Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package kubescape for openSUSE:Factory checked in at 2026-07-23 23:10:39 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/kubescape (Old) and /work/SRC/openSUSE:Factory/.kubescape.new.2004 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "kubescape" Thu Jul 23 23:10:39 2026 rev:45 rq:1367310 version:4.0.11 Changes: -------- --- /work/SRC/openSUSE:Factory/kubescape/kubescape.changes 2026-07-01 16:51:04.995172735 +0200 +++ /work/SRC/openSUSE:Factory/.kubescape.new.2004/kubescape.changes 2026-07-23 23:13:47.775552056 +0200 @@ -1,0 +2,80 @@ +Thu Jul 23 05:59:31 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 4.0.11: + * fix(scan): don't let + --exceptions/--controls-config/--attack-tracks trigger + air-gapped mode (#2532) + * fix(scan): restore root PersistentPreRun for kubescape scan + invocations (#2530) + * feat: run CEL controls as part of the scan (#2525) + * [Fix] : severity-based image exceptions in JSON, SARIF, and + patch output -- use filtered Matches instead of + RemainingMatches (#2522) + * rbac file todo to check api version is resolved (#2523) + * fix(imagescan): preserve matches on metadata lookup errors + (#2519) + * Fix control-inputs fallback to return real local getter instead + of unloaded store (#2515) + * docs: fix stale KS_CACHE TODO comment in customerloader.go + (#2516) + * fix(vap): deploy-library serves the embedded bundle, downloads + only via --from-release (#2507) (#2514) + * docs(cli): improve report protection help and examples (#2510) + * feat(mcp): Add headless OPAProcessor for low-latency Network + Policy s… (#2512) + * Fix/helm templates plain yaml warnings (#2509) + * docs(cli): document report protection workflow (#2508) + * feat(printer): add GitLab SAST report output format (#2505) + * fix(mcp): add double-checked mutex locking to k8sClient lazy + init (#2506) + * Cache compiled CEL programs across scanned objects (#2503) + * feat(mcp): implement headless OPAProcessor rbac scanner (#2492) + * fix(sarif): don't os.Exit on unencodable fix, avoid empty SARIF + file (#2499) + * fix(printer): don't append .txt to /dev/null in + PrettyPrinter.SetWriter (#2502) + * feat(reportcrypto): add decryption support for encrypted + resource metadata (#2493) + * docs: add ICS/OT workload scanning guide (#2475) + * fix(sarif): surface PrettyWrite errors instead of silently + writing empty file (#2497) + * fix: preserve explicit exceptions/inputs with + use-artifacts-from (#2490) + * feat: implement AWS ECR vulnerability adaptor (#2488) + * add unit tests for GetPreReqCmd and kubeconfig flag (#2486) + * Derive cmd/vap policy metadata from the embedded VAP bundle + (#2485) + * fix(httphandler): populate report in synchronous scan response + (#2483) + * feat: introduce Container Image Vulnerability (CIV) Adaptor + interfaces (#2482) + * Embed and load VAP YAML from the vendored bundle (#2474) + * feat(anonymizer): support reversible container metadata + transformation (#2473) + * refactor: decompose monolithic Results API handler (#2477) + * feat: add container profile tools and resources to MCP server + (#2479) + * [ LFX 2026] feat(exceptions): honor + objectSelector.matchExpressions via + PostureExceptionPolicy.ObjectSelector (#2480) + * feat(patch): add support for OCI and Local exports (#2471) + * test(core): cover Kubescape.Download unknown-target error path + (#2468) + * Fix local control cache (#2463) + * core: Add test coverage for Kubescape.Diff pretty-printer + output path (#2467) + * fix(httphandler): add missing panic recovery to Metrics handler + (#2465) + * feat(operator): add quarantine action to remediate CLI + subcommand (#2461) + * fix: support namespace/kind/name workload format (#2459) + (#2460) + * Fix air-gapped mode -- thread explicit offline flag to policy + getters instead of relying on nil (#2458) + * Vendor the CEL admission policy bundle (#2455) + * Expand encryption and decryption coverage for resource metadata + (#2442) + * fix(httphandler): decouple prometheus metrics scan from request + context (#2451) + +------------------------------------------------------------------- Old: ---- kubescape-4.0.10.obscpio New: ---- kubescape-4.0.11.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ kubescape.spec ++++++ --- /var/tmp/diff_new_pack.5P7G4s/_old 2026-07-23 23:13:53.119739987 +0200 +++ /var/tmp/diff_new_pack.5P7G4s/_new 2026-07-23 23:13:53.123740128 +0200 @@ -17,7 +17,7 @@ Name: kubescape -Version: 4.0.10 +Version: 4.0.11 Release: 0 Summary: Tool providing a multi-cloud K8s single pane of glass License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.5P7G4s/_old 2026-07-23 23:13:53.159741394 +0200 +++ /var/tmp/diff_new_pack.5P7G4s/_new 2026-07-23 23:13:53.167741675 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/armosec/kubescape.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/v4.0.10</param> + <param name="revision">refs/tags/v4.0.11</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">enable</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.5P7G4s/_old 2026-07-23 23:13:53.195742660 +0200 +++ /var/tmp/diff_new_pack.5P7G4s/_new 2026-07-23 23:13:53.199742800 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/armosec/kubescape</param> <param name="changesrevision">002e791cd39fed51dd4a86b321c6d184fa672349</param></service><service name="tar_scm"> <param name="url">https://github.com/armosec/kubescape.git</param> - <param name="changesrevision">f956507357091c3806777fe13ddf5e65efe36e44</param></service></servicedata> + <param name="changesrevision">8fb2eb1db185637c5ea5365dd4c05bea4f165741</param></service></servicedata> (No newline at EOF) ++++++ kubescape-4.0.10.obscpio -> kubescape-4.0.11.obscpio ++++++ ++++ 16273 lines of diff (skipped) ++++++ kubescape.obsinfo ++++++ --- /var/tmp/diff_new_pack.5P7G4s/_old 2026-07-23 23:13:56.995876293 +0200 +++ /var/tmp/diff_new_pack.5P7G4s/_new 2026-07-23 23:13:57.007876715 +0200 @@ -1,5 +1,5 @@ name: kubescape -version: 4.0.10 -mtime: 1782713468 -commit: f956507357091c3806777fe13ddf5e65efe36e44 +version: 4.0.11 +mtime: 1784729633 +commit: 8fb2eb1db185637c5ea5365dd4c05bea4f165741 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/kubescape/vendor.tar.gz /work/SRC/openSUSE:Factory/.kubescape.new.2004/vendor.tar.gz differ: char 128, line 2
