Skip to content

Releases: rancher/security-scan

v0.2.17-rc3

30 Jul 15:30
5fc81eb
Compare
Choose a tag to compare
v0.2.17-rc3 Pre-release
Pre-release

What's Changed

  • chore(deps): update dependency kubernetes-sigs/kind to v0.23.0 by @renovate-rancher in #209
  • chore(deps): update module github.com/aquasecurity/kube-bench to v0.7.3 by @renovate-rancher in #189
  • chore(deps): update module github.com/spf13/viper to v1.19.0 by @renovate-rancher in #210
  • Update bci-micro version by @krunalhinguu in #213
  • chore(deps): update module github.com/aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #215
  • chore(deps): update dependency aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #214
  • Modify Ensure that the API Server only makes use of Strong Cryptographic Ciphers by @andypitcher in #216
  • kubectl version bump to v1.28.12 by @krunalhinguu in #222
  • chore(deps): update module github.com/urfave/cli/v2 to v2.27.3 by @renovate-rancher in #223
  • K3s etcd check fix by @bvankampen in #218
  • Use variables instead of hardcoded values when possible in RKE2 CIS by @dereknola in #217
  • Transition from GH secrets to Vault by @pjbgf in #220

New Contributors

Full Changelog: v0.2.15...v0.2.17-rc3

v0.2.17-rc2

30 Jul 15:28
5fc81eb
Compare
Choose a tag to compare
v0.2.17-rc2 Pre-release
Pre-release

What's Changed

  • chore(deps): update dependency kubernetes-sigs/kind to v0.23.0 by @renovate-rancher in #209
  • chore(deps): update module github.com/aquasecurity/kube-bench to v0.7.3 by @renovate-rancher in #189
  • chore(deps): update module github.com/spf13/viper to v1.19.0 by @renovate-rancher in #210
  • Update bci-micro version by @krunalhinguu in #213
  • chore(deps): update module github.com/aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #215
  • chore(deps): update dependency aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #214
  • Modify Ensure that the API Server only makes use of Strong Cryptographic Ciphers by @andypitcher in #216
  • kubectl version bump to v1.28.12 by @krunalhinguu in #222
  • chore(deps): update module github.com/urfave/cli/v2 to v2.27.3 by @renovate-rancher in #223
  • K3s etcd check fix by @bvankampen in #218
  • Use variables instead of hardcoded values when possible in RKE2 CIS by @dereknola in #217
  • Transition from GH secrets to Vault by @pjbgf in #220

New Contributors

Full Changelog: v0.2.15...v0.2.17-rc2

v0.2.17-rc1

30 Jul 15:25
5fc81eb
Compare
Choose a tag to compare
v0.2.17-rc1 Pre-release
Pre-release

What's Changed

  • chore(deps): update dependency kubernetes-sigs/kind to v0.23.0 by @renovate-rancher in #209
  • chore(deps): update module github.com/aquasecurity/kube-bench to v0.7.3 by @renovate-rancher in #189
  • chore(deps): update module github.com/spf13/viper to v1.19.0 by @renovate-rancher in #210
  • Update bci-micro version by @krunalhinguu in #213
  • chore(deps): update module github.com/aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #215
  • chore(deps): update dependency aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #214
  • Modify Ensure that the API Server only makes use of Strong Cryptographic Ciphers by @andypitcher in #216
  • kubectl version bump to v1.28.12 by @krunalhinguu in #222
  • chore(deps): update module github.com/urfave/cli/v2 to v2.27.3 by @renovate-rancher in #223
  • K3s etcd check fix by @bvankampen in #218
  • Use variables instead of hardcoded values when possible in RKE2 CIS by @dereknola in #217
  • Transition from GH secrets to Vault by @pjbgf in #220

New Contributors

Full Changelog: v0.2.15...v0.2.17-rc1

v0.2.16

20 Aug 04:45
ddf7c13
Compare
Choose a tag to compare

What's Changed

  • chore(deps): update dependency kubernetes-sigs/kind to v0.23.0 by @renovate-rancher in #209
  • chore(deps): update module github.com/aquasecurity/kube-bench to v0.7.3 by @renovate-rancher in #189
  • chore(deps): update module github.com/spf13/viper to v1.19.0 by @renovate-rancher in #210
  • Update bci-micro version by @krunalhinguu in #213

