NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #3172 by repository stars
Last release 24 days ago
15 Sep 2026
Ships unpredictably
gaps range from 8 days to 6 months
Nearly every release is documented
notes for 24 of 26 stable releases
Nothing withdrawn
no release was ever pulled
1 years old
32 releases · first in 2025
One column per month.
Nothing published for this version
New: the vulnerability practices are answered from your scanner
The first stable release: a correctness and accuracy pass across the scanner
and the site. No framework was dropped and all 110 CMMC practices are still
reported. Several of the fixes change what a scan reports for the same account,
so a v1.0.0 score can differ from v0.8.7's - each case is described below.
RA.L2-3.11.2 and PCI-11.3.1 were answered with a note to document a
procedure. They are now answered from what the cloud's own scanner actually
reaches. The check inventories the account's instances, containers and
functions, asks Amazon Inspector, Microsoft Defender for Cloud or GCP VM Manager
which of them it covers and how recently each was scanned, and fails only on a
genuine gap: an in-scope asset the scanner has never heard of, or one whose last
scan is older than 30 days. Assets you scoped out, or that the scanner cannot
support (an unsupported OS, a stopped instance), are counted and listed, never
failed. A denied API call is an error, not a pass.
AuditKit is not a vulnerability scanner and does not become one here: findings
are not read and CVSS is not re-scored. Measuring open findings against a
remediation window (RA.L2-3.11.3), a configurable policy, Nessus/Trivy/Grype
import and the evidence-package appendix are AuditKit Pro.
A check whose scope was empty reported PASS - "all 0 NSGs have restricted
access rules" - so an empty or wrongly scoped account read as mostly compliant.
Zero resources in scope is now INFO, excluded from the score, with "nothing to
assess" as the evidence.
12 CMMC checks reported FAIL when the API call was denied, so a missing IAM
permission scored as a compliance failure. They now report ERROR, which is
excluded from the score, as the rest of the scanner already did.
-framework cmmc, pci, cis-aws and the rest ran every suite twice and
reported every row twice, counting each FAIL twice in the score: 123 rows for
110 CMMC practices. Each path now runs the suites once and adds only its own
reporters. The Azure and GCP PCI suites, which were only ever run by their own
path, are now in the shared suite list and run on every scan. Severity is read
from whichever field a suite filled.
cis-azure re-listed assessed recommendations and skipped the v6 suitesA cis-azure scan re-listed every assessed recommendation as an unassessed
MANUAL fill (162 rows for a 127-entry benchmark) because the reported-id lookup
missed the mixed-case CIS-Azure tag. The same path never reached the CIS
Azure v6 suites, so 90 recommendations with automated checks were reported as
not assessed. Both are fixed.
A project with VM Manager not enabled now FAILs RA.L2-3.11.2 and PCI-11.3.1
instead of reporting an error. This lowers the reported score for GCP
projects without VM Manager. The score is passed / (passed + failed), so an
error counted in neither half and the control dropped out entirely - a project
with no vulnerability scanning at all scored better than one being scanned
badly, and better than an AWS or Azure account in the identical state. "Nothing
is scanning these instances" is the finding the control exists to report, so it
is scored as one. A genuine permission denial still reports an error, because a
call that did not complete proves nothing about posture.
auditkit-aws, auditkit-azure and auditkit-gcp are gone. They were built
from separate, much simpler code that printed the scanner's rows raw: no
framework filter, no requirement counting, no PDF or HTML, and a
total_controls of "whatever passed or failed". The one auditkit binary
scans every cloud with -provider, correctly.
The site's numbers and claims were corrected against the scanner source:
control, CIS, PCI, HIPAA, NIST 800-53, ISO, CSF, GDPR and FedRAMP figures, the
CMMC "automated" counts (a practice is automated when the check reaches a PASS
or FAIL: 5 of 17 Level 1 on AWS, not 13), the homepage's "350+ automated
checks" (675 controls, measured), and a long list of smaller claims.
coverage-counts.py could not see a control id assigned after the literal or a
verdict assigned in a helper; GCP emits 173 controls where 168 was published.
The html doc pages are rendered from their markdown, and the provider pages'
control lists, the M365 rule lists and the CIS section breakdowns are generated
from the scanner's source and the shipped catalogs, so they cannot drift again.
Lint clean under golangci-lint 2.5: a report that fails to write, an unreadable
progress file and an unreadable release feed are reported rather than ignored;
the rest are explicit discards with the reason beside them. CI gates on lint.
Download the archive for your platform below and verify it against
auditkit-checksums.txt. Go users can also install from source now that the
module tag carries the subdirectory prefix:
go install github.com/guardian-nexus/AuditKit-Community-Edition/scanner/cmd/auditkit@latest
RA.L2-3.11.2 and PCI-11.3.1 are answered
from what the cloud's own scanner actually reaches - Amazon Inspector, Microsoft
Defender for Cloud and GCP VM Manager - instead of asking the reader to document
a procedure. The check inventories the account's instances, containers and
functions, asks the scanner which of them it covers and how recently each was
scanned, and fails only on a genuine gap: an in-scope asset the scanner has never
heard of, or one whose last scan is older than 30 days. Assets the operator
scoped out, or that the scanner cannot support (an unsupported OS, a stopped
instance), are counted and listed, never failed. A denied API call is ERROR, not
PASS. Findings are not read and CVSS is not re-scored; the check consumes the
provider's own severity. Remediation ageing against a policy window
(RA.L2-3.11.3), a configurable policy, third-party scan import and the evidence
appendix are AuditKit Pro.auditkit-aws, auditkit-azure and auditkit-gcp.
