Skip to content

v14.3.0

Choose a tag to compare

@czunker czunker released this 06 Oct 08:55
· 165 commits to main since this release
b836fde

What's Changed

  • 🐛 version: stop provider bumps from overwriting dependency MinVersions by @czunker in #11230
  • 🐛 opensearch: stop opensearch-go v5 from rerouting to discovered nodes by @czunker in #11231
  • 🎉 Release 74 providers by @github-actions[bot] in #11229
  • 🐛 windows: drop Uninstall entries superseded in the same directory by @chris-rock in #11227
  • ⭐ os: winget, Windows Package Manager presence and SYSTEM usability by @chris-rock in #11224
  • ⭐ os: idp.activeDirectory reports the Active Directory domain a device is joined to by @chris-rock in #11226
  • 🐛 os: list the macOS apps a partial system_profiler report leaves out by @chris-rock in #11232
  • 🐛 os: idp.activeDirectory honors SSSD enabled = false and Samba AD DCs by @chris-rock in #11233
  • 🐛 k8s: stop namespace scoping from emptying cluster-scoped collections by @tas50 in #10472
  • 🐛 os: don't read another user's program from the scanning user's profile by @chris-rock in #11234
  • 🐛 os: decode PowerShell CLIXML stderr in the command transports by @tas50 in #11199
  • 🐛 os: parse Windows process flags with Windows command-line rules by @tas50 in #11191
  • 🎉 os-14.10.0 by @chris-rock in #11235
  • ⭐ azure: VM run commands and patch posture, typed extensions, automation runbooks, SQL MI security, Arc agent config, APIM backends, backup instances by @tas50 in #11222
  • ⭐ aws: API Gateway v1 method auth, OpenSearch Serverless, Redshift Serverless, MWAA, backup and snapshot immutability by @tas50 in #11225
  • ⭐ gcp: regional firewall policies and secrets, org and folder deny policies, Firebase rules, machine images, NGFW endpoints, SCC custom modules, Secure Web Proxy by @tas50 in #11223
  • 🐛 os: reach docker daemons older than API 1.40 in the docker resource by @tas50 in #11156
  • ✨ os: elevate with doas when sudo is not installed by @tas50 in #11168
  • 🐛 os: report the nft version needed by nftables instead of failing by @tas50 in #11158
  • ⭐ hetzner: firewall rules with port ranges and internet exposure, network members by @tas50 in #11239
  • ⭐ digitalocean: database engine security settings, Kafka topics, clusterlint diagnostics, App Platform components by @tas50 in #11240
  • ⭐ oci: WAF policy rules, identity domain federation and settings, database homes and databases, OS Management Hub by @tas50 in #11242
  • ⭐ stackit: CDN, Git, Logs, Valkey, service enablement, Flex access scope and CMEK, observability scrape jobs by @tas50 in #11243
  • 🐛 os: read registry value types with reg.exe so hardened hosts report real data by @tas50 in #10391
  • 🐛 device/windows: restore disk read-only state, not online state by @tas50 in #8664
  • 🐛 config: write through a symlinked config rather than replacing the link by @chris-rock in #10943
  • 🐛 os: a WinRM command over the command-line limit fails silently by @tas50 in #10552
  • ⭐ alicloud: root account security, access key last use, identity providers, ECS backup and encryption defaults, API Gateway, SSL certificates, PrivateLink by @tas50 in #11245
  • 🐛 os: a Windows service that is stopping is StopPending, not Stopped by @chris-rock in #11241
  • 🎉 os-14.11.0 by @chris-rock in #11246
  • 🎉 hetzner-14.1.0, aws-14.2.0, alicloud-14.2.0, stackit-14.1.0, oci-14.1.0, digitalocean-14.1.0, gcp-14.3.0, azure-14.2.0 by @tas50 in #11266
  • 🐛 os: keep Solaris packages from publishers with a dot or hyphen by @tas50 in #11277
  • ✨ os: read SMBIOS, hypervisor, CPU clock and root certificates on Solaris by @tas50 in #11276
  • ⭐ os: detect network interfaces and routes on Solaris by @tas50 in #11275
  • ⭐ os: read zfs on Oracle Solaris by @tas50 in #11272
  • ✨ os: read kernel info and modules on Solaris by @tas50 in #11271
  • 🐛 os: keep mount sizes when df cannot stat one mount by @tas50 in #11274
  • ✨ os: list ports on Solaris by @tas50 in #11270
  • ✨ os: list mounts on Solaris by @tas50 in #11273
  • ✨ os: read sshd's effective config, ntp.conf and process state on Solaris by @tas50 in #11278
  • 🎉 os-14.12.0 by @tas50 in #11279
  • ✨ usb: list USB devices on Linux from sysfs by @tas50 in #11151
  • 🐛 os: report the Falcon sensor IDs on edr.product from one source by @chris-rock in #11280
  • ✨ os: accept a list and default in the id-detector flag by @chris-rock in #11282
  • 🐛 ci: start a provider release only on a version change, one per branch at a time by @chris-rock in #11285
  • 🎉 os-14.13.0 by @chris-rock in #11286
  • 🐛 os: Windows service description is the service's description, not its display name by @chris-rock in #11289
  • ✨ mql: version.stripEpoch to compare the upstream release by @tas50 in #11118
  • 🐛 os: stop reporting OpenZFS's zed daemon as the Zed editor by @tas50 in #11318
