Mondoo 14.0 is out!
๐ฅณ Mondoo 14.0 is out!
14.0 brings endpoint management across macOS, Windows, and Linux with new MDM and EDR resources; precise detection for 15 more operating systems; container scanning that reads hardened base images; one command to scan all your infrastructure as code, including OpenTofu; 500+ new resources and 6,000+ fields; cloud scans with up to 97% fewer API calls; and six new out of the box policies. MQL also gains strict mode, so a check passes only when it could actually look, plus cross-version support.
Endpoint management
14.0 adds new resources and fixes for the laptops and desktops your people use every day, across MDMs, endpoint agents, and user installed software.
New mdm and edr resources. mdm reports whether a Mac or PC is enrolled, in which MDM (Intune, Jamf, Kandji, Mosyle, Workspace ONE, and more), and how. edr reports whether an endpoint agent is installed and healthy on Windows, macOS, and Linux, down to the component that is not running. You can now write one policy that covers the whole fleet, whatever mix of vendors you have.
MDM managed settings are now read correctly. Mondoo now reads security settings from where current macOS and Windows releases keep them, including settings your MDM enforces through configuration profiles. Firewall, sharing, update, and security health checks now give a clear answer on those devices.
Per user software and more precise versions. Mondoo now inventories software users install for themselves on Windows, such as VS Code, Cursor, and Postman, alongside machine wide software. It also now reports precise versions for apps like Chrome, Safari, and .NET, so vulnerability results match what is on the device.
More accurate patch status. Available updates on Debian, Ubuntu, and RHEL family machines now match the package manager exactly, and Windows Update results now tell "fully patched" apart from "could not check".
AI tool inventory. Mondoo now inventories AI coding agents, their MCP servers, and IDE plugins, including Claude Desktop, Aider, and JetBrains, so you can see which external servers the agents on a laptop can reach.
Faster, lighter endpoint scans.
- Windows Update collection dropped from a median of 8.5 seconds to 5.4 seconds.
- IIS configuration and MDM enrollment each come back in a single PowerShell round trip, and local security policy lookups no longer start PowerShell at all.
- RPM based hosts run one
rpmquery instead of one per package. - A file search across 3,000 symlinked directories finishes in 31 ms instead of more than 7 seconds.
- The cnspec service now starts in under two seconds at boot, and cnspec keeps itself current on every platform.
Container scanning, from the base image to the host it runs on
For 14.0 we expanded our testing by an order of magnitude, covering hundreds of container image versions across the distributions teams build on. Detection, package reading, and in-container queries now cover every one of them.
Hardened and minimal base images support
Chainguard OS, MinimOS, Echo, BellSoft Alpaquita Linux (stream, 23, and 25 LTS), and BellSoft Hardened Containers are now detected as their own platforms, with their full package inventory and their own asset group in Mondoo Platform. Any other distribution that states an ID in /etc/os-release now reports that name, and an image that matches no known family is probed for a package database, which brings full inventory to images such as mcr.microsoft.com/cbl-mariner/base/core:2.0.
Container hosts
Talos, openSUSE MicroOS, Bottlerocket, and Container-Optimized OS are now detected, Flatcar reports its available updates, and Fedora CoreOS, bootc, and Universal Blue images are now fully readable.
Packages and queries inside images
- Alpine package versions now follow apk's version scheme exactly, and
kernel.installedlists Alpine kernels. - Void Linux (
xbps), ALT Linux, rpm 7 databases, and CBL-Mariner packages are now read. - Services are now listed on minimal images, including systemd images without
/sbin/init. os.uptimeandos.rebootpendingnow work across containers.- The
dockerresource now works over SSH, listing the images and containers on the remote host you scan. docker.container.runningnow points to the container's own asset, sodocker.containers { running.packages }returns what is installed inside each container. It replacesdocker.container.os, which reported the host.
Expanded Linux distribution support
The same expanded testing reached every Linux distribution Mondoo supports.
- New platforms: Clear Linux OS, Manjaro on ARM, Anolis OS, OpenCloudOS, deepin, and openKylin.