They were built from separate, much simpler code that printed the scanner's
rows raw: no framework filter, no requirement counting, no PDF or HTML, and
a total_controls of "whatever passed or failed". The one binary scans every
cloud with -provider, correctly; the download is ~62 MB.-framework cmmc, pci, cis-aws, ...) ran
every suite twice and reported every row twice, counting each FAIL twice
in the score: 123 rows for 110 CMMC practices. Each path now runs the
suites once and adds only its own reporters. Two suites that were
only ever run by their own path (the Azure and GCP PCI suites) are now in
the shared suite list, so they also run on every other scan. Severity is
read from whichever field a suite filled.cis-azure scan re-listed every assessed recommendation as an
unassessed MANUAL fill (162 rows for a 127-entry benchmark): the
reported-id lookup missed the mixed-case CIS-Azure tag. The cis-azure path also never reached the CIS Azure v6 suites, so 90 recommendations with automated checks were reported as not assessed; it does now.RA.L2-3.11.2 and
PCI-11.3.1 instead of reporting an error. This lowers the reported score
for GCP projects without VM Manager. The score is
passed / (passed + failed), so an error was counted in neither half and the
control dropped out entirely - a project with no vulnerability scanning at all
scored better than one being scanned badly, and better than an AWS or Azure
account in the identical state. "Nothing is scanning these instances" is the
finding the control exists to report, so it is now scored as one. A genuine
permission denial is unchanged and still reports an error, because a call that
did not complete proves nothing about posture.Nothing published for this version
Nothing published for this version
A maintenance release that fixes how AuditKit reports its own version. There are no changes to the scanners, the control catalogs, or the reports - co
A maintenance release that fixes how AuditKit reports its own version. There are
no changes to the scanners, the control catalogs, or the reports - coverage is
identical to v0.8.6.
Every defect below was in version reporting rather than in scanning, so a v0.8.6
install produces the same findings as v0.8.7. Upgrade to get an accurate answer
from auditkit version and a working update check.
auditkit update reported the wrong installed versionpkg/updater carried its own CurrentVersion = "v0.3.0" constant. Nothing
overrode it at build time, because the -ldflags -X injection targets
main.CurrentVersion, so the value shipped as written.
The visible effect was that every release told every user they were running
v0.3.0:
New version available: v0.8.6 (you have v0.3.0)
That message appeared even on a freshly installed, fully up-to-date binary. The
updater now takes its version from main at startup instead of holding a second
copy that could drift.
The same update check compared versions as strings. String ordering puts
v0.9.0 above v0.10.0, so the first double-digit minor release would have
silently stopped the update notice from ever firing again - a latent defect that
would have surfaced at v0.10.0 and been hard to attribute.
Versions are now compared numerically, component by component, with a
regression test covering the double-digit case.
The three provider-specific entry points (auditkit-aws, auditkit-azure,
auditkit-gcp) were pinned at v0.8.5 in source while the universal binary
said v0.8.6, and the Makefile passed no -ldflags at all. Both make build-aws and the go build command documented in the README therefore
produced binaries reporting a stale version regardless of the checked-out tree.
All four entry points now agree, and the Makefile derives the version from
git describe so a local build reports what was actually built.
The published archives were checked by extracting the binaries and querying
them, rather than by trusting the build:
v0.8.7 from auditkit versionv0.3.0 string is absent from the universal binaryauditkit update against the live release feed reportsYou're on the latest version (v0.8.7)auditkit-checksums.txtReplace the binary. There is no configuration, cache, or report-format change,
and no reason to re-run a scan you have already collected.
auditkit update reported every install as v0.3.0; it now takes its version
from the binary it is part of, and compares release numbers numerically so
v0.10.0 is correctly newer than v0.9.0.make build injects the version
instead of leaving it unset.No scanner, catalog or report changes - coverage is identical to v0.8.6.
AuditKit Community Edition v0.8.6
Coverage rebaseline and stability pass. The scanner now reports the full control
list each framework defines, rather than only the controls it automates, so a
scan shows the complete assessment scope from the start.
A CMMC scan now lists every Level 1 and Level 2 practice. Level 1 is the
automated set - 13 of the 17 practices carry checks - and 8 Level 2 practices
are automated on GCP. Every remaining practice is reported with
evidence-collection guidance describing what an assessor needs to see.
Automated Level 2 coverage across all three providers, and assessor-ready
evidence package generation, are AuditKit Pro capabilities.
Every supported framework now ships its full control list, so the denominator in
a report is the standard's own:
| Framework | Controls reported |
|---|---|
| CMMC Level 1 + 2 | 110 |
| NIST 800-53 Rev 5 | 1196 |
| PCI DSS v4.0.1 | 312 |
| NIST CSF 2.0 | 106 |
| ISO 27001:2022 | 93 |
| HIPAA Security Rule | 75 |
| SOC 2 | 43 |
| FedRAMP Low / Moderate / High | 149 / 287 / 370 |
Controls without an automated check are reported as such, with evidence guidance,
instead of being omitted.
Baseline membership is taken from the published Low, Moderate and High baselines
rather than a hand-maintained subset.
Scans for 800-53, ISO 27001, NIST CSF, GDPR, HIPAA and the FedRAMP baselines now
execute the complete check set, widening the controls each can reach through the
framework crosswalk.
RemediationDetail wass3:ListAllMyBuckets, Azure needed Microsoft Graph, GCP needed container.*bigquery.*); and the build requirement is Go 1.24, matching go.mod.-provider accepts.Replace the binary. No configuration changes. Expect a CMMC scan to report 110
practices where it previously reported 17; the automated Level 1 findings are
unchanged.
Nothing published for this version
Hotfix for v0.8.4. The binaries published for v0.8.4 were built before the CMMC corrections below had been made, so they report practice identifiers t
Release date: 2 September 2026
Hotfix for v0.8.4. The binaries published for v0.8.4 were built before the CMMC
corrections below had been made, so they report practice identifiers that do not
match the standard. Everything else in v0.8.4 is unchanged and still applies;
read those notes first if you are coming from v0.8.3 or earlier.
A CMMC practice identifier is fully determined: the family prefix follows from
the control number, and the level follows from whether the control is one of the
17 in FAR 52.204-21. Ten identifiers followed neither, all of them claiming
Level 1 for controls that are Level 2:
PE.L1-3.10.2 -> PE.L2-3.10.2
PE.L1-3.10.6 -> PE.L2-3.10.6
PS.L1-3.9.1 -> PS.L2-3.9.1
PS.L1-3.9.2 -> PS.L2-3.9.2
Because those four were labelled Level 1, the scanner appeared to cover all 17
Level 1 practices. It covers 13. That is the number now reported and documented.
The crosswalk was worse. Six keys carried the wrong level or family, four of them
under RE.L2-3.13.x, and RE is not a family at all; those controls belong to SC.