  • 📄 AGENTS.md: never identify a customer in commits, PRs or code by @tas50 in #11319
  • 🐛 os: match AI tools by the package names scanned assets report by @tas50 in #11320
  • 🎉 os-14.13.1 by @github-actions[bot] in #11321
  • ⭐ Add native Windows API for services enumeration by @chris-rock in #6474
  • 🐛 os: classify registry errors with ADR 046 kinds instead of bare errors and nulls by @chris-rock in #11238
  • 🐛 windows: computerInfo fallback reports culture names and processors like Get-ComputerInfo by @chris-rock in #11283
  • ⚡ registry: one resource per registry key, whatever the spelling by @chris-rock in #11284
  • ✨ windows: add the Uninstall entry's ProductCode, UpgradeCode or AppId to package urls by @chris-rock in #11325
  • ⚡ windows: look up each optional feature once per scan by @chris-rock in #11287
  • 🐛 os: packages.installDate on local Windows scans by @chris-rock in #11288
  • 🐛 registry: read every value kind the same on the native and PowerShell paths by @chris-rock in #11290
  • 🧹 Update deps for mql and providers 20260930 by @github-actions[bot] in #11322
  • 🐛 os: detect RHCOS on OpenShift 4.19+ by @tas50 in #11327
  • 🎉 os-14.14.0 by @tas50 in #11328
  • 🌟 claude: RBAC groups and roles, effective spend limits, plugins, external keys, compliance state by @tas50 in #11331
  • ⭐ aws: expose fields unlocked by the latest SDK bump by @tas50 in #11332
  • ⭐ oci: DRG NAT policies, DRG attachment NAT settings, Data Safe target features by @tas50 in #11330
  • ⭐ azure: AKS cluster-wide FIPS and Kubernetes resource object encryption by @tas50 in #11329
  • 🐛 ms365: fetch service principal assignments and managed device detail fields, read settings catalog children and current Autopilot properties by @tas50 in #11337
  • 🐛 ms365: include compromised risky users, fix DLP sensitive info types, app owners and license detail ids by @tas50 in #11338
  • 🐛 ms365: fix dict fields that fail to serialize and a cross-tenant policy panic by @tas50 in #11336
  • 🐛 ms365: key the credential cache on the credential, not only tenant and client by @tas50 in #11335
  • 🐛 ms365: stop failed lookups from reading as empty lists or false by @tas50 in #11339
  • 🟢 Unblock CI: skip zoom.us docs in link check, fix flaky ms365 role test by @tas50 in #11353
  • ⭐ ms365: workload identity trust on apps and service principals by @tas50 in #11347
  • ⭐ ms365: active PIM role assignments and PIM for Groups instances by @tas50 in #11354
  • ⭐ ms365: Exchange Online and Defender XDR unified RBAC roles and assignments by @tas50 in #11355
  • ⭐ ms365: Identity Protection for workload identities by @tas50 in #11351
  • 🐛 ms365: fix test package build after concurrent merges by @tas50 in #11357
  • ⭐ ms365: on-premises directory synchronization settings and features by @tas50 in #11345
  • ⭐ ms365: external identity providers and B2B self-service sign-up user flows by @tas50 in #11344
  • 🟢 ms365: fix test build on main, classify 401/429/5xx Graph errors by @tas50 in #11356
  • ⭐ ms365: cross-tenant access policy partner configurations by @tas50 in #11340
  • ⭐ ms365: Entra administrative units with members and scoped role assignments by @tas50 in #11341
  • ⭐ ms365: token lifetime, claims mapping, token issuance and home realm discovery policies by @tas50 in #11342
  • ⭐ ms365: tenant report settings, people settings, and service health by @tas50 in #11343
  • ⭐ ms365: authentication strength, authentication flows, and feature rollout policies by @tas50 in #11346
  • ⭐ ms365: Entra directory audit and provisioning logs by @tas50 in #11348
  • ⭐ ms365: Windows LAPS and BitLocker key escrow metadata by @tas50 in #11349
  • ⭐ ms365: Entra entitlement management settings, catalogs, access packages and assignment policies by @tas50 in #11350
  • ⭐ ms365: terms of use, lifecycle workflows, custom security attributes by @tas50 in #11352
  • 🐛 os: read ZFS pools, vdevs and version on ZFS on Linux before 0.8 by @tas50 in #11364
  • 🐛 os: parse.openpgp accepts a file path again by @tas50 in #11363
  • 🐛 os: report com2sec communities, snmpd.local.conf, and rwuser -s names in snmpd.config by @tas50 in #11360
  • 🐛 os: exim.localInterfaces reports all interfaces when unset, reads exim4.conf, resolves macros by @tas50 in #11365
  • 🐛 os: start journald.config settings from the defaults journald was built with by @tas50 in #11375
  • 🐛 os: list mount points with spaces and tell overmounted paths apart by @tas50 in #11380
  • 🐛 os: find loaded kernel modules by dashed name by @tas50 in #11386
  • 🐛 os: report an unreadable Open vSwitch database as an error, not an empty switch by @tas50 in #11393
  • 🐛 ms365: use types.String for identity provider domains and risk keyIds by @tas50 in #11394
  • 🐛 os: ufw reads removed packages as not installed, parse route and commented rules by @tas50 in #11395
