Changelog
- [88f24c] Add C-0298: detect subjects that can attach ephemeral containers to pods (#3017)
- [6bc13d] Add RBAC-police rules for issue [#916]: impersonate, token-mint, escalate, bind, node-proxy, PV create (#3093)
- [437bd6] Add URL context to repository scanner error messages (#3650)
- [321b6c] Add opt-in audit for posture exceptions (#3095)
- [80bddb] Fix memory allocation spikes during opa evaluations (#2920)
- [07bab2] Keep CRD exceptions that a narrower cloud exception does not actually cover (#3351)
- [c90ae8] [LFX 2026] chore(deps): bump opa-utils to v0.0.312 for alertOnly exception semantics (#3615)
- [e6fa8b] chore(cel): bump the pinned CEL policy library to v0.14 and sync the bundle (#3556)
- [cfc1db] chore(deps): bump github.com/armosec/armoapi-go in /httphandler (#3161)
- [16b28e] chore(deps): bump github.com/armosec/armoapi-go in /httphandler (#3526)
- [66df91] chore(deps): bump github.com/armosec/armoapi-go in /httphandler (#3686)
- [6f0b30] chore(deps): bump github.com/aws/aws-sdk-go-v2 from 1.43.7 to 1.45.1 (#3711)
- [7dbd0b] chore(deps): bump github.com/aws/aws-sdk-go-v2/config (#3528)
- [1824b7] chore(deps): bump github.com/go-openapi/runtime in /httphandler (#3685)
- [351e4c] chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.8 to 6.8.3 (#3530)
- [43588f] chore(deps): bump github.com/kubescape/backend in /httphandler (#3684)
- [e4868d] chore(deps): bump github.com/kubescape/go-git-url from 0.0.31 to 0.0.33 (#3529)
- [97aa96] chore(deps): bump github.com/kubescape/go-logger from 0.0.28 to 0.0.34 (#3695)
- [42158f] chore(deps): bump github.com/kubescape/go-logger in /httphandler (#3522)
- [9646cf] chore(deps): bump github.com/kubescape/k8s-interface in /httphandler (#3166)
- [6b9091] chore(deps): bump github.com/kubescape/opa-utils in /httphandler (#3524)
- [41a952] chore(deps): bump github.com/kubescape/rbac-utils from 0.0.21-0.20230806101615-07e36f555520 to 0.0.21 (#3170)
- [6cf53b] chore(deps): bump github.com/mark3labs/mcp-go from 0.29.0 to 0.57.0 (#3168)
- [b5bd33] chore(deps): bump github.com/mark3labs/mcp-go from 0.57.0 to 0.58.0 (#3692)
- [03814d] chore(deps): bump github.com/maruel/natural from 1.1.1 to 1.3.0 (#3696)
- [336432] chore(deps): bump github.com/mattn/go-isatty from 0.0.21 to 0.0.24 (#3710)
- [80bbc8] chore(deps): bump github.com/open-policy-agent/opa from 1.14.1 to 1.19.0 (#3167)
- [285aff] chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.2.0 to 2.3.3 (#3523)
- [4f0229] chore(deps): bump github.com/zclconf/go-cty from 1.17.0 to 1.19.0 (#3531)
- [b58600] chore(deps): bump go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux (#3169)
- [7dc067] chore(deps): bump go.opentelemetry.io/otel in /httphandler (#3163)
- [40ee29] chore(deps): bump go.opentelemetry.io/otel/sdk/metric (#3164)
- [44af76] chore(deps): bump google.golang.org/protobuf (#3690)
- [aecc40] chore(deps): bump k8s.io/apimachinery in /httphandler (#3165)
- [76485e] chore(deps): bump k8s.io/apimachinery in /httphandler (#3527)
- [f7e4d1] chore(deps): bump k8s.io/apimachinery in /httphandler (#3687)
- [29682f] chore(deps): bump opa-utils to v0.0.309 to pick up the NewScore singleton fix (#3416)
- [614497] chore(deps): bump sigs.k8s.io/kustomize/api from 0.20.1 to 0.21.1 (#3162)
- [cc91fb] chore(deps): fix Dependabot security vulnerabilities in Go dependencies (#3715)
- [a26f55] chore(goreleaser): embed E2E hook as single script (#3299)
- [8581f0] chore(hostsensor): delete leftover empty json.go file (#3121)
- [0f17e1] chore(printer): clarify strings import dependency in policyreportprinter.go (#3550)
- [0c1075] ci(comments): gate pr_agent on trusted commenter author_association (#3449)
- [bf9a1e] ci: bound pr-scanner job runtime with timeout-minutes (#3431)
- [a85802] ci: bump Codium-ai/pr-agent from 0.35.0 to 0.43.0 (#3535)
- [b7f4f6] ci: bump actions/attest-build-provenance from 2.4.0 to 4.2.2 (#3320)
- [3ff350] ci: bump actions/create-github-app-token from 1.12.0 to 3.2.0 (#3322)
- [562554] ci: bump actions/setup-go from 5.6.0 to 7.0.0 (#3157)
- [10d99f] ci: bump actions/setup-python from 5.6.0 to 7.0.0 (#3688)
- [451cbe] ci: bump actions/upload-artifact from 4.6.2 to 7.0.1 (#3159)
- [1a8909] ci: bump anchore/sbom-action/download-syft from 0.24.0 to 0.24.2 (#3689)
- [bf6040] ci: bump docker/login-action from 3.7.0 to 4.6.0 (#3156)
- [79a955] ci: bump docker/setup-buildx-action from 3.12.0 to 4.2.0 (#3321)
- [7bc9ea] ci: bump docker/setup-buildx-action from 4.2.0 to 4.3.0 (#3534)
