Repository navigation
v14.3.0
What's Changed
- 🐛 version: stop provider bumps from overwriting dependency MinVersions by @czunker in #11230
- 🐛 opensearch: stop opensearch-go v5 from rerouting to discovered nodes by @czunker in #11231
- 🎉 Release 74 providers by @github-actions[bot] in #11229
- 🐛 windows: drop Uninstall entries superseded in the same directory by @chris-rock in #11227
- ⭐ os: winget, Windows Package Manager presence and SYSTEM usability by @chris-rock in #11224
- ⭐ os: idp.activeDirectory reports the Active Directory domain a device is joined to by @chris-rock in #11226
- 🐛 os: list the macOS apps a partial system_profiler report leaves out by @chris-rock in #11232
- 🐛 os: idp.activeDirectory honors SSSD enabled = false and Samba AD DCs by @chris-rock in #11233
- 🐛 k8s: stop namespace scoping from emptying cluster-scoped collections by @tas50 in #10472
- 🐛 os: don't read another user's program from the scanning user's profile by @chris-rock in #11234
- 🐛 os: decode PowerShell CLIXML stderr in the command transports by @tas50 in #11199
- 🐛 os: parse Windows process flags with Windows command-line rules by @tas50 in #11191
- 🎉 os-14.10.0 by @chris-rock in #11235
- ⭐ azure: VM run commands and patch posture, typed extensions, automation runbooks, SQL MI security, Arc agent config, APIM backends, backup instances by @tas50 in #11222
- ⭐ aws: API Gateway v1 method auth, OpenSearch Serverless, Redshift Serverless, MWAA, backup and snapshot immutability by @tas50 in #11225
- ⭐ gcp: regional firewall policies and secrets, org and folder deny policies, Firebase rules, machine images, NGFW endpoints, SCC custom modules, Secure Web Proxy by @tas50 in #11223
- 🐛 os: reach docker daemons older than API 1.40 in the docker resource by @tas50 in #11156
- ✨ os: elevate with doas when sudo is not installed by @tas50 in #11168
- 🐛 os: report the nft version needed by nftables instead of failing by @tas50 in #11158
- ⭐ hetzner: firewall rules with port ranges and internet exposure, network members by @tas50 in #11239
- ⭐ digitalocean: database engine security settings, Kafka topics, clusterlint diagnostics, App Platform components by @tas50 in #11240
- ⭐ oci: WAF policy rules, identity domain federation and settings, database homes and databases, OS Management Hub by @tas50 in #11242
- ⭐ stackit: CDN, Git, Logs, Valkey, service enablement, Flex access scope and CMEK, observability scrape jobs by @tas50 in #11243
- 🐛 os: read registry value types with reg.exe so hardened hosts report real data by @tas50 in #10391
- 🐛 device/windows: restore disk read-only state, not online state by @tas50 in #8664
- 🐛 config: write through a symlinked config rather than replacing the link by @chris-rock in #10943
- 🐛 os: a WinRM command over the command-line limit fails silently by @tas50 in #10552
- ⭐ alicloud: root account security, access key last use, identity providers, ECS backup and encryption defaults, API Gateway, SSL certificates, PrivateLink by @tas50 in #11245
- 🐛 os: a Windows service that is stopping is StopPending, not Stopped by @chris-rock in #11241
- 🎉 os-14.11.0 by @chris-rock in #11246
- 🎉 hetzner-14.1.0, aws-14.2.0, alicloud-14.2.0, stackit-14.1.0, oci-14.1.0, digitalocean-14.1.0, gcp-14.3.0, azure-14.2.0 by @tas50 in #11266
- 🐛 os: keep Solaris packages from publishers with a dot or hyphen by @tas50 in #11277
- ✨ os: read SMBIOS, hypervisor, CPU clock and root certificates on Solaris by @tas50 in #11276
- ⭐ os: detect network interfaces and routes on Solaris by @tas50 in #11275
- ⭐ os: read zfs on Oracle Solaris by @tas50 in #11272
- ✨ os: read kernel info and modules on Solaris by @tas50 in #11271
- 🐛 os: keep mount sizes when df cannot stat one mount by @tas50 in #11274
- ✨ os: list ports on Solaris by @tas50 in #11270
- ✨ os: list mounts on Solaris by @tas50 in #11273
- ✨ os: read sshd's effective config, ntp.conf and process state on Solaris by @tas50 in #11278
- 🎉 os-14.12.0 by @tas50 in #11279
- ✨ usb: list USB devices on Linux from sysfs by @tas50 in #11151
- 🐛 os: report the Falcon sensor IDs on edr.product from one source by @chris-rock in #11280
- ✨ os: accept a list and
defaultin the id-detector flag by @chris-rock in #11282 - 🐛 ci: start a provider release only on a version change, one per branch at a time by @chris-rock in #11285
- 🎉 os-14.13.0 by @chris-rock in #11286
- 🐛 os: Windows service description is the service's description, not its display name by @chris-rock in #11289
- ✨ mql: version.stripEpoch to compare the upstream release by @tas50 in #11118
- 🐛 os: stop reporting OpenZFS's zed daemon as the Zed editor by @tas50 in #11318
- 📄 AGENTS.md: never identify a customer in commits, PRs or code by @tas50 in #11319