  • 🐛 os: an unlistable ~/.ssh or polkit directory is an error, not empty by @tas50 in #11388
  • 🐛 os: apply exports(5) defaults and last-wins to Linux NFS exports by @tas50 in #11389
  • 🐛 os: read modprobe.d the way kmod does by @tas50 in #11385
  • 🐛 os: read systemd.timer.onCalendar from TimersCalendar by @tas50 in #11384
  • 🐛 os: error when nft cannot read the ruleset, list nftables maps by @tas50 in #11378
  • 🐛 os: list stopped Docker containers in docker.containers by @tas50 in #11373
  • 🐛 haproxy: read the config files haproxy loads, and classic peer lines by @tas50 in #11371
  • 🐛 ms365: keep Graph durations in days form and stop Kiota duration panics by @tas50 in #11399
  • 🐛 ms365: resolve 15 listed resources when queried directly by id by @tas50 in #11401
  • 🟢 os: drop embedded field from selector in listing test by @tas50 in #11408
  • 🐛 ms365: skip a single failed group in PIM for Groups lists, read chunks concurrently by @tas50 in #11409
  • 🐛 os: replace the archived WMI library with microsoft/wmi, and fall back to PowerShell on WMI errors by @chris-rock in #11291
  • 🐛 os: docker.file stage.hasHealthcheck is false for HEALTHCHECK NONE by @tas50 in #11415
  • 🐛 os: read lsblk and LUKS volumes on util-linux without --json by @tas50 in #11416
  • 🐛 os: keep every apt.repo line, ignore trailing comments, read apt.config keys case-insensitively by @tas50 in #11411
  • 🐛 ms365: report includeTargets on authentication method configurations by @tas50 in #11424
  • 🐛 ms365: read quarantine policy end-user permissions from EndUserQuarantinePermissions by @tas50 in #11423
  • 🐛 os: podman port hostIp is 0.0.0.0 for all interfaces, podman < 2.0 errors instead of guessing by @tas50 in #11418
  • 🐛 os: Windows network routes from the target, over SSH too, and the same on both paths by @chris-rock in #11292
  • 🐛 windows: read the firewall from the ActiveStore, including rules delivered by Group Policy by @chris-rock in #11293
  • 🟢 ci: run every Windows-only test, and vet the Windows build of the os provider by @chris-rock in #11294
  • 🟢 ci: check GitHub file links through raw.githubusercontent.com by @chris-rock in #11459
  • 🐛 os: encode the GCE metadata crawl on Windows, and read Hetzner metadata on Windows by @chris-rock in #11295
  • 🧹 os: PowerShell helpers fail loudly, quote safely, and accept a single environment variable by @chris-rock in #11296
  • 🐛 os: decode PowerShell lists with one element as a list by @chris-rock in #11297
  • 🐛 os: list Windows processes without elevation, and resolve process(pid) by @chris-rock in #11298
  • ⭐ os: collect UDP ports on Windows, and report bound TCP sockets as bound by @chris-rock in #11299
  • 🐛 os: read AppArmor 3.0.8's aa-status JSON and 2.12's process shape, list only confined processes by @tas50 in #11472
  • 🐛 os: read interface flags and state from sysfs as the kernel writes them by @tas50 in #11446
  • 🐛 os: a registry key exists whether or not it holds values by @chris-rock in #11300
  • 🐛 os: selinux reads sysfs booleans correctly, lists disabled modules with their priority, and reads mode from the running kernel by @tas50 in #11444
  • 🐛 os: list limits.d files in pam_limits' order, skip what its glob skips by @tas50 in #11471
  • 🐛 os: read the inetd and ntp configs Debian's daemons read, report ntp pools and peers by @tas50 in #11470
  • 🐛 os: apt.config trust options count apt-get's and apt's Binary overrides by @tas50 in #11465
  • 🐛 os: podman.image repoDigests, os and architecture from podman image inspect, one image per ID by @tas50 in #11457
  • 🐛 os: report the running sshd's command-line options in effective*, keep every included multi-value keyword by @tas50 in #11442
  • 🐛 os: fail sshd.config on an unreadable Include, run sshd -T with -C on OpenSSH 7.9 by @tas50 in #11464
  • 🐛 os: read yum.repo ids and names on RHEL 7, yum.vars on RHEL 7 and dnf5, yum.config as dnf resolves it by @tas50 in #11445
  • 🐛 os: polkit.installed requires polkitd or its tools, not just action files by @tas50 in #11443
  • 🐛 os: report cgroup v1 controllers from /proc/cgroups, null list on v1 by @tas50 in #11438
  • 🐛 os: read os.base.lastUpdate from dnf5's transaction history by @tas50 in #11440
  • 🐛 os: firewalld reads forward ports on 0.9+, reports the FAILED state (0.4 included), and finds rich rule actions followed by options by @tas50 in #11435
  • 🐛 os: find kernel-core kernels, count needs-restarting reboots, parse /proc/cmdline per parameter by @tas50 in #11431
  • 🐛 os: keep every value of a repeated boot parameter, expand BLS initrd, report refused GRUB reads by @tas50 in #11439
  • 🐛 os: read zypper needs-rebooting's 102 as a pending reboot by @tas50 in #11473
  • 🐛 os: drop inline comments from sudoers entries, keep #uid users by @tas50 in #11482