One key was not in 800-171 Rev 2. Canonicalising them merged four duplicate pairs
and dropped the invalid one, so controls that previously derived nothing now
resolve. NIST 800-53 coverage is 96 controls, up from 94, for that reason rather
than any new check.
.github/scripts/check-cmmc.py rejects any non-conforming identifier, in both
the Control field and the framework tags, and runs in CI.
Every count the documentation states is a property of the checks and the
crosswalk. .github/scripts/coverage-counts.py computes them and fails CI if any
documented claim disagrees, against 61 declared claims.
Writing it found that 144, the NIST 800-53 total published in v0.8.4, counted
every control named anywhere in the crosswalk, including entries no check can
reach. Four more numbers were understated on AWS because the earlier measurement
missed criteria written in the Control field, which the scanner does read.
NIST 800-53 total 144 -> 96
NIST 800-53 AWS 77 -> 88
NIST CSF AWS 75 -> 87
ISO 27001 AWS 46 -> 48
GDPR AWS 13 -> 14
GDPR and NIST CSF 2.0 have pages for the first time. Both frameworks started
returning results in v0.8.4 and neither was documented; both pages are explicit
about the limit of what a configuration scan can say, which for GDPR is Article
32 and parts of 25, 30 and 33, and for CSF excludes Govern entirely.
The site claimed AWS 90+ checks, Azure 64+ and GCP 170+ against 229, 178 and 135;
CIS as AWS 126+, Azure ~40+ and GCP 61 against 125, 108 and 26; and HIPAA as
experimental with ~10 controls against 17 safeguards. The published sample report
and the Azure Arc page still cited PCI DSS v3.2.1 requirement numbers that v0.8.4
renumbered, so cross-referencing either against a scan would have matched nothing.
The navigation led with CMMC, which described a tool that assesses nine
frameworks. It now leads with a frameworks index listing all of them. The
homepage banner claimed all new DoW contracts require CMMC compliance; Phase 1
requires self-assessment and Phase 2 was suspended on 13 July 2026, which is what
it says now.
Replace the binary. No configuration changes. If you ran v0.8.4, your CMMC
control identifiers will change and Level 1 coverage will read 13 of 17 rather
than 17 of 17. Nothing regressed; the previous labelling was wrong.
Hotfix for v0.8.4. The v0.8.4 binaries were built before these corrections, so they report CMMC practice identifiers that do not match the standard.
RE.L2-3.13.x, and RE is not a family. One key was not in 800-171.
Merging the resulting duplicates is why NIST 800-53 coverage moved 94 to 96./docs/frameworks/, and navigation that leads with it
rather than with CMMC alone..github/scripts/check-cmmc.py rejects non-conforming practice identifiers in
CI, in both the Control field and the framework tags..github/scripts/coverage-counts.py derives every documented count from the
code and fails CI when a documented claim disagrees.Your compliance score will go down, and that is the point of this release.
Release date: 1 September 2026
Your compliance score will go down, and that is the point of this release.
A control the scanner could not evaluate used to be counted as if it had passed.
Scanning an account with no RDS instances produced "all RDS instances are
encrypted" and scored it as a pass. So did an account where the scanner lacked
the permission to look. On the AWS account used to validate this release, the
reported score fell from 55.0% to 30.8% with no change to the account
itself. The second number is the accurate one.
If your score drops after upgrading, nothing regressed in your environment.
The previous number was counting absences as evidence.
s3:GetBucketTagging, or with buckets in another region, failed theMost PCI requirements a scan emitted derived no NIST 800-53 controls at all,
which meant they were also missing from the ISO 27001, GDPR, NIST CSF and
FedRAMP output derived from it. Three separate causes, all fixed:
5.2.1) and prefixedReq 5.2.1), but the lookup only built a key from the bare form.The SOC2 side of the crosswalk never split multi-value tags, so a check
declaring CC6.1, CC6.6 had the whole string looked up as one key and resolved
to nothing. The Azure CC6 summary declared the range CC6.1-CC6.8, which could
never have matched.
PCI requirements resolving to 800-53: 19 of 97 before, 69 of 69 after.
SOC2 criteria: 38 of 38. NIST 800-53 coverage is 144 controls.
Mappings corrected to match what the service actually does:
| Check | Was | Now |
|---|---|---|
| Macie | 3.5.1 render PAN unreadable | 3.2.1, 12.5.2 data discovery and scope |
| Security Hub | 10.4.1, 11.5.1 | 10.7.2 security control failure detection |
| Inspector | 11.3.2 external ASV scan | 11.3.1 internal scan |
| GCP OS Login | 8.1 (v3.2.1 heading) | 8.2.1 unique identification |
GuardDuty at 11.5.1 was already correct and is unchanged. No part of AuditKit
can evidence an ASV scan, so 11.3.2 was unsatisfiable by construction.
Evidence collection is now durable and tracks staleness.
auditkit evidence status shows what is outstanding and what has gone staleauditkit evidence collect CONTROL-ID records a collection with notes,auditkit evidence import PROGRESS.json imports progress from the HTMLEvidence older than 90 days is reported as stale. evidence import never
worked in any prior build: it consumed its own path argument during flag
parsing and exited 1 on every invocation.
go vet and go test ./... pass; vet, test, build, a check-status guard andThe site claimed features that do not exist. The evidence command was
documented with -format text|html|excel and an evidence-tracker.xlsx
example; there is no Excel support anywhere in AuditKit and the command accepts
neither flag. CSV export is real, via scan -format csv.
Control counts were corrected against the code: GCP 135, Azure 178, PCI DSS 69
requirements, NIST 800-53 144. The compliance score definition now explains what
is excluded from it.
No configuration changes are required. Re-run your usual scan and expect a lower,
more accurate score.
evidence status,
evidence collect, evidence importevidence import consumed its own path argument during flag parsing and
failed on every invocation-format and -framework flags on
evidence that do not exist; control counts corrected against the codeNothing published for this version
This release fixes a reporting defect that affected every generated PDF and HTML report, and repairs the binary download links, which had been returni
Release Date: August 18, 2026
This release fixes a reporting defect that affected every generated PDF and HTML
report, and repairs the binary download links, which had been returning 404.
