This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+6 more
Affected surfaces
ReleasePort's take
Moderate signalThe release adds verification of EC2SA‑P256 signatures on external custom checks before loading.
Why it matters: Security: Requires signing custom check code with severity score 90 to load, enforcing integrity validation for all custom pipelines.
Summary
AI summaryVerify ECDSA‑P256 signatures on external custom checks before loading.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Verifies EC2SA‑P256 signatures on external custom checks before loading. Verifies EC2SA‑P256 signatures on external custom checks before loading. Source: llm_adapter@2026-06-03 Confidence: high |
— |
Full changelog
Feature
- general: verify ECDSA-P256 signatures on external custom checks before loading - #7556
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Checkov
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Related context
Related tools
Beta — feedback welcome: [email protected]