- Bump library github.com/fairwindsops/insights-plugins/plugins/opa to version v0.0.0-20260320193800-30ba3f036b7d
- Bump library github.com/fairwindsops/insights-plugins/plugins/trivy to version v0.0.0-20260320193800-30ba3f036b7d
- Bump indirect library dependencies
- Bump library github.com/fairwindsops/insights-plugins/plugins/opa to version v0.0.0-20260311165234-dec7bf83ba9c
- Bump library github.com/fairwindsops/insights-plugins/plugins/trivy to version v0.0.0-20260311165234-dec7bf83ba9c
- Bump library helm to version 4.1.3
- Bump indirect library dependencies
- Bump polaris to 10.1.6, pluto to 5.23.5
- Bump trivy to 0.69.3, pluto to 5.23.0
- Bump library dependencies
- Bump indirect library dependencies
- Bump library dependencies
- Bump indirect library dependencies
- Bump nova to v3.11.10, pluto to v5.22.8, polaris to 10.1.5
- Bumped to Go 1.26
- Bump library dependencies
- Bump indirect library dependencies
- Bump helm to 4.1.1
- Bump library k8s.io/api, k8s.io/apimachinery, k8s.io/client-go to v0.35.1
- Bump library github.com/fairwindsops/insights-plugins/plugins/opa
- Bump library github.com/fairwindsops/insights-plugins/plugins/trivy
- Bump library golang.org/x/crypto to v0.48.0
- Bump library golang.org/x/net to v0.50.0
- Bump library golang.org/x/term to v0.40.0
- Bump library golang.org/x/text to v0.34.0
- Bump indirect library dependencies
- Bump trivy to 0.69.1
- Bump polaris to 10.1.4
- Bump library github.com/docker/cli to v29.2.1
- Bump library github.com/klauspost/compress to v1.18.4
- Bump library github.com/lestrrat-go/httprc/v3 to v3.0.4
- Bump library go.opentelemetry.io/otel to v1.40.0
- Bump library golang.org/x/oauth2 to v0.35.0
- Bump library golang.org/x/sys to v0.41.0
- Bump library sigs.k8s.io/structured-merge-diff/v6 to v6.3.2
- Bump indirect library dependencies
- Bump trivy to 0.69.0
- Bump library github.com/fairwindsops/insights-plugins/plugins/opa
- Bump library github.com/fairwindsops/insights-plugins/plugins/trivy
- Bump library github.com/open-policy-agent/opa to v1.13.1
- Bump indirect library dependencies
- Bump indirect library dependencies
- Bump helm to version 4.1.0
- Bumped all libs
- Bump github.com/fairwindsops/insights-plugins/plugins/opa
- Bump github.com/fairwindsops/insights-plugins/plugins/trivy
- Bump library dependencies
- Bump k8s api libraries to 0.35.0
- Bump library dependencies
- Bump library dependencies
- Bumped helm version
- Bumped polaris
- Bumped to go 1.25.5
- Bumped trivy for fixing vulnerabilities
- Bumped go for fixing vulnerabilities
- Bumped libs
- Bumped libs version
- Bump trivy to 0.67.0
- Bump trivy to 0.66.0
- Bumped helm version
- Bumped go to 1.24.6 for fixing vulnerability
- Bump trivy to 0.65.0
- Bumping helm
- Bumped polaris version to 10.0.0
- Remove support to OPA V1
- Bump pluto to 5.21.9
- Bump trivy to 0.64.1
- Fixing vulnerabilities
- Fixing vulnerabilities
- Remove tfsec support
- Update libraries
- bumped alpine to 3.22
- Upgaded trivy to 0.62.1
- bumped tfsec
- bumped libs
- bumped libs
- upgaded trivy to 0.61.0
- Fixed trivy vulnerability
- Added annotations to scan workloads
- Support to Rego V0 and V1 libs
- Support to Rego V1
- Fixing vulnerabilities
- Fixed helm vulnerability
- Fixed trivy vulnerability
- Fixed tfsec vulnerability
- Fixing vulnerabilities
- Fixing vulnerabilities
- bumped alpine to 3.21
- bumped libs
- bumped trivy to v0.57.1
- bumped polaris to 9.6.0
- fix trivy db / java-db downloading
- bumped trivy to v0.57.0
- Use
RemoveTokensAndPasswordfunction from trivy - Add trivy OCI repositories fallback
- bumped trivy to v0.56.2
- bumped tfsec to 1.28.11 for fixing vulnerabilities
- Fixing vulnerabilities
- Bumped pluto to 5.20.2
- upgrading due to trivy API change
- fixed helm vulnerability
- fixed docker vulnerability
- Add support for OPA custom libs
- fixed docker vulnerability
