Releases: stackrox/stackrox
Release list
5.0.0-rc.2
Added Features
- ROX-32148: Virtual machine scanning is now enabled by default. RHEL VMs created with OpenShift Virtualization can be scanned for package vulnerabilities after installing roxagent in the guest.
- ROX-34997: The Central CR now supports
spec.central.rolloutStrategy(RecreateorRollingUpdate) to configure the central deployment rollout strategy. Default remainsRecreate. - ROX-35181: Administrative events are now exposed as configurable custom Prometheus metrics (
rox_central_admin_event_*), aggregated by Type, Level, Domain, ResourceType, and ResourceName. Requires permission to read Administration resource, globally scoped. - ROX-35545: Added ACL change as a file access operation for runtime policies.
- ROX-35546: File access policies now detect extended attribute (xattr) changes.
- ROX-32461: Red Hat OpenShift Data Foundation is now officially supported as an S3-compatible backup target.
- ROX-35962: On OCP, central API is exposed via a new
central-ocpservice, signed and rotated by OCP. - ROX-35508: Scanner V4 now suppresses duplicate OSV.dev vulnerability records when Red Hat VEX data covers the same CVE for a Red Hat product image, showing Red Hat's own severity/CVSS/remediation data instead of a conflicting OSV.dev one. Enabled by default; disable via
ROX_SCANNER_V4_SUPPRESS_OSV_WITH_RED_HAT_VEX=falseif needed. - ROX-34488: Added support for cosign signature discovery via OCI 1.1 referrers, including
DSSE envelope verification for sigstore bundle-format signatures. - ROX-36858: Added more supported labels to the image and node vulnerability central custom metrics.
Removed Features
- Compliance container no longer collects Scanner V2 node inventories. Node scanning continues via Scanner V4 index reports, as long as Scanner V4 is enabled.
- ROX-36654: Removed legacy scanner (StackRox Scanner) across all installation methods.
Deprecated Features
- ROX-26281: block creation of new GCR integrations. Users are directed to use Google Artifact Registry instead.
- ROX-35079: installation of the
app.k8s.io/v1beta1/Applicationresource when central is installed is deprecated. It will be removed in a future release. - The
priorityfield on API responses for deployments, images, nodes, and components is deprecated and will be removed in a future release. Use therisk_scorefield on the same objects instead. Sorting by "Risk Priority" in search queries is also deprecated; sort by "Risk Score" instead. For clusters and namespaces, thepriorityfield will be removed and replaced by arisk_scorefield where applicable. - ROX-37014: The Images by severity, Nodes by severity, CVEs by severity, and Virtual machines by severity counts—including summary widgets and table columns—are deprecated and will be removed in a future release to improve page performance
Technical Changes
-
ROX-36784: Scanner V4 node indexing on OpenShift now reads the host RPM database Claircore reports: SQLite on RHEL 9+ (
/usr/share/rpm,/usr/lib/sysimage/rpm) and Berkeley DB on RHEL 8 (/usr/share/rpm,/usr/lib/sysimage/rpm-ostree-base-db). -
ROX-36824: Diagnostic bundles now redact the value of the
openshift.io/token-secret.valueannotation on secrets. Previously this OpenShift-managed annotation, which contains a plaintext service account token on generated dockercfg secrets, was included unredacted in the bundle. -
ROX-36660: The Fixable → CVE is not yet fixable policy criterion now matches Scanner V4 CVEs that have no fix version. Scanner V4 leaves
Fixed Byunset instead of empty (Scanner V2 always set an empty string), so the matcher previously skipped those CVEs. -
ROX-36490: The virtual machine enhanced data model (
ROX_VIRTUAL_MACHINES_ENHANCED_DATA_MODEL) is now enabled by default. -
ROX-32969: The
roxctl-linuxsymlink has been removed from the/assets/downloads/cli/directory inside the main container image. Only the architecture-specific binaries (roxctl-linux-amd64,roxctl-linux-arm64, etc.) remain. This change does not affect CLI downloads from the Central UI or any other supported download path. -
ROX-33078: Fixed telemetry gatherer failing to report database size metrics when using an external database. The database name is now read from the connection config instead of using the hardcoded default.
-
ROX-35006: Go runtime upgraded to 1.26. Unbracketed IPv6 addresses (e.g.
