Skip to content

Releases: stackrox/scanner

2.12.0

31 Mar 01:12
4951ca6

Choose a tag to compare

  • DSOP-related logic is removed
  • Expose the minimum required fixedBy version for a component to resolve all fixable vulnerabilities
  • Fix Distroless support

2.11.1

17 Mar 16:10
55ba2f3

Choose a tag to compare

  • Adds support for OCI versioned manifests

2.11.0

23 Feb 23:28
6567873

Choose a tag to compare

  • No longer match kernel/linux vulns in images
  • Fix Docker matching to account for Docker version format xx.yy.z
  • Officially add alpine:v3.13 support and mark oracle:5 as stale
  • Update kernel component support to return correct package name
  • Bug fixes

2.10.0

26 Jan 21:48
ec7c701

Choose a tag to compare

Adds support for OS-specific linux kernel vulnerabilities. OSes include: Amazon 2, Debian, Garden Linux, CentOS, RHEL, Ubuntu, etc

2.9.0

12 Jan 23:39
d07ad26

Choose a tag to compare

  • Blocklist Python pip

2.8.1

10 Dec 01:32
a458309

Choose a tag to compare

  • Add gRPC Ping to version control
    • Removes need for multiple empty.protos and fixes issue with registration

2.8.0

09 Dec 22:12
42411cd

Choose a tag to compare

  • Add K8s vulns to offline dump
  • Add new gRPC endpoint: GetVulnerabilities
  • Fix .NET and ASP.NET vulnerability updating
  • Add shared generated protos to git
  • Update .NET and ASP.NET vulnerabilities to only include runtime vulns
  • Add vuln def metadata gRPC and HTTP endpoints

2.7.1

05 Dec 19:18
50bbe6d

Choose a tag to compare

2.7.0

13 Nov 02:43
69b9d12

Choose a tag to compare

  • Add ubuntu:20.10 support
  • Add distroless support
  • Add k8s vulns to definitions.stackrox.io
  • Fix .NET and ASP.NET vulnerability CPEs

2.6.0

22 Oct 17:39
6a2c818

Choose a tag to compare

  • Return exact (x.y.z) .NET Core runtime and ASP.NET Core runtime versions (opposed to x.y)
  • Reduce false-positive rate of Java and Ruby vulnerabilities