Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package kubescape for openSUSE:Factory 
checked in at 2026-09-21 12:06:56
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/kubescape (Old)
 and      /work/SRC/openSUSE:Factory/.kubescape.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "kubescape"

Mon Sep 21 12:06:56 2026 rev:47 rq:1379151 version:4.0.14

Changes:
--------
--- /work/SRC/openSUSE:Factory/kubescape/kubescape.changes      2026-08-13 
13:16:46.687883976 +0200
+++ /work/SRC/openSUSE:Factory/.kubescape.new.383539/kubescape.changes  
2026-09-21 12:07:23.788605214 +0200
@@ -1,0 +2,810 @@
+Sat Sep 19 09:12:30 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- Update to version 4.0.14:
+  * fix(opaprocessor): fix AllResources data race in
+    celParamObjectFinder (#3787)
+  * feat(fleet): add cross-cluster control matrix and fleet report
+    types (#3774)
+  * fix(printer): route SARIF, GitLab-SAST, HTML, and CSV fix-path
+    values through --show-secrets redaction (#3759)
+  * feat(mcpserver): introduce structured machine-readable error
+    responses (#3776)
+  * fix(httphandler): gracefully shut down HTTP server and scan
+    worker (#3769)
+  * fix(printer): honor --show-evidence in control and resource
+    views (#3775)
+  * chore: remove unused 1.png (#3772)
+  * test(cel): check the vendored bundle against the digests pinned
+    in the Makefile (#3742)
+  * fix(fix): warn when --output-dir is ignored for file-based
+    reports (#3767)
+  * ci: bump go.opentelemetry.io/otel/exporters/otlp/otlptrace
+    (#3762)
+  * ci: bump github.com/quay/claircore from 1.5.35 to 1.5.54
+    (#3764)
+  * ci: bump github.com/armosec/armoapi-go from 0.0.757 to 0.0.760
+    (#3766)
+  * ci: bump google.golang.org/api from 0.280.0 to 0.297.0 (#3761)
+  * fix(policyhandler): route mixed Framework/Control scan
+    identifiers by their own kind (#3768)
+  * feat(rules): add host-users-root-workload-v1 rule prototype
+    (#3754)
+  * ci: bump Codium-ai/pr-agent from 0.44.0 to 0.45.0 (#3765)
+  * ci: bump k8s.io/apimachinery from 0.36.2 to 0.37.0 (#3709)
+  * fix(diff): do not print usage when --fail-on-new fails (#3756)
+  * fix(scan): normalize kind case and support short names in
+    workload scan (#3730)
+  * fix(printer): generalize evidence redaction beyond
+    Secret-kind-only (#3752)
+  * fix(exposure): model GRPCRoute exposure paths with v1beta1
+    fallback (#3728)
+  * ci: bump docker/setup-qemu-action from 4.2.0 to 4.3.0 (#3750)
+  * chore(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0
+    (#3746)
+  * ci: bump Codium-ai/pr-agent from 0.43.0 to 0.44.0 (#3749)
+  * chore(deps): bump github.com/mark3labs/mcp-go from 0.58.0 to
+    1.0.0 (#3747)
+  * ci: bump helm/kind-action from 1.14.0 to 1.15.0 (#3751)
+  * chore(deps): bump helm.sh/helm/v3 from 3.20.2 to 3.21.4 (#3748)
+  * fix(mcpserver): return explicit error for unsupported
+    resource_kind in scan_resource_slice (#3740)
+  * fix(git): use hex encoding for hashRepoURL instead of raw bytes
+    (#3720)
+  * fix(rbacgraph): order escalation results instead of reading map
+    order (#3739)
+  * docs: point ARMO guide at verified installer, drop stale copies
+    (#3731)
+  * fix(resourcehandler): retrieve single workload via Get instead
+    of List (#3722)
+  * fix(resultshandling): rebuild namespace rollup after severity
+    filtering (#3726)
+  * fix: do not print scan usage when --severity-threshold fails
+    (#3716) (#3717)
+  * feat(rules): detect Azure AKS Workload Identity in
+    provider-iam-assumption-v1 (#3724)
+  * feat(scan): extend --kube-contexts fleet mode to
+    framework/control/workload (#3440)
+  * feat(list): add --framework and --search filters to list
+    controls (#3623) (#3718)