MANUAL status were counted in the report's denominator but canMANUAL status wereIf you compare a v0.8.3 report against an older one, the score will usually be
higher. Nothing about your environment changed - manual controls are no longer
counted as automated failures. The set of passing and failing technical checks is
unchanged.
auditkit-linux-amd64 rather thanauditkit-linux-amd64.tar.gz), so all three platform commands returned 404. Theauditkit-linux-amd64.tar.gz rather than auditkit-v0.8.3-linux-amd64.tar.gz,releases/latest/download/<name> resolves correctly and keeps working acrossauditkit-aws,auditkit-azure, and auditkit-gcp were pinned at v0.7.0 and had never been-ldflags. It previously targetedmain.Version, a symbol that does not exist, while the code used a const that-ldflags cannot overwrite - so the flag silently did nothing.go vet and go test ./... pass again. A fmt.Sprintf in the GCP manual checkspkg/gcp/checks. The dropped argument was the project ID, which shouldNo configuration changes are required. Replace the binary and re-run your scans.
Expect reported scores to rise if your scans include manual controls. The
underlying pass/fail results are unchanged.
Asset names are stable across releases:
| Platform | File |
|---|---|
| Linux amd64 | auditkit-linux-amd64.tar.gz |
| Linux arm64 | auditkit-linux-arm64.tar.gz |
| macOS Intel | auditkit-darwin-amd64.tar.gz |
| macOS Apple Silicon | auditkit-darwin-arm64.tar.gz |
| Windows amd64 | auditkit-windows-amd64.zip |
Replace auditkit with auditkit-aws, auditkit-azure, or auditkit-gcp in any
filename above. These are 6-11 MB rather than ~59 MB.
Verify downloads against auditkit-checksums.txt.
Release Date: February 17, 2026
Release Date: February 17, 2026
This release removes overclaimed features, fixes broken documentation, and ensures everything we advertise actually works.
report command - The auditkit report command printed a "not yet implemented" message. Removed from CLI. Use auditkit scan -format pdf to generate reports.drift-check command syntax - Website showed incorrect syntax. Updated to match actual CLI usage.fedramp-low, fedramp-moderate, fedramp-high as "coming soon" but the feature was fully implemented. Updated docs to reflect this.auditkit-aws, auditkit-azure, and auditkit-gcp are now built and published alongside the universal binary. Smaller downloads for single-cloud environments and faster CI/CD pipelines.NotImplemented constant from Azure checks| Platform | File | Size |
|---|---|---|
| Linux amd64 | auditkit-v0.8.2-linux-amd64.tar.gz |
59M |
| Linux arm64 | auditkit-v0.8.2-linux-arm64.tar.gz |
54M |
| macOS Intel | auditkit-v0.8.2-darwin-amd64.tar.gz |
61M |
| macOS Apple Silicon | auditkit-v0.8.2-darwin-arm64.tar.gz |
58M |
| Windows amd64 | auditkit-v0.8.2-windows-amd64.zip |
60M |
| Platform | File | Size |
|---|---|---|
| Linux amd64 | auditkit-aws-v0.8.2-linux-amd64.tar.gz |
6.7M |
| Linux arm64 | auditkit-aws-v0.8.2-linux-arm64.tar.gz |
6.0M |
| macOS Intel | auditkit-aws-v0.8.2-darwin-amd64.tar.gz |
6.8M |
| macOS Apple Silicon | auditkit-aws-v0.8.2-darwin-arm64.tar.gz |
6.3M |
| Windows amd64 | auditkit-aws-v0.8.2-windows-amd64.zip |
6.8M |
| Platform | File | Size |
|---|---|---|
| Linux amd64 | auditkit-azure-v0.8.2-linux-amd64.tar.gz |
6.8M |
| Linux arm64 | auditkit-azure-v0.8.2-linux-arm64.tar.gz |
6.4M |
| macOS Intel | auditkit-azure-v0.8.2-darwin-amd64.tar.gz |
7.0M |
| macOS Apple Silicon | auditkit-azure-v0.8.2-darwin-arm64.tar.gz |
6.7M |
| Windows amd64 | auditkit-azure-v0.8.2-windows-amd64.zip |
7.0M |
| Platform | File | Size |
|---|---|---|
| Linux amd64 | auditkit-gcp-v0.8.2-linux-amd64.tar.gz |
12M |
| Linux arm64 | auditkit-gcp-v0.8.2-linux-arm64.tar.gz |
11M |
| macOS Intel | auditkit-gcp-v0.8.2-darwin-amd64.tar.gz |
13M |
| macOS Apple Silicon | auditkit-gcp-v0.8.2-darwin-arm64.tar.gz |
12M |
| Windows amd64 | auditkit-gcp-v0.8.2-windows-amd64.zip |
13M |
# Universal (all providers)
tar -xzf auditkit-v0.8.2-linux-amd64.tar.gz
chmod +x auditkit-linux-amd64
./auditkit-linux-amd64 version
# AWS-only (90% smaller)
tar -xzf auditkit-aws-v0.8.2-linux-amd64.tar.gz
chmod +x auditkit-aws-linux-amd64
./auditkit-aws-linux-amd64 scan -framework soc2
# Azure-only
tar -xzf auditkit-azure-v0.8.2-linux-amd64.tar.gz
chmod +x auditkit-azure-linux-amd64
./auditkit-azure-linux-amd64 scan -framework soc2
# GCP-only
tar -xzf auditkit-gcp-v0.8.2-linux-amd64.tar.gz
chmod +x auditkit-gcp-linux-amd64
./auditkit-gcp-linux-amd64 scan -framework soc2ef1accc4f7acf62397e0b84918a14266e84dd7eaa4ec974ea89934f7cb7a7d7e auditkit-v0.8.2-linux-amd64.tar.gz
9b0be75a35822f76684aee21adbe71c2766fc7fea8647799b2cd3957fbecd3d0 auditkit-v0.8.2-linux-arm64.tar.gz
19a0218f71aab3ab46dbf2deda34c9dad62472b2bd6b68987368f28fb1d8bb0a auditkit-v0.8.2-darwin-amd64.tar.gz
445b9c7c93875edf1118d92970b4c2775b4e6f917de01d2f8f05f7c132b5f34f auditkit-v0.8.2-darwin-arm64.tar.gz
a812be54b65f62787e3c41a2d6d970308f74cc1f45b9321a0917b5062cd4ffd0 auditkit-v0.8.2-windows-amd64.zip
1dbdb07fe4215cd6803e8cce8e1508f7e3fc14d9be0abb88814dfe9752cebb12 auditkit-aws-v0.8.2-linux-amd64.tar.gz
0b9939c718815fc6c3ef719ae8d4222cfa6a205823af0faa1e8f691827288d7e auditkit-aws-v0.8.2-linux-arm64.tar.gz
