## mondoohq/cnspec — v13.33.2…v13.34.0

_157+ commits._

### Features
- **✨ nextdns: add bypass, safe browsing, dynamic dns, and log domain checks (#3432)** (f44890f)
- **📝 validation: document wiring a new policy into content validation (#3376)** (8373d96)
- **✨ content: add Terraform variants to the ClickHouse Cloud, HCP and Neon policies (#3375)** (3fd4e97)
- **✨ content: add self-hosted database security policies (#3337)** (6a1aae8)
- **✨ content: add SaaS and cloud platform security policies (#3338)** (7b7b848)
- **📝 plcnext: add missing audit sections to the PLCnext Security policy (#3370)** (3215965)
- **📝 stackit: add missing audit sections to the STACKIT Security policy (#3369)** (52d111d)
- **🐛 content: add the missing impact score to the Terraform template provider check (#3368)** (1eba4d8)
- **✨ aws: add CloudFormation remediation where it exists, document where it cannot (#3296)** (7f6462f)
- **✨ content: add Mondoo PostgreSQL Security policy (#3150)** (8b54082)
- **🐛 freebsd: map the two new checks to OWASP Top 10:2025 (#3263)** (165cc2a)
- **✨ freebsd: add time-synchronization and pkg signature-verification checks (#2917)** (2f2783f)
- **✨ aws: add RDS maintenance and recommendation checks (#3167)** (9dd2db6)

### Fixes
- **🐛 chef: fix three server checks that punish hardening or miss exposure (#3400) (#3427)** (87425e3)
- **🐛 github: fix remediation defects in the GitHub and GitLab policies (#3353)** (8eaef31)
- **🐛 content: fix database remediation that never reaches the option file (#3363)** (b994a41)
- **🐛 freebsd: fix remediation that cannot reach the state the check demands (#3357)** (efdcb45)
- **🐛 content: fix network-device remediation that cannot satisfy its own check (#3350)** (ec0c566)
- **🐛 aws: fix remediation that cannot close its own check (#3366)** (27da20a)
- **🐛 alibaba: fix remediation commands that cannot run and console paths that do not exist (#3364)** (3259e1e)
- **🐛 dockerfile/chef: fix remediation that does not satisfy its own check (#3362)** (9f8af55)
- **🐛 content: fix remediation defects in the virtualization policies (#3360)** (2812083)
- **🐛 content: fix twelve remediation defects across four cloud policies (#3361)** (b93dc43)
- **🐛 content: fix remediation defects in the network device policies (#3359)** (6b0eab7)
- **🐛 ai: fix remediation that does not resolve the finding in ai, mcp, and vllm (#3358)** (0a6204c)
- **🐛 k8s: fix remediation snippets that do not apply, parse, or satisfy their own check (#3354)** (c2bb41b)
- **🐛 content: fix remediation defects in the vercel, portainer, and grafana policies (#3356)** (a690ade)
- **🐛 content: fix remediation defects in the dns, email, http and tls policies (#3351)** (3f0bef5)
- **🐛 m365: fix remediation snippets that the Graph, Exchange and Terraform APIs reject (#3348)** (4f21dc7)
- **🐛 macos: fix remediation steps that cannot resolve their own finding (#3352)** (b68f1de)
- **🐛 windows: fix remediations that write keys the check never reads (#3349)** (88cd8b7)
- **🐛 content: fix SaaS remediation paths that name settings the consoles do not have (#3347)** (d8c4b59)
- **🐛 azure: fix a second batch of remediation and variant defects (#3346)** (3b4d726)
- **🐛 gcp: fix remediation snippets and the checks that cannot confirm them (#3345)** (c3eb5c1)
- **🐛 azure: fix remediation snippets that do not close the check (#3344)** (087d590)
- **🐛 gcp: fix Terraform remediation naming resources the provider does not have (#3342)** (0766ce4)
- **🐛 aws: fix remediation that cannot run, and check required CLI parameters (#3331)** (1197b13)
- **✨ alibaba: use the provider's typed verdicts and fix range-blind port matching (#3319)** (ffb186d)
- **🐛 aws: fix remediation examples that violate the check recommending them (#3293)** (d78e8a9)
- **🐛 aws: fix seven CloudFormation checks that could never pass (#3292)** (79fc73c)

### Backend
- **🧹 Bump mql to v13.34.0 (#3440)** (a539274)
- **📝 panos: rewrite check descriptions to the prose standard (#3424)** (76c5edc)
- **✨ validation: cover the upstream pin resolvers with offline tests (#3437)** (1fd576f)
- **📝 shodan: rewrite check descriptions to the current standard (#3423)** (ba8f83c)
- **🐛 validation: stop the drift report crying wolf (#3438)** (97af572)
- **🧹 validation: regenerate the Azure CLI command grammar (#3435)** (8d69972)
- **📝 openstack: rewrite check descriptions to the prose standard (#3425)** (4a5ae8a)
- **📝 portainer: rewrite check descriptions to the content standard (#3426)** (3e8e4fe)