- 🐛 os: match AI tools by the package names scanned assets report by @tas50 in #11320
- 🎉 os-14.13.1 by @github-actions[bot] in #11321
- ⭐ Add native Windows API for services enumeration by @chris-rock in #6474
- 🐛 os: classify registry errors with ADR 046 kinds instead of bare errors and nulls by @chris-rock in #11238
- 🐛 windows: computerInfo fallback reports culture names and processors like Get-ComputerInfo by @chris-rock in #11283
- ⚡ registry: one resource per registry key, whatever the spelling by @chris-rock in #11284
- ✨ windows: add the Uninstall entry's ProductCode, UpgradeCode or AppId to package urls by @chris-rock in #11325
- ⚡ windows: look up each optional feature once per scan by @chris-rock in #11287
- 🐛 os: packages.installDate on local Windows scans by @chris-rock in #11288
- 🐛 registry: read every value kind the same on the native and PowerShell paths by @chris-rock in #11290
- 🧹 Update deps for mql and providers 20260930 by @github-actions[bot] in #11322
- 🐛 os: detect RHCOS on OpenShift 4.19+ by @tas50 in #11327
- 🎉 os-14.14.0 by @tas50 in #11328
- 🌟 claude: RBAC groups and roles, effective spend limits, plugins, external keys, compliance state by @tas50 in #11331
- ⭐ aws: expose fields unlocked by the latest SDK bump by @tas50 in #11332
- ⭐ oci: DRG NAT policies, DRG attachment NAT settings, Data Safe target features by @tas50 in #11330
- ⭐ azure: AKS cluster-wide FIPS and Kubernetes resource object encryption by @tas50 in #11329
- 🐛 ms365: fetch service principal assignments and managed device detail fields, read settings catalog children and current Autopilot properties by @tas50 in #11337
- 🐛 ms365: include compromised risky users, fix DLP sensitive info types, app owners and license detail ids by @tas50 in #11338
- 🐛 ms365: fix dict fields that fail to serialize and a cross-tenant policy panic by @tas50 in #11336
- 🐛 ms365: key the credential cache on the credential, not only tenant and client by @tas50 in #11335
- 🐛 ms365: stop failed lookups from reading as empty lists or false by @tas50 in #11339
- 🟢 Unblock CI: skip zoom.us docs in link check, fix flaky ms365 role test by @tas50 in #11353
- ⭐ ms365: workload identity trust on apps and service principals by @tas50 in #11347
- ⭐ ms365: active PIM role assignments and PIM for Groups instances by @tas50 in #11354
- ⭐ ms365: Exchange Online and Defender XDR unified RBAC roles and assignments by @tas50 in #11355
- ⭐ ms365: Identity Protection for workload identities by @tas50 in #11351
- 🐛 ms365: fix test package build after concurrent merges by @tas50 in #11357
- ⭐ ms365: on-premises directory synchronization settings and features by @tas50 in #11345
- ⭐ ms365: external identity providers and B2B self-service sign-up user flows by @tas50 in #11344
- 🟢 ms365: fix test build on main, classify 401/429/5xx Graph errors by @tas50 in #11356
- ⭐ ms365: cross-tenant access policy partner configurations by @tas50 in #11340
- ⭐ ms365: Entra administrative units with members and scoped role assignments by @tas50 in #11341
- ⭐ ms365: token lifetime, claims mapping, token issuance and home realm discovery policies by @tas50 in #11342
- ⭐ ms365: tenant report settings, people settings, and service health by @tas50 in #11343
- ⭐ ms365: authentication strength, authentication flows, and feature rollout policies by @tas50 in #11346
- ⭐ ms365: Entra directory audit and provisioning logs by @tas50 in #11348
- ⭐ ms365: Windows LAPS and BitLocker key escrow metadata by @tas50 in #11349
- ⭐ ms365: Entra entitlement management settings, catalogs, access packages and assignment policies by @tas50 in #11350
- ⭐ ms365: terms of use, lifecycle workflows, custom security attributes by @tas50 in #11352
- 🐛 os: read ZFS pools, vdevs and version on ZFS on Linux before 0.8 by @tas50 in #11364
- 🐛 os: parse.openpgp accepts a file path again by @tas50 in #11363
- 🐛 os: report com2sec communities, snmpd.local.conf, and rwuser -s names in snmpd.config by @tas50 in #11360
- 🐛 os: exim.localInterfaces reports all interfaces when unset, reads exim4.conf, resolves macros by @tas50 in #11365
- 🐛 os: start journald.config settings from the defaults journald was built with by @tas50 in #11375
- 🐛 os: list mount points with spaces and tell overmounted paths apart by @tas50 in #11380
- 🐛 os: find loaded kernel modules by dashed name by @tas50 in #11386
- 🐛 os: report an unreadable Open vSwitch database as an error, not an empty switch by @tas50 in #11393
- 🐛 ms365: use types.String for identity provider domains and risk keyIds by @tas50 in #11394
- 🐛 os: ufw reads removed packages as not installed, parse route and commented rules by @tas50 in #11395
- 🐛 os: an unlistable ~/.ssh or polkit directory is an error, not empty by @tas50 in #11388