- add support for go workspace
- Add support for scan-workloads labels
- Bumped trivy version
- Fixed CI vulnerability
- Bump alpine to 3.20
- bumped versions
- bumped pluto to 5.19.4
- bumped pluto to 5.19.3
- bumped polaris to 9.0.1
- bumped tfsec to 1.28.6 for fixing vulnerabilities
- update dependencies
- update tfsec and trivy version
- update dependencies
- update dependencies
- update dependencies
- update dependencies
- update dependencies
- Added tfsec custom checks
- Fix image owners matching logic
- Trim spaces from masterBranch before using it
- Only skip failed files instead of halting the process
- Print soft-errors to output to increase error awareness
- Added files that were modified to CI scan response
- update trivy to 0.48.1
- Bump alpine to 3.19
- Ignore
setExitCodewhen running on auto-scan mode
- Update dependencies
- Fix removing
.gitfrom repository name
- Update to go 1.21
- Update binary dependency
trivy
- Update dependencies
- Update dependencies
- Add
reports.goldilocks.enabledsupport (defaulttrue) - Add
reports.prometheus-metrics.enabledsupport (defaulttrue)
- Add warning message and prevent panic when we find a podSpec with no containers
- Bump polaris version to 8.2.3
- Update go libraries
- Update trivy/opa version
- Update dependencies (polaris 8.0.0)
- Update dependencies
- Update dependencies
- update dependencies
- Support for insecure TLS override in uploader
- Fixes bug where relative path were not preserved on filename field for yaml manifest files.
- update alpine and x/net
- Restore command standard-error being returned and reflected in CI logs and scan-error report action items, from PR #754.
- Fix STDOUT parsing
- update dependencies
- update alpine and go modules
- Clarify the log message when there have been no tfsec findings after processing all terraform paths.
- Fix removal of the repository path from tfsec result file names, when said result is for a Terraform module. THis bug caused these file names to begin with
/app/repository/{repository name}. - Log the version of the CI plugin.
- Revert 4.2.2
- Update pluto from 5.11.2 to 5.12.0
- Update Polaris from 7.2.1 to 7.3.0
- Update Helm from 3.10.3 to 3.11.0
- update dependencies
- CI scanning will continue when an error is encountered, such as templating a Helm chart into Kubernetes manifests. These errors will be reflected as Insights action items, in a new
ScanErrorsreport type.
- skip downloading in-container
images.dockerimages that has env. variables on their names
- update go modules
- Fixes when using
helm.valuescauses tmp filepath to get mangled
- Fixes missing image info (name and owner name) when the download of
docker.imagesare done inside the CI plugin execution
- update x/net and alpine
- Add support for configuring reports when using auto-discovery via
REPORTS_CONFIGenv var
- Enable the tfsec report by default. If
terraform -> pathsare specified, they will be scanned unlessreports -> tfsec -> enabledis explicitly set tofalsein fairwinds-insights.yaml.
- Support for private images (REGISTRY_CREDENTIALS)
- Support
images.dockerdownload images inside the plugin
- update trivy
- Add alternative GIT commands to fetch masterHash
- Make some GIT commands optional (masterHash, commitMessage, branch and origin)
- Add CI_RUNNER env. var support
- Add hint logs based on CI runner
- Update tfsec, pluto, and polaris to adress additional
x/textandx/netCVEs - Bump Helm to 3.10.2
- Add Terraform scanning via a tfsec report
- Temporarily revert terraform scanning
- Add Terraform scanning via a tfsec report
- Update trivy to version 0.34.0
- Update x/text to remove CVE
- Update dependencies
- Update to go 1.19
- Update versions
- Build docker images for linux/arm64, and update to Go 1.19.1
- Improves logging to show k8s and helm files
- Fix
helm templatecommand in some environments
- Fix leaking access token in std out.
