Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package kubescape for openSUSE:Factory checked in at 2026-09-21 12:06:56 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/kubescape (Old) and /work/SRC/openSUSE:Factory/.kubescape.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "kubescape" Mon Sep 21 12:06:56 2026 rev:47 rq:1379151 version:4.0.14 Changes: -------- --- /work/SRC/openSUSE:Factory/kubescape/kubescape.changes 2026-08-13 13:16:46.687883976 +0200 +++ /work/SRC/openSUSE:Factory/.kubescape.new.383539/kubescape.changes 2026-09-21 12:07:23.788605214 +0200 @@ -1,0 +2,810 @@ +Sat Sep 19 09:12:30 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 4.0.14: + * fix(opaprocessor): fix AllResources data race in + celParamObjectFinder (#3787) + * feat(fleet): add cross-cluster control matrix and fleet report + types (#3774) + * fix(printer): route SARIF, GitLab-SAST, HTML, and CSV fix-path + values through --show-secrets redaction (#3759) + * feat(mcpserver): introduce structured machine-readable error + responses (#3776) + * fix(httphandler): gracefully shut down HTTP server and scan + worker (#3769) + * fix(printer): honor --show-evidence in control and resource + views (#3775) + * chore: remove unused 1.png (#3772) + * test(cel): check the vendored bundle against the digests pinned + in the Makefile (#3742) + * fix(fix): warn when --output-dir is ignored for file-based + reports (#3767) + * ci: bump go.opentelemetry.io/otel/exporters/otlp/otlptrace + (#3762) + * ci: bump github.com/quay/claircore from 1.5.35 to 1.5.54 + (#3764) + * ci: bump github.com/armosec/armoapi-go from 0.0.757 to 0.0.760 + (#3766) + * ci: bump google.golang.org/api from 0.280.0 to 0.297.0 (#3761) + * fix(policyhandler): route mixed Framework/Control scan + identifiers by their own kind (#3768) + * feat(rules): add host-users-root-workload-v1 rule prototype + (#3754) + * ci: bump Codium-ai/pr-agent from 0.44.0 to 0.45.0 (#3765) + * ci: bump k8s.io/apimachinery from 0.36.2 to 0.37.0 (#3709) + * fix(diff): do not print usage when --fail-on-new fails (#3756) + * fix(scan): normalize kind case and support short names in + workload scan (#3730) + * fix(printer): generalize evidence redaction beyond + Secret-kind-only (#3752) + * fix(exposure): model GRPCRoute exposure paths with v1beta1 + fallback (#3728) + * ci: bump docker/setup-qemu-action from 4.2.0 to 4.3.0 (#3750) + * chore(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0 + (#3746) + * ci: bump Codium-ai/pr-agent from 0.43.0 to 0.44.0 (#3749) + * chore(deps): bump github.com/mark3labs/mcp-go from 0.58.0 to + 1.0.0 (#3747) + * ci: bump helm/kind-action from 1.14.0 to 1.15.0 (#3751) + * chore(deps): bump helm.sh/helm/v3 from 3.20.2 to 3.21.4 (#3748) + * fix(mcpserver): return explicit error for unsupported + resource_kind in scan_resource_slice (#3740) + * fix(git): use hex encoding for hashRepoURL instead of raw bytes + (#3720) + * fix(rbacgraph): order escalation results instead of reading map + order (#3739) + * docs: point ARMO guide at verified installer, drop stale copies + (#3731) + * fix(resourcehandler): retrieve single workload via Get instead + of List (#3722) + * fix(resultshandling): rebuild namespace rollup after severity + filtering (#3726) + * fix: do not print scan usage when --severity-threshold fails + (#3716) (#3717) + * feat(rules): detect Azure AKS Workload Identity in + provider-iam-assumption-v1 (#3724) + * feat(scan): extend --kube-contexts fleet mode to + framework/control/workload (#3440) + * feat(list): add --framework and --search filters to list + controls (#3623) (#3718) + * ci: bump sigstore/cosign-installer from 3.5.0 to 3.10.1 + * chore(deps): fix Dependabot security vulnerabilities in Go + dependencies (#3715) + * feat(fix): select which controls to remediate with + --include-controls and --skip-controls (#3714) + * test: add vulnerability identity and deduplication test + coverage (#3653) + * fix(printer): include the scanned platform in GitLab finding + ids (#3713) + * chore(deps): bump github.com/aws/aws-sdk-go-v2 from 1.43.7 to + 1.45.1 (#3711) + * chore(deps): bump github.com/mattn/go-isatty