Back to updates
New releaseAug 12, 2026

kubescape v4.0.12

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA, MITRE, and CIS benchmarks across the full development lifecycle.

Share

Version build Go Report Card Gitpod Ready-to-Code GitHub CNCF Artifact HUB FOSSA Status OpenSSF Best Practices OpenSSF Scorecard Docs Stars Twitter Follow Slack

Kubescape

Kubescape logo

Comprehensive Kubernetes Security from Development to Runtime

Kubescape is an open-source Kubernetes security platform that provides comprehensive security coverage, from left to right across the entire development and deployment lifecycle. It offers hardening, posture management, and runtime security capabilities to ensure robust protection for Kubernetes environments.

Kubescape was created by ARMO and is a Cloud Native Computing Foundation (CNCF) incubating project.

Please star ⭐ the repo if you want us to continue developing and improving Kubescape!


📑 Table of Contents


✨ Features

FeatureDescription
🔍 Misconfiguration ScanningScan clusters, YAML files, and Helm charts against NSA-CISA, MITRE ATT&CK®, and CIS Benchmarks
🐳 Image Vulnerability ScanningDetect CVEs in container images using Grype
🩹 Image PatchingAutomatically patch vulnerable images using Copacetic
🔧 Auto-RemediationAutomatically fix misconfigurations in Kubernetes manifests
🛡️ Admission ControlEnforce security policies with Validating Admission Policies (VAP)
📊 Runtime SecurityeBPF-based runtime monitoring via Inspektor Gadget
🤖 AI IntegrationMCP server for AI assistant integration

🎬 Demo

Kubescape CLI demo

🚀 Quick Start

1. Install Kubescape

curl -s https://raw.githubusercontent.com/kubescape/kubescape/master/install.sh | /bin/bash

💡 See Installation for more options (Homebrew, Krew, Windows, etc.)

2. Run Your First Scan

# Scan your current cluster
kubescape scan

# Scan a specific YAML file or directory
kubescape scan /path/to/manifests/

# Scan a container image for vulnerabilities
kubescape scan image nginx:latest

3. Explore the Results

Kubescape provides a detailed security posture overview including:

  • Control plane security status
  • Access control risks
  • Workload misconfigurations
  • Network policy gaps
  • Compliance scores (MITRE, NSA)

📦 Installation

One-Line Install (Linux/macOS)

curl -s https://raw.githubusercontent.com/kubescape/kubescape/master/install.sh | /bin/bash

Package Managers

PlatformCommand
Homebrewbrew install kubescape
Krewkubectl krew install kubescape
Arch Linuxyay -S kubescape
Ubuntusudo add-apt-repository ppa:kubescape/kubescape && sudo apt install kubescape
NixOSnix-shell -p kubescape
Chocolateychoco install kubescape
Scoopscoop install kubescape

Windows (PowerShell)

iwr -useb https://raw.githubusercontent.com/kubescape/kubescape/master/install.ps1 | iex

📖 Full Installation Guide →


🛠️ CLI Commands

Kubescape provides a comprehensive CLI with the following commands:

CommandDescription
kubescape scanScan cluster, files, or images for security issues
kubescape scan imageScan container images for vulnerabilities
kubescape fixAuto-fix misconfigurations in manifest files
kubescape patchPatch container images to fix vulnerabilities
kubescape listList available frameworks and controls
kubescape downloadDownload artifacts for offline/air-gapped use
kubescape configManage cached configurations
kubescape operatorInteract with in-cluster Kubescape operator
kubescape vapManage Validating Admission Policies
kubescape mcpserverStart MCP server for AI assistant integration
kubescape completionGenerate shell completion scripts
kubescape versionDisplay version information

📖 Usage Examples

Scanning

Scan a Running Cluster

# Default scan (all frameworks)
kubescape scan

# Scan with a specific framework
kubescape scan framework nsa
kubescape scan framework mitre
kubescape scan framework cis-v1.23-t1.0.1

# Scan a specific control
kubescape scan control C-0005 -v

Scan Files and Repositories

# Scan local YAML files
kubescape scan /path/to/manifests/

Categories