- [dba15b] ci: bump docker/setup-qemu-action from 3.7.0 to 4.2.0 (#3160)
- [65b05f] ci: bump github.com/armosec/armoapi-go in /httphandler (#3318)
- [1aa786] ci: bump github.com/go-openapi/runtime in /httphandler (#3315)
- [9ffcbd] ci: bump github.com/kubescape/go-logger in /httphandler (#3317)
- [09b04d] ci: bump github.com/stretchr/testify in /httphandler (#3525)
- [4ad86b] ci: bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 (#3323)
- [a01609] ci: bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9 (#3691)
- [1f143f] ci: bump golangci/golangci-lint-action from 9.2.0 to 9.3.0 (#3693)
- [29c3ac] ci: bump goreleaser/goreleaser-action from 6.4.0 to 7.2.3 (#3158)
- [c92319] ci: bump helm/kind-action from 1.10.0 to 1.14.0 (#3532)
- [e8d34e] ci: bump mikepenz/action-junit-report from 5.6.2 to 6.4.2 (#3533)
- [8df7c6] ci: bump mikepenz/action-junit-report from 6.4.2 to 6.5.0 (#3708)
- [2c90b1] ci: bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#3319)
- [bbb0c9] ci: bump rajatjindal/krew-release-bot from 0.0.47 to 0.0.51 (#3536)
- [79734b] ci: bump sigstore/cosign-installer from 3.5.0 to 3.10.1
- [16693e] ci: pin golangci-lint to v2.12.2 to avoid v2.13.0 staticcheck timeout (#3429)
- [71caf0] core: add ScanContext, an explicit-context scan entry point (#3237) (#3432)
- [858f1d] core: add ScanImageContext, closing the last explicit-context gap from [#3237] (#3442) (#3443)
- [145590] docs(cel): correct the authorizer skip scope and make the verification recipe reproducible (#3496)
- [08f449] docs(opaprocessor): add process flow documentation and package comment (#3290)
- [a9728d] docs(workflows): correct default branch and stale CI process in workflows README (#3118)
- [61ca76] feat(anonymizer): detect pseudo-ID collisions in Mapping.GetOrCreate (#3417)
- [1c5470] feat(cel): evaluate VAP matchConditions offline instead of refusing the control (#3222)
- [5aff86] feat(cel): honor VAP spec.failurePolicy for validation expression errors (#3583)
- [6bd868] feat(config): add cached config validation (#3663)
- [3496ee] feat(config): add config view output formats (#3055)
- [c10947] feat(config): support --format / -f flag in config view (#3641) (#3642)
- [bd7ffe] feat(containerscan): validate layers, layer hashes, and vulnerability names in
ScanResultReport.Validate()(#3591) - [3286d8] feat(coverage): flag frameworks scored 100% purely from irrelevant controls (#3421)
- [a819b8] feat(coverage): report resource kinds no control examined (#3588)
- [352a39] feat(diff): add aggregate summary outputs (#3626)
- [2fe500] feat(exposure): model external exposure via Ingress, Gateway API, and Service type (#3648)
- [a87aed] feat(exposure): model spec.externalIPs, flag unconfirmed cross-namespace backendRef as unclear (#3679)
- [75e692] feat(fix): select which controls to remediate with --include-controls and --skip-controls (#3714)
- [f0914b] feat(fix): support cluster scan reports by printing patched manifests (#3705)
- [991932] feat(fixhandler): apply fixes to JSON manifests (#3608)
- [76cf9a] feat(getter): load custom rules from the standard rule directory layout (#3553)
- [146d46] feat(getter): support --custom-rules for user-authored Rego rules (#3419)
- [fcc1fd] feat(gitlab-sast): populate Solution field with fix paths and current values (#3182)
- [e06a1c] feat(image): surface VEX status in reports (#3594)
- [ca4253] feat(imagescan): add --skip-db-update flag for offline image scanning (#3387)
- [78f148] feat(imagescan): add native GitLab vulnerability adaptor (#3210)
- [ad7b41] feat(imagescan): add native Harbor vulnerability adaptor (#3209)
- [e34034] feat(imagescan): scan the correct platform for multi-arch images (#3345)
- [00b709] feat(list): filter controls by framework and search (#3624)
- [1a73d2] feat(list): show the control configuration a scan evaluates against (#3586)
- [dcc5a0] feat(mapreconcile): add MutatingAdmissionPolicy discovery and impact matching (#3606)
- [23ac4a] feat(markdown): support image scan reports (#3573)
- [35ff0d] feat(mcp): add scan_controls, scan_local_iac_controls, list_frameworks, and list_controls tools (#3252)
- [1ee4b9] feat(mcpserver): add SSE transport and advanced MCP tools for LLMs (#3375)
- [3ba821] feat(mcpserver): add apply_remediation tool for deterministic AI auto-patching (#3568)
- [7ac644] feat(mcpserver): add scan_workload tool for single-resource scanning (#3669)
- [aa3fb7] feat(networkpolicy): add real NetworkPolicy reachability engine (#3601)
