Skip to content

Releases: stackrox/stackrox

5.0.0-rc.2

5.0.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

@rhacs-bot rhacs-bot released this 01 Oct 21:10

Added Features

  • ROX-32148: Virtual machine scanning is now enabled by default. RHEL VMs created with OpenShift Virtualization can be scanned for package vulnerabilities after installing roxagent in the guest.
  • ROX-34997: The Central CR now supports spec.central.rolloutStrategy (Recreate or RollingUpdate) to configure the central deployment rollout strategy. Default remains Recreate.
  • ROX-35181: Administrative events are now exposed as configurable custom Prometheus metrics (rox_central_admin_event_*), aggregated by Type, Level, Domain, ResourceType, and ResourceName. Requires permission to read Administration resource, globally scoped.
  • ROX-35545: Added ACL change as a file access operation for runtime policies.
  • ROX-35546: File access policies now detect extended attribute (xattr) changes.
  • ROX-32461: Red Hat OpenShift Data Foundation is now officially supported as an S3-compatible backup target.
  • ROX-35962: On OCP, central API is exposed via a new central-ocp service, signed and rotated by OCP.
  • ROX-35508: Scanner V4 now suppresses duplicate OSV.dev vulnerability records when Red Hat VEX data covers the same CVE for a Red Hat product image, showing Red Hat's own severity/CVSS/remediation data instead of a conflicting OSV.dev one. Enabled by default; disable via ROX_SCANNER_V4_SUPPRESS_OSV_WITH_RED_HAT_VEX=false if needed.
  • ROX-34488: Added support for cosign signature discovery via OCI 1.1 referrers, including
    DSSE envelope verification for sigstore bundle-format signatures.
  • ROX-36858: Added more supported labels to the image and node vulnerability central custom metrics.

Removed Features

  • Compliance container no longer collects Scanner V2 node inventories. Node scanning continues via Scanner V4 index reports, as long as Scanner V4 is enabled.
  • ROX-36654: Removed legacy scanner (StackRox Scanner) across all installation methods.

Deprecated Features

  • ROX-26281: block creation of new GCR integrations. Users are directed to use Google Artifact Registry instead.
  • ROX-35079: installation of the app.k8s.io/v1beta1/Application resource when central is installed is deprecated. It will be removed in a future release.
  • The priority field on API responses for deployments, images, nodes, and components is deprecated and will be removed in a future release. Use the risk_score field on the same objects instead. Sorting by "Risk Priority" in search queries is also deprecated; sort by "Risk Score" instead. For clusters and namespaces, the priority field will be removed and replaced by a risk_score field where applicable.
  • ROX-37014: The Images by severity, Nodes by severity, CVEs by severity, and Virtual machines by severity counts—including summary widgets and table columns—are deprecated and will be removed in a future release to improve page performance

Technical Changes

  • ROX-36784: Scanner V4 node indexing on OpenShift now reads the host RPM database Claircore reports: SQLite on RHEL 9+ (/usr/share/rpm, /usr/lib/sysimage/rpm) and Berkeley DB on RHEL 8 (/usr/share/rpm, /usr/lib/sysimage/rpm-ostree-base-db).

  • ROX-36824: Diagnostic bundles now redact the value of the openshift.io/token-secret.value annotation on secrets. Previously this OpenShift-managed annotation, which contains a plaintext service account token on generated dockercfg secrets, was included unredacted in the bundle.

  • ROX-36660: The Fixable → CVE is not yet fixable policy criterion now matches Scanner V4 CVEs that have no fix version. Scanner V4 leaves Fixed By unset instead of empty (Scanner V2 always set an empty string), so the matcher previously skipped those CVEs.

  • ROX-36490: The virtual machine enhanced data model (ROX_VIRTUAL_MACHINES_ENHANCED_DATA_MODEL) is now enabled by default.

  • ROX-32969: The roxctl-linux symlink has been removed from the /assets/downloads/cli/ directory inside the main container image. Only the architecture-specific binaries (roxctl-linux-amd64, roxctl-linux-arm64, etc.) remain. This change does not affect CLI downloads from the Central UI or any other supported download path.

  • ROX-33078: Fixed telemetry gatherer failing to report database size metrics when using an external database. The database name is now read from the connection config instead of using the hardcoded default.

  • ROX-35006: Go runtime upgraded to 1.26. Unbracketed IPv6 addresses (e.g. 2001:db8::1) are no longer accepted; use bracketed format instead (e.g. [2001:db8::1]:443).

  • ROX-34804: The machine access configuration for config-controller now validates the audience (aud claim) of the service account token. The expected audience is central.stackrox.io. When users have added their own role bindings to this machine access configuration, the audience check is not enforced by default to keep backwards compatibility. It is recommended to set the expected audience to central.stackrox.io after ensuring that all exchange tokens are being created with this audience claim.

