<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SBOM Scanner on Kubewarden</title><link>https://www.kubewarden.io/components/sbom-scanner/</link><description>Recent content in SBOM Scanner on Kubewarden</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 21 Sep 2026 13:56:55 +0200</lastBuildDate><atom:link href="https://www.kubewarden.io/components/sbom-scanner/index.xml" rel="self" type="application/rss+xml"/><item><title>SBOMscanner 0.12 Release: Full-Stack Security with Node Scanning</title><link>https://www.kubewarden.io/blog/2026/07/sbomscanner-0.12-release/</link><pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate><guid>https://www.kubewarden.io/blog/2026/07/sbomscanner-0.12-release/</guid><description>&lt;p&gt;We are thrilled to announce the release of SBOMscanner&#10;&lt;a href="https://github.com/kubewarden/sbomscanner/releases/tag/v0.12.0"&gt;&lt;code&gt;v0.12.0&lt;/code&gt;&lt;/a&gt;!&#10;With this version, SBOMscanner takes a big step forward in its mission to&#10;provide a complete, SBOM-based security picture of your Kubernetes clusters.&#10;The highlight of this release is the brand new&#10;&lt;a href="https://docs.kubewarden.io/sbom-scanner/0.12.0/en/user-guide/scanning-nodes.html"&gt;&lt;strong&gt;Node Scan&lt;/strong&gt;&lt;/a&gt;&#10;feature, which extends visibility from container images all the way down to&#10;the nodes that run them.&lt;/p&gt;&#10;&lt;h2 id="why-scan-nodes"&gt;Why scan nodes?&lt;/h2&gt;&#10;&lt;p&gt;Until now, SBOMscanner focused on what runs &lt;em&gt;inside&lt;/em&gt; your cluster: container&#10;images pulled from your registries and, more recently, the workloads actually&#10;deployed on the cluster. That is a big part of the story, but it is not the&#10;whole story.&lt;/p&gt;</description></item><item><title>SBOMscanner 0.11.0 release</title><link>https://www.kubewarden.io/blog/2026/05/sbomscanner-0-11-0-release/</link><pubDate>Wed, 06 May 2026 00:00:00 +0000</pubDate><guid>https://www.kubewarden.io/blog/2026/05/sbomscanner-0-11-0-release/</guid><description>&lt;p&gt;We are happy to announce SBOMscanner v0.11.0. This release introduces an MCP&#10;server for AI assistants, a new way to target a subset of a registry from a&#10;&lt;code&gt;ScanJob&lt;/code&gt;, supply chain hardening with &lt;a href="https://woodruffw.github.io/zizmor/"&gt;zizmor&lt;/a&gt;,&#10;and several fixes for race conditions in the storage controller watches.&lt;/p&gt;&#10;&lt;h2 id="mcp-server"&gt;MCP server&lt;/h2&gt;&#10;&lt;p&gt;SBOMscanner now ships an MCP server that puts everything the controller knows&#10;in front of your AI assistant of choice. Instead of crafting &lt;code&gt;kubectl&lt;/code&gt; queries&#10;across CRDs and joining the results in your head, you can ask Claude, Claude&#10;Code, GitHub Copilot, or any other MCP client questions like &amp;ldquo;which workloads&#10;in cluster &lt;code&gt;prod&lt;/code&gt; are running an image with a critical CVE?&amp;rdquo;, &amp;ldquo;give me the&#10;top ten most vulnerable images across all my registries&amp;rdquo;, or &amp;ldquo;open a scan for&#10;the new tag I just pushed to &lt;code&gt;library/nginx&lt;/code&gt;&amp;rdquo;. The assistant calls into&#10;SBOMscanner to list registries, scan jobs and workloads, inspect specific&#10;CVEs, follow scan progress, manage VEX hubs, and (when you want it to)&#10;create, update, or delete the corresponding resources for you.&lt;/p&gt;</description></item><item><title>SBOMscanner 0.10 Release</title><link>https://www.kubewarden.io/blog/2026/03/sbomscanner-0.10-release/</link><pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate><guid>https://www.kubewarden.io/blog/2026/03/sbomscanner-0.10-release/</guid><description>&lt;p&gt;The Kubewarden ecosystem continues to expand its supply chain security capabilities!&#10;Hot on the heels of the &lt;a href="https://www.kubewarden.io/blog/2026/03/adm-controller-1.33-release/"&gt;Admission Controller 1.33 release&lt;/a&gt;, we are excited to&#10;announce SBOMscanner &lt;code&gt;v0.10.0&lt;/code&gt;. This release introduces powerful new features and&#10;critical stability fixes. Let’s dive in!&lt;/p&gt;&#10;&lt;h2 id="workload-scan"&gt;Workload Scan&lt;/h2&gt;&#10;&lt;p&gt;Until now, SBOMscanner required explicit &lt;code&gt;Registry&lt;/code&gt; configurations to scan images.&#10;However, what usually matters most are the images actively running in your cluster.&lt;/p&gt;&#10;&lt;p&gt;The new Workload Scan feature automatically discovers and scans container images&#10;based on live workloads.&lt;/p&gt;</description></item><item><title>The year in review: Kubewarden's progress in 2025</title><link>https://www.kubewarden.io/blog/2026/01/end-year-2025/</link><pubDate>Wed, 07 Jan 2026 00:00:00 +0000</pubDate><guid>https://www.kubewarden.io/blog/2026/01/end-year-2025/</guid><description>&lt;p&gt;Join us in celebrating a fruitful 2025 for the Kubewarden project!&lt;/p&gt;&#10;&lt;p&gt;The team has spent time planting kernels and enjoying the fruit of&#10;the grown ideas. Let&amp;rsquo;s look together at what the basket brings as we say ciao to 2025.&#10;Grab anything you like for the trip!&lt;/p&gt;&#10;&lt;h2 id="expanding-the-scope-introducing-sbomscanner"&gt;Expanding the Scope: Introducing SBOMScanner&lt;/h2&gt;&#10;&lt;p&gt;2025 saw Kubewarden expand beyond admission policies with the introduction of&#10;&lt;a href="https://www.kubewarden.io/blog/2025/11/expanding-kubewarden-scope/"&gt;&lt;strong&gt;SBOMScanner&lt;/strong&gt;&lt;/a&gt;,&#10;a new project donated to CNCF under the Kubewarden umbrella.&lt;/p&gt;</description></item><item><title>Expanding Kubewarden Scope</title><link>https://www.kubewarden.io/blog/2025/11/expanding-kubewarden-scope/</link><pubDate>Tue, 11 Nov 2025 00:00:00 +0000</pubDate><guid>https://www.kubewarden.io/blog/2025/11/expanding-kubewarden-scope/</guid><description>&lt;p&gt;The Kubewarden project was created four years ago at SUSE with the goal of redefining Policy As Code. We built a universal policy engine for Kubernetes and donated it to the CNCF.&lt;/p&gt;&#10;&lt;p&gt;When the project started, policies could only be written in Rust and Go. Since then, we&amp;rsquo;ve worked to increase flexibility. Today, policies can also be written in other programming languages such as C#, and even JavaScript and TypeScript (stay tuned for the upcoming announcement).&lt;/p&gt;</description></item></channel></rss>