- 🐛 os: apply exports(5) defaults and last-wins to Linux NFS exports by @tas50 in #11389
- 🐛 os: read modprobe.d the way kmod does by @tas50 in #11385
- 🐛 os: read systemd.timer.onCalendar from TimersCalendar by @tas50 in #11384
- 🐛 os: error when nft cannot read the ruleset, list nftables maps by @tas50 in #11378
- 🐛 os: list stopped Docker containers in docker.containers by @tas50 in #11373
- 🐛 haproxy: read the config files haproxy loads, and classic peer lines by @tas50 in #11371
- 🐛 ms365: keep Graph durations in days form and stop Kiota duration panics by @tas50 in #11399
- 🐛 ms365: resolve 15 listed resources when queried directly by id by @tas50 in #11401
- 🟢 os: drop embedded field from selector in listing test by @tas50 in #11408
- 🐛 ms365: skip a single failed group in PIM for Groups lists, read chunks concurrently by @tas50 in #11409
- 🐛 os: replace the archived WMI library with microsoft/wmi, and fall back to PowerShell on WMI errors by @chris-rock in #11291
- 🐛 os: docker.file stage.hasHealthcheck is false for HEALTHCHECK NONE by @tas50 in #11415
- 🐛 os: read lsblk and LUKS volumes on util-linux without --json by @tas50 in #11416
- 🐛 os: keep every apt.repo line, ignore trailing comments, read apt.config keys case-insensitively by @tas50 in #11411
- 🐛 ms365: report includeTargets on authentication method configurations by @tas50 in #11424
- 🐛 ms365: read quarantine policy end-user permissions from EndUserQuarantinePermissions by @tas50 in #11423
- 🐛 os: podman port hostIp is 0.0.0.0 for all interfaces, podman < 2.0 errors instead of guessing by @tas50 in #11418
- 🐛 os: Windows network routes from the target, over SSH too, and the same on both paths by @chris-rock in #11292
- 🐛 windows: read the firewall from the ActiveStore, including rules delivered by Group Policy by @chris-rock in #11293
- 🟢 ci: run every Windows-only test, and vet the Windows build of the os provider by @chris-rock in #11294
- 🟢 ci: check GitHub file links through raw.githubusercontent.com by @chris-rock in #11459
- 🐛 os: encode the GCE metadata crawl on Windows, and read Hetzner metadata on Windows by @chris-rock in #11295
- 🧹 os: PowerShell helpers fail loudly, quote safely, and accept a single environment variable by @chris-rock in #11296
- 🐛 os: decode PowerShell lists with one element as a list by @chris-rock in #11297
- 🐛 os: list Windows processes without elevation, and resolve process(pid) by @chris-rock in #11298
- ⭐ os: collect UDP ports on Windows, and report bound TCP sockets as bound by @chris-rock in #11299
- 🐛 os: read AppArmor 3.0.8's aa-status JSON and 2.12's process shape, list only confined processes by @tas50 in #11472
- 🐛 os: read interface flags and state from sysfs as the kernel writes them by @tas50 in #11446
- 🐛 os: a registry key exists whether or not it holds values by @chris-rock in #11300
- 🐛 os: selinux reads sysfs booleans correctly, lists disabled modules with their priority, and reads mode from the running kernel by @tas50 in #11444
- 🐛 os: list limits.d files in pam_limits' order, skip what its glob skips by @tas50 in #11471
- 🐛 os: read the inetd and ntp configs Debian's daemons read, report ntp pools and peers by @tas50 in #11470
- 🐛 os: apt.config trust options count apt-get's and apt's Binary overrides by @tas50 in #11465
- 🐛 os: podman.image repoDigests, os and architecture from podman image inspect, one image per ID by @tas50 in #11457
- 🐛 os: report the running sshd's command-line options in effective*, keep every included multi-value keyword by @tas50 in #11442
- 🐛 os: fail sshd.config on an unreadable Include, run sshd -T with -C on OpenSSH 7.9 by @tas50 in #11464
- 🐛 os: read yum.repo ids and names on RHEL 7, yum.vars on RHEL 7 and dnf5, yum.config as dnf resolves it by @tas50 in #11445
- 🐛 os: polkit.installed requires polkitd or its tools, not just action files by @tas50 in #11443
- 🐛 os: report cgroup v1 controllers from /proc/cgroups, null list on v1 by @tas50 in #11438
- 🐛 os: read os.base.lastUpdate from dnf5's transaction history by @tas50 in #11440
- 🐛 os: firewalld reads forward ports on 0.9+, reports the FAILED state (0.4 included), and finds rich rule actions followed by options by @tas50 in #11435
- 🐛 os: find kernel-core kernels, count needs-restarting reboots, parse /proc/cmdline per parameter by @tas50 in #11431
- 🐛 os: keep every value of a repeated boot parameter, expand BLS initrd, report refused GRUB reads by @tas50 in #11439
- 🐛 os: read zypper needs-rebooting's 102 as a pending reboot by @tas50 in #11473
- 🐛 os: drop inline comments from sudoers entries, keep #uid users by @tas50 in #11482
- 🐛 os: selinux.mode reads "disabled" on a running host without SELinux by @tas50 in #11484