91d2a6d84d140e475f6e37a2899d136abcd3793fe9d3acb09a27315fe788f338 auditkit-aws-v0.8.2-darwin-amd64.tar.gz
aa09c60e6e5615be460088455c91fad98767c114e00e45c9e651d3efcb7a18cc auditkit-aws-v0.8.2-darwin-arm64.tar.gz
d9bda173d6d0013acc0af89e9f3feecc625c22b9c716f5a0e0f8fcd52c1d10b7 auditkit-aws-v0.8.2-windows-amd64.zip
cc3de62ae4401ddc44facc97ad6b89cf81cb45ace2f05a8a32294eb47c49c710 auditkit-azure-v0.8.2-linux-amd64.tar.gz
465f6ea9522623dfdf661f03c672e9008dd46b3534573e2371981446fc22e6dd auditkit-azure-v0.8.2-linux-arm64.tar.gz
346a10fd7d79d60c3139ae20bbc7330e5067685525724c5da34ddfddea675562 auditkit-azure-v0.8.2-darwin-amd64.tar.gz
297703efa0e5af9ec43d290807adef3ab3d58cf1a94f30c9aa906d3356e0ce40 auditkit-azure-v0.8.2-darwin-arm64.tar.gz
dcda5095e6549188d370f592767f0fab4c0c63d82b5f2bc14bfcc70113ad0014 auditkit-azure-v0.8.2-windows-amd64.zip
cb8f8ec06d2a074962f5c6ab9c678692831ddeeb7cfdbac77223de5086a6a03e auditkit-gcp-v0.8.2-linux-amd64.tar.gz
e90c437d88fe690a297ccdd7256043eb43ac3d60356c7e6489c01c3a31939c9e auditkit-gcp-v0.8.2-linux-arm64.tar.gz
d6bf724824d9d9be62cc1b2db140671c97a85264d1d4eaee1e9fa7aaae4d145e auditkit-gcp-v0.8.2-darwin-amd64.tar.gz
9063888ed41bdb9f02ec3a7759188bdaf1eae5de7a9c0c5e1287695842c9dd4d auditkit-gcp-v0.8.2-darwin-arm64.tar.gz
b24650e90b8717399a3327915f7d11a069bc85827a46d31d3618797c3fd94bf9 auditkit-gcp-v0.8.2-windows-amd64.zip
Full Changelog: v0.8.1...v0.8.2
report command; use auditkit scan -format pdfImport Prowler scan results directly into AuditKit with automatic framework mapping.
Import Prowler scan results directly into AuditKit with automatic framework mapping.
# Run Prowler first
prowler aws --output-formats json -o prowler-output
# Import into AuditKit
auditkit integrate -source prowler -file prowler-output.json
# Generate PDF report from Prowler results
auditkit integrate -source prowler -file prowler-output.json -format pdf -output report.pdfSupported:
Generate remediation scripts for Azure resources - completing support for all three major cloud providers.
# Generate Azure fix script
auditkit fix -provider aws # Already supported
auditkit fix -provider gcp # Already supported
auditkit fix -provider azure # NEW in v0.8.1Interactive HTML checklist for tracking evidence collection during audit prep.
Features:
auditkit evidence-tracker -provider aws -output tracker.htmlDownload the binary for your platform below and run:
chmod +x auditkit-*
./auditkit-linux-amd64 scan -provider aws -framework soc2See CHANGELOG.md for complete version history.
auditkit integrate -source prowler -file prowler-output.jsonauditkit fix -provider azureauditkit evidence -provider aws (writes evidence-tracker.html)pkg/integrations/prowler/parser.go - Prowler JSON parserrunIntegration() to handle Prowler sourcegenerateEvidenceTrackerHTML() with full interactive featuresAuditKit v0.8.1 - Full Prowler Integration + Other Improvements
Compare
AWS Data Analytics & ML Services (24 new checks)
SageMaker (6 checks)
Redshift (7 checks)
ElastiCache (5 checks)
OpenSearch (6 checks)
Run scans without cloud connectivity - essential for air-gapped and classified environments.
Download the binary for your platform below and run:
chmod +x auditkit-*
./auditkit-linux-amd64 scan -provider aws -framework soc2See CHANGELOG.md for complete version history.
--offline flag to use cached scan results--cache-file to specify cache file pathauditkit cache command to manage cached scans-framework gdpr-framework nist-csfRelease Date: December 14, 2025
Release Date: December 14, 2025
This release focuses on fixing compliance check accuracy issues across all three major cloud providers.
Connected the comprehensive PCI-DSS v4.0 implementation covering all 12 requirements. The implementation existed but was not being used by the scanner.
Connected the comprehensive AzurePCIChecks implementation. Previously, Azure PCI scans were using filtered basic checks instead of the dedicated PCI implementation.
Fixed CSV parsing for IAM credential reports. The unused credentials check was returning empty results due to parsing errors when processing the credential report CSV.
Added proper NetworkInterfaces and PublicIPAddresses client integration for accurate detection of VMs with public IP exposure. Previous implementation was incomplete and could miss exposed VMs.
Download the new binary for your platform and replace your existing auditkit binary.
# Verify version
./auditkit --version
# Should show: AuditKit v0.7.1See auditkit-v0.7.1-checksums.txt in the release assets.
These fixes improve compliance check accuracy across all three major cloud providers.
AuditKit now supports Google Cloud Platform (GCP) alongside AWS and Azure, making it the first open-source compliance scanner with unified coverage ac
Release Date: November 4, 2025
AuditKit now supports Google Cloud Platform (GCP) alongside AWS and Azure, making it the first open-source compliance scanner with unified coverage across all three major cloud providers.
Scan GCP projects for SOC2, PCI-DSS, CMMC Level 1, NIST 800-53, ISO 27001, and CIS Benchmarks compliance.
Supported GCP Services:
170+ automated security checks across these services.