- [d41b6f] feat(networkpolicy,vulnexposure): correlate vulnerabilities with NetworkPolicy exposure (#3632)
- [4d2053] feat(opaprocessor): add inline exception suppression via resource annotations (#3392)
- [e86026] feat(operator): add findings-driven targeting to the remediate CLI (#3474)
- [2f23ee] feat(policy): add kubescape policy test to run rule fixtures against the real evaluator (#3477)
- [e02e22] feat(policy): scaffold custom Rego rules and refresh test fixtures from rule output (#3635)
- [0cf33c] feat(printer): add github-actions output format for inline PR annotations (#3637)
- [42ced6] feat(printer): generate a posture exceptions baseline from scan results (#3560)
- [b08c55] feat(printer): include evidence paths in GitHub Actions annotation messages (#3677)
- [60f501] feat(printer): render map/slice values in AssistedRemediation evidence (#3254)
- [4ea7d4] feat(printer): support initContainers and ephemeralContainers in assisted remediation paths (#3578)
- [f6ec4e] feat(printer): surface failed-path evidence values in JSON/YAML output (#3256)
- [4ae94d] feat(rbacgraph): model multi-hop RBAC privilege-escalation paths (#3681)
- [5cde74] feat(resourcehandler): collect via namespaced endpoints under --include-namespaces (#3683)
- [b0ea53] feat(rules): add approve-csr-v1 (#3298)
- [ceef75] feat(rules): add assign-serviceaccount-to-pod-v1 (#3148)
- [cae364] feat(rules): add issue-token-secrets-v1 (#3174)
- [24b1fd] feat(rules): add modify-node-status-v1 (#3330)
- [6a1fe8] feat(rules): add modify-pod-status-v1 (#3332)
- [b3cf05] feat(rules): add modify-privileged-pods-v1 (#3146)
- [357542] feat(rules): add modify-service-status-v1 (#3291)
- [281d9f] feat(rules): add provider-iam-assumption-v1 (#3149)
- [d5b1f4] feat(rules): add steal-privileged-pods-v1 (#3224)
- [b4faa6] feat(rules): add weak-namespace-pod-rce-v1 (#3147)
- [d9c937] feat(rules): add weak-namespace-token-access-v1 (#3339)
- [40e302] feat(sarif): add stable scan fingerprints (#3639)
- [2b435a] feat(sarif): resolve each FailedPath to its own relatedLocation (#3257)
- [2d1912] feat(sarif): show current field values in evidence paths (#3062)
- [1e3820] feat(scan): add --dry-run RBAC preflight check (#3083)
- [61927a] feat(scan): add --exclude-controls to drop controls from a framework scan (#3441)
- [ce654f] feat(scan): add --exclude-path and .kubescapeignore for local scans (#3422)
- [dc08f5] feat(scan): add --include-kinds and --exclude-kinds resource kind filters (#3372)
- [803554] feat(scan): add --show-evidence (-E) and --show-secrets flags (#3220)
- [e693bc] feat(scan): add SARIF contract validation output (#3622)
- [dcd711] feat(scan): add Slack webhook notifications (#3571)
- [ef61a5] feat(scan): add contract report provenance (#3607)
- [9f0bb3] feat(scan): add generic webhook notifications (#3504)
- [71fd98] feat(scan): add per-namespace compliance rollup (#3704)
- [77e5ff] feat(scan): apply repository scan contracts (#3537)
- [bd56cb] feat(scan): emit CycloneDX and SPDX SBOMs from posture scans with --scan-images (#3698)
- [d255b2] feat(scan): extend --min-severity to all output formats and add --max-severity (#3337)
- [fbe8ee] feat(scan): implement missing controls listing in ScanAll functionality (#3300)
- [3e0635] feat(scan): record contract runner input digests (#3640)
- [8932c9] feat(scan): scan multiple images in one run sharing the vulnerability database (#3682)
- [93e722] feat(scan): send Microsoft Teams Adaptive Card notifications for --notify webhooks (#3645)
- [c8a0bb] feat(scan): validate repository scan contracts (#3481)
- [c8e5d7] feat(scan): wire CEL ValidatingAdmissionPolicy evaluation into the scan pipeline (#3513)
- [2b0dea] feat(scan): wire up sequential multi-cluster scanning via --kube-contexts (#3438)
- [f8a166] feat(telemetry): export scan traces and metrics to an OTLP collector (#3521)
- [ba47e9] feat(telemetry): report image DB freshness (#3604)
- [1644f5] feat(vap): allow a policy binding to declare multiple validation actions (#3295)
- [39a381] feat(vap): list embedded admission policies and the controls they implement (#3674)
- [11d6db] feat(vap): scope a generated policy binding to specific resources (#3283)
- [9e90ed] feat(vapreconcile): add dynamic discovery and fallback for VAP versions (#2880)
- [06edc3] feat(vapreconcile): add per-resource VAPBinding scope coverage (#3570)
- [1e914a] feat(vapreconcile): discover the served VAP API version instead of assuming v1 (#3196)
- [a9934d] feat(version): add yaml output format support (#3542) (#3543)