- 🐛 os: take SUSE's asset.cpes from os-release CPE_NAME by @tas50 in #11476
- 🐛 os: containerd.containers through docker's bundled containerd and SUSE's containerd-ctr, pid 0 for stopped tasks by @tas50 in #11463
- 🐛 os: mondoo.eol needs a product and version, a copied /etc/localtime beats a stale /etc/timezone by @tas50 in #11460
- 🐛 mongodb: report the server's auth defaults and honor net.bindIpAll by @tas50 in #11450
- 🐛 os: read os.lastUpdate on SUSE from zypper's history log by @tas50 in #11479
- 🐛 os: report httpd's defaults for unset ServerTokens, ServerSignature and TraceEnable by @tas50 in #11454
- 🐛 os: read the bind9 configuration named loads with -c, find DNSSEC keys in zone key-directory by @tas50 in #11462
- ⚡ os: detect the Windows hypervisor from the natively read SMBIOS data by @chris-rock in #11302
- 🐛 os: never start systemd-timesyncd when reading systemd.timesyncd by @tas50 in #11456
- 🐛 os: read inline realm usernames and keep jboss(home:) to its own installation by @tas50 in #11461
- 🐛 os: read the logrotate.d files SUSE's logrotate reads by @tas50 in #11492
- 🐛 os: read xinetd service blocks in inetd.config instead of making up service names by @tas50 in #11491
- 🐛 os: report string results like 'yes' in polkit.rule.results by @tas50 in #11488
- 🐛 os: report a missing explicit snmpd.config path as an error by @tas50 in #11485
- 🐛 os: read AIDE configurations the way AIDE does: built-in groups, @@if, restricted and "-" rules, x_include scripts, unreadable aide.conf by @tas50 in #11441
- 🐛 os: read the mongod.conf the mongod service is started with by @tas50 in #11480
- 🐛 os: apply login.defs.d drop-ins to logindefs.params on SUSE by @tas50 in #11477
- 🐛 os: find lvm and zfs tools off a non-root PATH, report refused lvm reports by @tas50 in #11434
- 🐛 os: report an unreadable sudoers includedir instead of skipping it by @tas50 in #11487
- ⚡ windows: optional features through the DISM API, behind MONDOO_WINDOWS_NATIVE by @chris-rock in #11303
- 🐛 os: read the cron files cron runs and the rsyslog files rsyslog includes, report the ones the scan cannot read by @tas50 in #11433
- ⚡ windows: read the local security policy natively on a local scan by @chris-rock in #11304
- 🐛 os: resolve a systemd unit symlink with Unix paths on a Windows scanner by @chris-rock in #11496
- 🐛 os: search SUSE's /srv/www/htdocs for WordPress plugins and Composer files by @tas50 in #11495
- 🐛 os: find jars in /usr/share/java package subdirectories by @tas50 in #11494
- 🐛 os: continue postfix logical lines across comment and blank lines by @tas50 in #11483
- 🐛 os: list tomcat webapps deployed as symlinked directories by @tas50 in #11478
- 🐛 os, network: read trust-store roots with a negative serial number by @tas50 in #11466
- 🐛 os: take a jar's Maven groupId from its pom.properties path when the file has none by @tas50 in #11455
- 🐛 ms365: report Teams federation allow-all and stop inventing false meeting policy fields by @tas50 in #11429
- 🐛 ms365: name APIConnectors.Read.All when Graph refuses a user flow's API connectors by @tas50 in #11419
- 🐛 githubactions: inventory reusable workflows called with a job-level uses by @tas50 in #11407
- 🐛 os: report a WordPress plugin's installed version from its main file by @tas50 in #11392
- 🐛 os: report cassandra.version for tarball installs by @tas50 in #11449
- 🐛 os: resolve relative sudoers includes like sudo, skip includedir subdirectories by @tas50 in #11432
- 🐛 os: evaluate Exim's built-in macros, doubled list separators, Debian's listening interfaces and .include in exim by @tas50 in #11426
- 🐛 os: list each Java truststore once, find SUSE's store under /var/lib/ca-certificates by @tas50 in #11425
- 🐛 os: ufw reads Fedora/EPEL rules from /var/lib/ufw and reports status from the loaded firewall by @tas50 in #11422
- 🐛 ms365: resolve the user behind an Exchange Online shared mailbox by @tas50 in #11414
- 🐛 os: read only the modprobe.d directories the installed kmod reads by @tas50 in #11417
- 🐛 ms365: key app roles on their parent so shared role IDs keep their own text by @tas50 in #11413
- 🐛 ms365: report Graph's year-1 "never set" timestamps as null by @tas50 in #11421
- 🐛 os: read /etc/default/grub.d drop-ins into grub.config.params on the Debian family by @tas50 in #11400
- 🐛 os: read PKCS#12 keystore aliases and trusted certificates by @tas50 in #11362
- 🐛 os: keep every command and the runas spec in sudoers.userSpecs by @tas50 in #11367
- 🐛 os: keep every load_module in nginx.conf.params and list the modules nginx runs in nginx.modules by @tas50 in #11428
- 🐛 os: keep iptables negation and report non-root refusals by @tas50 in #11376
