Releases: mondoohq/mondoo-operator
Releases · mondoohq/mondoo-operator
v13.0.4
What's Changed
- 🧪 WIF test suites by @slntopp in #1441
- chore(deps): bump sigstore/cosign-installer from 4.0.0 to 4.1.0 by @dependabot[bot] in #1432
- chore(deps): bump docker/build-push-action from 6.19.2 to 7.0.0 by @dependabot[bot] in #1431
- chore(deps): bump docker/setup-buildx-action from 3.12.0 to 4.0.0 by @dependabot[bot] in #1430
- chore(deps): bump dawidd6/action-download-artifact from 16 to 18 by @dependabot[bot] in #1428
- chore(deps): bump docker/login-action from 3.7.0 to 4.0.0 by @dependabot[bot] in #1429
- chore: pin GitHub Actions to commit SHAs by @philipbalinov in #1450
- 🧹chore: Bump kube-rbac-proxy image version to v0.16.0 by @slntopp in #1457
- ✨ add secure metrics support with secure endpoint instead of the RBAC proxy and improve helm values structure by @slntopp in #1458
- chore: update chart-releaser action to v1.7.0 and specify charts directory by @slntopp in #1461
- chore(deps): bump the gomodupdates group across 1 directory with 5 updates by @dependabot[bot] in #1460
- chore(deps): bump actions/setup-go from 6.3.0 to 6.4.0 by @dependabot[bot] in #1453
- chore(deps): bump go.mondoo.com/mql/v13 from 13.3.4 to 13.4.0 in the gomodupdates group by @dependabot[bot] in #1463
- chore(deps): bump softprops/action-gh-release from 2.5.0 to 2.6.1 by @dependabot[bot] in #1456
- chore(deps): bump azure/setup-helm from 4.3.1 to 5.0.0 by @dependabot[bot] in #1454
- chore(deps): bump nolar/setup-k3d-k3s from 1.0.9 to 1.0.10 by @dependabot[bot] in #1455
- ✨ add spaceId support for MondooAuditConfig to route assets to specific spaces by @slntopp in #1464
- chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 by @dependabot[bot] in #1468
- chore(deps): bump sigstore/cosign-installer from 4.1.0 to 4.1.1 by @dependabot[bot] in #1467
- chore(deps): bump softprops/action-gh-release from 2.6.1 to 3.0.0 by @dependabot[bot] in #1466
- chore(deps): bump actions/download-artifact from 7.0.0 to 8.0.1 by @dependabot[bot] in #1465
- chore(deps): bump slackapi/slack-github-action from 2.1.1 to 3.0.1 by @dependabot[bot] in #1451
- 🌟 Implement WIF for Container Registry Scanning by @slntopp in #1471
- ✨ refactor garbage collection to use GarbageCollectAssets API by @slntopp in #1470
- chore(deps): bump the gomodupdates group across 1 directory with 4 updates by @dependabot[bot] in #1478
- chore(deps): bump raven-actions/actionlint from 2.1.1 to 2.1.2 by @dependabot[bot] in #1477
- chore(deps): bump nolar/setup-k3d-k3s from 1.0.10 to 1.1.0 by @dependabot[bot] in #1473
- ✨ Extend operator-side labeling/annotation for asset routing by @slntopp in #1480
- chore(deps): bump check-spelling/check-spelling from 0.0.25 to 0.0.26 by @dependabot[bot] in #1475
- chore(deps): bump docker/setup-qemu-action from 3.7.0 to 4.0.0 by @dependabot[bot] in #1476
- ✨ Update ReportStatusRequestFromAuditConfig to include skipContainerResolution parameter by @slntopp in #1481
- ✨ Enable organization-scoped garbage collection by updating MRN handling and related tests by @slntopp in #1483
- 🚀 Release v13.0.4 by @github-actions[bot] in #1484
New Contributors
- @philipbalinov made their first contribution in #1450
Full Changelog: v13.0.3...v13.0.4
mondoo-operator-13.0.4
A Helm chart for installing mondoo-operator on Kubernetes
v13.0.3
What's Changed
- ✨ fix: update image tag formatting to include 'v' prefix in deploymet by @slntopp in #1447
- chore(deps): bump the gomodupdates group with 2 updates by @dependabot[bot] in #1443