+  * ci: bump sigstore/cosign-installer from 3.5.0 to 3.10.1
+  * chore(deps): fix Dependabot security vulnerabilities in Go
+    dependencies (#3715)
+  * feat(fix): select which controls to remediate with
+    --include-controls and --skip-controls (#3714)
+  * test: add vulnerability identity and deduplication test
+    coverage (#3653)
+  * fix(printer): include the scanned platform in GitLab finding
+    ids (#3713)
+  * chore(deps): bump github.com/aws/aws-sdk-go-v2 from 1.43.7 to
+    1.45.1 (#3711)
+  * chore(deps): bump github.com/mattn/go-isatty from 0.0.21 to
+    0.0.24 (#3710)
+  * Add URL context to repository scanner error messages (#3650)
+  * ci: bump mikepenz/action-junit-report from 6.4.2 to 6.5.0
+    (#3708)
+  * feat(scan): add per-namespace compliance rollup (#3704)
+  * feat(rbacgraph): model multi-hop RBAC privilege-escalation
+    paths (#3681)
+  * feat(scan): wire up sequential multi-cluster scanning via
+    --kube-contexts (#3438)
+  * feat(exposure): model spec.externalIPs, flag unconfirmed
+    cross-namespace backendRef as unclear (#3679)
+  * chore(deps): bump google.golang.org/protobuf (#3690)
+  * chore(deps): bump github.com/maruel/natural from 1.1.1 to 1.3.0
+    (#3696)
+  * refactor: consolidate httphandler into root Go module (#3706)
+  * chore(deps): bump github.com/go-openapi/runtime in /httphandler
+    (#3685)
+  * chore(deps): bump github.com/kubescape/backend in /httphandler
+    (#3684)
+  * fix(ci): prevent shell injection in tag-action composite action
+    (#3700)
+  * feat(fix): support cluster scan reports by printing patched
+    manifests (#3705)
+  * ci: bump anchore/sbom-action/download-syft from 0.24.0 to
+    0.24.2 (#3689)
+  * fix(score): route dead telemetry scorer output to
+    logger.L().Debug (#3702)
+  * ci: bump github/codeql-action/upload-sarif from 4.37.7 to
+    4.37.9 (#3691)
+  * ci: bump actions/setup-python from 5.6.0 to 7.0.0 (#3688)
+  * feat(scan): emit CycloneDX and SPDX SBOMs from posture scans
+    with --scan-images (#3698)
+  * chore(deps): bump github.com/mark3labs/mcp-go from 0.57.0 to
+    0.58.0 (#3692)
+  * chore(deps): bump k8s.io/apimachinery in /httphandler (#3687)
+  * chore(deps): bump github.com/armosec/armoapi-go in /httphandler
+    (#3686)
+  * chore(deps): bump github.com/kubescape/go-logger from 0.0.28 to
+    0.0.34 (#3695)
+  * ci: bump golangci/golangci-lint-action from 9.2.0 to 9.3.0
+    (#3693)
+  * fix(getter): give custom rules a base score instead of leaving
+    it zero (#3676)
+  * feat(printer): include evidence paths in GitHub Actions
+    annotation messages (#3677)
+  * feat(printer): surface failed-path evidence values in JSON/YAML
+    output (#3256)
+  * fix(core): ensure OpenTelemetry spans are ended across all exit
+    and error paths (#3665)
+  * perf: stream JSON outputs instead of massive byte array
+    allocations in memory (#3670)
+  * feat(vap): list embedded admission policies and the controls
+    they implement (#3674)
+  * feat(resourcehandler): collect via namespaced endpoints under
+    --include-namespaces (#3683)
+  * feat(scan): scan multiple images in one run sharing the
+    vulnerability database (#3682)
+  * feat(exposure): model external exposure via Ingress, Gateway
+    API, and Service type (#3648)
+- Update to version 4.0.13:
+  * test(resourcehandler): add a synthetic-cluster collector memory
+    harness (#3614)
+  * test(cel): compare Rego and CEL verdicts for the converted
+    controls (#3603)
+  * feat(scan): record contract runner input digests (#3640)
+  * fix(opaprocessor): match CIS section numbers in
+    --skip-controls/--include-controls (#3658)
+  * feat(scan): send Microsoft Teams Adaptive Card notifications