- [7e8bc5] feat: Add GCP and Azure support for DescribeRepositories and ListEnti… (#2573)
- [1527e5] feat: Add context-aware VAP for ActorTemplate and WorkerPool (#3466)
- [54c4d0] feat: Add eBPF telemetry correlation interface (#3226)
- [0c15c0] feat: Implement global chunked pagination for Kubernetes resource retrieval (#3428)
- [200054] feat: Streaming OpenVEX / CSAF Attestation Engine (#3294)
- [a072e3] feat: add --min-severity flag to filter JSON scan output by severity (#3053)
- [5c34e8] feat: add PolicyReport/ClusterPolicyReport (wgpolicyk8s.io) output format (#3125)
- [a613ff] feat: baseline drift detection for live cluster scans (--baseline) (#3353)
- [b86ed4] feat: emit exception-match events for file/cloud exceptions too (#3373)
- [36749b] feat: incremental scan caching to skip unchanged resources (--incremental) (#3412)
- [2ade57] feat: parallelize OPA control evaluation (#2825)
- [b8fe42] feat: support --format json for the update command (#3617)
- [4c7dc1] feat: support downloading all controls when no ID is specified (#3435)
- [6827c3] feat: surface skipped manifests at scan completion (#3031)
- [35a201] feat: surface vulnerability DB freshness in image-scan results (#3356)
- [0fbe65] fix(anonymizer): anonymize Secret/ConfigMap names referenced via spec.volumes (#3619)
- [4adf32] fix(anonymizer): anonymize container names and images on scanned workloads (#3463)
- [431b14] fix(anonymizer): anonymize env var names referencing fieldRef and resourceFieldRef (#3484)
- [f7916a] fix(anonymizer): hide scan path, host and cluster identity under --hide and --encrypt (#3611)
- [d22e5a] fix(anonymizer): pseudonymize image-scan results under --hide/--encrypt (#3661)
- [e540e2] fix(anonymizer): restore reference-backed env var name anonymization (#3579)
- [19ccc8] fix(anonymizer): stop a Windows drive letter from masking sourcePath (#3202)
- [275028] fix(anonymizer): transform env var names referencing secrets/configmaps (#3364)
- [27b77e] fix(anonymizer): widen --hide pseudonym suffix past the 32-bit collision bound (#3221)
- [e04750] fix(cache): preserve rolling fallback across pinned scans (#3258)
- [1a6c10] fix(cautils): add cluster-context isolation helper for sequential multi-cluster scans (#3218)
- [c12153] fix(cautils): make config serialization non-mutating (#3228)
- [e24b7e] fix(cautils): propagate scan errors from splitYAMLDocuments instead of truncating silently (#3423)
- [c8fef2] fix(cautils): use sync.Once to safely stop PortForwarder without dropping stop signals (#3272) (#3273)
- [79a95b] fix(cautils): validate file-scan YAML manifests against the client-go scheme (#3078)
- [722fa5] fix(cel): derive remediation paths through concatenated container lists (#3079)
- [5460f7] fix(cel): evaluate every matchCondition, not just up to the first false (#3630)
- [9ce6ce] fix(cel): honor an equivalent matchPolicy when scoping a policy to a scanned object (#3673)
- [d8a07e] fix(cel): honor failurePolicy Fail for validation eval errors (#3082)
- [421410] fix(cel): honor matchConstraints rule scope when scoping offline VAP evaluation (#3251)
- [b84137] fix(cel): match CRD plurals the kind guess spells wrong (#3355)
- [a4a630] fix(cel): populate request.resource plural from the same guess appliesTo scopes with (#3099)
- [855468] fix(cel): refuse a control whose paramKind the scan has no binding to resolve (#3495)
- [a86372] fix(cel): resolve CRD resource plurals the kind guess cannot reach (#3177)
- [0a12e7] fix(cel): resolve a cluster-scoped paramRef, and refuse one that selects params (#3575)
- [bd467c] fix(ci): prevent shell injection in tag-action composite action (#3700)
- [013adc] fix(ci): refresh expired SECURITY-INSIGHTS.yml and enforce its freshness (#3285)
- [f9a0a3] fix(ci): restore valid YAML in dependabot.yaml and guard it (#3128)
- [80403c] fix(config): make config set keys case-insensitive and accept kebab-case (#3540) (#3541)
- [8f023c] fix(config): mask the cached access key in
config viewoutput (#3266) - [9cfff6] fix(containerscan): make IsRCE classification case-insensitive (#3143)
- [4e7770] fix(core): close output writers when Scan fails (#3232)
- [70c681] fix(core): ensure OpenTelemetry spans are ended across all exit and error paths (#3665)
- [355e44] fix(core): pin policy handler during collection (#3250)
- [3b0dec] fix(core): report cached exceptions as degraded (#3241)
- [2b0171] fix(core): return finalized data with OPA errors (#3243)
- [6ac9c3] fix(core): stop TestGetDownloadReleasedPolicy failing on transient GitHub 5xx (#3122)
