## bytedance/vArmor — v0.10.3…v0.10.4-beta.1

_16 commits._

### Features
- **feat(networkproxy): add global default sidecar resources via varmor-config (#363)** (590ae4f)
- **feat(networkproxy): support audit logging for kata and micro-VM runtimes via in-sidecar ALS sink (#359)** (1019f60)
- **feat(networkproxy): auto-detect iptables backend (legacy/nft) before injecting proxy-init rules (#358)** (0b0fe58)
- **feat(policy-advisor): detect shell usage via script file extensions (#348)** (a26f6d3)

### Fixes
- **fix(crd): use int64 format for mount flags to avoid int32 overflow (#357)** (82baa15)
- **fix(auditor): serialize rate-limit boundary decision with sysctl save/restore (#356)** (8bb4cfb)
- **fix(networkproxy): snapshot cacher maps in ProxyConfigPropagator to fix data race (#355)** (b6d1f6f)
- **fix(mitm): validate CA cert/key are an actual key pair in ParseCA (#354)** (4118f0e)
- **fix(policy): validate NetworkProxyEgress.defaultAction against legal value set (#353)** (10453c7)
- **fix(auditor): guard subscriber channel maps with an RWMutex to fix data race (#352)** (bf24295)
- **fix(policycacher): handle nil NetworkProxyConfig transitions on update (#351)** (cd64a5c)

### Docs
- **docs(practices): add network egress control & AI Agent hardening section (#349)** (6dc3241)

### Chore
- **chore(mitm): refresh embedded Mozilla CA bundle (#364)** (566739e)
- **chore: Upgrade golang and nodejs packages (#362)** (826fd86)
- **ci: add scheduled workflow to refresh embedded Mozilla CA bundle (#361)** (84b3289)
- **refactor(policy): simplify NP-secret error flow and drop forward-compat ownerReference block (#350)** (908d999)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/bytedance/vArmor?utm_source=github-action)._