Quick Start:
# Authenticate with GCP
gcloud auth application-default login
export GOOGLE_CLOUD_PROJECT=my-project-id
# Run SOC2 scan
./auditkit scan -provider gcp -framework soc2
# Generate PDF report
./auditkit scan -provider gcp -framework soc2 -format pdf -output gcp-soc2-report.pdfNIST 800-53 Rev 5
-framework 800-53ISO 27001:2022
-framework iso27001CIS Benchmarks
-framework cis-aws, -framework cis-azure, -framework cis-gcpAll cloud providers now support the same frameworks with consistent reporting:
| Framework | AWS | Azure | GCP | Purpose |
|---|---|---|---|---|
| SOC2 Type II | 64 controls | 64 controls | 40 controls | SaaS trust & security |
| PCI-DSS v4.0 | 30 controls | 30 controls | 30 controls | Payment card security |
| HIPAA | 70 mappings | 62 mappings | 40 mappings | Healthcare data protection |
| CMMC Level 1 | 17 practices | 17 practices | 17 practices | DoD contractor compliance |
| NIST 800-53 Rev 5 | 150+ controls | 150+ controls | 150+ controls | Federal/FedRAMP foundation |
| ISO 27001:2022 | 54+ controls | 54+ controls | 54+ controls | International InfoSec |
| CIS Benchmarks | 129 controls | 40+ controls | 56 controls | Security hardening |
PCI-DSS Completion
HIPAA Production Ready
CMMC Level 1 Verified
Export compliance results to spreadsheet format for compliance teams:
./auditkit scan -provider gcp -framework soc2 -format csv -output results.csvChoose the right binary for your environment:
Universal Binary (All Platforms)
Provider-Specific Binaries (Linux Only)
auditkit-aws - AWS-only (20MB, 93% smaller)auditkit-azure - Azure-only (26MB, 91% smaller)auditkit-gcp - GCP-only (44MB, 84% smaller)Important: Provider-specific binaries are available for Linux only. Windows and macOS users should use the universal binary.
The README was getting unwieldy at 1000+ lines, so we reorganized:
Before: Everything crammed into README.md
After:
docs/frameworks/ - One guide per framework (CIS, ISO 27001, NIST 800-53)docs/setup/ - Provider-specific authentication and setupdocs/examples/ - CI/CD integration examplesREADME.md - Clean overview with links to detailed docsLinux (amd64):
wget https://github.com/guardian-nexus/auditkit/releases/download/v0.7.0/auditkit-v0.7.0-linux-amd64.tar.gz
tar -xzf auditkit-v0.7.0-linux-amd64.tar.gz
chmod +x auditkit-linux-amd64
./auditkit-linux-amd64 scan -provider gcp -framework soc2Linux (arm64):
wget https://github.com/guardian-nexus/auditkit/releases/download/v0.7.0/auditkit-v0.7.0-linux-arm64.tar.gz
tar -xzf auditkit-v0.7.0-linux-arm64.tar.gz
chmod +x auditkit-linux-arm64
./auditkit-linux-arm64 scan -provider aws -framework pciWindows (amd64):
# Download auditkit-v0.7.0-windows-amd64.zip from releases
# Extract and run:
.\auditkit-windows-amd64.exe scan -provider azure -framework soc2macOS (Intel):
wget https://github.com/guardian-nexus/auditkit/releases/download/v0.7.0/auditkit-v0.7.0-darwin-amd64.tar.gz
tar -xzf auditkit-v0.7.0-darwin-amd64.tar.gz
chmod +x auditkit-darwin-amd64
./auditkit-darwin-amd64 scan -provider aws -framework 800-53macOS (Apple Silicon):
wget https://github.com/guardian-nexus/auditkit/releases/download/v0.7.0/auditkit-v0.7.0-darwin-arm64.tar.gz
tar -xzf auditkit-v0.7.0-darwin-arm64.tar.gz
chmod +x auditkit-darwin-arm64
./auditkit-darwin-arm64 scan -provider gcp -framework iso27001AWS Only (20MB):
wget https://github.com/guardian-nexus/auditkit/releases/download/v0.7.0/auditkit-aws-v0.7.0-linux-amd64.tar.gz
tar -xzf auditkit-aws-v0.7.0-linux-amd64.tar.gz
chmod +x auditkit-aws-linux-amd64
./auditkit-aws-linux-amd64 scan -framework cis-awsAzure Only (26MB):
wget https://github.com/guardian-nexus/auditkit/releases/download/v0.7.0/auditkit-azure-v0.7.0-linux-amd64.tar.gz
tar -xzf auditkit-azure-v0.7.0-linux-amd64.tar.gz
chmod +x auditkit-azure-linux-amd64
./auditkit-azure-linux-amd64 scan -framework cis-azureGCP Only (44MB):
wget https://github.com/guardian-nexus/auditkit/releases/download/v0.7.0/auditkit-gcp-v0.7.0-linux-amd64.tar.gz
tar -xzf auditkit-gcp-v0.7.0-linux-amd64.tar.gz
chmod +x auditkit-gcp-linux-amd64
./auditkit-gcp-linux-amd64 scan -framework soc2Three authentication methods supported:
Option 1: Application Default Credentials (Recommended)
gcloud auth application-default login
export GOOGLE_CLOUD_PROJECT=my-project-id
./auditkit scan -provider gcp -framework soc2Option 2: Service Account Key
export GOOGLE_APPLICATION_CREDENTIALS=/path/to/key.json
export GOOGLE_CLOUD_PROJECT=my-project-id
./auditkit scan -provider gcp -framework pciOption 3: GCE Metadata (for Compute Engine)
# Automatically detected when running on GCE, just set project ID
export GOOGLE_CLOUD_PROJECT=my-project-id
./auditkit scan -provider gcp -framework cmmcRequired Permissions: roles/viewer or equivalent read-only access to your GCP project.
