v13.30.0
What's Changed
- 🐛 ci: unblock tflint plugin install after GitHub attestation API change by @tas50 in #3076
- ✨ aws/oci: map 5 cloud AI checks to NIST AI 100-1 by @tas50 in #3074
- ✨ stackit: add compliance tags to 33 security checks by @tas50 in #3072
- 🐛 Fix compliance tag mappings for nis-2, vda-isa-5 and bsi-sys-1-5 by @tas50 in #3073
- 🐛 aws: overhaul terraform-hcl variants to match live AWS scan results by @AdamVB in #3069
- 🐛 aws: fix malformed nist-ai-100-1 compliance tag (invalid control id) by @tas50 in #3078
- 📄 dedup Generated-code section and add null && null MQL gotcha to CLAUDE.md by @tas50 in #3079
- ✨ aws/azure/gcp: add 16 AI-service security checks by @tas50 in #3080
- ✨ Add
cnspec uploadfor third-party scan reports (hidden/experimental) by @chris-rock in #3081 - Bump the gomodupdates group with 3 updates by @dependabot[bot] in #3086
- Bump crate-ci/typos from 1.47.2 to 1.48.0 by @dependabot[bot] in #3085
- Bump slackapi/slack-github-action from 3.0.3 to 3.0.5 by @dependabot[bot] in #3084
- Bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.0 by @dependabot[bot] in #3082
- ✨ cnspec upload: SBOM formats (CycloneDX/SPDX) via platform scan by @chris-rock in #3088
- ✨ cnspec upload: OWASP DefectDojo Generic Findings Import (JSON + CSV) by @chris-rock in #3091
- ✨ cnspec upload: JUnit XML converter by @chris-rock in #3092
- ✨ cnspec upload: OWASP ZAP XML converter (DAST) by @chris-rock in #3093
- ✨ cnspec upload: Burp Suite XML converter (DAST) by @chris-rock in #3094
- ✨ converters: first-class evidence (HttpRequest for DAST, code location for SARIF) by @chris-rock in #3095
- 🐛 converters: fix status mapping, HTTP evidence, and id collisions by @chris-rock in #3099
- 🐛 SARIF: keep NONE severity + document error→HIGH mapping by @chris-rock in #3100
- ✨ Refresh asset scores endpoint proto &
platformids-excludeoption by @slntopp in #3101 - 🧹 Bump mql to v13.30.0 by @mondoo-mergebot[bot] in #3102
Full Changelog: v13.29.2...v13.30.0