Releases: rancher/security-scan
Releases · rancher/security-scan
v0.2.17-rc3
What's Changed
- chore(deps): update dependency kubernetes-sigs/kind to v0.23.0 by @renovate-rancher in #209
- chore(deps): update module github.com/aquasecurity/kube-bench to v0.7.3 by @renovate-rancher in #189
- chore(deps): update module github.com/spf13/viper to v1.19.0 by @renovate-rancher in #210
- Update bci-micro version by @krunalhinguu in #213
- chore(deps): update module github.com/aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #215
- chore(deps): update dependency aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #214
- Modify
Ensure that the API Server only makes use of Strong Cryptographic Ciphers
by @andypitcher in #216 - kubectl version bump to v1.28.12 by @krunalhinguu in #222
- chore(deps): update module github.com/urfave/cli/v2 to v2.27.3 by @renovate-rancher in #223
- K3s etcd check fix by @bvankampen in #218
- Use variables instead of hardcoded values when possible in RKE2 CIS by @dereknola in #217
- Transition from GH secrets to Vault by @pjbgf in #220
New Contributors
- @krunalhinguu made their first contribution in #213
- @bvankampen made their first contribution in #218
Full Changelog: v0.2.15...v0.2.17-rc3
v0.2.17-rc2
What's Changed
- chore(deps): update dependency kubernetes-sigs/kind to v0.23.0 by @renovate-rancher in #209
- chore(deps): update module github.com/aquasecurity/kube-bench to v0.7.3 by @renovate-rancher in #189
- chore(deps): update module github.com/spf13/viper to v1.19.0 by @renovate-rancher in #210
- Update bci-micro version by @krunalhinguu in #213
- chore(deps): update module github.com/aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #215
- chore(deps): update dependency aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #214
- Modify
Ensure that the API Server only makes use of Strong Cryptographic Ciphers
by @andypitcher in #216 - kubectl version bump to v1.28.12 by @krunalhinguu in #222
- chore(deps): update module github.com/urfave/cli/v2 to v2.27.3 by @renovate-rancher in #223
- K3s etcd check fix by @bvankampen in #218
- Use variables instead of hardcoded values when possible in RKE2 CIS by @dereknola in #217
- Transition from GH secrets to Vault by @pjbgf in #220
New Contributors
- @krunalhinguu made their first contribution in #213
- @bvankampen made their first contribution in #218
Full Changelog: v0.2.15...v0.2.17-rc2
v0.2.17-rc1
What's Changed
- chore(deps): update dependency kubernetes-sigs/kind to v0.23.0 by @renovate-rancher in #209
- chore(deps): update module github.com/aquasecurity/kube-bench to v0.7.3 by @renovate-rancher in #189
- chore(deps): update module github.com/spf13/viper to v1.19.0 by @renovate-rancher in #210
- Update bci-micro version by @krunalhinguu in #213
- chore(deps): update module github.com/aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #215
- chore(deps): update dependency aquasecurity/kube-bench to v0.8.0 by @renovate-rancher in #214
- Modify
Ensure that the API Server only makes use of Strong Cryptographic Ciphers
by @andypitcher in #216 - kubectl version bump to v1.28.12 by @krunalhinguu in #222
- chore(deps): update module github.com/urfave/cli/v2 to v2.27.3 by @renovate-rancher in #223
- K3s etcd check fix by @bvankampen in #218
- Use variables instead of hardcoded values when possible in RKE2 CIS by @dereknola in #217
- Transition from GH secrets to Vault by @pjbgf in #220
New Contributors
- @krunalhinguu made their first contribution in #213
- @bvankampen made their first contribution in #218
Full Changelog: v0.2.15...v0.2.17-rc1
v0.2.16
What's Changed
- chore(deps): update dependency kubernetes-sigs/kind to v0.23.0 by @renovate-rancher in #209
- chore(deps): update module github.com/aquasecurity/kube-bench to v0.7.3 by @renovate-rancher in #189
- chore(deps): update module github.com/spf13/viper to v1.19.0 by @renovate-rancher in #210
- Update bci-micro version by @krunalhinguu in #213