Full Changelog: v0.2.15...v0.2.16

v0.2.15

03 May 06:14
7272aac
Compare
Choose a tag to compare

What's Changed

  • Bumped kubectl to v1.28.7 by @chiukapoor in #200
  • Enable auto-bump for kube-bench and sonobuoy by @pjbgf in #199
  • Auto-source KUBECTL digest by @pjbgf in #205
  • Fix audit and remediation for K3s master 1.1.20/1.1.21 by @andypitcher in #206
  • Removed support for versions prior to K8s 1.23 by @chiukapoor in #201
  • chore(deps): update dependency kubernetes-sigs/kind to v0.22.0 by @renovate-rancher in #204
  • chore(deps): update dependency vmware-tanzu/sonobuoy to v0.57.1 by @renovate-rancher in #203
  • k3s profiles: fix remediation for 1.1.20 and 1.1.21 checks by @vardhaman22 in #207
  • chore(deps): update module github.com/urfave/cli/v2 to v2.27.2 by @renovate-rancher in #208

New Contributors

Full Changelog: v0.2.14...v0.2.15

v0.2.15-rc2

30 Apr 14:24
c34215b
Compare
Choose a tag to compare
v0.2.15-rc2 Pre-release
Pre-release

What's Changed

  • Auto-source KUBECTL digest by @pjbgf in #205
  • Fix audit and remediation for K3s master 1.1.20/1.1.21 by @andypitcher in #206
  • Removed support for versions prior to K8s 1.23 by @chiukapoor in #201
  • chore(deps): update dependency kubernetes-sigs/kind to v0.22.0 by @renovate-rancher in #204
  • chore(deps): update dependency vmware-tanzu/sonobuoy to v0.57.1 by @renovate-rancher in #203
  • k3s profiles: fix remediation for 1.1.20 and 1.1.21 checks by @vardhaman22 in #207

Full Changelog: v0.2.15-rc1...v0.2.15-rc2

v0.2.15-rc1

05 Apr 12:50
25af374
Compare
Choose a tag to compare
v0.2.15-rc1 Pre-release
Pre-release

What's Changed

New Contributors

Full Changelog: v0.2.14...v0.2.15-rc1

v0.2.14

21 Mar 04:32
0e09e07
Compare
Choose a tag to compare

What's Changed

  • Add CODEOWNERS by @macedogm in #168
  • Use dl.k8s.io for getting kubectl by @rancher-security-bot in #170
  • Add EKS 1.2.0 Benchmark and Bump kube-bench, sonobuoy by @rayandas in #171
  • Dockerfile multistage with bci-micro by @andypitcher in #166
  • Improve k3s journactl scripts by @andypitcher in #167
  • Add yamllint to script/validate to test cfg's yaml files by @andypitcher in #172
  • Add kube-bench dry run to script/validate by @andypitcher in #173
  • Update registry.suse.com/bci/golang Docker tag to v1.20 by @renovate-rancher in #164
  • Bump Go to 1.21 by @pjbgf in #175
  • Dependency bumps by @pjbgf in #176
  • chore(deps): update module github.com/urfave/cli/v2 to v2.27.0 by @renovate-rancher in #182
  • Add CIS-1.8 for RKE, RKE2 and K3s by @rayandas in #179
  • updated incorrect CIS controls Ids and version mapping by @KiranBodipi in #174
  • fix version value in configuration files by @vardhaman22 in #183
  • fix k3s scan profiles by @vardhaman22 in #184
  • fix k3s tests for k3s-cis-1.23-profile by @vardhaman22 in #186
  • bumped viper and kube-bench deps by @vardhaman22 in #188
  • Refactoring build and test logic by @pjbgf in #185
  • build: Remove use of --gpg-auto-import-keys by @pjbgf in #190
  • chore(deps): update registry.suse.com/bci/golang docker tag to v1.22 by @renovate-rancher in #193
  • chore(deps): update module github.com/urfave/cli/v2 to v2.27.1 by @renovate-rancher in #192
  • fix 4.1.7 test case for k3s-cis-1.23-permissive profile by @vardhaman22 in #191
  • added non-interactive option for zypper refresh command by @vardhaman22 in #194
  • Run image build for all target architectures as part of CI by @pjbgf in #195
  • fixed 4.1.7 test case audit command for k3s profiles by @vardhaman22 in #196
  • build: Remove cross emulation for zypper by @pjbgf in #197
  • bumped kubectl to 1.28.3 by @vardhaman22 in #198

New Contributors

Full Changelog: v0.2.13...v0.2.14

v0.2.14-rc6

01 Feb 16:26
bfeebc5
Compare
Choose a tag to compare
v0.2.14-rc6 Pre-release
Pre-release

What's Changed

  • Refactoring build and test logic by @pjbgf in #185

Full Changelog: v0.2.14-rc5...v0.2.14-rc6

v0.2.14-rc5

15 Jan 12:54
b5e706b
Compare
Choose a tag to compare
v0.2.14-rc5 Pre-release
Pre-release

What's Changed

Full Changelog: v0.2.14-rc4...v0.2.14-rc5