What's Changed
- feat(aws): ingest flattened billing, encryption, and stream properties by @Tushar240503 in #2198
- chore: disable stale on issues by @jychp in #2322
- fix(ontology): enable PublicIP sync in ontology orchestrator by @jychp in #2324
- feat(scaleway): add iam policy support (+ small fix) by @EmFl in #2295
- chore: bump protobuf from 6.33.2 to 6.33.5 by @dependabot[bot] in #2323
- chore(ci): remove pip ecosystem from Dependabot by @jychp in #2319
- chore: bump types-requests from 2.32.4.20250913 to 2.32.4.20260107 by @dependabot[bot] in #2328
- chore: bump black from 25.12.0 to 26.1.0 by @dependabot[bot] in #2330
- chore: bump the minor-and-patch group with 3 updates by @dependabot[bot] in #2325
- chore: bump shibuya from 2025.12.17 to 2026.1.9 by @dependabot[bot] in #2329
- feat(ontology): add image-related ontology labels to ECR entities by @jychp in #2318
- chore: bump packaging from 25.0 to 26.0 by @dependabot[bot] in #2327
- docs(rules): add autodoc for rules module by @jychp in #2321
- chore: bump the minor-and-patch group with 12 updates by @dependabot[bot] in #2326
- feat(metrics): add resource count metrics to load operations by @jychp in #2331
- feat(rules): Google Workspace CIS benchmarks by @kunaals in #2197
- feat(rules): GCP CIS benchmarks by @kunaals in #2196
- feat(rules): Standardize CIS rule IDs with provider prefixes by @kunaals in #2334
- fix(rules): Remove unrestricted_all_ports rule from CIS AWS networking by @kunaals in #2336
- refactor(pagerduty): datamodel migration by @jychp in #1606
- feat(rules): Add Framework object for structured compliance metadata by @jychp in #2335
- refactor(github): Refactor integration tests by @jychp in #2339
- chore(deps): Upgrade Neo4j Python driver to 6.0.0 by @jychp in #2340
- feat(apigateway): Add exposed_internet property based on endpoint type by @jychp in #2341
- feat(ontology): add Image/ImageManifestList labels to GCP and GitLab images by @kunaals in #2337
- feat(cli): migrate from argparse to Typer by @jychp in #2333
- chore(azure): upgrade azure-mgmt-sql to v3.0.1 and migrate to database_security_alert_policies API by @jychp in #2344
- feat(ontology): add CodeRepository semantic label for source code repositories by @jychp in #2350
- feat(ontology): add ObjectStorage semantic label for cross-cloud bucket querying by @jychp in #2348
- feat(ontology): add missing UserAccount mappings for GitLab and OCI by @jychp in #2347
- feat(ontology): add Secret semantic label for cross-platform secret queries by @jychp in #2349
- chore: bump the minor-and-patch group with 2 updates by @dependabot[bot] in #2353
- fix: Azure SDK import and add version constraint by @achantavy in #2360
- chore: bump the minor-and-patch group with 12 updates by @dependabot[bot] in #2354
- chore: bump packaging from 25.0 to 26.0 by @dependabot[bot] in #2357
- chore: bump sphinxcontrib-mermaid from 1.2.3 to 2.0.0 by @dependabot[bot] in #2355
- chore: bump python from
f5d029fto218027aby @dependabot[bot] in #2352 - fix(ec2): Use execute_read for AWS EC2 image/snapshot reads by @kunaals in #2361
- chore: miscellaneous cleanup and security hardening by @jychp in #2363
- feat: code-to-cloud supply chain traceability (PACKAGED_FROM, PACKAGED_BY, SLSA provenance) by @jychp in #2313
- fix(cli): add version flags, restore -h, and speed up --help by @jychp in #2367
- feat(gitlab): Adding Coverage for Gitlab Image Layers by @shyammukund in #2351
New Contributors
Full Changelog: 0.127.0...0.128.0