- Arch Linux on ARM is now detected, and Mondoo reads its installed packages.
- More precise identities: CloudLinux OS is now in the Red Hat family and reports its full RPM inventory. Red Hat Enterprise Linux CoreOS reports the RHEL version that lines up with advisories. CentOS Stream is its own platform, and RHEL 8+ on Extended Life Support is recognized.
- openSUSE Leap 16 and SUSE Linux Enterprise Server 16 are supported, including their new configuration locations outside
/etc. - NixOS now reports its packages, kernels, and when it was last updated.
- Virtualization detection now maps Hyper-V, GCE, VirtualBox, and Apple.
Solaris and FreeBSD
We extended Solaris and FreeBSD coverage to return richer data from your hosts. New in 14.0:
- New
pkgandpkg.reporesources on FreeBSD report each repository's URL, enabled state, mirror and signature type, priority, source file, and key material. Definitions from/etc/pkg/and/usr/local/etc/pkg/repos/are merged the way libpkg merges them, so overrides likeFreeBSD: { enabled: no }are reflected. portson FreeBSD now lists listening ports.processeson Solaris now lists running processes.- Solaris uptime, CPU core counts, and release detection are accurate on every architecture and cloud configuration.
OpenTofu support
OpenTofu is the open source fork of Terraform, and many teams are moving their infrastructure code to it. Mondoo 14.0 scans OpenTofu configurations, plans, and state files directly, so your security and compliance checks come with you when you migrate:
Bashcnspec scan opentofu ./infrastructure
Mondoo understands OpenTofu's own file types (.tofu, .tofu.json, .tofuvars, and .tofuvars.json) and reads them the way OpenTofu does, including when a .tofu file overrides a .tf file of the same name. In Mondoo Platform, OpenTofu assets appear as their own asset types alongside Terraform.
Scans of both Terraform and OpenTofu also give clearer errors. A malformed .tf file now reports the file, line, and column, and an encrypted or raw state file tells you to run terraform show -json or tofu show -json first, instead of scanning as empty.
Unified infrastructure as code scanning
Most repositories hold more than one kind of infrastructure as code: Terraform modules, Helm charts, Kubernetes manifests, Dockerfiles, and more. Teams migrating large Terraform installations to OpenTofu often have both side by side for a long time. Until now, each kind needed its own provider and its own command, and a pipeline had to know in advance what lived where.
The new iac provider unifies all of it behind one entry point. Point it at a repository, and it walks the tree and asks every infrastructure as code provider which files it recognizes. The repository becomes one IaC project, and each project found inside it becomes its own asset, scanned by the provider that already knows that format:
Plain Text> cnspec shell iac ./repoAvailable assets> 1. IaC project repo (Infrastructure as Code Project)2. Dockerfile Dockerfile (Dockerfile)3. Ansible Project Static Analysis directory ansible (Ansible Project)4. Bicep file directory bicep (Azure Bicep)5. CloudFormation template stack (AWS CloudFormation)6. K8s Manifest directory k8s (Kubernetes Manifest)7. Ansible Project Static Analysis directory playbook-only (Ansible Project)
One command scans them all with the policies you already use, which fits easily into a CI pipeline:
Bashcnspec scan iac ./repo
cnspec discovers Terraform, OpenTofu, Ansible, CloudFormation, Bicep, Helm, Kustomize, Kubernetes manifests, and Dockerfiles. When someone adds a new chart or module, it is covered on the next run, with no pipeline changes.
Add --discover terraform,opentofu to include Terraform and OpenTofu, which is especially handy mid migration: a folder with both .tf and .tofu files is scanned as both Terraform and OpenTofu, so you can track both halves of the move. Use --discover all to scan everything, or --iac-ignore to skip directories.
The iac provider is experimental in 14.0, so its discovery names and flags may change.
Notion scanning
14.0 expands Mondoo's SaaS coverage to Notion. Workspaces often hold runbooks, architecture notes, and customer data, and a page shared to the public web is easy to miss. The new Notion provider reports which pages and databases are publicly exposed, along with the integrations and users that can reach them:
Bashcnspec scan notion --token YOUR_TOKEN
To learn more, read Secure Notion with cnspec in the Mondoo docs.