- 🐛 os: read my.cnf option groups, prefixes and defaults the way the server does by @tas50 in #11405
- 🐛 os: read systemd.resolved on every systemd release, with its drop-ins by @tas50 in #11377
- 🐛 os: detect passphrase-protected OpenSSH and PKCS#8 private keys by @tas50 in #11369
- 🐛 os: evaluate apache2 /, keep # inside arguments, read httpd's unit environment and launch arguments (SUSE sysconfig) by @tas50 in #11361
- 🐛 chrome: read extensions from Preferences and Secure Preferences by @tas50 in #11404
- 🐛 os: read every key of armored and binary OpenPGP keyrings in parse.openpgp by @tas50 in #11430
- 🐛 os: report a refused grub.cfg instead of SUSE's EFI stub, read BLS entries on the ESP by @tas50 in #11481
- 🐛 os: parse multi-pair ENV/ARG, registry ports and EXPOSE in docker.file by @tas50 in #11374
- 🐛 os: report the patches zypper holds back behind a package manager update in os.updates by @tas50 in #11475
- 🐛 os: read Windows group members, including orphaned SIDs by @chris-rock in #11306
- 🐛 postgresql: find RHEL and SUSE clusters the server runs, follow hba_file, report refusals by @tas50 in #11452
- 🐛 os: read systemd units on systemd 219/232, SysV enablement on RHEL 7 and Debian by @tas50 in #11420
- 🐛 os: report held, kept-back and foreign-arch deb updates in package.available by @tas50 in #11410
- 🐛 os: end Gemfile.lock sections at every header, read GIT and PATH gems by @tas50 in #11398
- 🐛 npm: parse classic yarn.lock with mixed-quote headers and yarn berry lockfiles by @tas50 in #11383
- 🐛 os: read LuaRocks rock trees instead of Lua module directories by @tas50 in #11382
- 🐛 os: read Flathub Firefox's systemconfig policy file, stop crediting /etc/firefox to it by @tas50 in #11486
- 🐛 os: read the modification time, not the access time, from stat over SSH --sudo by @tas50 in #11453
- 🐛 os: read systemd.unit capability, syscall filter and address family lists as systemd means them by @tas50 in #11372
- 🐛 os: keep systemd.targets runtime state when a template target exists by @tas50 in #11370
- 🐛 os: keep Match-block values out of sshd.config.params by @tas50 in #11358
- 🐛 os: find snap, flatpak and XDG Firefox and Chromium profiles by @tas50 in #11403
- 🐛 os: identify the MySQL/MariaDB server by its binary, redact option file passwords by @tas50 in #11451
- 🐛 os: read claude, codex and ollama versions when sudo's PATH misses /usr/local/bin by @tas50 in #11448
- ⚡ os: read Windows users and groups natively by @chris-rock in #11307
- 🐛 os: report a systemd service looked up by an alias with its unit's state by @tas50 in #11359
- ⚡ windows: read computerInfo natively behind MONDOO_WINDOWS_NATIVE by @chris-rock in #11308
- 🐛 os: report the nginx settings each server runs with, from the config nginx loads by @tas50 in #11497
- 🐛 os: keep the word after a --flag=value out of that flag's value by @tas50 in #11490
- 🐛 network: stop tls() probing SSLv3 ciphers forever against OpenSSL 1.0.2 by @tas50 in #11427
- ⚡ os: run PowerShell in the SSH server's own shell on Windows by @chris-rock in #11309
- 🐛 os: elevate every command of a compound line under --sudo by @tas50 in #11379
- ⚡ registry: read the policy roots in one PowerShell run over remote connections by @chris-rock in #11311
- ✨ os: date dpkg packages from their file-list mtime by @tas50 in #11162
- 🐛 network: report a cookie's name when its value is empty by @tas50 in #10461
- ⚡ os: limit the commands that run at once over SSH on Windows by @chris-rock in #11312
- ⚡ os: persistent PowerShell session per SSH connection on Windows by @chris-rock in #11313
- ⭐ windows: auditpol settings in English, the same natively and through auditpol by @chris-rock in #11314
- ⚡ os: detect Windows first on an OpenSSH for Windows server by @chris-rock in #11315
- ✨ os: kernel.parameter with live and configured sysctl values by @chris-rock in #11498
- 🐛 os: probe rpm and resolve binaries without the
commandbuiltin under --sudo by @tas50 in #11489 - 🐛 os: skip SUSE's ipv6-localhost and ipv6-loopback when resolving the hostname by @tas50 in #11474
- 🐛 os: quote the IMDS token in the Windows metadata command by @chris-rock in #11316
- 🐛 os: run brew as the Homebrew owner when scanning as root by @tas50 in #11412
- 🐛 os: report a failed rpm update check as an error, keep multilib and arch-changing updates by @tas50 in #11436
- ⚡ os: run staged scripts and plain commands in the PowerShell session by @chris-rock in #11317
- ⚡ os: check the Windows 10 ESU license with one property over PowerShell by @chris-rock in #11323
- 🐛 os: read OpenSSH-format DSA private keys from their unencrypted header by @tas50 in #11468
- 🐛 os: apply systemd type-level and prefix drop-ins to a unit's environment by @tas50 in #11447
