Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package kubescape for openSUSE:Factory checked in at 2026-10-01 16:46:44 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/kubescape (Old) and /work/SRC/openSUSE:Factory/.kubescape.new.1253 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "kubescape" Thu Oct 1 16:46:44 2026 rev:48 rq:1381779 version:4.0.15 Changes: -------- --- /work/SRC/openSUSE:Factory/kubescape/kubescape.changes 2026-09-21 12:07:23.788605214 +0200 +++ /work/SRC/openSUSE:Factory/.kubescape.new.1253/kubescape.changes 2026-10-01 16:47:33.434328736 +0200 @@ -1,0 +2,207 @@ +Thu Oct 01 05:24:53 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 4.0.15: + * feat(printer): add scan coverage to markdown, HTML, and CSV + (#3937) + * fix(sarif): aggregate container image vulnerability runs in + combined scans (#3945) (#3946) + * feat(opa): let C-0236 accept key-signed images without a + transparency log entry (#3967) + * feat(imagescan): support Quay vulnerability scanning (#3917) + * fix(cel): avoid false findings when Namespace data is + unavailable (#3920) + * ci: bump github/codeql-action/upload-sarif from 4.38.1 to + 4.38.2 (#3965) + * ci: bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#3962) + * ci: bump the kubernetes group with 4 updates (#3960) + * ci: bump + go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp + (#3963) + * fix(pdf): include image CVEs in combined scan reports (#3949) + * fix(httphandler): set DisableKeepAlives to true in + postScanCallback (#3948) + * fix(perf): eliminate O(N^2) memory allocations in image scan + target deduplication (#3939) + * fix(scancache): bypass cache when resource fails to encode to + JSON (#3953) + * fix(printer): include skipped and unevaluated controls in CSV + report output (#3934) (#3935) + * fix(prometheus): emit container image vulnerability metrics in + combined scans (#3941) (#3942) + * chore: ignore every result file the smoke test writes (#3936) + * fix(networkpolicy): allow a Pod to always reach itself (#3905) + * fix(cautils): skip non-regular manifest files instead of + reading them (#3931) + * fix(junit): aggregate and serialize skipped count in root + testsuites element (#3932) (#3933) + * fix(portforwarder): add timeout to waitForPortForwardReadiness + to prevent infinite hang (#3873) + * docs: add image scanning documentation (#3907) + * feat(fleet): print a fleet summary after a multi-context scan + [LFX 2026] (#3929) + * fix(opa): validate signed image digest in cosign verification + (#3930) + * fix: populate framework resource counters and root metadata in + ReportV2ToV1 (#3927) (#3928) + * fix(release): write the cosign signing key owner-only and + remove it after the release (#3736) + * feat(printer): report degraded scan coverage and skipped + controls (#3926) + * fix(hostsensor): surface partial node-data loss as + partialGVRPulls (#3844) + * feat(httphandler): reload namespace filters without restarting + (#3925) + * fix(imagescan): prevent silent swallow of azure image id + validation errors (#3900) + * fix(scan): re-evaluate policies that read status through + object.get (#3918) + * fix(diff): extract failedPath evidence in granular comparison + (#3921) (#3922) + * fix: complete V2 to V1 Control Report field mapping (#3812) + * fix(scan): hash policy-visible resource metadata (#3919) + * fix(opaprocessor): fix excluded control reinsert regression + (#3915) + * feat(helm): thread the document index through chart rendering + (#3911) + * fix(ci): build and test master on push, not only inside a pull + request (#3910) + * fix(opaprocessor): propagate skip reasons to control summary + and junit (#3885) + * chore: bump regolibrary to v2.0.36 (#3893) + * test(pdf): regenerate info-rows fixture for maroto v2.4.2 + height truncation (#3912) + * test(cel): fail the build if a bundle policy starts reading + namespaceObject (#3826) + * ci: bump github.com/johnfercher/maroto/v2 from 2.2.2 to 2.4.2 + (#3836) + * ci: bump github.com/hashicorp/hcl/v2 from 2.24.0 to 2.25.0 + (#3894) + * ci: bump golang.org/x/mod from 0.40.0 to 0.41.0 (#3896) + * fix(scan): prevent stale incremental verdicts across scan + contexts (#3890) + * ci: bump github.com/moby/buildkit from 0.31.1 to 0.33.0 (#3895) + * ci: bump github.com/project-copacetic/copacetic from 0.10.0 to + 0.15.0 (#3763) + * fix(networkpolicy): require a common port and protocol for + reachability (#3909) + * fix(reportcrypto): decrypt namespace summaries and env var + names in encrypted reports (#3908) + * fix(anonymizer): keep failed transformations from corrupting + reports (#3888) + * fix(hostsensor): preserve virtual host resource identities + (#3891) + * fix(scan): make incremental cache writes durable (#3889) + * ci: bump github/codeql-action/upload-sarif from 4.38.0 to + 4.38.1 (#3897) + * fix(printer): emit PolicyReport timestamps as seconds and nanos + per CRD schema (#3887) + * ci: bump docker/setup-qemu-action from 4.3.0 to 4.4.0 (#3899) + * fix(scan): isolate fleet context configuration (#3881) + * feat(fix): honour --output-dir for file-based reports (#3880) + * fix(imagescan): stop stalled ECR pagination (#3882) + * fix(imagescan): stop stalled Azure pagination (#3883) + * feat(opaprocessor): define execution policies for whole-cluster + controls (#3877) + * refactor: inject host sensor controls default via ScanInfo + (#3876) + * feat(fleet): report the controls clusters disagree on (#3878) + * fix(locationresolver): reject negative nodeIndex in + ResolveLocation (#3879) + * refactor(resultshandling): decouple downstream consumers from + AllResources via ResourceCatalog (#3874) + * feat(vap): include complete Agent Runtime policy set (#3871) + * feat(cautils): introduce ResourceCatalog and replace direct + AllResources accesses (#3868) + * fix(storage): persist workload scan report timestamps (#3869) + * test(core): cover cached config set and delete (#3870) + * fix: print separator for control scans (#3842) + * fix(mcpserver): skip IaC scan tests if offline policies missing + (#3806) + * Refactor: Move getReadableID out of filesloaderutils (#3862) + * feat(resourcehandler): wire partition store into streaming + collector (#3235) (#3863) + * feat(evidence): warn on incompatible flags and skip lines for + anonymized source path (#3864) + * fix(imagescan): support nested Harbor repositories (#3860) + * fix(kubernetes): stop stalled pagination loops (#3859) + * fix(patch): do not print usage when --severity-threshold fails + (#3857) + * feat(imagescan): support full Azure credential chain for ACR + image pulls (#3853) + * fix(scan): validate format of workload name, kind, namespace, + and API group (#3809) + * fix(imagescan): correct misleading log in ProcessImages and + break severity loop (#3856) + * fix(scan): restore fleet context after runner panic (#3848) + * fix(scan): write fleet reports atomically (#3849) + * feat(fleet): add the compliance rollup to the fleet report + (#3852) + * fix(partitionstore): recognise a full disk on Windows (#3855) + * fix(streaming): update partition counts after purge (#3850) + * fix(printer): assign info stars deterministically instead of by + map iteration order (#3851) + * feat(printer): resolve line numbers for delete and review paths + in --show-evidence (#3845) + * fix(imagescan): warn on stale vulnerability DB, fail with + --fail-on-stale-db (#3830) + * fix(imagescan): fail closed on unknown-severity CVEs in + threshold gates (#3832) + * fix(httphandler): do not abandon a posture report on one store + error (#3822) + * ci: bump github.com/deckarep/golang-set/v2 from 2.8.0 to 2.9.0 + (#3835) + * ci: bump github.com/anubhav06/copa-grype (#3837) + * ci: bump github/codeql-action/upload-sarif from 4.37.9 to + 4.38.0 (#3838) + * ci: bump github.com/anchore/clio (#3834) + * test(mcpserver): verify Agent Runtime posture findings (#3833) + * feat(resourcehandler): introduce partition and spill store + engine (#3818) + * fix(httphandler): deliver scan-completion callback on scan + panic (#3828) + * feat(scan): add --fleet-report to write one combined report + across --kube-contexts (#3815) + * fix(diff): honor /dev/stdout and /dev/null in diff --output + (#3820) + * test(scan): validate live Agent Runtime CRD collection (#3819) + * feat(locationresolver): resolve bracketed-key paths by building + yq expressions from parsed segments (#3816) + * fix(cautils): recurse