2001:db8::1) are no longer accepted; use bracketed format instead (e.g.[2001:db8::1]:443). -
ROX-34804: The machine access configuration for
config-controllernow validates the audience (audclaim) of the service account token. The expected audience iscentral.stackrox.io. When users have added their own role bindings to this machine access configuration, the audience check is not enforced by default to keep backwards compatibility. It is recommended to set the expected audience tocentral.stackrox.ioafter ensuring that all exchange tokens are being created with this audience claim. -
ROX-34535: Fixes an issue where if ScannerV2 is disabled or unavailable on initial startup the central deployment leaks GRPC connections until the scanner becomes available.
-
ROX-36509: Improved Central memory efficiency by optimizing process filter data structures in high-cardinality scenarios. The
ROX_PROCESS_FILTER_FAN_OUT_LEVELSenvironment variable now accepts values up to 255; higher values are automatically clamped with a warning.
4.11.5-rc.2
Full Changelog: 4.11.4...4.11.5
For a description of the changes, review the Release Notes on the Red Hat Documentation portal.
5.0.0-rc.1
Added Features
- ROX-32148: Virtual machine scanning is now enabled by default. RHEL VMs created with OpenShift Virtualization can be scanned for package vulnerabilities after installing roxagent in the guest.
- ROX-34997: The Central CR now supports
spec.central.rolloutStrategy(RecreateorRollingUpdate) to configure the central deployment rollout strategy. Default remainsRecreate. - ROX-35181: Administrative events are now exposed as configurable custom Prometheus metrics (
rox_central_admin_event_*), aggregated by Type, Level, Domain, ResourceType, and ResourceName. Requires permission to read Administration resource, globally scoped. - ROX-35545: Added ACL change as a file access operation for runtime policies.
- ROX-35546: File access policies now detect extended attribute (xattr) changes.
- ROX-32461: Red Hat OpenShift Data Foundation is now officially supported as an S3-compatible backup target.
- ROX-35962: On OCP, central API is exposed via a new
central-ocpservice, signed and rotated by OCP. - ROX-35508: Scanner V4 now suppresses duplicate OSV.dev vulnerability records when Red Hat VEX data covers the same CVE for a Red Hat product image, showing Red Hat's own severity/CVSS/remediation data instead of a conflicting OSV.dev one. Enabled by default; disable via
ROX_SCANNER_V4_SUPPRESS_OSV_WITH_RED_HAT_VEX=falseif needed. - ROX-34488: Added support for cosign signature discovery via OCI 1.1 referrers, including
DSSE envelope verification for sigstore bundle-format signatures. - ROX-36858: Added more supported labels to the image and node vulnerability central custom metrics.
Removed Features
- Compliance container no longer collects Scanner V2 node inventories. Node scanning continues via Scanner V4 index reports, as long as Scanner V4 is enabled.
- ROX-36654: Removed legacy scanner (StackRox Scanner) across all installation methods.
Deprecated Features
- ROX-26281: block creation of new GCR integrations. Users are directed to use Google Artifact Registry instead.
- ROX-35079: installation of the
app.k8s.io/v1beta1/Applicationresource when central is installed is deprecated. It will be removed in a future release. - The
priorityfield on API responses for deployments, images, nodes, and components is deprecated and will be removed in a future release. Use therisk_scorefield on the same objects instead. Sorting by "Risk Priority" in search queries is also deprecated; sort by "Risk Score" instead. For clusters and namespaces, thepriorityfield will be removed and replaced by arisk_scorefield where applicable. - ROX-37014: The Images by severity, Nodes by severity, CVEs by severity, and Virtual machines by severity counts—including summary widgets and table columns—are deprecated and will be removed in a future release to improve page performance
Technical Changes
-
ROX-36784: Scanner V4 node indexing on OpenShift now reads the host RPM database Claircore reports: SQLite on RHEL 9+ (
/usr/share/rpm,/usr/lib/sysimage/rpm) and Berkeley DB on RHEL 8 (/usr/share/rpm,/usr/lib/sysimage/rpm-ostree-base-db). -
ROX-36824: Diagnostic bundles now redact the value of the
openshift.io/token-secret.valueannotation on secrets. Previously this OpenShift-managed annotation, which contains a plaintext service account token on generated dockercfg secrets, was included unredacted in the bundle. -
ROX-36660: The Fixable → CVE is not yet fixable policy criterion now matches Scanner V4 CVEs that have no fix version. Scanner V4 leaves
Fixed Byunset instead of empty (Scanner V2 always set an empty string), so the matcher previously skipped those CVEs. -
ROX-36490: The virtual machine enhanced data model (
ROX_VIRTUAL_MACHINES_ENHANCED_DATA_MODEL) is now enabled by default. -
ROX-32969: The
roxctl-linuxsymlink has been removed from the/assets/downloads/cli/directory inside the main container image. Only the architecture-specific binaries (roxctl-linux-amd64,roxctl-linux-arm64, etc.) remain. This change does not affect CLI downloads from the Central UI or any other supported download path. -
ROX-33078: Fixed telemetry gatherer failing to report database size metrics when using an external database. The database name is now read from the connection config instead of using the hardcoded default.