500+ new resources and 6,000+ new fields
MQL now ships 5,848 resources and 60,137 fields. Since the 13.x line, 578 resources and 6,253 fields are new, and nearly 2,000 of those fields land on resources you already query.
Windows
27 new windows resources, 7 new iis resources, and 58 new fields on existing Windows resources.
windows.acl, withwindows.acl.entryandwindows.acl.auditEntry, reads filesystem and registry access control lists.iisreports resolved IIS configuration: sites, applications, app pools, bindings, virtual directories, and configuration.windows.dnsServercovers recursion, forwarders, root hints, scavenging, response rate limiting, cache, diagnostics, and per zone DNSSEC.windows.schannelexposes SCHANNEL protocols, ciphers, hashes, and key exchange algorithms.- BitLocker key protectors via
windows.bitlocker.volume.keyProtector, plus Device Guard running state. windows.lsaadds FIPS mode, Kerberos encryption types, and LDAP signing.windows.powershell.moduleLoggingis new, andwindows.winrm.listener, eventlog, and TPM were extended.windows.firewall.rulenow reports what a rule permits.windows.certificates,windows.logonSessions, andwindows.driversreport trusted certificate stores, logged on sessions, and loaded drivers.
Network devices and bare metal
- MikroTik RouterOS: 33 new resources, including IPv6 firewall and NAT, IPsec, SSH, certificates, RADIUS, SNMP, VPN servers, scripts, schedulers, logging, RouterBOOT, and containers.
- Arista EOS: SNMPv3 users, groups, hosts, and views, console settings, and storm control.
- IPMI: channels, users, LAN and SOL configuration, the event log, and the watchdog.
Cloud and SaaS
- Azure: six new services (NetApp Files, Azure Files, Elastic SAN, Managed Lustre, Data Box, and Backup vaults), plus Defender for Servers plan components, diagnostic settings, Defender for Cloud continuous export, Service Fabric clusters, and NetApp ransomware protection. Azure gains 75 resources and 806 fields in all.
- Alibaba Cloud: 40 new resources across Cloud Firewall, WAF, Security Center, Log Service, ACK, RDS, VPN, PolarDB, and ACR.
- MongoDB Atlas: 18 new resources for federation, online archives, alerts, role mappings, users, teams, and certificates.
- Cloudflare: 14 new resources for WAF overrides, IP access rules, zone lockdowns, Gateway, tunnels, Workers, R2 custom domains, and Log Explorer.
- Neon: 12 new resources for Data API, advisors, buckets, auth, credentials, functions, snapshots, and operations.
- Portainer and Netlify: 9 new resources each.
- AWS: Security Hub aggregators and organization configuration, Access Analyzer archive rules, IAM user SSH keys and service specific credentials, Macie, ELB listener certificates, WAF rate based statements, GuardDuty custom detection rules, and more.
- GitHub: code scanning default setup, Dependabot secrets, signing keys, immutable releases, and the organization's plan tier.
- Hetzner:
hetzner.image.deprecationreports when a deprecated image stops being served. - Zoom: 44 new fields for identity, domain claims, recording governance, and locked defaults.
- Okta, Vercel, Microsoft 365, GCP, OCI, StackIt, Datadog, Databricks, Snowflake, GitLab, DigitalOcean, Proxmox, Atlassian, OpenStack, Redis, and Kubernetes also gained new resources and fields.
AI infrastructure
- OpenAI: 7 new resources for batches, skills, vector store and container files, fine tuning checkpoints, and user role assignments.
- OpenAI Agents API:
openai.agent,openai.agent.tool,openai.vault,openai.vault.credential, andopenai.environmentTemplatereport what agents can call, which stored credentials they use, and their sandbox network policy. For example, you can query which agents reach an external MCP server with a static bearer token and no tool allowlist. Header values and raw response bodies are never stored. - vLLM: engine configuration, tokenizer info, and route permissions.
- Claude: how a platform uses the API on behalf of a user profile.