- 🚀 Release v13.0.3 by @github-actions[bot] in #1448
Full Changelog: v13.0.2...v13.0.3
v13.0.2
mondoo-operator-13.0.3
A Helm chart for installing mondoo-operator on Kubernetes
mondoo-operator-13.0.2
A Helm chart for installing mondoo-operator on Kubernetes
v13.0.1
What's Changed
- fix prepare-release by @slntopp in #1427
- ✨ add MONDOO_TMP_DIR environment variable to CronJob configurations and ensure
disable-cache: falseby @slntopp in #1434 - ✨ add garbage collection for stale node scan assets by @slntopp in #1435
- 🧹GC cutoff based on schedule by @slntopp in #1437
- chore(deps): bump the gomodupdates group across 1 directory with 2 updates by @dependabot[bot] in #1438
- ✨ bump: update chart and app version to 13.0.1 by @slntopp in #1439
Full Changelog: v13.0.0...v13.0.1
mondoo-operator-13.0.1
A Helm chart for installing mondoo-operator on Kubernetes
v13.0.0-beta6
What's Changed
- 🧹 improved testing and release by @imilchev in #1323
- Bump actions/checkout from 4 to 6 by @dependabot[bot] in #1328
- Bump actions/download-artifact from 5 to 7 by @dependabot[bot] in #1327
- Bump actions/upload-artifact from 4 to 6 by @dependabot[bot] in #1326
- Bump dawidd6/action-download-artifact from 11 to 12 by @dependabot[bot] in #1330
- Bump EnricoMi/publish-unit-test-result-action from 2.21.0 to 2.22.0 by @dependabot[bot] in #1325
- Bump docker/setup-buildx-action from 3.11.1 to 3.12.0 by @dependabot[bot] in #1324
- Bump actions/setup-go from 6.1.0 to 6.2.0 by @dependabot[bot] in #1332
- 🧹 fix gh action for "Push multi-platform virtual tag" by @chris-rock in #1333
- Bump the gomodupdates group across 1 directory with 5 updates by @dependabot[bot] in #1329
- Bump the gomodupdates group with 2 updates by @dependabot[bot] in #1335
- 🧹 update test matrix by @chris-rock in #1334
- 🧹 remove admission controller by @chris-rock in #1336
- ✨ Pin GitHub actions to hashes by @czunker in #1343
- 🧹 update copyright year by @chris-rock in #1344
- ⭐️ refactor: simplify k8s scanning to direct cnspec execution by @chris-rock in #1341
- Bump the gomodupdates group across 1 directory with 2 updates by @dependabot[bot] in #1345
- Replace deprecated --score-threshold by @anurag-2911 in #1340
- ⭐️ refactor cluster scan new external cluster scan capability by @chris-rock in #1338
- Feature/multiple private registry secrets by @AdamVB in #1339
- 🧹 use qemu for cross builds by @chris-rock in #1346
- fix(ci): skip image scan for arm/arm64 builds by @chris-rock in #1347
- 🧹 improve error handling by @chris-rock in #1348
- 🧹 update documentation by @chris-rock in #1349
- 🐛 fix docker/build-push-action by @chris-rock in #1350
- Bump docker/setup-qemu-action from 3.6.0 to 3.7.0 by @dependabot[bot] in #1351
- Bump docker/setup-buildx-action from 3.10.0 to 3.12.0 by @dependabot[bot] in #1352
- Bump docker/login-action from 3.6.0 to 3.7.0 by @dependabot[bot] in #1353
- Bump actions/checkout from 6.0.1 to 6.0.2 by @dependabot[bot] in #1354
- 🐛 allow scanning external clusters when local cluster scan is disabled by @imilchev in #1356
- 🐛 fix service account permissions to support wif scans by @imilchev in #1357
- Bump github.com/cert-manager/cert-manager from 1.19.2 to 1.19.3 in the gomodupdates group by @dependabot[bot] in #1360
- Bump go.mondoo.com/cnquery/v12 from 12.20.1 to 12.21.0 in the gomodupdates group by @dependabot[bot] in #1361
- Bump dawidd6/action-download-artifact from 12 to 14 by @dependabot[bot] in #1355
- external cluster setup by @chris-rock in #1358
- ⭐️ publish helm charts to OCI by @chris-rock in #1367