- [60de56] fix(decrypt): restore complete encrypted reports (#3198)
- [3a4668] fix(diff): detect evidence-level regressions (#3275)
- [250e58] fix(diff): emit CI regression artifacts (#3379)
- [c79187] fix(diff): propagate output errors (#3191)
- [18fefe] fix(download): accept plural and alias target arguments (#3666) (#3667)
- [0e3423] fix(download): handle nested output directory creation and error wrapping (#3305) (#3306)
- [bfa3b3] fix(exceptions): error on zero-match namespaceSelector in ClusterSecurityException (#3310)
- [0fe7a9] fix(fixhandler): check the error from closing a fixed file, not just writing it (#3580)
- [b2a089] fix(fixhandler): cross-control fix promotion checks the value, not just the path (#3634)
- [22e6aa] fix(fixhandler): reject yq expression syntax in report fix paths (#3096)
- [a064d7] fix(getter): give custom rules a base score instead of leaving it zero (#3676)
- [d1330f] fix(getter): propagate context to cloud requests (#3246)
- [ae599c] fix(gitlabsast): reject absolute paths filepath.IsAbs does not recognise (#3076)
- [895328] fix(gomod): bump module path to /v4 to match release tags (#3350)
- [6b39f6] fix(host-cache): isolate concurrent temporary files (#3108)
- [6ca8e5] fix(hostsensor): emit error when CRD list is empty but nodes exist (#3172)
- [647e45] fix(hostsensor): enforce bounded decompression read in cache to prevent OOM (CWE-400) (#3490)
- [e199d7] fix(hostsensor): remove dead protobuf config code for dynamic client (#3115)
- [675afb] fix(hostsensor): return nil handler on initialization error (#3119)
- [d9e8ba] fix(hostsensor): stop caching empty host sensor collections (#3324)
- [824050] fix(hostsensorutils): record a status when reported CRD items cannot be read (#3561)
- [195cce] fix(http): add graceful shutdown to watchForScan goroutine (#3195)
- [747698] fix(http): handle JSON marshal errors in responseToBytes (#3193)
- [fa02c4] fix(httphandler): add optional bearer auth and trust boundary docs for /v1 endpoints (#3461)
- [0aa9c0] fix(httphandler): prevent metrics scrapes from hijacking latest scan status and results (#3034)
- [e79d7c] fix(httphandler): stop honoring client-supplied account/accessKey in scan requests (#3068)
- [9ba886] fix(imagescan): add guards for empty Hash and Tag in ECR adaptor (#3058)
- [256507] fix(imagescan): bound GCP GetImagesScanStatus pagination loop (#3566)
- [cdc03c] fix(imagescan): bound registry API responses (#3473)
- [b9c01e] fix(imagescan): prevent Grafeas filter injection via resourceURL (#3052)
- [a13726] fix(imagescan): reject invalid exception target regexes (#3192)
- [03fabc] fix(imagescan): stop stalled GitLab pagination (#3472)
- [7d53a5] fix(imagescan): tighten gitlab imageMatches suffix check (#3340)
- [427552] fix(imagescan): use match metadata for severity gates (#3189)
- [9c61b8] fix(install): quote paths and limit cleanup to canonical locations (#3464)
- [9bcd13] fix(install): verify downloaded binaries against the release checksum manifest (#3067)
- [f4dca8] fix(junit): disambiguate duplicate testcase names with control ID (#3141)
- [580c58] fix(junit): distinguish image scan platforms (#3544)
- [6f98e7] fix(junit): include image findings in combined scans (#3190)
- [1937ec] fix(krew): make .krew.yaml renderable and match published asset names (#3389)
- [b09267] fix(ksinit): resolve the kubeconfig home directory with os.UserHomeDir (#3197)
- [89c1f9] fix(makefile): verify sync-vap downloads against pinned SHA256 digests (#3036)
- [6bca9f] fix(mapreconcile): a policy gated by matchConditions is not a confirmed match (#3654)
- [4bcf79] fix(mapreconcile): match the subresource form of a resource rule (#3646)
- [d78183] fix(mcpserver): add concurrency limits for expensive scans (#3089)
- [bcf03d] fix(mcpserver): detach new callers from canceled scans (#3176)
- [33b3ac] fix(mcpserver): guard getPolicyGetter's lazy init, matching its siblings (#3445)
- [5fbcc6] fix(mcpserver): log policy-store initialization errors at startup (#3091)
- [cf896e] fix(mcpserver): prefer ScanCoverage over the seeded summary when flagging unevaluated controls (#3574)
- [685eab] fix(mcpserver): return marshal errors from get_configuration_drift (#3211)
- [90f9ae] fix(mcpserver): scan_resource_slice returns [] not null for an empty result set (#3506)
- [6ab34b] fix(metrics): export ResetForTest so external packages can rebind instruments (#3483)
- [33512a] fix(metrics): report latest resource counts (#3248)