- **✨ scan: report CPU consumption alongside memory (#3301)** (2720da9)
- **🐛 Apply severity bands in BANDED policy scoring (#3240)** (ed904fe)
- **🐛 cisco: fail the NX-OS CoPP check when no policing is applied (#3430)** (ac2c0f6)
- **📝 nextdns: rewrite check descriptions to the content standard (#3420)** (5e73562)
- **📝 cisco: describe the copp and snmp check gaps honestly (#3421)** (4fed979)
- **📝 okta: rewrite check descriptions to the current standard (#3402)** (98b1fc9)
- **📝 snowflake: rewrite check descriptions to the prose standard (#3401)** (6a82bc5)
- **📝 gitlab: rewrite check descriptions to the content/CLAUDE.md standard (#3396)** (5bf63b3)
- **📝 mikrotik: rewrite check descriptions as prose (#3415)** (1b4ed31)
- **📝 bigip: rewrite check descriptions to the content authoring standard (#3397)** (c85d2e2)
- **📝 arista: rewrite check descriptions for the eos security policy (#3403)** (a3c7069)
- **📝 cloudflare: rewrite check descriptions to the content standard (#3407)** (057fc71)
- **📝 cisco: rewrite check descriptions across iosxe, iosxr, and nxos policies (#3410)** (14b5a66)
- **📝 fortios: rewrite check descriptions to the content standard (#3414)** (b28a3dc)
- **📝 junos: rewrite check descriptions to the prose standard (#3412)** (ee82567)
- **📝 tailscale: rewrite check descriptions to the capability-first standard (#3408)** (050b607)
- **📝 chef: rewrite check descriptions to the docs standard (#3398)** (796c9ce)
- **🐛 github: scope the organization security policy check to the organization (#3384)** (3f5c6ee)
- **📝 content: update the check-description standard in content/CLAUDE.md (#3393)** (aff11af)
- **📝 email: rewrite check descriptions to the content/CLAUDE.md standard (#3395)** (4bb2a0e)
- **📝 stackit: rewrite check descriptions to the content/CLAUDE.md standard (#3394)** (c63a774)
- **🐛 github: correct the Dependabot check title and its one/any predicates (#3380) (#3388)** (1c1e889)
- **📝 content: rewrite check descriptions in the GitHub and HTTP policies (#3378)** (d385a81)
- **🐛 github: accept the stricter `none` base permission (#3379) (#3383)** (9791e5d)
- **📝 phoenix: rewrite PLCnext check descriptions for an OT audience (#3377)** (4612eff)
- **📝 content: rewrite OS policy check descriptions to state what is checked and why it matters (#3371)** (0bc5c8a)
- **🐛 content: close the remediation budget across aws, azure and gcp (#3373)** (87d3a3e)
- **✨ validation: resolve terraform snippets against the provider schema (#3367)** (c9954c3)
- **🐛 linux: make the documented remediation actually satisfy the check (#3365)** (0c8b1e0)
- **🐛 unifi: lint remediation against the provider the snippets actually target (#3355)** (6fa9f47)
- **🧹 azure: remove the checks for Azure services that no longer exist (#3343)** (cb52d30)
- **🐛 aws: point the SSM document sharing check at a resource that exists (#3341)** (3d19635)
- **🐛 dns: use the cloudflare_dns_record resource the pinned provider has (#3340)** (8b4d7f8)
- **🐛 oci: stop the CLI remediation from deleting the rules it does not mention (#3332)** (f8561d3)
- **STACKIT security: prefer private SKE control plane (#3214)** (5f0cc44)
- **🐛 embed a VERSIONINFO resource in Windows builds (#3233)** (8aaeddc)
- **🐛 regenerate the protobufs, and watch go.mod for the next bump (#3336)** (698354c)
- **🧹 content: give every security check an impact and compliance tags (#3333)** (8ed63d6)
- **Bump google.golang.org/protobuf (#3335)** (0350d3a)
- **Bump the gomodupdates group with 2 updates (#3334)** (b42319c)
- **🧹 aws: replace deprecated IAM inline-policy fields with inlinePolicyDetails (#3248)** (8342e3d)
- **📝 repo: document the guard-chain idiom that reviewers keep misreading (#3330)** (02ac0b9)
- **📝 repo: correct the null && null gotcha and stop duplicating content/CLAUDE.md (#3329)** (044654b)
- **📝 content: bring the policy README back in line with what ships (#3328)** (88d82ce)
- **📝 content: document the MQL traps that return a wrong verdict silently (#3327)** (04952e0)
- **✨ validation: validate the Okta and Portainer REST APIs in remediation blocks (#3326)** (ae79a23)
- **🧹 validation: gather every content test under content/validation with one README (#3324)** (872eaf6)
- **🧹 validation: bump 2 Terraform provider constraints (#3323)** (3291873)
- **✨ alibaba: cover nine services the provider models and the policy never read (#3320)** (fa2ef7e)
- **✨ oci: read the fields the provider added instead of working around their absence (#3321)** (b11769a)