Much faster cloud scans
Same data, same scores, far fewer API requests.
| Provider | Before | After | Change |
|---|---|---|---|
| GitLab | 149 calls | 5 | 97% fewer |
| GCP | 2,651 calls | 1,113 | 58% fewer |
| GitHub | 1,291 calls | 1,049 | 19% fewer |
| Query or scan | Before | After |
|---|---|---|
Microsoft 365 microsoft.applications { servicePrincipal.id } | 123 s | 27 s |
| Microsoft 365 user registration details | 47 s | 18 s |
| Okta API calls on a small organization | 7 | 3 |
Faster hosts and images
- Docker image scans now save images to a file instead of memory: peak memory on an 847 MB image is 88 MB instead of 2,191 MB. Thanks for this contribution, @maxrink!
- Fleet scans fetch the provider version manifest once an hour instead of once per provider start.
- GCP snapshot scans work across zones and poll far less.
- The engine allocates less memory per query, and file searches with a permission filter run about 74% faster. Thanks for these contributions, @maxrink!
Assets scan in parallel by default
--parallelism now defaults to 0, which means "ask the providers." The scanner uses the smallest value declared by the providers behind your root assets, capped at half the machine's CPUs. On a 6 host inventory, that cut a scan from 10.9 to 5.7 seconds.
Declared values in 14.0: network and host scans 10; AWS, GCP, and Kubernetes 8; Azure 6; GitHub and GitLab 4. Providers that have not declared a value, including SSH fleets on the os provider, stay sequential. An explicit --parallelism or MONDOO_PARALLELISM still wins, and 1 is still sequential.
Scan results in the formats your pipeline already reads
OCSF
cnspec scan -o ocsf-json and -o ocsf-parquet write OCSF events for Amazon Security Lake or a SIEM:
Bashcnspec scan aws -o ocsf-parquet --output-target ./events/
- Checks are Compliance Finding (2003) events by default, or Detection Finding (2004) events with
-o ocsf-json,ocsf-findings=detectionfor Splunk Enterprise Security. - Scans also emit Vulnerability Finding (2002) and Device Inventory Info (5001) events.
- OCSF 1.3.0 is the default, the highest version Amazon Security Lake accepts. Add
ocsf-version=1.9.0for the current schema. - Errored checks are
Unknown, skipped checks areSuppressed, and unscannable assets produce an asset error event. -o ocsfis shorthand forocsf-json.
cnspec vuln now also writes SARIF, ocsf-json, and ocsf-parquet, so vulnerability findings can go to GitHub code scanning next to your policy results.
OHDF
cnspec scan -o hdf writes InSpec exec-json for Heimdall and MITRE SAF tooling. With a directory --output-target, it writes one document per asset.
CSV
cnspec scan -o csv writes one row per asset and check, with asset, MRN, platform, check uid and title, status, score, impact, and message. Cells are escaped against spreadsheet formula injection.
Report files are now private by default (0600 for files, 0700 for directories), and cnspec refuses to write through a symlink.
Reachability for transitive dependencies in .NET, Ruby, uv, and pdm projects
Mondoo now reads the dependency graph from packages.lock.json, Gemfile.lock, uv.lock, and pdm.lock, so it can tell you whether a transitive dependency is reachable from a package your code imports. Previously, these transitive dependencies were reported as undetermined.
MQL strict mode: a check that couldn't look is no longer a check that passed
Without strict mode, a misspelled key silently returns null, and the check passes without ever looking:
MQL# Without strict mode: the typo resolves to null, and null != "yes" passes> sshd.config.params.PermitRootLogn != "yes"[ok] value: _
The same happens when a scan lacks permission to read a value. Strict mode makes every link in an access chain resolve, and ? waives one:
MQL# Strict mode: the missing key is an error, not a pass> sshd.config.params.PermitRootLogn != "yes"[failed] sshd.config.params[PermitRootLogn] != "yes"error: cannot find key "PermitRootLogn"# Strict mode with ?: you said the key may be absent, so null is fine> sshd.config.params.PermitRootLogn? != "yes"[ok] value: _
Turn it on with --strict on mql or cnspec, the strict config key, or MONDOO_STRICT=true. A policy or query pack can also declare it:
YAMLpolicies:- uid: lunalectric-ssh-baselinename: Lunalectric SSH baselinestrict: true
strict: true and strict: false always win; a policy that leaves it out follows --strict or the config. The out of the box Mondoo, CIS, and BSI policies do not declare it yet, so --strict applies to them too; try it on a test fleet first. cnspec policy lint --require-strict-declaration flags policies that leave strict unset.
