- The MITRE ATT&CK Navigator layer contained invalid technique IDs and was written as UTF-16, which ATT&CK Navigator cannot read. (#358) (@fukusuket) +- Running WELA from a directory other than the one it is installed in failed. (#358) (@fukusuket) +- `audit-filesize` aborted the whole check when a single log was missing. (#358) (@fukusuket) +- PowerShell logging settings were only read from the 32-bit registry view, so a machine configured by GPO was reported as `Disabled`. (#358) (@fukusuket) +- Parsing of the `auditpol` output could fail, and running `audit-settings` without Administrator privileges produced a confidently wrong report. (#358) (@fukusuket) +- `configure -Baseline ASD` silently applied the YamatoSecurity settings. (#358) (@fukusuket) +- A failed download in `update-rules` could corrupt the existing config files. (#358) (@fukusuket) +- CSV output was inconsistent between the `std`, `table` and `gui` output types. (#358) (@fukusuket) +- The release and CSV creation GitHub Actions workflows were failing. (#358) (@fukusuket) + +**Note:** because of the fixes above, the reported utilization is now lower than in 2.1.0 (23.38% -> 12.94% on the same machine). The new number is the correct one: rules whose logs are disabled are no longer counted as usable, and rules that were previously dropped are now included in the total. + ## 2.1.0 [2026/02/13] - Winter Release **Bug Fixes:**