kubescape

kubescape·kubescape.kubescape

An open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters

Kubescape is an open-source Kubernetes security platform. It includes risk analysis, security compliance, and misconfiguration scanning. Targeted at the DevSecOps practitioner or platform engineer, it offers an easy-to-use CLI interface, flexible output formats, and automated scanning capabilities. It saves Kubernetes users and admins precious time, effort, and resources. Kubescape scans clusters, YAML files, and Helm charts. It detects misconfigurations according to multiple frameworks (including NSA-CISA, MITRE ATT&CK® and the CIS Benchmark). Kubescape was created by ARMO and is a Cloud Native Computing Foundation (CNCF) sandbox project.

winget install --id kubescape.kubescape --exact --source winget

Latest 4.0.11·July 22, 2026

Release Notes

Changelog

  • 411b179 Cache compiled CEL programs across scanned objects (#2503)
  • 6bbcccd Derive cmd/vap policy metadata from the embedded VAP bundle (#2485)
  • 1a6cf89 Embed and load VAP YAML from the vendored bundle (#2474)
  • 6cb59a4 Expand encryption and decryption coverage for resource metadata (#2442)
  • df44c79 Fix air-gapped mode -- thread explicit offline flag to policy getters instead of relying on nil (#2458)
  • 949a569 Fix control-inputs fallback to return real local getter instead of unloaded store (#2515)
  • e4ab628 Fix local control cache (#2463)
  • 3c4b059 Fix/helm templates plain yaml warnings (#2509)
  • efb658f Vendor the CEL admission policy bundle (#2455)
  • 7dbe430 [ LFX 2026] feat(exceptions): honor objectSelector.matchExpressions via PostureExceptionPolicy.ObjectSelector (#2480)
  • 8a2e1a2 [Fix] : severity-based image exceptions in JSON, SARIF, and patch output -- use filtered Matches instead of RemainingMatches (#2522)
  • 5afd77b add unit tests for GetPreReqCmd and kubeconfig flag (#2486)
  • 21e2db5 core: Add test coverage for Kubescape.Diff pretty-printer output path (#2467)
  • 55df2bd docs(cli): document report protection workflow (#2508)
  • ef65747 docs(cli): improve report protection help and examples (#2510)
  • 80191c7 feat(anonymizer): support reversible container metadata transformation (#2473)
  • 3f29f09 feat(mcp): Add headless OPAProcessor for low-latency Network Policy s… (#2512)
  • 062d9cf feat(mcp): implement headless OPAProcessor rbac scanner (#2492)
  • f68fdc0 feat(operator): add quarantine action to remediate CLI subcommand (#2461)
  • 29928b8 feat(patch): add support for OCI and Local exports (#2471)
  • 79ae44e feat(printer): add GitLab SAST report output format (#2505)
  • df68301 feat(reportcrypto): add decryption support for encrypted resource metadata (#2493)
  • b830283 feat: add container profile tools and resources to MCP server (#2479)
  • 5757418 feat: implement AWS ECR vulnerability adaptor (#2488)
  • 20b5a83 feat: introduce Container Image Vulnerability (CIV) Adaptor interfaces (#2482)
  • 9ea839a feat: run CEL controls as part of the scan (#2525)
  • f7e805a fix(httphandler): add missing panic recovery to Metrics handler (#2465)
  • 05e3cc9 fix(httphandler): decouple prometheus metrics scan from request context (#2451)
  • 8d5d0d7 fix(httphandler): populate report in synchronous scan response (#2483)
  • 4d80ab4 fix(imagescan): preserve matches on metadata lookup errors (#2519)
  • 5b93069 fix(mcp): add double-checked mutex locking to k8sClient lazy init (#2506)
  • 0b3d0f6 fix(printer): don't append .txt to /dev/null in PrettyPrinter.SetWriter (#2502)
  • 6ba3a1d fix(sarif): don't os.Exit on unencodable fix, avoid empty SARIF file (#2499)
  • ef6b608 fix(sarif): surface PrettyWrite errors instead of silently writing empty file (#2497)
  • 8fb2eb1 fix(scan): don't let --exceptions/--controls-config/--attack-tracks trigger air-gapped mode (#2532)
  • 497f086 fix(scan): restore root PersistentPreRun for kubescape scan invocations (#2530)
  • 2adea95 fix(vap): deploy-library serves the embedded bundle, downloads only via --from-release (#2507) (#2514)
  • 82dd34d fix: preserve explicit exceptions/inputs with use-artifacts-from (#2490)
  • 81617ed fix: support namespace/kind/name workload format (#2459) (#2460)
  • 85933c9 rbac file todo to check api version is resolved (#2523)
  • 5bffddf refactor: decompose monolithic Results API handler (#2477)
  • 11a05e1 test(core): cover Kubescape.Download unknown-target error path (#2468) Released by GoReleaser.