To learn where to place ?, read Strict mode and the ? operator.
The MQL language keeps getting better
Parse JSON anywhere with string.json
Any string can be parsed into a JSON structure with .json:
MQL# Parse a JSON string> '{"tls": {"min": "1.2"}}'.jsonjson: {tls: {min: "1.2"}}
Once parsed, access nested values directly:
MQL# Access a nested value> '{"tls": {"min": "1.2"}}'.json.tls.minjson.tls.min: "1.2"# Works on any string, such as a file's content> file("/etc/app/config.json").content.json.logging.levelfile.content.json.logging.level: "info"
Parentheses and unary minus
MQL(1 + 2) * 3 == 9-(2 - 5) == 3(asset.arch == "x86_64" || asset.arch == "arm64") && asset.platform == "ubuntu"
Better version comparisons
version() now sorts distro revisions the way package managers do (1.2.3 before 1.2.3-1ubuntu1, 1.2.3-r4 before 1.2.3-r10), compares four part versions numerically, and understands Debian ~ pre-releases and PEP 440 forms such as 1.0rc1, 1.0.post1, and 1!2.0. inRange handles epochs, ^ bounds, and five part versions.
String escapes
Double quoted strings now interpret escape sequences, and an invalid escape is a compile error. Single quoted strings stay raw, which suits Windows paths and regular expressions:
MQL# Double quoted: \" \\ \n \t and friends are interpreted"say \"hi\"\tthere" # โ say "hi"<tab>there# Double quoted with an invalid escape: compile error"C:\Users\admin"# failed to compile: invalid escape sequence \U in string literal,# use \\ for a literal backslash or a single-quoted raw string# Single quoted: raw, every backslash stays as written'C:\Users\admin' # โ C:\Users\admin
This is a breaking change for double quoted strings with a literal backslash.
Keys with dots and nested paths
Dict keys that contain dots, such as com.apple.security.firewall, now resolve directly, and nested values resolve by full path, for example windows.deviceGuard.credentialGuardConfig.
Clearer results and errors
Failed assertions inside a block now show what was expected and what was found:
Plain Textparse.json: {[failed] params.a == 9expected: == 9actual: 1.000000}
Deprecated fields name their replacement, unknown fields name your installed provider version, and -j JSON output stays valid with multi line errors.
Cross-version MQL: content and clients no longer have to match
MQL content now records which schema it was compiled against and which engine version it needs. The engine can migrate older content forward and adapt newer content for an older client, so a newer policy no longer breaks on an agent you have not upgraded yet. Platform support follows as Mondoo Platform moves onto the 14.0 engine.
When a query names a field your installed provider does not know yet, the error now says so:
Plain Textcannot find field 'nosuchfield' in sshd.config (os provider 14.1.0 is installed; this field may require a newer one)
Typed asset roots, available early
Every asset now exposes a typed root resource, which is why you will see new os.any resources in the resource explorer. Some of it works today:
- Cross-asset traversal.
docker.containers { running.packages }returns each container's packages. AI agent MCP server resources (Claude Code, Claude Desktop, Codex, Cursor, GitHub Copilot, Gemini, and Windsurf) have the samerunningedge. - Root members without a prefix.
hostname,machineid,lastUpdate, and_.uptimeresolve directly. - Multi-asset
mql runnow skips assets a query does not apply to instead of aborting.
The fully rooted query model is opt in with MONDOO_FEATURES=RootedNamespace. The flat os resource is deprecated in favor of the root.