from 0.0.21 to + 0.0.24 (#3710) + * Add URL context to repository scanner error messages (#3650) + * ci: bump mikepenz/action-junit-report from 6.4.2 to 6.5.0 + (#3708) + * feat(scan): add per-namespace compliance rollup (#3704) + * feat(rbacgraph): model multi-hop RBAC privilege-escalation + paths (#3681) + * feat(scan): wire up sequential multi-cluster scanning via + --kube-contexts (#3438) + * feat(exposure): model spec.externalIPs, flag unconfirmed + cross-namespace backendRef as unclear (#3679) + * chore(deps): bump google.golang.org/protobuf (#3690) + * chore(deps): bump github.com/maruel/natural from 1.1.1 to 1.3.0 + (#3696) + * refactor: consolidate httphandler into root Go module (#3706) + * chore(deps): bump github.com/go-openapi/runtime in /httphandler + (#3685) + * chore(deps): bump github.com/kubescape/backend in /httphandler + (#3684) + * fix(ci): prevent shell injection in tag-action composite action + (#3700) + * feat(fix): support cluster scan reports by printing patched + manifests (#3705) + * ci: bump anchore/sbom-action/download-syft from 0.24.0 to + 0.24.2 (#3689) + * fix(score): route dead telemetry scorer output to + logger.L().Debug (#3702) + * ci: bump github/codeql-action/upload-sarif from 4.37.7 to + 4.37.9 (#3691) + * ci: bump actions/setup-python from 5.6.0 to 7.0.0 (#3688) + * feat(scan): emit CycloneDX and SPDX SBOMs from posture scans + with --scan-images (#3698) + * chore(deps): bump github.com/mark3labs/mcp-go from 0.57.0 to + 0.58.0 (#3692) + * chore(deps): bump k8s.io/apimachinery in /httphandler (#3687) + * chore(deps): bump github.com/armosec/armoapi-go in /httphandler + (#3686) + * chore(deps): bump github.com/kubescape/go-logger from 0.0.28 to + 0.0.34 (#3695) + * ci: bump golangci/golangci-lint-action from 9.2.0 to 9.3.0 + (#3693) + * fix(getter): give custom rules a base score instead of leaving + it zero (#3676) + * feat(printer): include evidence paths in GitHub Actions + annotation messages (#3677) + * feat(printer): surface failed-path evidence values in JSON/YAML + output (#3256) + * fix(core): ensure OpenTelemetry spans are ended across all exit + and error paths (#3665) + * perf: stream JSON outputs instead of massive byte array + allocations in memory (#3670) + * feat(vap): list embedded admission policies and the controls + they implement (#3674) + * feat(resourcehandler): collect via namespaced endpoints under + --include-namespaces (#3683) + * feat(scan): scan multiple images in one run sharing the + vulnerability database (#3682) + * feat(exposure): model external exposure via Ingress, Gateway + API, and Service type (#3648) +- Update to version 4.0.13: + * test(resourcehandler): add a synthetic-cluster collector memory + harness (#3614) + * test(cel): compare Rego and CEL verdicts for the converted + controls (#3603) + * feat(scan): record contract runner input digests (#3640) + * fix(opaprocessor): match CIS section numbers in + --skip-controls/--include-controls (#3658) + * feat(scan): send Microsoft Teams Adaptive Card notifications + for --notify webhooks (#3645) + * feat(config): add cached config validation (#3663) + * feat(mcpserver): add scan_workload tool for single-resource + scanning (#3669) + * fix(anonymizer): pseudonymize image-scan results under + --hide/--encrypt (#3661) + * fix(cel): honor an equivalent matchPolicy when scoping a policy + to a scanned object (#3673) + * fix(download): accept plural and alias target arguments (#3666) + (#3667) + * fix(mapreconcile): a policy gated by matchConditions is not a + confirmed match (#3654) + * fix(resourcesprioritization): don't drop attack tracks when a + resource matches more than one (#3659) + * fix(fixhandler): cross-control fix promotion checks the value, + not just the path (#3634) + * feat(networkpolicy,vulnexposure): correlate vulnerabilities + with NetworkPolicy exposure (#3632) + * fix(scancache): reset dirty flag after Flush writes cache file + (#3515) + * feat(config): support --format / -f flag in config view (#3641) + (#3642) + * fix(mapreconcile): match the subresource form of a resource + rule (#3646) + * feat(sarif): add stable scan fingerprints (#3639) + * feat(printer): add github-actions output format for inline PR + annotations (#3637) + * feat(scan): add SARIF contract validation output (#3622) + * fix(opaprocessor): evaluate rules against full input after + enumeration (#3628) + * feat(policy): scaffold custom Rego rules and refresh test + fixtures from rule output (#3635) + * feat(diff): add aggregate summary outputs (#3626) + * refactor: migrate gorilla/mux to net/http ServeMux (#3620) + * feat(telemetry): report image DB freshness (#3604) + * fix(anonymizer): anonymize Secret/ConfigMap names referenced + via spec.volumes (#3619) + * feat(list): filter controls by framework and search (#3624) + * fix(cel): evaluate every matchCondition, not just up to the + first false (#3630) + * feat: support --format json for the update command (#3617) + * feat(scan): add contract report provenance (#3607) + * feat(mapreconcile): add MutatingAdmissionPolicy discovery and + impact matching (#3606) + * fix: validate URLs in config set (#3585) + * refactor(resourcehandler): partition streaming collector items + as the pager yields them (#3613) + * fix(anonymizer): hide scan path, host and cluster identity + under --hide and --encrypt (#3611) + * fix(scan): enforce compliance-threshold in scan workload + (#3610) (#3612) + * feat(fixhandler): apply fixes to JSON manifests (#3608) + * fix(resourcehandler): do not report a kind's other served + versions as unexamined (#3609) + * [LFX 2026] chore(deps): bump opa-utils to v0.0.312 for + alertOnly exception semantics (#3615) + * feat(networkpolicy): add real NetworkPolicy reachability engine + (#3601) + * fix(vap): report a namespace selector that cannot narrow a + policy's cluster-scoped resources (#3597) + * refactor: remove deprecated FailedPath from codebase (#3598) + * fix: deduplicate included namespaces in splitNamespaces (#3599) + * feat(coverage): report resource kinds no control examined + (#3588) + * feat(cel): honor VAP spec.failurePolicy for validation + expression errors (#3583) + * feat(containerscan): validate layers, layer hashes, and + vulnerability names in `ScanResultReport.Validate()` (#3591) + * test(printer): add regression test for sensitive data exposure + in res… (#3582) + * fix(vapreconcile): correct binding-scope coverage for + cluster-scoped resources and Namespaces (#3592) + * fix(patch): filesystem-safe intermediate filenames and + update-all nil guard (#3596) + * fix(resultshandling): deterministic AssociatedControls ordering + across scans (#3590) + * feat(image): surface VEX status in reports (#3594) + * feat(list): show the control configuration a scan evaluates + against (#3586) + * fix(fixhandler): check the error from closing a fixed file, not + just writing it (#3580) + * feat(scan): add Slack webhook notifications (#3571) + * fix(anonymizer): restore reference-backed env var name + anonymization (#3579) + * feat(version): add yaml output format support (#3542) (#3543) + * feat(printer): support initContainers and ephemeralContainers + in assisted remediation paths (#3578) + * fix(cel): resolve a cluster-scoped paramRef, and refuse one + that selects params (#3575) + * feat(printer): generate a posture exceptions baseline from scan + results (#3560) + * feat(markdown): support image scan reports (#3573) + * fix(mcpserver): prefer ScanCoverage over the seeded summary + when flagging unevaluated controls (#3574) + * feat(mcpserver): add apply_remediation tool for deterministic + AI auto-patching (#3568) + * chore(cel): bump the pinned CEL policy library to v0.14 and + sync the bundle (#3556) + * fix(hostsensorutils): record a status when reported CRD items + cannot be read (#3561) + * fix(opaprocessor): guard InfoMap read against concurrent writes + in hasUnreachableDependency (#3563) + * fix(imagescan): bound GCP GetImagesScanStatus pagination loop + (#3566) + * feat(vapreconcile): add per-resource VAPBinding scope coverage + (#3570) + * fix(scan-coverage): surface skipped manifests in coverage and + fail gate (#3555) + * fix(opaprocessor): honor ResourceEnumerator output in scan path + (#3559) + * fix(opaprocessor): quote inline exception