  • 🐛 os: selinux.mode reads "disabled" on a running host without SELinux by @tas50 in #11484
  • 🐛 os: take SUSE's asset.cpes from os-release CPE_NAME by @tas50 in #11476
  • 🐛 os: containerd.containers through docker's bundled containerd and SUSE's containerd-ctr, pid 0 for stopped tasks by @tas50 in #11463
  • 🐛 os: mondoo.eol needs a product and version, a copied /etc/localtime beats a stale /etc/timezone by @tas50 in #11460
  • 🐛 mongodb: report the server's auth defaults and honor net.bindIpAll by @tas50 in #11450
  • 🐛 os: read os.lastUpdate on SUSE from zypper's history log by @tas50 in #11479
  • 🐛 os: report httpd's defaults for unset ServerTokens, ServerSignature and TraceEnable by @tas50 in #11454
  • 🐛 os: read the bind9 configuration named loads with -c, find DNSSEC keys in zone key-directory by @tas50 in #11462
  • ⚡ os: detect the Windows hypervisor from the natively read SMBIOS data by @chris-rock in #11302
  • 🐛 os: never start systemd-timesyncd when reading systemd.timesyncd by @tas50 in #11456
  • 🐛 os: read inline realm usernames and keep jboss(home:) to its own installation by @tas50 in #11461
  • 🐛 os: read the logrotate.d files SUSE's logrotate reads by @tas50 in #11492
  • 🐛 os: read xinetd service blocks in inetd.config instead of making up service names by @tas50 in #11491
  • 🐛 os: report string results like 'yes' in polkit.rule.results by @tas50 in #11488
  • 🐛 os: report a missing explicit snmpd.config path as an error by @tas50 in #11485
  • 🐛 os: read AIDE configurations the way AIDE does: built-in groups, @@if, restricted and "-" rules, x_include scripts, unreadable aide.conf by @tas50 in #11441
  • 🐛 os: read the mongod.conf the mongod service is started with by @tas50 in #11480
  • 🐛 os: apply login.defs.d drop-ins to logindefs.params on SUSE by @tas50 in #11477
  • 🐛 os: find lvm and zfs tools off a non-root PATH, report refused lvm reports by @tas50 in #11434
  • 🐛 os: report an unreadable sudoers includedir instead of skipping it by @tas50 in #11487
  • ⚡ windows: optional features through the DISM API, behind MONDOO_WINDOWS_NATIVE by @chris-rock in #11303
  • 🐛 os: read the cron files cron runs and the rsyslog files rsyslog includes, report the ones the scan cannot read by @tas50 in #11433
  • ⚡ windows: read the local security policy natively on a local scan by @chris-rock in #11304
  • 🐛 os: resolve a systemd unit symlink with Unix paths on a Windows scanner by @chris-rock in #11496
  • 🐛 os: search SUSE's /srv/www/htdocs for WordPress plugins and Composer files by @tas50 in #11495
  • 🐛 os: find jars in /usr/share/java package subdirectories by @tas50 in #11494
  • 🐛 os: continue postfix logical lines across comment and blank lines by @tas50 in #11483
  • 🐛 os: list tomcat webapps deployed as symlinked directories by @tas50 in #11478
  • 🐛 os, network: read trust-store roots with a negative serial number by @tas50 in #11466
  • 🐛 os: take a jar's Maven groupId from its pom.properties path when the file has none by @tas50 in #11455
  • 🐛 ms365: report Teams federation allow-all and stop inventing false meeting policy fields by @tas50 in #11429
  • 🐛 ms365: name APIConnectors.Read.All when Graph refuses a user flow's API connectors by @tas50 in #11419
  • 🐛 githubactions: inventory reusable workflows called with a job-level uses by @tas50 in #11407
  • 🐛 os: report a WordPress plugin's installed version from its main file by @tas50 in #11392
  • 🐛 os: report cassandra.version for tarball installs by @tas50 in #11449
  • 🐛 os: resolve relative sudoers includes like sudo, skip includedir subdirectories by @tas50 in #11432
  • 🐛 os: evaluate Exim's built-in macros, doubled list separators, Debian's listening interfaces and .include in exim by @tas50 in #11426
  • 🐛 os: list each Java truststore once, find SUSE's store under /var/lib/ca-certificates by @tas50 in #11425
  • 🐛 os: ufw reads Fedora/EPEL rules from /var/lib/ufw and reports status from the loaded firewall by @tas50 in #11422
  • 🐛 ms365: resolve the user behind an Exchange Online shared mailbox by @tas50 in #11414
  • 🐛 os: read only the modprobe.d directories the installed kmod reads by @tas50 in #11417
  • 🐛 ms365: key app roles on their parent so shared role IDs keep their own text by @tas50 in #11413
  • 🐛 ms365: report Graph's year-1 "never set" timestamps as null by @tas50 in #11421
  • 🐛 os: read /etc/default/grub.d drop-ins into grub.config.params on the Debian family by @tas50 in #11400
  • 🐛 os: read PKCS#12 keystore aliases and trusted certificates by @tas50 in #11362
  • 🐛 os: keep every command and the runas spec in sudoers.userSpecs by @tas50 in #11367
  • 🐛 os: keep every load_module in nginx.conf.params and list the modules nginx runs in nginx.modules by @tas50 in #11428