-
ROX-35006: Go runtime upgraded to 1.26. Unbracketed IPv6 addresses (e.g.
2001:db8::1) are no longer accepted; use bracketed format instead (e.g.[2001:db8::1]:443). -
ROX-34804: The machine access configuration for
config-controllernow validates the audience (audclaim) of the service account token. The expected audience iscentral.stackrox.io. When users have added their own role bindings to this machine access configuration, the audience check is not enforced by default to keep backwards compatibility. It is recommended to set the expected audience tocentral.stackrox.ioafter ensuring that all exchange tokens are being created with this audience claim. -
ROX-34535: Fixes an issue where if ScannerV2 is disabled or unavailable on initial startup the central deployment leaks GRPC connections until the scanner becomes available.
-
ROX-36509: Improved Central memory efficiency by optimizing process filter data structures in high-cardinality scenarios. The
ROX_PROCESS_FILTER_FAN_OUT_LEVELSenvironment variable now accepts values up to 255; higher values are automatically clamped with a warning.
4.11.5-rc.1
Full Changelog: 4.11.4...4.11.5
For a description of the changes, review the Release Notes on the Red Hat Documentation portal.
4.10.9
Full Changelog: 4.10.8...4.10.9
For a description of the changes, review the Release Notes on the Red Hat Documentation portal.
4.10.9-rc.2
Full Changelog: 4.10.8...4.10.9
For a description of the changes, review the Release Notes on the Red Hat Documentation portal.
4.10.9-rc.1
Full Changelog: 4.10.8...4.10.9
For a description of the changes, review the Release Notes on the Red Hat Documentation portal.
4.11.4
Technical Changes
- ROX-36824: Diagnostic bundles now redact the value of the
openshift.io/token-secret.valueannotation on secrets. Previously this OpenShift-managed annotation, which contains a plaintext service account token on generated dockercfg secrets, was included unredacted in the bundle. - ROX-36660: The Fixable → CVE is not yet fixable policy criterion now matches Scanner V4 CVEs that have no fix version. Scanner V4 leaves
Fixed Byunset instead of empty (Scanner V2 always set an empty string), so the matcher previously skipped those CVEs.
Full Changelog: 4.11.3...4.11.4
For a description of the changes, review the Release Notes on the Red Hat Documentation portal.
4.10.8
Technical Changes
- ROX-36824: Diagnostic bundles now redact the value of the
openshift.io/token-secret.valueannotation on secrets. Previously this OpenShift-managed annotation, which contains a plaintext service account token on generated dockercfg secrets, was included unredacted in the bundle. - ROX-36660: The Fixable → CVE is not yet fixable policy criterion now matches Scanner V4 CVEs that have no fix version. Scanner V4 leaves
Fixed Byunset instead of empty (Scanner V2 always set an empty string), so the matcher previously skipped those CVEs.
Full Changelog: 4.10.7...4.10.8
For a description of the changes, review the Release Notes on the Red Hat Documentation portal.
4.11.4-rc.1
Technical Changes
- ROX-36824: Diagnostic bundles now redact the value of the
openshift.io/token-secret.valueannotation on secrets. Previously this OpenShift-managed annotation, which contains a plaintext service account token on generated dockercfg secrets, was included unredacted in the bundle. - ROX-36660: The Fixable → CVE is not yet fixable policy criterion now matches Scanner V4 CVEs that have no fix version. Scanner V4 leaves
Fixed Byunset instead of empty (Scanner V2 always set an empty string), so the matcher previously skipped those CVEs.
Full Changelog: 4.11.3...4.11.4
For a description of the changes, review the Release Notes on the Red Hat Documentation portal.