designator attributes + (#3558) + * chore(printer): clarify strings import dependency in + policyreportprinter.go (#3550) + * feat(getter): load custom rules from the standard rule + directory layout (#3553) + * feat(scan): apply repository scan contracts (#3537) + * chore(deps): bump github.com/kubescape/go-git-url from 0.0.31 + to 0.0.33 (#3529) + * chore(deps): bump github.com/zclconf/go-cty from 1.17.0 to + 1.19.0 (#3531) + * chore(deps): bump github.com/aws/aws-sdk-go-v2/config (#3528) + * chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.2.0 + to 2.3.3 (#3523) + * chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.8 to + 6.8.3 (#3530) + * test(policy): validate all in-tree rule fixtures in CI (#3546) + * test(printer): add edge case coverage for + AssistedRemediationPathsToString (#3548) + * ci: bump github.com/stretchr/testify in /httphandler (#3525) + * fix(storage): recover missing workload posture controls (#3545) + * ci: bump Codium-ai/pr-agent from 0.35.0 to 0.43.0 (#3535) + * chore(deps): bump github.com/kubescape/opa-utils in + /httphandler (#3524) + * fix(resourcehandler): a namespace filter naming no namespace + silently skips every namespaced query (#3539) + * fix: scope cluster size estimation to included namespaces + (#3538) + * chore(deps): bump github.com/kubescape/go-logger in + /httphandler (#3522) + * ci: bump docker/setup-buildx-action from 4.2.0 to 4.3.0 (#3534) + * fix(junit): distinguish image scan platforms (#3544) + * fix(opaprocessor): hard error when --include-controls matches + no known control (#3552) + * fix(config): make config set keys case-insensitive and accept + kebab-case (#3540) (#3541) + * chore(deps): bump github.com/armosec/armoapi-go in /httphandler + (#3526) + * fix(core): close output writers when Scan fails (#3232) ++++ 513 more lines (skipped) ++++ between /work/SRC/openSUSE:Factory/kubescape/kubescape.changes ++++ and /work/SRC/openSUSE:Factory/.kubescape.new.383539/kubescape.changes Old: ---- kubescape-4.0.12.obscpio New: ---- kubescape-4.0.14.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ kubescape.spec ++++++ --- /var/tmp/diff_new_pack.Jw0h5I/_old 2026-09-21 12:07:28.994823478 +0200 +++ /var/tmp/diff_new_pack.Jw0h5I/_new 2026-09-21 12:07:28.996823562 +0200 @@ -17,7 +17,7 @@ Name: kubescape -Version: 4.0.12 +Version: 4.0.14 Release: 0 Summary: Tool providing a multi-cloud K8s single pane of glass License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.Jw0h5I/_old 2026-09-21 12:07:29.035825197 +0200 +++ /var/tmp/diff_new_pack.Jw0h5I/_new 2026-09-21 12:07:29.039825365 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/armosec/kubescape.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/v4.0.12</param> + <param name="revision">refs/tags/v4.0.14</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">enable</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.Jw0h5I/_old 2026-09-21 12:07:29.059826203 +0200 +++ /var/tmp/diff_new_pack.Jw0h5I/_new 2026-09-21 12:07:29.062826329 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/armosec/kubescape</param> <param name="changesrevision">002e791cd39fed51dd4a86b321c6d184fa672349</param></service><service name="tar_scm"> <param name="url">https://github.com/armosec/kubescape.git</param> - <param name="changesrevision">469969f6bebf46bef5e808b91a4bb46fb2bbf4ed</param></service></servicedata> + <param name="changesrevision">031cd40cc8de696fa30a648001853443019ec97a</param></service></servicedata> (No newline at EOF) ++++++ kubescape-4.0.12.obscpio -> kubescape-4.0.14.obscpio ++++++ ++++ 143969 lines of diff (skipped) ++++++ kubescape.obsinfo ++++++ --- /var/tmp/diff_new_pack.Jw0h5I/_old 2026-09-21 12:07:31.473927411 +0200 +++ /var/tmp/diff_new_pack.Jw0h5I/_new 2026-09-21 12:07:31.480927705 +0200 @@ -1,5 +1,5 @@ name: kubescape -version: 4.0.12 -mtime: 1786522719 -commit: 469969f6bebf46bef5e808b91a4bb46fb2bbf4ed +version: 4.0.14 +mtime: 1788956681 +commit: 031cd40cc8de696fa30a648001853443019ec97a ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/kubescape/vendor.tar.gz /work/SRC/openSUSE:Factory/.kubescape.new.383539/vendor.tar.gz differ: char 83, line 1