Quality of life
- AWS, Azure, GCP, and OCI now have 280+ new sub-resources that make queries simpler. The
dictfields they replace still work and are marked deprecated. lastUpdateandlastUpdateAgeon the asset root report when an asset last installed an OS update.certificate.isRevokednow checks CRLs.- Better dependency data: Gradle projects without lockfiles and Maven dependency versions now resolve, duplicate CVE and GHSA records are merged, and SBOMs round trip through SPDX and CycloneDX with licenses.
cnspec vulnnow reports VEX.cnspec servepicks up inventory changes without a restart.cnspec statuschecks the Mondoo Platform ingest endpoint, so a missing firewall rule shows up before the first scan.cnspec providers install --schema-onlyinstalls a provider's schema without the binary.- Policy overlays can override imported checks, so you can tailor a Mondoo or CIS check without forking it.
cnspec integrate ms365no longer assigns the unnecessary Exchange Administrator role.- New resources for Ollama, Redfish, DNSSEC validation, and Kubernetes runtime classes and volumes, plus scanning for secured OPC UA servers.
Windows clients update themselves
Mondoo 13.0 introduced automatic client updates on Linux and macOS. 14.0 extends them to Windows, so Windows clients now update seamlessly too. cnspec on Windows checks for a newer version of itself and installs it without anyone reinstalling the package, so your whole fleet stays current on its own.
- The binary is replaced in place. cnspec keeps its install path, so existing firewall rules keep working and nobody sees a new firewall prompt after an update.
- Windows reports the right version. When cnspec runs with administrator rights, it updates the version listed under installed apps, so your inventory and software management tools report what is actually running.
cnspec updateuses the same mechanism, replacing the binary directly instead of rerunning the PowerShell install script.
Automatic updates are on by default. cnspec checks at most once an hour, before it runs a command. To turn them off, set auto_update: false in mondoo.yml or MONDOO_AUTO_UPDATE=false. To learn more, read Update cnspec in the Mondoo docs.
Try the next major version before it ships
Every cnspec and mql release now belongs to a channel derived from its version: 13.38.1 is stable, and 14.0.0-rc.7 is preview. This gives you a supported way to test a release candidate against your own assets before it ships.
Check what each channel points at:
Bashcurl -s https://install.mondoo.com/package/cnspec/latest.json | jq -r .versioncurl -s "https://install.mondoo.com/package/cnspec/latest.json?channel=preview" | jq -r .version
Install a preview build:
BashMONDOO_PRODUCT=cnspec MONDOO_CHANNEL=preview \bash -c "$(curl -sSL https://install.mondoo.com/download/sh)"
Or update an existing install once:
Bashcnspec update --channel previewcnspec providers install notion --channel preview
To stay on preview, set update_channel: preview in mondoo.yml or MONDOO_UPDATE_CHANNEL=preview. Stable is the default. The macOS and Windows install pages in the Mondoo console also have a preview switch. The apt, yum, zypper, and Homebrew repositories serve stable only.
Release candidates for 15.0 and later will be published to preview as they are built. Read Release channels for details.
๐จ Breaking changes
If you use out of the box Mondoo, CIS, or BSI policies, the content is already updated. Custom policies may need adjustment. Providers update independently of cnspec, so a 13.x client with provider auto-update already receives the 14.0 providers and their schema changes.
Find deprecations in your custom policies first
Bashcnspec policy lint ./policies
You get one warning per deprecated symbol:
Plain Textquery 'lunalectric-postgres-tls' uses deprecated field 'azure.subscription.postgreSqlService.servers'policy 'lunalectric-baseline' group 1 uses deprecated resource 'aws.workdocs' in its filters
Expect many warnings for the deprecated dict fields and the flat os resource. The dict fields are not scheduled for removal in 15.0. Pay close attention to filter warnings: when a symbol in a filter is removed, the whole group silently drops out of scoring.
To fail a build on these warnings:
Bashcnspec policy lint --strict-rule query-deprecated-symbol --strict-rule filter-deprecated-symbol ./policies
--strict-rule all promotes every warning, and -o sarif writes a report for GitHub code scanning.
The Equinix Metal provider is removed
Equinix has shut down Equinix Metal. The provider was deprecated in 13.0 and is removed from cnspec and Mondoo Platform in 14.0.