Installer type: portable

x6477F74DB439C9326E4FA3556A08EC8D83C61EC9C1038CDF32D26BEF5467385798
arm64B868B0B3E9C280D8939A16A994A0DA20667A182805438434C7BA68C974E35D39

Details

Homepage
https://github.com/kubescape/kubescape
License
Apache-2.0
Publisher
kubescape
Support
https://github.com/kubescape/kubescape/issues
Copyright
Copyright 2021-2023, the Kubescape Authors
Moniker
kubescape

Tags

best-practicedevopskubernetesmitre-attacknsasecurityvulnerability-detection

Older versions (26)

4.0.10
x64387A01E7D4E3D52CD565B97F411390EAB393AB5527E40D93527063716BFDD4AC
arm64DEEEDE3591937B511DD9F122030377FA53B5822095DA100A0AFD2A9116CD72C4
4.0.9
x64C9F9E268FF974F3C4A2E1960DFAA5C8ABED3B24760E727790632427853CAF387
arm640D41DA98C24C036317DD6FAC2C95636B4A54662D7ADF4D6E59B34805B1EECF43
4.0.8
x648CD8D6A166B4FFBC1239F2B56221527406A2B200C83043739AFCC27825603E64
arm64C36CAAC6F1DD00C03BA1FA43ACFDEDB7593E564FCB5E78029AB1A142625F5CBF
4.0.7
x6422179761A27F9761A206BA2C28E77796EB8776497FABFDBC8245567C86B5DC36
arm649C9C2EF45506FE48EB5A670035DA56A008CEA4EA24FF3347D04687CFC5F109E6
4.0.6
x64592CB071C507CB49231E1D288181FAA76A5E8FC0543484B24DEE5F737E2B6BF0
arm649BD2730A9568F42DA83AD38CBB57EC7A6BC46C883D927C3EB20B8D99121C11F1
4.0.5
x64F3009C9D55A1113EFB9635D2C0947C5590C6C54C98EACB4F34B1755ADC8D7907
arm64E523C8E4A3465DD38497EB3EB3DA13736E81DCAB111CA1335A4338F568BE668B
4.0.3
x64DAF4D257FC7417EA6ED91AFC1D795FCB024A90301A96D75AAD63A88EAE21EB35
arm64F17475A766453726103E8ABE4507E2BD33548E3EC5BD6D681E2818EC04496D62
4.0.2
x646D9D65C3F0D49600F8163EC69710579F99F68DC980DBCD8C91A2385D2B69B204
arm64ABAF3F920B1BC0A088852D7B0B3501D501FDFE6A70ABD460C8F11C8FFD5691B8
4.0.1
x64DE3F6CF1BF55FDA0D154B4C502AA7D6C908E9D920ED26EA3D9FC255D86259EB7
arm64BF57DD5CCCD680EE71B21869CBF706D71DACEC9BD691160AE6EB0C33EA1E3AC3
4.0.0
x6400B3254C502B67B18818396DD72BEBB324D5470F69BC7B1023F10834649907B2
arm64F200DA7180BE8375AC31EAB3D049AF4DEFF3A0108C37EE1C7C4A428A0BBF1CCA
3.0.46
x64B49D04F7F197FC44262F08597B91D2E8E15C1855E1C40D3560694139AC3917FA
arm647EF9F7421F13656B4435EA04E291FF6C6F4EFCAC0582A6A632A1FDCCC8630034
3.0.45