- [40ec81] fix(opaprocessor): add C-0261 to whole-cluster control fallback (#3150)
- [c7699a] fix(opaprocessor): apply --skip-controls/--include-controls on the streaming path (#3520)
- [5de926] fix(opaprocessor): deduplicate merged paths for resources evaluated in every scope (#3060)
- [f3a9fc] fix(opaprocessor): evaluate rules against full input after enumeration (#3628)
- [7218a7] fix(opaprocessor): evaluate whole-cluster controls once after per-namespace batching (#3080)
- [2acaba] fix(opaprocessor): flag Passed verdicts reached on incomplete RBAC-dependent data (#3183)
- [3b24b2] fix(opaprocessor): guard InfoMap read against concurrent writes in hasUnreachableDependency (#3563)
- [a70fa5] fix(opaprocessor): hard error when --include-controls matches no known control (#3552)
- [905c32] fix(opaprocessor): honor ResourceEnumerator output in scan path (#3559)
- [fdd64f] fix(opaprocessor): honor namespace scope on incremental cache hits (#3501)
- [337866] fix(opaprocessor): make --skip-controls and --include-controls case-insensitive (#3508)
- [0ff591] fix(opaprocessor): make scope-less exceptions apply to resource-backed findings too (#3427)
- [793f95] fix(opaprocessor): match CIS section numbers in --skip-controls/--include-controls (#3658)
- [3619aa] fix(opaprocessor): quote inline exception designator attributes (#3558)
- [1376e5] fix(opaprocessor): redact ConfigMap binaryData (#3132)
- [55366a] fix(opaprocessor): stop caching rules that read resource status (#3482)
- [740586] fix(output): keep combined renderers from mutating scan data (#3139)
- [323ae8] fix(output): return explicit output setup errors (#3140)
- [ca764b] fix(patch): close intermediate scan file and guarantee cleanup on error (#3269) (#3271)
- [2fe630] fix(patch): filesystem-safe intermediate filenames and update-all nil guard (#3596)
- [255763] fix(patch): read registry credentials from the environment (#3145)
- [7b69eb] fix(policyhandler): bypass shared cache for local policies (#3234)
- [b712af] fix(portforward): preserve kubeconfig server URL (#3103)
- [206057] fix(preflight): skip Kubescape-served resources in dry-run access review (#3391)
- [173f57] fix(prettyprinter): stop treating resource-derived text as a format string (#3333)
- [d68971] fix(printer): add container names to HTML/SARIF evidence paths (#3301)
- [074f34] fix(printer): aggregate multiple image scan runs in SARIF report printer (#3395) (#3396)
- [48303c] fix(printer): annotate init/ephemeral container names on evidence paths (#3292)
- [371f4a] fix(printer): centralize output path resolution (#3492)
- [ca2ec4] fix(printer): dedupe enriched failed paths against bare delete paths (#3358)
- [ca8c63] fix(printer): format N/A and percentage compliance score correctly in… (#3362)
- [7da2a1] fix(printer): include the scanned platform in GitLab finding ids (#3713)
- [b4e662] fix(printer): migrate v2 report printers to return errors from CloseWriter (#3214) (#3215)
- [8c792c] fix(printer): normalize resource object before evidence path extraction (#3397)
- [2799b9] fix(printer): prevent out-of-bounds slice index panic in getSortedControlsIDs (#3363) (#3365)
- [2bbe31] fix(printer): resolve indexed paths when lists are []map[string]any (#3357)
- [1c4727] fix(printer): restore missing strings import and add YAML SetWriter tests (#3493)
- [893a44] fix(printer): restore missing strings import in policyreportprinter.go (#3503)
- [8628d4] fix(printer): sanitize cluster and namespace identifiers in PolicyReport names and labels (#3470)
- [5d498b] fix(printer): show assisted-remediation paths in control-view resource list (#3359)
- [e6a794] fix(printer): stop printTopComponents eating the dash on empty severities (#3450) (#3451)
- [129b49] fix(printer): support multiple image SBOM generation in CycloneDX and SPDX printers (#3399) (#3400)
- [e7074e] fix(printer): truncate control names on rune boundaries to avoid inva… (#3048)
- [38eca9] fix(prometheus): escape dynamic label values (#3104)
- [ea0e1f] fix(release): sign release assets with keyless cosign (#3344)
- [f7bdc9] fix(reportcrypto): bind AEAD ciphertexts to the report that owns them (#3414)
- [153936] fix(reportcrypto): derive the report master key with Argon2id (#3382)
- [72820b] fix(reporter): clean up generated credentials on all early returns (#3180)
- [e81611] fix(reporter): make posture report chunking deterministic (#3230)
- [64ddd0] fix(reporter): split report before first result exceeds limit (#3137)
- [7f48ca] fix(reporter): thread context to HTTP submissions to allow cancellation (#3153)