Multi-cloud SOC2 assessment:
./auditkit-linux-amd64 scan -provider aws -framework soc2 -format pdf -output aws-soc2.pdf
./auditkit-linux-amd64 scan -provider azure -framework soc2 -format pdf -output azure-soc2.pdf
./auditkit-linux-amd64 scan -provider gcp -framework soc2 -format pdf -output gcp-soc2.pdfGCP security hardening with CIS Benchmarks:
./auditkit-gcp-linux-amd64 scan -framework cis-gcp -format html -output gcp-hardening.htmlNIST 800-53 assessment for FedRAMP:
./auditkit-linux-amd64 scan -provider aws -framework 800-53 -format csv -output nist-results.csvISO 27001 technical controls:
./auditkit-linux-amd64 scan -provider gcp -framework iso27001 -format pdf -output iso-report.pdfPCI-DSS for payment processing:
./auditkit-linux-amd64 scan -provider azure -framework pci -format html -output pci-report.htmlAuditKit v0.7.0 - SOC2 Compliance Scan
======================================
Provider: GCP
Project: production-project-12345
Framework: SOC2 Type II Trust Services Criteria
Scan Date: 2025-11-04 10:30:00 UTC
Overall Compliance Score: 72.5% (29/40 controls passed)
CRITICAL - Fix These NOW:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[FAIL] CC6.6 - User MFA Enforcement
Evidence: 12 users without MFA enabled
Remediation: gcloud iam policies set-iam-policy ...
[FAIL] CC6.2 - Public Storage Access
Evidence: 3 GCS buckets allow public access
Buckets: backup-prod, logs-archive, static-assets
[FAIL] CC6.1 - Service Account Key Rotation
Evidence: 5 service account keys older than 90 days
Keys: sa-prod@project.iam (183 days), sa-backup@project.iam (274 days)
HIGH - Address Soon:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[FAIL] CC7.1 - Audit Logging
[FAIL] CC6.3 - Disk Encryption
Report saved to: gcp-soc2-report-2025-11-04.pdf
None. This is a purely additive release. All existing functionality for AWS and Azure remains unchanged.
Automated Checks Only
This tool scans technical infrastructure configurations. Full compliance certification requires:
Not a Certification
High scan scores do not equal compliance certification. AuditKit helps you:
Use AuditKit as part of a comprehensive compliance program, not as a replacement for professional audits.
The following features are available in AuditKit Pro:
Interested in Pro features? Contact: info@auditkit.io
Roadmap for upcoming releases:
v0.8.0 (Planned: December 2025)
v0.9.0 (Planned: Q1 2026)
See CHANGELOG.md for complete details of all changes in this release.
AuditKit v0.7.0 - Multi-cloud compliance scanning for AWS, Azure, and GCP.
-framework 800-53-framework iso27001-framework cis-aws, -framework cis-azure, -framework cis-gcp-format csv -output report.csvgcloud CLIauditkit (280MB) - Universal scanner supporting all cloud providersauditkit-aws (20MB) - AWS-only scanner (93% smaller, faster deployment)auditkit-azure (26MB) - Azure-only scanner (91% smaller)auditkit-gcp (44MB) - GCP-only scanner (84% smaller)docs/frameworks/cis-benchmarks.md, docs/frameworks/iso27001.md, docs/frameworks/fedramp.mddocs/setup/ and docs/providers/docs/examples/cicd.mdAuditKit v0.7.0 - Google Cloud Platform Support
Compare
NIST 800-53 Rev 5 Framework Crosswalk
Release Date: October 13, 2025
AuditKit now supports NIST 800-53 Rev 5 scanning through an intelligent framework crosswalk system. Instead of building entirely new checks, we map your existing SOC2, PCI-DSS, and CMMC controls to NIST 800-53 control families.
Quick Example:
# Scan your AWS environment with 800-53 mapping
./auditkit scan -provider aws -framework 800-53
# See results with NIST control IDs
✓ Mapped CC6.6 → IA-2, IA-2(1), IA-5
✓ Mapped CC7.1 → AU-2, AU-3, AU-12
✓ Mapped CC6.1 → AC-2, AC-3, AC-17
[FAIL] IA-2, IA-2(1), IA-5 - Authentication Controls (via CC6.6)
[FAIL] AU-2, AU-3, AU-12 - Audit Logging (via CC7.1)
[FAIL] AC-2, AC-3, AC-17 - Access Controls (via CC6.1)Control Families Covered:
The crosswalk intelligently maps:
New pkg/mappings/crosswalk.go provides intelligent control mapping:
// Check if a control has 800-53 mappings
if crosswalk.ControlHas800_53(control.Frameworks, control.ID) {
// Get the NIST 800-53 IDs
nist80053IDs := crosswalk.Get800_53String(control.Frameworks, control.ID)
// Result: "IA-2, IA-2(1), IA-5"
}Primary: Uses your control's framework mappings
Frameworks: map[string]string{
"SOC2": "CC6.6",
"PCI": "8.3.1",
}
// Crosswalk looks up: SOC2 CC6.6 → IA-2, IA-2(1), IA-5Fallback: Uses control ID directly
Control: "CC6.6"
// Crosswalk looks up: CC6.6 → IA-2, IA-2(1), IA-5This means all controls get mapped, even if they don't have explicit framework mappings!
Control IDs are cleaned and truncated for readability:
Organizational Controls (~850 controls)
These require manual documentation and cannot be automated.
This is not:
This IS:
# Clone and build
git clone https://github.com/guardian-nexus/auditkit
cd auditkit/scanner
go build ./cmd/auditkit
# Or download from releases
wget https://github.com/guardian-nexus/auditkit/releases/download/v0.6.8/auditkit-linux-amd64
chmod +x auditkit-linux-amd64# Run 800-53 scan
./auditkit scan -provider aws -framework 800-53
# Verbose output with mapping details
./auditkit scan -provider aws -framework 800-53 -verbose
# Generate PDF report
./auditkit scan -provider aws -framework 800-53 -format pdf -output report.pdf
# See all controls (no truncation)
./auditkit scan -provider aws -framework 800-53 --full# Configure Azure credentials
az login
export AZURE_SUBSCRIPTION_ID="your-subscription-id"
# Run 800-53 scan on Azure
./auditkit scan -provider azure -framework 800-53pkg/mappings/crosswalk.go - Framework crosswalk enginepkg/mappings/framework-crosswalk.yaml - Control mappings databasecmd/auditkit/main.go - Added 800-53 framework validation and filteringpkg/report/pdf.go - Added 800-53 report sections and control ID handlingpkg/report/html.go - Added 800-53 framework label supportGet800_53ByControlID() - Direct control ID to 800-53 lookupGet800_53StringByControlID() - Formatted string outputControlHas800_53() - Check if control has 800-53 mappingGet800_53String() - Get comma-separated 800-53 IDscleanString() - Unicode character cleanup for PDFsNone. This release is fully backward compatible. Existing scans (SOC2, PCI, CMMC, HIPAA) work exactly as before.