nested JSON arrays and ignore + non-manifest JSON values (#3817) + * test(scan): add Agent Runtime Hardening integration coverage + (#3807) + * fix(printer): support combined posture and image scan output in + Markdown and HTML printers (#3814) + * test(mcpserver): assert rejected argument details (#3810) + * fix(cautils): do not carry tenant identity across + --kube-contexts scans (#3813) + * feat: use mmap and fastjson for manifest parsing (#3500) + * fix(printer): qualify bracketed keys with a following index and + keep quoted digits keys (#3801) + * feat: add support for deleting specific configuration keys + (#3672) + * fix: make GetScanningContext side-effect free (#3802) + * fix(scan): default omitted workload namespace to 'default' and + require '*' for cluster-wide search (#3798) + * feat(config): Filter configurations by key in kubescape config + view (#3644) + * fix(printer): parse bracketed path keys instead of splitting on + every… (#3796) + * fix(printer): support multi-image scan output in YAML printer + (#3795) + * fix(getter): fail on checksum verification errors (#3791) + * fix(printer): stream configuration scan JSON and SARIF output + (#3794) + * fix(opaprocessor): select whole controls in + --skip-controls/--include-controls (#3793) + * fix: preserve YAML source formatting during remediation (#3788) + * test(mcpserver): add integration smoke test for live-cluster + scan_workload path (#3785) + * feat(printer): resolve fix-path line numbers in --show-evidence + output (#3786) + * fix(printer): honor /dev/stdout and /dev/null in every output + printer (#3781) + * fix(exceptions): generate suppressing exception baselines + (#3783) + +------------------------------------------------------------------- Old: ---- kubescape-4.0.14.obscpio New: ---- kubescape-4.0.15.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ kubescape.spec ++++++ --- /var/tmp/diff_new_pack.UoPjZn/_old 2026-10-01 16:47:36.481456448 +0200 +++ /var/tmp/diff_new_pack.UoPjZn/_new 2026-10-01 16:47:36.483456532 +0200 @@ -17,14 +17,14 @@ Name: kubescape -Version: 4.0.14 +Version: 4.0.15 Release: 0 Summary: Tool providing a multi-cloud K8s single pane of glass License: Apache-2.0 URL: https://github.com/armosec/kubescape Source: kubescape-%{version}.tar.gz Source1: vendor.tar.gz -BuildRequires: go1.26 >= 1.26.0 +BuildRequires: go1.26 >= 1.26.3 %description Kubescape is a K8s open-source tool providing a multi-cloud K8s single pane of ++++++ _service ++++++ --- /var/tmp/diff_new_pack.UoPjZn/_old 2026-10-01 16:47:36.522458167 +0200 +++ /var/tmp/diff_new_pack.UoPjZn/_new 2026-10-01 16:47:36.525458292 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/armosec/kubescape.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/v4.0.14</param> + <param name="revision">refs/tags/v4.0.15</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">enable</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.UoPjZn/_old 2026-10-01 16:47:36.551459382 +0200 +++ /var/tmp/diff_new_pack.UoPjZn/_new 2026-10-01 16:47:36.556459592 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/armosec/kubescape</param> <param name="changesrevision">002e791cd39fed51dd4a86b321c6d184fa672349</param></service><service name="tar_scm"> <param name="url">https://github.com/armosec/kubescape.git</param> - <param name="changesrevision">031cd40cc8de696fa30a648001853443019ec97a</param></service></servicedata> + <param name="changesrevision">16cfe102f11551a6455fe9bf8e37d7083da90484</param></service></servicedata> (No newline at EOF) ++++++ kubescape-4.0.14.obscpio -> kubescape-4.0.15.obscpio ++++++ ++++ 59160 lines of diff (skipped) ++++++ kubescape.obsinfo ++++++ --- /var/tmp/diff_new_pack.UoPjZn/_old 2026-10-01 16:47:40.412621212 +0200 +++ /var/tmp/diff_new_pack.UoPjZn/_new 2026-10-01 16:47:40.416621380 +0200 @@ -1,5 +1,5 @@ name: kubescape -version: 4.0.14 -mtime: 1788956681 -commit: 031cd40cc8de696fa30a648001853443019ec97a +version: 4.0.15 +mtime: 1790660939 +commit: 16cfe102f11551a6455fe9bf8e37d7083da90484 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/kubescape/vendor.tar.gz /work/SRC/openSUSE:Factory/.kubescape.new.1253/vendor.tar.gz differ: char 15, line 1