  • 🐛 os: keep iptables negation and report non-root refusals by @tas50 in #11376
  • 🐛 os: read my.cnf option groups, prefixes and defaults the way the server does by @tas50 in #11405
  • 🐛 os: read systemd.resolved on every systemd release, with its drop-ins by @tas50 in #11377
  • 🐛 os: detect passphrase-protected OpenSSH and PKCS#8 private keys by @tas50 in #11369
  • 🐛 os: evaluate apache2 /, keep # inside arguments, read httpd's unit environment and launch arguments (SUSE sysconfig) by @tas50 in #11361
  • 🐛 chrome: read extensions from Preferences and Secure Preferences by @tas50 in #11404
  • 🐛 os: read every key of armored and binary OpenPGP keyrings in parse.openpgp by @tas50 in #11430
  • 🐛 os: report a refused grub.cfg instead of SUSE's EFI stub, read BLS entries on the ESP by @tas50 in #11481
  • 🐛 os: parse multi-pair ENV/ARG, registry ports and EXPOSE in docker.file by @tas50 in #11374
  • 🐛 os: report the patches zypper holds back behind a package manager update in os.updates by @tas50 in #11475
  • 🐛 os: read Windows group members, including orphaned SIDs by @chris-rock in #11306
  • 🐛 postgresql: find RHEL and SUSE clusters the server runs, follow hba_file, report refusals by @tas50 in #11452
  • 🐛 os: read systemd units on systemd 219/232, SysV enablement on RHEL 7 and Debian by @tas50 in #11420
  • 🐛 os: report held, kept-back and foreign-arch deb updates in package.available by @tas50 in #11410
  • 🐛 os: end Gemfile.lock sections at every header, read GIT and PATH gems by @tas50 in #11398
  • 🐛 npm: parse classic yarn.lock with mixed-quote headers and yarn berry lockfiles by @tas50 in #11383
  • 🐛 os: read LuaRocks rock trees instead of Lua module directories by @tas50 in #11382
  • 🐛 os: read Flathub Firefox's systemconfig policy file, stop crediting /etc/firefox to it by @tas50 in #11486
  • 🐛 os: read the modification time, not the access time, from stat over SSH --sudo by @tas50 in #11453
  • 🐛 os: read systemd.unit capability, syscall filter and address family lists as systemd means them by @tas50 in #11372
  • 🐛 os: keep systemd.targets runtime state when a template target exists by @tas50 in #11370
  • 🐛 os: keep Match-block values out of sshd.config.params by @tas50 in #11358
  • 🐛 os: find snap, flatpak and XDG Firefox and Chromium profiles by @tas50 in #11403
  • 🐛 os: identify the MySQL/MariaDB server by its binary, redact option file passwords by @tas50 in #11451
  • 🐛 os: read claude, codex and ollama versions when sudo's PATH misses /usr/local/bin by @tas50 in #11448
  • ⚡ os: read Windows users and groups natively by @chris-rock in #11307
  • 🐛 os: report a systemd service looked up by an alias with its unit's state by @tas50 in #11359
  • ⚡ windows: read computerInfo natively behind MONDOO_WINDOWS_NATIVE by @chris-rock in #11308
  • 🐛 os: report the nginx settings each server runs with, from the config nginx loads by @tas50 in #11497
  • 🐛 os: keep the word after a --flag=value out of that flag's value by @tas50 in #11490
  • 🐛 network: stop tls() probing SSLv3 ciphers forever against OpenSSL 1.0.2 by @tas50 in #11427
  • ⚡ os: run PowerShell in the SSH server's own shell on Windows by @chris-rock in #11309
  • 🐛 os: elevate every command of a compound line under --sudo by @tas50 in #11379
  • ⚡ registry: read the policy roots in one PowerShell run over remote connections by @chris-rock in #11311
  • ✨ os: date dpkg packages from their file-list mtime by @tas50 in #11162
  • 🐛 network: report a cookie's name when its value is empty by @tas50 in #10461
  • ⚡ os: limit the commands that run at once over SSH on Windows by @chris-rock in #11312
  • ⚡ os: persistent PowerShell session per SSH connection on Windows by @chris-rock in #11313
  • ⭐ windows: auditpol settings in English, the same natively and through auditpol by @chris-rock in #11314
  • ⚡ os: detect Windows first on an OpenSSH for Windows server by @chris-rock in #11315
  • ✨ os: kernel.parameter with live and configured sysctl values by @chris-rock in #11498
  • 🐛 os: probe rpm and resolve binaries without the command builtin under --sudo by @tas50 in #11489
  • 🐛 os: skip SUSE's ipv6-localhost and ipv6-loopback when resolving the hostname by @tas50 in #11474
  • 🐛 os: quote the IMDS token in the Windows metadata command by @chris-rock in #11316
  • 🐛 os: run brew as the Homebrew owner when scanning as root by @tas50 in #11412
  • 🐛 os: report a failed rpm update check as an error, keep multilib and arch-changing updates by @tas50 in #11436
  • ⚡ os: run staged scripts and plain commands in the PowerShell session by @chris-rock in #11317
  • ⚡ os: check the Windows 10 ESU license with one property over PowerShell by @chris-rock in #11323
  • 🐛 os: read OpenSSH-format DSA private keys from their unencrypted header by @tas50 in #11468
