v13.33.0
·
263 commits
to main
since this release
What's Changed
- 🧹 bump mql to v13.32.2 by @arlimus in #3164
- 🧹 docs: move ambiguous-path MQL gotcha from mql skill to CLAUDE.md by @preslavgerchev in #3166
- ✨ content: add Mondoo MariaDB Security policy by @tas50 in #3152
- ✨ content: add Mondoo MySQL Security policy by @tas50 in #3151
- Bump docker/login-action from 4.4.0 to 4.5.1 by @dependabot[bot] in #3157
- ✨ content: add GCP primitive-role, GKE Binary Authorization, and lien checks by @tas50 in #3170
- ✨ content: add AWS IAM trust policy, RDS patching/logging, and EKS access checks by @tas50 in #3169
- 🐛 aws: skip CloudTrail bucket checks when the bucket is unreadable cr… by @AdamVB in #3161
- 🧹 ci: bump pinned CLIs in the remediation validator job by @tas50 in #3171
- ✨ reporter: bring SARIF output up to the detail level of JUnit detailed by @AdamVB in #3172
- 🐛 executor: make score error messages deterministic by @preslavgerchev in #3179
- Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.106.2 to 1.106.5 in the gomodupdates group across 1 directory by @dependabot[bot] in #3200
- Bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.4 by @dependabot[bot] in #3197
- Bump docker/login-action from 4.5.1 to 4.6.0 by @dependabot[bot] in #3194
- Bump cloudposse-github-actions/get-pr from 2.0.0 to 3.1.0 by @dependabot[bot] in #3195
- 🐛 snowflake: drop the nonexistent password policy UI and never-fail lockout range by @tas50 in #2985
- OpenStack security: address-group-aware public-source detection by @tas50 in #3205
- STACKIT security: add SKE end-of-support, federated-identity, and KMS rotation checks by @tas50 in #3222
- Vercel security: add deployment-protection bypass and team-governance checks by @tas50 in #3221
- Azure security: add Synapse firewall and ML datastore identity checks by @tas50 in #3217
- Alibaba Cloud security: require IMDSv2 on ECS instances by @tas50 in #3219
- DigitalOcean security: reachability verdicts and combined public-bucket detection by @tas50 in #3213
- GCP security: add hierarchical-firewall and Dataproc SSH checks by @tas50 in #3218
- AWS security: add VPC endpoint wildcard-policy and RDS security-recommendation checks by @tas50 in #3216
- ✨ content: export serving-container image IDs for internet-exposed pods by @AdamVB in #3223
- Vercel security: detect firewall bypass rules by @tas50 in #3209
- OCI security: parsed IAM statements and typed security rules by @tas50 in #3204
- AWS security: adopt new MQL reachability, inline-policy, and exposure fields by @tas50 in #3201
- ✨ content: add AIX inventory query pack by @AdamVB in #3168
- 🐛 ci: bump codeql-action init and analyze together by @tas50 in #3227
- ✨ aws: add IAM group, Route 53, and SageMaker checks; fix DNSSEC query by @tas50 in #3226
- Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.106.5 to 1.107.0 in the gomodupdates group by @dependabot[bot] in #3229
- 🐛 Retry the scan-data upload instead of discarding the scan by @vjeffrey in #3234
- 🧹 Bump mql to v13.33.0 by @mondoo-mergebot[bot] in #3235
Full Changelog: v13.32.1...v13.33.0