Kubescape
v4.0.14Security2026년 9월 9일
기능 확장과 스캔, 보고서, 종료 과정의 오류 수정이 함께 포함된 유지보수 릴리스입니다. 보안 수정 사항은 명시되지 않았으며 운영자 조치가 필요하지 않습니다.
그 외 기록된 변경 25건 전체fixes 16 · additions 4 · value changes 4 · constraints 1
fixes (16)
- 483a5706fc07a9caae0a6a96fc176ba18ef1903a fix(diff): do not print usage when --fail-on-new fails (#3756)
- a696bda98b45c41914e9fd4c9d980b3f6249ecbe fix(exposure): model GRPCRoute exposure paths with v1beta1 fallback (#3728)
- 4a949f3165084c5f1ade6132d1e070c4dc93e1d1 fix(fix): warn when --output-dir is ignored for file-based reports (#3767)
- 33c14753f6a033a76efc548fa06543f5ed8c33bf fix(git): use hex encoding for hashRepoURL instead of raw bytes (#3720)
- 194d7abe230ad48c4986e59736f8e28244c12bf3 fix(httphandler): gracefully shut down HTTP server and scan worker (#3769)
- e7b3dfbaafa1fe595eb9a3c1a4b54b5214a8afe1 fix(mcpserver): return explicit error for unsupported resource_kind in scan_resource_slice (#3740)
- 031cd40cc8de696fa30a648001853443019ec97a fix(opaprocessor): fix AllResources data race in celParamObjectFinder (#3787)
- 8850cc5c6bb1c0d0566a14352d46a36153b068ce fix(policyhandler): route mixed Framework/Control scan identifiers by their own kind (#3768)
- 53246391c77e542716f9094679ac3115a8f464a1 fix(printer): generalize evidence redaction beyond Secret-kind-only (#3752)
- d3c0138686a54ec152aee16563e16a6919d35a58 fix(printer): honor --show-evidence in control and resource views (#3775)
- 7817ea5052357798e3a01a7f9c98057376266508 fix(printer): route SARIF, GitLab-SAST, HTML, and CSV fix-path values through --show-secrets redaction (#3759)
- 023d1285ef37c7ffbf9eba16ad3a861bc86680fd fix(rbacgraph): order escalation results instead of reading map order (#3739)
- 75e9d0bf4faef77b63b1a89a146c5a7134ff8960 fix(resourcehandler): retrieve single workload via Get instead of List (#3722)
- 20053d7596f6e84d881b81617f59c4cfe6ddca7e fix(resultshandling): rebuild namespace rollup after severity filtering (#3726)
- 13849cb74966273c5a1017a5044b1644468bb13f fix(scan): normalize kind case and support short names in workload scan (#3730)
- 074bf30fbf503fb6194bd9e3a50b775d42e33655 fix: do not print scan usage when --severity-threshold fails (#3716) (#3717)
additions (4)
- 0b3d016f69b7487c4d03d92450b0887969c953a0 feat(fleet): add cross-cluster control matrix and fleet report types (#3774)
- 299509daed16c05372a69f0cf528af831878ce11 feat(list): add --framework and --search filters to list controls (#3623) (#3718)
- 6a97de109f97f85d6896a45685e636b5ef4ed0ca feat(mcpserver): introduce structured machine-readable error responses (#3776)
- 10d4c964214f493afdf1a838aa834b0104ebefb7 feat(rules): add host-users-root-workload-v1 rule prototype (#3754)
value changes (4)
- fbe710b37c20ba81bc467d7298a3020c6bc56ea6 chore(deps): bump github.com/mark3labs/mcp-go from 0.58.0 to 1.0.0 (#3747)
- c2dbab133b131df67835aa20a7218f8768e2ea64 chore(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0 (#3746)
- 74269b787a0fd68f0fe370289a2b5a4e4a4f056d chore(deps): bump helm.sh/helm/v3 from 3.20.2 to 3.21.4 (#3748)
- 153e9d9f8a169239855dc6212a0c7c0590754aab feat(rules): detect Azure AKS Workload Identity in provider-iam-assumption-v1 (#3724)
constraints (1)
- ddbd0ac38977f05af3dc55540d1c205f8f2ad97d feat(scan): extend --kube-contexts fleet mode to framework/control/workload (#3440)
Kubescape 스택에 추가
조치가 필요한 변경이 나오면 주간 메일로 받아볼 수 있습니다. 이번 릴리스처럼 조치가 없는 주에는 메일을 보내지 않습니다.