- ⭐️ ecr auth for container images by @chris-rock in #1368
- 🐛 add ephemeral storage limits for GKE Autopilot compatibility by @chris-rock in #1375
- 🐛 add missing delete verb to batch jobs RBAC by @chris-rock in #1376
- 🐛 preserve active jobs when cleaning up completed scan jobs by @chris-rock in #1377
- Bump github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring from 0.88.1 to 0.89.0 in the gomodupdates group by @dependabot[bot] in #1378
- ⭐️ add actionlint for GitHub Actions linting by @chris-rock in #1373
- ⭐️ fix logging severity for GKE/cloud log explorers by @chris-rock in #1372
- Explicitly set permissions on all GitHub Actions workflows by @chris-rock in #1384
- 🐛 use DeleteCompletedJobs to preserve active scans during CronJob updates by @chris-rock in #1385
- Support image digest in MondooAuditConfig by @chris-rock in #1382
- ⭐️ add annotations support for scanned assets by @chris-rock in #1379
- Bump go.mondoo.com/cnquery/v12 from 12.21.0 to 12.22.0 in the gomodupdates group by @dependabot[bot] in #1386
- docs: add WIF testing documentation for issue #1364 by @chris-rock in #1371
- Format README.md for consistent markdown style by @chris-rock in #1387
- Use smaller container images in integration tests by @chris-rock in #1388
- 🧹 resource watcher improvements by @chris-rock in #1369
- ⭐️ Automate release process via GitHub Release by @chris-rock in #1380
- ⭐️ Improve Helm chart management and cleanup by @chris-rock in #1374
- ⭐️ use Server-Side Apply (SSA) for resource reconciliation by @chris-rock in #1381
- Migrate K8s scanner to plain cnspec image by @chris-rock in #1389
- Add Helm chart documentation and improve values.yaml annotations by @chris-rock in #1390
- feat: add MondooOperatorConfig for proxy and image registry support by @chris-rock in #1391
- Bump helm/chart-testing-action from 2.7.0 to 2.8.0 by @dependabot[bot] in #1394
- Bump azure/setup-helm from 4.3.0 to 4.3.1 by @dependabot[bot] in #1392
- Bump docker/build-push-action from 6.18.0 to 6.19.2 by @dependabot[bot] in #1393
- fix: add nolint:gosec annotations for new gosec rules by @chris-rock in #1398
- fix: skip version file updates on main for pre-release tags by @chris-rock in #1396
- Bump the gomodupdates group with 2 updates by @dependabot[bot] in #1395
- Tests and improvements v13-beta by @slntopp in #1409
- Update publish.yaml to include write permissions by @slntopp in #1410
- 🐛 fix integration tests errors by @slntopp in #1411
- fix: skip minikube image load and pass git tag as VERSION for pre-built operator in helm tests by @slntopp in #1412
- fix: use published image matching git tag in Helm chart installation by @slntopp in #1413
- Bump actions/setup-go from 6.2.0 to 6.3.0 by @dependabot[bot] in #1405
- Bump hashicorp/setup-terraform from 3.1.2 to 4.0.0 by @dependabot[bot] in #1404
- Bump the gomodupdates group across 1 directory with 2 updates by @dependabot[bot] in #1403
- Bump actions/upload-artifact from 6.0.0 to 7.0.0 by @dependabot[bot] in #1406
- Bump dawidd6/action-download-artifact from 14 to 16 by @dependabot[bot] in #1407
- Bump EnricoMi/publish-unit-test-result-action from 2.22.0 to 2.23.0 by @dependabot[bot] in #1402
- v13 Release tests batch by @slntopp in #1416
- v13 registry mirroring and proxying testing by @slntopp in #1422
- 📚 v13 Documentation improvements by @slntopp in #1420
- feat: replace VaultAuth init container with operator-side vault-client-go by @chris-rock in https://github.com/mondoohq/mondoo-operator/pull/...