  • ROX-34535: Fixes an issue where if ScannerV2 is disabled or unavailable on initial startup the central deployment leaks GRPC connections until the scanner becomes available.

  • ROX-36509: Improved Central memory efficiency by optimizing process filter data structures in high-cardinality scenarios. The ROX_PROCESS_FILTER_FAN_OUT_LEVELS environment variable now accepts values up to 255; higher values are automatically clamped with a warning.

4.11.5-rc.2

4.11.5-rc.2 Pre-release
Pre-release

Choose a tag to compare

@rhacs-bot rhacs-bot released this 01 Oct 05:48

Full Changelog: 4.11.4...4.11.5

For a description of the changes, review the Release Notes on the Red Hat Documentation portal.

5.0.0-rc.1

5.0.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@rhacs-bot rhacs-bot released this 28 Sep 05:09

Added Features

  • ROX-32148: Virtual machine scanning is now enabled by default. RHEL VMs created with OpenShift Virtualization can be scanned for package vulnerabilities after installing roxagent in the guest.
  • ROX-34997: The Central CR now supports spec.central.rolloutStrategy (Recreate or RollingUpdate) to configure the central deployment rollout strategy. Default remains Recreate.
  • ROX-35181: Administrative events are now exposed as configurable custom Prometheus metrics (rox_central_admin_event_*), aggregated by Type, Level, Domain, ResourceType, and ResourceName. Requires permission to read Administration resource, globally scoped.
  • ROX-35545: Added ACL change as a file access operation for runtime policies.
  • ROX-35546: File access policies now detect extended attribute (xattr) changes.
  • ROX-32461: Red Hat OpenShift Data Foundation is now officially supported as an S3-compatible backup target.
  • ROX-35962: On OCP, central API is exposed via a new central-ocp service, signed and rotated by OCP.
  • ROX-35508: Scanner V4 now suppresses duplicate OSV.dev vulnerability records when Red Hat VEX data covers the same CVE for a Red Hat product image, showing Red Hat's own severity/CVSS/remediation data instead of a conflicting OSV.dev one. Enabled by default; disable via ROX_SCANNER_V4_SUPPRESS_OSV_WITH_RED_HAT_VEX=false if needed.
  • ROX-34488: Added support for cosign signature discovery via OCI 1.1 referrers, including
    DSSE envelope verification for sigstore bundle-format signatures.
  • ROX-36858: Added more supported labels to the image and node vulnerability central custom metrics.

Removed Features

  • Compliance container no longer collects Scanner V2 node inventories. Node scanning continues via Scanner V4 index reports, as long as Scanner V4 is enabled.
  • ROX-36654: Removed legacy scanner (StackRox Scanner) across all installation methods.

Deprecated Features

  • ROX-26281: block creation of new GCR integrations. Users are directed to use Google Artifact Registry instead.
  • ROX-35079: installation of the app.k8s.io/v1beta1/Application resource when central is installed is deprecated. It will be removed in a future release.
  • The priority field on API responses for deployments, images, nodes, and components is deprecated and will be removed in a future release. Use the risk_score field on the same objects instead. Sorting by "Risk Priority" in search queries is also deprecated; sort by "Risk Score" instead. For clusters and namespaces, the priority field will be removed and replaced by a risk_score field where applicable.
  • ROX-37014: The Images by severity, Nodes by severity, CVEs by severity, and Virtual machines by severity counts—including summary widgets and table columns—are deprecated and will be removed in a future release to improve page performance

Technical Changes

  • ROX-36784: Scanner V4 node indexing on OpenShift now reads the host RPM database Claircore reports: SQLite on RHEL 9+ (/usr/share/rpm, /usr/lib/sysimage/rpm) and Berkeley DB on RHEL 8 (/usr/share/rpm, /usr/lib/sysimage/rpm-ostree-base-db).

  • ROX-36824: Diagnostic bundles now redact the value of the openshift.io/token-secret.value annotation on secrets. Previously this OpenShift-managed annotation, which contains a plaintext service account token on generated dockercfg secrets, was included unredacted in the bundle.

  • ROX-36660: The Fixable → CVE is not yet fixable policy criterion now matches Scanner V4 CVEs that have no fix version. Scanner V4 leaves Fixed By unset instead of empty (Scanner V2 always set an empty string), so the matcher previously skipped those CVEs.

  • ROX-36490: The virtual machine enhanced data model (ROX_VIRTUAL_MACHINES_ENHANCED_DATA_MODEL) is now enabled by default.

  • ROX-32969: The roxctl-linux symlink has been removed from the /assets/downloads/cli/ directory inside the main container image. Only the architecture-specific binaries (roxctl-linux-amd64, roxctl-linux-arm64, etc.) remain. This change does not affect CLI downloads from the Central UI or any other supported download path.