  • 🐛 os: apply systemd type-level and prefix drop-ins to a unit's environment by @tas50 in #11447
  • 🐛 os: parse SKILL.md allowed-tools per the Agent Skills spec by @tas50 in #11402
  • 🐛 os: list dotfiles and odd names over SSH --sudo by @tas50 in #11390
  • 🐛 os: keep apt's solver log out of the package update dry run by @tas50 in #11108
  • 🐛 claude.code: read the live .claude.json before falling back to backups by @tas50 in #11387
  • 🐛 os: systemd reads type-level drop-ins since 244, not 246 by @tas50 in #11511
  • 🐛 os: key Firefox addons on the profile directory, read absolute profiles by @tas50 in #11572
  • 🐛 os: read systemd releases before 231 from the manager binary by @tas50 in #11569
  • ✨ os: report per-source trust options on apt.repo by @tas50 in #11566
  • 🐛 os: compare Amazon Linux kernels without their epoch, list kernel6.x packages by @tas50 in #11604
  • 🐛 os: os.machineid is null without a machine-id file, ALT takes its CPE from os-release by @tas50 in #11620
  • 🐛 os: read the apk database on OpenWrt snapshots that moved off opkg by @tas50 in #11617
  • 🐛 os: read Azure Linux distroless packages from the rpm manifest, error without a database by @tas50 in #11609
  • 🐛 haproxy.config: follow the haproxy that runs without a pid file, and the image's command by @tas50 in #11605
  • 🐛 os: no reboot is pending inside a container by @tas50 in #11593
  • 🐛 os: name interfaces without the @peer suffix iproute2 prints by @tas50 in #11615
  • 🐛 os: report apk and xbps updates, and fail the check when no index was read by @tas50 in #11595
  • 🐛 os: report snaps the store has a newer revision of as outdated by @tas50 in #11562
  • 🐛 os: list Tomcat apps deployed by context descriptors and server.xml Contexts by @tas50 in #11561
  • 🐛 os: read auditd rules.d the way augenrules concatenates it by @tas50 in #11557
  • 🐛 os: report an unreadable kubelet config instead of kubelet's defaults by @tas50 in #11553
  • 🐛 os: ufw.status never reads "active" from ufw.conf alone by @tas50 in #11551
  • 🐛 os: report a local scan inside a container as a container by @tas50 in #11600
  • 🐛 os: read pacman install dates and every license, and apk world pins by @tas50 in #11627
  • 🐛 ollama.config: read the environment the server runs with by @tas50 in #11626
  • 🐛 postgresql.conf: apply the postmaster's -c settings over the file by @tas50 in #11621
  • 🐛 os: scan the file given to docker tar and container tar by @tas50 in #11624
  • 🐛 os: detect the platform and arch of a local scan on an image without a shell by @tas50 in #11623
  • 🐛 os: read crontab with cronie's rules on Amazon Linux by @tas50 in #11630
  • 🐛 os: os.rootCertificates errors when no trust bundle could be read by @tas50 in #11622
  • 🐛 os: firefox.policies needs a Firefox binary, not just its install directory by @tas50 in #11634
  • 🐛 os: systemd.resolved.resolvConfMode is null when systemd does not report it by @tas50 in #11633
  • 🐛 os: aide.installed needs the aide binary, null version without one, reject '-' rules before AIDE 0.19 by @tas50 in #11519
  • 🐛 redisdb, mssql, clickhousedb, elasticsearch, opensearch: accept the positional host, fail fast by @tas50 in #11592
  • 🐛 os: read authorized_keys lines of any length, error instead of truncating by @tas50 in #11594
  • 🐛 mssql: list offline databases, name permission securables, complete role and login rows by @tas50 in #11591
  • 🐛 mongo, cassandra: accept the positional host, render parameter arrays as JSON by @tas50 in #11587
  • 🐛 mysqldb: TLS state on MySQL 8.4+, routine/column/proxy grants, manifest keyrings by @tas50 in #11586
  • 🐛 redisdb: read requirepassSet from the default user, honor optional bind addresses by @tas50 in #11582
  • ⚡ os: find JBoss systemd units with one grep and scan them once per connection by @tas50 in #11577
  • 🐛 opensearch: error instead of an empty list when the scanner cannot read by @tas50 in #11585
  • 🐛 os: read cron and logrotate files the way the installed daemons do by @tas50 in #11578
  • 🐛 os: key jenkins and wordpress packages on their plugin file by @tas50 in #11602
  • 📄 agents: tests live in the test file named after the source file by @tas50 in #11636
  • 🐛 mssql: error instead of a partial or empty list when the scanner cannot read by @tas50 in #11589
  • 🐛 cassandra: refused role reads are errors, and resolve superuser status through grants by @tas50 in #11584
  • 🐛 mysqldb: connect timeouts, TLS mode semantics, classified connect errors by @tas50 in #11588
  • 🐛 elasticsearch: error instead of an empty list when the scanner cannot read by @tas50 in #11580
  • 🐛 redisdb: error instead of an empty list or null when the credential is refused by @tas50 in #11581
  • 🐛 os: keep systemctl's JOB column out of service, timer and socket descriptions by @tas50 in #11632
  • 🐛 redisdb: scan servers without CONFIG and servers that require a client certificate by @tas50 in #11583