v13.0.0
What's Changed
- 🧹 improved testing and release by @imilchev in #1323
- Bump actions/checkout from 4 to 6 by @dependabot[bot] in #1328
- Bump actions/download-artifact from 5 to 7 by @dependabot[bot] in #1327
- Bump actions/upload-artifact from 4 to 6 by @dependabot[bot] in #1326
- Bump dawidd6/action-download-artifact from 11 to 12 by @dependabot[bot] in #1330
- Bump EnricoMi/publish-unit-test-result-action from 2.21.0 to 2.22.0 by @dependabot[bot] in #1325
- Bump docker/setup-buildx-action from 3.11.1 to 3.12.0 by @dependabot[bot] in #1324
- Bump actions/setup-go from 6.1.0 to 6.2.0 by @dependabot[bot] in #1332
- 🧹 fix gh action for "Push multi-platform virtual tag" by @chris-rock in #1333
- Bump the gomodupdates group across 1 directory with 5 updates by @dependabot[bot] in #1329
- Bump the gomodupdates group with 2 updates by @dependabot[bot] in #1335
- 🧹 update test matrix by @chris-rock in #1334
- 🧹 remove admission controller by @chris-rock in #1336
- ✨ Pin GitHub actions to hashes by @czunker in #1343
- 🧹 update copyright year by @chris-rock in #1344
- ⭐️ refactor: simplify k8s scanning to direct cnspec execution by @chris-rock in #1341
- Bump the gomodupdates group across 1 directory with 2 updates by @dependabot[bot] in #1345
- Replace deprecated --score-threshold by @anurag-2911 in #1340
- ⭐️ refactor cluster scan new external cluster scan capability by @chris-rock in #1338
- Feature/multiple private registry secrets by @AdamVB in #1339
- 🧹 use qemu for cross builds by @chris-rock in #1346
- fix(ci): skip image scan for arm/arm64 builds by @chris-rock in #1347
- 🧹 improve error handling by @chris-rock in #1348
- 🧹 update documentation by @chris-rock in #1349
- 🐛 fix docker/build-push-action by @chris-rock in #1350
- Bump docker/setup-qemu-action from 3.6.0 to 3.7.0 by @dependabot[bot] in #1351
- Bump docker/setup-buildx-action from 3.10.0 to 3.12.0 by @dependabot[bot] in #1352
- Bump docker/login-action from 3.6.0 to 3.7.0 by @dependabot[bot] in #1353
- Bump actions/checkout from 6.0.1 to 6.0.2 by @dependabot[bot] in #1354
- 🐛 allow scanning external clusters when local cluster scan is disabled by @imilchev in #1356
- 🐛 fix service account permissions to support wif scans by @imilchev in #1357
- Bump github.com/cert-manager/cert-manager from 1.19.2 to 1.19.3 in the gomodupdates group by @dependabot[bot] in #1360
- Bump go.mondoo.com/cnquery/v12 from 12.20.1 to 12.21.0 in the gomodupdates group by @dependabot[bot] in #1361
- Bump dawidd6/action-download-artifact from 12 to 14 by @dependabot[bot] in #1355
- external cluster setup by @chris-rock in #1358
- ⭐️ publish helm charts to OCI by @chris-rock in #1367
- ⭐️ ecr auth for container images by @chris-rock in #1368
- 🐛 add ephemeral storage limits for GKE Autopilot compatibility by @chris-rock in #1375
- 🐛 add missing delete verb to batch jobs RBAC by @chris-rock in #1376
- 🐛 preserve active jobs when cleaning up completed scan jobs by @chris-rock in #1377
- Bump github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring from 0.88.1 to 0.89.0 in the gomodupdates group by @dependabot[bot] in #1378