  • ROX-33078: Fixed telemetry gatherer failing to report database size metrics when using an external database. The database name is now read from the connection config instead of using the hardcoded default.

  • ROX-35006: Go runtime upgraded to 1.26. Unbracketed IPv6 addresses (e.g. 2001:db8::1) are no longer accepted; use bracketed format instead (e.g. [2001:db8::1]:443).

  • ROX-34804: The machine access configuration for config-controller now validates the audience (aud claim) of the service account token. The expected audience is central.stackrox.io. When users have added their own role bindings to this machine access configuration, the audience check is not enforced by default to keep backwards compatibility. It is recommended to set the expected audience to central.stackrox.io after ensuring that all exchange tokens are being created with this audience claim.

  • ROX-34535: Fixes an issue where if ScannerV2 is disabled or unavailable on initial startup the central deployment leaks GRPC connections until the scanner becomes available.

  • ROX-36509: Improved Central memory efficiency by optimizing process filter data structures in high-cardinality scenarios. The ROX_PROCESS_FILTER_FAN_OUT_LEVELS environment variable now accepts values up to 255; higher values are automatically clamped with a warning.

4.11.5-rc.1

4.11.5-rc.1 Pre-release
Pre-release

Choose a tag to compare

@rhacs-bot rhacs-bot released this 28 Sep 19:47

Full Changelog: 4.11.4...4.11.5

For a description of the changes, review the Release Notes on the Red Hat Documentation portal.

4.10.9

Choose a tag to compare

@rhacs-bot rhacs-bot released this 28 Sep 18:42

Full Changelog: 4.10.8...4.10.9

For a description of the changes, review the Release Notes on the Red Hat Documentation portal.

4.10.9-rc.2

4.10.9-rc.2 Pre-release
Pre-release

Choose a tag to compare

@rhacs-bot rhacs-bot released this 25 Sep 09:57

Full Changelog: 4.10.8...4.10.9

For a description of the changes, review the Release Notes on the Red Hat Documentation portal.

4.10.9-rc.1

4.10.9-rc.1 Pre-release
Pre-release

Choose a tag to compare

@rhacs-bot rhacs-bot released this 24 Sep 12:44

Full Changelog: 4.10.8...4.10.9

For a description of the changes, review the Release Notes on the Red Hat Documentation portal.

4.11.4

Choose a tag to compare

@rhacs-bot rhacs-bot released this 14 Sep 18:42

Technical Changes

  • ROX-36824: Diagnostic bundles now redact the value of the openshift.io/token-secret.value annotation on secrets. Previously this OpenShift-managed annotation, which contains a plaintext service account token on generated dockercfg secrets, was included unredacted in the bundle.
  • ROX-36660: The Fixable → CVE is not yet fixable policy criterion now matches Scanner V4 CVEs that have no fix version. Scanner V4 leaves Fixed By unset instead of empty (Scanner V2 always set an empty string), so the matcher previously skipped those CVEs.

Full Changelog: 4.11.3...4.11.4

For a description of the changes, review the Release Notes on the Red Hat Documentation portal.

4.10.8

Choose a tag to compare

@rhacs-bot rhacs-bot released this 14 Sep 18:41

Technical Changes

  • ROX-36824: Diagnostic bundles now redact the value of the openshift.io/token-secret.value annotation on secrets. Previously this OpenShift-managed annotation, which contains a plaintext service account token on generated dockercfg secrets, was included unredacted in the bundle.
  • ROX-36660: The Fixable → CVE is not yet fixable policy criterion now matches Scanner V4 CVEs that have no fix version. Scanner V4 leaves Fixed By unset instead of empty (Scanner V2 always set an empty string), so the matcher previously skipped those CVEs.

Full Changelog: 4.10.7...4.10.8

For a description of the changes, review the Release Notes on the Red Hat Documentation portal.

4.11.4-rc.1

4.11.4-rc.1 Pre-release
Pre-release

Choose a tag to compare

@rhacs-bot rhacs-bot released this 11 Sep 08:26

Technical Changes

  • ROX-36824: Diagnostic bundles now redact the value of the openshift.io/token-secret.value annotation on secrets. Previously this OpenShift-managed annotation, which contains a plaintext service account token on generated dockercfg secrets, was included unredacted in the bundle.
  • ROX-36660: The Fixable → CVE is not yet fixable policy criterion now matches Scanner V4 CVEs that have no fix version. Scanner V4 leaves Fixed By unset instead of empty (Scanner V2 always set an empty string), so the matcher previously skipped those CVEs.

Full Changelog: 4.11.3...4.11.4

For a description of the changes, review the Release Notes on the Red Hat Documentation portal.