- [53befa] fix(resourcehandler): a namespace filter naming no namespace silently skips every namespaced query (#3539)
- [406560] fix(resourcehandler): block Secret reads via single-resource scan (#2892)
- [78ea1c] fix(resourcehandler): dedupe served-version aliases in streaming collector (#3303)
- [827d92] fix(resourcehandler): do not report a kind's other served versions as unexamined (#3609)
- [753bac] fix(resourcehandler): resolve the core API group spelling on live cluster scans (#3426)
- [c33d2f] fix(resourcehandler): scan Terraform-only directories (#3135)
- [d37bc8] fix(resourcehandler): skip discovered resources that do not support list (#3346)
- [eb14d3] fix(resourcehandler): treat an undecided access review as unchecked, not denied (#3446)
- [df3d64] fix(resourcehandler): use path aliases for containment (#3064)
- [caeb57] fix(resourcesprioritization): don't drop attack tracks when a resource matches more than one (#3659)
- [86b436] fix(results): preserve exception audit in programmatic JSON (#3277)
- [a5fe36] fix(results): preserve scan ID in posture reports (#3239)
- [d7bb62] fix(resultshandling): apply severity filters to framework control maps (#3455)
- [b10118] fix(resultshandling): deterministic AssociatedControls ordering across scans (#3590)
- [7ee60c] fix(resultshandling): filter per-resource findings by severity, not the unused Report.Results field (#3388)
- [5963cb] fix(resultshandling): recompute score and counters after severity filtering (#3436)
- [94a635] fix(rules): guard privilege-escalation RBAC rules with resourceNames (#3201)
- [87e7dc] fix(rules): handle empty resourceNames in modify-privileged-pods-v1 (#3313)
- [806e14] fix(scan): add --skip-controls and --include-controls flags for selective control execution (#3480)
- [55a79e] fix(scan): apply the resource kind filters before collection, not after (#3411)
- [285ea5] fix(scan): clarify --min-severity is output-only and warn about thresholds (#3458)
- [4a86dd] fix(scan): collect a resource once when several API versions serve it (#3297)
- [303d72] fix(scan): enforce compliance-threshold in scan workload (#3610) (#3612)
- [e09dbc] fix(scan): fail closed on unknown-severity findings in --severity-threshold (#3281)
- [cd20fc] fix(scan): fail explicitly on unmatched severity threshold (#3456)
- [1e1aa3] fix(scan): keep CRD policy clients target-scoped (#3262)
- [c7ba7d] fix(scan): preserve exact manifest file selection (#3270)
- [585671] fix(scan): propagate combined image scan failures (#2965)
- [a8e70c] fix(scan): re-register --fail-threshold as hidden deprecated flag (#3066)
- [a5efbb] fix(scan): reject NaN posture thresholds (#3279)
- [231da9] fix(scan): reject invalid persistent flag values (#3130)
- [70a8c5] fix(scan): reject trailing JSON manifest data (#3264)
- [d12ecd] fix(scan): report parse failures suppressed by "{{" content sniff (#3274)
- [39aa0e] fix(scan): resolve markdown output paths with the .md extension (#3073)
- [295577] fix(scan): treat zero loaded controls as a coverage failure (#3200)
- [11a4c7] fix(scan): validate --label-selector in ValidateCommonScanFlags (#3502)
- [164753] fix(scan): validate minimum severity for subcommands (#3131)
- [8c4483] fix(scan-coverage): surface skipped manifests in coverage and fail gate (#3555)
- [eaffd1] fix(scancache): reset dirty flag after Flush writes cache file (#3515)
- [68ade8] fix(score): route dead telemetry scorer output to logger.L().Debug (#3702)
- [8d468e] fix(storage): implement control merge strategy for WorkloadConfigurationScan (#3107)
- [aa3b8a] fix(storage): recover missing workload posture controls (#3545)
- [429df6] fix(streaming): report complete resource telemetry (#3260)
- [dfc7b0] fix(terraform): map sysctl blocks to Kubernetes sysctls (#3133)
- [83c9db] fix(update): make version-check handler injectable for unit tests (#3152)
- [8084b6] fix(vap): refuse a parameter reference that does not match the bound policy's paramKind (#3511)
- [a9d0ba] fix(vap): reject a resource rule the bound policy can never match (#3394)
- [45d642] fix(vap): report a namespace selector that cannot narrow a policy's cluster-scoped resources (#3597)
- [ecf6e1] fix(vap): stop create-policy-binding silently rewriting the label selector it was given (#3468)
- [141001] fix(vap): validate the --from-release tag before building the release URL (#3296)
- [7838f6] fix(vapreconcile): correct binding-scope coverage for cluster-scoped resources and Namespaces (#3592)