+    for --notify webhooks (#3645)
+  * feat(config): add cached config validation (#3663)
+  * feat(mcpserver): add scan_workload tool for single-resource
+    scanning (#3669)
+  * fix(anonymizer): pseudonymize image-scan results under
+    --hide/--encrypt (#3661)
+  * fix(cel): honor an equivalent matchPolicy when scoping a policy
+    to a scanned object (#3673)
+  * fix(download): accept plural and alias target arguments (#3666)
+    (#3667)
+  * fix(mapreconcile): a policy gated by matchConditions is not a
+    confirmed match (#3654)
+  * fix(resourcesprioritization): don't drop attack tracks when a
+    resource matches more than one (#3659)
+  * fix(fixhandler): cross-control fix promotion checks the value,
+    not just the path (#3634)
+  * feat(networkpolicy,vulnexposure): correlate vulnerabilities
+    with NetworkPolicy exposure (#3632)
+  * fix(scancache): reset dirty flag after Flush writes cache file
+    (#3515)
+  * feat(config): support --format / -f flag in config view (#3641)
+    (#3642)
+  * fix(mapreconcile): match the subresource form of a resource
+    rule (#3646)
+  * feat(sarif): add stable scan fingerprints (#3639)
+  * feat(printer): add github-actions output format for inline PR
+    annotations (#3637)
+  * feat(scan): add SARIF contract validation output (#3622)
+  * fix(opaprocessor): evaluate rules against full input after
+    enumeration (#3628)
+  * feat(policy): scaffold custom Rego rules and refresh test
+    fixtures from rule output (#3635)
+  * feat(diff): add aggregate summary outputs (#3626)
+  * refactor: migrate gorilla/mux to net/http ServeMux (#3620)
+  * feat(telemetry): report image DB freshness (#3604)
+  * fix(anonymizer): anonymize Secret/ConfigMap names referenced
+    via spec.volumes (#3619)
+  * feat(list): filter controls by framework and search (#3624)
+  * fix(cel): evaluate every matchCondition, not just up to the
+    first false (#3630)
+  * feat: support --format json for the update command (#3617)
+  * feat(scan): add contract report provenance (#3607)
+  * feat(mapreconcile): add MutatingAdmissionPolicy discovery and
+    impact matching (#3606)
+  * fix: validate URLs in config set (#3585)
+  * refactor(resourcehandler): partition streaming collector items
+    as the pager yields them (#3613)
+  * fix(anonymizer): hide scan path, host and cluster identity
+    under --hide and --encrypt (#3611)
+  * fix(scan): enforce compliance-threshold in scan workload
+    (#3610) (#3612)
+  * feat(fixhandler): apply fixes to JSON manifests (#3608)
+  * fix(resourcehandler): do not report a kind's other served
+    versions as unexamined (#3609)
+  * [LFX 2026] chore(deps): bump opa-utils to v0.0.312 for
+    alertOnly exception semantics (#3615)
+  * feat(networkpolicy): add real NetworkPolicy reachability engine
+    (#3601)
+  * fix(vap): report a namespace selector that cannot narrow a
+    policy's cluster-scoped resources (#3597)
+  * refactor: remove deprecated FailedPath from codebase (#3598)
+  * fix: deduplicate included namespaces in splitNamespaces (#3599)
+  * feat(coverage): report resource kinds no control examined
+    (#3588)
+  * feat(cel): honor VAP spec.failurePolicy for validation
+    expression errors (#3583)
+  * feat(containerscan): validate layers, layer hashes, and
+    vulnerability names in `ScanResultReport.Validate()` (#3591)
+  * test(printer): add regression test for sensitive data exposure
+    in res… (#3582)
+  * fix(vapreconcile): correct binding-scope coverage for
+    cluster-scoped resources and Namespaces (#3592)
+  * fix(patch): filesystem-safe intermediate filenames and
+    update-all nil guard (#3596)
+  * fix(resultshandling): deterministic AssociatedControls ordering
+    across scans (#3590)
