- Add adaptive scanning for image scanning after Docker Version 25.0.0
- Add checking of
CVE-2024-21626
- Add checking of
CVE-2024-3094
liblzma.so backdoor
- Add the severity of each Linux capabilities
- Add account checking in
/etc/passwd
- Add filesystem scanning
- Add checking of ingress nginx
- Add BearerToken for authentication
- Add insecure and server flags in k8s analysis
- Add environment checking in docker images
- Add the counter of each severity
- Add some rules of annotation checking
- Delete the inside flag due to duplicate
- Add
.dockerconfigjson
in secret checking - Add Docker Histories environment checking
- Add the date of kernel compiling checking in checking of kernel version
- Add the error output in image saving
- Fix the out of range in container extract
- Add dangerous image used checking in Docker
- Add Docker Swarm Service checking
- Add checking of ephemeral-storage usage
- Annotate the tag of image checking
- Add unauthorized kubelet checking for each node
- Add support of k3s and k0s
- fix the error of compared version
- fix the error of parameter input in file scan
- Add trampoline attacking check
- Add malicious value checking in docker history
- Add source
OSCS
for malware checking - Add Windows path Volume checking
- Add Kubernetes
DaemonSet
checking - Add rootkit and backdoor checking in K8s and Docker
- Add k8s version checking
- Add k8s
PodSecurityPolicy
checking for k8s version under the v1.25
- Add some rules for CAP checking
- Change the namespace checking of Secret and ConfigMap
- Improve the rules of
DeamonSet
scanning - Change the scan rules of
Job
andCronJob
- Optimize the method of annotation checking
- fix the comparison of kernel version
- fix the errors of base64 decode
- Add Docker
--pid=host
checking - Add Python pip analysis from poetry and venv
- Change the minimum of downloaded vulnerable data year from 2002 to 2010
- Parse the env command in Docker Histories
- Rewrite method of java libraries, especially log4j
- Change the format of output of image scan
- Add sidecar Environment Checking, including
Env
andEnvFrom
- Add pip name checking, detect whether package is potential malware
- Add pod annotation checking
- Change method of rpm analysis
- Change folder structure
- Change method of kernel version checking
- Change command
upgrade
toupdate
- Add java libraries analysis
- Add php libraries analysis
- Add rust libraries analysis
- Add istio checking
- Add Docker history analysis
- Change the method of npm analysis
- Add mount filesystem for container scan
- Change method of cilium checking
- Change the method of image scanning
- Add RBAC User output for untrusted User checking
- Revise the rules of RBAC checking
- Fixed error of version comparison
- Add cilium checking
- Add Kubelet
read-only-port
andkubectl proxy
checking - Add Etcd safe configuration checking
- Add RoleBinding checking
- Optimize layer integration
- Add go binary analysis
- Add weak password checking in Configmap and Secret
- Add weak password checking in Docker env
- Add
--skip
parameter for image or container scanning - Add Envoy admin checking
- Image or Container scan
- Docker configuration scan
- Kubernetes configuration scan