Configuration and inventory cleanup
- The legacy connection
backendfield is removed from inventory. Usetype. - The
--providers-urlflag is removed. Theproviders_urlkey andMONDOO_PROVIDERS_URLstill work but warn;cnspec migratemoves you toupdates_url. min_mondoo_versionis removed from the resource schema. Usemin_provider_version.- The
fleetasset category and theec2:tag:/ec2:exclude:tag:filters now warn and name their replacements (inventory,tag:,exclude:tag:). They go away in 15.0. - Azure no longer includes
instances-apiinautodiscovery. Use--discover instances-apito keep it.
Behavior changes
- Terraform variable resolution is built into the engine, so local runs resolve variables the same way platform scans do.
- CentOS Stream is now
centos-stream, so filters onplatform.name == "centos"no longer match Stream hosts. - Azure Database for MySQL and PostgreSQL Single Server are no longer discovered, because Microsoft has retired both services. Use the Flexible Server targets instead.
mql runreturns a non-zero exit code when no asset could be connected.cnspec sbomandcnspec aibomreject an unsupported--outputbefore scanning.- Assets scan in parallel by default.
--parallelism 0now means "ask the providers"; use1for sequential. - Report files are private (
0600/0700). Pipelines that read reports as a different user need to account for this. cnspec vulnoutput has a new layout. JSON and YAML are a flatvulnerabilitieslist withadvisory,severity,package,installed,fixed,purl,summary,references, andremediation.score,available,cves, andpatchare gone, andvulnerablebecamefixed. CSV columns areSeverity, Advisory, Package, Installed, Fixed, Purl, References, Remediation. Without platform credentials, the command now warns and exits 0.- A policy overlay that overrides an unknown check uid is now a compile error.
alicloud.kms.key.rotationIntervalandalicloud.kms.secret.rotationIntervalare now integers in seconds, so you can writerotationInterval <= 365 * 86400. Values that cannot be parsed are null.
MQL and schema changes
- Double quoted strings honor escapes.
"C:\Windows\System32"now fails withinvalid escape sequence \W in string literal, use \\ for a literal backslash or a single-quoted raw string. Use\\or single quotes. - 758 fields deprecated in 13.x are removed. The out of the box policies no longer use any of them. To check your own policies for deprecated fields that need updating, run
cnspec policy lint. - Four resources are renamed:
gitlab.user.emailโgitlab.user.emailAddress,mikrotik.user.groupโmikrotik.userGroup,ms365.exchangeonline.mailboxโms365.exchangeonline.mailboxWithAudit, andproxmox.vm.diskโproxmox.vm.virtualDisk. Queries through the parent field keep working. - Removed resources:
cloudflare.zone.firewallRule(usecloudflare.zone.ruleset),cloudflare.zone.plan,grafana.apiKey(usegrafana.serviceAccountToken), themicrosoft.identityAndAccess.policyfamily (use the PIM policy resources),bitwarden.organization,zoom.account.sso, and the emptyweaviateroot (useweaviate.instance). docker.container.osis removed. Usedocker.container.running.snowflake.authenticationPolicy.createdAtis atime.
Newly deprecated, removed in 15.0
- Amazon WorkDocs (shut down 2025-04-25)
- GCP legacy Notebooks (shut down 2026-03-30, use
workbench) - Azure classic administrators (use
roleAssignments), plus Azure MySQL and PostgreSQL Single Server and Log Profile resources - The flat
osresource and its 13 fields, in favor of the same names on the asset root versionon eight providers (Jamf, MongoDB, SQL Server, MySQL, Portainer, PostgreSQL, vLLM, and Weaviate), in favor ofasset.version
For developers integrating with Mondoo
- The Go module path is no longer versioned. If you import Mondoo as a Go dependency, drop the
/v13suffix. ScoreValue.scoreis removed fromcnspec scan -o json. ReadriskScore, its inverse.- The v8 vulnerability report fallback is removed.
ReportingJob.deprecated_v8_is_datais removed, replaced by theTypeenum.