+  * feat(image): surface VEX status in reports (#3594)
+  * feat(list): show the control configuration a scan evaluates
+    against (#3586)
+  * fix(fixhandler): check the error from closing a fixed file, not
+    just writing it (#3580)
+  * feat(scan): add Slack webhook notifications (#3571)
+  * fix(anonymizer): restore reference-backed env var name
+    anonymization (#3579)
+  * feat(version): add yaml output format support (#3542) (#3543)
+  * feat(printer): support initContainers and ephemeralContainers
+    in assisted remediation paths (#3578)
+  * fix(cel): resolve a cluster-scoped paramRef, and refuse one
+    that selects params (#3575)
+  * feat(printer): generate a posture exceptions baseline from scan
+    results (#3560)
+  * feat(markdown): support image scan reports (#3573)
+  * fix(mcpserver): prefer ScanCoverage over the seeded summary
+    when flagging unevaluated controls (#3574)
+  * feat(mcpserver): add apply_remediation tool for deterministic
+    AI auto-patching (#3568)
+  * chore(cel): bump the pinned CEL policy library to v0.14 and
+    sync the bundle (#3556)
+  * fix(hostsensorutils): record a status when reported CRD items
+    cannot be read (#3561)
+  * fix(opaprocessor): guard InfoMap read against concurrent writes
+    in hasUnreachableDependency (#3563)
+  * fix(imagescan): bound GCP GetImagesScanStatus pagination loop
+    (#3566)
+  * feat(vapreconcile): add per-resource VAPBinding scope coverage
+    (#3570)
+  * fix(scan-coverage): surface skipped manifests in coverage and
+    fail gate (#3555)
+  * fix(opaprocessor): honor ResourceEnumerator output in scan path
+    (#3559)
+  * fix(opaprocessor): quote inline exception designator attributes
+    (#3558)
+  * chore(printer): clarify strings import dependency in
+    policyreportprinter.go (#3550)
+  * feat(getter): load custom rules from the standard rule
+    directory layout (#3553)
+  * feat(scan): apply repository scan contracts (#3537)
+  * chore(deps): bump github.com/kubescape/go-git-url from 0.0.31
+    to 0.0.33 (#3529)
+  * chore(deps): bump github.com/zclconf/go-cty from 1.17.0 to
+    1.19.0 (#3531)
+  * chore(deps): bump github.com/aws/aws-sdk-go-v2/config (#3528)
+  * chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.2.0
+    to 2.3.3 (#3523)
+  * chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.8 to
+    6.8.3 (#3530)
+  * test(policy): validate all in-tree rule fixtures in CI (#3546)
+  * test(printer): add edge case coverage for
+    AssistedRemediationPathsToString (#3548)
+  * ci: bump github.com/stretchr/testify in /httphandler (#3525)
+  * fix(storage): recover missing workload posture controls (#3545)
+  * ci: bump Codium-ai/pr-agent from 0.35.0 to 0.43.0 (#3535)
+  * chore(deps): bump github.com/kubescape/opa-utils in
+    /httphandler (#3524)
+  * fix(resourcehandler): a namespace filter naming no namespace
+    silently skips every namespaced query (#3539)
+  * fix: scope cluster size estimation to included namespaces
+    (#3538)
+  * chore(deps): bump github.com/kubescape/go-logger in
+    /httphandler (#3522)
+  * ci: bump docker/setup-buildx-action from 4.2.0 to 4.3.0 (#3534)
+  * fix(junit): distinguish image scan platforms (#3544)
+  * fix(opaprocessor): hard error when --include-controls matches
+    no known control (#3552)
+  * fix(config): make config set keys case-insensitive and accept
+    kebab-case (#3540) (#3541)
+  * chore(deps): bump github.com/armosec/armoapi-go in /httphandler
+    (#3526)
+  * fix(core): close output writers when Scan fails (#3232)
++++ 513 more lines (skipped)
++++ between /work/SRC/openSUSE:Factory/kubescape/kubescape.changes
++++ and /work/SRC/openSUSE:Factory/.kubescape.new.383539/kubescape.changes

