What kubescape/kubescape shipped
Written by FoxPlug from public releases; not affiliated with Kubescape. An automatic summary of the public release, pull request and commit data of github.com/kubescape/kubescape. Kubescape did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Fleet scans now print a summary showing how each cluster performed and where they disagree, instead of requiring jq to parse JSON output. Pull request #3929
- Image signature verification now validates that the signed digest matches the image being verified, closing a gap where invalid signatures could be accepted. Pull request #3930
- SARIF and GitHub Actions output now report degraded scan coverage and skipped controls with their reasons. Pull request #3926
- Namespace filters can now be reloaded from a ConfigMap without restarting the Kubescape server. Pull request #3925
- Evidence resolution for resources rendered from Helm charts now works correctly and shows accurate line numbers. Pull request #3911
- The
kubescape fixcommand now respects--output-dirfor file-based reports instead of rewriting manifests in place. Pull request #3880 - Incremental scans no longer incorrectly reuse cached verdicts when a policy reads resource status through object.get. Pull request #3918
- Network policy analysis now correctly requires matching ports and protocols between source and destination for reachability. Pull request #3909
- RegoLibrary bumped to v2.0.36 to support signed checksum-manifest verification. Pull request #3893
- Port forwarder now times out after 30 seconds by default to prevent infinite hangs. Pull request #3873
Why it matters
This week addressed critical scan reliability issues in incremental caching, image verification, and fleet scanning. Fixes to incremental verdict reuse, network policy analysis, and report encryption ensure scans produce consistent and correct results. New features like fleet summaries and namespace filter reloading make the tool more operational.
Changelog entry
- Fleet scans print a summary after completion showing cluster status and fleet-wide results Pull request #3929
- Image signature verification validates signed digest matches the image through cosign claim verification Pull request #3930
- SARIF and GitHub Actions printers report degraded scan coverage and skipped controls with reasons Pull request #3926
- Namespace filters reload from KS_NAMESPACE_FILTERS_FILE without server restart Pull request #3925
- Incremental scans no longer reuse verdicts when policies read status through object.get Pull request #3918
- Incremental scans respect metadata.resourceVersion and metadata.managedFields changes Pull request #3919
- Helm chart resources now resolve evidence line numbers correctly Pull request #3911
- Network policy reachability analysis requires matching ports and protocols Pull request #3909
- kubescape fix command respects --output-dir for file-based reports Pull request #3880
- Port forwarder adds 30-second timeout to prevent infinite hangs Pull request #3873
Kubescape improved scan reliability this week: fixed incremental cache reuse bugs, added fleet scan summaries, strengthened image signature verification, and enabled runtime namespace filter updates without restarts.
This week's Kubescape updates focus on reliability and operational improvements. Critical fixes prevent incremental scans from reusing verdicts incorrectly when policies read status fields or when scan context changes. Fleet scans now print human-readable summaries. Image signature verification now validates digest matching. Namespace filters reload at runtime. Network policy analysis correctly requires matching ports. These changes ensure scan results stay consistent and accurate across different contexts.
Week of September 14, 2026
What shipped
- Added
--fleet-reportflag to write a combined report across multiple--kube-contextsscans instead of separate reports per context. Pull request #3815 - Fleet reports now highlight which controls clusters disagree on, making it easier to spot divergence in a fleet. Pull request #3878
- Fleet reports now include a fleet-wide compliance rollup score instead of requiring manual calculation from per-cluster figures. Pull request #3852
- Introduced partition and spill store engine to bound memory usage during streaming resource collection on disk. Pull request #3818
- Wired partition store into streaming collector so resource batches no longer all accumulate in heap memory at once. Pull request #3863
- Image scanning now supports full Azure credential chain for ACR authentication including service principals, managed identity, and workload federation. Pull request #3853
- Updated embedded CEL admission-policy bundle from v0.14 to v0.15 with new Agent Runtime policies for Sandbox and Substrate resources. Pull request #3871
- Fleet reports are now written atomically to prevent corruption if a write fails partway through. Pull request #3849
- Added line number resolution for delete and review paths in
--show-evidenceoutput, completing coverage of all three remediation path types. Pull request #3830 - Fixed stalled pagination loops when Kubernetes API servers return the same continuation token multiple times. Pull request #3859
Why it matters
Fleet scanning now has dedicated reporting that shows agreement and disagreement across clusters at a glance, addressing a major pain point for multi-cluster operators. Memory efficiency improvements enable scanning very large clusters without unbounded heap growth. Image scanning gains better credential support and stricter vulnerability validation.
Changelog entry
- Add
--fleet-reportflag to generate a single combined report across multiple Kubernetes contexts Pull request #3815 - Fleet reports now identify which controls clusters disagree on Pull request #3878
- Fleet reports include fleet-wide compliance score rollup Pull request #3852
- Introduce partition and spill store engine for bounded memory in streaming collection Pull request #3818
- Integrate partition store into streaming collector to reduce heap pressure Pull request #3863
- Support Azure DefaultAzureCredential chain for ACR image authentication Pull request #3853
- Update CEL admission-policy bundle to v0.15 with Agent Runtime policies Pull request #3871
- Write fleet reports atomically to prevent corruption on write failures Pull request #3849
- Resolve line numbers for delete and review remediation paths in evidence output Pull request #3830
- Fix infinite pagination loops from duplicate Kubernetes API continuation tokens Pull request #3859
- Support nested Harbor repository paths in image scanning Pull request #3860
- Warn when incompatible flags combine with anonymized source paths in evidence Pull request #3830
- Skip evidence lines when source paths are anonymized Pull request #3830
- Persist workload scan report timestamps to spec.metadata.report.createdAt Pull request #3869
- Fix panic from negative nodeIndex values in location resolver Pull request #3874
- Fix misleading skip log and severity loop break in image processing Pull request #3848
- Restore fleet context after runner panic instead of leaving stale context Pull request #3856
- Stop printing usage text when patch severity threshold validation fails Pull request #3857
- Skip IaC scan tests when offline policies are missing to prevent CI failures Pull request #3806
Fleet scanning gets its first dedicated reports: see compliance rollup, control disagreement, and per-cluster findings in one file. Memory now bounded during large scans. Azure ACR auth chain and stricter CVE validation for images.
Kubescape fleet scanning now has dedicated multi-cluster reports showing fleet-wide compliance, which controls clusters disagree on, and per-cluster detail—no more opening individual files to compare. Streaming resource collection now bounds memory with partition storage. Image scans validate vulnerability freshness and unknown-severity CVEs. Azure Container Registry gains full credential chain support.