- **🐛 content: aggregate provider schemas before the IaC suites scan in parallel (#3300)** (bb1b661)
- **🧹 validation: name the pin-bumping workflow after what it does (#3318)** (2abad55)
- **🧹 validation: bump mongodbatlas spec to f6a978f003 (#3316)** (04f2540)
- **🧹 validation: regenerate the Azure CLI command grammar (#3310)** (783f609)
- **👷 validation: one dependency-update PR per kind, not per pin (#3317)** (ca4522e)
- **🧹 validation: bump terraform-provider-aws to ~> 6.0 (#3306)** (7f95a64)
- **🧹 validation: bump grafana spec to 2003eb0385 (#3315)** (54509da)
- **🧹 validation: bump terraform-provider-time to ~> 0.14 (#3312)** (a91e410)
- **🧹 validation: bump terraform-provider-okta to ~> 6.0 (#3311)** (4ce3faf)
- **🧹 validation: bump terraform-provider-alicloud to ~> 2.0 (#3313)** (3488499)
- **🧹 validation: bump cloudflare spec to 2ac8369e9b (#3314)** (f59afb7)
- **🧹 validation: bump terraform-provider-google to ~> 7.0 (#3307)** (d09916b)
- **🧹 validation: bump terraform-provider-azurerm to ~> 5.0 (#3305)** (8cddee8)
- **🧹 validation: regenerate the vercel CLI command grammar (#3304)** (adc2f9e)
- **🧹 validation: refresh the checked-in OpenAPI specs (#3303)** (dbdcc89)
- **👷 validation: open weekly PRs for the validators' pinned upstreams (#3302)** (91b83d2)
- **✨ scan: report memory consumption upstream as scan statistics (#3274)** (be191f2)
- **📝 ADR-0004: scan memory telemetry (#3270)** (dde86c1)
- **✨ content: require an IaC remediation to satisfy the check that recommends it (#3298)** (6e443b6)
- **✨ validation: validate PowerShell remediation and audit snippets (#3295)** (be9dfdb)
- **🧹 aws: use the indented heredoc form in the EMR snippets (#3297)** (21bae1a)
- **🧹 validation: shellcheck every shell snippet, not one id in seven policies (#3290)** (3da0750)
- **👷 validation: stamp the Azure grammar and watch every pinned upstream (#3288)** (f240cf5)
- **🐛 aws: point the Elasticsearch remediation at Elasticsearch resources (#3294)** (0bd1d57)
- **🧹 content: label the code fences that carried no language (#3291)** (c382f22)
- **✨ validation: lint Bicep remediation with the Bicep CLI (#3285)** (13b8ac9)
- **✨ validation: lint CloudFormation remediation with cfn-lint (#3284)** (d35511e)
- **✨ validation: validate audit: commands for the cloud CLI targets (#3282)** (fc4331e)
- **🧹 validation: drop the "had never been linted" TARGETS comments (#3286)** (4f18b16)
- **🐛 validation: record real az option strings, not argparse dest names (#3281)** (1261007)
- **✨ validation: lint the remediation the existing validators were skipping (#3283)** (089929f)
- **✨ content: reach 100% IaC-variant coverage and enforce it flatly (#3279)** (1cf41bf)
- **✨ content: cover the Azure terraform-hcl IaC-variant coverage gaps (#3278)** (4c168ac)
- **✨ content: cover the AWS CloudFormation IaC-variant coverage gaps (#3277)** (26678ce)
- **✨ content: cover the AWS terraform-hcl IaC-variant coverage gaps (#3276)** (afea652)
- **✨ content: cover the Alibaba Cloud IaC-variant coverage gaps (#3275)** (247b12c)
- **✨ content: cover the Snowflake IaC-variant coverage gaps (#3273)** (f11918f)
- **🧹 proxmox: replace deprecated fields in the Proxmox inventory querypack (#3272)** (21a6d29)
- **✨ content: cover the OCI, OpenStack, and GCP IaC-variant coverage gaps (#3271)** (242cfd8)
- **🧹 ci: bump tflint rulesets used to validate Terraform remediation (#3269)** (7cdc457)
- **👷 ci: enforce IaC-variant fixture coverage with a ratchet (#3261)** (1b78ec5)
- **🐛 policy: deterministic query compile order (#3182)** (95078fd)
- **🧹 gcp: migrate firewall checks off the deprecated `allowed` field (#3268)** (daf9182)
- **🧹 lint: report every filter under filter-deprecated-symbol (#3267)** (4d30bd0)
- **🧹 lint: report deprecated symbols in group and pack filters (#3266)** (3303e52)
- **🧹 lint: report deprecated symbols used in query filters (#3264)** (b827d06)
- **Proxmox security: verify backup archive encryption at rest (#3215)** (089f403)
- **Alibaba Cloud security: RAM admin and OSS public-bucket verdicts (#3206)** (843be46)
- **Databricks security: cover service principal secret expiry (#3210)** (c37da8a)
- **🧹 claude: stop writing session URLs into commits and PRs (#3260)** (abbfaf3)
- **MongoDB Atlas security: cover Flex clusters (#3211)** (c582118)
- **Okta security: flag group owners on admin groups (#3207)** (0d33c9a)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/mondoohq/cnspec?utm_source=github-action)._