Old:
----
  kubescape-4.0.12.obscpio

New:
----
  kubescape-4.0.14.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ kubescape.spec ++++++
--- /var/tmp/diff_new_pack.Jw0h5I/_old  2026-09-21 12:07:28.994823478 +0200
+++ /var/tmp/diff_new_pack.Jw0h5I/_new  2026-09-21 12:07:28.996823562 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           kubescape
-Version:        4.0.12
+Version:        4.0.14
 Release:        0
 Summary:        Tool providing a multi-cloud K8s single pane of glass
 License:        Apache-2.0

++++++ _service ++++++
--- /var/tmp/diff_new_pack.Jw0h5I/_old  2026-09-21 12:07:29.035825197 +0200
+++ /var/tmp/diff_new_pack.Jw0h5I/_new  2026-09-21 12:07:29.039825365 +0200
@@ -3,7 +3,7 @@
     <param name="url">https://github.com/armosec/kubescape.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="revision">refs/tags/v4.0.12</param>
+    <param name="revision">refs/tags/v4.0.14</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>
     <param name="changesgenerate">enable</param>

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.Jw0h5I/_old  2026-09-21 12:07:29.059826203 +0200
+++ /var/tmp/diff_new_pack.Jw0h5I/_new  2026-09-21 12:07:29.062826329 +0200
@@ -3,6 +3,6 @@
                 <param name="url">https://github.com/armosec/kubescape</param>
               <param 
name="changesrevision">002e791cd39fed51dd4a86b321c6d184fa672349</param></service><service
 name="tar_scm">
                 <param 
name="url">https://github.com/armosec/kubescape.git</param>
-              <param 
name="changesrevision">469969f6bebf46bef5e808b91a4bb46fb2bbf4ed</param></service></servicedata>
+              <param 
name="changesrevision">031cd40cc8de696fa30a648001853443019ec97a</param></service></servicedata>
 (No newline at EOF)
 

++++++ kubescape-4.0.12.obscpio -> kubescape-4.0.14.obscpio ++++++
++++ 143969 lines of diff (skipped)

++++++ kubescape.obsinfo ++++++
--- /var/tmp/diff_new_pack.Jw0h5I/_old  2026-09-21 12:07:31.473927411 +0200
+++ /var/tmp/diff_new_pack.Jw0h5I/_new  2026-09-21 12:07:31.480927705 +0200
@@ -1,5 +1,5 @@
 name: kubescape
-version: 4.0.12
-mtime: 1786522719
-commit: 469969f6bebf46bef5e808b91a4bb46fb2bbf4ed
+version: 4.0.14
+mtime: 1788956681
+commit: 031cd40cc8de696fa30a648001853443019ec97a
 

++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/kubescape/vendor.tar.gz 
/work/SRC/openSUSE:Factory/.kubescape.new.383539/vendor.tar.gz differ: char 83, 
line 1

Reply via email to