  • 🐛 os: keep every priority of an SELinux module in selinux.modules by @tas50 in #11638
  • 🐛 os: ufw reads the upstream tarball install in /usr/local/sbin as installed by @tas50 in #11637
  • 🐛 apache2.conf: follow the httpd an image runs, with or without a pid file by @tas50 in #11629
  • 🐛 clickhousedb: error instead of an empty list when the scanner cannot read by @tas50 in #11575
  • 🐛 postgresql.conf: apply postgresql.auto.conf (ALTER SYSTEM) by @tas50 in #11573
  • 🐛 mysqldb: read MariaDB accounts, replication, encryption and identity by @tas50 in #11579
  • 🐛 postgresdb: connect to PostgreSQL 9.2-9.5 and tolerate version-specific catalog columns by @tas50 in #11574
  • 🐛 os: gate resolved settings and boot paths on what systemd supports, read 219's socket listeners by @tas50 in #11570
  • 🐛 os: read modprobe.d lines like libkmod (continuations, CR) by @tas50 in #11563
  • ✨ clickhousedb: add user and role roles, fix grant-option revokes and XML hasPassword by @tas50 in #11590
  • 🐛 postgresdb: key and order hbaRules by file and rule number on PG 16+ by @tas50 in #11559
  • 🐛 mongo: report a refused command as an error, not as a default posture by @tas50 in #11564
  • 🐛 mongo: keep a mongodb:// password out of the asset name and platform id by @tas50 in #11560
  • 🐛 mongo: audit the server you name, and flag custom roles that are root in all but name by @tas50 in #11576
  • 🐛 mysqldb: key privilege rows by grantee and plugin rows by type by @tas50 in #11555
  • 🐛 java: read an OpenSSL -nokeys PKCS#12 bundle instead of blaming the password by @tas50 in #11549
  • 🐛 lua: stop reading a rock tree as a rocks directory when it has no rocks by @tas50 in #11608
  • 🐛 os: read bind9's -c inside its -t chroot; haproxy http-check send and httpchk defaults by @tas50 in #11546
  • 🐛 java: attach a PKCS#12 key's certificate chain to the key's entry by @tas50 in #11544
  • 🐛 os: read sudoers.d/README like sudo does; null, not an error, for a key that cannot be decoded by @tas50 in #11542
  • 🐛 mysqldb: error instead of an empty list when the scanner cannot read by @tas50 in #11565
  • 🐛 postgresdb: redact every libpq password form in subscription connection strings by @tas50 in #11558
  • 🐛 mongodb.conf: follow the mongod that runs, and its command line by @tas50 in #11547
  • 🐛 os: nginx TLSv1.3 default on RHEL 8/9, add_header without always, out-of-tree modules by @tas50 in #11532
  • 🐛 postgresdb: report default grants when an object's ACL is NULL by @tas50 in #11556
  • 🐛 os: apply /etc/login.defs.d where useradd links libeconf (RHEL 10, Fedora) by @tas50 in #11529
  • 🐛 opam: skip commented-out dependencies in depends lists by @tas50 in #11531
  • 🐛 mysql.conf, mariadb.conf: read the option files, groups and persisted settings the server uses by @tas50 in #11521
  • 🐛 os: report a refused /etc/default/grub and secboot config.json as refused, not absent by @tas50 in #11525
  • 🐛 os: expand $VAR in /etc/default/grub and its drop-ins like grub-mkconfig's shell by @tas50 in #11513
  • 🐛 os: run sudo -V and visudo -c in the C locale by @tas50 in #11514
  • 🐛 os: report a sniffer's PROMISC from ip, and LOWER_UP from sysfs, so both interface detectors agree by @tas50 in #11516
  • 🐛 mycnf: read option groups, fragment names and plugin lists as the server does by @tas50 in #11510
  • 🐛 ai.model: name Ollama models like ollama list, key models on their path by @tas50 in #11506
  • 🐛 os: list yum repos in the C locale so a non-English locale doesn't empty them by @tas50 in #11508
  • 🐛 os: read httpd's -f from its unit, evaluate IfVersion and IfFile, apply type-level drop-ins by @tas50 in #11523
  • 🐛 os: find lvm, mdadm and cryptsetup off PATH and under sudo, run lvm in the C locale, report failed mdadm and cryptsetup runs by @tas50 in #11543
  • 🐛 os: error on a missing explicit exim, squid, postfix and tomcat path; no jboss version from a missing dir by @tas50 in #11540
  • 🐛 ruby: list a gem resolved for several platforms once by @tas50 in #11538
  • 🐛 lua: report the rockspec for rocks luarocks lists, as for rocks read from disk by @tas50 in #11545
  • 🐛 os: don't date a deb package by its trigger runs by @tas50 in #11502
  • 🐛 os: decode podman 3 port mappings, podman.installed false only when podman is missing by @tas50 in #11503
  • 🐛 os: reject an AIDE configuration that names an undefined group by @tas50 in #11610
  • 🐛 os: evaluate docker.file variables, heredocs and port ranges the way BuildKit does by @tas50 in #11499
  • 🐛 cassandra, mysql.conf, mariadb.conf: a refused config directory is not an absent product by @tas50 in #11536
  • 🐛 os: keep Debian derivatives and Debian without os-release in the debian family, handle sid by @tas50 in #11625