- [7cb079] fix(vapreconcile): credit admission enforcement to the policy a binding names (#3433)
- [6834f9] fix(version): propagate text output errors (#3129)
- [6c68c5] fix: Add chunked pagination to SecurityException CRD retrieval (#3393)
- [76dd1b] fix: PolicyReportPrinter.CloseWriter now returns the close error (#3408)
- [9192e1] fix: Terraform loader now recurses into subdirectories, like Helm/Kustomize (#3349)
- [68b964] fix: Windows absolute paths parse correctly when document index is omitted (#3070)
- [d93b6f] fix: accept key==value label selectors in vap create-policy-binding (#3404)
- [254cbc] fix: add missing CronJob, ReplicaSet, and Job support to MCP get_configuration_drift tool (#3282)
- [a32b07] fix: avoid multiple and empty setNotBusy calls (#3311)
- [f4958e] fix: check SetWriter's error in writeBaselineHeadReport (#3410)
- [006173] fix: compare --output file extensions case-insensitively (#3334)
- [e1a700] fix: count manual-control exceptions in the exception audit (#3371)
- [460a0d] fix: deduplicate included namespaces in splitNamespaces (#3599)
- [be9c57] fix: diff --severity-threshold fails closed on unresolvable severity (#3406)
- [4c734b] fix: embed HTML report logo instead of loading it from GitHub (#3336)
- [a1d088] fix: enforce keep-local/omit-raw-resources and submit flag mutual exclusivity for all scan commands (#3307)
- [815116] fix: enforce per-file size limit on file-scan path (#3453)
- [89bc23] fix: guard mergeMaps against nil new parameter for defensive nil-safety (#3072)
- [64abe4] fix: implement chunked pagination for namespace counting (#3467)
- [53af99] fix: initialize all vulnerability severities with placeholders (#3498)
- [3c7fd6] fix: normalize namespace '*' to empty string for cluster-wide scans (#3087)
- [18f4ff] fix: prevent panic in getLastLineOfResource for empty yaml files (#3203)
- [c2c1d3] fix: remove secrets from cluster size estimation to tighten RBAC (#3478)
- [1fb665] fix: repair master build breaks from module v4 bump and min-severity PR (#3361)
- [cab64a] fix: scope cluster size estimation to included namespaces (#3538)
- [d4c981] fix: stringify error before json.Marshal in RecoverFunc to avoid empty body (#3075)
- [cd00b5] fix: subsume CRD exceptions with a scope-less cloud exception (#3370)
- [f755eb] fix: use C-0035 instead of C-0016 for RBAC scanning (#3085)
- [f0a62d] fix: validate URLs in config set (#3585)
- [88840d] fix: validate layers and vulnerabilities in ScanResultReport (#3126)
- [ee50c2] perf(fileutils): resolve directory ownership by ancestor lookup instead of scanning every directory (#3092)
- [0bf630] perf(opaprocessor): cache LARGE_CLUSTER_SIZE threshold per OPAProcessor (#3342)
- [1d96e4] perf(printer): dedupe image scan summary in O(N) via a shared helper (#3178)
- [0d842d] perf: stream JSON outputs instead of massive byte array allocations in memory (#3670)
- [a02027] refactor(resourcehandler): count streaming namespaces in place (#3236)
- [856af1] refactor(resourcehandler): partition streaming collector items as the pager yields them (#3613)
- [e4735a] refactor: consolidate httphandler into root Go module (#3706)
- [50b81d] refactor: extract shared image adaptor boilerplate (#3026)
- [d68c4b] refactor: migrate gorilla/mux to net/http ServeMux (#3620)
- [80b2ab] refactor: remove deprecated FailedPath from codebase (#3598)
- [881a4c] security: remediate gosec v2.27.1 SAST findings (#3114)
- [455c07] test(cautils): skip helm chart symlink test when symlinks are unavailable (#3398)
- [52df22] test(cel): assert every params.settings key a bundle policy reads is shipped (#3205)
- [2796a8] test(cel): compare Rego and CEL verdicts for the converted controls (#3603)
- [1bad0e] test(config): assert view flags are passed to ViewConfig (#3216)
- [9bdb20] test(diff): cover --fail-on-new and severity-threshold gating (#3213)
- [156790] test(imagescan): add DI-based Login and pagination coverage for Azure/ECR adaptors (#3035)
- [3b55a1] test(mcpserver): treat CallTool namespace '*' as cluster-wide (#3212)
- [30f888] test(policy): validate all in-tree rule fixtures in CI (#3546)
- [3a8b9b] test(printer): add edge case coverage for AssistedRemediationPathsToString (#3548)
- [534609] test(printer): add regression test for sensitive data exposure in res… (#3582)
- [26f2b8] test(printer): close leaked file handles and skip POSIX mode check on Windows (#3077)
- [697dc8] test(resourcehandler): add a synthetic-cluster collector memory harness (#3614)
Released by GoReleaser.