- 🐛 os: parse SKILL.md allowed-tools per the Agent Skills spec by @tas50 in #11402
- 🐛 os: list dotfiles and odd names over SSH --sudo by @tas50 in #11390
- 🐛 os: keep apt's solver log out of the package update dry run by @tas50 in #11108
- 🐛 claude.code: read the live .claude.json before falling back to backups by @tas50 in #11387
- 🐛 os: systemd reads type-level drop-ins since 244, not 246 by @tas50 in #11511
- 🐛 os: key Firefox addons on the profile directory, read absolute profiles by @tas50 in #11572
- 🐛 os: read systemd releases before 231 from the manager binary by @tas50 in #11569
- ✨ os: report per-source trust options on apt.repo by @tas50 in #11566
- 🐛 os: compare Amazon Linux kernels without their epoch, list kernel6.x packages by @tas50 in #11604
- 🐛 os: os.machineid is null without a machine-id file, ALT takes its CPE from os-release by @tas50 in #11620
- 🐛 os: read the apk database on OpenWrt snapshots that moved off opkg by @tas50 in #11617
- 🐛 os: read Azure Linux distroless packages from the rpm manifest, error without a database by @tas50 in #11609
- 🐛 haproxy.config: follow the haproxy that runs without a pid file, and the image's command by @tas50 in #11605
- 🐛 os: no reboot is pending inside a container by @tas50 in #11593
- 🐛 os: name interfaces without the @peer suffix iproute2 prints by @tas50 in #11615
- 🐛 os: report apk and xbps updates, and fail the check when no index was read by @tas50 in #11595
- 🐛 os: report snaps the store has a newer revision of as outdated by @tas50 in #11562
- 🐛 os: list Tomcat apps deployed by context descriptors and server.xml Contexts by @tas50 in #11561
- 🐛 os: read auditd rules.d the way augenrules concatenates it by @tas50 in #11557
- 🐛 os: report an unreadable kubelet config instead of kubelet's defaults by @tas50 in #11553
- 🐛 os: ufw.status never reads "active" from ufw.conf alone by @tas50 in #11551
- 🐛 os: report a local scan inside a container as a container by @tas50 in #11600
- 🐛 os: read pacman install dates and every license, and apk world pins by @tas50 in #11627
- 🐛 ollama.config: read the environment the server runs with by @tas50 in #11626
- 🐛 postgresql.conf: apply the postmaster's -c settings over the file by @tas50 in #11621
- 🐛 os: scan the file given to docker tar and container tar by @tas50 in #11624
- 🐛 os: detect the platform and arch of a local scan on an image without a shell by @tas50 in #11623
- 🐛 os: read crontab with cronie's rules on Amazon Linux by @tas50 in #11630
- 🐛 os: os.rootCertificates errors when no trust bundle could be read by @tas50 in #11622
- 🐛 os: firefox.policies needs a Firefox binary, not just its install directory by @tas50 in #11634
- 🐛 os: systemd.resolved.resolvConfMode is null when systemd does not report it by @tas50 in #11633
- 🐛 os: aide.installed needs the aide binary, null version without one, reject '-' rules before AIDE 0.19 by @tas50 in #11519
- 🐛 redisdb, mssql, clickhousedb, elasticsearch, opensearch: accept the positional host, fail fast by @tas50 in #11592
- 🐛 os: read authorized_keys lines of any length, error instead of truncating by @tas50 in #11594
- 🐛 mssql: list offline databases, name permission securables, complete role and login rows by @tas50 in #11591
- 🐛 mongo, cassandra: accept the positional host, render parameter arrays as JSON by @tas50 in #11587
- 🐛 mysqldb: TLS state on MySQL 8.4+, routine/column/proxy grants, manifest keyrings by @tas50 in #11586
- 🐛 redisdb: read requirepassSet from the default user, honor optional bind addresses by @tas50 in #11582
- ⚡ os: find JBoss systemd units with one grep and scan them once per connection by @tas50 in #11577
- 🐛 opensearch: error instead of an empty list when the scanner cannot read by @tas50 in #11585
- 🐛 os: read cron and logrotate files the way the installed daemons do by @tas50 in #11578
- 🐛 os: key jenkins and wordpress packages on their plugin file by @tas50 in #11602
- 📄 agents: tests live in the test file named after the source file by @tas50 in #11636
- 🐛 mssql: error instead of a partial or empty list when the scanner cannot read by @tas50 in #11589
- 🐛 cassandra: refused role reads are errors, and resolve superuser status through grants by @tas50 in #11584
- 🐛 mysqldb: connect timeouts, TLS mode semantics, classified connect errors by @tas50 in #11588
- 🐛 elasticsearch: error instead of an empty list when the scanner cannot read by @tas50 in #11580
- 🐛 redisdb: error instead of an empty list or null when the credential is refused by @tas50 in #11581
- 🐛 os: keep systemctl's JOB column out of service, timer and socket descriptions by @tas50 in #11632
- 🐛 redisdb: scan servers without CONFIG and servers that require a client certificate by @tas50 in #11583
