Update cnspec
Update cnspec to a new version, understand how versioning works, and learn about supported releases
Keep cnspec up to date so you stay on the latest policies, fixes, and features. To check the currently installed version:
cnspec versionFor provider versioning (separate from cnspec itself), read Manage cnspec Providers.
To run a release candidate of the next version before it ships, read Release channels.
How cnspec versioning works
cnspec versions follow MAJOR.MINOR.PATCH (for example, 14.0.1). Each release bumps one of those components based on the kind of changes shipped.
Breaking changes
Major releases can include soft-breaking changes that may require updates to your policies, query packs, or automation. Mondoo announces these well in advance, and they don't become hard-breaking until the following major release.
Supported releases
cnspec follows an N-1 support cycle: the current major version (N) and the previous one (N-1) are officially supported. Both can talk to Mondoo Platform and run every published policy and query pack. With 14.0 released, 14.x and 13.x are supported, and all 12.x releases have reached end of life (EOL).
Update cnspec
Integrations that run on Mondoo Platform, the Kubernetes operator, and the AWS Lambda-based integration automatically update to the latest version. There's no need to manually update these.
Update with cnspec update
To update the cnspec binary right away, run:
cnspec updatecnspec reads the release manifest for its release channel from the Mondoo install service (install.mondoo.com, or the updates_url you configured), downloads the build for this platform, verifies it, and switches to it. It only moves forward: if no newer version exists on the channel, it reports that cnspec is already the latest version.
- Windows: cnspec replaces the installed binary in place. When it runs with administrator rights, it also updates the version Windows lists for the installed package.
- Linux and macOS: cnspec stores the new binary in the
.config/mondoo/bindirectory in the home directory of the account that ran it, and switches to that binary each time you run the installed one.cnspec versionstill reports the version of the installed binary. To see the version that actually runs, usecnspec status.
To update from the preview channel for one command, without changing any configuration:
cnspec update --channel previewcnspec update runs even when auto_update is false. Only the MONDOO_AUTO_UPDATE=false and MONDOO_AUTO_UPDATE_ENGINE=false environment variables block it.
Automatic updates
With auto_update on (the default), cnspec checks for a newer version of itself at most once an hour, before it runs a command, and uses the same mechanism as cnspec update. The help, version, update, login, and logout commands never trigger this check. To turn automatic updates off, read Updates in the configuration reference.
Update using the install script
The simplest way to update cnspec is to re-run the installation script.
bash -c "$(curl -sSL https://install.mondoo.com/sh)"Update using a package manager
If you installed cnspec through a package manager, use the same package manager to update.
apt update && apt install --only-upgrade -y mondooVerify the update
After updating, confirm the new version and, if cnspec is registered with Mondoo Platform, that it's communicating properly:
cnspec statusThe Version row shows the version that runs, and the Channel row shows the release channel cnspec updates from.