Full Changelog: v0.2.15...v0.2.16
v0.2.15
What's Changed
- Bumped kubectl to v1.28.7 by @chiukapoor in #200
- Enable auto-bump for kube-bench and sonobuoy by @pjbgf in #199
- Auto-source KUBECTL digest by @pjbgf in #205
- Fix audit and remediation for K3s master 1.1.20/1.1.21 by @andypitcher in #206
- Removed support for versions prior to K8s 1.23 by @chiukapoor in #201
- chore(deps): update dependency kubernetes-sigs/kind to v0.22.0 by @renovate-rancher in #204
- chore(deps): update dependency vmware-tanzu/sonobuoy to v0.57.1 by @renovate-rancher in #203
- k3s profiles: fix remediation for 1.1.20 and 1.1.21 checks by @vardhaman22 in #207
- chore(deps): update module github.com/urfave/cli/v2 to v2.27.2 by @renovate-rancher in #208
New Contributors
- @chiukapoor made their first contribution in #200
Full Changelog: v0.2.14...v0.2.15
v0.2.15-rc2
What's Changed
- Auto-source KUBECTL digest by @pjbgf in #205
- Fix audit and remediation for K3s master 1.1.20/1.1.21 by @andypitcher in #206
- Removed support for versions prior to K8s 1.23 by @chiukapoor in #201
- chore(deps): update dependency kubernetes-sigs/kind to v0.22.0 by @renovate-rancher in #204
- chore(deps): update dependency vmware-tanzu/sonobuoy to v0.57.1 by @renovate-rancher in #203
- k3s profiles: fix remediation for 1.1.20 and 1.1.21 checks by @vardhaman22 in #207
Full Changelog: v0.2.15-rc1...v0.2.15-rc2
v0.2.15-rc1
What's Changed
- Bumped kubectl to v1.28.7 by @chiukapoor in #200
- Enable auto-bump for kube-bench and sonobuoy by @pjbgf in #199
New Contributors
- @chiukapoor made their first contribution in #200
Full Changelog: v0.2.14...v0.2.15-rc1
v0.2.14
What's Changed
- Add CODEOWNERS by @macedogm in #168
- Use dl.k8s.io for getting kubectl by @rancher-security-bot in #170
- Add EKS 1.2.0 Benchmark and Bump kube-bench, sonobuoy by @rayandas in #171
- Dockerfile multistage with bci-micro by @andypitcher in #166
- Improve k3s journactl scripts by @andypitcher in #167
- Add yamllint to script/validate to test cfg's yaml files by @andypitcher in #172
- Add kube-bench dry run to script/validate by @andypitcher in #173
- Update registry.suse.com/bci/golang Docker tag to v1.20 by @renovate-rancher in #164
- Bump Go to 1.21 by @pjbgf in #175
- Dependency bumps by @pjbgf in #176
- chore(deps): update module github.com/urfave/cli/v2 to v2.27.0 by @renovate-rancher in #182
- Add CIS-1.8 for RKE, RKE2 and K3s by @rayandas in #179
- updated incorrect CIS controls Ids and version mapping by @KiranBodipi in #174
- fix version value in configuration files by @vardhaman22 in #183
- fix k3s scan profiles by @vardhaman22 in #184
- fix k3s tests for k3s-cis-1.23-profile by @vardhaman22 in #186
- bumped viper and kube-bench deps by @vardhaman22 in #188
- Refactoring build and test logic by @pjbgf in #185
- build: Remove use of
--gpg-auto-import-keys
by @pjbgf in #190 - chore(deps): update registry.suse.com/bci/golang docker tag to v1.22 by @renovate-rancher in #193
- chore(deps): update module github.com/urfave/cli/v2 to v2.27.1 by @renovate-rancher in #192
- fix 4.1.7 test case for k3s-cis-1.23-permissive profile by @vardhaman22 in #191
- added non-interactive option for zypper refresh command by @vardhaman22 in #194
- Run image build for all target architectures as part of CI by @pjbgf in #195
- fixed 4.1.7 test case audit command for k3s profiles by @vardhaman22 in #196
- build: Remove cross emulation for zypper by @pjbgf in #197
- bumped kubectl to 1.28.3 by @vardhaman22 in #198
New Contributors
- @rancher-security-bot made their first contribution in #170
- @KiranBodipi made their first contribution in #174
Full Changelog: v0.2.13...v0.2.14
v0.2.14-rc6
What's Changed
Full Changelog: v0.2.14-rc5...v0.2.14-rc6
v0.2.14-rc5
What's Changed
- fix k3s scan profiles by @vardhaman22 in #184
- fix k3s tests for k3s-cis-1.23-profile by @vardhaman22 in #186
- bumped viper and kube-bench deps by @vardhaman22 in #188
Full Changelog: v0.2.14-rc4...v0.2.14-rc5