- upgrade plugins on build
- Fix for missing fields in container manifests
- Update dependencies
- Fix OPA panic if
kindfield is missing
- update packages
- update packages
- Fix for git 2.35.2
- support HPA v2beta1 in OPA checks
- update to go 1.18 and update packages
- update Trivy plugin
- Update alpine to remove CVE
- Add debug info
- update versions
- updated CI NewActionItemThreshold default to -1
- Fix auto-detection on resolving non-kubernetes manifests.
- Bump alpine to 3.16
- Add
ValuesFilesto fairwinds-insights.yaml, allowing specification of multiple Helm values files. - Allow both Helm values files and inline fairwinds-insights.yaml values to be used. The inline values override those from values files.
- update versions
- update versions
- Add option to add more skopeo arguments through
SKOPEO_ARGSenvironment variable
- Fix trivy scan output location
- Revert trivy version
- Update packages
- Image scannning update
- Update vulnerable packages
- Trivy no longer downloads images
- Update alpine to remove CVE
- Obtain the OPA version from its Go package when submitting an OPA report (commit cd93f76).
- Update Trivy to 0.24
- Fix go.mod.
- Fix trivy
image.ScanImageFilearguments
- Fix go.mod
module, andimports, to use plugins sub-directory.
- Process v2 CustomChecks, which no longer have an Instance accompanying the rego policy.
- Debug output can be enabled by setting the
LOGRUS_LEVELenvironment variable todebug. - Processing of checks will now continue when there has been a failure, to collect and output all failure conditions. Multiple errors may be reflected in plugin output.
- Updated libs
- Fix trivy command parameters on 0.23.0
- Updated trivy version to 0.23.0
- Drop root command
- Adds auto config. file generation by scanning the repository files
- Fix reading helm
valuesFileandfluxFilewhen on cloned repo context - Fix internal
baseFolderwhen not in cloned repo context
- Add an
insightsinfofunction to make Insights information available in rego.
- Update plugin version
- Run apk update
- Support for external git repository
- Update dependencies
- Update OPA for removed CRD.
- Update Polaris to version 5.0.0
- Update Pluto to version v5.3.2
- Updated trivy version to 0.22.0
- Adds the HTTP body to the error to provide better error messages
- Update Go modules
- Updated trivy version
- Fix panic for missing sha in the image
- Bump alpine to 3.15
- Bump go modules
- Added environment variable for git informations.
- rebuild to fix CVEs in alpine:3.14
- Add helm
fluxFileandversionsupport
- Add helm remote chart functionality
- Bump dependencies and rebuild
- Handle type conversion errors for resource metadata
- rebuild to fix CVEs in alpine:3.14
- rebuilt to fix CVEs in alpine 3.14
- update trivy version
- update Go modules
- Improve error messages
- Add missing error checks
- Add SHA for docker images
- Add option to skip images contained in manifests when running trivy
- Add some debug logs
- Handle error in walkpath
- Update Go and modules
- Improve error handling in CI's git fetch info process
- update go dependencies
- Fix bug in Trivy to allow namespace to be sent up.
- Bump Alpine to 3.14
- Added configuration options to disable individual reports
- Fix
Options.TempFolderdefault destination
- Update alpine image
- Fix workload names
- Fix helm file name by replacing the release-name prefix.
- Dedupe Trivy scans
- Improved logging and output
- Respect mainline branch specified in config.
- update Trivy
- Add commit messages to scan
- Start sending fairwinds-insights.yaml to backend
- Add OPA as another check
- Add Pluto as another check
- Strip tags from manifest free images
- Added containers to workloads report
- Add container name to Trivy results
- Add log statement to Trivy
- Update Trivy to 0.11.0
- Added name to images that aren't in manifest
- Remove "**.com:" prefix and ".git" suffix from default repo name
- Update CHANGELOG
- Made
repositoryNameoptional
- Fixed a bug in error output
- created a separate
RunCommandthat doesn't have trivy-specific logic - started logging stdout/stderr directly instead of through logrus, to preserve newlines
- fixed formatting on message
- remove
panics - push helm values to file instead of using
--set - change output message
- set config defaults
- Updating Polaris version from 0.6 to 1.1
- New config format
- Send Kubernetes Resources to be saved
- Base results based on new action items instead of "Score"
- Process helm templates
- Initial release