- ⭐️ add actionlint for GitHub Actions linting by @chris-rock in #1373
- ⭐️ fix logging severity for GKE/cloud log explorers by @chris-rock in #1372
- Explicitly set permissions on all GitHub Actions workflows by @chris-rock in #1384
- 🐛 use DeleteCompletedJobs to preserve active scans during CronJob updates by @chris-rock in #1385
- Support image digest in MondooAuditConfig by @chris-rock in #1382
- ⭐️ add annotations support for scanned assets by @chris-rock in #1379
- Bump go.mondoo.com/cnquery/v12 from 12.21.0 to 12.22.0 in the gomodupdates group by @dependabot[bot] in #1386
- docs: add WIF testing documentation for issue #1364 by @chris-rock in #1371
- Format README.md for consistent markdown style by @chris-rock in #1387
- Use smaller container images in integration tests by @chris-rock in #1388
- 🧹 resource watcher improvements by @chris-rock in #1369
- ⭐️ Automate release process via GitHub Release by @chris-rock in #1380
- ⭐️ Improve Helm chart management and cleanup by @chris-rock in #1374
- ⭐️ use Server-Side Apply (SSA) for resource reconciliation by @chris-rock in #1381
- Migrate K8s scanner to plain cnspec image by @chris-rock in #1389
- Add Helm chart documentation and improve values.yaml annotations by @chris-rock in #1390
- feat: add MondooOperatorConfig for proxy and image registry support by @chris-rock in #1391
- Bump helm/chart-testing-action from 2.7.0 to 2.8.0 by @dependabot[bot] in #1394
- Bump azure/setup-helm from 4.3.0 to 4.3.1 by @dependabot[bot] in #1392
- Bump docker/build-push-action from 6.18.0 to 6.19.2 by @dependabot[bot] in #1393
- fix: add nolint:gosec annotations for new gosec rules by @chris-rock in #1398
- fix: skip version file updates on main for pre-release tags by @chris-rock in #1396
- Bump the gomodupdates group with 2 updates by @dependabot[bot] in #1395
- Tests and improvements v13-beta by @slntopp in #1409
- Update publish.yaml to include write permissions by @slntopp in #1410
- 🐛 fix integration tests errors by @slntopp in #1411
- fix: skip minikube image load and pass git tag as VERSION for pre-built operator in helm tests by @slntopp in #1412
- fix: use published image matching git tag in Helm chart installation by @slntopp in #1413
- Bump actions/setup-go from 6.2.0 to 6.3.0 by @dependabot[bot] in #1405
- Bump hashicorp/setup-terraform from 3.1.2 to 4.0.0 by @dependabot[bot] in #1404
- Bump the gomodupdates group across 1 directory with 2 updates by @dependabot[bot] in #1403
- Bump actions/upload-artifact from 6.0.0 to 7.0.0 by @dependabot[bot] in #1406
- Bump dawidd6/action-download-artifact from 14 to 16 by @dependabot[bot] in #1407
- Bump EnricoMi/publish-unit-test-result-action from 2.22.0 to 2.23.0 by @dependabot[bot] in #1402
- v13 Release tests batch by @slntopp in #1416
- v13 registry mirroring and proxying testing by @slntopp in #1422
- 📚 v13 Documentation improvements by @slntopp in #1420
- feat: replace VaultAuth init container with operator-side vault-client-go by @chris-rock in https://github.com/mondoohq/mondoo-operator/pull/...