  • 🐛 os: read commented gemini settings, native Claude Code versions, refused Firefox profiles by @tas50 in #11524
  • 🐛 os: decode octal escapes and quotes in fstab and exports paths, skip malformed fstab lines and hidden exports fragments by @tas50 in #11548
  • ⭐ os: expand PAM includes into pam.conf.service.stack, count [success=N default=ignore] as enabled by @tas50 in #11641
  • ✨ os: report rebootpending on openEuler, EulerOS and Huawei Cloud EulerOS by @tas50 in #11642
  • Bump crate-ci/typos from 1.50.2 to 1.50.3 by @dependabot[bot] in #11645
  • Bump dawidd6/action-download-artifact from 24 to 25 by @dependabot[bot] in #11644
  • Bump the codeql-action group with 3 updates by @dependabot[bot] in #11643
  • 📄 ADR 049: tell OS packages from third-party software (package.osProvided) by @tas50 in #11646
  • 👷 ci: stop the release gate failing commits that have no test run yet, or need none by @chris-rock in #11649
  • 🧹 os: refresh the IEEE OUI table 20261005 by @github-actions[bot] in #11651
  • 📄 docs: providers built from the root module run go mod tidy at the root by @chris-rock in #11653
  • ⭐ os: let the server switch on the native Windows paths by @chris-rock in #11654
  • ✨ windows: report the installer and per-user install scope on package urls by @chris-rock in #11650
  • 🧹 os: bump to 14.15.0-rc.1 (os-14.15.0-rc.1) by @chris-rock in #11655
  • 🐛 windows: report 64-bit apps registered under Wow6432Node with their real architecture by @chris-rock in #11656
  • 🐛 os: match AIDE's @@ifhost and HOSTNAME against the full node name by @tas50 in #11530
  • ✨ windows: report Squirrel and Chromium installers on package urls by @chris-rock in #11658
  • 🐛 login: exit 1 when the token is expired or invalid by @vjeffrey in #11657
  • 🧹 Update deps for mql and providers 20261005 by @github-actions[bot] in #11652
  • 🐛 llx: compound where blocks on a string dict no longer panic by @vjeffrey in #11659
  • 📄 google-workspace: add GOOGLEBOOK to endpoint device types by @tas50 in #11661
  • ✨ databricks: maintenance notification targets and job environment variable names by @tas50 in #11665
  • ✨ hetzner: report why a load balancer target health check fails by @tas50 in #11662
  • ✨ slack: IdP provisioning and lock flags on user groups by @tas50 in #11663
  • ✨ cloudflare: token provisioner, Access strict service-token auth, logpush attack-traffic filter by @tas50 in #11664
  • ✨ gcp: WildFire and partial-response settings on firewall endpoints, Cloud SQL CMEK log encryption, policy association priority by @tas50 in #11666
  • ✨ aws: Cognito ACR mapping and levels, Transfer workflow log groups by @tas50 in #11667
  • 🎉 slack-14.1.0, cloudflare-14.2.0, gcp-14.4.0, azure-14.3.0, aws-14.3.0, hetzner-14.2.0, ms365-14.1.0, oci-14.2.0, claude-14.1.0, stackit-14.2.0, digitalocean-14.2.0, k8s-14.1.0, google-workspace-14.0.2, mssql-14.0.2, mysqldb-14.0.2, postgresdb-14.0.2, redisdb-14.0.2, mongo-14.0.2, cassandra-14.0.2, clickhousedb-14.0.2, elasticsearch-14.0.2, opensearch-14.0.2, snowflake-14.0.2, weaviate-14.0.2 by @tas50 in #11668
  • 🎉 os-14.15.0 by @tas50 in #11660
  • 🐛 os: don't mount the EFI system partition behind an untriggered automount when reading boot entries by @tas50 in #11537
  • 🐛 os: list template instances in systemd.timers and systemd.sockets by @tas50 in #11631
  • 🐛 oci: list DRG attachments in the DRG's compartment, include automatic database backups by @tas50 in #11675
  • 🐛 aws: read AgentCore payment manager tags from ListTagsForResource by @tas50 in #11670
  • 🐛 azure: read run command execution results and runbook details from a GET by @tas50 in #11671
  • 🐛 gcp: resolve versioned KMS keys, read Cloud Tasks CMEK over REST, null empty Bigtable configs by @tas50 in #11673
  • 🐛 digitalocean: read app component routes from ingress rules, null lint results on unlinted clusters by @tas50 in #11672
  • 🎉 aws-14.3.1, gcp-14.4.1, azure-14.3.1, digitalocean-14.2.1, oci-14.2.1, os-14.15.1 by @tas50 in #11677
  • 🐛 aws: fix live-verified field bugs in Bedrock, CloudFront, DataSync, SSM, DocumentDB, Neptune, DMS and Glue by @tas50 in #11682
  • 🎉 aws-14.3.2 by @tas50 in #11683
  • 🐛 macos.gatekeeper: report disabled Gatekeeper instead of an error by @chris-rock in #11679
  • 🐛 os: report a container's own architecture, keep package ids per package by @tas50 in #11619
  • 🎉 os-14.15.2 by @tas50 in #11684
  • ✨ aws: expose tags on 111 more resources by @tas50 in #11674
  • 🎉 aws-14.4.0 by @tas50 in #11685
  • 🐛 os: read space-form -o algorithm options from the sshd listener title by @tas50 in #11541
  • 🐛 hotpatch: Windows 11 Pro can be hotpatch-enrolled; check VBS is running by @czunker in #11648
  • 🧹 Update deps for mql and providers 20261006 by @github-actions[bot] in #11686
  • 🧹 Automate the weekly minor release tag by @czunker in #11687

Full Changelog: v14.2.0...v14.3.0