- 🐛 os: keep every priority of an SELinux module in selinux.modules by @tas50 in #11638
- 🐛 os: ufw reads the upstream tarball install in /usr/local/sbin as installed by @tas50 in #11637
- 🐛 apache2.conf: follow the httpd an image runs, with or without a pid file by @tas50 in #11629
- 🐛 clickhousedb: error instead of an empty list when the scanner cannot read by @tas50 in #11575
- 🐛 postgresql.conf: apply postgresql.auto.conf (ALTER SYSTEM) by @tas50 in #11573
- 🐛 mysqldb: read MariaDB accounts, replication, encryption and identity by @tas50 in #11579
- 🐛 postgresdb: connect to PostgreSQL 9.2-9.5 and tolerate version-specific catalog columns by @tas50 in #11574
- 🐛 os: gate resolved settings and boot paths on what systemd supports, read 219's socket listeners by @tas50 in #11570
- 🐛 os: read modprobe.d lines like libkmod (continuations, CR) by @tas50 in #11563
- ✨ clickhousedb: add user and role roles, fix grant-option revokes and XML hasPassword by @tas50 in #11590
- 🐛 postgresdb: key and order hbaRules by file and rule number on PG 16+ by @tas50 in #11559
- 🐛 mongo: report a refused command as an error, not as a default posture by @tas50 in #11564
- 🐛 mongo: keep a mongodb:// password out of the asset name and platform id by @tas50 in #11560
- 🐛 mongo: audit the server you name, and flag custom roles that are root in all but name by @tas50 in #11576
- 🐛 mysqldb: key privilege rows by grantee and plugin rows by type by @tas50 in #11555
- 🐛 java: read an OpenSSL -nokeys PKCS#12 bundle instead of blaming the password by @tas50 in #11549
- 🐛 lua: stop reading a rock tree as a rocks directory when it has no rocks by @tas50 in #11608
- 🐛 os: read bind9's -c inside its -t chroot; haproxy http-check send and httpchk defaults by @tas50 in #11546
- 🐛 java: attach a PKCS#12 key's certificate chain to the key's entry by @tas50 in #11544
- 🐛 os: read sudoers.d/README like sudo does; null, not an error, for a key that cannot be decoded by @tas50 in #11542
- 🐛 mysqldb: error instead of an empty list when the scanner cannot read by @tas50 in #11565
- 🐛 postgresdb: redact every libpq password form in subscription connection strings by @tas50 in #11558
- 🐛 mongodb.conf: follow the mongod that runs, and its command line by @tas50 in #11547
- 🐛 os: nginx TLSv1.3 default on RHEL 8/9, add_header without always, out-of-tree modules by @tas50 in #11532
- 🐛 postgresdb: report default grants when an object's ACL is NULL by @tas50 in #11556
- 🐛 os: apply /etc/login.defs.d where useradd links libeconf (RHEL 10, Fedora) by @tas50 in #11529
- 🐛 opam: skip commented-out dependencies in depends lists by @tas50 in #11531
- 🐛 mysql.conf, mariadb.conf: read the option files, groups and persisted settings the server uses by @tas50 in #11521
- 🐛 os: report a refused /etc/default/grub and secboot config.json as refused, not absent by @tas50 in #11525
- 🐛 os: expand $VAR in /etc/default/grub and its drop-ins like grub-mkconfig's shell by @tas50 in #11513
- 🐛 os: run sudo -V and visudo -c in the C locale by @tas50 in #11514
- 🐛 os: report a sniffer's PROMISC from
ip, and LOWER_UP from sysfs, so both interface detectors agree by @tas50 in #11516 - 🐛 mycnf: read option groups, fragment names and plugin lists as the server does by @tas50 in #11510
- 🐛 ai.model: name Ollama models like ollama list, key models on their path by @tas50 in #11506
- 🐛 os: list yum repos in the C locale so a non-English locale doesn't empty them by @tas50 in #11508
- 🐛 os: read httpd's -f from its unit, evaluate IfVersion and IfFile, apply type-level drop-ins by @tas50 in #11523
- 🐛 os: find lvm, mdadm and cryptsetup off PATH and under sudo, run lvm in the C locale, report failed mdadm and cryptsetup runs by @tas50 in #11543
- 🐛 os: error on a missing explicit exim, squid, postfix and tomcat path; no jboss version from a missing dir by @tas50 in #11540
- 🐛 ruby: list a gem resolved for several platforms once by @tas50 in #11538
- 🐛 lua: report the rockspec for rocks luarocks lists, as for rocks read from disk by @tas50 in #11545
- 🐛 os: don't date a deb package by its trigger runs by @tas50 in #11502
- 🐛 os: decode podman 3 port mappings, podman.installed false only when podman is missing by @tas50 in #11503
- 🐛 os: reject an AIDE configuration that names an undefined group by @tas50 in #11610
- 🐛 os: evaluate docker.file variables, heredocs and port ranges the way BuildKit does by @tas50 in #11499
- 🐛 cassandra, mysql.conf, mariadb.conf: a refused config directory is not an absent product by @tas50 in #11536
- 🐛 os: keep Debian derivatives and Debian without os-release in the debian family, handle sid by @tas50 in #11625
- 🐛 os: read commented gemini settings, native Claude Code versions, refused Firefox profiles by @tas50 in #11524
- 🐛 os: decode octal escapes and quotes in fstab and exports paths, skip malformed fstab lines and hidden exports fragments by @tas50 in #11548
- ⭐ os: expand PAM includes into pam.conf.service.stack, count [success=N default=ignore] as enabled by @tas50 in #11641
- ✨ os: report rebootpending on openEuler, EulerOS and Huawei Cloud EulerOS by @tas50 in #11642
- Bump crate-ci/typos from 1.50.2 to 1.50.3 by @dependabot[bot] in #11645
- Bump dawidd6/action-download-artifact from 24 to 25 by @dependabot[bot] in #11644
- Bump the codeql-action group with 3 updates by @dependabot[bot] in #11643
- 📄 ADR 049: tell OS packages from third-party software (package.osProvided) by @tas50 in #11646
- 👷 ci: stop the release gate failing commits that have no test run yet, or need none by @chris-rock in #11649
- 🧹 os: refresh the IEEE OUI table 20261005 by @github-actions[bot] in #11651
- 📄 docs: providers built from the root module run go mod tidy at the root by @chris-rock in #11653
- ⭐ os: let the server switch on the native Windows paths by @chris-rock in #11654
- ✨ windows: report the installer and per-user install scope on package urls by @chris-rock in #11650
- 🧹 os: bump to 14.15.0-rc.1 (os-14.15.0-rc.1) by @chris-rock in #11655
- 🐛 windows: report 64-bit apps registered under Wow6432Node with their real architecture by @chris-rock in #11656
- 🐛 os: match AIDE's @@ifhost and HOSTNAME against the full node name by @tas50 in #11530
- ✨ windows: report Squirrel and Chromium installers on package urls by @chris-rock in #11658
- 🐛 login: exit 1 when the token is expired or invalid by @vjeffrey in #11657
- 🧹 Update deps for mql and providers 20261005 by @github-actions[bot] in #11652
- 🐛 llx: compound where blocks on a string dict no longer panic by @vjeffrey in #11659
- 📄 google-workspace: add GOOGLEBOOK to endpoint device types by @tas50 in #11661
- ✨ databricks: maintenance notification targets and job environment variable names by @tas50 in #11665
- ✨ hetzner: report why a load balancer target health check fails by @tas50 in #11662
- ✨ slack: IdP provisioning and lock flags on user groups by @tas50 in #11663
- ✨ cloudflare: token provisioner, Access strict service-token auth, logpush attack-traffic filter by @tas50 in #11664
- ✨ gcp: WildFire and partial-response settings on firewall endpoints, Cloud SQL CMEK log encryption, policy association priority by @tas50 in #11666
- ✨ aws: Cognito ACR mapping and levels, Transfer workflow log groups by @tas50 in #11667
- 🎉 slack-14.1.0, cloudflare-14.2.0, gcp-14.4.0, azure-14.3.0, aws-14.3.0, hetzner-14.2.0, ms365-14.1.0, oci-14.2.0, claude-14.1.0, stackit-14.2.0, digitalocean-14.2.0, k8s-14.1.0, google-workspace-14.0.2, mssql-14.0.2, mysqldb-14.0.2, postgresdb-14.0.2, redisdb-14.0.2, mongo-14.0.2, cassandra-14.0.2, clickhousedb-14.0.2, elasticsearch-14.0.2, opensearch-14.0.2, snowflake-14.0.2, weaviate-14.0.2 by @tas50 in #11668
- 🎉 os-14.15.0 by @tas50 in #11660
- 🐛 os: don't mount the EFI system partition behind an untriggered automount when reading boot entries by @tas50 in #11537
- 🐛 os: list template instances in systemd.timers and systemd.sockets by @tas50 in #11631
- 🐛 oci: list DRG attachments in the DRG's compartment, include automatic database backups by @tas50 in #11675
- 🐛 aws: read AgentCore payment manager tags from ListTagsForResource by @tas50 in #11670
- 🐛 azure: read run command execution results and runbook details from a GET by @tas50 in #11671
- 🐛 gcp: resolve versioned KMS keys, read Cloud Tasks CMEK over REST, null empty Bigtable configs by @tas50 in #11673
- 🐛 digitalocean: read app component routes from ingress rules, null lint results on unlinted clusters by @tas50 in #11672
- 🎉 aws-14.3.1, gcp-14.4.1, azure-14.3.1, digitalocean-14.2.1, oci-14.2.1, os-14.15.1 by @tas50 in #11677
- 🐛 aws: fix live-verified field bugs in Bedrock, CloudFront, DataSync, SSM, DocumentDB, Neptune, DMS and Glue by @tas50 in #11682
- 🎉 aws-14.3.2 by @tas50 in #11683
- 🐛 macos.gatekeeper: report disabled Gatekeeper instead of an error by @chris-rock in #11679
- 🐛 os: report a container's own architecture, keep package ids per package by @tas50 in #11619
- 🎉 os-14.15.2 by @tas50 in #11684
- ✨ aws: expose tags on 111 more resources by @tas50 in #11674
- 🎉 aws-14.4.0 by @tas50 in #11685
- 🐛 os: read space-form -o algorithm options from the sshd listener title by @tas50 in #11541
- 🐛 hotpatch: Windows 11 Pro can be hotpatch-enrolled; check VBS is running by @czunker in #11648
- 🧹 Update deps for mql and providers 20261006 by @github-actions[bot] in #11686
- 🧹 Automate the weekly minor release tag by @czunker in #11687
Full Changelog: v14.2.0...v14.3.0