Skip to content

v13.33.0

Choose a tag to compare

@mondoo-mergebot mondoo-mergebot released this 11 Aug 19:02
· 263 commits to main since this release
3dce59a

What's Changed

  • 🧹 bump mql to v13.32.2 by @arlimus in #3164
  • 🧹 docs: move ambiguous-path MQL gotcha from mql skill to CLAUDE.md by @preslavgerchev in #3166
  • ✨ content: add Mondoo MariaDB Security policy by @tas50 in #3152
  • ✨ content: add Mondoo MySQL Security policy by @tas50 in #3151
  • Bump docker/login-action from 4.4.0 to 4.5.1 by @dependabot[bot] in #3157
  • ✨ content: add GCP primitive-role, GKE Binary Authorization, and lien checks by @tas50 in #3170
  • ✨ content: add AWS IAM trust policy, RDS patching/logging, and EKS access checks by @tas50 in #3169
  • 🐛 aws: skip CloudTrail bucket checks when the bucket is unreadable cr… by @AdamVB in #3161
  • 🧹 ci: bump pinned CLIs in the remediation validator job by @tas50 in #3171
  • ✨ reporter: bring SARIF output up to the detail level of JUnit detailed by @AdamVB in #3172
  • 🐛 executor: make score error messages deterministic by @preslavgerchev in #3179
  • Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.106.2 to 1.106.5 in the gomodupdates group across 1 directory by @dependabot[bot] in #3200
  • Bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.4 by @dependabot[bot] in #3197
  • Bump docker/login-action from 4.5.1 to 4.6.0 by @dependabot[bot] in #3194
  • Bump cloudposse-github-actions/get-pr from 2.0.0 to 3.1.0 by @dependabot[bot] in #3195
  • 🐛 snowflake: drop the nonexistent password policy UI and never-fail lockout range by @tas50 in #2985
  • OpenStack security: address-group-aware public-source detection by @tas50 in #3205
  • STACKIT security: add SKE end-of-support, federated-identity, and KMS rotation checks by @tas50 in #3222
  • Vercel security: add deployment-protection bypass and team-governance checks by @tas50 in #3221
  • Azure security: add Synapse firewall and ML datastore identity checks by @tas50 in #3217
  • Alibaba Cloud security: require IMDSv2 on ECS instances by @tas50 in #3219
  • DigitalOcean security: reachability verdicts and combined public-bucket detection by @tas50 in #3213
  • GCP security: add hierarchical-firewall and Dataproc SSH checks by @tas50 in #3218
  • AWS security: add VPC endpoint wildcard-policy and RDS security-recommendation checks by @tas50 in #3216
  • ✨ content: export serving-container image IDs for internet-exposed pods by @AdamVB in #3223
  • Vercel security: detect firewall bypass rules by @tas50 in #3209
  • OCI security: parsed IAM statements and typed security rules by @tas50 in #3204
  • AWS security: adopt new MQL reachability, inline-policy, and exposure fields by @tas50 in #3201
  • ✨ content: add AIX inventory query pack by @AdamVB in #3168
  • 🐛 ci: bump codeql-action init and analyze together by @tas50 in #3227
  • ✨ aws: add IAM group, Route 53, and SageMaker checks; fix DNSSEC query by @tas50 in #3226
  • Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.106.5 to 1.107.0 in the gomodupdates group by @dependabot[bot] in #3229
  • 🐛 Retry the scan-data upload instead of discarding the scan by @vjeffrey in #3234
  • 🧹 Bump mql to v13.33.0 by @mondoo-mergebot[bot] in #3235

Full Changelog: v13.32.1...v13.33.0