x642C490E289F20806A7627E658B943540A7D0DDAC646CE55F54CAEC04CBEAA3E13
arm64BF109703372FC13C9B0C47F39DB87AE67CB8397AE1DB467CBCF30F4B2E43BCE9
3.0.44
x64B99317A5D264F279F5017C24C43DD956A6A194C78BC879AEA348500172E56849
arm64FBAC25477704373C66D12145DA19C09C2871864D7923622B05BF19EEBC734A64
3.0.43
x6489983322CC4F7AEA18B890DFB3396EB7E28B9E7D70262886C0C676B1CB606F9C
arm64870FAE09E4FECECAD3A324146BEEC7942D0ACB0B0E8089D3564E5A7176F567C5
3.0.42
x6485B86FE756FAF272F2BD5DFCB5D666FC776D096CB88B62E7824FB4970D10D24B
arm64146BDC184DF8EC932CC818327E929DB94066C3DB3F0286080AD27437AB267532
3.0.41
x64BDA29D7C79787896DD27D8C36D937989FF949C699C79E1D7B425CB436279E9F3
arm644CFC2FE709561E2DF8DFBD649702DCF989822FF91E1D6A99C95FA16BBEC62185
3.0.40
x64BF1A9DFE958D720D0C741ABE491C5CEAAB3B0B492C24C65D9ABA7F73BA86BA95
arm64ECA6D038D724B1D172FB8F4A4CAD2A0C51BD4B45C14C1F2ADB5AEC20AAE47C73
3.0.39
x64DC6FBF0965547FD25537A672E77DD6B429E232675B0645FD3C710313CD04C42D
arm640FD4A20B0741E1D912FCA6529B9FA5E9C8A13828ECCFEA992063EA26FE8B4420
3.0.38
x648F286A213A1B42145F68B5AE8767E31DD5419AA8ED47B22A26867AF10E0BA1E9
arm6448F4A62C60B72CD04F3C2FB65A56C811E720448254CC43858DB586333A9F7569
3.0.37
x645699688B1936CE1095164E5975F18791F48BC0FD032A3879D750C7BD8DF27598
arm6485D48BE170B3264B523272B2C7856C483C4B00A4DEFF26334F64FA0F7ED9C486
3.0.36
x644CD7AF2E55598E1A27ACB98D96C6E0E262F12829255AD77CF77260FACB131C62
arm647B41F6539042C8E7FF3C56DAE7FC2676D0D0AB6EABABA4793249C409ED409AB6
3.0.35
x649DF4DCEA8EB61C537BDFC06361F433A8D3D0774E549C395A0BC89DC44742DBC3
arm64AB5971A6D34EFA0901E31602FF67944CE459BCA237406CB37017B9F6DC8E7355
3.0.34
x6469F0CAEF7CDD1B6809829E08AFC71B278C0900B7FE31B20F6EC363A4B7899923
arm64F6F8C131745D476D50E3ED750717C121AF1041D8ABF4944938FDE321815B5D36
3.0.28
neutralFB697B4C0DFD65A9BA8BB8D7B3F8828E3B5D0C612F46C9CB297198E088DB36BD
3.0.11
x64E81A8055BA4207C16A090D431DF50613F30E81E85373B4E738ECFB0717945467
arm64E81A8055BA4207C16A090D431DF50613F30E81E85373B4E738ECFB0717945467
3.0.6
x64C463CA5B0E6DE497447F5389BF8E67B8E7FFE917D404F944E4816C0EE5910E11
arm64B7FCE4384F84ED7D9AAA322AC74CF11C493832AF1E3B37C514B9D02A3718FFBA