See our roadmap for planned features and vote on what you'd like to see next.
pkg/mappings/crosswalk.go - Framework crosswalk enginepkg/mappings/framework-crosswalk.yaml - SOC2/PCI/CMMC to 800-53 mappingsGet800_53ByControlID() - Direct control ID lookupGet800_53StringByControlID() - Fallback for controls without framework mapsControlHas800_53() - Tries framework map first, then control IDcleanString() function for better unicode handlingv0.6.8 - NIST 800-53 Rev 5 Mapping Support
Compare
Long console URLs in evidence guides now wrap properly instead of breaking page layout.
Long console URLs in evidence guides now wrap properly instead of breaking page layout.
Before:
After:
# Download binary
wget https://github.com/guardian-nexus/auditkit/releases/download/v0.6.7/auditkit-linux-amd64
# Or rebuild from source
git pull origin main
go build ./cmd/auditkitv0.6.6 - Critical Hotfix + Examples
PCI-DSS Scanner Crash
Build Issues
min function causing compilation errorsExamples Added
View examples: docs/examples/
If using v0.6.5, upgrade immediately. That release contains the PCI-DSS crash bug and embedded build paths.
Linux (x64)
curl -LO https://github.com/guardian-nexus/auditkit/releases/download/v0.6.6/auditkit-v0.6.6-linux-amd64.tar.gz
tar -xzf auditkit-v0.6.6-linux-amd64.tar.gz
chmod +x auditkit-linux-amd64
./auditkit-linux-amd64 versionmacOS (Apple Silicon)
curl -LO https://github.com/guardian-nexus/auditkit/releases/download/v0.6.6/auditkit-v0.6.6-darwin-arm64.tar.gz
tar -xzf auditkit-v0.6.6-darwin-arm64.tar.gz
chmod +x auditkit-darwin-arm64
./auditkit-darwin-arm64 versionWindows
Invoke-WebRequest -Uri "https://github.com/guardian-nexus/auditkit/releases/download/v0.6.6/auditkit-v0.6.6-windows-amd64.zip" -OutFile "auditkit.zip"
Expand-Archive -Path auditkit.zip -DestinationPath .
.\auditkit-windows-amd64.exe versionSee CHANGELOG.md for complete version history.
min function compilation errordocs/examples/Critical Bug Fix: PCI-DSS scans no longer crash when AWS credentials have limited EC2 permissions. The scanner now gracefully handles permission error
Release Date: October 11, 2025
Critical Bug Fix: PCI-DSS scans no longer crash when AWS credentials have limited EC2 permissions. The scanner now gracefully handles permission errors instead of panicking.
Anyone running PCI-DSS scans with restricted AWS credentials.
curl -L https://github.com/guardian-nexus/auditkit/releases/download/v0.6.5/auditkit-linux-amd64.tar.gz -o auditkit
chmod +x auditkit
./auditkit --versionInvoke-WebRequest -Uri "https://github.com/guardian-nexus/auditkit/releases/download/v0.6.5/auditkit-windows-amd64.exe" -OutFile "auditkit.exe"
.\auditkit.exe --versiongo install github.com/guardian-nexus/auditkit/scanner/cmd/auditkit@v0.6.5Changed:
Fixed:
Full Changelog: guardian-nexus/AuditKit@v0.6.4...v0.6.5
Added comprehensive compliance disclaimers to PDF and HTML reports
Report Improvements:
Technical Updates:
User Experience:
High automated check scores do not equal full compliance. This update helps users:
PDF Unicode rendering issues (bullets, checkmarks now display correctly)
/pkg/report/html.go with 644 lines of clean HTML generationmain.go HTML output to use new generatorFixed CMMC showing 0/17 controls (now properly returns results)
This is a hotfix for v0.6.1
M365 Integration: New integrate command for importing ScubaGear M365 security results
integrate command for importing ScubaGear M365 security resultspkg/integrations/mappings/scubagear/entra.jsonSpecial thanks to our community contributor for the comprehensive Entra ID security mappings that make AuditKit the first open-source tool providing unified AWS, Azure, and M365 compliance reporting.
CMMC Level 1 Support: Complete implementation of all 17 CMMC Level 1 practices for both AWS and Azure DoW Contractor Compliance: Support for Federal C
Added
CMMC Level 1 Support: Complete implementation of all 17 CMMC Level 1 practices for both AWS and Azure DoW Contractor Compliance: Support for Federal Contract Information (FCI) protection requirements November 10, 2025 Deadline Tracking: Built-in countdown and deadline warnings for CMMC compliance CMMC Evidence Collection: Screenshot guides and console URLs for all 17 Level 1 practices Framework-Specific Help: Enhanced verbose output with control counts and deadline information Upgrade Messaging: Clear path to CMMC Level 2 Pro for organizations handling CUI
Enhanced
Multi-Framework Support: CMMC now joins SOC2 and PCI-DSS as fully supported compliance frameworks Deadline Awareness: Time-sensitive compliance requirements now show days remaining Evidence Collection: Consistent screenshot guide format across all frameworks Framework Validation: Improved error handling and help text for supported frameworks
Technical
Added cmmc_level1.go for AWS provider with all 17 practices Added cmmc_level1.go for Azure provider with all 17 practices Enhanced main.go with CMMC-specific verbose output and deadline calculations Improved framework filtering logic to handle CMMC controls Added CMMC control name mappings and categorization
Business
Open Source Strategy: CMMC Level 1 freely available to build credibility with DoD contractors Clear Monetization Path: Level 2 Pro offering for organizations requiring CUI protection (110 practices) Market Timing: Release aligns with growing urgency around November 2025 deadline
Azure Support - Complete Azure provider implementation
/pkg/azure/ provider structureComplete SOC2 Common Criteria implementation (64 controls across CC1-CC9)
Multi-framework support (SOC2, PCI-DSS, HIPAA)
Evidence collection tracker (auditkit evidence)
auditkit evidence)auditkit progress)auditkit fix)auditkit compare)Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →