Skip to content

v14.2.0

Choose a tag to compare

@czunker czunker released this 29 Sep 08:30
· 464 commits to main since this release
3e4e0ed

What's Changed

  • ✨ use the operating system's proxy settings on Windows by @AdamVB in #10755
  • ⭐ os: add windows.lsa.crashOnAuditFail and relaxMinimumPasswordLengthLimits by @tas50 in #11079
  • ✨ os: parse openBSMAudit expire-after into typed age, size and retention floors by @tas50 in #11083
  • ✨ os: add windows.uac for User Account Control policy by @tas50 in #11081
  • ✨ os: add memory resource (Windows, Linux, macOS, FreeBSD, Solaris) by @tas50 in #11078
  • 🎉 os-14.4.0 by @tas50 in #11089
  • ✨ ADR-046 phase 5: Rendering + Aggregation of errors by @arlimus in #11087
  • 🐛 providers: don't let the heartbeat watchdog reap a provider after a host suspend by @vjeffrey in #11055
  • ✨ os: read memory on NetBSD by @tas50 in #11090
  • ✨ os: add windows.disks from Windows Storage Management (MSFT_Disk) by @tas50 in #11082
  • ✨ os: read mount and mount.point on Windows by @tas50 in #11080
  • ✨ os: add user.system and user.hasLoginShell by @tas50 in #11075
  • ✨ ADR46 Phase6: Baseline: return structured errors on connect by @arlimus in #11091
  • 🎉 os-14.5.0 by @tas50 in #11092
  • ✨ add a separate helper to print bits and bytes by @arlimus in #11093
  • 📃 ADR-046 Phase 6 adjustments + phase 9 addition by @arlimus in #11094
  • ✨ named permissions errors (ADR-046 Phase 7) by @arlimus in #11100
  • 📄 add missing enum values to .lr field descriptions by @tas50 in #11101
  • 🏇 don't rerun asset-level failures (ARD-046 Phase-8) by @arlimus in #11107
  • 🐛 Release archives: store the binary as root:root by @chris-rock in #11103
  • ✨ macOS apps: bundle id, signer, App Store receipt, arch and install scope, plus a Spotlight-independent fallback by @chris-rock in #11104
  • 🐛 macOS apps: keep the purl identity (host arch, display name) until consumers switch to the bundle id by @chris-rock in #11114
  • ⭐ os: detect the Microsoft Intune and Entra device identity on Windows by @chris-rock in #11111
  • ⭐ os: device IDs on mdm and mdm.intune, directory membership with directory.entra, and agent IDs on edr.product by @chris-rock in #11112
  • 🛑 os: rename the directory resource to idp, and report idp.joined as null where no identity is read by @chris-rock in #11119
  • 🐛 os: read PAM service files from /usr/lib/pam.d and /usr/etc/pam.d like PAM does by @tas50 in #11116
  • 🐛 os: chrony.conf reads /usr/etc/chrony.conf and follows include, confdir and sourcedir by @tas50 in #11117
  • 🎉 os-14.6.0 by @chris-rock in #11115
  • 🐛 os: auditd.rules applies -d and -W deletions instead of reporting them as controls by @tas50 in #11121
  • 🐛 os: yum.vars reports the custom variables defined in /etc/dnf/vars and /etc/yum/vars by @tas50 in #11120
  • 📄 document AWS region fan-out, paginator and Azure resource ID patterns by @chris-rock in #11123
  • Bump docker/setup-buildx-action from 4.3.0 to 4.4.1 by @dependabot[bot] in #11126
  • Bump the codeql-action group with 3 updates by @dependabot[bot] in #11125
  • Bump docker/setup-qemu-action from 4.3.0 to 4.4.0 by @dependabot[bot] in #11127
  • Bump alpine from 3.24.1 to 3.24.2 by @dependabot[bot] in #11124
  • Bump crate-ci/typos from 1.50.1 to 1.50.2 by @dependabot[bot] in #11128
  • ⭐ os: kernel.livepatch reports the live patches applied to the running kernel by @tas50 in #11122
  • ⭐️ edr.product: report the Microsoft Defender for Endpoint machine and org IDs by @chris-rock in #11129
  • ⭐ os: read FreeBSD crontabs from /var/cron/tabs and /usr/local/etc/cron.d by @tas50 in #11134
  • ⭐ inetd.config: support address prefixes, wrapped entries, and quoted tokens across inetd dialects by @tas50 in #11135
  • ⭐ os: FreeBSD packages report install date, license, purl, files and available updates by @tas50 in #11137
  • 🐛 zfs: read pools and datasets on OpenZFS releases without JSON output by @tas50 in #11136
  • ⭐ os: report kernel.aslr, machineid, hypervisor, and rebootpending on FreeBSD by @tas50 in #11144
  • ⭐ os: network routes on FreeBSD, and ports that keep IPv6 zones and dual-stack listeners by @tas50 in #11138
  • ⭐ os: read MySQL, MariaDB, PostgreSQL, logrotate and snmpd configuration from FreeBSD package layouts by @tas50 in #11142
  • ⭐ os: FreeBSD user.system, process state and executable, and rc.d service status by @tas50 in #11140
  • 🐛 kernel.parameters: keep sysctl values that contain the separator and multi-line values by @tas50 in #11143
  • 🐛 apache2.version reports the full version; npm.packages.scripts no longer fails on a default search by @tas50 in #11141
  • ⭐ os: detect clouds and read SMBIOS on FreeBSD by @tas50 in #11139
  • ✨ os: detect the hypervisor on arm64 Linux guests by @tas50 in #11155
  • 🐛 os: yum.repos lists repositories on dnf5 hosts by @tas50 in #11149
  • ✨ os: report rebootpending on Alpine Linux by @tas50 in #11164
  • 🧹 providers-sdk: stop selecting the deprecated Advisory.cves by @vjeffrey in #11088
  • 🐛 os: ai.model.parameterSize reports small models in millions of parameters by @chris-rock in #11132
  • 🐛 aws: apply tag filters to CloudTrail trails by @chris-rock in #11179
  • 🐛 aws: read a scanned asset's VPC in full under tag filters by @chris-rock in #11180
  • 🐛 network: make the non-SNI handshake without SNI by @chris-rock in #11181
  • 🐛 sudoers: parse negated global Defaults by @chris-rock in #11098
  • 🐛 os: resolve shared user and group IDs to the first entry by @chris-rock in #11099
  • 🐛 dpkg: removed packages (config-files) are not installed by @chris-rock in #11106
  • 🐛 os: match Windows NVMe disk serial numbers when selecting a device by serial by @VasilSirakov in #11184
  • ⭐ os: idp.entra.joinType reports whether a device is Entra joined or hybrid joined by @chris-rock in #11131
  • ⚡ os: ask the package manager for updates only when available or outdated is read by @VasilSirakov in #11183
  • 🎉 os-14.7.0 by @VasilSirakov in #11186
  • 🧹 os: refresh the IEEE OUI table 20260928 by @github-actions[bot] in #11175
  • 🐛 os: serialize launchd.job content by @tas50 in #11174
  • ✨ os: read the last update on Alpine from apk.log by @tas50 in #11169
  • 🐛 os: fix apache2.conf.envvars erroring on Debian and Ubuntu by @tas50 in #11159
  • 🐛 lvm: fall back to --nameprefixes output on LVM2 before 2.02.158 by @tas50 in #11147
  • 🐛 proxmox: resolve node, pool, storage and backup-target fields that never answered by @tas50 in #11049
  • 🐛 proxmox: decode the response shapes Proxmox actually sends by @tas50 in #11048
  • ✨ os: report macOS application install dates from installer receipts by @tas50 in #11172
  • 🐛 os: fix os.rebootpending on Photon OS by @tas50 in #11190
  • ✨ os: kernel.installed on Azure Linux, CBL-Mariner, openEuler and Mageia by @tas50 in #11196
  • 🐛 os: set vuln.cve.unscored from the vulnerability report by @tas50 in #11195
  • 🐛 os: return no fstab entries when the fstab file does not exist by @tas50 in #11188
  • 🧹 Update deps for mql and providers 20260928 by @github-actions[bot] in #11176
  • 🎉 os-14.8.0, aws-14.0.1, network-14.0.1 by @chris-rock in #11182
  • ✨ os: read the Windows sshd_config in sshd.config by @tas50 in #11198
  • 🧹 providers: name the released providers and versions in the Slack message by @VasilSirakov in #11193
  • 🐛 os: report the architecture on container image scans by @tas50 in #10439
  • ✨ azure: report cross-tenant and user-bound delegation SAS settings on storage accounts by @tas50 in #11201
  • ✨ auth0: My Organization, anonymous session, and subject-type authorization fields by @tas50 in #11202
  • ✨ alicloud: report Elasticsearch automatic snapshot settings by @tas50 in #11203
  • ✨ tailscale: external tailnets, service display name, organization tailnets by @tas50 in #11204
  • ✨ gitlab: add creator and pipeline to gitlab.project.package by @tas50 in #11205
  • ⭐ cloudflare: CASB posture policies, service-token inactivity, k2 binding targets by @tas50 in #11206
  • ✨ gcp: Cloud Tasks queue HTTP target and CMEK key, Bigtable effective backup policy by @tas50 in #11208
  • ⭐ datadog: workflows, Security Inbox rules, Snowflake and Databricks integrations by @tas50 in #11207
  • ✨ os: report sudo.version for sudo-rs and add sudo.implementation by @tas50 in #11145
  • ⭐ aws: AgentCore payments, knowledge base VPC configurations, managedBy, federated Glue tables by @tas50 in #11209
  • 🐛 gomod: a local replace keeps the original module path, not the directory by @chris-rock in #11211
  • ⭐ os: apt.config, the effective APT configuration by @chris-rock in #11214
  • 🎉 os-14.9.0, datadog-14.1.0, gcp-14.2.0, cloudflare-14.1.0, gitlab-14.1.0, tailscale-14.1.0, alicloud-14.1.0, auth0-14.1.0, azure-14.1.0, aws-14.1.0 by @tas50 in #11217
  • ⭐ gitlab: system hook delivery health, signing token, branch filters by @tas50 in #11219
  • 🧹 providers: refresh SDK dependencies by @tas50 in #11220
  • ⭐ aws: Client VPN device posture and Cedar authorization policy by @tas50 in #11221
  • 🐛 os: return no server features on Windows client editions by @tas50 in #11210
  • 🐛 os: list macOS apps from their folders when system_profiler reports nothing by @chris-rock in #11218

Full Changelog: v14.1.0...v14.2.0